WO2010067650A1 - 通信装置、サーバ、通信方法及びプログラム - Google Patents

通信装置、サーバ、通信方法及びプログラム Download PDF

Info

Publication number
WO2010067650A1
WO2010067650A1 PCT/JP2009/065664 JP2009065664W WO2010067650A1 WO 2010067650 A1 WO2010067650 A1 WO 2010067650A1 JP 2009065664 W JP2009065664 W JP 2009065664W WO 2010067650 A1 WO2010067650 A1 WO 2010067650A1
Authority
WO
WIPO (PCT)
Prior art keywords
piece
information
node
communication device
conversion
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2009/065664
Other languages
English (en)
French (fr)
Inventor
建司 大熊
達之 松下
晋爾 山中
博文 村谷
嘉一 花谷
泰知 磯谷
智子 米村
憲一郎 古田
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Toshiba Corp
Original Assignee
Toshiba Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Toshiba Corp filed Critical Toshiba Corp
Publication of WO2010067650A1 publication Critical patent/WO2010067650A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/083Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/60Digital content management, e.g. content distribution

Definitions

  • the present invention relates to a communication apparatus, a server, a communication method, and a program.
  • a delivery method for delivering data using P2P does not require a data delivery server having a huge storage and a large communication bandwidth, and is a delivery method with a large cost advantage. is there.
  • P2P data delivery has a great merit, but on the other hand, there is concern about security from the viewpoint of data security such as copyright protection.
  • the following is assumed as a general premise when considering data security such as copyright protection. It means that not all terminal equipment or nodes are hacked. If this premise is denied, the terminal device can not hold the data to be kept confidential or can not perform the process to be kept confidential, and most security techniques and devices for securing security can not be established.
  • P2P distribution there is a content distribution system in which encrypted data is distributed, and a node receiving the distribution of data acquires a decryption key for decrypting the data (referred to as distribution data).
  • distribution data A major problem in data security in P2P delivery of such a system is that the combination of the delivery data and the decryption key for decrypting the delivery data is single or small in number. In this case, it is assumed that a node is hacked and the decryption key is revealed. In this case, this decryption key can be used to decrypt most of the distribution data.
  • One way to solve this problem is to personalize the distribution data for each node.
  • the method of Marking shown in Patent Document 1 is known.
  • the distribution data is divided into pieces, and encryption is performed using a key matrix to generate encrypted pieces.
  • a piece group of encrypted pieces encrypted in a matrix form is generated.
  • Such pieces are distributed via the P2P network.
  • One node connected to the P2P network will obtain one encrypted piece from among a plurality of encrypted pieces encrypted in a matrix for each piece.
  • it is expected that the combination of encrypted pieces in which each piece constituting the delivery data is encrypted is statistically unique for each node.
  • the present invention has been made in view of the above, and it is possible to make combinations of pieces distributed in the content distribution system unique for each communication device, and to improve the degree of freedom in system construction. It is an object of the present invention to provide a communication device, a server, a communication method and a program capable of improving the efficiency of calculation in the communication device.
  • the present invention solves the problems described above, and the present invention is a communication device that transmits a piece that is a part of data, and is assigned to a first piece reversibly converted by another communication device and to the other communication device.
  • Reception means for receiving the first device identification information and the first temporary information generated by the other communication device, the first piece, the first device identification information, and the first temporary information
  • a first storage unit for storing in association, a second storage unit for storing the second device identification information allocated to the communication apparatus, and a first generation unit for generating second temporary information that may differ for each generation thereof
  • converting means for converting the first piece and outputting the second piece using the second temporary information, the second piece, the first device identification information, and the second device identification information.
  • Said first temporary information, and said second temporary information And a sending means for sending a multi-address.
  • the present invention is a communication device that receives a piece that is a part of data, and is reversibly converted by the first storage unit that stores device identification information assigned to the communication device and another communication device.
  • First receiving means for receiving the selected piece, device identification information assigned to the other communication device, and temporary information generated by the other communication device, the piece, the device identification information, and
  • a second storage unit that stores temporary information in association with each other, requests decoding information for reversely converting the piece, and associates the device identification information and the temporary information stored in association with the piece.
  • a second receiving means for receiving the decryption information from the key server in response to the request, and using the received decryption information. Characterized in that it comprises a decoding means for decoding the piece.
  • a server wherein secret information assigned to each of a plurality of other communication devices for transmitting a piece that is a part of data, and device identification information assigned to each of the communication devices.
  • a first storage unit for storing in association with each other, requesting decoding information for inversely converting the reversibly converted piece, and the device identification information of the plurality of other communication devices and the plurality of other communications
  • Receiving means for receiving from the first communication device a request including information generated by each device and being associated with temporary information that may be different for each generation, and is associated with each device identification information included in the request
  • And forming means characterized by comprising a transmitting means for transmitting the decoding information including the transformation parameters to the first communication device.
  • the combination of pieces distributed in the content delivery system can be made unique for each communication device, and the freedom in system construction can be improved, and the calculation efficiency in the communication device can be improved. Can be improved.
  • FIG. 1 is a diagram showing a configuration of a data delivery system according to a first embodiment.
  • FIG. 6 is a diagram illustrating a functional configuration of a node 50.
  • FIG. 6 is a diagram illustrating a functional configuration of a node 51.
  • FIG. 7 schematically shows information transmitted from the node 50 to the node 51A.
  • FIG. The figure which illustrates the functional composition of the key server 53. 6 is a flowchart showing the procedure of distribution processing performed by the node 50.
  • the flowchart which shows the procedure of the reception process in which the node 51 receives an encryption piece The figure which shows typically the information received by a node.
  • 5 is a flowchart showing a procedure of distribution processing performed by a node 51 other than the distribution start node. The figure which shows typically the information which a node transmits.
  • the flowchart which shows the procedure of the decoding process in which the node 51 decodes an encryption piece. The figure which shows typically the information which a node transmits.
  • the figure which shows typically the symmetrical key which a node receives. 12 is a flowchart showing a procedure of decryption information transmission processing in which the key server 53 transmits decryption information in response to a key request from the node 51.
