-
公开(公告)号:US09544138B2
公开(公告)日:2017-01-10
申请号:US13985431
申请日:2012-02-17
申请人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
发明人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
CPC分类号: H04L9/085 , H04L9/0819 , H04L9/3242 , H04L9/3271
摘要: According to one embodiment, an authentication method between an authenticatee which stores key information having a data structure composed of a key transition record, secret information XY of a matrix form, and secret information XYE which is created by encrypting the secret information XY, and an authenticator which authenticates the authenticatee, includes selecting, by the authenticator, a record corresponding to a device index of the authenticator from the key information which is received from the authenticatee, and decrypting the record by a device key, thereby taking out a key transition, and executing, by the authenticator, a decryption process on the secret information XYE, which is received from the authenticatee, by using the corresponding key transition, and sharing the secret information XY.
摘要翻译: 根据一个实施例,存储具有由密钥转换记录,矩阵形式的秘密信息XY和通过加密秘密信息XY创建的秘密信息XYE组成的密钥信息的认证方的认证方法,以及 验证认证者的认证方包括由认证者从从认证者接收到的密钥信息中选择与认证者的设备索引对应的记录,并通过设备密钥解密记录,从而进行密钥转换, 并且由认证器执行对从认证者接收的秘密信息XYE的解密处理,通过使用相应的密钥转换并共享秘密信息XY。
-
公开(公告)号:US08995657B2
公开(公告)日:2015-03-31
申请号:US13523290
申请日:2012-06-14
申请人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
发明人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
IPC分类号: H04L9/00
CPC分类号: G09C1/00 , H04L9/3242 , H04L2209/122 , H04L2209/60 , H04N21/25816
摘要: According to one embodiment, a device includes a memory area being used to store a first key (NKey), unique secret identification information (SecretID), and encrypted secret identification information (E-SecretID), the encrypted secret identification information (E-SecretID) being generated by encrypting the secret identification information (SecretID), the first key (NKey) and the secret identification information (SecretID) being prohibited from being read from outside, the encrypted secret identification information (E-SecretID) being readable from outside; a data generator configured to generate a session key (SKey) by using a second key (HKey), the second key (HKey) being generated based on the first key (NKey); and a one-way function processor configured to generate an authentication information by processing the secret identification information (SecretID) with the session key (SKey) in one-way function operation.
摘要翻译: 根据一个实施例,一种设备包括用于存储第一密钥(NKey),唯一秘密识别信息(SecretID)和加密秘密识别信息(E-SecretID)的存储区域,加密的秘密识别信息(E-SecretID )秘密识别信息(SecretID)生成,第一密钥(NKey)和秘密识别信息(SecretID)被禁止从外部读取,加密的秘密识别信息(E-SecretID)可从外部读取; 数据生成器,被配置为通过使用第二密钥(HKey)生成会话密钥(SKey),所述第二密钥(HKey)基于所述第一密钥(NKey)生成; 以及单向功能处理器,被配置为通过在单向功能操作中通过会话密钥(SKey)处理秘密识别信息(SecretID)来生成认证信息。
-
公开(公告)号:US08761389B2
公开(公告)日:2014-06-24
申请号:US13524873
申请日:2012-06-15
CPC分类号: H04L9/0816 , G11B20/00086 , G11B20/0021 , G11B20/00217 , G11B20/00253 , H04L9/0822 , H04L9/0833 , H04L9/0897 , H04L9/32 , H04L2209/601
摘要: According to one embodiment, a memory includes a first storage region capable of storing first key (NKey) information, and secret identification information (SecretID) unique to the authenticate, reading and writing data from and to the first storage region from an outside of the authenticatee being inhibited at least after the authenticatee is shipped.
摘要翻译: 根据一个实施例,存储器包括能够存储第一密钥(NKey)信息的第一存储区域和从第一存储区域的外部识别,读取和写入数据的唯一的秘密识别信息(SecretID) 至少在验证者发货后,验证者被禁止。
-
公开(公告)号:US08751814B2
公开(公告)日:2014-06-10
申请号:US13517900
申请日:2012-06-14
申请人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
发明人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
IPC分类号: G06F21/00
CPC分类号: H04L63/061 , G06F21/10
摘要: According to one embodiment, a device includes a second data generator configured to generate a session key (SKey) by encrypting a random number (RN) with the second key (HKey) in AES operation; a one-way function processor configured to generate an authentication information (Oneway-ID) by processing the secret identification information (SecretID) with the session key (SKey) in one-way function operation; and a data output interface configured to output the encrypted secret identification information (E-SecretID) and the authentication information (Oneway-ID) to outside of the device.
