Sign In to Follow Application
View All Documents & Correspondence

Communication Device, Communication Method, Communication System, And Recording Medium

Abstract: The present invention reduces the impact from the load of encryption processing while maintaining the safety of encrypted communication. To this end, a communication device (100) is equipped with: an encryption method selection unit (101) for selecting encryption methods which entail different processing loads for the encryption processing used in encrypted communication, according to the synchronization accuracy, which expresses the quantity of times at which it is possible to change the encryption method to be used in encrypted communication between a given device and another device; and an encryption processing unit (102) for subjecting the communication data between the given device and the other device to encryption processing and/or decryption processing by using the selected encryption method.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
12 March 2019
Publication Number
23/2019
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
archana@anandandanand.com
Parent Application
Patent Number
Legal Status
Grant Date
2024-01-17
Renewal Date

Applicants

NEC CORPORATION
7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Inventors

1. ONO Masakazu
c/o NEC CORPORATION, 7-1, Shiba 5-chome, Minato-ku, Tokyo 1088001

Specification

Technical field
[0001]
 The present disclosure relates to a technique for performing communications using encrypted communication data.
BACKGROUND
[0002]
 Recently, a communication method for transmitting and receiving the encrypted data (encrypted communication) has been widely used. In the cryptographic communication, the communication device, using the secret information (e.g. key), executes encryption processing and decryption processing of the communication data. Hereinafter, the encryption process and decryption processing of data, collectively referred to as "cryptographic processing". The data that has not been encrypted as "plain text data", the data obtained by encrypting the plaintext data is referred to as "encrypted data". Together with the key used for encryption, and a key used for decoding is referred to as "encryption key". The key used for decryption key used for encryption may be the same key data (e.g., common key encryption scheme), may be a pair of different key data (e.g., public key cryptography).
[0003]
 If the encryption key is leaked, ciphertext encrypted to compromise by using the encryption key. Further, if the number of encrypted ciphertext is increased using the same encryption key, it may give a clue attacks on encryption processing to the attacker. Therefore, in the cryptographic communication, sometimes the encryption key and the encryption algorithm is changed as appropriate. To maintain the encrypted communication, each communication device, for example, to change the encryption key synchronization.
[0004]
 Technology related to the change of encryption key according is described in the following patent documents. That is, Patent Document 1 was used first and encryption communication device that acquires the temporary key from the management device, between the second encryption communication device having a master key that identical or corresponding and the management device, the temporary key techniques for performing cryptographic communication is described. By managing device updates the data periodically temporary key generation, temporary key used for encrypted communication is changed.
CITATION
Patent Document
[0005]
Patent Document 1: International Publication No. WO 2013/076848
Summary of the Invention
Problems that the Invention is to Solve
[0006]
 Hereinafter, the encryption algorithm, encryption key, cipher modes such as, in some cases together elements used in encrypted communication is described as an encryption method. In general, the processing load of the encryption strength is high encryption method is the more likely, there is a possibility that the throughput of the communication by the encryption process is reduced. Further, if the load of encryption processing is high, generally the power consumption increases. On the other hand, the encryption strength of the impact on the communication throughput is relatively small (processing load is relatively low) cryptography, may be relatively low. That is, while reducing the influence on the processing load on cryptography process, to maintain the security of the encrypted communication, there is a problem in that.
[0007]
 Incidentally, Patent Document 1 is configured to periodically change the encryption key used for encrypted communication, a technique for verifying the validity of the encryption key according discloses. That is, the technique disclosed in Patent Document 1 is a technique that focuses on the change of the encryption key, the processing load related to the encryption processing is not considered.
[0008]
 The present disclosure has been made in view of the circumstances described above. That is, the present disclosure, while maintaining the security of the encrypted communication, to provide a reduced available communication device or the like the influence of the load of encryption processing, and one of the main purposes.
Means for Solving the Problems
[0009]
 To achieve the above object, the communication apparatus according to an embodiment of the present disclosure, the own device and another synchronization accuracy representing a multitude of possible change timing the encryption scheme used for the cryptographic communication with the communication device in response, the encryption method selection portion the processing load related to the encryption processing in the encryption communication selects a different said encryption method, using the encryption method selected, encrypted concerning communication data between said another communication device and a cryptographic processing unit for performing at least one of the processing and the decryption processing.
[0010]
 The communication method according to one aspect of the present disclosure, depending on the own device and another synchronization accuracy representing a multitude of possible change timing the encryption scheme used for the cryptographic communication with the communication device, the encrypted communication the processing load on cryptography process selects different said encryption method in using the encryption method selected, to perform at least one of the encryption process and the decryption process regarding the communication data between said another communication device .
[0011]
 Furthermore, the object is a communication apparatus with the above configuration, a computer program for implementing the communication method by a computer (communication program), and also achieved by the computer program computer-readable is stored a storage medium that.
[0012]
 That is, the computer program according to one aspect of the present disclosure, the computer constituting the communication device, represents the abundance of the own apparatus and the other changeable timing the encryption scheme used in the cryptographic communication with the communication device synchronization depending on the accuracy, a process of processing load related to the encryption process to select a different said encryption method in the encryption communication by using the encryption method selected, encryption processing concerning communication data between said another communication device so as to execute a processing for executing at least one of the decoding process to be composed.
Effect of the invention
[0013]
 According to the present disclosure, the communication device, while maintaining the security of the cryptographic communication, it is possible to reduce the influence of the load of encryption processing.
BRIEF DESCRIPTION OF THE DRAWINGS
[0014]
[1] Figure 1 is a block diagram illustrating a functional configuration of a communication apparatus according to the first embodiment of the present disclosure.
FIG. 2 is a flowchart showing an example of operation of the communication device in the first embodiment of the present disclosure.
FIG. 3 is a block diagram illustrating a functional configuration of a communication apparatus in the second embodiment of the present disclosure.
[4] FIG. 4 is a block diagram illustrating another functional configuration of the communication apparatus in the second embodiment of the present disclosure.
FIG. 5 shows a communication device according to a second embodiment of the present disclosure, an example of information that holds the synchronization accuracy between the other communication device is an explanatory diagram.
FIG. 6 is an explanatory diagram showing a specific example of the second embodiment can realize a communication device in a hardware configuration of the present disclosure.
[7] FIG. 7 is an explanatory diagram showing another example of the second embodiment can realize a communication device in a hardware configuration of the present disclosure.
[8] FIG. 8 is a diagram showing another example of the second embodiment of the communication device hardware configuration capable of realizing the present disclosure.
[9] FIG. 9 is a sequence diagram illustrating the operation of the communication apparatus in the second embodiment of the present disclosure (an example of a synchronization clock information).
[10] FIG 10 is an explanatory diagram showing an example of information used in determining the synchronization accuracy in the second embodiment of the present disclosure.
[11] FIG 11 is a flowchart showing an operation of the communication apparatus in the second embodiment of the present disclosure (an example of the selection operation of the encryption method).
[12] FIG 12 is a flowchart showing an operation of the communication apparatus in the second embodiment of the present disclosure (an example of the operation of updating the encryption key).
[13] FIG 13 is a flowchart showing an operation of the communication apparatus in the second embodiment of the present disclosure (another example of the operation of updating the encryption key).
[14] FIG. 14 shows an example of information held communication device according to a modified example of the second embodiment of the present disclosure, the difference between the clock information with another communication device is an explanatory diagram.
DESCRIPTION OF THE INVENTION
[0015]
 Prior to description of embodiments of the present disclosure, made by the inventors of the present disclosure will be described in more detail technical considerations concerning the present disclosure.
[0016]
 As described above, each communication apparatus capable of performing cryptographic communication using a certain encryption method and executes the cryptographic processing concerning communication data. For example, when using a common key encryption method, each communication device, using a common encryption key, and executes the cryptographic processing concerning communication data. For example, when using a public key encryption method, each communication device performs encryption processing and decryption processing of the communication data by using the public key and a private key. In either case, each communication device performs encryption processing by using the same encryption method.
[0017]
 For example, in the cryptographic communication, the encrypted data is increased by using the same encryption method, an attacker may increase clue decryption available. From the viewpoint of reducing the risk of, in the cryptographic communication, a process of properly changing the encryption method is performed. In this case, each communication apparatus, from the viewpoint of maintaining the encrypted communication, to the same encryption method as the other communication devices can be used, for example, to change the encryption method in synchronization (update).
[0018]
 However, the environment in which the communication device is deployed, there may be is difficult to each communication device to change the encryption method in conjunction with other communication devices. If the change of the encryption method is difficult, the communication devices may execute the encrypted communication by using the same encryption method over a relatively long period of time (e.g., the same cryptographic key, cryptographic algorithm, etc.). Thus, there is a possibility that the ciphertext generated by one encryption method is increased. In this case, from the viewpoint of maintaining the security of the encrypted communication, but decryption is difficult (encryption strength is high) encryption scheme may be employed, in general, difficult cryptosystem cryptanalysis requires the encryption processing load is considered to be greater (the processing load is high).
[0019]
 On the other hand, the communication device is also considered appropriate modification possible situations an encryption scheme with another communication device. In situations of, for example, are frequently possible to change the encryption method, the same encryption method (e.g., cryptographic keys, cryptographic algorithm, etc.) is considered the amount of ciphertext generated by (size) is suppressed . In such a situation, for example, since the range of influence if the encryption key related to a certain encryption system is compromised can be limited, the load required for the cryptographic processing is small (processing load is low) could use a cryptosystem It is.
[0020]
 Therefore, the communication apparatus according to the present disclosure will be described in the following embodiments, the degree capable of changing the encryption method (e.g., the degree of abundance of possible change timing) in accordance with the encryption scheme to be used for encrypted communication appropriate configured to select.
[0021]
 Each communication device, if the timing can be changed encryption method is large, frequently is considered possible to update the encryption scheme. Specifically, each communication device to facilitate synchronization process to synchronize information related to the encryption method (frequently) If feasible, each communication device is often considered to be possible to change the encryption method. Further, each of the communication device, aging also (over time errors such as by difference) capable of maintaining a small, each communication apparatus frequently cryptographic information relating to the encryption scheme (information to be synchronized) considered method it is possible to update.
[0022]
 In contrast, for example, if each communication apparatus can not often perform a synchronization process, and if that each communication device maintaining a small change with time of information held difficult, each communication device a cryptosystem It may become difficult to update.
[0023]
 In view of the above, the communication apparatus according to the present disclosure, for example, the more timing capable of changing the encryption method, configured to process load to adopt a low encryption method. The communication apparatus according to the present disclosure, for example, the smaller the timing capable of changing the other communication apparatus and the encryption method, configured to adopt decryption is difficult encryption method (processing load is high encryption method) . According to the communication apparatus of the present disclosure constructed as described above, communication device according to changeable situation encryption method, using the appropriate encryption method, while maintaining the security of encrypted communication It may reduce the impact on the communication throughput. It will be described in detail a possible embodiment implementing a communication apparatus according.
[0024]
 The configuration of the communication apparatus described in the following embodiments are illustrative and the technical scope of the present disclosure is not limited thereto. The following distinctions between components constituting the communication apparatus in each embodiment (for example, divided by functional units) is an example that can realize the communication device. Upon implementation of the communication device is not limited to the following examples, various configurations are envisioned. That is, the components constituting the communication apparatus in the following embodiments may be further divided, one or more components may be integrated.
[0025]
 Communication apparatus described below may be configured with a single device (physical or virtual device), be implemented using a plurality of spaced apart devices (physical or virtual device) good. Communication device will be described below, or, for the hardware configuration capable of realizing the components thereof will be described later.
[0026]
 