  • FIG. 1 is a diagram showing the configuration of a data delivery system according to the present embodiment.
  • a plurality of nodes 50, 51A to 51B are connected via a P2P network NT.
  • other nodes may also be connected via the P2P network NT.
  • Each of the nodes 50 and 51A to 51B is connected to the key server 53.
  • Each of the nodes 50 and 51A to 51B holds a node ID which is device identification information uniquely assigned to each node, and a secret key as assignment information uniquely assigned to each node.
  • the node IDs assigned to the nodes 50 and 51A to 51B are ID # 0, ID # 1 and ID # 2, respectively, and the secret keys are s 0 , s 1 and s 2 respectively.
  • the node 50 is a distribution start node which is a base point of data distribution, and holds data to be distributed (referred to as distribution data).
  • the distribution data may be either plaintext or already encrypted ciphertext.
  • the delivery data may be video data protected by some digital right management (DRM) system as encryption.
  • DRM digital right management
  • the key server 53 holds a secret key assigned to each of the nodes 50 and 51A to 51B.
  • the nodes 51A to 51B are simply referred to as the node 51 when it is not necessary to distinguish them.
  • Each device includes a control device such as a central processing unit (CPU) that controls the entire device, a storage device such as a read only memory (ROM) or a random access memory (RAM) that stores various data and various programs, and various devices. It has an external storage device such as an HDD (Hard Disk Drive) or CD (Compact Disk) drive device that stores data and various programs, and a bus that connects these, resulting in a hardware configuration that uses a normal computer. ing.
  • a display device for displaying information
  • an input device such as a keyboard and a mouse for receiving user's instruction input
  • a communication I / F interface
  • FIG. 2 is a diagram illustrating the functional configuration of node 50.
  • the node 50 includes a unique information storage unit 500, a random number generation unit 501, a symmetric key generation unit 502, a piece encryption unit 503, a segmentation unit 504, a data transmission unit 505, and a transmission request reception unit 506. It has a parameter generation unit 507 and a conversion unit 508.
  • the unique information storage unit 500 is secured as a storage area in an external storage device such as the HDD of the node 50, for example.
  • Random number generation unit 501 symmetric key generation unit 502, fragmentation unit 504, piece encryption unit 503, data transmission unit 505, transmission request reception unit 506, parameter generation unit 507, and conversion unit 508
  • the entity is generated on a storage device such as a RAM when the CPU of the node 50 executes a program.
  • a storage device such as a RAM when the CPU of the node 50 executes a program.
  • distribution data is stored in advance.
  • the unique information storage unit 500 stores the node ID and the secret key assigned to the node 50.
  • the fragmentation unit 504 divides the distribution data into a plurality of pieces. Although the data size at the time of dividing
  • the transmission request receiving unit 506 receives, from another node 51, a piece request for requesting a piece divided by the fragmentation unit 504. When the transmission request receiving unit 506 receives a piece request, the random number generation unit 501 generates three random numbers, which are temporary information that may differ for each occurrence.
  • the temporary information may be a value that can be different each time it is generated by a node, and is, in addition to a random number, for example, a time stamp, a communication sequence number, a value of a node-specific counter, a Time Variant Parameter.
  • the Time Variant Parameter is described, for example, in the document ISO / IEC 9798-1. Let r, r 0 and r ' 0 be the random numbers generated here. Among them, the random numbers r and r 0 are used to change the symmetric key used for piece encryption every time as described later, and the random number r ' 0 changes the conversion parameters used for conversion every time Used for
  • the symmetric key generation unit 502 uses the two random numbers r and r 0 of the random numbers generated by the random number generation unit 501 and the secret key s 0 stored in the unique information storage unit 500 to obtain two symmetric keys according to the function F Generate k, k 0 .
  • F F (s 0 , r)
  • k 0 F (s 0 , r 0 )
  • This function F is a one-way function, and even if it knows the secret key or random number that is the input value, it can not estimate the symmetric key that is the output value from them.
  • the symmetric key generation unit 502 further encrypts the generated symmetric key with an encryption key unknown to the user and stores the external storage such as an HDD or the like. It is desirable to store it on the device and keep it secret so that the actual value of the symmetric key is not known to the user. In addition, it is desirable to conceal the algorithm of conversion by the function F so that the user can not specify it.
  • the parameter generation unit 507 generates the conversion parameter k ′ 0 by the function G using the random number r ′ 0 not used for generating the symmetric key among the random numbers generated by the random number generation unit 501 and the secret key s 0 .
  • This is expressed by the following equation.
  • k ' 0 G (s 0 , r' 0 )
  • This function G is a one-way function, and even if it knows the conversion parameter which is the output value and the random number which is the input value, it can not estimate the secret key which is the input value from them.
  • the parameter generation unit 507 encrypts the generated conversion parameter with an encryption key that is not known to the user, and stores it in an external storage device such as an HDD. It is desirable to store and conceal the actual value of the conversion parameter so that the user can not know it.
  • the piece encryption unit 503 encrypts a piece using one symmetric key k of the symmetric keys generated by the symmetric key generation unit 502, and outputs an encrypted piece.
  • the encrypted piece in which the piece P is encrypted with the symmetric key k is denoted as E (k) P.
  • the piece encryption unit 503 further encrypts the one obtained by converting the encrypted piece E (k) P by the conversion unit 508 described below using the target key k_0 and outputs a new encrypted piece. .
  • the converted encrypted piece is expressed as L (k ′ 0 ) E (k) P
  • the encrypted piece obtained by encrypting this using the target key k 0 is E (k 0 ) L (k ′ 0 ) E (k) It is written as P.
  • the conversion unit 508 converts the encrypted piece E (k) P output from the piece encryption unit 503 by the function L using the conversion parameter k ′ 0 generated by the parameter generation unit 507.
  • the converted encrypted piece is denoted as L (k ′ 0 ) E (k) P.
  • the result of conversion using conversion parameters (aggregation parameters) in which each conversion parameter is integrated into one value is identical to the result of conversion by overlapping using each conversion parameter.
  • it is a reversible transformation that can be inverse transformed using aggregation parameters.
