IP Library Granted Patent US 9,712,499
Granted Patent B2
US 9,712,499 · App. 14/667,832 · Granted Jul 18, 2017

Method and apparatus for cryptographic processing

Inventors: Yumi Sakemi (Kawasaki, JP); Tetsuya Izu (London, GB); Masahiko Takenaka (Kawasaki, JP)
Assignee: FUJITSU LIMITED
H04L63/0428H04L9/3231H04L63/0478H04L63/061H04L63/0861G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,712,499
App. No.
14/667,832
Granted
Jul 18, 2017
Kind
B2
Abstract

A cryptographic processing apparatus that holds a first key, and receives authentication object data upon authentication includes a communication unit and a computing unit. The communication unit communicates with a calculation apparatus and a determination apparatus. In the calculation apparatus, encrypted registration data obtained by encrypting registration data twice, once with the first key and once with a second key, is registered. The registration data is data against which the authentication object data is verified. The determination apparatus uses the second key upon the authentication. When registering the encrypted registration data in the calculation apparatus, the computing unit generates a key different from the first key, generates encrypted data by encrypting the registration data twice, once with the first key and once with the different key, transmits the different key to the determination apparatus, and the encrypted data to the calculation apparatus, through the communication unit.

Claims (28)

1. A non-transitory computer-readable storage medium storing a computer program that causes a computer having a memory and a processor, to perform a process comprising:

acquiring, by the processor, a first key and a second key different from the first key, from the memory;

generating, by the processor, first encrypted data by making a logical calculation between data for authentication and the first key, and generating second encrypted data by making the logical calculation between the first encrypted data and the second key;

transmitting, by the processor, the second encrypted data to a calculation apparatus which manages third encrypted data as registered data, the third encrypted data being generated by making the logical calculation between the first encrypted data and a third key; and

transmitting, by the processor, the second key to a determination apparatus which maintains the third key, generates encrypted key data by making the logical calculation between a key received from the computer and the third key, and transmits the encrypted key data to the calculation apparatus;

receiving, by the processor, an authentication result from the determination apparatus, wherein the authentication result is based on the data for authentication;

wherein the third encrypted data are equal to data generated by making the logical calculation between the second encrypted data and the encrypted key data.

2. The non-transitory computer-readable storage medium according to claim 1 , wherein:

the calculation apparatus generates the third encrypted data by using the second encrypted data received from the computer and the encrypted key data received from the determination apparatus.

3. The non-transitory computer-readable storage medium according to claim 1 , wherein at least one of the first key and the second key is generated using a specified key generation function.

4. A cryptographic processing method executed by a computer having a memory and a processor, the cryptographic processing method comprising:

acquiring, by the processor, a first key and a second key different from the first key, from the memory;

generating, by the processor, first encrypted data by making a logical calculation between data for authentication and the first key, and generating second encrypted data by making the logical calculation between the first encrypted data and the second key;

transmitting, by the processor, the second encrypted data to a calculation apparatus which manages third encrypted data as registered data, the third encrypted data being generated by making the logical calculation between the first encrypted data and a third key; and

transmitting, by the processor, the second key to a determination apparatus which maintains the third key, generates encrypted key data by making the logical calculation between a key received from the computer and the third key, and transmits the encrypted key data to the calculation apparatus;

receiving an authentication result from the determination apparatus, wherein the authentication result is based on the data for authentication;

wherein the third encrypted data are equal to data generated by making the logical calculation between the second encrypted data and the encrypted key data.

5. A cryptographic processing apparatus comprising:

a memory configured to store a first key and a second key different from the first key; and

a processor configured to perform a process including:

generating first encrypted data by making a logical calculation between data for authentication and the first key, and generating second encrypted data by making the logical calculation between the first encrypted data and the second key;

transmitting the second encrypted data to a calculation apparatus which manages third encrypted data as registered data, the third encrypted data being generated by making the logical calculation between the first encrypted data and a third key; and

transmitting the second key to a determination apparatus which maintains the third key, generates encrypted key data by making the logical calculation between a key received from the cryptographic processing apparatus and the third key, and transmits the encrypted key data to the calculation apparatus;

receiving an authentication result from the determination apparatus, wherein the authentication result is based on the data for authentication;

wherein the third encrypted data are equal to data generated by making the logical calculation between the second encrypted data and the encrypted key data.

6. The cryptographic processing apparatus according to claim 5 , wherein:

the calculation apparatus generates the third encrypted data by using the second encrypted data received from the cryptographic processing apparatus and the encrypted key data received from the determination apparatus.

7. The cryptographic processing apparatus according to claim 5 , wherein at least one of the first key and the second key is generated using a specified key generation function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2015
From: SAKEMI, YUMI; IZU, TETSUYA; TAKENAKA, MASAHIKO
To: FUJITSU LIMITED
Reel/Frame 035432/0928 →
Priority Claims (1)
JP 2014-070845 · Mar 31, 2014 · national
Continuity (1)
Related Publication 20150281188A1 · Oct 1, 2015