 The following describes a basic embodiment of the present disclosure.
[0027]
 Figure 1 is a block diagram illustrating a functional configuration of a communication apparatus 100 according to the first embodiment of the present disclosure.
[0028]
 Communication device 100 is capable of executing device encrypted communications. For one communication device 100, one or more other communication devices may be communicatively coupled. A communication device 100, the communication path connecting the other communication devices, for example, wireless communication, wired communication, or may be realized by a combination thereof. The communication protocol used for communications according is not particularly limited, may be appropriately selected. Another communication device 100 is communicatively coupled to the communication device 100 may be a communication device configured similarly to the communication device 100.
[0029]
 As illustrated in FIG. 1, the communication device 100, the encryption method selection unit 101 and includes an encryption processing unit 102. During these components constituting the communication apparatus 100, the data and the command (command) or the like may be connected in a transmit. The following describes these constituent elements constituting the communication device 100.
[0030]
 Encryption method selection unit 101 (the encryption method selection means) in accordance with the synchronization accuracy representing the degree capable of updating the encryption scheme used for encryption communication between the own apparatus and the other communication devices (synchronization state) configured to process loads for encryption processing in encryption communication selects a different encryption method.
[0031]
 Encryption method selection unit 101, for example, as the timing of its own device and the other communication device to update the encryption scheme in synchronization is large, it may be determined to be high synchronization accuracy. In this case, the encryption method selection unit 101, for example, according higher synchronization accuracy may select an encryption scheme processing load is low required for cryptographic processing. For example, the own apparatus, when the other communication apparatus is frequently updatable encryption method (i.e., if alterable timing cryptography is large), the amount of ciphertext generated by one cryptosystem It may be limited. Therefore, even if when one encryption method is compromised, the influence range is limited. In this case, the encryption method selection unit 101, for example, by employing an encryption scheme load is low relatively encryption process, while still maintaining some security of encrypted communication, reducing the influence of the communication by the encryption process can.
[0032]
 The encryption method selection unit 101, for example, as the own device and another timing capable of changing the encryption method and communication device are synchronized is small, it may be determined to be low synchronization accuracy. In this case, the encryption method selection unit 101, for example, according the lower synchronization accuracy, decryption is difficult (processing load required for encryption processing is high) may select the encryption method. For example, the own apparatus, it is difficult to synchronize with other communication devices, if you can not frequently updated encryption method (i.e., if changes possible timing the encryption scheme is small), cipher generated by one cryptosystem there is a possibility that the amount of the sentence is increased. In this case, the encryption method selection unit 101, a relatively load of the encryption processing is heavy by selecting the (decryption difficult) encryption method, which makes it possible to maintain the security of the encrypted communication.
[0033]
 Encryption processing unit 102 (the encryption processing unit), using the encryption method selected by the encryption method selection unit 101, performs at least one of the encryption process and the decryption process regarding the communication data with the other communication devices configured to. That is, the encryption processing section 102 uses the encryption method selected by the encryption method selection unit 101, executes the cryptographic processing concerning communication data exchanged with another communication device.
[0034]
 Description is given of operations performed by the communication device 100 as described above will be described with reference to the flow chart illustrated in FIG. Flowchart illustrated in FIG. 2, for example, the communication device 100 may be performed at the start of another communication device and encryption communication may be performed periodically, be performed in other suitable timing it may be.
[0035]
 Encryption method selection unit 101, the own device (the communication device 100), to check the synchronization accuracy between the other communication device (step S201). Synchronization accuracy of, for example, the own device and another communication device size of the difference of the information that is synchronized between (for example, the difference of the clock synchronized size, etc.), and the configuration of the other communication devices it may be determined based on the equal.
[0036]
 Encryption method selection unit 101 selects the encryption method corresponding to the synchronization accuracy was confirmed in the step S201 (step S202). Encryption method selection unit 101, for example, synchronization accuracy between the own device and another communication device is high (i.e., the timing can be changed encryption method is large) enough, the processing load is low cryptosystem required for the cryptographic processing the may be selected. The encryption method selection unit 101, for example, synchronization accuracy between the own device and another communication device is low (i.e., encryption method timing is less capable of changing) as the processing load required for cryptographic processing high You may select the encryption method. Encryption method selection unit 101, for example, as an encryption method, an encryption key used in the encryption process, the encryption algorithm, parameters associated with the cryptographic algorithm (key length, block length, the encryption mode, etc.) can be selected.
[0037]
 Note that the encryption method selection unit 101, if necessary, may execute processing to agree the encryption method selected with another communication device.
[0038]
 Encryption unit 102 uses the encryption method selected at step S202, the encryption processing concerning communication data to and from another communication device (e.g., at least one of the encryption process and the decryption process) (steps S203). Thereby, the encryption processing unit 102 uses the own device (the communication device 100), selected according to the state of synchronization with another communication device, the encryption method suitable processing load, encrypted concerning communication data it is possible to execute the process.
[0039]
 Configured communication apparatus 100 as described above, while maintaining the security of the cryptographic communication, it is possible to reduce the influence of the load of encryption processing. This is because the encryption method selection unit 101 selects an appropriate encryption method according to the synchronization state between the communication device 100 and another communication device.
[0040]
 For example, (if the timing can be changed encryption method is large) and the communication apparatus 100, when the other communication apparatus is synchronized with high accuracy, the communication device 100 (encryption method selection unit 101) is relatively processing load You may select a low encryption method. Thus, the influence of the communication processing by the load of the encryption processing can be reduced. Further, since it is frequently change the encryption scheme, if one of the encryption method (encryption key, the encryption algorithm or the like) even if has been compromised, it is possible to easily switch to a safe encryption method, influence range by cryptography compromised also limited. Thus, it is possible to maintain the security of the encrypted communication.
[0041]
 Further, for example, a communication device 100, when it is difficult to synchronize the other communication apparatus with high accuracy, there is a possibility that is used the same encryption method over a relatively long period of time. Therefore, in this case, the communication device 100, the decryption is difficult (relatively high processing load) may select the encryption method. Accordingly, the communication device 100 is capable of maintaining the security of the encrypted communication.
[0042]
 