  • Such transformation includes, for example, linear transformation, but is not limited thereto.
  • the data transmission unit 505 transmits the node ID stored in the unique information storage unit 500 and the three random numbers r, r 0 , r ′ generated by the random number generation unit 501 to the other nodes 51 that have transmitted the piece request. 0 and a new encrypted piece E (k 0 ) L (k ′ 0 ) E (k) P output from the piece encryption unit 503 are transmitted.
  • the data transmission unit 505 transmits a piece request separately from the symmetric keys k 0 used for encryption of the converted encrypted piece among the symmetric keys generated by the symmetric key generation unit 502. It transmits to other nodes 51. It is desirable that the data transmission unit 505 encrypts and transmits the symmetric key using a protocol such as SSL (Secure Socket Layer).
  • FIG. 3 is a diagram illustrating a functional configuration of the node 51.
  • the node 51 includes a unique information storage unit 510, a random number generation unit 511, a symmetric key generation unit 512, a piece encryption unit 513, a data reception unit 514, a data transmission unit 515, and a transmission request reception unit 516.
  • the unique information storage unit 510 and the data storage unit 517 are secured as storage areas in an external storage device such as an HDD of the node 51, for example.
  • the substance of the conversion unit 521, the inverse conversion unit 522, and the parameter generation unit 523 is generated on a storage device such as a RAM when the CPU of the node 51 executes a program.
  • the unique information storage unit 510 stores the node ID and the secret key assigned to the node 51.
  • the configuration of the transmission request receiving unit 516 is the same as the configuration of the transmission request receiving unit 506 of the node 50 described above.
  • the transmission request transmission unit 518 transmits a piece request requesting a piece to the node 50 or another node 51.
  • the data receiving unit 514 transmits, from the node 50 or other node 51 which is the other party to which the transmission request transmission unit 518 has transmitted the piece request, the encrypted piece which is a piece converted and encrypted, and the transmission of the encrypted piece.
  • a node ID sequence including each node ID assigned to at least one other node 50 or 51 that has intervened, and a random number sequence including random numbers generated by the other nodes 50 and 51 are received.
  • the data receiving unit 514 separately receives the symmetric key generated by the node 50 or another node 51 which is the other party to which the transmission request transmission unit 518 has transmitted the piece request.
  • the data storage unit 517 associates and stores the node ID sequence, the random number sequence, the encrypted piece, and the symmetric key received by the data reception unit 514. It is desirable to conceal the received symmetric key by further encrypting it with an encryption key unknown to the user as described above and storing it in an external storage device such as an HDD.
  • the random number generation unit 511 generates two random numbers, which are temporary information. One random number is used to change the symmetric key used to encrypt the encrypted piece each time, and the other random number is used to change the conversion parameters used to perform the conversion each time.
  • the symmetric key generation unit 512 generates a symmetric key by the above-described function F using one random number of the random numbers generated by the random number generation unit 511 and the secret key stored in the unique information storage unit 510. Also in the node 51, the symmetric key generation unit 512 desirably conceals the generated symmetric key as described above.
  • the parameter generation unit 523 generates a conversion parameter by the above-described function G using a random number not used for generating a symmetric key among the random numbers generated by the random number generation unit 511 and a secret key. Also in the node 51, the parameter generation unit 523 desirably conceals the generated conversion parameter as described above.
  • the piece encryption unit 513 decrypts the encrypted piece using the symmetric key stored in the data storage unit 517 in association with the encrypted piece.
  • the encrypted piece decrypted here is referred to as a half decrypted piece for convenience of explanation.
  • the piece encryption unit 513 encrypts the half-decrypted piece converted by the conversion unit 521 described below using the symmetric key generated by the symmetric key generation unit 512, and outputs a new encrypted piece.
  • the conversion unit 521 converts the half-decrypted piece obtained by the piece encryption unit 513 using the conversion parameter generated by the parameter generation unit 523 using the function L described above.
  • the data transmission unit 515 transmits, to the other node 51 that has transmitted the piece request, the node ID stored in the unique information storage unit 510, the two random numbers generated by the random number generation unit 511, and the piece encryption unit 513. Send the new encrypted piece output by Also, the data transmission unit 515 separately transmits the symmetric key generated by the symmetric key generation unit 512 to the other node 51 that has transmitted the piece request.
  • the node ID sequence, the random number sequence, the encrypted piece, and the symmetric key transmitted from the nodes 50 and 51 will be specifically described.
  • one node ID is transmitted together with one encrypted piece from the node 50, for convenience of description, these may be described as a node string here.
  • the case where the encrypted piece is transmitted from the node 50 to the node 51A and further from the node 51A to the node 51B as a distribution path of the encrypted piece and the key request is transmitted from the node 51B to the key server 53 will be described.
  • the node 50 in response to a piece request from the node 51A for a certain piece P, the node 50 generates symmetric keys k and k 0 respectively using the random numbers r and r 0 and the secret key s 0 as described above, The piece P is encrypted using the symmetric key k to output an encrypted piece E (k) P.
  • the node 50 generates a 0 'conversion parameter k by using a 0 and a secret key s 0' random number r, the conversion parameter k '0 converts encrypted piece E (k) P was used to transform Encrypt the encrypted piece L (k ' 0 ) E (k) P using the symmetric key k 0 and output a new encrypted piece E (k 0 ) L (k' 0 ) E (k) P .
  • FIG. 4 is a diagram schematically showing information transmitted from the node 50 to the node 51A.
  • the node 51A associates the node ID ID # 0, the random number r, r 0 r ′ 0 , the encrypted piece E (k 0 ) L (k ′ 0 ) E (k) P, and the symmetric key k_ 0 with each other to generate data. It will be stored in the storage unit 517.
  • the data storage unit 517 stores each node ID sequence and each random number sequence while holding the correspondence between the node ID and the random number generated by the node to which the node ID is assigned.
