JP2009303188A5 - - Google Patents
Download PDFInfo
- Publication number
- JP2009303188A5 JP2009303188A5 JP2008172561A JP2008172561A JP2009303188A5 JP 2009303188 A5 JP2009303188 A5 JP 2009303188A5 JP 2008172561 A JP2008172561 A JP 2008172561A JP 2008172561 A JP2008172561 A JP 2008172561A JP 2009303188 A5 JP2009303188 A5 JP 2009303188A5
- Authority
- JP
- Japan
- Prior art keywords
- shared key
- communication terminal
- generation information
- management device
- registered communication
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Claims (26)
非登録通信端末が有する「前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報」を、前記認証基盤を経由せずに受信する、第二共有鍵生成情報管理部と、
前記第一共有鍵及び前記第二共有鍵生成情報を用いて前記第二共有鍵を生成する第二共有鍵管理部と、を備える管理装置。 A first shared key that is shared between the registered communication terminal that has been authenticated in the authentication infrastructure and the device itself is generated, the generated first shared key is stored, and the registered communication is performed via the authentication infrastructure. A first shared key management unit to be transmitted to the terminal;
The "second common key generation information capable of generating a second shared key by using together with the first shared key" with non-registered communication terminal to receive without going through the authentication infrastructure, second covalent A key generation information management unit;
And a second shared key management unit that generates the second shared key using the first shared key and the second shared key generation information.
前記認証基盤を経由した通信によって、第一共有鍵を管理装置と共有する、第一共有鍵管理部と、
前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報を生成して、生成された前記第二共有鍵生成情報を記憶する第二共有鍵生成情報管理部と、
前記第二共有鍵生成情報および前記第二共有鍵を非登録通信端末へ出力する出力部と、を備える登録通信端末。 An authentication management unit that receives authentication in the authentication infrastructure;
A first shared key management unit that shares a first shared key with a management device by communication via the authentication infrastructure;
Second shared key generation information that generates second shared key generation information that can be used together with the first shared key to generate a second shared key and stores the generated second shared key generation information The management department,
An output unit that outputs the second shared key generation information and the second shared key to an unregistered communication terminal.
認証基盤を経由せずに前記第二共有鍵生成情報を前記管理装置へ送信し、前記管理装置によって生成される前記第二共有鍵及び前記第二共有鍵記憶部が記憶する前記第二共有鍵を用いた暗号化通信を前記管理装置と行うことによって、当該管理装置と第三共有鍵を共有する第三共有鍵管理部と、
を備え、
前記第三共有鍵が前記管理装置において他の通信端末に転送されることによって、前記他の通信端末と前記第三共有鍵を共有する、非登録通信端末。 A second shared key storage unit that stores a second shared key shared with the management apparatus and second shared key generation information for generating the second shared key;
Transmitting the second shared key generation information to the management device without going through an authentication infrastructure, and the second shared key generated by the management device and the second shared key storage unit storing the second shared key A third shared key management unit that shares the third shared key with the management device by performing encrypted communication using the management device,
With
An unregistered communication terminal that shares the third shared key with the other communication terminal by transferring the third shared key to the other communication terminal in the management device.
前記管理装置は、前記認証基盤における認証を受けた前記登録通信端末と自装置とで共有する第一共有鍵を生成し、生成された前記第一共有鍵を、記憶すると共に前記認証基盤を経由して前記登録通信端末へ送信し、
前記登録通信端末は、前記管理装置から前記第一共有鍵を受信し、前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報を生成し、生成された前記第二共有鍵生成情報および前記第二共有鍵を前記非登録通信端末へ出力し、
前記管理装置は、前記非登録通信端末が有する前記第二共有鍵生成情報を、前記認証基盤を経由せずに受信し、前記第一共有鍵と前記第二共有鍵生成情報を用いて前記第二共有鍵を生成し、
前記登録通信端末は、前記第一共有鍵及び前記第二共有鍵生成情報を用いて前記第二共有鍵を生成し、
前記非登録通信端末は、前記登録通信端末によって生成された前記第二共有鍵生成情報および前記第二共有鍵の入力を受けて記憶する、ことを特徴とするネットワークシステム。 Includes a registered communication terminal, an unregistered communication terminal, an authentication infrastructure, and a management device, and guarantees confidentiality and integrity in communication between the registered communication terminal and the authentication infrastructure and communication between the authentication infrastructure and the management device. A network system,
The management device generates a first shared key that is shared between the registered communication terminal that has been authenticated by the authentication infrastructure and the device itself, stores the generated first shared key, and stores the authentication infrastructure To the registered communication terminal via
The registered communication terminal receives the first shared key from the management device, generates second shared key generation information that can be used together with the first shared key to generate a second shared key, Outputting the generated second shared key generation information and the second shared key to the unregistered communication terminal ;
The management device receives the second shared key generation information included in the unregistered communication terminal without passing through the authentication infrastructure, and uses the first shared key and the second shared key generation information to Generate a second shared key,
The registered communication terminal generates the second shared key using the first shared key and the second shared key generation information,
The network system, wherein the non-registered communication terminal receives and stores the second shared key generation information and the second shared key generated by the registered communication terminal.