摘要翻译: 根据一个实施例,一种设备包括:第二数据生成器,被配置为通过在AES操作中用第二密钥(HKey)加密随机数(RN)来生成会话密钥(SKey); 单向功能处理器,被配置为通过在单向功能操作中通过会话密钥(SKey)处理秘密识别信息(SecretID)来生成认证信息(Oneway-ID); 以及数据输出接口,被配置为将加密的秘密识别信息(E-SecretID)和认证信息(Oneway-ID)输出到设备外部。
-
25.
公开(公告)号:US08745391B2
公开(公告)日:2014-06-03
申请号:US13513469
申请日:2012-03-22
申请人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
发明人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
IPC分类号: G06F21/00
CPC分类号: H04L9/0869 , G06F21/10 , G06F21/445 , G06F21/73 , G06F21/78 , G06F2221/0724 , H04L9/0861 , H04L9/0866 , H04L9/3263 , H04L2209/60
摘要: A data storage unit can store an encrypted medium device key Enc (Kcu, Kmd_i), and a medium device key certificate (Certmedia). A controller can include an information recording unit to store a controller key (Kc) and first controller identification information (IDcu). A key generation unit executes a one-way function calculation based on the controller key and the first controller identification information to generate a controller unique key (Kcu). An identification information generating unit executes a one-way function calculation based on the controller key and the first controller identification information to generate second controller identification information (IDcntr). A key encryption unit encrypts the medium device key (Kmd_i) by the controller unique key (Kcu) to generate encrypted medium device key Enc (Kcu, Kmd_i). A key exchange unit executes an authentication key exchange process with a host device using the medium device key (Kmd_i) and the medium device key certificate (Certmedia).
摘要翻译: 数据存储单元可以存储加密的介质设备密钥Enc(Kcu,Kmd_i)和中等设备密钥证书(Certmedia)。 控制器可以包括用于存储控制器密钥(Kc)和第一控制器标识信息(IDcu)的信息记录单元。 密钥生成单元基于控制器密钥和第一控制器识别信息执行单向函数计算,以生成控制器唯一密钥(Kcu)。 识别信息生成单元基于控制器键和第一控制器识别信息执行单向函数计算,以生成第二控制器识别信息(IDcntr)。 密钥加密单元通过控制器唯一密钥(Kcu)加密介质设备密钥(Kmd_i),以产生加密的介质设备密钥Enc(Kcu,Kmd_i)。 密钥交换单元使用介质设备密钥(Kmd_i)和介质设备密钥证书(Certmedia)来执行与主机设备的认证密钥交换过程。
-
公开(公告)号:US08693694B2
公开(公告)日:2014-04-08
申请号:US13524842
申请日:2012-06-15
申请人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
发明人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
IPC分类号: H04L9/08
CPC分类号: H04L9/14 , H04L9/0822 , H04L9/3247 , H04L2209/60 , H04N21/26613
摘要: A data storage unit may store an encrypted medium device key Enc (Kcu, Kmd_i), and a medium device key certificate (Certmedia). A controller further includes: an information recording unit configured to store a controller key (Kc) and first controller identification information (IDcu). A key generation unit executes a one-way function calculation based on the controller key and the first controller identification information to generate a controller unique key (Kcu). An identification information generating unit executes a one-way function calculation based on the controller key and the first controller identification information to generate second controller identification information (IDcntr). A key encryption unit encrypts the medium device key (Kmd_i) by the controller unique key (Kcu) to generate encrypted medium device key Enc (Kcu, Kmd_i). A key exchange unit executes an authentication key exchange process with a host device using the medium device key (Kmd_i) and the medium device key certificate (Certmedia).
摘要翻译: 数据存储单元可以存储加密的介质设备密钥Enc(Kcu,Kmd_i)和介质设备密钥证书(Certmedia)。 控制器还包括:信息记录单元,被配置为存储控制器密钥(Kc)和第一控制器标识信息(IDcu)。 密钥生成单元基于控制器密钥和第一控制器识别信息执行单向函数计算,以生成控制器唯一密钥(Kcu)。 识别信息生成单元基于控制器键和第一控制器识别信息执行单向函数计算,以生成第二控制器识别信息(IDcntr)。 密钥加密单元通过控制器唯一密钥(Kcu)加密介质设备密钥(Kmd_i),以产生加密的介质设备密钥Enc(Kcu,Kmd_i)。 密钥交换单元使用介质设备密钥(Kmd_i)和介质设备密钥证书(Certmedia)来执行与主机设备的认证密钥交换过程。
-
公开(公告)号:US20140047240A1
公开(公告)日:2014-02-13
申请号:US13513406
申请日:2012-03-22
申请人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
发明人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
CPC分类号: H04L63/061 , G06F21/44 , G06F21/445 , G06F21/72 , G06F21/73 , G06F21/78 , G06F21/85 , H04L9/0844 , H04L9/0866 , H04L9/0869 , H04L9/3247 , H04L9/3263 , H04L2209/60
摘要: A controller is provided with a controller key and a first controller identification information unique to the controller. The controller generates a controller unique key unique to a respective controller based on the controller key and the first controller identification information, and a second controller identification information based on the first controller identification information. A decryptor decrypts the encrypted medium device key using the controller unique key to obtain a medium device key. An authentication/key exchange process unit performs authentication/key exchange process with the host device through an interface unit using the medium device key, the medium device key certificate and the second controller identification information to establish a secure channel.