  • the node 51A transmits the encrypted piece for the piece P in response to the piece request from the node 51B, the random number r 1 , r ′ 1 is generated, and the random number r 1 and the secret key s 1 are used. generating a symmetric key k 1, to generate a 'conversion parameter k by using a 1 and a secret key s_ 1' random number r. Also, the node 51A uses the symmetric key k 0 stored in the data storage unit 517 in association with the encrypted piece E (k 0 ) L (k ′ 0 ) E (k) P to store the encrypted piece. Decrypt.
  • a half-decoded piece L (k ′ 0 ) E (k) P is obtained.
  • the node 51A is, by using the transformation parameters K'_ 1, to convert the half-decoded piece L (k '0) E ( k) P.
  • a converted half-decoded piece L (k ′ 1 ) L (k ′ 0 ) E (k) P is obtained.
  • the node 51A encrypts the converted half-decrypted piece L (k ′ 1 ) L (k ′ 0 ) E (k) P using the symmetric key k 1 generated by itself and a new encrypted piece E (k 1 ) L (k ′ 1 ) L (k ′ 0 ) E (k) P is output.
  • the node 51A is allocated to the node 51B, in addition to the node ID ID # 0 stored in the data storage unit 517 and allocated to the node 50, stored in the unique information storage unit 510.
  • FIG. 5 is a diagram schematically showing information transmitted from the node 51A to the node 51B.
  • the node 51 B includes the node ID sequence ID # 0, ID # 1, the random number sequence r, r 0 , r ′ 0 , r 1 , r ′ 1 , and the encrypted piece E (k 1 ) L (k ′ 1 ) L. (k ′ 0 ) E (k) P and the symmetric key k_1 are associated with each other and stored in the data storage unit 517.
  • the conversion is repeatedly performed by each node 51 which mediates the transmission of the encrypted piece, and the encrypted piece Is finally encrypted by the node 51 that has transmitted the last, and the encrypted piece is stored in the node 51 that has received the encrypted piece.
  • the key request transmission unit 519 transmits, to the key server 53, a key request for requesting decryption information for inversely converting and decrypting the encrypted piece stored in the data storage unit 517.
  • the key request transmission unit 519 includes the node ID sequence and the random number sequence stored in the data storage unit 517 corresponding to the encrypted piece in the key request and transmits the key request to the key server 53.
  • the node 51B transmits a key request for the encrypted piece E (k 1 ) L (k ′ 1 ) L (k ′ 0 ) E (k) P shown in FIG.
  • the key request transmission unit 519 transmits a key request including the node ID sequence ID # 0, ID # 1 and the random number sequence r, r 0 , r ′ 0 , r 1 , r ′ 1 .
  • FIG. 6 schematically shows information transmitted from the node 51B to the key server 53.
  • the node 51 is a distribution start node, as a distribution start node of the encrypted piece.
  • the node ID sequence including the node ID of each of the nodes 50 and 51 that mediates the transmission of the encrypted piece and the random number sequence including the random number generated by each of the nodes 50 and 51 are transmitted to the key server 53. Note that, at the time of such transmission, the key request transmission unit 519 transmits in a state in which the correspondence between each node ID and the random number outputted by the node to which each node ID is assigned is held.
  • the piece decryption unit 520 receives the decryption information including the two symmetric keys and the conversion parameter transmitted from the key server 53 in response to the key request transmitted by the key request transmission unit 519.
  • the two symmetric keys are the symmetric key that was first used to encrypt a piece of the symmetric keys generated by the distribution start node, node 50, and the encrypted piece was last transmitted to the node 51.
  • a symmetric key generated by the node 51 (referred to as a final node) and used for encryption.
  • the conversion parameter received here is a conversion parameter (referred to as an aggregation parameter) in which each conversion parameter generated by each node that mediates transmission of the encrypted piece is aggregated into one value. Details of the aggregation parameter will be described later. FIG.
  • the node 51B is configured to receive symmetric keys k and k_1 transmitted from the key server 53 in response to a key request including the node ID sequence and the random number sequence shown in FIG. And receiving decoded information.
  • the piece decrypting unit 520 first decrypts the encrypted piece using the symmetric key generated by the final node among the received symmetric keys. As a result, a half-decoded piece is obtained.
  • the piece decoding unit 520 causes the inverse conversion unit 522 to perform inverse transformation on the obtained half-decoded piece using the aggregation parameter with the function L ⁇ 1 , and receives the half-decoded piece subjected to the inverse conversion Among the symmetric keys, the node 50 which is the distribution start node decrypts using the symmetric key generated. This results in available pieces.
  • the inverse conversion unit 522 Under control of the piece decoding unit 520, the inverse conversion unit 522 performs inverse conversion on the half-decoded pieces obtained by the piece decoding unit 520 using the aggregation parameter and the function L- 1 .
  • each of the plurality of pieces of the node 51 is encrypted.
  • Each encrypted piece is acquired from the other nodes 50 and 51 by a piece request.
  • the node 51 receives decryption information including each symmetric key and aggregation parameter from the key server 53 in response to a key request for each encrypted piece, and obtains the distribution data described above by decrypting each encrypted piece.
  • FIG. 8 is a diagram illustrating a functional configuration of the key server 53.
  • the key server 53 includes a secret key storage unit 530, a data reception unit 531, a parameter generation unit 532, a symmetric key generation unit 533, and a data transmission unit 534.
  • the secret key storage unit 530 is secured as a storage area in an external storage device such as an HDD of the key server 53, for example.
  • the entities of the data reception unit 531, the parameter generation unit 532, the symmetric key generation unit 533, and the data transmission unit 534 are generated on a storage device such as a RAM when a program of the CPU of the key server 53 is executed. .
  • the secret key storage unit 530 stores the secret key assigned to each of the nodes 50 and 51 in association with the node ID assigned to each of the nodes 50 and 51.
  • the data receiving unit 531 requests decryption information for inversely converting and decrypting the encrypted piece, and receives from the node 51 a key request including the above-described node ID sequence and random number sequence.
  • the parameter generation unit 532 encrypts the node 50 that is the distribution start node that first encrypted the piece in the node ID string included in the key request received by the data reception unit 531, and the node 51 that has transmitted the key request.