前記管理装置は、暗号化された前記第三共有鍵を受信し、前記第二共有鍵を用いて復号化することによって前記第三共有鍵を生成し、他の前記非登録通信端末に係る他の前記第二共有鍵を用いて前記第三共有鍵を暗号化して前記他の非登録通信端末に送信し、
前記他の非登録通信端末は、暗号化された前記第三共有鍵を受信し、前記他の第二共有鍵を用いて復号化することによって前記第三共有鍵を生成し記憶する、ことを特徴とする、請求項5に記載のネットワークシステム。 The unregistered communication terminal generates a third shared key, encrypts the generated third shared key using the second shared key, and transmits the encrypted third shared key to the management device.
The management device receives the encrypted third shared key, generates the third shared key by decrypting using the second shared key, and other related to the other unregistered communication terminal Encrypting the third shared key using the second shared key and sending it to the other unregistered communication terminal,
The other non-registered communication terminal receives the encrypted third shared key, and generates and stores the third shared key by decrypting using the other second shared key. The network system according to claim 5, wherein the network system is characterized.
前記管理装置が、生成された前記第一共有鍵を、記憶するステップと、
前記管理装置が、前記認証基盤を経由して前記登録通信端末へ前記第一共有鍵を送信するステップと、
前記管理装置が、非登録通信端末が有する「前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報」を、前記認証基盤を経由せずに受信するステップと、
前記管理装置が、受信された前記第二共有鍵生成情報を記憶するステップと、
前記管理装置が、前記第一共有鍵及び前記第二共有鍵生成情報を用いて前記第二共有鍵を生成するステップと、を含む管理方法。 The management device generates a first shared key shared between the registered communication terminal and the own device that have been authenticated in the authentication infrastructure; and
The management device storing the generated first shared key;
The management device transmitting the first shared key to the registered communication terminal via the authentication infrastructure;
The management device, the "second common key generation information capable of generating a second shared key by using together with the first shared key" with non-registered communication terminal, receive without going through the authentication infrastructure And steps to
The management device storing the received second shared key generation information;
The management device includes the step of generating the second shared key using the first shared key and the second shared key generation information.
前記管理装置が、当該第三共有鍵を他の非登録通信端末に対し他の非登録通信端末に対応する前記第二共有鍵を用いて暗号化して送信するステップと、を含む請求項7に記載の管理方法。 The management device sharing the third shared key with the non-registered communication terminal by performing encrypted communication using the second shared key with the non-registered communication terminal without going through the authentication infrastructure; ,
The management device includes a step of encrypting and transmitting the third shared key to another non-registered communication terminal using the second shared key corresponding to the other non-registered communication terminal. The management method described.
前記登録通信端末が、前記認証基盤を経由した通信によって、第一共有鍵を管理装置と共有するステップと、
前記登録通信端末が、前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報を生成するステップと、
前記登録通信端末が、生成された前記第二共有鍵生成情報を記憶するステップと、
前記登録通信端末が、前記第二共有鍵生成情報および前記第二共有鍵を非登録通信端末へ出力するステップと、を含む通信方法。 The registered communication terminal is authenticated in the authentication infrastructure;
The registered communication terminal sharing a first shared key with a management device by communication via the authentication infrastructure;
The registered communication terminal generating second shared key generation information that can be used together with the first shared key to generate a second shared key;
The registered communication terminal storing the generated second shared key generation information;
A method in which the registered communication terminal outputs the second shared key generation information and the second shared key to an unregistered communication terminal .
前記非登録通信端末が、前記第三共有鍵が前記管理装置において他の通信端末に転送されることによって、前記他の通信端末と前記第三共有鍵を共有するステップと、を含む通信方法。 A non-registered communication terminal including a second shared key storage unit that stores a second shared key shared with the management apparatus and second shared key generation information for generating the second shared key does not pass through the authentication infrastructure. The second shared key generation information is transmitted to the management device, and the second shared key generated by the management device and the encrypted communication using the second shared key stored in the second shared key storage unit Sharing the third shared key with the management device by performing
The non-registered communication terminal includes a step of sharing the third shared key with the other communication terminal by transferring the third shared key to the other communication terminal in the management device.
