IP Library › Granted Patent US 11,070,365
Granted Patent B2
US 11,070,365 · App. 16/083,557 · Granted Jul 20, 2021

Encryption communication system, encryption communication method, security chip, communication apparatus, and control method and control program of communication apparatus

Inventor: Masayuki Satou (Tokyo, JP)
Assignee: NEC CORPORATION
H04L9/0825G09C1/00G09C5/00H04L9/0618H04L9/0637H04L9/0841H04L9/0877H04L63/0428H04L63/0435H04L63/061H04L63/062H04L2209/127H04L2463/061H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,070,365
App. No.
16/083,557
Granted
Jul 20, 2021
Kind
B2
Abstract

This invention is directed to an encryption communication system for preventing leakage of a common key and improving the confidentiality of communication information. The encryption communication system uses a pair of a first private portion and a first public portion and a pair of a second private portion and a second public portion in a key predistribution system (KPS) The encryption communication system comprises a ciphertext generator that generates a ciphertext by generating, in a first security chip (TPM) of a first communication apparatus, a first common key by the first private portion held in the first security chip using the second public portion transmitted from a second communication apparatus as a communication partner, and encrypting a plaintext using the first common key in the first security chip, and a decryptor that generates a plaintext by generating, in a second security chip of the second communication apparatus, a second common key by the second private portion held in the second security chip using the first public portion transmitted from the first communication apparatus as a communication partner, and decrypting the ciphertext received from the first communication apparatus using the second common key in the second security chip.

Claims (41)

1. An encryption communication system that uses a pair of a first private portion and a first public portion and a pair of a second private portion and a second public portion in a key predistribution system (KPS), comprising:

a ciphertext generator that generates a ciphertext by generating, in a first security chip (TPM: Trusted Platform Module) of a first communication apparatus, a first common key by the first private portion held in the first security chip using the second public portion transmitted from a second communication apparatus as a communication partner, and encrypting a plaintext using the first common key in the first security chip; and

a decryptor that generates a plaintext by generating, in a second security chip of the second communication apparatus, a second common key by the second private portion held in the second security chip using the first public portion transmitted from the first communication apparatus as a communication partner, and decrypting the ciphertext received from the first communication apparatus using the second common key in the second security chip,

wherein said ciphertext generator generates an initialization vector (IV) when performing encryption of block units, based on a part for the initialization vector held in the first private portion and a part for the initialization vector held in the second public portion, and use the generated initialization vector for the encryption, and

said decryptor generates the initialization vector when performing decryption of block units, based on a part for the initialization vector held in the second private portion and a part for the initialization vector held in the first public portion, and use the generated initialization vector for the decryption, and

further comprising:

a first function provider that causes the first security chip to function as said ciphertext generator by making the first security chip store a program and data for providing functions of:

a first private portion holder that receives and holds the first private portion;

a first common key generator that generates the first common key in accordance with the key predistribution system based on the first private portion and the second public portion;

a ciphertext generation controller that receives an encryption command attached with a plaintext and the second public portion, causes said first common key generator to generate the first common key, and encrypting the plaintext based on the first common key to generate a ciphertext; and

a first initialization vector generator that generates the initialization vector based on the part for the initialization vector held in the first private portion and the part for the initialization vector held in the second public portion, and

a second function provider that causes the second security chip to function as said decryptor by making the second security chip store a program and data for providing functions of:

a second private portion holder that receives and holds the second private portion;

a second common key generator that generates the second common key in accordance with the key predistribution system based on the second private portion and the first public portion;

a decryption controller that receives a decryption command attached with a ciphertext and the first public portion, causes said second common key generator to generate the second common key, and decrypts the ciphertext based on the second common key to generate a plaintext; and

a second initialization vector generator that generates the initialization vector based on the part for the initialization vector held in the second private portion and the part for the initialization vector held in the first public portion.

2. The encryption communication system according to claim 1 , wherein said ciphertext generation controller discards the first common key after encryption using the first common key, and said decryption controller discards the second common key after decryption using the second common key.

