Network system using a threshold secret sharing method
    1.
    发明授权
    Network system using a threshold secret sharing method 失效
    网络系统采用阈值秘密共享方式

    公开(公告)号:US06477254B1

    公开(公告)日:2002-11-05

    申请号:US09246845

    申请日:1999-02-09

    IPC分类号: H04L908

    CPC分类号: H04L9/085 H04L9/3066

    摘要: In a data encryption/decryption method including an encryption step and a decryption step. In the encryption step, there are prepared n pairs of secret keys and public keys in a public-key cryptographic scheme, where n is a positive integer. A new key is generated in accordance with at least one of the public keys. Data is encrypted in a common-key cryptographic scheme by use of the new key. There is prepared a (k,n) threshold logic (k is an integer equal to or less than n) having terms associated with the new key and the n public keys. A calculation of the threshold logic is conducted by use of the new key and the n public keys, and encrypted data and a result of the calculation of the threshold logic are stored. In the decryption step, the new key is restored from k secret keys selected from the n secret keys and the stored result of the threshold logic calculation in accordance with a threshold reverse logic corresponding to the threshold logic and stored data is decrypted by the restored key in the common-key cryptographic scheme.

    摘要翻译: 在包括加密步骤和解密步骤的数据加密/解密方法中。 在加密步骤中,在公钥加密方案中准备了n对密钥和公钥,其中n是正整数。 根据至少一个公共密钥生成新的密钥。 数据通过使用新密钥以公共密钥加密方案进行加密。 准备具有与新密钥和n个公钥相关联的术语的(k,n)阈值逻辑(k是等于或小于n的整数)。 通过使用新密钥和n个公钥进行阈值逻辑的计算,并且存储加密数据和阈值逻辑的计算结果。 在解密步骤中,根据与阈值逻辑相对应的阈值反向逻辑,从n个秘密密钥中选出的k个秘密密钥和阈值逻辑计算的存储结果中恢复新密钥,并且存储的数据被恢复的密钥解密 在共密密码方案中。

    IC card equipped with elliptical curve encryption processing facility
    2.
    发明授权
    IC card equipped with elliptical curve encryption processing facility 失效
    IC卡配有椭圆曲线加密处理设备

    公开(公告)号:US06466668B1

    公开(公告)日:2002-10-15

    申请号:US09236590

    申请日:1999-01-26

    IPC分类号: H04L930

    CPC分类号: G06F7/725 G06F7/728

    摘要: In an IC card incorporating residual multiplier hardware for implementing a high-speed algorithm for a residual multiplication arithmetic, a method and a device capable of executing public key encryption processing such as an elliptic curve encryption processing at a high speed. Residual arithmetic succeeding to generation of a random number and residual arithmetic in a signature generating processing can be executed by using a residual multiplier. Further, in order to use effectively the residual multiplier for arithmetic operation on an elliptic curve, the point on the elliptic curve is transformed from a two-dimensional affine coordinate system to a three-dimensional coordinate system. Additionally, multiplicative inverse arithmetic for realizing reverse transformation from the three-dimensional coordinate system to the two-dimensional affine coordinate system as well as for determining a signature s can be executed only with the residual multiplication arithmetic. By making use of the residual multiplier in this manner, the processing speed can be increased. Computation complexity can be reduced by storing previously those parameters which are used frequently and constant multiplies of a base point of the elliptic curve in the form of tables, which also contributes to increasing of processing speed.

    摘要翻译: 在包含用于实现用于残余乘法运算的高速算法的残余乘法器硬件的IC卡中,能够以高速执行诸如椭圆曲线加密处理之类的公钥加密处理的方法和装置。 可以通过使用剩余乘数来执行在签名生成处理中继续生成随机数和残差算术的剩余算术。 此外,为了有效地使用用于椭圆曲线上的算术运算的剩余乘数,将椭圆曲线上的点从二维仿射坐标系变换为三维坐标系。 另外,用于实现从三维坐标系到二维仿射坐标系的反向变换以及用于确定签名s的乘法逆运算只能用剩余乘法运算来执行。 通过以这种方式利用剩余乘数,可以提高处理速度。 可以通过先前存储经常使用的那些参数和椭圆曲线的基点的恒定倍数以表的形式来减少计算复杂度,这也有助于提高处理速度。