 Hereinafter, was in the first embodiment and the base, a description will be given of a second embodiment of the present disclosure.
[0043]
 Figure 3 is a block diagram illustrating a functional configuration of the communication apparatus 300 in this embodiment. Communication device 300 is capable of executing device encrypted communications. For one communication device 300, one or more other communication devices 400 may be communicatively coupled. Another communication device 400 according, for example, may be a communication apparatus having the same configuration as the communication device 300.
[0044]
 Communication path for connecting the communication device 300 and communication device 400 is, for example, wireless communication, wired communication, or may be realized by a combination thereof. The communication protocol used for communications according is not particularly limited, may be appropriately selected.
[0045]
 In the present embodiment, for convenience of explanation, the communication device 300 illustrate the manner of changing the encryption key constituting the encryption system, the present embodiment is not limited thereto. Each communication device, for example, encryption algorithms that constitute the encryption method, an encryption use mode, and other various parameters relating to the encryption processing may be changed.
[0046]
 As illustrated in FIG. 3, the communication device 300 includes device status management unit 301, a clock generator 302, an encryption method selection unit 303, the key generation unit 304, the encryption processing unit 305. Communication device 300 may include a communication unit 306 and the data transfer unit 307. During these components constituting the communication apparatus 300, the data and the command (command) or the like may be connected in a transmit. The following describes these constituent elements constituting the communication device 300.
[0047]
 Equipment status management unit 301 (equipment status management means), manages the self-device (the communication device 300), a synchronization state between the other communication device 400. In this embodiment, device state management unit 301 manages the own apparatus, the synchronization state of the clock information (described later) in another communication device 400..
[0048]
 Equipment status management unit 301, for example, by using a table as illustrated in FIG. 5, with other communication devices 400 may be held in association with the information representative of the synchronization accuracy (store). In the table illustrated in FIG. 5, the communication device (501 in FIG. 5) is capable of specifying identification information of other communication device 400 (ID: Idetentifier) ​​shows a. According identification information may be, for example, an address in the communication network of another communication device 400 may be a host name, and the like. According identification information is not limited to the above, it can be appropriately selected. Also, synchronization accuracy (502 in FIG. 5) shows a communication device 300, the synchronization accuracy between the other communication device 400. For the specific example shown in FIG. 5, "high Synchronization" as synchronization accuracy 502, "low synchronization", and "asynchronous", a label indicating the synchronization accuracy are set. In this case, "high Synchronization", "low sync", in the order of "asynchronous", the synchronization accuracy becomes lower. Note that the synchronization accuracy 502 is not limited to the above, data capable of indicating the synchronization accuracy in multiple stages (e.g., numeric, etc.) may be set.
[0049]
 Equipment status management unit 301 includes a communication device 300, with the other communication device 400, as the information about the encryption method, the clock generator 302 (described later) is configured to perform a process to synchronize the clock information to produce that.
[0050]
 Incidentally, equipment status management unit 301, the data used to generate the encryption key in the cryptographic communication (hereinafter referred to as "apparatus information") may be stored (held) a. Equipment status management unit 301, as one variation of the device information may hold pre-shared key or the like that are common to all of the communication device.
[0051]
 Clock generating unit 302 (clock generating means), using a periodic clock signal, configured to generate a clock information which is information indicating a timing. Clock generator 302, the generated clock information can be provided to other components of the communication device 300.
[0052]
 Clock generating unit 302, for example, using a predetermined generating possible suitable device a clock signal that satisfies the frequency accuracy (oscillation device), and generates a clock signal. Specifically, the clock generator 302, for example, may generate a clock signal using an atomic clock device comprising rubidium atomic oscillator, a cesium atomic oscillator or the like. In this case, the clock generator 302 can generate a clock signal of very high accuracy (e.g., frequency accuracy is approximately "± 5 × 10E-11"). For example, if the clock generating unit 302 uses an atomic clock device, using a signal input for synchronization that are available in the atomic clock device, it is possible to adjust the clock signal. Specific timing adjusting a clock signal, for example, be a periodical timing, it may be timing representing a particular time.
[0053]
 Instead of using a very high-precision devices atomic clock device etc., a clock generator 302, for example, may generate a clock signal by using a general crystal oscillator. For example, the clock generating unit 302, by adjusting the clock signal to match the particular timing may maintain the accuracy of the clock signal.
[0054]
 The timing of adjusting the clock signal, for example, may be provided from the equipment status management unit 301. Thus, equipment status management unit 301, for example, a clock clock generator 302 generates, it is possible to synchronize with other communication devices 400.
[0055]
 Clock information clock generator 302 generates, for example, may be information representing a periodic clock signal itself. The clock information may be information indicating a counter value obtained by counting the clock signal from a certain timing. The clock generator 302 may generate clock information including information indicating the time. The clock generator 302 may generate clock information including information indicating an elapsed time from a certain timing.
[0056]
 Encryption method selection unit 303 (the encryption method selection means) selects the encryption method corresponding to the synchronization accuracy between the other communication device 400. Encryption method selection unit 303, for example, its own device (the communication device 300) higher synchronization accuracy between the other communication device 400, processing load required for cryptographic processing may select a low encryption method. The encryption method selection unit 303, for example, as the synchronization accuracy between the own device (the communication device 300) with another communication device 400 is low, the processing load required for cryptographic processing may select a higher encryption scheme .
[0057]
 As an example, the case of the example shown in FIG. 5, the encryption method selection unit 303 as the encryption scheme used in the cryptographic communication with the "communication apparatus # 1", the cryptographic communication with the "communication apparatus # 2" processing load than the encryption scheme may select a lower encryption method used for. Encryption method selection unit 303 as the encryption scheme used in the cryptographic communication with the "communication apparatus # 2", "communication device # 3" cryptographic processing load lower than that of the encryption scheme used in the cryptographic communication with the You may select the method. Encryption method selection unit 303, for example, as the processing load is different encryption method, key length in the same algorithm may select a different encryption method. As a specific example, the encryption method selection unit 303, for example, "communication device # 1", as the encryption scheme for the "communication apparatus # 2", "communication device # 3", the safety index of encryption strength, respectively 128bit, 192bit, encryption method of 256bit may be selected. More specifically, the encryption method selection unit 303, for example, key length of 128bit AES-128 (AES: Advanced Encryption Standard), AES-192 key lengths 192bit, the AES-256 key length 256bit respectively selected and it may be. Encryption method selection unit 303, for example, key length 3072bit, 7680bit, may select an RSA public key cryptography 15360Bit. Not limited to the above, the encryption method selection unit, the processing load is different encryption schemes may be selected cryptosystem encryption algorithm itself are different encryption algorithms and key lengths may select a different encryption method. Cryptographic algorithm constituting the encryption method encryption method selection unit 303 selects is not particularly limited, for example, it is possible to employ appropriate cryptographic algorithms safety has been confirmed.
[0058]
 Encryption method selection unit 303, in accordance with the synchronization accuracy between the other communication device 400 may be configured to adjust the change the encryption method selected (updated) to the interval (update interval). Encryption method selection unit 303, for example, the higher the accuracy of synchronization between the own device (the communication device 300) with other communication devices 400, so as to change the encryption method at short intervals, be adjusted update interval good. The encryption method selection unit 303, for example, its own device (the communication device 300) the lower the accuracy of synchronization with another communication device 400, to update the encryption scheme with a long interval, to adjust the update interval it may be.
[0059]
 Encryption method selection unit 303 may be further configured to perform a process to agree the encryption method to be used with another communication device 400.
[0060]
 Encryption method selection unit 303 configured as described above is also contemplated that the encryption method, which is one specific example capable of realizing the selection unit 101 in the first embodiment.
[0061]
 The key generation unit 304 (key generation means) generates a cipher key used in the encryption method selected by the encryption method selection unit 303. For example, the encryption method selection unit 303, if the encryption system using a cryptographic key of a particular key length is selected, the key generation unit 304 generates an encryption key of the specific key length.
[0062]
 In this embodiment, the key generating unit 304 using the clock information provided from the clock generating unit 302 generates an encryption key. More specifically, the key generating unit 304, by using the clock information, and device information held by the device state management unit 301 may generate an encryption key.
[0063]
 How key generating unit 304 generates an encryption key is not particularly limited, and may select the appropriate method. The key generating unit 304, for example, generates a selection information selected from at least a portion of the device information, and clock information as a seed, a random number using a pseudo-random number generator cryptographically safety has been confirmed and it may provide the random number as an encryption key. The key generating unit 304, for example, using the selected information as a key, the result of encrypting the clock information by using the encryption algorithm cryptographically safety has been confirmed, also be provided as an encryption key good. The key generation unit 304 calculates a hash value of the selected information and clock information using a suitable hash function may provide the hash value as an encryption key. Thus, the key generation unit 304 may generate the selection information, an encryption key different depending on the clock information. When a plurality of communication devices have a common device information, their communication device 300, by using the same clock information, and the same device information can generate the same encryption key.
[0064]
 As another example, the key generation unit 304, for example, the clock information (seed key) information provided from an external communication device 300 and may generate an encryption key using the.
[0065]
 Key generating unit 304 may be configured to change the encryption key at the right time (updated). By the key generation unit 304 changes the encryption key (updated), it is possible to properly maintain the safety of the cryptographic communication. The key generating unit 304, a specific timing (e.g., timing, etc. corresponding to the update interval of the encryption method that is adjusted by the equipment status management section 301) generates an encryption key in the generated encryption key to the encryption processing unit 305 it may be provided.
[0066]
 A communication device 300, when the other communication device 400 is synchronized with high accuracy, the respective clock information are synchronized. In this case, each communication apparatus, it is possible to update the encryption key at the same (or substantially identical) timing may without distributing keys updated.
[0067]
 If the communication device 300, the synchronization accuracy between the other communication device 400 low, the respective clock information is a difference. In this case, the communication device 300, in the other communication device 400, and a key update timing, it is possible that differences in encryption key generated occurs. In situations of, when updating the encryption key, the communication device 300 (e.g., equipment status management section 301) is another communication device 400 and the clock information synchronized, the encryption key using the clock synchronized information it may be updated.
[0068]
 The communication device 300 may optionally be configured to distribute the updated encryption key to another communication device 400. How to safely distribute the encryption key, for example, it may be implemented using well-known techniques.
[0069]
 Encryption processing unit 305 (the encryption processing unit), using an encryption key key generating unit 304 has generated, executes encryption processing by the encryption method selected by the encryption method selection unit 303.
[0070]
 Specifically, the encryption processing unit 305 receives the encrypted communication data from the communication unit 306 (described later) by using the key data key generating unit 304 has generated, and decodes the communication data. Encryption processing unit 305 may provide a communication data decoded in the data transfer unit 307 (described later). Further, the cryptographic processing unit 305, using the encryption key key generating unit 304 has generated, encrypted communication data in plain text provided by the data transfer unit 307. Encryption processing unit 305, a communication data encrypted, may be provided to the communication unit 306.
[0071]
 Encryption processing unit 305, when the communication unit 306 there are a plurality, for example, as illustrated in FIG. 4, may be configured to perform encryption processing in parallel for each communication unit 306. For example, the encryption unit 305a using the encryption key, executes the process of encrypting the communication data in plain text. Also, the decryption unit 305b receives the encrypted communication data from the communication unit 306, and decodes the communication data using the encryption key. The encryption unit 305a, the decryption unit 305b includes, for example, threads, processes, may be implemented as a software program tasks, and the like. Also, the encryption unit 305a, the decryption unit 305b includes, for example, may be implemented in parallel and processed as a viable hardware (circuitry).
[0072]
 Encryption unit 305 configured as described above is also believed to be one of the embodiment capable of realizing the encryption processing section 102 in the first embodiment.
[0073]
 The communication unit 306 (communication means), the communication data encrypted by the encryption processing unit 305, transmitted to and received from the other communication device 400. Specifically, the communication unit 306 receives the communication data encrypted from the encryption processing unit 305, and transmits to the other communication device 400. The communication unit 306, a communication data encrypted received from the other communication device 400, and provides the encryption processing unit 305.
