Secret key transfer method which is highly secure and can restrict the
damage caused when the secret key is leaked or decoded
    1.
    发明授权
    Secret key transfer method which is highly secure and can restrict the damage caused when the secret key is leaked or decoded 有权
    秘密密钥传输方法,高度安全,可以限制秘密密钥泄漏或解码时造成的损害

    公开(公告)号:US6160890A

    公开(公告)日:2000-12-12

    申请号:US470250

    申请日:1999-12-22

    摘要: A transmission apparatus 100 includes a secret key storage unit 103 that stores three secret keys K1, K2 and K3, a secret key selection unit 104 that selects one secret key Ks from the secret keys, a message generation unit 106 for generating a message M used as a carrier for indicating a secret key, an encryption module 105 for generating a cryptogram Ca by encrypting the generated message M using the secret key Ks, an encryption module 107 for generating a cryptogram Cm by encrypting the message M using the message M itself as the secret key, and two transmission units 111 and 112 for transmitting the cryptograms Ca and Cm to the reception apparatus 200 to indicate the selected secret key Ks. The reception apparatus 200 includes a decryption module, such as 221, for generating decrypted data Mi by decrypting the cryptogram Ca using a secret key Ki out of the three secret keys, and a decryption module, such as 222, for generating decrypted data Mii by decrypting the cryptogram Cm using the decrypted data Mi, and authorizes that the secret key Ki has been selected when the decrypted data Mi matches the decrypted data Mii.

    摘要翻译: 发送装置100包括存储三个秘密密钥K1,K2和K3的秘密密钥存储单元103,从密钥中选择一个秘密密钥Ks的秘密密钥选择单元104,用于生成使用的消息M的消息生成单元106 作为用于指示秘密密钥的载体,用于通过使用秘密密钥Ks加密生成的消息M来生成密码Ca的加密模块105,用于通过使用消息M自身通过加密消息M来生成密码Cm的加密模块107 秘密密钥和用于将密码Ca和Cm发送到接收装置200的两个发送单元111和112,以指示所选择的秘密密钥Ks。 接收装置200包括用于通过使用三个秘密密钥中的秘密密钥Ki对密码Ca进行解密来生成解密数据Mi的解密模块,以及用于通过以下方式生成解密数据Mii的解密模块: 使用解密数据Mi解密密码Cm,并且授权当解密数据Mi与解密数据Mii匹配时已经选择了秘密密钥Ki。

    Encrypted communication system that limits the damage caused when a
secret key has been leaked
    3.
    发明授权
    Encrypted communication system that limits the damage caused when a secret key has been leaked 失效
    加密通信系统,限制秘密密钥泄露时造成的损坏

    公开(公告)号:US6151394A

    公开(公告)日:2000-11-21

    申请号:US940052

    申请日:1997-09-30

    IPC分类号: H04L9/08 H04L9/00

    CPC分类号: H04L9/0833 H04L9/0822

    摘要: In an encrypted transmission system composed of one transmission apparatus 10 and twenty-eight reception apparatuses A1-G4 that are classified into seven groups A-G, two secret key exclusively selected out of a total of fourteen secret keys are distributed beforehand to each group. The transmission apparatus 10 encrypts the same message M using one of the two secret keys distributed to each group and sends each group a message M encrypted with one of the group's secret keys. The reception apparatuses each decrypt the received cryptogram separately using each of the secret keys assigned to the of group to which each reception apparatus belongs, judge whether either of the two decryption results conforms to a predetermined rule, and specify the correct decryption result.

    摘要翻译: 在由分组为七组A-G的一个发送装置10和二十八个接收装置A1-G4组成的加密传输系统中,预先向每个组分发从总共14个秘密密钥中唯一选择的两个秘密密钥。 发送装置10使用分配给每个组的两个秘密密钥中的一个对相同的消息M进行加密,并且向每个组发送用该组的秘密密钥之一加密的消息M. 接收装置分别使用分配给每个接收装置所属的组的每个秘密密钥来分别接收密码,判断两个解密结果是否符合预定规则,并指定正确的解密结果。

    Device authentication system which allows the authentication function to
be changed
    7.
    发明授权
    Device authentication system which allows the authentication function to be changed 失效
    允许更改认证功能的设备认证系统

    公开(公告)号:US6034618A

    公开(公告)日:2000-03-07

    申请号:US940076

    申请日:1997-09-29

    IPC分类号: H04L9/32 G06F11/00

    CPC分类号: H04L9/3271

    摘要: The decoder apparatus 90 generates a random number R1 for authenticating the optical disc drive apparatus 70 and sends it to the optical disc drive apparatus 70 as the challenge data CHA1. The optical disc drive apparatus 70 selects one out of the sixteen claimant functions stored in the claimant function unit 722 and calculates the function value fi(CHA1) which it sends to the decoder apparatus 90 as the response data RES1. The decoder apparatus 90 compares the response data RES1 with sixteen function values f1(R1) to f16(R1) that are obtained using the sixteen verification functions stored in the verification function unit 922, and authenticates the optical disc drive apparatus 70 when at least one of the function values matches the response data RES1.

    摘要翻译: 解码器装置90生成用于认证光盘驱动装置70的随机数R1,并将其发送到作为挑战数据CHA1的光盘驱动装置70。 光盘驱动装置70选择存储在权利要求函数单元722中的十六个要求函数中的一个,并将作为响应数据RES1发送给解码装置90的函数值fi(CHA1)进行计算。 解码器装置90将响应数据RES1与使用存储在验证功能单元922中的十六个验证功能获得的十六个功能值f1(R1)至f16(R1)进行比较,并且当至少一个 的功能值与响应数据RES1匹配。

    One-way data conversion apparatus and device authentication system
    8.
    发明授权
    One-way data conversion apparatus and device authentication system 失效
    单向数据转换装置和设备认证系统

    公开(公告)号:US6049611A

    公开(公告)日:2000-04-11

    申请号:US963680

    申请日:1997-10-31

    IPC分类号: H04L9/32 G09C1/00 H04L9/00

    摘要: The verifier apparatus 50 includes a random number generation unit 51 that generates a 2n-bit random number, a separator unit 52 that separates the random number into two sets of n-bit data, a data conversion module 53 that converts one set of separated data using the other set of separated data as a key, and a comparator unit 54 that judges whether the converted result matches claimant data sent back from the claimant apparatus 60. The claimant apparatus 60 includes a separator unit 61 and a data conversion module 62 that have the same functions as the separator unit 52 and the data conversion module 53 in the verifier apparatus 50. The claimant apparatus 60 generates n-bit claimant data from the 2n-bit random number generated by the verifier apparatus 50, and sends the generated claimant data to the verifier apparatus 50.

    摘要翻译: 验证装置50包括生成2n位随机数的随机数生成单元51,将随机数分成两组n位数据的分离单元52,将一组分离数据进行转换的数据转换模块53 使用另一组分离的数据作为键,以及比较器单元54,其判断转换的结果是否与从索赔者装置60发回的索赔数据相匹配。索赔者装置60包括分离单元61和数据转换模块62, 与验证器装置50中的分离器单元52和数据转换模块53具有相同的功能。索赔装置60根据由验证器装置50生成的2n位随机数生成n位请求者数据,并发送所生成的请求者数据 到验证器装置50。