Sign In to Follow Application
View All Documents & Correspondence

A Communication Method

Abstract: Provided is a communication device capable of performing encrypted communication using an appropriate encryption key. To this end, a communication device is equipped with: a device information management unit capable of storing device information, which is information that is commonly stored in one or more communication devices; a clock generation unit for generating clock information expressing timing, by using a periodic clock signal; a device information selection unit for selecting at least some of the one or more units of device information according to the clock information, and generating selection information, which is information that differs for each unit of clock information, from the selected device information; a key generation unit for generating an encryption key by at least using the clock information and the selection information that was generated by the device information selection unit; and an encryption processing unit for executing encryption processing and/or decryption processing, by using the generated encryption key.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
12 March 2019
Publication Number
23/2019
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application
Patent Number
Legal Status
Grant Date
2021-11-08
Renewal Date

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Inventors

1. ONO Masakazu
c/o NEC CORPORATION, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Specification

Technical field
[0001]
 The present disclosure relates to a technique for performing communications using encrypted communication data.
BACKGROUND
[0002]
 Recently, a communication method for transmitting and receiving encrypted data between the communication device (hereinafter referred to as "cryptographic communication") is widely used. In the cryptographic communication, the communication device, using the secret information (e.g. key), executes encryption processing and decryption processing of the communication data. Hereinafter, the encryption process and decryption processing of data, collectively referred to as "cryptographic processing". The data that has not been encrypted as "plain text data", the data obtained by encrypting the plaintext data is referred to as "encrypted data". Together with the key used for encryption, and a key used for decoding is referred to as "encryption key". The key used for decryption key used for encryption may be the same key data (e.g., common key encryption scheme), may be a pair of different key data (e.g., public key cryptography).
[0003]
 If the encryption key is leaked, ciphertext encrypted to compromise by using the encryption key. Further, if the number of encrypted ciphertext is increased using the same encryption key, it may give a clue attacks on encryption processing to the attacker. Therefore, in the cryptographic communication, there is a cryptographic keys to be changed as appropriate.
[0004]
 Technology related to such encryption communication is described in Patent Document 1. That is, the method in Patent Document 1, which has a key data table of the terminal and the host in advance the same contents, by using the clock data that is synchronized between the terminal and the host, selecting an encryption key from the key data table There has been disclosed.
CITATION
Patent Document
[0005]
Patent Document 1: JP 2003-101528 JP
Summary of the Invention
Problems that the Invention is to Solve
[0006]
 When each communication device performs the encrypted communication, the encryption key used for encryption processing is distributed to each communication device. However, the situation in which the environment and the communication device the communication device is deployed are running, it may not be easy to distribute the encryption key according.
[0007]
 For example, in some cases from the viewpoint of reducing the risk of the encryption key is leaked, which (without using the words channel) off-line to each communication device encryption key is distributed. In this scenario, the deployment location or communication device, the number of communication devices, is not always easy to distribute the encryption key by hand to each communication device. If the distribution of the encryption key is not easy and may not be appropriately change the encryption key. In other words, each communication device, the encryption communication may not be able to use the appropriate encryption key from the viewpoint of safety.
[0008]
 Meanwhile, in Patent Document 1, instead of distributing the encryption key, by selecting an encryption key from the key data table prepared in advance, it describes a method of changing the encryption key. In accordance art, variation of the encryption key is limited to the encryption key previously registered in the key data table. Therefore, it is believed that improved safety by changing the encryption key is limited. Further, in the technology according to Patent Document 1, the key if the data table itself is compromised, how to properly change the key data table itself is not considered.
[0009]
 The present disclosure has been made in view of the circumstances described above. That is, the present disclosure is that the communication device is to provide a technique that makes it possible to perform cryptographic communication by using the appropriate encryption key, and one of the main purposes.
Means for Solving the Problems
[0010]
 To achieve the above object, the communication apparatus according to an embodiment of the present disclosure includes one or more communication devices capable of storing device information is information that is stored in common to the device information management unit, periodic clock using a signal, and a clock generator for generating clock information indicating a timing to select at least a portion of one or more of the above device information according to the clock information from at least a portion of the selected the device information, the a device information selecting unit which generates selection information which is information different for each clock information, and the clock information, using at least the above selection information generated by the device information selection unit, a key generation unit for generating an encryption key comprising the, using the generated encryption key, and the encryption processing unit for performing at least one of the encryption processing and decryption processing, the.
[0011]
 The communication method according to one aspect of the present disclosure, using a periodic clock signal, generates a clock information representing a timing, in response to the clock information, it is stored in common to one or more communication devices selecting at least a portion of the device information that is information, from at least a portion of the selected the device information, generates selection information which is information different for each of the clock information, and the clock information, by the device information selection unit by using the generated the selection information at least to generate an encryption key using the generated encryption key, and executes at least one of the encryption processing and decryption processing.
[0012]
 Furthermore, the object is a communication apparatus with the above configuration, a computer program for implementing the communication method by a computer, and also achieved by a computer readable storage medium in which the computer program is stored.
[0013]
 That is, the computer program according to one aspect of the present disclosure, the computer constituting the communication device, using a periodic clock signal, and generating a clock information representing a timing, in response to the clock information, one or more common to the communication apparatus selects at least a portion of the device information is information that is stored in, from at least a portion of the selected the device information, and generating the selection information which is information different for each of the clock information , and the clock information, using at least the generated the selection information, and generating an encryption key,
 performed using the generated encryption key, at least one of the encryption processing and decryption processing concerning communication data It adapted to the process of the execution.
Effect of the invention
[0014]
 According to the present disclosure, the communication device can perform cryptographic communication by using the appropriate encryption key.
BRIEF DESCRIPTION OF THE DRAWINGS
[0015]
[Figure 1A] Figure 1A is a block diagram illustrating a functional configuration of a communication apparatus according to the first embodiment of the present disclosure.
FIG 1B] Figure 1B is a block diagram illustrating another functional configuration of the communication apparatus according to the first embodiment of the present disclosure.
[Figure 2A] Figure 2A is an explanatory diagram showing an example of the hardware configuration capable of realizing the communication apparatus in the first embodiment of the present disclosure.
[Figure 2B] Figure 2B is an explanatory diagram showing a first another example of the hardware configuration capable of realizing the communication device in the embodiment of the present disclosure.
[Figure 2C] FIG 2C is a further explanatory diagram showing another example of the first embodiment can realize a communication device in a hardware configuration of the present disclosure.
FIG. 3 is an operation of the communication device in the first embodiment of the present disclosure flowchart describing the (cryptographic process) (Part 1).
[4] FIG. 4 is an operation of the communication device in the first embodiment of the present disclosure flowchart describing the (process of generating the encryption key) (Part 2).
FIG. 5 is an operation of the communication device in the first embodiment of the present disclosure flowchart describing the (updating encryption key) (Part 3).
[6] FIG. 6 is an operation of the communication device in the first embodiment of the present disclosure sequence diagram illustrating (adjustment processing of the clock information) (Part 1).
[7] FIG. 7 is an explanatory view schematically explaining the operation (adjustment processing clock information) of the communication device in the first embodiment of the present disclosure.
[8] FIG. 8 is a sequence diagram illustrating the operation of the communication device in the first embodiment of the present disclosure (adjustment processing clock information) (Part 2).
[9] FIG. 9 is an explanatory diagram a specific example relating to the adjustment information of the clock information communication apparatus according to the first embodiment of the present disclosure retains shown schematically.
FIG. 10 is a specific example relating to the adjustment of the encryption key by the communication device in the first embodiment of the present disclosure is an explanatory view schematically showing.
FIG 11A] FIG 11A is an explanatory view of the specific example is shown schematically concerning transfer of device information by the communication apparatus according to the first embodiment of the present disclosure (Part 1).
FIG 11B] FIG 11B is an explanatory view of the specific example is shown schematically concerning transfer of device information by the communication apparatus according to the first embodiment of the present disclosure (Part 2).
[12] FIG 12 is an explanatory diagram showing a configuration example of a device information selecting unit constituting the communication apparatus according to the first embodiment of the present disclosure.
[13] FIG 13 is a flowchart illustrating the operation of the communication device in the first embodiment of the present disclosure (generation process of the selection information and the encryption key).
[Figure 14A] Figure 14A is a block diagram illustrating a functional configuration of a communication apparatus in the second embodiment of the present disclosure.
FIG 14B] FIG 14B is a block diagram illustrating another functional configuration of the communication apparatus in the second embodiment of the present disclosure.
DESCRIPTION OF THE INVENTION
[0016]
 Prior to description of embodiments of the present disclosure will be described in more detail technical considerations concerning the present disclosure.
[0017]
 As described above, each communication apparatus capable of performing encrypted communication has a cipher key used for encryption processing concerning communication data. For example, when using the common key cryptosystem, certain communication device, using a common encryption key with another communication device and executes the cryptographic processing concerning communication data. For example, when using a public key cryptosystem, certain communication device encrypts the communication data by using the public key by the other communication device is disclosed. In this case, the communication apparatus receiving the encrypted communication data, decodes the communication data using the secret key. In either case, each communication device, the encryption key is distributed.
[0018]
 In the cryptographic communication, the encrypted data is increased by using the same encryption key, an attacker may increase clue decryption available. From the viewpoint of reducing this risk, in the cryptographic communication, a process of properly changing the encryption key is executed.
[0019]
 When the encryption key is changed, there is a cryptographic keys to be distributed to each communication device. On-line (i.e. via a communication line), a general method for distributing encryption keys are widely used. However, for example, if by any chance the encryption key in the distribution of the encryption key online is leaked, performer encrypted communication is likely not care-to decrypt the communication data due to leakage and attacker encryption key.
[0020]
 One way to reduce the risk related to leakage of the encryption key, the off-line (i.e., not through the communication line) are considered a method of distributing the encryption key. One method of distributing the encryption key by offline, for example, a user of the executor and the communication device of the encrypted communication (hereinafter simply referred to as "user") may be distributed manually encryption key to each communication device can. However, and if the number of communication devices is large, if the location of the communication device are separated, to distribute keys manually to each communication device, it may not always easy. If the distribution of the encryption key is not easy, it may not be possible to change the encryption key at the right time. Thus, there is a possibility that problems regarding the safety of the cryptographic communication is caused.
[0021]
 Therefore, in each of the embodiments of the present disclosure described below, explaining the problem of key distribution off-line for resolvable communication device. The communication apparatus in each embodiment, for example, the information the communication device holds, changing information over time (e.g., time, elapsed time, the counter value or the like increases or decreases according to the time or elapsed time) and the used to generate the encryption key. For example, each communication device, if the information used to generate the encryption key is shared, the communication device can generate an encryption key in common. Thus, each communication device, for example, explicitly another without distributing the encryption key, it is possible use a common encryption key. Follows is a detailed description of each embodiment.
[0022]
 The configuration of the communication apparatus described in the following embodiments are illustrative, the scope of the present disclosure is not limited thereto. The following distinctions between components constituting the communication apparatus in each embodiment (for example, divided by functional units) is an example that can realize the communication device. Upon implementation of the communication device is not limited to the following examples, various configurations are envisioned. That is, the components constituting the communication apparatus in the following embodiments may be further divided, one or more components may be integrated.
[0023]
 Communication apparatus described below may be configured with a single device (physical or virtual device), be implemented using a plurality of spaced apart devices (physical or virtual device) good. Communication device will be described below, or, for the hardware configuration capable of realizing the components thereof will be described later.
[0024]
 