  • the secret key stored in the secret key storage unit 530 is read out corresponding to the node 51 (final node) that last encrypted and transmitted the encrypted piece, and is included in the random number sequence included in the key request Of the random numbers generated by the node 50 by using the random number used to generate the symmetric key used for the first encryption of the piece and the random number used to generate the symmetric key among the random numbers generated by the final node. Generate two symmetric keys.
  • the node ID of the node 51 that has transmitted the key request is ID # (j)
  • each node ID included in the node ID string included in the key request is ID # 0, ..., ID # (j-1).
  • r m and s m correspond to each node ID ID # m (0 ⁇ m ⁇ j).
  • the secret key of the node 50 which is the distribution start node is s 0
  • the secret key of the final node is s j -1 .
  • one of the random numbers used for generating the symmetric key is r.
  • the random number used to generate the symmetric key is r j -1 .
  • the symmetric key generation unit 533 generates two symmetric keys k and k j-1 represented by the following equation. As a result, two, a symmetric key k used for the first encryption for the piece and a symmetric key k j-1 used for the last encryption are obtained.
  • k F (s 0 , r)
  • k j-1 F (s j -1 , r j -1 )
  • the parameter generation unit 532 corresponds to the secret key associated with each node ID included in the node ID string included in the key request received by the data reception unit 531, and each node ID included in the key request.
  • the conversion parameter is generated for each node ID by the function G described above using the random number sequence to be generated.
  • the parameter generation unit 532 integrates these conversion parameters into one value by the function H using all the generated conversion parameters.
  • the parameter generation unit 532 generates aggregation parameters.
  • k ′ * j ⁇ 1 H (k' 0 , k ' 1 , ..., k' j-1 )
  • the data transmission unit 534 transmits, to the node 51 that has transmitted the key request received by the data reception unit 531, the decryption information including the symmetric key generated by the symmetric key generation unit 533 and the aggregation parameter generated by the parameter generation unit 532. Send.
  • the key server 53 obtains the symmetric keys k and k 1 from the random numbers r and r 1 according to the key request including the node ID sequence and the random number sequence shown in FIG. 6, and converts the conversion parameters k ′ 0 , k
  • the transformation parameter obtained by aggregating ' 1 ' is obtained k ′ * 1 , and as shown in FIG. 7, the decoding information including these is transmitted to the node 51B.
  • the node 50 divides the distribution data into a plurality of pieces (step S1).
  • step S2 receives a piece request requesting a piece from another node 51
  • step S3 the node 50 generates random numbers r, r 0 and r ′ 0 (step S3).
  • step S4 the node 50 generates symmetric keys k and k 0 by the function F using the random numbers r and r 0 generated in step S 3 and the secret key s 0 stored in the unique information storage unit 500 (step S 4) .
  • the node 50 generates a conversion parameter k ′ 0 by the function G using the random number r ′ 0 generated in step S3 and the secret key s 0 (step S5). Then, the node 50 encrypts the piece P to be transmitted using the symmetric key k generated in step S4 (step S6). There is no particular limitation on how to determine the piece to be sent. Next, the node 50 converts the encrypted piece E (k) P by the function L using the conversion parameter k ' 0 generated in step S5 on the encrypted piece (encrypted piece) E (k) P. (Step S7).
  • the node 50 encrypts the encrypted piece L (k ′ 0 ) E (k) P converted in step S 7 using the symmetric key k 0 to create a new encrypted piece E (k 0 ) L (k). ' 0 ) E (k) P is output (step S8). Then, for the other node 51 that has transmitted the piece request received in step S2, for example, as shown in FIG. 4, the node 50 stores the node ID ID # 0 stored in the unique information storage unit 500, The random numbers r, r 0 and r ′ 0 generated in step S 3 and the encrypted piece E (k 0 ) L (k ′ 0 ) E (k) P output in step S 8 are transmitted (step S 9).
  • node 50 Apart from these, sends the symmetric key k 0 generated in step S4 with respect to the other nodes 51 (step S10). Thereafter, the process returns to step S2, and the node 50 waits for reception of a new piece request.
  • the piece request received in step S2 is not limited to the same node 51, and the pieces P required by the piece request are not necessarily the same piece.
  • the random numbers generated in step S3 basically differ in each process of step S3.
  • the node 51 transmits a piece request requesting a piece to the node 50 or another node 51 (step S20).
  • the node 51 receives a node ID sequence, a random number sequence, and an encrypted piece from the node 50 or another node 51 which is the other party that transmitted the piece request in step S20 (step S21),
  • the symmetric key is separately received (step S22).
  • the node 51 associates and stores the node ID string, the random number string and the encrypted piece received in step S21 with the symmetric key received in step S22 (step S23).
  • the node 51 transmits a piece request to the node 50
  • the node ID sequence, the random number sequence, and the encrypted piece shown in FIG. 4 for the piece P are received in step S21.
  • a node connected to the P2P network NT where f is an integer of 1 or more, will be generalized and described as a node that receives the piece P at the f-th position.
  • the node ID of the node be ID # f. From the node to which the node ID ID # f is assigned, from the node to which the (f-1) -th node ID ID # (f-1) is assigned, as shown in FIG.
  • step S30 When receiving a piece request requesting a piece from another node 51 (step S30: YES), the node 51 generates two random numbers (step S31). Next, the node 51 generates a symmetric key with the function F using one of the random numbers generated in step S31 and the secret key stored in the unique information storage unit 510 (step S32). Next, the node 51 generates a conversion parameter by the above-described function G using a random number not used to generate a symmetric key among the random numbers generated in step S31 and the secret key (step S33).
  • the node 51 decrypts the encrypted piece using the symmetric key stored in the data storage unit 517 in association with the encrypted piece (step S34). As a result, a half-decoded piece is obtained. Thereafter, the node 51 converts the half-decoded piece obtained in step S34 using the conversion parameter generated in step S33 (step S35). Then, the node 51 encrypts the half-decrypted piece converted in step S35 using the symmetric key generated in step S32, and outputs a new encrypted piece (step S36). After that, the node 51 adds unique information to the node ID stored in the data storage unit 517 in association with the encrypted piece to be transmitted, with respect to the other node 51 that has transmitted the piece request received in step S30.
