Data file encryption and transmission/reception system and data file encryption and transmission/reception method
A data file encryption transmission/reception system includes a computer with a registration module that encrypts input data files. The registration module includes a string conversion module that configured to convert the data file to be encrypted to string data, a key generation module that configured to generate a common key, and to divide the common key and the string data into first input information and second input information, a common key encryption module is configured to encrypt the first input information with the common key, to thereby generate common key encrypted data, a searchable encryption module that configured to encrypt the second input information in accordance with searchable encryption with a user secret key set in advance, to thereby generate searchable encrypted data and a communication module is configured to register a set of the common key encrypted data and the searchable encrypted data in the data management server.
1 . A data file encryption, transmission and reception system, comprising:
a temporary database server configured to store data; and
a computer, which is coupled to the temporary database server via a network, and includes a processor and a memory, the computer configured to:
convert the data file to be encrypted to string data,
generate a common key, which changes every time and an initial vector, which is a pseudo random number,
divide the string data into a first string data and second string data,
encrypt first input information and the first string data with the common key, thereby generating common key encrypted data,
encrypt second input information, the common key, and the second string data in accordance with probabilistic encryption which uses a mask using the user secret key, the pseudo random number, and a homomorphic function, thereby generating searchable encrypted data, and
register a set of the common key encrypted data and the searchable encrypted data in the data management server,
wherein the computer further includes:
an applicant terminal which includes a public key distributed in advance; and
a registrant terminal which has a secret key corresponding to the public key distributed in advance,
wherein the applicant terminal is configured to encrypt the data file with the common key, to thereby generate the common key encrypted data, encrypt the common key and the association ID with the public key, to thereby generate public key encrypted data, and to register the common key encrypted data and the public key encrypted data in the temporary database server, and
wherein the registrant terminal is configured to acquire the common key encrypted data and the public key encrypted data from the temporary database server, decrypt the public key encrypted data with the secret key, encrypt the decrypted common key and the association ID with the user secret key in accordance with the searchable encryption, to thereby generate the searchable encrypted data, and to register the common key encrypted data and the searchable encrypted data in the data management server.
2 . The data file encryption, transmission and reception system according to claim 1 ,
wherein the computer is configured to:
generate an association ID for associating the set of the common key encrypted data and the searchable encrypted data with each other,
acquire the association ID, to thereby identify the set of the common key encrypted data and the searchable encrypted data stored in the data management server, and
acquire the identified common key encrypted data and searchable encrypted data from the data management server.
3 . The data file encryption, transmission and reception system according to claim 2 ,
wherein the generated association ID is included in the second input information,
wherein the computer is configured to:
decrypt the searchable encrypted data acquired from the data management server with the user secret key, to thereby acquire the association ID from the second input information and the common key,
search the data management server by the association ID for the common key encrypted data corresponding to the searchable encrypted data to acquire the common key encrypted data corresponding to the association ID, and to decrypt the common key encrypted data with the decrypted common key, to thereby generate the string data, and
generate the data file from the string data.
4 . The data file encryption, transmission and reception system according to claim 3 ,
wherein the computer includes a first computer and a second computer which are coupled to the data management server,
wherein the first computer is configured to register a set of the common key encrypted data and the searchable encrypted data in the data management server, and
wherein the second computer is configured to:
acquire the association ID, to thereby identify the set of the common key encrypted data and the searchable encrypted data stored in the data management server, and
acquire the identified common key encrypted data and searchable encrypted data from the data management server.
5 . The data file encryption, transmission and reception system according to claim 3 ,
wherein the computer is configured to:
include the association ID and the initial vector in the second input information, and
encrypt the first input information through use of the common key and the initial vector.
6 . The data file encryption, transmission and reception system according to claim 4 ,
wherein the first computer is configured to generate the searchable encrypted data through use of common key encryption, and
wherein the second computer is configured to decrypt the searchable encrypted data acquired from the data management server with the user secret key different from the user secret key of the first computer.
7 . The data file encryption, transmission and reception system according to claim 1 , wherein the computer is configured to include one of a name or attribute information of the data file in the second input information.
8 . The data file encryption, transmission and reception system according to claim 3 ,
wherein the data management server includes:
a first data management server configured to store the common key encrypted data; and
a second data management server configured to store the searchable encrypted data, and
wherein the computer is configured to search the first data management server by the decrypted association ID, to thereby acquire the common key encrypted data.
9 . A data file encryption, transmission and reception method executed by a system including a computer the method comprising:
a string conversion step of converting the data file to be encrypted to string data;
a key generation step of generating a common key, which changes every time and an initial vector, which is a pseudo random number, and dividing the string data into first string data and second string data;
a common key encryption step of encrypting the first input information and the first string data with the common key, to thereby generate common key encrypted data;
a searchable encryption step of encrypting the second input information, the common key, and the second string data, in accordance with probabilistic encryption which uses a mask using the user secret key, the pseudo random number, and a homomorphic function, to thereby generate searchable encrypted data;
a communication step of registering a set of the common key encrypted data and the searchable encrypted data in the data management server,
wherein the computer further includes:
an applicant terminal which includes a public key distributed in advance, and is configured to execute the registration step; and
a registrant terminal which has a secret key corresponding to the public key distributed in advance, and is configured to execute the registration step and the search step, and
wherein the data file encryption, transmission and reception method further comprises:
encrypting, by the applicant terminal, the data file with the common key, to thereby generate the common key encrypted data, encrypting the common key and the association ID with the public key, to thereby generate public key encrypted data, and registering the common key encrypted data and the public key encrypted data in a temporary database server coupled via the network; and
acquiring, by the registrant terminal, the common key encrypted data and the public key encrypted data from the temporary database server coupled via the network, decrypting the public key encrypted data with the secret key, encrypting the decrypted common key and the association ID with the user secret key in accordance with the searchable encryption, to thereby generate the searchable encrypted data, and registering the common key encrypted data and the searchable encrypted data in the data management server.
10 . The data file encryption, transmission and reception method according to claim 9 , further comprising:
a search step of acquiring, by the computer, the common key encrypted data and the searchable encrypted data from the data management server, and decrypting the common key encrypted data and the searchable encrypted data into the data file,
wherein the registration step further includes an association ID generation step of generating an association ID for associating the set of the common key encrypted data and the searchable encrypted data with each other, and
wherein the search step includes acquiring the association ID, to thereby identify the set of the common key encrypted data and the searchable encrypted data stored in the data management server, and acquiring the identified common key encrypted data and searchable encrypted data.
11 . The data file encryption, transmission and reception method according to claim 10 ,
wherein the key generation step includes including the generated association ID in the second input information, and
wherein the search step includes:
a searchable cryptograph decryption step of decrypting the searchable encrypted data acquired from the data management server with the user secret key, to thereby acquire the association ID from the second input information and the common key;
a common key cryptograph decryption step of searching the data management server by the association ID for the common key encrypted data corresponding to the searchable encrypted data to acquire the common key encrypted data corresponding to the association ID, and decrypting the common key encrypted data with the decrypted common key, to thereby generate the string data; and
a string conversion step of generating the data file from the string data.
12 . The data file encryption, transmission and reception method according to claim 11 ,
wherein the computer includes a first computer and a second computer which are coupled to the data management server,
wherein the registration step is executed by the first computer, and
wherein the search step is executed by the second computer.
13 . The data file encryption, transmission and reception method according to claim 11 ,
wherein the association ID and the initial vector are included in the second input information,
wherein the common key encryption step includes encrypting the first input information through use of the common key and the initial vector.