 Hereinafter, a description will be given of a communication apparatus according to the first embodiment of the present disclosure.
[0025]
 [Functional Configuration]
 FIG. 1A is a block diagram illustrating a functional configuration of the communication apparatus 100 in this embodiment.
[0026]
 Communication device 100 is capable of executing device encrypted communications. For one communication device 100, one or more other communication devices 100 are communicatively connected. Communication path connecting each communication device 100 is, for example, wireless communication, wired communication, or may be realized by a combination thereof. The communication protocol used for communications according is not particularly limited, may be appropriately selected.
[0027]
 As illustrated in Figure 1A, the communication device 100 includes a device information management unit 101, a clock generator 102, device information selection unit 103, the key generation unit 104, the encryption processing unit 105. Communication device 100 may include a communication unit 106 and the data transfer unit 107. During these components constituting the communication apparatus 100, the data and the command (command) or the like may be connected in a transmit. The following describes these constituent elements constituting the communication device 100.
[0028]
 Device information management unit 101, the data used to generate the encryption key in the cryptographic communication (hereinafter referred to as "apparatus information") (retention). Device information management unit 101, for example, information specific to the communication device 100 (e.g., information relating to devices included in the communication device 100) may be stored as apparatus information. The device information management unit 101, data externally applied to the communication device 100 (e.g., various setting information, etc.) may be stored as apparatus information.
[0029]
 Specific device information, for example, may information such as is used below. That is, as the device information, identifiable ID a CPU (Central Processing Unit) included in the communication device (identifier: Identifier) ​​CPUID may be used is. As device information, for example, assigned to the communication interface MAC (Media Access Control) included in a communication device address may be used. As device information, e.g., a serial number of the communication device 100, model number, etc. may be used. Not limited to the above, as the device information, and other suitable information may be selected.
[0030]
 As one variation of the device information, device information management unit 101 is included in common to all of the communication device 100 may hold a certain common data. Certain common data relating, for example, the manufacture of the communication device 100, deployment, operation, and may be set appropriately for each scene, such as maintenance. Certain common data relating, for example, may be a key to each communication device 100 is commonly held (pre-shared key). Incidentally, it is not essential that the communication device 100 to hold the pre-shared key. That is, the communication device 100 may optionally, may hold the pre-shared key, it may not be retained.
[0031]
 A certain communication device 100, the other communication device 100, for example, may be given device information in advance the same contents. A certain communication device 100 and the other communication device 100, for example, another by transmitting and receiving data may hold a device information of the same content. Certain communication device 100 and another communication device 100, respectively, using the data held by it to perform a predetermined operation, may generate system information of the same content.
[0032]
 Clock generating unit 102 uses a periodic clock signal, configured to generate a clock information which is information indicating a timing. Clock generator 102, the generated clock information can be provided to other components of the communication device 100.
[0033]
 Clock generating unit 102, for example, using a predetermined generating possible suitable device a clock signal that satisfies the frequency accuracy (oscillation device), and generates a clock signal. Specifically, the clock generator 102, for example, rubidium atomic oscillator, an atomic clock comprising the cesium atomic oscillator or the like may generate a clock signal with. In this case, the clock generator 102 can generate a clock signal of very high accuracy (e.g., frequency accuracy is approximately "± 5 × 10E-11").
[0034]
 Instead of using an extremely high-precision device such as an atomic clock, a clock generator 102, for example, it may generate a clock signal by using a general crystal oscillator. In this case, the clock generator 102, by properly adjusting the clock signal may maintain the accuracy of the clock signal. For example, clock generator 102, the timing of the rise timing or fall of the clock signal, so as to match the specific timing may be adjusted clock signal. Specific timing adjusting a clock signal, for example, be a periodical timing, it may be timing representing a particular time.
[0035]
 Clock generating unit 102, for example, by using the time information provided from an external communication device 100 may adjust the clock signal. How the clock generating unit 102 obtains the time information is not particularly limited, and may employ a suitable method. As an example of a method for acquiring time information, the clock generating unit 102, for example, GPS (Global Positioning System) signal, it may acquire the time method from the standard radio signal (JJY), and the like. Clock generating unit 102, for example, the communication unit 106 may acquire the time information from the NTP (Network Time Protocol) server via a (later). GPS, standard radio, from NTP, since it is possible to obtain accurate time information generated using atomic clocks, the clock generator 102 is capable of adjusting a clock signal with accurate time information.
[0036]
 Clock information clock generator 102 generates, for example, may be information representing a periodic clock signal itself. The clock information may be information indicating a counter value obtained by counting the clock signal from a certain timing. The clock generation unit 102 may generate clock information including information indicating the time. In this case, the clock generator 102 may use the time information acquired from outside, and a generated clock signal, and generates clock information including the time at a certain timing. The clock generation unit 102 may generate clock information including information indicating an elapsed time from a certain timing.
[0037]
 Clock generator 102 may be configured to perform a process of adjusting the difference between the clock information with the other communication device 100. The process of adjusting the difference of clock information will be described later.
[0038]
 Device information selecting unit 103 according to the clock information provided from the clock generating unit 102 selects at least a portion of the device information held in the device information management unit 101, using the selected information, according to the clock It generates selection information which is information different Te. That is, the device information selection unit 103, using at least a portion of the held in the device information management section 101 device information to generate different information for each clock information. Hereinafter, a method for selecting at least a portion of the device information held in the device information management section 101, may be referred to as "selection algorithm".
[0039]
 Specific methods of generating selection information is not particularly limited. Device information selection section 103, for example, the device information, by executing a predetermined arithmetic processing and a clock information as an input, may generate different information according to the clock information.
[0040]
 Device information selection unit 103, a clock information provided by the clock generator 102, for each particular range related to the clock information, and converts the representative value (e.g., the upper limit of the range, the lower limit value, median, etc.) it may be.
[0041]
 For example, if the clock information indicating the time, device information selection unit 103, a time represented by the clock information, may be converted into a representative value of a certain time range. For one embodiment, it is assumed that the time range of is set to "10 seconds". In this case, device information selection section 103, for example, of a time less than 10 seconds 0 seconds, may be converted into a representative value (lower limit value) "0 seconds". Similarly, device information selection section 103, for example, of less than 10 seconds or more 20 seconds, may be converted into a representative value (lower limit value) "10 seconds". The same is true for 20 seconds or more of the time. The time range of may be a shorter time range (for example, milliseconds, etc.), of longer time range (e.g., in minutes, hourly, etc.).
[0042]
 For example, if the clock information indicates the counter value, the device information selection unit 103, a counter value represented by the clock information, may be converted into a representative value of the range. As the range of the counter values ​​of, assume a case where, for example, "100" is set. In this case, device information selection section 103, for example, a counter value of 0 to less than 100 may be converted into a representative value (lower limit value) "0". Similarly, device information selection section 103, for example, a counter value of less than 100 or 200 may be converted into "100" is a representative value (minimum value). For more than the counter value 200 is the same. Range of the counter values ​​associated may be a smaller range, it may be a greater range.
[0043]
 By processing as described above, device information selection section 103, even if the clock information is varied within a predetermined range, by using the representative value as the clock information can be absorbed to fluctuations.
[0044]
 Hereinafter, a specific example of a method of generating selection information.
[0045]
 For example, the device information management section 101, as the device information, "device information # 1", "device information # 2", "device information # 3" · · ·, "i-number" (i a "device information #i" It is assumed that the data representing information positive integer) is held.
[0046]
 As a method for selecting at least a portion of the device information, device information selection section 103, for example, according to the clock information, you may select one or more devices information from i pieces of device information. For example, device information selection unit 103 treats the clock information as a numerical value, (hereinafter referred to "mod i") remainder by "i" of numbers according may be calculated. The device information selection section 103, of the i pieces of device information, may select the "mod i" th device information.
[0047]
 Other methods of selecting at least a portion of the device information, device information selection section 103, for example, dividing data representing device information into one or more portions, according to the clock information, one or more portions of which it may be selected.
[0048]
 Specifically, for example, device information selection unit 103, the device of the information # 1 to device information #i, select one or more devices information, the data representing the device information, each n (n is a natural number) It is divided into a number of parts. For example, device information selection unit 103, the data in accordance with the size of the data representing the device information may be divided into n equal parts. How to divide the data representing the device information is not limited to the above, it may be selected an appropriate method appropriately. Device information selection unit 103 selects one or more portions from the data representing the respective device information, may couple them.
[0049]
 Other methods of selecting at least a portion of the device information, device information selection section 103, for example, according to the clock information, to select one or more devices information from i pieces of device information data arranged in random generation may be.
[0050]
 Other methods of selecting at least a portion of the device information, device information selection section 103, for example, from the data coupled side by side i pieces of device information, according to the clock information, be extracted portion of data good. For example, the size of the data obtained by arranging i pieces of device information is assumed to be "N" bit (bit). Device information selection section 103, the "N" bit of the data may be selected or "n" bits data at random. In this case, device information selection section 103, for example, clock information as a seed, one or more "N" the following random number "n" pieces produced. If a value of the random number is "j" (1 ≦ j ≦ N), the device information selection unit 103, "N" of the bits of the data to extract the "j" th bit of the data. By performing the "n" pieces of random numbers the process, apparatus information selection unit 103 is capable of extracting at least "n" bits data.
[0051]
 Method for selecting at least a portion of the device information is not limited to the above examples. Device information selection unit 103, as a method for selecting at least a portion of the device information may be a combination of the above methods may be suitably employed appropriately differently from the above. By the above processing, the device information selecting unit 103, according to the clock information can be selected at least a portion of the device information.
[0052]
 Device information selection unit 103 may provide the selected one or more devices information (or part thereof) as it is as the selection information. If the device information management section 101 is sufficiently large variation of the device information held, the device information selection section 103, thereby, it is possible to provide different selection information according to the clock information.
[0053]
 The device information selection unit 103 selects the device information (or part thereof), the result of executing predetermined arithmetic processing by using the clock information, it may be provided as the selection information. Device information selection section 103, for example, provide a hash value to calculate a hash value, according to data including the selected device information and clock information (e.g., data obtained by combining the selected device information and clock information) as selection information it may be. Device information selection unit 103, a hash function, cryptographically secure hash function (e.g., SHA (Secure Hash Algorithm) -2, etc.) may be used. Thus, even if a relatively small variation of the device information device information management unit 101 holds, it is possible to generate different information according to the clock information as selection information. That is, it is possible to increase the variation of information used to generate the encryption key. Also, the original data from the hash value (e.g., a portion of the device information), it is difficult to calculate the, it is possible to conceal the data used to generate the selection information.
[0054]
 The key generation unit 104 uses the clock information provided by the clock generator 102, and a selection information generated by the device information selection section 103, it generates an encryption key.
[0055]
 The key generation unit 104, for example, as a seed and a selection information and clock information, and generates a random number using a cryptographically secure well-known pseudo-random number generator may provide the random number as an encryption key. Further, the key generation unit 104, for example, using the selected information as a key, the result of encrypting the clock information by using a cryptographically secure well-known encryption algorithms, may be provided as an encryption key. Further, the key generation unit 104, the hash value of the selected information and the clock information is calculated using a suitable hash function may be provided as an encryption key. Thus, the key generation unit 104 may generate the selection information, an encryption key different depending on the clock information.
[0056]
 Incidentally, the key generation unit 104, like the device information selection section 103, a clock information provided by the clock generator 102, for each predetermined range regarding the clock information, may be converted into a representative value. Thus, the key generation unit 104, even if the clock information is varied within a predetermined range, by using the representative value as the clock information can be absorbed to fluctuations.
[0057]
 The key generation unit 104 is configured to change the encryption key at the right time (updated). By the key generation unit 104 changes the encryption key (updated), it is possible to properly maintain the safety of the cryptographic communication.
[0058]
 Specifically, the key generation unit 104, for example, may be provided to the encryption processing unit 105 (described later) to generate a regular encryption key. The key generation unit 104, for example, may be provided have generated an encryption key at a specific time to the encryption processing unit 105. The key generation unit 104, for example, to generate an encryption key in response to a request from the encryption processing unit 105 may be provided to the encryption processing unit 105.
[0059]
 The key generation unit 104 may hold a set value representing a timing of changing the encryption key. For example, if the clock information includes time information, the set value of the time when the encryption key is changed may be set. For example, if the clock information includes counter value, the setting of the counter value when the encryption key is changed it may be set.
[0060]
 Encryption unit 105 uses the encryption key key generating unit 104 has generated, executes encryption processing. Encryption algorithm encryption unit 105 uses the encryption processing is not particularly limited, and for example, it is possible to employ known encryption algorithm cryptographically safety has been confirmed.
[0061]
 Encryption processing unit 105 receives the encrypted communication data from the communication unit 106, using the key data key generation unit 104 has generated, and decodes the communication data. Encryption processing unit 105 may provide a communication data decoded in the data transfer unit 107. Further, the cryptographic processing unit 105 uses the encryption key key generating unit 104 has generated, and encrypts the communication data in plain text provided by the data transfer unit 107 is provided to the communication unit 106.
[0062]
 Encryption processing unit 105, when the communication unit 106 (described later) there are a plurality, as illustrated in Figure 1B, may be configured to perform encryption processing in parallel for each communication unit 106. For example, the encryption unit 105a using the encryption key, executes the process of encrypting the communication data in plain text. Also, the decryption unit 105b receives the encrypted communication data from the communication unit 106, and decodes the communication data using the encryption key. The encryption unit 105a, the decryption unit 105b, for example, threads, processes, may be implemented as a software program tasks, and the like. Also, the encryption unit 105a, the decryption unit 105b, for example, may be implemented as circuit elements of hardware capable of executing parallel processing.
[0063]
 Encryption processing unit 105, whether or not correctly decoded communication data received from another communication device 100, the communication unit 106 may be configured to notify the other communication apparatus 100 using.
[0064]
 The communication unit 106, a communication data encrypted by the encryption processing unit 105, transmitted to and received from the other communication device 100. Specifically, the communication unit 106 receives the communication data encrypted from the encryption processing unit 105, and transmits to the other communication device 100. The communication unit 106, a communication data encrypted received from the other communication device 100, and provides the encryption processing unit 105.
[0065]
 The communication device 100 may include one or more communication unit 106 may be provided. Each communication unit 106 may send and receive communication data to and from separate other communication device 100. That is, a communication unit 106, and the other communication device 100 to which the communication unit 106 to transmit and receive communication data may be one-to-one correspondence. Also, one communication unit 106 may be communicatively coupled to a plurality of other communication devices 100.
[0066]
 The communication unit 106 may measure the delay caused in the communication path between the other communication device 100 to which the communication unit 106 to transmit and receive communication data. How to measure the delay in the communication path may employ well-known techniques.
