摘要:
A group administration organization device admits a user device to an authorized group by request and sends authority permission information to the user device. The user device holds the authority permission information received from the group administration organization device and, on access, sends authority proof information created from the authority permission information using a group signature scheme to a service provider device as requested by it. The service provider device, upon being accessed, requests the authority proof information and verifies the authority proof information received from the user device in accordance with the request on the basis of the group signature scheme. When the verification result indicates validity, the service provider device provides a service. Thus, there is no need for the service provider to manage personal information of the user because the user device proves to the service provider device using the group signature scheme that it belongs to the authorized group.
摘要:
A device that relieves a service provider of the burden of managing personal information. A group administration organization device admits a user device to an authorized group by request and sends authority permission information to the user device. The user device holds the authority permission information received from the group administration organization device and, on access, sends authority proof information created from the authority permission information using a group signature scheme to a service provider device as requested by it. The service provider device, upon being accessed, requests the authority proof information and verifies the authority proof information received from the user device in accordance with the request on the basis of the group signature scheme. When the verification result indicates validity, the service provider device provides a service. Thus, there is no need for the service provider to manage personal information of the user because the user device proves to the service provider device using the group signature scheme that it belongs to the authorized group.
摘要:
Each embodiment of this invention implements step-by-step and empirical authentication of devices upon digital authentication among a plurality of devices. Each of a plurality of authentication devices of each embodiment can unidirectionally generate a hash value of a low experience rank from a hash value of a high experience rank, and receives a set of high experience rank and hash value in accordance with an experience. Upon receiving a certification request of the experience rank from another authentication device, the authentication device transmits a corresponding hash value to the authentication device as a request source. Upon sending a certification request of an experience rank to another authentication device, the authentication device verifies a hash value obtained from the other authentication device on the basis of a self hash value. In this way, the authentication devices authenticate each other's experience ranks.
摘要:
According to one embodiment, an information management server device determines whether to permit the duplicating of the original data selected in the duplication source selection information. The information management server device reads the management ID of the original data related to the management ID in the duplication request and the electronic data body related to the entity ID with reference to the first and second storage units when the determination result for the original data has shown that the duplicating is permitted and creates duplicated original data by giving a new management ID to duplicated data obtained by duplicating the electronic data body.
摘要:
According to one embodiment, even when the information media controlling apparatus which requests replication registration of electronic data and the information media controlling apparatus which acquires a child management file generated by replication registration are separate apparatuses, the information management server apparatus registers a child management ID of electronic data and a post office box ID of the acquisition destination of a child management file, in the post office box management table based on replication registration request information received from one information media controlling apparatus, and has the other information media controlling apparatus which is the acquisition destination acquire the child management file based on the post office box management table.
摘要:
A secret sharing system and a storage medium where each of the n shareholders P1 to Pn holds a (n, n) share di (0≦i≦n), turns the share di into t(r+1) partial random numbers Sj of the (t, n) type, shares r+1 partial random numbers Sj to the respective shareholders P1 to Pn on the basis of a t-ary representation (value k at the tj-th digit, 0≦k≦t−1, 0≦j≦r) of the identification number z of each of the shareholders Pi, and puts together the shared partial random numbers for each digit tj in the t-ary representation to obtain r+1 shares dj,k. Then, the user unit U selects t shareholders TZ and transmits encrypted data C to the selected t shareholders TZ. The t shareholders Tz perform an operation on the encrypted data C on the basis of the share dj,k to obtain partial outputs XZ and return the partial outputs XZ to the user unit U. Then, the user unit U combines the t partial outputs XZ to obtain the result of decryption.
摘要:
According to one embodiment, a document management system in the embodiments, includes an information acquisition unit that acquires a management ID, acquires, using the management ID, document type information, and outputs the document type information. The document management system in the embodiments of the invention, includes a policy selection evaluation unit that acquires operation information, user information, and the document type information, selects policy information defining an operation extent of user based on the document type information, and evaluates whether or not that a user defined in the user information is authorized to perform an operation defined in the operation information in accordance with a definition of the selected policy information.
摘要:
In one embodiment of the present invention, the information management server apparatus includes an information management relation DB which stores the issued management ID and forming time and date information, user information, a medium type, a use limitation policy, and information management server information in a header portion of the copied management file in association with each other with respect to a management ID of a management file in management file copying request information. The electronic medium control apparatus requests an electronic copying of the management file. The management file is managed in the information management relation DB.
摘要:
A cryptographic module management apparatus searches for cryptographic module meta-information based on the category information of a requested cryptographic module and, if associated cryptographic module category information is contained in this cryptographic module meta-information, searches for the cryptographic module meta-information of an associated cryptographic module, to generate composite type cryptographic module evaluation information based on this cryptographic module meta-information, select a cryptographic module based on this composite type cryptographic module evaluation information, and read this cryptographic module from a cryptographic module storage portion and output such composite type cryptographic module evaluation information.
摘要:
In a cryptographic module distribution system, a cryptographic management server apparatus encrypts a cryptographic module using a key shared by a cryptographic apparatus, and transmits the encrypted cryptographic module to a client apparatus. The client apparatus transmits the encrypted cryptographic module to a cryptographic apparatus. The cryptographic apparatus decrypts the encrypted cryptographic module using the key shared by the cryptographic management server apparatus, and transmits the decrypted cryptographic module to the client apparatus. The client apparatus stores the received cryptographic module.