[0074]
 Communication device 300 may include a plurality of communication unit 306. Each communication unit 306 may send and receive communication data to and from separate other communication device 400. That is, a communication unit 306, and other communication devices 400 to which the communication unit 306 to transmit and receive communication data may be one-to-one correspondence. Also, one communication unit 306 may be communicatively coupled to a plurality of other communication devices 400.
[0075]
 The communication unit 306 is optionally the communication unit 306 may be measurably constituting the delay occurring in the communication path between the other communication device 400 for transmitting and receiving communication data. How to measure the delay in the communication path, for example, it may be implemented by employing well-known techniques.
[0076]
 Data transfer unit 307 (data transfer unit) executes the transfer process regarding the communication data. The data transfer unit 307, for example, by analyzing the communication data in plain text provided by the encryption processing unit 305, the routing regarding the communication data, or performs processing such as switching.
[0077]
 The data transfer unit 307 receives the data generated inside or outside the communication device 300, the data is encrypted by the encryption processing unit 305, it is configured to transmit via the communication unit 306 to another communication device 400 it may be.
[0078]
 [Hardware Configuration]
 A specific example of the above-described functional as a communication device 300 having the configuration can realize the hardware configuration will be described with reference to FIGS. The hardware illustrated in FIG. 6 through FIG. 8 is one specific example capable of realizing the communication device 300, the hardware is not limited to a feasible communication device 300. The hardware configuration illustrated in FIGS. 6-8 may be implemented by physical hardware, it may be realized by virtualized hardware. The following describes the configuration illustrated in the figures.
[0079]
 Communication device 300 illustrated in FIG. 6 includes a processor 601, a memory 602, a clock generator 603, a communication interface 604 that includes a communications port, a. Communication device 300 includes a storage 605, an input-output interface 606, a drive device 608 may include more. These components, for example, are connected to one another via a suitable communication line (communication bus, etc.).
[0080]
 Communication device 300 illustrated in FIGS. 6 to 8, each component, for example, may be implemented by providing possible circuit configurations each function (Circuitry). Circuit arrangement according include, for example, and integrated circuits such as SoC (System on a Chip), a chipset or the like which is realized by using the integrated circuit. In this case, the data components of the communication device 300 is held, e.g., RAM integrated as SoC (Random Access Memory) area and the flash memory area, or connected storage devices to the SoC (semiconductor memory device) it may be stored in. Hereinafter, each component will be described.
[0081]
 The processor 601 may be a general-purpose CPU or microprocessor, or may be a logic circuit implemented using a programmable device. The processor 601, in accordance with a software program that is read into the memory 602, executes the process.
[0082]
 Memory 602 is, for example, a memory device such as a RAM that can be referenced from the processor 601. The memory 602, for example, a software program capable of realizing the respective components of the communication device 300 described above are stored. Each software program executed by the processor 601, for example, by a suitable method such as a communication between the shared memory and processes may be configured to allow transmitting various data mutually.
[0083]
 Clock generator 603 is, for example, a device comprising a device (e.g., atomic clocks, etc.) to generate a clock signal. The clock generator 603 is a device that acquires time information (eg, GPS units, the standard radio wave receiving unit, etc.). The clock generator 603 generates clock signal (or time information), may be provided to other components. For example, clock generator 302, a software program executed by the processor 601 may be implemented by using a clock signal generated by the clock generator 603. Incidentally, the clock generator 603 may be input-capable interface (signal input section) is provided with a synchronizing signal.
[0084]
 Communication interface 604 is a device including a communication port connected to the communication network, and a controller for controlling the transmission and reception of data. When the communication device 300 is connected to a wired communication line, the communication interface may be connected to the communication cable. When the communication device 300 is connected to a wireless communication line, the communication interface may be an antenna or the like for communication connections. For example, the communication unit 306 may be implemented using a communications interface 604.
[0085]
 Storage 605 may be, for example, a magnetic disk drive, such as a semiconductor memory device according to a flash memory is a nonvolatile storage device. Storage 605 stores various software programs and, the software program can store data to be used. For example, the device information held by the device state management unit 301, the information and the like indicating the synchronization accuracy, may be held in the storage 605.
[0086]
 Output interface 606, for example, a device for controlling input and output between the output device 607. Output device 607, for example, a communication device 300, the device for realizing an interface between a user (display, operation buttons, audio input and output devices, etc.). Whether the communication device 300 includes input and output interface 606 may be selected as appropriate.
[0087]
 Drive device 608 is, for example, a device for processing reading and writing of data to the storage medium 609 to be described later. Incidentally, whether the communication device 300 includes a drive apparatus 608 may be selected as appropriate.
[0088]
 Storage medium 609, for example an optical disc, a magneto-optical disk, a semiconductor flash memory or the like, a recordable storage medium data. The software program stored in the storage medium 609, shipment of the communication device 300, or in the operational phase, etc., may be stored through suitable drive device 608 in the storage 605. In the above case, various software programs may be installed on the communication device 300 by using an appropriate tool. In the above case, components of the communication device 300, where the code constituting the respective software program or a code, is recorded, can be regarded as constituted by a computer-readable storage medium.
[0089]
 Incidentally, manually encryption key to each communication device (e.g., pre-shared keys, etc.) When setting, according encryption key, the storage medium 609 may be distributed to the communication device 300 using.
[0090]
 Not limited to the above, the communication device 300 can be realized by the configuration as illustrated in FIG. 7, the configuration of FIG. 6, further comprising an encryption processing device 701.
[0091]
 The encryption processing device 701 is a device that includes a circuit configured to perform encryption processing, the circuit components, etc., that perform the key generation process. The encryption processing device 701 is, for example, a FPGA (field-programmable gate array), may be implemented using a ASIC (application specific integrated circuit).
[0092]
 Cryptographic processing device 701, for example, the encryption unit 305a and capable of executing the processing of the decryption unit 305b circuit may be multiple implementation illustrated in FIG. These circuits, each communication port communications interface 604 has, may perform the cryptographic processing concerning communication data transmitted and received in the communications port in parallel.
[0093]
 Note that the encryption processing device 701 is, for example, as illustrated in FIG. 8, may be implemented in the communication interface 604. In this case, the encryption processing device 701 mounted on each of the communication interface 604 performs the cryptographic processing concerning communication data transmitted and received in a communication port included in the communication interface 604.
[0094]
 [Operation]
 Operation of the configured communication apparatus 300 as described above will be described.
[0095]
 (Clock synchronization information)
 or less, between communication devices (e.g., a communication device 300, the communication device 400) will be described operation of adjusting the difference (error) of the clock information used to generate the encryption key . Incidentally, the process of adjusting the difference of the clock information, may be referred to as synchronization of clock information.
[0096]
 As explained above, in the present embodiment, the encryption key is generated using the clock information. For example, if the clock information in a certain communication device 300 (provisionally referred to as "communication device X"), another communication device 400 (provisionally referred to as "communication device Y") are synchronized, each communication device it is possible to generate a common encryption key.
[0097]
 Communication device 300 may be adjusted periodically clock information, may adjust the clock information at a predetermined timing determined by the setting values. The communication device 300 in accordance with the synchronization accuracy of the determination result will be described later, may control the frequency of adjusting the clock information.
[0098]
 As a method of communication device 300 to synchronize the clock information, it is possible to employ various methods. As an example of a method according a method of transmitting and receiving communication data for synchronization (hereinafter may be referred to as "clock adjustment data") between the communication devices can be considered. 9, by transmitting and receiving clock adjustment data is a sequence diagram showing an example of the operation to synchronize the clock information. By the components of the communication device 300 (particularly the equipment status management section 301 or the like) executes an appropriate process, the processing of the steps illustrated in FIG. 9 is advanced.
[0099]
 As illustrated in FIG. 9, the communication apparatus X transmits the clock adjustment data including the clock information of the own device to the communication device Y (step S901). The clock adjustment data is, for example, the clock information of the own device, information indicating the accuracy of the clock information device itself generates may be further included. Information indicating the accuracy of the clock information according, for example, may be information indicating the accuracy itself of the clock information, components for generating clock information in a communication device X (e.g., an atomic oscillator, such as a clock) in the information representing the it may be. Communication device X, the information representative of the timing of transmitting to the communication device Y clock adjustment data (e.g., time, or clock information or the like) may be stored.
[0100]
 Communication device X, when the encrypted channel between the communication device Y has been established, by using the encrypted communication path may transmit clock adjustment data to the communication device Y . In addition, when the communication apparatus X and the communication apparatus Y is holding the pre-shared key, the communication apparatus X, the clock adjustment data encrypted by using the pre-shared key according, may be transmitted to the communication device Y . In this case, the pre-shared key is used for encryption processing to a clock adjustment data, other than the clock adjustment data (usually) not used to encrypt the communication data. Since the pre-total of the encrypted data that is encrypted using a shared key is considered relatively low, it can be caused a problem on the safety of cipher communication by the pre-shared key compromise, etc. is considered low .
[0101]
 Communication device Y receives the clock adjustment data (step S902), transmits the response data to the clock adjustment data (step S903). The response data, for example, may include clock information in the communication apparatus Y is. Also, the response data, for example, information indicating the accuracy of the clock information communication apparatus Y is produced may be further included. Information indicating the accuracy of the clock information according, for example, may be information indicating the accuracy itself of the clock information, components for generating clock information in a communication device Y (e.g., an atomic oscillator, such as a clock) in the information representing the it may be.
[0102]
 Communication device X receives the response data from the communication device Y (step S904).
[0103]
 Communication apparatus X, in response to the clock information in the communication device Y included in the response data, to adjust the clock information in its own apparatus (step S905). More specifically, the communication apparatus X, the clock information of the communication device Y contained in the response data, calculates a difference between the clock information of the own device, based on the difference, the clock information device itself generates it may be adjusted. In this case, for example, the communication apparatus X, such that the clock information generated in the clock generator 302 is synchronized with the communication device Y, may control the clock generator 302. Accordingly, the communication device X can generate a clock signal synchronized with the communication device Y.
[0104]
 The above-described processing, the communication device X is capable of generating clock information synchronized at the timing of executing at least the processing, the communication device Y.
[0105]
 Note that the communication device X, a method of communication device Y to synchronize the clock information is not limited to the above, may be employed other suitable methods.
[0106]
 (Synchronization accuracy determination)
 below, the communication device 300 (communication device X) is described process of determining synchronization accuracy between the other communication device 400 (communication device Y).
[0107]
 In the present embodiment, since to generate the encryption key using the clock information, each communication device (communication device 300, the communication device 400) as the timing at which the clock information is synchronized often, each communication device is often it is possible to change the encryption key. Further, if the timing of the clock information is synchronized is small, the communication device 300 may be limited modifiable timing the encryption key.
[0108]
 For example, communication device 300 facilitates the synchronization process (frequently) If feasible, the timing at which the clock information is synchronized is considered large. Further, since the communication apparatus 300 generates if the clock information by using a high accuracy clock signal, is considered the difference after the clock information is once synchronized (e.g. temporal error) is small, the clock information but timing is synchronized is considered to many. On the other hand, if the execution of the synchronization process is difficult, or if the accuracy of the clock information generated is low, there is a possibility that the timing of the clock information is synchronization is relatively small.
[0109]
 In view of the above, in this embodiment, the communication device 300, depending on the synchronization status of the clock information, determines the synchronization precision. More specifically, as the timing at which the clock information is synchronized is large, since the timing that can change the encryption method is large, it is determined that there is a high synchronization accuracy. Further, if the timing of the clock information is synchronized it is small, since the timing that can change the encryption scheme is small, is determined to be low synchronization accuracy.