  • the row and the new encrypted piece output in step S36 are transmitted (step S37).
  • the node 51 transmits the symmetric key generated in step S32 to the other node 51 separately (step S38).
  • the node to which the above-described node ID ID # f is assigned is shown in FIG. 13 for the node to which the (f + 1) -th node ID ID # (f + 1) is assigned in step S36.
  • the node 51 reads out the node ID sequence and the random number sequence associated with the encrypted piece stored in the data storage unit 517 (step S40), and requests the decryption information for inversely converting and decrypting the encrypted piece
  • a key request including the node ID sequence and the random number sequence is transmitted to the key server 53 (step S41).
  • the node 51 receives the decryption information including the two symmetric keys and the aggregation parameter transmitted from the key server 53 in response to the key request transmitted in step S40 (step S42).
  • the two symmetric keys are, as described above, the symmetric key first used to encrypt a piece of the symmetric key generated by the node 50 and the symmetric key generated by the last node, which are used for the final encryption. And the symmetric key.
  • the node 51 first decrypts the encrypted piece using the symmetric key generated by the final node among the received symmetric keys (step S43). As a result, a half-decoded piece is obtained.
  • the node 51 performs inverse transformation on the half-decoded piece obtained in step S43 using the aggregation parameter received in step S42 with the function L -1 (step S44). Thereafter, the node 51 decrypts the half-decrypted piece subjected to the inverse conversion in step S44 using the symmetric key generated by the node 50 among the symmetric keys received in step S43 (step S45). This results in available pieces.
  • the node to which the above-described node ID ID # (f + 1) is assigned to the key server 53, as shown in FIG. f-1), and the ID # f, random number sequence r, r 0, r '0 , ..., r f-1, r' f-1, r f, to send and r 'f. Then, from the key server 53, as shown in FIG. 16, the relevant node obtains symmetric keys k,..., K f ⁇ 1 and aggregation parameters “k ′ * f ⁇ 1 H (k ′ f ⁇ ) for piece P.
  • each node 51 receives, from the key server 53, decryption information including each symmetric key and aggregation parameter according to a key request for each encrypted piece in which each of a plurality of pieces is encrypted, and each encrypted piece
  • decryption information including each symmetric key and aggregation parameter according to a key request for each encrypted piece in which each of a plurality of pieces is encrypted, and each encrypted piece
  • the above-mentioned delivery data can be obtained by decrypting.
  • the key server 53 requests decryption information for reversely converting and decrypting the encrypted piece, and receives the key request including the node ID sequence and the random number sequence from the node 51 (step S50: YES), the received key request
  • the secret key stored in the secret key storage unit 530 in association with each node ID included in the node ID string included in is read out for each node ID (step S51).
  • the key server 53 is used to generate a symmetric key among the random numbers used for generating the symmetric key used for the first encryption among the random numbers generated by the node 50 which is the distribution start node and the random numbers generated for the final node.
  • Two symmetric keys are generated by the function F using the random numbers (step S52).
  • the two symmetric keys are, as described above, the symmetric key first used to encrypt a piece of the symmetric key generated by the node 50 and the symmetric key generated by the last node, which are used for the final encryption. And the symmetric key.
  • the key server 53 performs conversion by the function G described above using the secret key associated with each node ID included in the node ID sequence and the random number sequence corresponding to each node ID included in the key request.
  • a parameter is generated for each node ID (step S53).
  • the key server 53 aggregates these conversion parameters into one value by the function H using all the conversion parameters generated in step S53, and generates an aggregation parameter (step S54). Thereafter, the key server 53 transmits the decryption information including the symmetric key generated in step S52 and the aggregation parameter generated in step S54 to the node 51 that has transmitted the key request received in step S50 (step S55).
  • the key server 53 responds to the key request including the node ID sequence and the random number sequence as shown in FIG. 15 for the piece P with respect to the node to which the above-described node ID ID # (f + 1) is assigned. , Symmetric key k, k f-1 and aggregation parameter H (k ' f-1 , ..., k' 0 ) as shown in FIG.
  • the piece is basically encrypted using a one-time symmetric key, but the encryption is not simply repeated.
  • the encryption is performed using the temporarily generated conversion parameters, and encryption is performed using the newly generated symmetric key.
  • the encrypted piece acquired by a certain node 51 is the encryption performed by the distribution start node at the beginning, the conversion performed by the node 51 that mediates the transmission of the encrypted piece, and the encryption performed by the node. It is in a state in which the last node which encrypted and transmitted the finalized piece has performed the encryption performed by the last node.
  • the sequence of conversion performed by each of the nodes 50 and 51 in the process of transmitting the encrypted piece varies according to the distribution route. Also, in the case of a combination of all the encrypted pieces in which each of a plurality of pieces is encrypted, it is likely that the delivery path will be different if the encrypted pieces are different, so the conversion performed in each encrypted piece There is a high possibility that the sequences of Also, if the delivery paths of different encrypted pieces are the same, the combination of node IDs associated with each encrypted piece will be the same, but the symmetric key used for encryption in each node may be different each time. Therefore, even if the delivery routes are identical, the symmetric keys for decrypting the encryption may be different.
  • the distribution path may be different for each node and each piece, the combination of encrypted pieces acquired by a certain node is unique to the distribution path and the distribution timing, and may be surely unique.
  • the encrypted piece can be used for calculation of two times of decryption for the first encryption and last encryption for the piece and one reverse conversion using aggregation parameters It is possible to decode into a state of interest, and to make the amount of calculation required for decoding and inverse transformation constant. Therefore, the processing load on the node 51 can be reduced.
  • the symmetric key used for encryption is basically generated only once by using random numbers, the influence of leakage of the symmetric key can be reduced.
  • the uniqueness of each node can be surely improved for the combination of each encrypted piece acquired by each node without special devising on the delivery method in P2P delivery. , Can improve safety. Furthermore, it becomes possible to maintain the independence of the data protection and the data delivery method, it is possible to improve the degree of freedom in system construction, and further to improve the calculation efficiency in the communication device. Become.
