IP Library Granted Patent US 9,509,510
Granted Patent B2
US 9,509,510 · App. 14/645,910 · Granted Nov 29, 2016

Communication device, communication method, and computer program product

Inventor: Yoshimichi Tanizawa (Yokohama, JP)
Assignee: Kabushiki Kaisha Toshiba
H04L9/16H04L9/0852H04L63/061H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,509,510
App. No.
14/645,910
Granted
Nov 29, 2016
Kind
B2
Abstract

According to an embodiment, a communication device includes a first manager, and a second manager, a first communication unit, a determination unit, a controller, and a second communication unit. The first manager shares a first cryptographic key with a first external device connected via a link. The second manager shares a second cryptographic key to be provided to an application, with the first external device and with a second external device connected via links. The first communication unit transmits the second cryptographic key to the first external device. The determination unit determines whether a device with which the second cryptographic key is to be shared is the first external device. If it is affirmative, the controller controls the second manager to share, as the second cryptographic key, a cryptographic key obtained by converting the first cryptographic key. The second communication unit provides the application with the second cryptographic key.

Claims (34)

1. A communication device comprising:

a first manager to share a first cryptographic key with a first external device that is connected via a link;

a second manager to share a second cryptographic key that is provided to an application, with the first external device and with a second external device that is connected via a plurality of links;

a first communication unit to transmit to the first external device, the second cryptographic key being encrypted using the first cryptographic key;

a determination unit to determine whether a device with which the second cryptographic key is to be shared is the first external device;

a controller to control the second manager to share, as the second cryptographic key, a cryptographic key that is obtained by converting the first cryptographic key, when the device with which the second cryptographic key is to be shared is the first external device; and

a second communication unit to provide the application with the second cryptographic key, wherein

the controller further controls the second manager to convert the first cryptographic key when at least one of

a residual quantity of the first cryptographic key is equal to or greater than a first threshold, and

frequency of use of the first cryptographic key in encryption of the second cryptographic key is equal to or less than a second threshold.

2. The device according to claim 1 , wherein the first communication unit further transmits specific information that specifies the converted first cryptographic key to the first external device.

3. The device according to claim 1 , wherein the determination unit determines whether a device with which the application performs cryptographic communication is the first external device with reference to setup information on processing in which the first manager shares the first cryptographic key.

4. The device according to claim 1 , wherein the determination unit determines whether a device with which the application performs cryptographic communication is the first external device with reference to network information.

5. The device according to claim 1 , wherein the first manager shares the first cryptographic key based on quantum key distribution.

6. A communication method comprising:

sharing a first cryptographic key with a first external device that is connected via a link;

sharing a second cryptographic key that is provided to an application, with the first external device and with a second external device that is connected via a plurality of links;

transmitting the second cryptographic key to the first external device, the second cryptographic key being encrypted using the first cryptographic key;

determining whether a device with which the second cryptographic key is to be shared is the first external device, the second cryptographic key being provided to the application;

controlling the sharing of the second cryptographic key to share, as the second cryptographic key, a cryptographic key that is obtained by converting the first cryptographic key, when the device with which the second cryptographic key is to be shared is the first external device; and

transmitting the second cryptographic key to the application, wherein

the controlling includes controlling converting the first cryptographic key when at least one of

a residual quantity of the first cryptographic key is equal to or greater than a first threshold, and

frequency of use of the first cryptographic key in encryption of the second cryptographic key is equal to or less than a second threshold.

7. A non-transitory computer-readable medium including programmed instructions stored therein, wherein the instructions cause a computer to function as:

a first manager to share a first cryptographic key with a first external device that is connected via a link;

a second manager to share a second cryptographic key that is provided to an application, with the first external device and with a second external device that is connected via a plurality of links;

a first communication unit to transmit the second cryptographic key to the first external device, the second cryptographic key being encrypted using the first cryptographic key;

a determination unit to determine whether a device with which the second cryptographic key is to be shared is the first external device, the second cryptographic key being provided to the application;

a controller to control the second manager to share, as the second cryptographic key, a cryptographic key that is obtained by converting the first cryptographic key, when the device with which the second cryptographic key is to be shared is the first external device; and

a second communication unit to provide the application with the second cryptographic key, wherein

the controller further controls the second manager to convert the first cryptographic key when at least one of

a residual quantity of the first cryptographic key is equal to or greater than a first threshold, and

frequency of use of the first cryptographic key in encryption of the second cryptographic key is equal to or less than a second threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: TANIZAWA, YOSHIMICHI
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 035689/0938 →
Priority Claims (1)
JP 2014-056596 · Mar 19, 2014 · national
Continuity (1)
Related Publication 20150270963A1 · Sep 24, 2015