    IC card equipped with elliptic curve encryption processing facility
    3.
    发明授权
    IC card equipped with elliptic curve encryption processing facility 失效
    IC卡配有椭圆曲线加密处理设备

    公开(公告)号:US06714648B2

    公开(公告)日:2004-03-30

    申请号:US10252669

    申请日:2002-09-24

    IPC分类号: H04L928

    CPC分类号: G06F7/725 G06F7/728

    摘要: In an IC card incorporating residual multiplier hardware for implementing a high-speed algorithm for a residual multiplication arithmetic, a method and a device capable of executing a public key encryption processing such as an elliptic curve encryption processing at a high speed. Residual arithmetic succeeding to generation of a random number and residual arithmetic in a signature generating processing can be executed by using a residual multiplier. Further, in order to use effectively the residual multiplier for arithmetic operation on an elliptic curve, the point on the elliptic curve is transformed from a two-dimensional affine coordinate system to a three-dimensional coordinate system. Additionally, multiplicative inverse arithmetic for realizing reverse transformation from the three-dimensional coordinate system to the two-dimensional affine coordinate system as well as for determining a signature s can be executed only with the residual multiplication arithmetic. By making use of the residual multiplier in this manner, the processing speed can be increased. Computation complexity can be reduced by storing previously those parameters which are used frequently and constant multiplies of a base point of the elliptic curve in the form of tables, which also contributes to increasing of processing speed.

    摘要翻译: 在包含用于实现用于残余乘法运算的高速算法的残余乘法器硬件的IC卡中,能够以高速执行诸如椭圆曲线加密处理的公钥加密处理的方法和装置。 可以通过使用剩余乘数来执行在签名生成处理中继续生成随机数和残差算术的剩余算术。 此外,为了有效地使用用于椭圆曲线上的算术运算的剩余乘数,将椭圆曲线上的点从二维仿射坐标系变换为三维坐标系。 另外,用于实现从三维坐标系到二维仿射坐标系的反向变换以及用于确定签名s的乘法逆运算只能用剩余乘法运算来执行。 通过以这种方式利用剩余乘数,可以提高处理速度。 可以通过先前存储经常使用的那些参数和椭圆曲线的基点的恒定倍数以表的形式来减少计算复杂度,这也有助于提高处理速度。

    Method and apparatus for symmetric-key decryption
    4.
    发明授权
    Method and apparatus for symmetric-key decryption 有权
    用于对称密钥解密的方法和装置

    公开(公告)号:US07359515B2

    公开(公告)日:2008-04-15

    申请号:US11602263

    申请日:2006-11-21

    IPC分类号: H04L9/00

    摘要: A symmetric-key cryptographic technique capable of realizing both high-speed cryptographic processing having a high degree of parallelism, and alteration detection. The invention includes dividing plaintext composed of redundancy data and a message to generate plaintext blocks each having a predetermined length; generating a random number sequence based on a secret key, generating a random number block corresponding to one of the plaintext blocks from the random number sequence, outputting a feedback value obtained as a result of operation on the one plaintext block and the random number block, the feedback value being fed back for using the operation on another plaintext block, and performing an encryption operation using the one plaintext block, random number block, and feedback value.

    摘要翻译: 一种对称密钥加密技术,能够实现具有高度并行性和改变检测的高速密码处理。 本发明包括划分由冗余数据组成的明文和消息,以产生每个具有预定长度的明文块; 基于秘密密钥生成随机数序列,从随机数序列生成与一个明文块相对应的随机数块,将作为操作结果获得的反馈值输出到一个明文块和随机数块上, 对反馈值进行反馈以对另一明文块进行操作,并使用一个明文块,随机数块和反馈值进行加密操作。

    Pseudorandom number generating apparatus or encryption or decryption apparatus using the same
    5.
    发明授权
    Pseudorandom number generating apparatus or encryption or decryption apparatus using the same 有权
    伪随机数生成装置或使用其的加密或解密装置

    公开(公告)号:US07280659B2

    公开(公告)日:2007-10-09

    申请号:US10124577

    申请日:2002-04-18

    IPC分类号: H04L9/00

    CPC分类号: G06F7/582

    摘要: In a buffer and a state included in a pseudorandom number generating apparatus, the state has the configuration of assuming that the unit length of data processing is n, the state has a size of 3×n bits, and the buffer has a capacity of 32×n bits, and according to clock control, a state transformation section (state transformation function) for conducting a state alteration from time t to time t+1 uses a nonlinear function F (having an n-bit input and an n-bit output) twice, or two different nonlinear functions F and G respectively once. The state transformation section has such a configuration that a nonlinear function such as a round function of a block cipher sufficiently evaluated as to the cryptographic security and implementation.

