摘要:
A key recovery condition encryption apparatus includes a hashing unit, a first concatenating unit, and a condition information encryption unit. The hashing unit calculates a hash value on the basis of a hash function using a key recovery information text serving as information necessary for performing key recovery. The first concatenating unit concatenates the hash value from the hashing unit to the key recovery condition. The condition information encrytion unit encrypts a concatenating result from the first concatenating unit by using a first encryption key. Also is disclosed a key recovery condition decryption apparatus for decrypting the encrypted data from the above encryption apparatus.
摘要:
The present invention has an object to overcome problems of a key recovery system using a conventional KRF system and to achieve efficient operation of the overall key recovery system. A key recovery system of the present invention includes check units 12a, 12b for checking whether a user has a recovery authorization for a common key KS, on the basis of a recovery condition RC specified by a recovery condition index RCI which is added to an encrypted message (encrypted message obtained by encrypting the common key KS with a public key KRCpub) supplied from a terminal (10a to 10d) of the user concerned, and a key recovery control unit 14 which is provided separately from the check units 12a, 12b and decrypts the encrypted message with a private key KRCpri paired with the public key KRCpub to recover the common key. The check unit 12a, 12b supplies the common key KS recovered in the key recovery control unit 14 to the user concerned only when the user has the recovery authorization.
摘要:
A key recovery information distribution device is provided between a recoverer device and a key recovery device, recovers a data key for the recoverer device, and reduces the load of the recoverer device. Data is encrypted using the data key and stored with key recovery information. The recoverer device which decrypts the encrypted data distributes the key recovery information to key recovery devices through the key recovery information distribution device to recover key information. A recoverer is authenticated directly between the key recovery device and the recoverer device, and then the key information is transmitted to the recoverer device, and the recoverer device recovers the data key.
摘要:
The present invention has an object to overcome problems of a key recovery system using a conventional KRF system and to achieve efficient operation of the overall key recovery system. A key recovery system of the present invention includes check units 12a, 12b for checking whether a user has a recovery authorization for a common key KS, on the basis of a recovery condition RC specified by a recovery condition index RCI which is added to an encrypted message (encrypted message obtained by encrypting the common key KS with a public key KRCpub) supplied from a terminal (10a to 10d) of the user concerned, and a key recovery control unit 14 which is provided separately from the check units 12a, 12b and decrypts the encrypted message with a private key KRCpri paired with the public key KRCpub to recover the common key. The check unit 12a, 12b supplies the common key KS recovered in the key recovery control unit 14 to the user concerned only when the user has the recovery authorization.
摘要:
A key recovery information distribution device is provided between a recoverer device and a key recovery device, recovers a data key for the recoverer device, and reduces the load of the recoverer device. Data is encrypted using the data key and stored with key recovery information. The recoverer device which decrypts the encrypted data distributes the key recovery information to key recovery devices through the key recovery information distribution device to recover key information. A recoverer is authenticated directly between the key recovery device and the recoverer device, and then the key information is transmitted to the recoverer device, and the recoverer device recovers the data key.
摘要:
A key recovery condition encryption apparatus includes a hashing unit, a first concatenating unit, and a condition information encryption unit. The hashing unit calculates a hash value on the basis of a hash function using a key recovery information text serving as information necessary for performing key recovery. The first concatenating unit concatenates the hash value from the hashing unit to the key recovery condition. The condition information encrytion unit encrypts a concatenating result from the first concatenating unit by using a first encryption key. Also is disclosed a key recovery condition decryption apparatus for decrypting the encrypted data from the above encryption apparatus.
摘要:
It is characterized to comprise an authentication device 4 having invalid information of a key in relation to cryptology, and for disapproving authentication in case that information of an authentication key is included in the invalid information, which is used for authentication when a first cryptographic key in relation to encrypting is shared between a first encrypting device 3 and a first decryption section 11, and an certificate revocation list updating device 5 for updating contents of the invalid information in the authentication device 4 when receiving information of a key of an object to be invalidated, which is provided together with an input data in relation to a work.
摘要:
An encryption key processing system includes a user terminal system (10, 300) which uses a key and a sub-system (20, 100, 200) for holding information regarding the user terminal system (10, 300), the sub-system (20, 100, 200) generating predetermined public information, secret information corresponding to the public information and a secret key dependent on an identifier of said user terminal system (10, 300), sending a secret key to the user terminal system (10, 300) in secret and the user terminal system generating and using a key and necessary information based on a secret key and public information received from the sub-system (20, 100, 200).