[0067]
 The data transfer unit 107 performs transfer processing concerning communication data. The data transfer unit 107, for example, by analyzing the communication data in plain text provided by the encryption processing unit 105, the routing regarding the communication data, or performs processing such as switching.
[0068]
 The data transfer unit 107 receives the data generated inside or outside of the communication apparatus 100, the data is encrypted by the encryption processing unit 105, it is configured to transmit via the communication unit 106 to another communication device 100 it may be.
[0069]
 [Hardware Configuration]
 A specific example of the above-described functional capable of realizing the communication apparatus 100 having the configuration hardware configuration will be described with reference to FIGS. 2A to 2C. The hardware illustrated in FIGS. 2A-2C is one embodiment capable of realizing the communication device 100, the hardware is not limited to a feasible communication device 100. The hardware configuration illustrated in FIG. 2A through 2C may be implemented by physical hardware, it may be realized by virtualized hardware. The following describes the configuration illustrated in the figures.
[0070]
 Communication device 100 illustrated in Figure 2A, includes a processor 201, a memory 202, a clock generator 203, a communication interface 204 that includes a communications port, a. Communication device 100 includes a storage 205, an input-output interface 206, a drive device 208 may include more. These components, for example, are connected to one another via a suitable communication line (communication bus, etc.).
[0071]
 The communication device 100 illustrated in FIGS. 2A-2C, the respective components, for example, may be implemented by providing possible circuit configurations each function (Circuitry). Circuit arrangement according include, for example, and integrated circuits such as SoC (System on a Chip), a chipset or the like which is realized by using the integrated circuit. In this case, the data components of the communication device 100 is held, e.g., RAM integrated as SoC (Random Access Memory) area and the flash memory area, or connected storage devices to the SoC (semiconductor memory device) it may be stored in. Hereinafter, each component will be described.
[0072]
 The processor 201 may be a general-purpose CPU or microprocessor, or may be a logic circuit implemented using a programmable device. The processor 201, in accordance with a software program that is read into the memory 202, executes the process.
[0073]
 Memory 202 is, for example, a memory device such as a RAM that can be referenced from the processor 201. The memory 202, for example, the description the communication device 100 can be a software program realizing the components of that is stored.
[0074]
 For example, the device information managing unit 101 may be realized by the processor 201 executes the device information management program. Device information device information management unit 101 holds, for example, may be retained in the storage 205 to be described later.
[0075]
 For example, clock generator 102 may be implemented by the processor 201 executes the clock generation program. In this case, the clock generation program, using the data provided by the clock generator 203 to be described later, and generates clock information. The function corresponding to the clock generation program may be incorporated into the clock generator 203.
[0076]
 For example, device information selection unit 103 may be realized by the processor 201 executes the device information selecting program. Device information selection program obtains the data representing the clock information from the clock generating program, acquires the device information provided by the device information management program.
[0077]
 For example, the key generation unit 104 may be implemented by the processor 201 executes the key generation program. In this case, the key generation program obtains clock information from the clock generating program, it acquires the selection information provided by the device information selecting program.
[0078]
 For example, the cryptographic processing unit 105 may be implemented by the processor 201 executes the encryption processing program. In this case, the cryptographic processing program, for example, acquires the encryption key by the key generation program is provided. Further, the cryptographic processing program, for example, the communication data encrypted from the communication interface 204 may acquire.
[0079]
 The data transfer unit 107 may be realized by the processor 201 executes the data transfer program. In this case, the data transfer unit, for example, to obtain the plaintext data encryption program provided.
[0080]
 Each software program executed by the processor 201, for example, by a suitable method such as a communication between the shared memory and processes may be configured to allow transmitting various data mutually.
[0081]
 Clock generator 203 is, for example, a device comprising a device (e.g., atomic clocks, etc.) to generate a clock signal. The clock generator 203 is a device that acquires time information (eg, GPS units, the standard radio wave receiving unit, etc.). Clock generator 203, the generated clock signal or time information may be provided to other components.
[0082]
 Communication interface 204 is a device including a communication port connected to the communication network, and a controller for controlling the transmission and reception of data. If the communication device 100 is connected to a wired communication line, the communication interface may be connected to the communication cable. If the communication device 100 is connected to a wireless communication line, the communication interface may be an antenna or the like for communication connections. Figure 1A, a communication unit 106 in FIG. 1B, it may be implemented using a communications interface 204.
[0083]
 Storage 205 may be, for example, a magnetic disk drive, such as a semiconductor memory device according to a flash memory is a nonvolatile storage device. Storage 205 stores various software programs and, the software program can store data to be used.
[0084]
 Output interface 206 is, for example, a device for controlling input and output between the output device 207. Output device 207, for example, a communication device 100, the device for realizing an interface between a user (display, operation buttons, audio input and output devices, etc.). The communication device 100 may not include the input and output interface 206.
[0085]
 Drive device 208 is, for example, a device for processing reading and writing of data to the storage medium 209 to be described later. The communication device 100 may not include the drive unit 208.
[0086]
 Storage medium 209, for example an optical disc, a magneto-optical disk, a semiconductor flash memory or the like, a recordable storage medium data. The software program stored in the storage medium 209, shipment of the communication device 100, or in the operational phase, etc., may be stored through suitable drive device 208 in the storage 205. In the above case, various software programs may be installed on the communication device 100 using a suitable tool. In the above case, the components of the communication device 100, where the code constituting the respective software program or a code, is recorded, can be regarded as constituted by a computer-readable storage medium.
[0087]
 Incidentally, manually encryption key to each communication device (e.g., pre-shared key) When setting, according encryption key, the storage medium 209 may be distributed to each of the communication devices 100 using.
[0088]
 Not limited to the above, the communication device 100 can also be realized by the configuration as illustrated in Figure 2B. 2B is the configuration of Figure 2A, further comprising an encryption processing device 210.
[0089]
 The encryption processing device 210 is a device that includes a circuit configured to perform encryption processing, the circuit components, etc., that perform the key generation process. The encryption processing device 210, for example, FPGA (field-programmable gate array) or may be implemented using a ASIC (application specific integrated circuit).
[0090]
 Cryptographic processing device 210, for example, the encryption unit 105a and a processing capable of executing circuit decryption unit 105b may be a plurality implementation illustrated in Figure 1B. These circuits, for each communication port communication interface 204 has, may perform the cryptographic processing concerning communication data transmitted and received in the communications port in parallel.
[0091]
 Note that the encryption processing device 210, for example, as illustrated in Figure 2C, may be implemented in the communication interface 204. In this case, the encryption processing device 210 mounted on each of the communication interface 204 performs the cryptographic processing concerning communication data transmitted and received in a communication port included in the communication interface 204.
[0092]
 [Operation]
 description is given of operations performed by the communication device 100 as described above will be described.
[0093]
 (Generation and encryption process of the encryption key)
 or less, in the communication apparatus 100 will be described the execution of the encryption process. In the following description, with a certain communication device 100 (provisionally referred to as "communication device X"), another communication device 100 (provisionally referred to as "communication device Y") and is a device information of the same content it is assumed that. Further, the respective communication device 100 generates a clock signal using an atomic clock, and, assuming that the clock information generated by using the clock signal are synchronous. Note that the two or more clock information are synchronized, whether they clock information are the same (i.e. no difference (deviation) is), or, to be within the reference range that is a difference between them means. Further, each communication apparatus is assumed to encrypt communication data using the common key cryptosystem.
[0094]
 Figure 3 is a flowchart of an example of an operation when the communication apparatus 100 executes the other communication device 100 and the cryptographic communication.
[0095]
 In step S301, the device information to the communication device 100 is registered. Device information management unit 101 holds the device information. For example, if the advance device information to the communication apparatus is set, step S301 may not be performed. Each communication device 100 (e.g., communication device X and the communication device Y), the CPU assumes that the device information of the same contents are registered.
[0096]
 Clock generator 102 in the communication apparatus 100 generates a clock information (step S302). Clock generator 102, as described above, to generate a clock signal with an atomic clock, and generates the clock information by using the clock signal. Atomic clock is capable of generating high clock signal accuracy, error is accumulated (i.e. clock drift (difference) occurs) in a short period of time not likely. Therefore, when the clock signal of the communication device 100 are synchronized, the clock signal each communication apparatus using 100 according is considered to be capable of generating a clock information of the same content. Therefore, if it can generate a high-accuracy clock signal using an atomic clock or the like, each communication device 100 may not be frequently adjusted difference of clock information with another communication device 100.
[0097]
 Clock generating unit 102, the information representative of the counted the generated clock signal counter may be clock information. Timing for starting the counting of the clock signal may be determined as appropriate. Not limited to the above, the clock generation unit 102 may generate clock information including information indicating the time.
[0098]
 Communication device 100, from a registered device information, and clock information generated in step S302 in step S301, generates an encryption key (step S303). Referring to FIG. 4, it illustrates the formation process of the encryption key.
[0099]
 Device information selection unit 103 in the communication device 100 includes a device information registered in step S301, and a clock information generated in step S302, it generates the selection information (step S401). Device information selecting unit 103 according to the clock information, selecting at least a portion of the device information held in the device information management unit 101. Specific examples of the operation device information selecting unit 103 selects at least a portion of the device information is as described above.
[0100]
 Device information selecting unit 103 uses at least part of the selected device information, generates different selection information every clock information. Specific examples of the operation device information selecting unit 103 generates the selection information is the same as described above.
[0101]
 Device information selection unit 103, as described above, the clock information obtained from the clock generator 102, may be converted into a representative value. Thus, even if the small difference in clock information of each communication device 100 has occurred it is possible to absorb the difference of even, selection information each communication device 100 (communication device X and the communication device Y) are the same it is possible to generate a.
[0102]
 The key generation unit 104 in the communication device 100 includes a selection information generated in step S401, and a clock information, and generates an encryption key corresponding to the encryption algorithm used in the encryption process (step S402). The key generation unit 104, a specific example of an operation of generating an encryption key is the same as that described above. The process according, each communication device 100 (communication device X and the communication apparatus Y) can generate an encryption key having the same contents.
[0103]
 The key generation unit 104, as described above, the clock information obtained from the clock generator 102, may be converted into a representative value. Thus, it is possible to fine difference in the clock information of each communication device 100 absorbs the difference of even when produced.
[0104]
 The above-described processing, the communication device 100 is capable of generating an encryption key for many variations according to the clock information and device information. The reason is that part of the device information is selected according to the clock information, because Fuyaseru variations selection information used in generating the encryption key. Even if the device information device information management unit 101 holds is relatively small, by generating the selection information using the clock information, it is possible to increase the variation of the encryption key.
[0105]
 Encryption processing unit 105 in the communication device 100 performs encryption processing using the encryption key generated in step S303 (step S401 to S402) (step S304).
[0106]
 Encryption processing unit 105, for example, to encrypt the plaintext data provided from the data transfer unit 107 is provided to the communication unit 106. For example, the communication unit 106 in the communication apparatus X transmits the encrypted communication data to the communication device Y.
[0107]
 Encryption processing unit 105, for example, decodes the communication data by the communication unit 106 is encrypted received, may be provided to the data transfer unit 107. For example, the communication unit 106 in the communication apparatus X, the encrypted data received from the communication apparatus Y, which provides the encryption processing section 105 in the communication apparatus X. Encryption processing unit 105 in the communication apparatus X, decodes the communication data, provides the data transfer unit 107 in the communication apparatus X.
[0108]
 (Encryption key updating)
 below, with reference to FIG. 5, described change of the encryption key (updated). Described in the following, the processing of each component of the communication device 100 (operation) is one specific example, components that perform certain processing (operation) can be appropriately selected. As an example, the following processes, device information management unit 101 may be executed by giving instructions to other components.
[0109]
 The key generation unit 104 confirms clock information clock generator 102 is generated (step S501).
[0110]
 The key generation unit 104, a result of confirmation in step S501, determines whether the key change timing has arrived. The key generation unit 104, for example, the clock information obtained from the clock generating unit 102, by comparing the set value that represents the timing of changing an encryption key, also determine whether the key change timing has arrived good.
[0111]
 For example, if the clock information indicates the counter value, the key generation unit 104, a counter value included in the clock information, by comparing the counter value included in the set value, whether the key change timing has arrived it may be determined.
[0112]
 For example, when the clock information indicating the time information, the key generation unit 104, and time on the clock information, by comparing the time included in the set value, whether the key change timing has arrived it may be determined.
[0113]
 If key change timing has arrived (YES in step S502), the key generation unit 104 executes encryption key generation processing (step S503). Processing executed in step S503 may be the same as steps S401 and step S402 illustrated in FIG. The key generation unit 104, the generated new encryption key may be provided to the encryption processing unit 105.
[0114]
 If key change timing has not arrived (NO in step S502), the key generation unit 104 continues the processing from step S501.
[0115]
 The key generation unit 104 updates the key change timing (step S504). The key generation unit 104, for example, the set value representing a timing of changing the encryption key, sets the next timing of changing the encryption key.
[0116]
 The key generation unit 104, (YES in step S505) To continue key update process, to continue the process from step S501. If you do not continue the key update process (at step S505 NO), the key generating unit 104 ends the process.
[0117]
 The process described above, the key generation unit 104 can change the encryption key at the right time (updated). Further, when the encryption key is changed, it is not necessary to explicitly distribute an encryption key to each communication device 100. The reason is that each communication device 100 is because it generates an encryption key using the device information of the same content, and clock information. Specifically, for example, if the synchronization clock signal each communication device 100 generates, each communication device 100 may generate the clock information of the same contents. Each communication device 100 at the same timing (i.e. the same clock information), by using the device information of the same content, it is possible to generate an encryption key having the same contents. Therefore, when changing the encryption key (updated) may not distribute an encryption key to each communication device 100.
[0118]
 Thus, the communication apparatus 100 in this embodiment, the other communication device 100, it is possible to perform cryptographic communication by using the appropriate encryption key.
[0119]
 In the case where the key generation unit 140 changes the encryption key, the encryption processing unit 105 may change the encryption key used in the encryption processing as appropriate. For example, one data to be transmitted from the transmitting communication device 100, "M" ( "M" is a natural number) assumed to be transmitted is divided into pieces of communication data (e.g., "M" number of packets) . 1 th ~ "m" th when the cryptographic key is changed at the timing of transmitting a packet to ( "m" is a natural number less than "M"), the encryption processing unit 105, ( "m + 1") th a packet of up to ~ "M" th, use of an encryption key after it has been changed. Accordingly, one data is divided into a plurality of portions (packets) are encrypted using different encryption keys for each part. Thus, the encryption key used to encrypt the if a moiety even when the compromise, never entire data is decoded.
[0120]
 Each communication device 100, for example, because it generates the clock information by using a highly accurate clock signal generated using the atomic clock, the timing of the encryption key is changed at each communication device 100 is also synchronized with high precision obtain. Therefore, each communication device 100, according to the timing at which the encryption key is changed, one of the data can be encrypted with a different encryption key for each partial.
[0121]