    摘要翻译: 在包括在伪随机数生成装置中的缓冲器和状态中,状态具有假设数据处理的单位长度为n,状态具有3×n位的大小,并且缓冲器具有32×n位的容量的配置, 并且根据时钟控制,用于从时间t到时间t + 1进行状态改变的状态变换部分(状态变换函数)使用两次非线性函数F(具有n位输入和n位输出),或 分别有两种不同的非线性函数F和G。 状态变换部具有对加密安全性和实现充分评估的块密码的循环函数等非线性函数。

    Method and apparatus for symmetric-key encryption
    6.
    发明授权
    Method and apparatus for symmetric-key encryption 有权
    用于对称密钥加密的方法和装置

    公开(公告)号:US07110545B2

    公开(公告)日:2006-09-19

    申请号:US09784254

    申请日:2001-02-16

    IPC分类号: H04L9/28

    摘要: A symmetric-key cryptographic technique capable of realizing both high-speed cryptographic processing having a high degree of parallelism, and alteration detection. The invention includes dividing plaintext composed of redundancy data and a message to generate plaintext blocks each having a predetermined length, generating a random number sequence based on a secret key, generating a random number block corresponding to one of the plaintext blocks from the random number sequence, outputting a feedback value obtained as a result of operation on the one plaintext blocks and the random number block, the feedback value being fed back for using in the operation on another plaintext blocks, and performing an encryption operation using the one plaintext blocks, random number block, and feedback value.

    摘要翻译: 一种对称密钥加密技术,能够实现具有高度并行性和改变检测的高速密码处理。 本发明包括划分由冗余数据组成的明文和消息,以产生每个具有预定长度的明文块,根据秘密密钥产生一个随机数序列,从随机数序列中产生一个对应于明文块的随机数块 输出作为对一个明文块和随机数块的操作结果获得的反馈值,反馈值被反馈以在对另一个明文块的操作中使用,并且使用一个明文块进行加密操作,随机 数字块和反馈值。

    Identification code management method and management system
    7.
    发明授权
    Identification code management method and management system 失效
    识别码管理方法和管理系统

    公开(公告)号:US06934842B2

    公开(公告)日:2005-08-23

    申请号:US09801748

    申请日:2001-03-09

    CPC分类号: G06K17/00 G06Q10/087

    摘要: An identification code management method and management system includes that the issue and distribution of an ID code having a message authentication code are managed thereby to efficiently and reliably manage a material object using the ID code. An electronic circuit chip with an ID code having a message authentication code stored in a read-only area is used as an identification tag. The information at an ID code order receiving terminal and an identification tag production factory terminal are consolidated and collectively managed at an ID code management terminal. Thereby, the ID code management terminal is inquired of highly confidential information or requested to process the information as required so that an ID code utilization terminal is not required to store the same information.

    摘要翻译: 识别代码管理方法和管理系统包括管理具有消息验证码的ID代码的发行和分发,从而有效且可靠地使用ID代码来管理物料对象。 使用具有存储在只读区域中的具有消息认证码的ID码的电子电路芯片作为识别标签。 在ID码管理终端中,将ID码订单接收终端和识别标签生成工厂终端的信息合并统一管理。 由此,向ID码管理终端询问高度机密信息,或者根据需要请求处理该信息,使ID码利用终端不需要存储相同的信息。

    System and method for performing interlocution at a plurality of
terminals connected to communication network
    8.
    发明授权
    System and method for performing interlocution at a plurality of terminals connected to communication network 失效
    用于在连接到通信网络的多个终端处执行交互的系统和方法

    公开(公告)号:US5280583A

    公开(公告)日:1994-01-18

    申请号:US938593

    申请日:1992-09-03

    摘要: A plurality of work stations each imparted with a multi-window control function are interconnected through an integrated service digital network (ISDN), wherein control communication route is established among a plurality of stations between which interlocutory communication are to be performed. The work stations transfer control commands by way of the control communication route in accordance with operation by users under the control of an interlocution control program to thereby establish or disconnect a logical communication route between designated application programs of the work stations. So long as the logical communication route is established, the application programs can execute data processing in cooperation with each other. In that case, identical change of display in the windows corresponding to the application programs, respectively, takes place in the work stations. User can perform conference or document edition processing by designating the position of data of concern by a pointing object while conducting conversation by using a telephone set installed at the work station.