[0110]
 As a method communication device X determines synchronization accuracy, it is possible to employ various methods. As an example of the method according, the communication apparatus X, based on the setting information given in advance by a user or the like, may determine the synchronization accuracy. Specifically, for example, a user of the communication device X is preset in the communication device X synchronization accuracy between the other communication apparatus Y. In this case, the user placed the environment of each communication apparatus Y, in consideration of the network environment, it is possible to set the synchronization accuracy between appropriate communication device. Communication device X can be, for example, based on the setting of the information indicating the synchronization accuracy between the other communication apparatus Y, it may be set to the synchronization accuracy 502 illustrated in FIG.
[0111]
 As another example, communication device X, based on the result of the synchronization process described above, may determine the synchronization accuracy. Communication device X is specifically a difference in the size of the clock information, the other communication device Y configuration, and, depending on the response time of the synchronization processing for the another communication device Y, determines the synchronization accuracy it may be. Hereinafter, a method according is described with reference to specific examples shown in FIG. 10.
[0112]
 Communication apparatus X, when determining the synchronization accuracy between the communication device Y, for example, a difference of clock information between the communication device Y may be taken into account. Differential clock information, for example, be determined by calculating the difference between the clock information included in the response data received from the communication apparatus Y, the clock information of the communication device X. Communication device X includes a differential clock information between the communication device Y, based on a result of comparison between a certain reference difference value may be determined synchronization accuracy. If the difference of the clock information is large, for example, a communication device X, and a communication device Y, it may be difficult to synchronize with high accuracy. The reference difference value as a set value or the like, may be given in advance communication device X.
[0113]
 The communication apparatus X, when determining the synchronization accuracy between the communication device Y, for example, included in the response data received may be considered information indicating the accuracy of the clock information. Communication device X can be, for example, information indicating the accuracy of the clock information included in the response data, based on a result of comparison between the reference accuracy, may determine the synchronization accuracy. Reference accuracy of may be given to advance communication device X as a set value or the like. The communication apparatus X, which can generate constituting the clock generator 302 is highly accurate clock information in the communication device Y (e.g., atomic clocks, etc.) may be considered whether provided with. If the communication apparatus Y is capable of generating highly accurate clock information, the communication device Y may be able to remain a small difference in clock information. In this case, the communication apparatus X, the information components for generating clock information indicating the accuracy of the generated possible clock information may be given in advance as a set value or the like.
[0114]
 The communication apparatus X, when determining the synchronization accuracy between the communication device Y, e.g., the response time of the synchronization process between the communication apparatus Y, the result of comparison between the reference response time may be considered. The response time of the synchronization process, for example, communication device X is, from the transmission of the clock adjustment data at step S901, the determined by measuring the time until a response is received data in step S904. If the response time is long, for example, it may be difficult to frequently perform the synchronization process between the communication apparatus Y and the communication device X. Reference response time, as the set value or the like, may be given in advance communication device X.
[0115]
 In view of the above, communication device X, for example, the synchronization accuracy between the communication device Y may be determined as follows. That is, the communication apparatus X, for example, less than the difference reference difference value of the clock information, determines that the response time of the synchronization process is shorter than the reference response time, it is possible to appropriately execute the synchronization and communication device Y it may be. In this case, the communication apparatus X, the synchronization accuracy between the communication device Y may be determined as "high Synchronization".
[0116]
 Communication device X can be, for example, smaller than the reference difference value difference of the clock information, when the communication apparatus Y is configured to generate a highly accurate clock information, the difference of the clock information between the communication device Y is small state may be determined that the to be maintained. In this case, the communication apparatus X, the synchronization accuracy between the communication device Y may be determined as "high Synchronization".
[0117]
 Communication device X can be, for example, longer than the response time is the reference response time of the synchronization process, when the communication apparatus Y is configured to generate a low-accuracy clock information, the communication apparatus X, the communication device Y the synchronization accuracy may be determined to be "low-sync". Communication device X is also greater than the difference reference difference value of the clock information, is longer than the response time is the reference response time of synchronization processing, synchronization accuracy between the communication device Y determines "Low sync" good. Communication device X is also greater than the difference reference difference value of the clock information, when the communication device Y to generate clock information of low accuracy, the accuracy of synchronization between the communication device Y determines "Low sync" it may be. In these cases, it is considered a communication device X or communication device Y is difficult to perform the synchronization process, and it is difficult to difference of the clock information (e.g., temporal error) to maintain a small state it is from.
[0118]
 As a modification of the above, the communication apparatus X, for example, regardless of the response time of the synchronization process, the difference of the clock information, based on the configuration of the communication apparatus Y, may be determined synchronization accuracy. Communication device X can be, for example, less than the difference reference difference value of the clock information, when the communication device Y can be generated highly accurate clock information, "high sync" synchronization accuracy between the communication device Y it may be determined that. Communication apparatus X, the otherwise may be determined that the "low sync".
[0119]
 Communication device X can be, for example, not be able to perform synchronization between the communication device Y (e.g., such as when it is not possible to transmit the clock adjustment data), the synchronization accuracy between the communication device Y determines that "asynchronous" it may be. The communication apparatus X, for example, even if the communication apparatus Y does not receive a response, the synchronization accuracy between the communication device Y may be determined as "asynchronous".
[0120]
 Communication device X can be, for example, based on the determination result, the information indicating the synchronization accuracy between the other communication apparatus Y, may be set to the synchronization accuracy 502 illustrated in FIG.
[0121]
 (Selection of encryption method)
 Hereinafter, the operation of communication device X to select the encryption method will be described with reference to the flow chart illustrated in FIG. 11.
[0122]
 Communication device X confirms the synchronization accuracy between the communication device Y (step S1101). For example, communication device X (encryption method selection unit 303) may verify the synchronization accuracy of equipment status management unit 301 holds (502 in FIG. 5).
[0123]
 Communication apparatus X, in response to the synchronization accuracy confirming in step S1101, selects the encryption method used for encryption communication between the communication device Y (step S1102). If "high synchronization" is set as the synchronization accuracy to a communication apparatus Y, a communication apparatus X (the encryption method selection unit 303), for example, the processing load is relatively light cryptosystem (e.g., safety index of encryption strength it may be selected 128bit of the encryption method). If the "Low sync" as the synchronization accuracy to a communication apparatus Y is set, the communication apparatus X (the encryption method selection unit 303), for example, relatively high cryptography processing load (for example, the safety index of the encryption strength the encryption method) may be selected by the 192bit. If "asynchronous" is set as the synchronization accuracy to a communication apparatus Y, a communication apparatus X (the encryption method selection unit 303), for example, higher cryptography processing load (for example, the safety index of the encryption strength is 256bit encryption method) may be selected.
[0124]
 The communication apparatus X, in response to the synchronization accuracy, the interval of changing the encryption method used for encryption communication (update interval) may be adjusted between a communication device Y. If "high synchronization" is set as the synchronization accuracy to a communication apparatus Y, a communication apparatus X (the encryption method selection unit 303), for example, relatively short interval as the update interval of (e.g., in the time "milliseconds" it may be set the order of the "second" unit) from. If the "Low sync" is set as the synchronization accuracy to a communication apparatus Y, a communication apparatus X (the encryption method selection unit 303), for example, according relatively long intervals as the update interval (e.g., "Time (hour)" units of the order) may be set. If "asynchronous" is set as the synchronization accuracy to a communication apparatus Y, a communication apparatus X (the encryption method selection unit 303), for example, it may be set longer interval as the update interval of, not to change the encryption method it may be set as. Specific update interval, e.g., response time and the synchronization process, the trial and the like in the design and operation stages, can be appropriately selected. Incidentally, if the clock information clock generator 302 generates represents a counter value, update interval of may be represented by using the counter value. If the clock information clock generator 302 generates represents time, update interval of may be represented using a time (or time).
[0125]
 Communication device X (encryption method selection unit 303), information indicating an encryption scheme and update interval selected may be held in association with the communication apparatus Y, the information to the key generation unit 304 and the encryption processing unit 305 it may be provided. The communication apparatus X (the encryption method selection unit 303) calculates the timing of updating the next encryption key based on the update interval may be held as a set value.
[0126]
 Communication device X (encryption method selection unit 303), the encryption method selected in step S1102, may be performed a process of agreement between the communication device Y (step S1103). Communication device X can be, for example, by transmitting data including the update interval of the encryption method and encryption method selected in the communication apparatus Y, with the communication device Y, may be agreed encryption scheme and its update interval . For example, the communication apparatus Y is, by the same communication device X method, if available encryption scheme and its update interval, the communication device X may without executing step S1103. In this case, the communication device Y can be, for example, when executing the synchronization process, the difference of clock information between the communication device X, the information representing the configuration of the communication apparatus X, the synchronization accuracy of the communication device X it may be determined. The communication device Y, according in accordance with the result of the determination may be appropriately selected encryption scheme and its update interval.
[0127]
 Communication device X (encryption processing unit 305), using an encryption method selected in step S1102, executes the cryptographic communication with the communication device Y. Specifically, for example, the key generation unit 304 generates an encryption key corresponding to the encryption method selected at step S1102. Encryption processing unit 305, using the encryption key generated by the key generation unit 304, executes the selected encryption processing in accordance with the encryption method (encryption and decryption) in step S1102.
[0128]
 (Encryption key updating)
 below, a communication device X will be described the process of updating the encryption scheme. Flowchart illustrated in FIG. 12, as an example of the update of the encryption scheme, it represents the process of updating the encryption key constituting the encryption method.
[0129]
 In the present embodiment, before executing the processing illustrated in FIG. 12, the update timing of the encryption method may be initialized. Timing of initialization of, for example, may be a timing at which the communication apparatus X has been started may be a timing when the synchronization processing is performed between the communication apparatus X and the communication device Y, and communication device X and the communication device Y cryptography between or at a timing selected.
[0130]
 Communication device X (encryption method selection unit 303) checks the clock information clock generator 302 is generated (step S1201).
[0131]
 Communication device X (encryption method selection unit 303), the clock information confirmed are in step S1201, based on the update interval of the encryption method that holds, determines whether the key change timing has arrived (step S1202).
[0132]
 For example, if the clock information indicates the counter value, the communication device X determines the counter value included in the clock information, by comparing the counter value indicated by the update interval, whether key change timing has arrived it may be. For example, when the clock information indicating the time information, the communication apparatus X, whether the time on the clock information, by comparing the time indicated by the update interval (or time), the key change timing has arrived or it may be determined.
[0133]
 If key change timing has arrived (YES in step S1202), the communication apparatus X (the key generation unit 304) generates the encryption key (step S1203). For example, the encryption method selection unit 303 notifies the arrival of the key change timing to the key generation unit 304, the key generating unit 304 may generate an encryption key. And clock information the device itself (the communication device X) is generated, when the clock information of the communication apparatus Y is synchronized, it is possible to generate an encryption key common to the communication apparatus X and the communication device Y. Key generating unit 304, the generated new encryption key may be provided to the encryption processing unit 305.
[0134]
 If key change timing has not arrived (NO in step S1202), the key generation unit 304 continues the process from step S1201.
[0135]
 Key generating unit 304 updates the key change timing (step S1204). The key generation unit 104, for example, the set value representing a timing of changing the encryption key, may be set for the next timing of changing the encryption key.
[0136]