3. The encryption communication system according to claim 1 , further comprising:

a first operation preparation unit that causes the first communication apparatus to hold, out of the pair of the first private portion and the first public portion in the key predistribution system, the first private portion in the first security chip of the first communication apparatus and transmit the first public portion to the second communication apparatus; and

a second operation preparation unit that causes the second communication apparatus to hold, out of the pair of the second private portion and the second public portion in the key predistribution system, the second private portion in the second security chip of the second communication apparatus and transmit the second public portion to the first communication apparatus.

4. A communication apparatus comprising a security chip (TPM: Trusted Platform Module), that functions as the ciphertext generator in an encryption communication system according to claim 1 ,

said security chip comprising:

a private portion holder that holds a private portion in a key predistribution system (KPS);

a common key generator that generates a common key by the held private portion using a public portion in the key predistribution system transmitted from a communication partner;

a ciphertext generation controller that receives an encryption command attached with a plaintext and the public portion, causes said common key generator to generate the common key and generates a ciphertext by encrypting a plaintext using the common key; and

an initialization vector (IV) generator that generates an initialization vector when performing encryption of block units, based on a part for the initialization vector held in the private portion and a part for the initialization vector held in the public portion, and

said communication apparatus further comprising a function provider that makes the security chip store a program and data for providing functions of the private portion holder, the common key generator, the ciphertext generation controller and the initialization vector generator.

5. The communication apparatus according to claim 4 , wherein said ciphertext generation controller discards the common key after encryption using the common key.

6. The communication apparatus according to claim 4 , wherein said security chip further comprising a decryption controller that receives a decryption command attached with a ciphertext and the public portion from the communication partner, causes said common key generator to generate the common key and generates a plaintext by decrypting the ciphertext using the common key.

7. The communication apparatus according to claim 6 , wherein said decryption controller discards the common key after decryption using the common key.

8. A security chip (TPM: Trusted Platform Module) of a communication apparatus according to claim 4 , comprising:

a private portion holder that holds a private portion in a key predistribution system (KPS);

a common key generator that generates a common key in accordance with the key predistribution system based on the held private portion and a public portion in the key predistribution system transmitted from a communication partner;

a ciphertext generation controller that receives an encryption command attached with a plaintext and the public portion transmitted from the communication partner, causing said common key generator to generate the common key, and encrypting the plaintext using the common key to generate a ciphertext; and

an initialization vector (IV) generator that generates an initialization vector when performing encryption of block units, based on a part for the initialization vector held in the private portion and a part for the initialization vector held in the public portion,

wherein said security chip is provided with functions of the private portion holder, the common key generator, the ciphertext generation controller and the initialization vector generator by storing a program and data for providing the functions.

9. The security chip according to claim 8 , wherein said ciphertext generation controller discards the common key after encryption using the common key.

10. The security chip according to claim 8 , further comprising a decryption controller that receives a decryption command attached with a ciphertext and the public portion transmitted from the communication partner, causing said common key generator to generate the common key, and decrypting the ciphertext using the common key to generate a plaintext.

11. The security chip according to claim 10 , wherein said decryption controller discards the common key after decryption using the common key.

12. The encryption communication system according to claim 2 , further comprising an operation preparation unit that causes the first communication apparatus to hold, out of the pair of the first private portion and the first public portion in the key predistribution system, the first private portion in the first security chip of the first communication apparatus and transmit the first public portion to the communication partner of the first communication apparatus, and the second communication apparatus to hold, out of the pair of the second private portion and the second public portion in the key predistribution system, the second private portion in the second security chip of the second communication apparatus and transmit the second public portion to the communication partner of the second communication apparatus.

13. The communication apparatus according to claim 5 , further comprising an operation preparation unit that causes the communication apparatus to hold, out of the pair of the private portion and the public portion in the key predistribution system, the private portion in the security chip of the communication apparatus and transmit the public portion to the communication partner of the communication apparatus.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2018
From: SATOU, MASAYUKI
To: NEC CORPORATION
Reel/Frame 046830/0149 →
Priority Claims (1)
JP JP2016-048244 · Mar 11, 2016 · national
Continuity (1)
Related Publication 20190081776A1 · Mar 14, 2019