 Further, the cryptographic processing unit 105 in the middle of the cryptographic processing for one of the communication data (e.g., a packet) may change the encryption key. If, at "M" ( "M" is a natural number) of the communication data bytes (byte), "m" data up byte ( "m" is a natural number less than "M") is encrypted timing, it is assumed that the encryption key is changed. Specifically, 1 data up to "m" bytes are encrypted by the clock information CKLI (t1) encryption key KEY that is generated using (t1), ( "m + 1") ~ "M" byte to the data is assumed to be encrypted by the clock information CLKI (t1 + 1) generated using the encryption key kEY (t1 + 1).
[0122]
 In this case, the communication apparatus 100 on the transmission side, for example, a data which can specify each part encrypted by different encryption keys, and data capable of identifying the encryption key used to encrypt the parts, KEY (t1 + 1) is encrypted by, it added to communication data. Hereinafter, the added data to as "additional data". Possible data identifying each part encrypted by different encryption keys, for example, the offset from the beginning, the combination of the size (e.g., the offset is "0 bytes", size "m bytes", etc.) and a good. Information capable of specifying the encryption key used to encrypt each piece of communication data, for example, clock information used for the generation of the encryption key (e.g., CLKI (t1)) may represent.
[0123]
 Communication data encrypted as described above, clock information in the communication device 100 of the transmission side is transmitted at the timing of the CLKI (t1 + 1). In this case, the receiving-side communication device 100 is, for example, clock information receives the communication data at the timing of the CLKI (t1 + 1).
[0124]
 Receiving communication device 100 uses the clock information CLKI (t1 + 1), decoding the additional data. Accordingly, the receiving communication device 100, among the communication data received, each portion that is encrypted by different encryption keys (e.g., 1 ~ m byte parts, (m + 1) ~ M byte portion) identify possible it is. The receiving-side communication device 100, from the available specific data encryption key used to encrypt the parts, it is possible to generate the encryption key (e.g., KEY (t1)). By the above processing, the receiving-side communication device 100, each portion of the communication data, can be decrypted using the appropriate encryption key.
[0125]
 The timing of changing the encryption key may be finely adjusted as appropriate according to the encryption algorithm used in the encryption processing unit 105. For example, if the block cipher algorithm is employed, the encryption key may be changed in units of blocks. For example, if the stream cipher algorithm is employed, the encryption key as a seed for the pseudo-random number generator may be appropriately changed.
[0126]
 (Clock adjustment information)
 Hereinafter, between the communication device 100 executes communication, when the difference in the clock information used to generate the encryption key (shift) occurs, the operation for adjusting the difference of. Described in the following, the processing of each component of the communication device 100 (operation) is one specific example, components that perform certain processing (operation) can be appropriately selected. As an example, the following processes, device information management unit 101 may be executed by giving instructions to other components.
[0127]
 As described above, the encryption key is generated using the clock information. For example, if the clock information generated in the transmitting communication device 100 (e.g. communication device X), and the clock information generated at the receiving side of the communication device 100 (e.g. communication device Y) are different, it encrypts the communication data the encryption key used at the time of the encryption key used in decoding may be different.
[0128]
 Further, there may be a delay occurs in the communication path between the communication devices 100. As a result, communication data communication apparatus 100 transmits the transmission side, until arriving at the receiving communication device 100, there is a possibility that the encryption key is updated at the receiving communication device 100. That is, if the encryption key used to encrypt the communication data, the encryption key used when decoding different.
[0129]
 In contrast, for example, the communication device 100, estimates the clock information of the other communication device 100, by generating an encryption key using the estimated clock information, the encrypted communication even in the above situation it is possible to run.
[0130]
 The timing of each communication device 100 to adjust the clock information can be appropriately selected. In other words, each communication device 100 may be adjusted periodically clock information, may adjust the clock information at a predetermined timing determined by the setting values. Further, each communication device 100, when it fails to decode communication data at the receiving communication device 100 may adjust the clock information.
[0131]
 The operation of the communication device 100 adjusts the clock information used for generating the encryption key, will be described with reference to specific examples.
[0132]
 One method of the communication device 100 (e.g. communication device X and the communication apparatus Y) to adjust the difference of the clock information, at least one of the communication device, to the other communication device 100, directly clock information of its own device how to send is considered. Hereinafter, the communication data used for adjustment of the clock information, may be referred to as the clock adjustment data.
[0133]
 From another communication device 100 (communication device X), the clock adjustment data communication apparatus 100 (communication device Y) which has received the example, the clock information included in the clock adjustment data, its own device upon reception of the clock adjustment data of it may calculate the difference between the clock information. Communication device Y can be, for example, by reflecting the difference in the generated clock information in its own device (e.g. adding or subtracting) to generate an adjusted clock information.
[0134]
 Communication device Y, by using the clock information that is adjusted as described above, may generate a cryptographic key used for encryption processing concerning communication data transmitted and received between the communication device X. Thus, a communication device X, the communication device Y, it is possible to execute the encryption process using the same encryption key.
[0135]
 For the above-described method, since the clock adjustment data is transferred between the communication device 100, it is possible that the clock information in a communication path may leak. Therefore, in order to prevent leakage of clock information in the communication path, each communication device 100 is considered to be transmitted and received by encrypting the clock adjustment data. However, for example, encryption key generated by using the clock information in each communication device 100 may not be able to use a clock adjustment data as an encryption key for encrypting. This is because, if there is a difference in the clock information of each communication device 100, because the encryption key generated in each communication device 100 is different.
[0136]
 Therefore, each communication device 100, if all of the communication device 100 holds the same device information, using the device information, encrypts the clock adjustment data. For example, if each communication apparatus 100 holds a common key in advance as device information (e.g., pre-shared key as described above), each communication device 100 encrypts the clock adjustment data using the pre-shared key of it may be transmitted to another communication device 100.
[0137]
 Specifically, the encryption processing unit 105 uses the pre-shared key, encrypts the clock information, transmits the communication data by the communication unit 106 is the encrypted to another communication device 100.
[0138]
 In this case, the pre-shared key is used for encryption processing to a clock adjustment data. That is, the encryption key used to clock adjustment data other than the (normal) encryption of communication data is generated using the clock information that has been adjusted by the clock adjustment data. In other words, pre-shared key is not used to encrypt normal communications data.
[0139]
 Since the size of the data required to adjust the clock information is considered to be relatively small, the size of the clock adjustment data is considered relatively small. Also, when generating a high-precision clock signal with an atomic clock, etc., the frequency of the difference (deviation) occurs in the clock information between the communication device 100 is considered to be low. Therefore, the number of times the clock adjustment data are transmitted between the communication device 100 is also considered to be relatively small.
[0140]
 As described above, since the total amount of the encrypted data that is encrypted using a pre-shared key relatively small, it is not easy to mass-collecting ciphertext data according believed takes a long time. Even if when pre-shared key change itself (updated) less frequently, potential problems for the safety of the encrypted communication is caused is considered to be low.
[0141]
 The following describes another method of the communication apparatus 100 to adjust the clock information. Another way to each communication device 100 to adjust the clock information, receiving communication device 100 is a method for predicting the clock information can be considered in the transmitting communication device 100. Hereinafter, with reference to the specific example shown in FIGS. 6 and 7, a method according explained. Figure 6 is a sequence diagram illustrating a process of the communication device 100 to synchronize the clock information. Figure 7 is an explanatory view conceptually showing a method for estimating the clock information of the communication device 100. The present embodiment is not limited to the specific examples shown in FIGS.
[0142]
 In the specific example shown in FIGS. 6 and 7, at a certain timing, transmitting communication device 100 (communication device X) generates clock information (CLKI (t1)), receiving communication device 100 (communication device Y ) is assumed to generate the clock information (CLKI (t2)). That is, there is a difference between the clock information generated in each communication device 100. Hereinafter, the communication apparatus Y on the receiving side, a method of estimating the clock information generated in the communication apparatus X of the sender.
[0143]
 Communication apparatus X (hereinafter referred to "KEY (t1)") encryption key using the generated clock information CLKI (t1) at the right time (step S601 in FIG. 6), the clock information CLKI (t1) generating a (step S602 in FIG. 6). Specific processing for generating the cryptographic key is as described above, in accordance with the process may also include a process of generating the selection information according to the clock information CLKI (t1) (hereinafter the same).
[0144]
 Communication device Y, (hereinafter referred to "KEY (t2)") encryption key using the generated clock information CLKI (t2) at the right time (step S603 in FIG. 6), the clock information CLKI (t2) generating a (step S604 in FIG. 6).
[0145]
 Communication apparatus X (step S605 in FIG. 6) to encrypt communication data using an encryption key KEY (t1), transmits the encrypted communication data (hereinafter referred to as "C (t1)") to the communication apparatus Y (step S606 of FIG. 6).
[0146]
 When creating a communication data C (t1) at step S605, the communication apparatus X, a possible decision data (verification data) whether or not the decoded communication data C a (t1) correctly, in addition to communication data it may be. For example, the communication apparatus X, as verification data, may calculate a hash value of the payload of the previous communication data to be encrypted. Communication apparatus X from the coupling the hash value in the communication data, by encrypting the entire they may create a communication data C (t1). Alternatively, the communication device X may be added a message authentication code or message integrity code in the communication data. Message authentication code or message integrity code can be generated using well known techniques.
[0147]
 Communication device Y receives the encrypted communication data C (t1) (step S607 in FIG. 6), and decrypts the C (t1) communication data using the encryption key KEY (t2) (step S608 in FIG. 6 ). Decoding processing according, for example, the cryptographic processing unit 105 in the communication device Y may be executed. In this case, the communication device Y (encryption processing unit 105), the communication data C (t1) may determine whether or not decoded correctly.
[0148]
 For example, the communication device Y, and the hash value calculated from the payload of the communication data is decrypted using the encryption key KEY (t2) C (t1), when the appended verification data to the communication data C (t1) is equal to , it may be determined that can be decrypted communication data C a (t1) correctly. In the case where the message authentication code to the communication data is set, the communication apparatus Y, by verifying the message authentication code according, it is possible to determine whether or not the decoded communication data C a (t1) correctly.
[0149]
 In the specific example of FIG. 6, the encryption key KEY (t2), since it is different encryption key and the encryption key KEY (t1), the communication device Y, in step S608, the decrypting communication data C a (t1) correctly it can not be.
[0150]
 In this case, the communication device Y can be, for example, further generates a different clock information CLKI (tx) and the clock information CLKI (t2) (step S609 in FIG. 6). For example, the cryptographic processing unit 105 in the communication device Y may instruct the generation of the clock information according to the clock generator 102. Hereinafter, the clock information CLKI (tx) which is different from the clock information CLKI (t2), may be referred to as "first estimated clock information". Specifically described with reference to FIG.
[0151]
 Communication device Y (clock generator 102), for example, a specific range including the clock information CLKI (t2) (more specifically, for example, range around the clock information CLKI (t2)) in the first it may generate the estimated clock information. As described above, the communication apparatus X and the communication apparatus Y is because since it generates the clock information by using a high-precision clock signal, a difference (difference) occurring between them is considered to be relatively small. Considered a communication device X, when the difference of the clock information between the communication apparatus Y is small, the clock information CLKI of the communication device X (t1) is to be distributed to a specific range around the clock information CLKI (t2) . Incidentally, a specific range of, for example, it is possible to determine appropriately by such experiments in the development stage of the communication device 100 (or the actual measurement in deployment phase), it may be set in advance to the communication device 100.
[0152]
 For the embodiment shown in FIG. 7, the communication device Y (clock generator 102), for example, as a different clock information from the clock information CLKI (t2) (first estimated clock information), the clock information CLKI (point arrives) and to generate a CLKI (t2_2). Clock information CLKI (point arrives) and CLKI (t2_2), for example, may be included in a specific range of clock information including clock information CLKI (t2).
[0153]
 For example, clock information CLKI (t2) is, the counter value "N" (e.g., N is a positive integer) is assumed that represents the. In this case, the communication device Y can be, for example, it contains the specific range including the counter value "N" (e.g., the counter value from "N-n", the range of the counter value "N + n", where "n" is a positive integer) to clock information that may be generated. For specific example illustrated in FIG. 7, the communication device Y, clock information CLKI (point arrives) representing the counter value "N-1", clock information CLKI (t2_2) representing the counter value "N + 1", and generates a.
[0154]
 For example, clock information CLKI (t2) is, it is assumed that represents the time "t". In this case, the communication device Y can be, for example, the time "t" a specific range (e.g., the time "t" from "Δt" ( "Δt": a positive integer) before time, the time "t" from the "Delta] t "until the time after, it may generate the clock information included in the like). For specific example illustrated in FIG. 7, the communication device Y, clock information CLKI (point arrives) representing the time "t-1", generates the clock information CLKI (t2_2) representing the time "t + 1". Units of time may be selected appropriately (e.g., milliseconds, seconds, minutes, etc.).
[0155]
 Communication device Y (device information selection unit 103), by using the first estimated clock information generated as described above, generates the selection information. Communication device Y (key generating unit 104), a generated selection information, using the first estimated clock information, respectively encryption key (e.g., encryption key KEY (point arrives), the encryption key KEY (T2_2)) and generating (step S610 in FIG. 6). Hereinafter, an encryption key generated using the first estimation clock information may be referred to as "first estimated encryption key."
[0156]
 Communication device Y (encryption processing unit 105) using the generated encryption key (first estimated encryption key) to decrypt the communication data C (t1) (step S611 in FIG. 6). The method determines whether the successfully decoded communication data C (t1) are as described above.
[0157]
 If you can decrypt the communication data C (t1), the communication device Y (encryption processing unit 105), the clock information used to generate the encryption key has been successfully decoded, is estimated as the clock information of the communication device X (FIG. 6 step S612 of). For the embodiment shown in FIG. 7, using the encryption key KEY (t2_2), it is possible to decode communication data C a (t1) correctly. Clock information used for generating the encryption key KEY (t2_2) is clock information CLKI (t2_2). In this case, the communication device Y, the clock information of the communication device X, is estimated to be CLKI (t2_2).
[0158]
 The communication device Y, the clock information included in a specific range of clock information (e.g., the CLKI (point arrives) and CLKI (t2_2)) and one by one generated by the encryption key generated by using the clock information it may be confirmed whether it is possible decode communication data C (t1).
[0159]
 By the above method, the communication device 100 without receiving a clock adjustment data, it is possible to estimate the clock information of the other communication device 100.
[0160]
 The key generation unit 104 in the communication apparatus Y is, for example, the clock information CLKI (t2), the difference between the clock information CLKI (t2_2), and stored as a difference of the clock information of the communication device X and the communication device Y (storage) it may be. The key generation unit 104 in the communication device Y, when generating an encryption key used for the cryptographic communication with the communication device X, the clock information obtained from the clock generating unit 102, adjusted with the difference, adjusted it may generate an encryption key using the clock information.
[0161]
 The following describes more in another way to the communication device 100 to adjust the clock information. As a further in another way the communication device 100 to adjust the clock information, transmitting communication device 100, a method of predicting the clock information at the receiving side of the communication device 100 are considered. For example, transmitting communication device 100, upon receiving a notification indicating that it can not decrypt the communication data transmitted correctly from the own apparatus from the receiving communication device 100, the predicted clock information at the receiving side of the communication device 100 it may be.
[0162]
 Hereinafter, with reference to the sequence diagram illustrated in FIG. 8, a method according explained. In the following description, the clock information communication device X to produce CLKI (t1), the clock information of the communication device Y to communication device X is predicted to as CLKI (t1 + Δt). Further, there is a case where the communication device X is a clock information of the communication device Y predicted to as second estimated clock information.
[0163]
 Transmitting communication device 100 (communication device X), the delay in the communication path, the time elapsed after adjusting the previous clock information, etc. into consideration, clock information at the receiving side of the communication device 100 (communication device Y) (second estimated clock information) to estimate (step S801). The method for measuring the delay in the communication path, it is possible to employ known techniques.
[0164]