  • the present invention is not limited to the above embodiment as it is, and at the implementation stage, the constituent elements can be modified and embodied without departing from the scope of the invention.
  • various inventions can be formed by appropriate combinations of a plurality of constituent elements disclosed in the embodiments. For example, some components may be deleted from all the components shown in the embodiment. Furthermore, components in different embodiments may be combined as appropriate. In addition, various modifications as exemplified below are possible.
  • various programs executed by each node 50 may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network.
  • the program is recorded in a computer readable recording medium such as a CD-ROM, a flexible disk (FD), a CD-R, a DVD (Digital Versatile Disk) or the like in an installable or executable file format. It may be configured to be provided.
  • the program is loaded from the storage medium at each node 50 and executed by being loaded onto the main storage (for example, RAM), and the units described in the functional configuration are generated on the main storage. Ru. The same applies to various programs executed by the key server 53.
  • all or part of the units described in the functional configuration of each node 50 may be configured by hardware. The same applies to all or some of the units described in the functional configuration of the key server 53.
  • the node ID may be any information that can uniquely identify each node, and may be, for example, the IP address, MAC address, or URL of each node.
  • the number of distribution start nodes may be plural. Also, the number of other nodes connected to the P2P network NT is not particularly limited.
  • a plurality of pieces may be required by one piece request.
  • the nodes 50 and 51 may transmit the set of the encrypted piece, the node ID sequence and the random number sequence to the other node 51 that has transmitted the piece request as described above for each of the plurality of pieces.
  • the nodes 50 and 51 transmit the encrypted piece in response to the piece request.
  • the present invention is not limited to this configuration.
  • the ID node sequence and the random number sequence may be transmitted together with the encrypted piece.
  • the node 51 when the encrypted pieces are obtained for all the pieces constituting the distribution data and stored in the data storage unit 517, the node 51 reversely converts and decrypts the encrypted pieces.
  • a key request for requesting each piece of decryption information may be transmitted to the key server 53.
  • the node 51 transmits, to the key server 53, a key request for the encrypted piece stored in the data storage unit 517, even when the encrypted piece is not obtained for all the pieces constituting the distribution data. You may do so.
  • the node 51 may request decryption information for reversely converting and decrypting one encrypted piece in response to one key request, or in order to reversely convert and decrypt a plurality of encrypted pieces. Each piece of decryption information may be requested.
  • a symmetric key which is also an encryption key and is a decryption key for decrypting the encryption is used.
  • the encryption key used to encrypt the piece and the decryption key for decrypting the encryption performed on the encrypted piece may be different.
  • the nodes 50 and 51 when transmitting the encrypted pieces stored in the data storage unit 517 to another node 51, the nodes 50 and 51 generate random numbers each time.
  • the nodes 50 and 51 may not generate random numbers each time, but may generate them, for example, according to the number of transmissions of the encrypted piece.
  • the nodes 50 and 51 may generate new random numbers each time transmission of an encrypted piece is performed a predetermined number of times (for example, five times).
  • the timing at which the nodes 50 and 51 generate random numbers may be when the piece request is received from another node 51, or may be every predetermined time.
  • the node 51 in the case where the encrypted piece stored in the data storage unit 517 is encrypted and transmitted to another node 51, the node 51 does not partially but all of the data of the encrypted piece. It is also possible to encrypt data of In this case, the data encrypted by each node 51 mediating the delivery of the encrypted piece overlaps the data encrypted by another node 51 mediating the delivery of the encrypted piece. The node 51 may encrypt part of the data of the encrypted piece. According to such a configuration, the processing load on encryption performed by each node 51 can be reduced, and by overlapping the encrypted portion, it is possible to suppress the influence when the decryption key is exposed. become.
  • the node ID sequence and the random number sequence that the node 51 transmits to the other node 51 together with the encrypted piece are not limited to the forms shown in FIGS. For example, (ID # 0, r 0 ), (ID # 1, r 1) ... (ID # f, r f) As such, each set of node ID of the random number corresponding to the node ID and the node ID The form shown in FIG.
  • the secret key is uniquely assigned to each of the nodes 50 and 51.
  • the present invention is not limited to this.
  • the same secret key may be assigned to some of the nodes 50 and 51.
  • the encrypted piece, the node ID sequence and the random number sequence may be distributed in the form of package data packaged.
  • the package data may be recorded on a computer readable recording medium and provided to the node, or may be configured to be downloaded to the node via the server.
  • the node which has acquired the package data in response to the piece request, in the same manner as in the above-described embodiment, an encrypted piece in which the encryption piece included in the package data is selectively encrypted;
  • the node ID and its own node ID included in the package data, the random number sequence included in the package data, and the random number generated by itself may be transmitted to another node.
  • the transmission of the ID sequence, the random number sequence and the encrypted piece is separated from the transmission of the symmetric key, but the nodes 50 and 51 may transmit these simultaneously.
  • the random number used to generate the conversion parameter is different from the random number used to generate the symmetric key.
  • the nodes 50 and 51 may generate the conversion parameter and the symmetric key using the same random number.
  • the key server 53 sends to the node 51 decryption information including the aggregation parameter, the symmetric key used for the first encryption for the piece, and the symmetric key used for the last encryption. It was made to send. However, the key server 53 sends to the node 51 decryption information including the aggregation parameter and the symmetric key used for the first encryption of the piece, not including the symmetric key used for the last encryption. It is good.
  • one or two encryptions are performed for each piece constituting the content, but three or more encryptions are performed multiple times.
  • the present embodiment may be applied to the content distribution system to be put into a state.
  • a content delivery system in which a piece is multiple-encrypted three or more times with a plurality of encryption keys.
  • Each of the nodes 50 and 51 is assigned a secret key and a node ID as in the above-described embodiment, and the nodes 50 and 51 use, for example, the secret key assigned to themselves as the encryption key. It encrypts the piece itself or the encrypted piece received from the other nodes 50 and 51 and transmits the encrypted one to the other node 51. Thus, each time an encrypted piece is transmitted from each node 50, 51, encryption is applied.
  • the node 50 serving as the distribution start node encrypts the piece using the secret key, and then transmits the encrypted piece and the node ID assigned to itself. And the other node 51.