-
公开(公告)号:US08627455B1
公开(公告)日:2014-01-07
申请号:US13523485
申请日:2012-06-14
申请人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
发明人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
IPC分类号: G06F21/00
CPC分类号: G06F12/1408 , G06F21/44 , G06F21/79 , H04L9/0816
摘要: According to one embodiment, a manufacturing method of a device to be authenticated, wherein the device includes a first memory area which is prohibited from data-reading and data-writing after shipping from a memory vendor; a second memory area which is allowed to data-read from outside after shipping from the memory vendor; and a third memory area which is allowed to data-read and data-write from outside after sipping from the memory vendor.
摘要翻译: 根据一个实施例,一种要认证的设备的制造方法,其中所述设备包括在从存储器供应商运送之后禁止数据读取和数据写入的第一存储区域; 第二存储器区域,其在从存储器供应商运送之后被允许从外部进行数据读取; 以及第三存储器区域,其在从存储器供应商处理之后被允许从外部进行数据读取和数据写入。
-
公开(公告)号:US08948400B2
公开(公告)日:2015-02-03
申请号:US13524579
申请日:2012-06-15
申请人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
发明人: Taku Kato , Yuji Nagai , Tatsuyuki Matsushita
IPC分类号: H04L9/08
CPC分类号: H04L9/0822 , H04L9/3247 , H04L2209/60
摘要: the host device being configured to receive, from a key issuer who issued the medium device key (Kmd_i) and the medium device key certificate, a host device key (Khd_i) and a host device certificate (Certhost), the host device being configured to execute authentication with the information recording device using the host device key (Khd_i) and the host device certificate (Certhost), the host device being configured to receive second controller identification information (IDcntr) from the information recording device, the second controller identification information being generated by executing a one-way function calculation based on the controller key (Kc) and the first controller identification information (IDcu), and the host device being configured to decrypt the encrypted content data stored in the information recording device, in response to reception of the second controller identification information (IDcntr) from the information recording device.
摘要翻译: 所述主机设备被配置为从发出所述介质设备密钥(Kmd_i)和所述介质设备密钥证书的密钥发行者接收主机设备密钥(Khd_i)和主机设备证书(Certhost),所述主机设备被配置为 使用所述主机设备密钥(Khd_i)和所述主机设备证书(Certhost)与所述信息记录设备一起执行认证,所述主机设备被配置为从所述信息记录设备接收第二控制器标识信息(IDcntr),所述第二控制器标识信息 通过执行基于控制器密钥(Kc)和第一控制器标识信息(IDcu)的单向函数计算而产生的,并且主机设备被配置为响应于接收来对存储在信息记录设备中的加密内容数据进行解密 的来自信息记录装置的第二控制器识别信息(IDcntr)。
-
公开(公告)号:US08938616B2
公开(公告)日:2015-01-20
申请号:US13523188
申请日:2012-06-14
申请人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
发明人: Yuji Nagai , Taku Kato , Tatsuyuki Matsushita
IPC分类号: H04L9/32
CPC分类号: H04L9/32 , H04L9/0877 , H04L9/0897 , H04L9/3234 , H04L9/3271
摘要: According to one embodiment, a authentication method comprising: generating a second key by the first key, the first key being stored in a memory and being prohibited from being read from outside; generating a session key by the second key; generating first authentication information, the secret identification information stored in a memory and being prohibited from being read from outside; transmitting encrypted secret identification information to an external device and receiving second authentication information from the external device, the encrypted secret identification information stored in a memory and readable, the second authentication information generated based on the encrypted secret identification information; and determining whether the first authentication information and the second authentication information match.
摘要翻译: 根据一个实施例,一种认证方法,包括:通过第一密钥生成第二密钥,第一密钥存储在存储器中并被禁止从外部读取; 通过第二个密钥生成会话密钥; 生成第一认证信息,存储在存储器中并被禁止从外部读取的秘密识别信息; 向外部设备发送加密的秘密识别信息并从外部设备接收第二认证信息,所述加密的秘密识别信息存储在存储器中并且可读,所述第二认证信息是基于所述加密的秘密识别信息生成的; 以及确定所述第一认证信息和所述第二认证信息是否匹配。
-
-
-
-
-
-
-
-
-