 Communication device X can be, for example, in a specific range of clock information including clock information CLKI generated in its own device (t1), it may be predicted a second estimated clock information. For example, the key generation unit 104 in the communication apparatus X is, the clock generator 102 may be instructed to generate a second estimated clock information.
[0165]
 Communication device X (device information selection unit 103) generates the selection information by using the clock information CLKI (t1 + Δt). The communication apparatus X (the key generation unit 104) includes a clock information CLKI (t1 + Delta] t), and the generated selection information to generate a cipher key (KEY (t1 + Delta] t)) from (step S802). Hereinafter may be an encryption key according to as "second estimated encryption key." Communication device X (encryption processing unit 105) using the generated encryption key (second estimation encryption key) to encrypt the communication data (step S803).
[0166]
 Communication device X (communication unit 106), the encrypted communication data C (t1 + Δt), to the communication device Y (step S804).
[0167]
 In the communication device Y, clock information CLKI (t2) is generated at the right time (step S805), the encryption key KEY using the clock information CLKI (t2) (t2) is generated (step S806).
[0168]
 Communication device Y receives the communication data C (t1 + Δt) from the communication device X (step S807), decrypts using the encryption key KEY (t2) (Step S808).
[0169]
 Communication device Y, whether communication data C of (t1 + Δt) can correctly decode in step S808, and notifies the communication device X (step S809).
[0170]
 Communication device X confirms the notification received from the communication device Y (step S810). When the communication apparatus Y is can be decrypted communication data C of (t1 + Δt) correctly, the communication apparatus X, estimates a clock of the communication apparatus Y is to be (t1 + Δt). In this case, the communication apparatus X, the own device, may be a difference of clock information with the communication device Y a (Delta] t) and stored (memory).
[0171]
 Communication device X, when executing the cryptographic communication with the communication device Y, by reflecting the difference in the clock information device itself generates, it is possible to adjust the clock information. Communication device X, by generating an encryption key using the clock information such adjustment, it is possible to perform cryptographic communication with the communication device Y.
[0172]
 When the communication device Y has failed to decode the communication data C (t1 + Δt), the communication device X changes the clock information predicted for the communication device Y (for example, change the CLKI (t1 + Δt2)) (step S812). Communication device X can be, for example, to the decoding processing in the communication apparatus Y is successful, it may be performed repeatedly step S801 to step S812.
[0173]
 Above, each communication device 100 has been described a specific example of a method of adjusting the clock information with another communication device 100.
[0174]
 If the communication device 100 communicates with a plurality of other communication devices 100, the key generation unit 104 in the communication device 100, the adjustment information used for adjusting the clock information, may be retained in association with other communication devices 100 (e.g., Figure 9). Adjustment information relating typically a clock information generated in one communication device 100 may represent the difference between the clock information generated in the other communication device 100.
[0175]
 (Encryption adjustment key)
 or less, using a clock signal which is adjusted as described above, used between the transmitting communication device 100 (communication device X), receiving communication device 100 (communication device Y) the method of adjusting the encryption key is, it will be described with reference to specific examples shown in FIG. 10. The specific example shown in FIG. 10 is an example for explanation, the present embodiment is not limited thereto. Described in the following, the processing of each component of the communication device 100 (operation) is one specific example, components that perform certain processing (operation) can be appropriately selected.
[0176]
 When executing the adjustment processing of the clock information described above, as illustrated in FIG. 10, the communication device 100 holds the adjustment information of the clock information on another communication device 100. That is, the communication apparatus X retains the adjustment information of the clock information regarding the communication apparatus Y, the communication device Y stores adjustment information of the clock information regarding the communication device X.
[0177]
 In this case, the communication device 100 as the transmission side of the communication data, either one of the communication device 100 serving as the receiving communication data, generates an encryption key using the adjusted clock information, using the encryption key to perform the cryptographic processing Te.
[0178]
 A communication device 100 that is the transmission side of the communication data, either the communication device 100 serving as the receiving communication data to generate an encryption key using the clock information adjustment may be predetermined, each communication device 100 may select to communicate with other communication devices 100.
[0179]
 Hereinafter, description will be given of a case where the communication apparatus 100 as a transmitting communication data to adjust the clock information.
[0180]
 When sending communication data from the communication device X to communication device Y, the communication apparatus X (in particular, device information selection unit 103 and the key generation unit 104), the clock information device itself has generated, adjustment information to the communication device Y adjusted using (t_xy). Specifically, the communication apparatus X, by adding the adjustment information to the clock information device itself has generated (or subtraction), may adjust the clock information. Communication device X, using the adjusted clock information, and generates the encryption key by the above-described method, encrypts the communication data by using the encryption key. On the other hand, in this case, the communication apparatus Y of the reception side generates the encryption key without adjusting the clock information. Communication device Y can be by using the encryption key, decrypts the encrypted data received from the communication device X.
[0181]
 Similarly, when transmitting the communication data to the communication device X from the communication apparatus Y, the communication device Y, the clock information device itself has generated, it is adjusted by using the adjustment information (t_yx) to the communication device X. Communication device Y, using the adjusted clock information, and generates the encryption key by the above-described method, encrypts the communication data by using the encryption key. On the other hand, in this case, the communication apparatus X of the reception side generates the encryption key without adjusting the clock information. Communication device X can be by using the encryption key, decrypts the encrypted data received from the communication apparatus Y.
[0182]
 The operation described above, transmitting communication device 100 by adjusting the clock information, without receiving communication device 100 to adjust the clock information can perform cryptographic communication.
[0183]
 Hereinafter, description will be given of a case where the communication device 100 as a receiving communication data to adjust the clock information.
[0184]
 For example, when transmitting the communication data to the communication device Y from the communication device X, the communication apparatus X, without adjusting the clock information device itself has generated, generates an encryption key by the above-described method, the encryption key encrypt communication data using. On the other hand, in this case, the communication apparatus Y of the reception side, the clock information device itself has generated, it is adjusted by using the adjustment information (t_yx) to the communication device X. Communication device Y can be by using the encryption key, decrypts the encrypted data received from the communication device X.
[0185]
 For example, when transmitting the communication data to the communication device X from the communication apparatus Y, the communication device Y, without adjusting the clock information device itself has generated, generates an encryption key by the above-described method, the encryption key encrypt communication data using. On the other hand, the communication apparatus X on the receiving side in this case, the clock information device itself has generated, it is adjusted by using the adjustment information (t_xy) to the communication device Y. Communication device X can be by using the encryption key, decrypts the encrypted data received from the communication apparatus Y.
[0186]
 The action of the above-described, without adjusting the communication device 100 is clock information on the transmitting side, the receiving side of the communication device 100 by adjusting the clock information can perform cryptographic communication.
[0187]
 It has been described the operation of the communication device 100. Communication device 100 configured as described above, may use the appropriate encryption key to perform the other communication device 100 and the cryptographic communication. The reason for this is as follows.
[0188]
 In other words, each communication device 100 includes at least a portion of the device information the communication device 100 is held, by using the clock information, to generate an encryption key. Each communication device 100 holds the apparatus information of the same content, if the synchronization clock information generated in each communication device, each communication device 100 can generate the same encryption key. That is, for each communication device 100, may not be explicitly distribute cryptographic keys.
[0189]
 Each communication device 100, since it generates an encryption key using at least a part and the clock information of the device information, it is not necessary to share the encryption key determined in advance. Further, variations of the encryption key generated, for example, is not limited to variations of known encryption key.
[0190]
 Each communication device 100, for example, from generating clock information by using a highly accurate clock signal generated using atomic clock or the like, the clock information of each communication device 100 may be synchronized with high accuracy. Therefore, each communication device 100 can be, for example, according to the clock information according to change the appropriate encryption key at the same timing. Further, when change of the encryption key according may not explicitly distribute the encryption key after the change.
[0191]
 Each communication device 100, if the difference in clock information occurs, as described above, is capable of executing processing for adjusting the differences. Even if the case where the difference in clock information is generated, by adjusting the respective passing the differences, each communication device 100, to generate a cryptographic key that can be used in encrypted communication with another communication device 100 it can. Further, by generating an encryption key using the clock information communication device 100 is appropriately adjusted in the communication device 100 or receiving the transmission side, it is possible to perform the other communication device 100 and the cryptographic communication.
[0192]
 [First Modification]
 Hereinafter, a description will be given of a first modification of the communication apparatus 100 in this embodiment. Functional configuration capable of realizing the communication device 100 in this variation may be the same as the first embodiment.
[0193]
 In this modification, the operation of the device information management unit 101 and the encryption processing unit 105, differs from the first embodiment. Hereinafter, the differences of, will be described with reference to specific example illustrated in FIGS. 11A and 11B.
[0194]
 For the specific example shown in FIG. 11A, the device information management unit 101 of each communication device 100 (communication device A to the communication device D), the data specific to the communication device 100, respectively (data1, data2, data3, data4) retention to. The device information management unit 101 of each communication device 100, at least one holding a common device information in each device. Device information common to each device, for example, be a pre-shared key described above. As explained above, the pre-shared key is an encryption key common to the communication device.
[0195]
 Device information management unit 101 of each communication device 100, for example, at a timing for starting communication with another communication device 100, the unique device information, each of which holds, to transmit and receive each other. In this case, the communication device 100, for example, by using a pre-shared key to encrypt communication data including the unique device information.
[0196]
 Specifically, the encryption processing unit 105, by using a pre-shared key to encrypt communication data including the unique device information to each communication device 100 device information management unit 101 holds. Transmitting the communication data by the communication unit 106 is the encrypted to another communication device 100.
[0197]
 Communication unit 106, from another communication device 100, when receiving the communication data including the unique device information, the encryption processing unit 105 decrypts the communication data using a pre-shared key. Encryption processing unit 105 is included in the decrypted communication data, to another communication device 100 may provide a unique device information to the device information management unit 101.
[0198]
 Result of the process, as illustrated in FIG. 11B, the communication device 100, for each other communication device 100, it is possible to hold the device information of the same content. For example, the communication device A and the communication apparatus C, as apparatus information, held respectively data1 and data3. Communication device A and the communication device D, as apparatus information, held respectively data1 and data4. Communication device B and the communication device D, as apparatus information, for holding the respective data2 and data4.
[0199]
 In subsequent communication, for example, device information selecting unit 103 in the communication apparatus A and communication apparatus C, by using the clock information, and device information (data1 and data3), to generate the selection information. Device information selection unit 103 in the communication device A and the communication device D, by using the clock information, and device information (data1 and data4), generates the selection information. Device information selection unit 103 in the communication device B and the communication device D, by using the clock information, and device information (data2 and data4), generates the selection information. The key generation unit 104 in the communication apparatus 100 uses the selection information generated as described above, a clock information, and generates an encryption key.
[0200]
 The above-described processing, the communication device 100 when communicating with other communication devices 100 may use different encryption keys for each said other communication device 100. FIG. 11A, the case of the example illustrated in FIG. 11B, the communication device A, the cryptographic communication with the communication device C, and the cryptographic communication with the communication device D, it is possible to use different encryption keys. Communication device D, and the cryptographic communication with the communication device A, in the cryptographic communication with the communication device B, and can use different encryption keys.
[0201]
 Than this, according to this modified example, there cryptographic communication device (e.g., a communication device A communication device C) also encryption key is compromised, among other communication devices (e.g., communication device A and the communication device D) it is possible to reduce the impact on the safety of communication.
[0202]
 Incidentally, pre-shared keys, each communication device 100 is used to encrypt the device information to be transmitted and received, not used to encrypt normal communications data. That is, the total amount of the encrypted data that is encrypted using a pre-shared key is relatively mild, considered is not easy to mass-collecting ciphertext data according. Therefore, the attack on pre-shared key is considered to be relatively difficult.
[0203]
 [Second Modification]
 Hereinafter, a description will be given of a first modification of the communication apparatus 100 in this embodiment. Functional configuration capable of realizing the communication device 100 in this variation may be the same as the first embodiment.
[0204]
 In this modification, the operation of the device information selection unit 103, differs from the first embodiment. Hereinafter, the difference will be described according.
[0205]
 A configuration example of a device information selecting unit 103 in this modification is shown in FIG. 12. Device information selection unit 103 in this modified example, each of a plurality have a selection processing section 1201 for selecting at least a portion of the device information according to different selection algorithms. Device information selecting unit in the present modified example 103, according to the clock information, to select at least one or more selected processing unit 1201 from a plurality of selection processing section 1201, at least one selected device information by the selection processing unit 1201 part was used to generate the selection information.
[0206]
 In the structure illustrated in FIG. 12, the device information selection unit 103, as an example, a selection processing unit A, the selection processing section B, and the selection processing unit C. The number of the selection processing unit 1201 is not particularly limited and may be appropriately determined. Each selection processing section 1201 (selection processing section A ~ selection processing section C) selects a part of the device information according to a selection algorithm, each different.
[0207]
 In the structure illustrated in FIG. 12, the selection processing unit A, for example, according to the clock information, to select a portion of the device information from a plurality of apparatus information held in the device information management unit 101. Selection processing section B is, for example, one or more device information is divided into a plurality of portions of the divided partial coupling suitably selected and according to the clock information. Selection processing unit C, for example, sort appropriate according to a plurality of apparatus information held in the device information management unit 101 to the clock information.
[0208]
 Device information selection unit 103, the respective selection processing section 1201 (selection processing section A ~ selection processing section C) is selected device information (or a portion thereof) may be provided as it is as the selection information. Device information selection section 103, for example, the result of executing the predetermined operation (for example, a hash function or the like) with respect to the selected device information by the selection processing section 1201 (or a portion thereof), provided as selection information it may be.
[0209]
 Process of generating the encryption key in this modification will be described with reference to the flow chart illustrated in FIG. 13.
[0210]
 Device information selecting unit 103 according to the clock information, selects the selection unit 1201 (step S1301). How to select the selection processing section 1201 may be appropriately determined. Device information selecting unit 103 according to the clock information, may be sequentially selecting the selection processing unit 1201. Device information selection section 103, by generating a random number of clock information and seed, the selection processing unit 1201 may be selected randomly.
[0211]
 Selection processing unit 1201 selected in step S1301, in response to the clock information, to obtain at least a portion of the device information (step S1302).
[0212]
 Device information selection unit 103 generates selection information by using the acquired device information in step S1302 (step S1303).
[0213]
 The key generation unit 104, a generated selection information, by using the clock information, and generates an encryption key corresponding to the encryption algorithm (step S1304). Processing in step S1304 may be the same as the processing in step S402.
[0214]
 According to this modification configured as described above, according to the clock information, selection information is generated by using different selection algorithms. That is, it is possible to increase the variations of the method of generating selection information. Thus, it is considered to be difficult to predict the original data used to generate the encryption key.
[0215]
 