 Key generating unit 304, when continuing the process of updating an encryption key (YES in step S1205), processing continues at step S1201. If you do not continue the process of updating an encryption key (in step S1205 NO), the key generation unit 304 may end the process.
[0137]
 The process described above, the key generation unit 304 can change the encryption key at the right time (updated).
[0138]
 As described above, a communication device X, and a communication device Y is, when such as changing the encryption method when executing the synchronization processing when (for example, a clock information clock information updates the encryption key at the timing synchronized ), the communication apparatus X and the communication device Y can generate an encryption key to be shared. A communication device X, if there is a difference in the clock information of the communication device Y, the communication apparatus X, the process of delivering the generated encryption key to the communication device Y may be executed.
[0139]
 Incidentally, the same processing as described above, not only the encryption key, it is also possible to update the cryptographic algorithm.
[0140]
 As a variation of the processes described above, the communication device X may perform processing as illustrated in FIG. 13. In the processing illustrated in FIG. 13, the processing illustrated in FIG. 12, further step S1301 optionally is performed. Other processing illustrated in FIG. 13 may be the same as that shown in FIG. 12.
[0141]
 In step S1301, communication device X may perform a synchronization process with the communication device Y. The communication apparatus X (equipment status management section 301) is specifically, for example, if the synchronization accuracy (502 in FIG. 5) between the communication device Y is "low sync" is set, the communication device Y it may execute a process to synchronize the clock information between. Process to synchronize the clock information between the communication device Y may be same as step S901 to step S905 in FIG. 9, for example.
[0142]
 If the synchronization accuracy between the communication apparatus X and the communication apparatus Y is low, the timing of changing the encryption key, but the difference in the clock information may be occurring, by performing the step S1301, a difference of it is possible to eliminate. As explained above, if the synchronization accuracy between the communication apparatus X and the communication apparatus Y is "low sync" is set, the update interval of the encryption method, a relatively long interval is set. This, also the synchronization process in step S1301, from being performed at relatively long intervals, the possibility of synchronous processing by the processing load (or traffic) is increased excessively considered low.
[0143]
 Communication device 300 according to this embodiment configured as described above, while maintaining the security of the cryptographic communication, it is possible to reduce the influence of the load of encryption processing. The reason is that the communication device 300, in accordance with the frequently whether it can change the encryption scheme with another communication apparatus (i.e., in response to the synchronization accuracy), the cryptographic load different required for the cryptographic processing This is because proper can choose the method.
[0144]
 More specifically, the communication device 300 (if the synchronization accuracy is high) when an encryption scheme is frequently changeable with another communication apparatus, together with the processing load to select a relatively low cryptosystem, it can be changed at relatively short intervals cryptosystem. Accordingly, the communication device 300 can reduce the load of encryption processing. Moreover, since the encryption method is frequently changed, the amount of ciphertext generated using a single encryption method (size) is reduced. Thus, considered information used for decryption is reduced. Moreover, even if in a case where one of the encryption method is compromised involves since the amount of ciphertext encrypted by using an encryption scheme that compromise is relatively small, the compromise of encryption method according affect the range is limited.
[0145]
 The communication device 300 (if the synchronization accuracy lower) when it is difficult to frequently change the encryption scheme with another communication device, relatively the processing load is high, decryption is difficult cryptography to select. Accordingly, the communication device 300 is capable of maintaining the security of the encrypted communication.
[0146]
 Modification of Second Embodiment]
 Hereinafter, a description will be given of a variation of the second embodiment. Hardware and software configuration of the communication device 300 in this modified example, may be the same as the second embodiment.
[0147]
 Communication device 300 in this modified example, holds information representing a difference of the clock information with another communication device 400, in that it generates an encryption key that reflects the difference, differs from the second embodiment to. Hereinafter, the difference will be described according.
[0148]
 In the present modification, equipment status management unit 301, for example, in association with a table as illustrated in FIG. 14, with another communication device 400, and information representing the difference of the clock information for the communication device 300 holding (Remember. In the table illustrated in FIG. 14, the communication device (1401 in FIG. 14) shows a possible identification information identifying the other communication device 400. According identification information may be information similar to the 501 of FIG. The adjustment information (1402 in FIG. 14) illustrates a communication device 300, a difference of clock information with another communication device 400.
[0149]
 In the present modification, equipment status management unit 301, for example, when receiving the response data to a clock adjusting data from another communication device 400 (described above step S904 that), adjustment information to illustrate the extracted difference in FIG. 14 ( it may be set to 1402) of FIG. 14. In this case, equipment status management unit 301, a clock information itself which is generated in the clock generator 302 may without adjustment.
[0150]
 In this modification, the key generating unit 304, for example, by using the adjustment information associated with another communication device 400 (1402 in FIG. 14), and a clock information the device itself (the communication device 300) is produced, adjusted to calculate the clock information. More specifically, the key generating unit 304, the clock information itself device (communication device 300) is generated by adding the adjustment information (or subtraction), and calculate the adjusted clock information good. Key generating unit 304 generates an encryption key by using the clock information that has been adjusted according, and a device information.
[0151]
 For this modification, the difference between the clock information between the communication device 300 is easily (often) performed if the synchronization processing, the communication device is accurately reflected in the adjustment information equipment status management unit 301 holds obtain. Further, generation if the high precision clock information in each of the communication device, once the error of the extracted adjustment information is considered small. Thus, in this modification, by using the clock information the device itself (the communication device 300) generates the clock information of the other communication device 400 that is estimated using the adjustment information, the cryptographic key generation, update and the like it is possible to run.
[0152]
 According to this modification configured as described above, by holding the individual adjustment information for each other communication device 400, without adjusting the clock information itself when the device itself generates, for each communication device 300 it is possible to perform the production or the like of the encryption key using a separate clock information.
[0153]
 Although the present disclosure has been described as an example applied to the exemplary embodiments described above. In the above embodiments explained the example of applying to the communication device technology related to the present disclosure (100, 300). For example, by operating the communication device (100, 300) in each of the above embodiments, it is possible to realize a communication method related to the present disclosure. How to implement a communication method according to the present disclosure is not limited to the above. Communication method according to the present disclosure, for example, capable of executing the same operation as the communication device (100, 300), suitable device (an information processing apparatus such as a computer, or a dedicated embedded device, etc.) may be implemented by possible it is. The present disclosure may be implemented as a system including a plurality of communication devices (100, 130).
[0154]
 Further, the technical scope of the present disclosure, the ranges set forth the embodiments and modifications described above are not limited. Those skilled in the art it is clear that it is possible to add various modifications or improvements to the embodiments according. In such a case, even a new embodiment changes or improvements according, be included in the technical scope of the present disclosure. Further, the embodiments and modifications described above, or also an embodiment combining new embodiments with changes or improvements according, be included in the technical scope of the present disclosure.
[0155]
 The present invention has been described with the above embodiments as exemplary examples. However, the present invention is the above-described embodiments are not limited. That is, the present invention is within the scope of the present invention can be applied to various aspects by those skilled in the art can understand.
[0156]
 A part or all of the above embodiments, can be described as the following notes, not limited to the following.
(Supplementary Note 1)
 own device and depending on the other synchronization accuracy representing abundance of alterable timing the encryption scheme used in the cryptographic communication with the communication device, the encryption processing load related to the encryption processing in the encryption communication is different an encryption method selection means for selecting a mode,
 and using the encryption method selected, the cryptographic processing means for performing at least one of the encryption process and the decryption process regarding the communication data between the other communication apparatus, communication device comprising a.
(Supplementary Note 2)
 The encryption method selection means,
  the higher the encryption scheme can change the timing is large, the judges that synchronization has high accuracy,
  among the processing load related to the encryption scheme is different from the plurality of encryption methods, the synchronization the higher the accuracy, the communication device according to note 1, the processing load related to the encryption processing to select the lower the encryption scheme.
(Supplementary Note 3)
 The encryption method selection means,
  the higher the encryption scheme can change the timing is small, the synchronization accuracy is determined to be lower,
  among the processing load related to the encryption scheme is different from the plurality of encryption methods, the synchronization the lower the accuracy, the communication apparatus according to Supplementary note 1 or 2 processing load related to the encryption processing to select the higher the encryption scheme.
(Supplementary Note 4)
 The encryption method selection means, in response to the synchronization accuracy, the communication device according to any one of Appendixes 2 or Appendix 3 to adjust the update interval to update the encryption scheme.
(Supplementary Note 5)
 The encryption method selection means, the synchronous higher accuracy, the communication device according to Note 4 for updating the encryption scheme at shorter intervals.
(Supplementary Note 6)
 The encryption method selection means, the lower the synchronization accuracy, the communication apparatus according to note 4, or note 5 to update the encryption method at longer intervals.
(Supplementary Note 7)
 with a periodic clock signal, and a clock generating means for generating clock information indicating the timing,
 receiving the own device, information used to synchronize the clock information with the other communication devices by executes processing for synchronizing the clock information, and determines equipment status management means the synchronization accuracy depending on the synchronization state of the clock information,
 the encryption key used for the encryption processing in response to the clock information Additionally and a key generating unit for generating
 the encryption method selection means, in response to the synchronization accuracy with the clock information determined by the equipment status management means, selects the encryption method,
 the key generation means the communication apparatus according to any one of appendices 2 to Supplementary note 6 to generate the encryption key corresponding to the encryption method which the selected.
(Supplementary Note 8)
 The device state management means, wherein said magnitude of the difference related to the clock information with another communication device, to at least one of information indicating the accuracy of the clock information which the other communication device generates based on, the communication device according to note 7 determines the synchronization accuracy with the clock information.
(Supplementary Note 9)
 The device state management means for each of the other communication apparatus, the own device, holds adjustment information representing a difference between the clock information between the said other communication device,
 the key generation means the clock information that has been adjusted is calculated from the clock information generated in the adjustment information and the own device, and the encryption method selected by the encryption method selection means, Appendix 7 to generate the encryption key in response to, or communication apparatus according to note 8.
(Supplementary Note 10)
 to said cryptography, encryption algorithm used in the encryption communication, the encryption key, and includes at least one or more of the cipher modes
communications device according to any one of Supplementary Notes 1 to Appendix 9.
(Supplementary Note 11)
 own device and depending on the other synchronization accuracy representing a multitude of possible change timing the encryption scheme used for the cryptographic communication with the communication device, the processing load related to the encryption processing in the encryption communication is different select an encryption method,
 a communication method using the encryption method selected, to perform at least one of the encryption process and the decryption process regarding the communication data between the other communication apparatus.
(Supplementary Note 12)
 to a computer constituting the communication device,
 in accordance with the own device and another synchronization accuracy representing a multitude of possible change timing the encryption scheme used for the cryptographic communication with the communication device, in the cryptographic communication a process of processing load related to the encryption processing to select a different said encryption method,
 performed using the encryption method selected, at least one of the encryption process and the decryption process regarding the communication data between the other communication apparatus recording medium on which a communication program is recorded to a process of the execution.
[0157]
 This application claims priority based on Japanese Patent Application No. 2016-195774 filed on October 3, 2016, the entire disclosure of which is incorporated herein.
DESCRIPTION OF SYMBOLS
[0158]
 100 communication device
 101 encryption method selection unit
 102 encryption processing unit
 300 communication device
 301 device status management unit
 302 clock generator
 303 encryption method selection unit
 304 key generation unit
 305 encryption unit
 306 communication unit
 307 the data transfer unit
 601 processor
 602 memory
 603 clock generator
 604 communication interface
 605 storage
 606 output interface
 607 input device
 608 drive
 609 storage medium
 701 cryptographic processing device