認証基盤における認証を受けた登録通信端末と自装置とで共有する第一共有鍵を生成するステップと、
生成された前記第一共有鍵を、記憶するステップと、
前記認証基盤を経由して前記登録通信端末へ前記第一共有鍵を送信するステップと、
非登録通信端末が有する「前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報」を、前記認証基盤を経由せずに受信するステップと、
受信された前記第二共有鍵生成情報を記憶するステップと、
前記第一共有鍵及び前記第二共有鍵生成情報を用いて前記第二共有鍵を生成するステップと、を実行させるためのコンピュータプログラム。 Against the computer
Generating a first shared key to be shared between the registered communication terminal and the own device that have been authenticated in the authentication infrastructure;
Storing the generated first shared key;
Transmitting the first shared key to the registered communication terminal via the authentication infrastructure;
Receiving " second shared key generation information capable of generating a second shared key by using it together with the first shared key " possessed by an unregistered communication terminal without going through the authentication infrastructure;
Storing the received second shared key generation information;
And generating the second shared key using the first shared key and the second shared key generation information.
前記認証基盤を経由せずに前記第二共有鍵を用いた暗号化通信を前記非登録通信端末と行うことによって、当該非登録通信端末と第三共有鍵を共有するステップと、
当該第三共有鍵を他の非登録通信端末に対し他の非登録通信端末に対応する前記第二共有鍵を用いて暗号化して送信するステップと、をさらに実行させるための請求項11に記載のコンピュータプログラム。 For the computer
Sharing the third shared key with the non-registered communication terminal by performing encrypted communication using the second shared key with the non-registered communication terminal without going through the authentication infrastructure;
The step of encrypting and transmitting the third shared key to another non-registered communication terminal using the second shared key corresponding to the other non-registered communication terminal. Computer program.
認証基盤における認証を受けるステップと、
前記認証基盤を経由した通信によって、第一共有鍵を管理装置と共有するステップと、
前記第一共有鍵とともに用いることによって第二共有鍵を生成することができる第二共有鍵生成情報を生成するステップと、
生成された前記第二共有鍵生成情報を記憶するステップと、
前記第二共有鍵生成情報および前記第二共有鍵を非登録通信端末へ出力するステップと、を実行させるためのコンピュータプログラム。 Against the computer
Receiving authentication in the authentication infrastructure;
Sharing the first shared key with the management device by communication via the authentication infrastructure;
Generating second shared key generation information that can be used together with the first shared key to generate a second shared key;
Storing the generated second shared key generation information;
A step of outputting the second shared key generation information and the second shared key to an unregistered communication terminal .
管理装置と共有される第二共有鍵及び前記第二共有鍵を生成するための第二共有鍵生成情報を記憶する第二共有鍵記憶部を備える非登録通信端末が、認証基盤を経由せずに前記第二共有鍵生成情報を前記管理装置へ送信し、前記管理装置によって生成される前記第二共有鍵及び前記第二共有鍵記憶部が記憶する前記第二共有鍵を用いた暗号化通信を前記管理装置と行うことによって、当該管理装置と第三共有鍵を共有するステップと、
前記第三共有鍵が前記管理装置において他の通信端末に転送されることによって、前記他の通信端末と前記第三共有鍵を共有するステップと、を実行させるためのコンピュータプログラム。 Against the computer
A non-registered communication terminal including a second shared key storage unit that stores a second shared key shared with the management apparatus and second shared key generation information for generating the second shared key does not pass through the authentication infrastructure. The second shared key generation information is transmitted to the management device, and the second shared key generated by the management device and the encrypted communication using the second shared key stored in the second shared key storage unit Sharing the third shared key with the management device by performing
A computer program for executing the step of sharing the third shared key with the other communication terminal by transferring the third shared key to the other communication terminal in the management device.
前記登録通信端末は、前記認証基盤に対し、前記第二共有鍵生成情報を登録することを特徴とする請求項17に記載の登録通信端末。 The second shared key generation information is a GRUU identifier of the unregistered communication terminal,
The registered communication terminal according to claim 17, wherein the registered communication terminal registers the second shared key generation information with the authentication infrastructure.
前記登録通信端末は、前記認証基盤に対し、前記第二共有鍵生成情報を登録することを特徴とする請求項21に記載の通信方法。 The second shared key generation information is a GRUU identifier of the unregistered communication terminal,
The communication method according to claim 21, wherein the registered communication terminal registers the second shared key generation information in the authentication infrastructure.