 Hereinafter, describes a second embodiment of the present disclosure. The second embodiment is a basic embodiment common to the first embodiment and its modifications.
[0216]
 Figure 14A is a block diagram illustrating a functional configuration of a communication apparatus 1400 of this embodiment. The communication device 1400 is, for example, be realized by hardware illustrated in FIGS. 2A-2C.
[0217]
 As illustrated in FIG. 14A, the communication device 1400 includes a device information management unit 1401, a clock generation unit 1402, a device information selecting unit 1403, a key generation unit 1404, an encryption unit 1405, a. Communication device 1400, as illustrated in FIG. 14B, may include a communication unit 1406. During these components constituting a communication device 1400, so that pass each other in the receiving data, it may be connected using any suitable method. Hereinafter, each component will be described.
[0218]
 Device information management section 1401 (device information management means) stores the device information is information that is stored in common to one or more communication devices. Device information relating, for example, may be the same information as the device information in the first embodiment. Device information management unit 1401, for example, every other communication device 1400 when the device itself communicates may store the individual device information. Device information management unit 1401, for example, may be configured to be executed the first processing similar to device information management unit 101 in the embodiment.
[0219]
 The clock generator 1402 (clock generating means), using a periodic clock signal, and generates clock information representing a timing. Clock generating unit 1402, for example, by using a highly accurate clock signal generated using atomic clock or the like, may generate the clock information. The clock information generated by the clock generating unit 1402, for example, as in the first embodiment, may include information indicating the time may include information that represents the counter value. Clock generating unit 1402, for example, may be configured to be able to perform the same processing as clock generator 102 in the first embodiment.
[0220]
 Device information selection section 1403 (device information selecting means), according to the clock information generated by the clock generating unit 1402 selects at least a portion of one or more devices information. The device information selection section 1403, from at least a portion of the selected device information, generates the selection information which is information different for each clock information. Device information selection section 1403, for example, by using the apparatus information selected by the selection algorithm described in the first embodiment, it may generate the selection information. Device information selection section 1403 may be configured to be able to perform the same processing as the device information selecting unit 103 in the first embodiment.
[0221]
 The key generation unit 1404 (the key generation means), a clock information, using at least the selection information generated by the device information selecting unit, to generate an encryption key. Thus, the key generation unit 1404 may generate the selection information, depending on the clock information, a different encryption key. The key generation unit 1404, for example, may be configured to be able to perform the same processing as the key generation unit 104 in the first embodiment.
[0222]
 Encryption processing unit 1405 (encryption processing unit), using the encryption key generated by the key generation unit 1404, executes at least one of the encryption processing and decryption processing. Encryption processing unit 1405, for example, may be configured to be able to perform the same processing as the encryption processing section 105 in the first embodiment.
[0223]
 The communication unit 1406 (communication means) is configured to transmit and receive communication data to and from another communication device 1400. The communication unit 1406 transmits, for example, the communication data encrypted in the encryption unit 1405 to another communication device 1400. The communication unit 1406 receives, for example, communication data encrypted by the other communication device 1400 is provided to the encryption processing unit 1405. The communication unit 1406, for example, may be configured to perform the same processing as the communication unit 106 in the first embodiment.
[0224]
 Communication apparatus 1400 configured as described above, without explicitly distribute an encryption key used for encrypted communication to another communication device 1400, possible is perform cryptographic communication with another communication device 1400 . Further, communication device 1400 configured as described above, without prior sharing an encryption key, is capable of executing encrypted communication. The reason is that if the clock information each communication device generates are the same contents, each communication device 1400, a common device information with another communication device 1400, based on the clock information, with another communication device 1400 it is because it generates the same encryption key. The communication device 1400 is capable of generating a different encryption keys according to the clock information when updating the encryption key. From the above, the communication device 1400, with the other communication device 1400 may perform encrypted communication using the appropriate encryption key.
[0225]
 Although the present disclosure has been described as an example applied to the exemplary embodiments described above. In the above embodiments explained the example of applying to the communication device technology related to the present disclosure (100,1400). For example, by operating the communication device (100,1400) in each of the above embodiments, it is possible to realize a communication method related to the present disclosure. How to implement a communication method according to the present disclosure is not limited to the above. Communication method according to the present disclosure, for example, capable of executing the same operation as the communication apparatus (100,1400), a suitable device (an information processing apparatus such as a computer, or a dedicated embedded device, etc.) may be implemented by possible it is. The present disclosure may be implemented as a system including a plurality of communication devices (100,1400).
[0226]
 Further, the technical scope of the present disclosure, the ranges set forth the embodiments and modifications described above are not limited. Those skilled in the art it is clear that it is possible to add various modifications or improvements to the embodiments according. In such a case, even a new embodiment changes or improvements according, be included in the technical scope of the present disclosure. Further, the embodiments and modifications described above, or also an embodiment combining new embodiments with changes or improvements according, be included in the technical scope of the present disclosure. And this is evident from the matters described in the claims.
[0227]
 A part or all of the above embodiments, can be described as the following notes, not limited to the following.
(Supplementary Note 1) 1
 or more and storable device information managing means device information is information that is stored in common to the communication apparatus,
 using a periodic clock signal, a clock generator for generating clock information indicating a timing means,
 selecting at least a portion of the device information according to the clock information from at least a portion of the selected the device information, the device information selection means for generating selection information which is information different for each of the clock information ,
 and the clock information, the device information selection means by using at least the generated the selection information by the key generation means for generating a cryptographic key,
 using the generated encryption key, and encryption processing concerning communication data communication apparatus and a cryptographic processing means for performing at least one of the decoding process.
(Supplementary Note 2)
 The device information management unit stores a plurality of said device information,
 the device information selection means, in response to the clock information,
  among the plurality of apparatus information, at least one or more of the device information a process of selecting,
  with selecting at least one or more of the device information from a plurality of said device information, divides the device information of each of the selected plurality of partial, one or more portions from the device information for each selected by executing the process of selecting, at least one of the communication device according to note 1 for selecting at least a portion of the device information.
(Supplementary Note 3)
 The clock generating means includes an atomic clock, the clock signal synchronized with the other of the communication device generated using the atomic clock, the communication apparatus according to Supplementary Note 1 or 2.
(Supplementary Note 4)
 The clock generating means is provided externally of the apparatus, the time information generated using atomic clocks, the communication apparatus according to Supplementary Note 1 or 2 adjusts the timing of the clock signal.
(Supplementary Note 5)
 comprises further communication means for transmitting and receiving communication data to and from other of said communication device,
 when the communication means the communication data received from another said communication apparatus, said encryption processing means can not be decoded correctly,
  said clock generating means, the first estimated clock information is different from the clock information from said clock information in its own device upon reception of the communication data generated 1 or more,
  the device information selection means, said first estimated selecting at least a portion of the device information according to the clock information from at least a portion of the selected said device information, and generates the selection information,
  the key generating means,
   said first estimated clock information first generates an estimated encryption key using at least said selection information,
   the encryption processing means, using the generated first estimated cryptographic key, or the communication device Depending on the result of determining whether or not decoded correctly received communication data, and estimates the clock information generated in another of the communication device, the communication device according to any one of Supplementary Notes 1 to Appendix 4.
(Supplementary Note 6)
 comprises further communication means for transmitting and receiving communication data to and from other of said communication device,
 said communication means, a notification indicating that it can not correctly decode the communication data transmitted from own apparatus, the other of said when receiving from the communication device,
  wherein the clock generating means, the second estimation clock information is different from the clock information from the clock information of the own apparatus generates one or more,
  the device information selection means, said second At least a portion select, from at least a portion of the selected said device information, and generates the selection information, the device information according to the estimated clock information
  said key generating means, said second estimation clock information, generating a second estimated encryption key using at least said selected information,
  said communication means has been encrypted by the encryption processing means using said second estimate encryption key communication Sends over data to another said communication apparatus,
  said key generating means, said second notification indicating that estimate was correctly decoded communication data encrypted using an encryption key, said communication means other wherein when receiving from the communication device, the communication device according to any one of Appendixes 1 to Appendix 4 estimates the second estimated clock information, and the clock information generated in another one of the communication device.
(Supplementary Note 7)
 The key generation means, and the clock information estimated for the other said communication device, the adjustment information representing a difference between said clock information clock generating means has generated in its own device, another one of the communication device and held in association with,
 the own device, when a receiving communication apparatus that receives communication data from another said communication device,
 wherein the device information selection means, the clock information generated by the clock generating means, with adjusted using the adjustment information, and generates the selection information using the clock information after adjustment,
 the key generating means, said clock information generated by the clock generating means, using said adjustment information with adjust it to generate an encryption key using the selection information generated by said clock information after adjustment and the device information selection means,
 before Cryptographic processing means, using the encryption key generated by the key generating unit, decodes the communication data by the communication unit receives a communication apparatus according to note 5 or Appendix 6.
(Supplementary Note 8)
 The key generation means, and the clock information estimated for the other said communication device, the adjustment information representing a difference between said clock information clock generating means has generated in its own device, another one of the communication device and held in association with,
 the own device, when a communication device on the transmitting side for transmitting communication data to the other said communication device,
 wherein the device information selection means, said clock information generated by said clock generating means and with adjusted using the adjustment information, and generates the selection information using the clock information after adjustment,
 the key generating means, said clock information generated by the clock generating means, said adjustment information with adjusted using, generates an encryption key using the selection information generated by said clock information after adjustment and the device information selection means
 Said cryptographic processing means, using the encryption key generated by the key generating unit, a communication device according to Note 5 or Appendix 6 to encrypt communication data transmitted from said communication means.
(Supplementary Note 9)
 The device information management means, a pre-shared key that all of the communication device held in common, to the own device stores a unique information, as the device information
 the encryption processing means preshared by using a key to encrypt communication data including information specific to the own device,
 the communication means transmits the encrypted communication data to another communication device,
 said communication means, the other said communication device from when receiving the communication data including information specific to other said communication device, said cryptographic processing means, using the pre-shared key to decrypt the communication data by the communication unit receives, decoded the specific information in addition to the communication device included in the communication data, and providing the device information management unit, a communication device according to any one of Appendixes 5 to Supplementary note 8.
(Supplementary Note 10)
 The device information selection means, wherein at least a portion of the selected the device information, the calculated hash value of data including the clock information generated by the clock generating means, the calculated hash value communication device according to note 2 provided as selection information.
(Supplementary Note 11)
 The device information selection means,
  in response to the clock information has a plurality of selection processing means for selecting at least a portion of the device information, each different,
  the selection of one or more in accordance with the clock information select processing means using at least a portion of the device information selected by the selecting unit, the communication apparatus according to note 2 or Appendix 10 generates the selection information.
(Supplementary Note 12)
 has a sending communication device is the communication device according to note 7, the, the receiving communication device is a communication device according to appendix 7,
 wherein the encryption processing means in the transmitting-side communication device , the communication data using an encryption key generated by the key generating means and encryption in accordance with the clock information generated by the clock generating means in the transmitting-side communication device, the communication means in the transmitting-side communication device but transmits the encrypted communication data to the reception side communication apparatus,
 the encryption processing means in the receiving communication device, the clock information generated by said clock generating means in the receiving communication device, wherein adjusted with adjustment data, using the encryption key generated by the key generating means by using the clock information after adjustment, or the sending communication device Communication system for decoding a received communication data.
(Supplementary Note 13)
 and the transmission device is the communication device according to Note 8, has a receiving-side communication device is the communication device according to Note 8,
 wherein in the transmitting-side communication apparatus encryption processing means is the clock information generated by said clock generating means in the transmission side communication apparatus adjusted using the adjustment information, the encryption key generated by the key generating means in response to said clock information after adjusting encrypts communication data using, transmits communication data by the communication means is encrypted at the transmitting side communication apparatus to the reception side communication apparatus,
 the encryption processing means in the receiving communication apparatus, the receiving communication using the encryption key generated by the key generating means in response to the clock information generated by the clock generating means in the device, whether the sending communication device Communication system for decoding a received communication data.
(Supplementary Note 14)
 with a periodic clock signal, generates a clock information representing a timing,
 in response to said clock information, at least a portion of the device information is information that is stored in common to one or more communication devices select, from at least a portion of the selected the device information, the generated selection information every clock information is different information,
 and the clock information, the selection information and using at least generated, the encryption key generated,
 using the generated encryption key, communication method for performing at least one of the encryption processing and decryption processing concerning communication data.
(Supplementary Note 15)
 to a computer constituting the communication device,
 using a periodic clock signal, and generating a clock information representing a timing,
 in response to the clock information, is stored in common to one or more communication devices selecting at least a portion of the device information is that information, from at least a portion of the selected said device information, and generating the selection information which is information different for each of the clock information,
 and the clock information, is generated the selection information and using at least a process of generating an encryption key,
 by using the generated encryption key, the communication program executed a process of executing at least one of the encryption processing and decryption processing concerning communication data, the but the recorded recording medium.
[0228]
 This application claims priority based on Japanese Patent Application No. 2016-195775 filed on October 3, 2016, the entire disclosure of which is incorporated herein.
DESCRIPTION OF SYMBOLS
[0229]
 100 communication device
 101 device information management unit
 102 clock generator
 103 device information selecting unit
 104 key generation unit
 105 encryption processing unit
 106 communication unit
 107 the data transfer unit
 201 processor
 202 memory
 203 clock generator
 204 communication interface
 205 storage
 206 input and output interface
 207 output device
 208 drive
 209 storage medium
 210 cryptographic processing device
 1400 communications device
 1401 device information management unit
 1402 clock generator
 1403 device information selecting unit
 1404 key generating unit
 1405 encryption processing unit