    摘要翻译: 各个赋予多窗口控制功能的多个工作站通过综合业务数字网(ISDN)互连,其中,在要执行非正常通信的多个站之间建立控制通信路由。 工作站根据控制通信路由,根据用户在交互控制程序控制下的操作来传送控制命令,从而建立或断开工作站的指定应用程序之间的逻辑通信路由。 只要建立了逻辑通信路由,应用程序可以彼此协作地执行数据处理。 在这种情况下,在工作站中分别进行与应用程序相对应的窗口中相同的显示变化。 用户可以通过使用安装在工作站的电话机进行通话来指定指示对象所关注的数据的位置来执行会议或文档编辑处理。

    Secret information service system and method
    9.
    发明授权
    Secret information service system and method 失效
    秘密信息服务系统和方法

    公开(公告)号:US5117458A

    公开(公告)日:1992-05-26

    申请号:US606898

    申请日:1990-10-31

    IPC分类号: H04L9/08

    CPC分类号: H04L9/0833 H04L2209/601

    摘要: An information service system including a plurality of receiving stations and information service facilities. The information service facilities include a memory circuit which stores beforehand a distribution destination information set of receiving station identifiers allocated to the receiving stations, distribution destination information set being disposed in a predetermined order within the memory circuit, a memory circuit for storing a plurality of information to be supplied to receiving stations, an enciphering circuit for generating an enciphering key for optical receiving stations within a group which performs broadcast communications, and enciphering the service information with the enciphering key, and a circuit for transmitting the enciphered service information and service destination codes of service destination receiving stations encoded from the distribution destination information set, through broadcast communications. Each receiving station includes a memory circuit for storing beforehand its own identifier and the distribution destination information set of the group which performs broadcast communications, a receiver unit for receiving the enciphered service information and the service destination codes from the information service facilities, and a deciphering circuit for generating a deciphering key corresponding to the distribution destination information set in accordance with the received service destination codes and the corresponding, and previously stored distribution destination information, only when the own identifier of the receiving station is contained in the service destination codes, and the deciphering the enciphered service information with the deciphering key.

    摘要翻译: 一种包括多个接收站和信息服务设施的信息服务系统。 信息服务设备包括预先存储分配给接收站的接收站标识符的分配目的地信息集合的存储电路,存储电路内以预定顺序设置的分发目的地信息集,存储多个信息的存储电路 提供给接收站的加密电路,用于产生用于执行广播通信的组内的光接收站的加密密钥和用加密密钥加密服务信息的加密密钥,以及用于发送加密服务信息和服务目的地代码的电路 通过广播通信从分发目的地信息集合编码的服务目的地接收站。 每个接收站包括用于预先存储其自己的标识符和执行广播通信的组的分发目的地信息集的存储器电路,用于从信息服务设施接收加密服务信息和服务目的地代码的接收器单元,以及解密 电路,用于仅当所述接收站的自身标识符包含在所述服务目的地代码中时才产生与根据所接收的服务目的地代码和所述相应的和预先存储的分发目的地信息所设定的分发目的地信息相对应的解密密钥,以及 用解密密钥对加密的服务信息进行解密。

    Encipher method and decipher method
    10.
    发明授权
    Encipher method and decipher method 失效
    ENCIPHER方法和DECIPHER方法

    公开(公告)号:US5103479A

    公开(公告)日:1992-04-07

    申请号:US618892

    申请日:1990-11-27

    IPC分类号: G09C1/00 H04L9/06

    CPC分类号: H04L9/0625

    摘要: There are provided an encipher method of enciphering message data made by a microcomputer or the like at a high speed by using encipher keys which have previously been stored in a smart card or the like and a decipher method of deciphering the ciphertext made by the encipher method at a high speed by using the encipher keys. The encipher method and the decipher method are suitable for, particularly, a 32-bit microcomputer and include a process expressed by the function Rot.sub.2 i(x) (i=2, 3, 4) in each process. Rot.sub.2 i(x) is the process to circular shift a data train x of 32 bits to the left or right by 2.sup.i bits (i=2, 3, 4).