前記コンピュータプログラムは、前記認証基盤に対し、前記第二共有鍵生成情報を登録するステップをさらにコンピュータに実行させることを特徴とする請求項25に記載のコンピュータプログラム。 The second shared key generation information is a GRUU identifier of the unregistered communication terminal,
The computer program according to claim 25, further causing the computer to execute a step of registering the second shared key generation information with respect to the authentication infrastructure.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2008172561A JP5342818B2 (en) | 2008-05-14 | 2008-07-01 | Management device, registered communication terminal, unregistered communication terminal, network system, management method, communication method, and computer program. |
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2008127760 | 2008-05-14 | ||
JP2008127760 | 2008-05-14 | ||
JP2008172561A JP5342818B2 (en) | 2008-05-14 | 2008-07-01 | Management device, registered communication terminal, unregistered communication terminal, network system, management method, communication method, and computer program. |
Publications (3)
Publication Number | Publication Date |
---|---|
JP2009303188A JP2009303188A (en) | 2009-12-24 |
JP2009303188A5 true JP2009303188A5 (en) | 2011-10-06 |
JP5342818B2 JP5342818B2 (en) | 2013-11-13 |
Family
ID=41549560
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
JP2008172561A Active JP5342818B2 (en) | 2008-05-14 | 2008-07-01 | Management device, registered communication terminal, unregistered communication terminal, network system, management method, communication method, and computer program. |
Country Status (1)
Country | Link |
---|---|
JP (1) | JP5342818B2 (en) |
Families Citing this family (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP5319016B2 (en) * | 2010-01-13 | 2013-10-16 | テレフオンアクチーボラゲット エル エム エリクソン(パブル) | System and method for providing local network configuration |
EP2355455A1 (en) * | 2010-02-04 | 2011-08-10 | Gemalto SA | Method for generating a permanent public SIP address associated with a private identity on an IMS network |
CN103079199B (en) * | 2011-10-26 | 2017-08-25 | 中兴通讯股份有限公司 | A kind of radio sensing network Bidirectional identity authentication method and system |
JP5931802B2 (en) * | 2013-06-06 | 2016-06-08 | 日本電信電話株式会社 | Terminal authentication method and system in network |
US10057765B2 (en) | 2014-09-04 | 2018-08-21 | Samsung Electronics Co., Ltd. | Master node and operation method of the master node |
JP6471039B2 (en) * | 2015-05-18 | 2019-02-13 | 株式会社Nttドコモ | Wireless communication system and wireless terminal |
KR102185215B1 (en) * | 2016-07-06 | 2020-12-01 | 주식회사 케이티 | Operating method of authentication apparatus, system for network access and uthentication, operating method of end terminal and operating method of access terminal |
Family Cites Families (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2006117323A1 (en) * | 2005-04-29 | 2006-11-09 | Telefonaktiebolaget Lm Ericsson (Publ) | Service profile handling in the ims |
US8276189B2 (en) * | 2006-02-06 | 2012-09-25 | Panasonic Corporation | Method, system and apparatus for indirect access by communication device |
JP2010506533A (en) * | 2006-10-11 | 2010-02-25 | テレフオンアクチーボラゲット エル エム エリクソン(パブル) | Reconfiguring IMS devices |
-
2008
- 2008-07-01 JP JP2008172561A patent/JP5342818B2/en active Active
Similar Documents
Publication | Publication Date | Title |
---|---|---|
TWI683566B (en) | Quantum key output method, storage consistency verification method, device and system | |
US10003966B2 (en) | Key configuration method and apparatus | |
JP5390844B2 (en) | Key distribution system and key distribution method | |
CN106789042B (en) | Authentication key agreement method for users in the IBC domain to access resources in the PKI domain | |
WO2013087039A1 (en) | Secure data transmission method, device and system | |
JP2009296190A5 (en) | ||
JP2009526322A5 (en) | ||
JP2009526321A5 (en) | ||
TW201701226A (en) | System, method, and apparatus for electronic prescription | |
JP2015146567A (en) | Computer-implemented system and method for lightweight authentication in datagram transfer for the Internet of Things | |
JP2013243667A5 (en) | ||
JP2009303188A5 (en) | ||
TW201417546A (en) | Instant messaging method and system | |
RU2013149306A (en) | METHOD AND SYSTEM FOR VISITING THIRD PARTY APPLICATIONS THROUGH A CLOUD PLATFORM | |
JP2005102163A5 (en) | ||
JP2009500904A5 (en) | ||
JP2017050849A5 (en) | ||
JP2008125075A5 (en) | ||
JP2009182958A (en) | User domain subscription method for digital rights management and its information exchange method | |
JP2017017686A5 (en) | ||
JP2006276093A5 (en) | ||
CN108183791A (en) | Applied to the Intelligent terminal data safe processing method and system under cloud environment | |
WO2014146609A1 (en) | Information processing method, trust server and cloud server | |
WO2023231817A1 (en) | Data processing method and apparatus, and computer device and storage medium | |
JP2016019233A (en) | Communication system, communication device, key managing device and communication method |