The scope of the claims
[Requested item 1]
 1 or more and storable device information managing means device information is information that is stored in common to the communication apparatus,
 using a periodic clock signal, and a clock generating means for generating clock information indicating the timing,
 the selecting at least a portion of the device information according to the clock information from at least a portion of the selected the device information, the device information selection means for generating selection information which is information different for each of the clock information,
 the clock information When the device information selection means by using at least the generated the selection information by the key generation means for generating a cryptographic key,
 using the generated encryption key, the encryption processing and decryption processing concerning communication data communication apparatus and a cryptographic processing means for performing at least one.
[Requested item 2]
 The device information management unit stores a plurality of said device information,
 the device information selection means, in response to the clock information,
  among the plurality of apparatus information, a process of selecting at least one or more of the device information ,
  together with selecting at least one or more of the device information from a plurality of said device information, divides the device information of each of the selected plurality of partial further selects one or more parts from the device information for each selected by executing the processing and, at least one communication device according to claim 1 for selecting at least a portion of the device information.
[Requested item 3]
 Said clock generating means includes an atomic clock, using the atomic clock, for generating the clock signal synchronized with the other said communication device, a communication device according to claim 1 or claim 2.
[Requested item 4]
 Said clock generating means is provided externally of the apparatus, the time information generated using atomic clocks, the communication apparatus according to claim 1 or claim 2 for adjusting the timing of the clock signal.
[Requested item 5]
 Further comprising a communication means for transmitting and receiving communication data to and from other of said communication device,
 when the communication means the communication data received from another said communication apparatus, said encryption processing means can not be decoded correctly,
  the clock generating means is the first estimated clock information is different from the clock information from said clock information in its own device upon reception of the communication data generated 1 or more,
  the device information selection means, said first estimated clock information At least a portion is selected, at least in part from, generates the selection information, the selected the device information of the device information in response to
  said key generation means,
   said first estimation clock information, the selection information DOO generates a first estimated encryption key using at least,
   the encryption processing means, using the generated first estimated encryption key received from the communication device Depending on the result of determining whether or not decode the signal data correctly estimates the clock information generated in another of the communication device, the communication device according to any one of claims 1 to 4.
[Requested item 6]
 Further comprising a communication means for transmitting and receiving communication data to and from other of said communication device,
 said communication means, a notification indicating that it can not decrypt the communication data transmitted correctly from the own apparatus, received from the other said communication device If you,
  the clock generating means, the second estimation clock information is different from the clock information from the clock information of the own apparatus generates one or more,
  the device information selection means to said second estimated clock information depending selecting at least a portion of the device information, from at least a portion of the selected said device information, and generates the selection information,
  the key generating means, said second estimation clock information, and the selection information the generating the second estimated encryption key using at least,
  said communication means, other communication data encrypted by the encryption processing means using said second estimate encryption key Transmitted to the communication device,
  the key generating means, a notification indicating that was correctly decoded communication data encrypted using the second estimation encryption key, from said communication means other said communication device when receiving, the second estimated clock information, communication apparatus according to any one of claims 1 to 4 for estimating said clock information generated in another one of the communication device.
[Requested item 7]
 The key generation means, and the clock information estimated for the other said communication device, the adjustment information representing a difference between said clock information clock generating means has generated in its own device, held in association with another said communication apparatus and,
 self apparatus when a receiving communication apparatus that receives communication data from another said communication device,
 wherein the device information selection means, the clock information generated by the clock generating means, said adjustment information with adjusted using, generates the selection information using the clock information after adjustment,
 the key generating means, said clock information generated by the clock generating means, with adjusted using the adjustment information , generates an encryption key using the selection information generated by said clock information after adjustment and the device information selection means,
 the encryption processing Stage, using the encryption key generated by the key generating unit, decodes the communication data by the communication unit receives a communication apparatus according to claim 5 or claim 6.
[Requested item 8]
 The key generation means, and the clock information estimated for the other said communication device, the adjustment information representing a difference between said clock information clock generating means has generated in its own device, held in association with another said communication apparatus and,
 self apparatus when a communication device on the transmitting side for transmitting communication data to the other said communication device,
 wherein the device information selection means, the clock information generated by the clock generating means, the adjusting with adjusted using information, generates the selection information using the clock information after adjustment,
 the key generating means, said clock information generated by the clock generating means, with the adjustment information adjust as well as to generate an encryption key using the selection information generated by said clock information after adjustment and the device information selection means,
 the encryption Management means using the encryption key generated by the key generating unit, a communication device according to claim 5 or claim 6 for encrypting the communication data transmitted from said communication means.
[Requested item 9]
 The device information management means, a pre-shared key that all of the communication device held in common, to the own device stores a unique information, as the device information
 the encryption processing unit uses the pre-shared key encrypts the communication data including information specific to the own device,
 the communication means transmits the encrypted communication data to another communication device,
 the communication means, from the other said communication device, other when receiving the communication data including information specific to the communication device, the encryption processing means uses the pre-shared key to decrypt the communication data by the communication unit receives, included in the decoded communication data other information specific to the communication device, provides the device information management unit, a communication device according to any one of claims 5 to 8 to be.
[Requested item 10]
 The device information selection means, provided with at least a portion of the selected the device information, the calculated hash value of data including the clock information generated by the clock generating means, the calculated hash value as the selection information the communication apparatus according to claim 2.
[Requested item 11]
 The device information selection means,
  in response to the clock information has a plurality of selection processing means selects at least some of said different device information, respectively,
  selecting one or more of said selection processing means in response to said clock information and, using at least a portion of the device information selected by the selecting unit, the communication apparatus according to claim 2 or claim 10 for generating the selection information.
[Requested item 12]
 Has a transmitting-side communication device is the communication device according to each claim 7, the receiving communication device, a
 said encryption processing means in the transmitting-side communication device, the clock generating means in the transmitting-side communication device using the encryption key generated by the key generating means to encrypt communication data according to the clock information generated by the communication means in the transmission side communication apparatus, the receiving-side encrypted communication data and transmitted to the communication device,
 the encryption processing means in the receiving communication device, the clock information generated by said clock generating means in the receiving communication device, adjusted with the adjustment information, the post-adjustment using the encryption key generated by the key generating means using the clock information, decodes the communication data received from the transmitting-side communication device communication Stem.
[Requested item 13]
 Has a transmitting-side communication device is the communication device according to claim 8, respectively, and the receiving-side communication device, and
 the encryption processing means in the transmitting-side communication device, the clock generating means in the transmitting-side communication device the clock information generated and adjusted using the adjustment information, the encrypted communication data using an encryption key generated by the key generating means in response to said clock information after adjusting its sending communication the communication means in the apparatus may transmit the encrypted communication data to the reception side communication apparatus,
 the encryption processing means in the receiving communication device is generated by the clock generating means in the receiving communication device the passing by using the encryption key generated by the key generating means in response to the clock information, decodes the communication data received from the sending communication device System.
[Requested item 14]
 Using a periodic clock signal, generates a clock information representing a timing,
 in response to said clock information, and selecting at least a portion of the device information is information that is stored in common to one or more communication devices, from at least a portion of the selected the device information, the generated selection information which is information different for each clock information,
 and the clock information, using at least the generated said selected information to generate an encryption key,
 generation It has been using the encryption key, communication method for performing at least one of the encryption processing and decryption processing concerning communication data.
[Requested item 15]
 A computer constituting the communication device,
 using a periodic clock signal, and generating a clock information representing a timing,
 in response to said clock information is the information stored in common to one or more communication devices selecting at least a portion of the device information, from at least a portion of the selected said device information, and generating the selection information which is information different for each of the clock information,
 and the clock information, and the generated the selection information at least with a process of generating an encryption key,
 by using the generated encryption key, the communication program executed a process of executing at least one of the encryption processing and decryption processing concerning communication data, a is recorded recoding media.