The scope of the claims
[Requested item 1]
 Depending on the synchronization accuracy representing a multitude of encryption method capable of changing the timing for use in encrypted communication between the own apparatus and the other communication device, selects the cryptosystem processing load related to the encryption processing in the encryption communication is different an encryption method selection means for,
 using the encryption method selected, communication and a cryptographic processing means for performing at least one of encryption processing and decryption processing concerning communication data between the other communication apparatus apparatus.
[Requested item 2]
 The encryption method selection means,
  the more changeable timing the encryption method with a own device and another communication device, said determined synchronized with high accuracy,
  the processing load related to the encryption method is different among the encryption scheme, the higher the synchronization accuracy, the communication apparatus according to claim 1, the processing load related to the encryption processing to select the lower the encryption scheme.
[Requested item 3]
 The encryption method selection means,
  the less changeable timing the encryption method with a own device and another communication device, the synchronization accuracy is determined to be lower,
  the processing load related to the encryption method is different among the encryption scheme, the lower the synchronization accuracy, the communication apparatus according to claim 1 or claim 2 processing load related to the encryption processing to select the higher the encryption scheme.
[Requested item 4]
 The encryption method selection means, said synchronization in accordance with the accuracy, the communication apparatus according to claim 2 or claim 3 to adjust the update interval to update the encryption scheme.
[Requested item 5]
 The encryption method selection means, the synchronous higher accuracy, the communication apparatus according to claim 4 for updating the encryption scheme at shorter intervals.
[Requested item 6]
 The encryption method selection means, the more the synchronization is less accurate, the communication apparatus according to claim 4 or claim 5 for updating the encryption method at longer intervals.
[Requested item 7]
 Using a periodic clock signal, and a clock generating means for generating clock information indicating the timing,
 the own device, by sending and receiving information used to synchronize the clock information with the other communication apparatus, the running process to synchronize the clock information, and determines equipment status management means the synchronization accuracy depending on the synchronization state of the clock information,
 the key to generate the encryption key used for the encryption processing in response to the clock information further comprising a generation unit, a
 the encryption method selection means, in response to the synchronization accuracy with the clock information determined by the equipment status management means, selects the encryption method,
 the key generation unit is the selected communication apparatus according to any one of claims 2 to 6 to generate the encryption key corresponding to the encryption method.
[Requested item 8]
 The device state management means includes: the magnitude of the difference related to the clock information between the other communication apparatus, based on at least one of said information representative of the accuracy of the clock information which the other communication apparatus is generated, the the communication apparatus according to claim 7 determines the synchronization accuracy to a clock information.
[Requested item 9]
 The device state management means for each of the other communication device holds the own device, the adjustment information representing the difference between the clock information between the said other communication device,
 said key generating means, said adjustment information and the adjusted clock information calculated from the clock information generated in its own device, and the encryption method selected by the encryption method selection means, according to claim 7 or claim 8 generates the encryption key in accordance with the the communication apparatus according to.
[Requested item 10]
 The said encryption method, an encryption algorithm used in the encryption communication, the encryption key, and includes at least one or more of the cipher modes
communication device according to any one of claims 1 to 9.
[Requested item 11]
 Depending on the synchronization accuracy representing a multitude of encryption method capable of changing the timing for use in encrypted communication between the own apparatus and the other communication device, selects the cryptosystem processing load related to the encryption processing in the encryption communication is different and,
 a communication method using the encryption method selected, to perform at least one of the encryption process and the decryption process regarding the communication data between the other communication apparatus.
[Requested item 12]
 A computer constituting the communication device,
 in accordance with the own device and another synchronization accuracy representing a multitude of possible change timing the encryption scheme used for the cryptographic communication with the communication device, processing related to encryption processing in the encryption communication the processing load to select different said encryption system,
 a process of using the encryption method selected, to perform at least one of the encryption process and the decryption process regarding the communication data between the other communication apparatus, recording medium on which a communication program is recorded for execution.