Documents

Application Documents

# Name Date
1 201917009625.pdf 2019-03-12
2 201917009625-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [12-03-2019(online)].pdf 2019-03-12
3 201917009625-STATEMENT OF UNDERTAKING (FORM 3) [12-03-2019(online)].pdf 2019-03-12
4 201917009625-REQUEST FOR EXAMINATION (FORM-18) [12-03-2019(online)].pdf 2019-03-12
5 201917009625-PRIORITY DOCUMENTS [12-03-2019(online)].pdf 2019-03-12
6 201917009625-POWER OF AUTHORITY [12-03-2019(online)].pdf 2019-03-12
7 201917009625-FORM 18 [12-03-2019(online)].pdf 2019-03-12
8 201917009625-FORM 1 [12-03-2019(online)].pdf 2019-03-12
9 201917009625-DRAWINGS [12-03-2019(online)].pdf 2019-03-12
10 201917009625-DECLARATION OF INVENTORSHIP (FORM 5) [12-03-2019(online)].pdf 2019-03-12
11 201917009625-COMPLETE SPECIFICATION [12-03-2019(online)].pdf 2019-03-12
12 201917009625-CLAIMS UNDER RULE 1 (PROVISIO) OF RULE 20 [12-03-2019(online)].pdf 2019-03-12
13 201917009625-RELEVANT DOCUMENTS [18-03-2019(online)].pdf 2019-03-18
14 201917009625-MARKED COPIES OF AMENDEMENTS [18-03-2019(online)].pdf 2019-03-18
15 201917009625-FORM 13 [18-03-2019(online)].pdf 2019-03-18
16 201917009625-AMMENDED DOCUMENTS [18-03-2019(online)].pdf 2019-03-18
17 201917009625-Power of Attorney-150319.pdf 2019-03-19
18 201917009625-OTHERS-150319.pdf 2019-03-19
19 201917009625-OTHERS-150319-.pdf 2019-03-19
20 201917009625-Correspondence-150319.pdf 2019-03-19
21 abstract.jpg 2019-04-13
22 201917009625-FORM 3 [14-05-2019(online)].pdf 2019-05-14
23 201917009625-Proof of Right (MANDATORY) [10-06-2019(online)].pdf 2019-06-10
24 201917009625-OTHERS-130619.pdf 2019-06-27
25 201917009625-Correspondence-130619.pdf 2019-06-27
26 201917009625-FORM-26 [04-12-2020(online)].pdf 2020-12-04
27 201917009625-FORM 3 [04-12-2020(online)].pdf 2020-12-04
28 201917009625-OTHERS [07-12-2020(online)].pdf 2020-12-07
29 201917009625-FER_SER_REPLY [07-12-2020(online)].pdf 2020-12-07
30 201917009625-DRAWING [07-12-2020(online)].pdf 2020-12-07
31 201917009625-COMPLETE SPECIFICATION [07-12-2020(online)].pdf 2020-12-07
32 201917009625-CLAIMS [07-12-2020(online)].pdf 2020-12-07
33 201917009625-ABSTRACT [07-12-2020(online)].pdf 2020-12-07
34 201917009625-FORM-26 [13-07-2021(online)].pdf 2021-07-13
35 201917009625-Correspondence to notify the Controller [13-07-2021(online)].pdf 2021-07-13
36 201917009625-FER_SER_REPLY [23-07-2021(online)].pdf 2021-07-23
37 201917009625-CLAIMS [23-07-2021(online)].pdf 2021-07-23
38 201917009625-SER.pdf 2021-10-18
39 201917009625-FER.pdf 2021-10-18
40 201917009625-PatentCertificate08-11-2021.pdf 2021-11-08
41 201917009625-IntimationOfGrant08-11-2021.pdf 2021-11-08
42 201917009625-RELEVANT DOCUMENTS [20-09-2022(online)].pdf 2022-09-20
43 201917009625-RELEVANT DOCUMENTS [11-09-2023(online)].pdf 2023-09-11

Search Strategy

1 SearchstrategyE_08-10-2020.pdf

ERegister / Renewals

3rd: 14 Jan 2022

From 02/10/2019 - To 02/10/2020

4th: 14 Jan 2022

From 02/10/2020 - To 02/10/2021

5th: 14 Jan 2022

From 02/10/2021 - To 02/10/2022

6th: 30 Sep 2022

From 02/10/2022 - To 02/10/2023

7th: 29 Sep 2023

From 02/10/2023 - To 02/10/2024

8th: 30 Sep 2024

From 02/10/2024 - To 02/10/2025

9th: 24 Sep 2025

From 02/10/2025 - To 02/10/2026