Documents

Application Documents

# Name Date
1 201917009624.pdf 2019-03-12
2 201917009624-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [12-03-2019(online)].pdf 2019-03-12
3 201917009624-STATEMENT OF UNDERTAKING (FORM 3) [12-03-2019(online)].pdf 2019-03-12
4 201917009624-REQUEST FOR EXAMINATION (FORM-18) [12-03-2019(online)].pdf 2019-03-12
5 201917009624-PRIORITY DOCUMENTS [12-03-2019(online)].pdf 2019-03-12
6 201917009624-POWER OF AUTHORITY [12-03-2019(online)].pdf 2019-03-12
7 201917009624-FORM 18 [12-03-2019(online)].pdf 2019-03-12
8 201917009624-FORM 1 [12-03-2019(online)].pdf 2019-03-12
9 201917009624-DRAWINGS [12-03-2019(online)].pdf 2019-03-12
10 201917009624-DECLARATION OF INVENTORSHIP (FORM 5) [12-03-2019(online)].pdf 2019-03-12
11 201917009624-COMPLETE SPECIFICATION [12-03-2019(online)].pdf 2019-03-12
12 201917009624-CLAIMS UNDER RULE 1 (PROVISIO) OF RULE 20 [12-03-2019(online)].pdf 2019-03-12
13 201917009624-RELEVANT DOCUMENTS [18-03-2019(online)].pdf 2019-03-18
14 201917009624-MARKED COPIES OF AMENDEMENTS [18-03-2019(online)].pdf 2019-03-18
15 201917009624-FORM 13 [18-03-2019(online)].pdf 2019-03-18
16 201917009624-AMMENDED DOCUMENTS [18-03-2019(online)].pdf 2019-03-18
17 201917009624-Power of Attorney-150319.pdf 2019-03-19
18 201917009624-OTHERS-150319.pdf 2019-03-19
19 201917009624-OTHERS-150319-.pdf 2019-03-19
20 201917009624-Correspondence-150319.pdf 2019-03-19
21 abstract.jpg 2019-04-13
22 201917009624-FORM 3 [14-05-2019(online)].pdf 2019-05-14
23 201917009624-Proof of Right (MANDATORY) [10-06-2019(online)].pdf 2019-06-10
24 201917009624-OTHERS-130619.pdf 2019-06-27
25 201917009624-Correspondence-130619.pdf 2019-06-27
26 201917009624-FORM 3 [24-11-2020(online)].pdf 2020-11-24
27 201917009624-Information under section 8(2) [04-12-2020(online)].pdf 2020-12-04
28 201917009624-FORM-26 [04-12-2020(online)].pdf 2020-12-04
29 201917009624-FORM 3 [04-12-2020(online)].pdf 2020-12-04
30 201917009624-OTHERS [14-12-2020(online)].pdf 2020-12-14
31 201917009624-FER_SER_REPLY [14-12-2020(online)].pdf 2020-12-14
32 201917009624-DRAWING [14-12-2020(online)].pdf 2020-12-14
33 201917009624-COMPLETE SPECIFICATION [14-12-2020(online)].pdf 2020-12-14
34 201917009624-CLAIMS [14-12-2020(online)].pdf 2020-12-14
35 201917009624-ABSTRACT [14-12-2020(online)].pdf 2020-12-14
36 201917009624-Power of Attorney-010421.pdf 2021-10-18
37 201917009624-FER.pdf 2021-10-18
38 201917009624-Correspondence-010421.pdf 2021-10-18
39 201917009624-PatentCertificate17-01-2024.pdf 2024-01-17
40 201917009624-IntimationOfGrant17-01-2024.pdf 2024-01-17

Search Strategy

1 searchstrategyE_12-10-2020.pdf

ERegister / Renewals

3rd: 09 Apr 2024

From 02/10/2019 - To 02/10/2020

4th: 09 Apr 2024

From 02/10/2020 - To 02/10/2021

5th: 09 Apr 2024

From 02/10/2021 - To 02/10/2022

6th: 09 Apr 2024

From 02/10/2022 - To 02/10/2023

7th: 09 Apr 2024

From 02/10/2023 - To 02/10/2024

8th: 09 Apr 2024

From 02/10/2024 - To 02/10/2025

9th: 24 Sep 2025

From 02/10/2025 - To 02/10/2026