  • the node 51 associates and stores the encrypted piece and the node ID.
  • the node 51 receives a piece request from another node 51, it further encrypts the encrypted piece using the secret key assigned to itself, and outputs a new encrypted piece to correspond to the encrypted piece.
  • the node ID stored and stored, the node ID assigned to itself and the new encrypted piece are transmitted to the other node 51.
  • the encrypted piece to be transmitted is further encrypted and assigned to the node ID stored in association with the encrypted piece and itself. Send the new node ID and the new encrypted piece.
  • the secret key SA itself assigned to the nodes 50 and 51 as an encryption key for encrypting the encrypted piece, and for example, using the random number RA generated by the nodes 50 and 51, hashing
  • RA) may be calculated and used as the encryption key, or the encryption key F (SA, RA) may be calculated by a function.
  • the nodes 50 and 51 also transmit the random number RA used for calculating the encryption key to the other node 51 that has transmitted the piece request.
  • the other node 51 further encrypts the encrypted piece and transmits the encrypted piece to the other node 51
  • the other node 51 combines the random number received with the encrypted piece and the random number generated by itself and transmits it to the other node 51.
  • the nodes 50 and 51 do not necessarily have to encrypt the entire encrypted piece, and only a part of the encrypted piece may be encrypted.
  • the nodes 50 and 51 may be configured to encrypt 32 bytes of data from the information on which part of the encrypted piece has been encrypted (for example, from the beginning of the encrypted piece (referred to as 0th data)). Sends (0, 31)) to the other node 51.
  • the other node 51 further encrypts the encrypted piece and transmits it to the other node 51, the information about which part of the encrypted piece is encrypted, which is received together with the encrypted piece, and itself is encrypted Information on which part of the piece has been encrypted is sent to the other node 51 together.
  • the node 50 serving as the distribution start node encrypts the whole piece (for example, 128 bytes of data), and then the node 51A receiving the encrypted piece is 16 from the top
  • the byte data is encrypted, and the node 51B that receives the encrypted piece from the node 51A encrypts the next 16 bytes of data skipped 16 bytes from the beginning, etc.
  • the information on which part of the encrypted piece has been encrypted may be used instead of the information on which part of the encrypted piece has been encrypted.
  • This information is '0' when the node 51 receives the encrypted piece, for example, when it is a distribution start node, '1' when it is the node 51A, and '2' when it is the node 51B. For example, upon receiving an encrypted piece from node 51A, node 51B overwrites this information from '1' to '2'.
  • the above request message sent by the nodes 50 and 51 to the key server 53 includes the node IDs of all the nodes through which the encrypted piece has passed. . Also, as described above, when using a random number for generating the encryption key, the above request message includes the random numbers of all the nodes through which the encrypted piece has passed. Similarly, information on which part of the encrypted piece has been encrypted may be included, or information on how many nodes the encrypted piece has passed may be included.
  • the key server 53 in the case of multiple encryption of a piece with a plurality of encryption keys is as follows.
  • the key server 53 holds the secret key assigned to each of the nodes 50 and 51, as in the above-described embodiment.
  • the key server 53 receives the request message from the node 51, the secret key assigned to each of the nodes 50 and 51 to which the encrypted piece has passed, from the node IDs of all the nodes 50 and 51 to which the encrypted piece has passed. Search for these and obtain them as a key ring.
  • the key server 53 decrypts the key using the secret key assigned to each of the nodes 50 and 51 through which the encrypted piece has passed and the random number of the corresponding node.
  • Each key is calculated (in the above example, it is H (SA
  • the key server 53 need not necessarily hold the secret key assigned to each of the nodes 50 and 51.
  • LIDA) or SA F (Kmaster, LIDA)', the key server 53 only needs to know the value of Kmaster and the algorithm of function H or F, and the request From the LID contained in the message, the secret key assigned to the corresponding node 50, 51 of that node ID can be calculated.
  • the node 51 receives a piece request from another node 51, if the number of times of encryption performed on the encrypted piece to be transmitted is equal to or more than a predetermined number of times, the node 51 receives the piece request. , And transmits the encrypted piece to another node 51 after performing one encryption. Specifically, the node 51 determines whether the number of node IDs stored in association with the encrypted piece to be transmitted is a predetermined number or more, and the number of the node IDs is a predetermined number or more.
  • a random number is generated to generate a symmetric key and a conversion parameter, the same conversion as in the above embodiment is performed on the encrypted piece, and the generated symmetric key is used.
  • Encrypt the converted encrypted piece and output a new encrypted piece.
  • the node 51 transmits the node ID stored in association with the encrypted piece, the node ID assigned to itself, the random number generated by itself, and the new encrypted piece to the other node 51, Apart from these, the symmetric key generated by itself is transmitted to the other node 51.
  • the other node 51 stores the received encrypted piece in association with the node ID, the random number and the symmetric key.
  • the other node 51 When the other node 51 transmits the encrypted piece to the other node 51, the other node 51 generates a random number and generates a symmetric key and a conversion parameter in the same manner as the above embodiment. And decrypting the encrypted piece once using the symmetric key stored in association with the encrypted piece, and performing the same conversion as in the above embodiment on the decrypted encrypted piece, to generate the symmetric The key is used to encrypt the converted encrypted piece, and a new encrypted piece is output. Then, the other node 51 adds the node ID stored in association with the encrypted piece, the node ID assigned to itself, the random number generated by itself, and the new encrypted piece to the other node 51. It transmits, and apart from these, transmits the symmetric key generated by itself to the other nodes 51.
  • the number of times of encryption can be reduced to a certain number of times or less. Can also be suppressed below a certain number of times. Therefore, it is possible to achieve both the improvement of security by multiple encryption and the improvement of calculation efficiency at the time of decryption.
  • each node 50, 51 according to a predetermined probability whether or not to encrypt the encrypted piece, not every time it is transmitted from the nodes 50, 51. It may be determined so that further encryption on the encrypted piece may be selectively performed.
  • a value obtained by multiplying the number of node IDs stored in association with the transmission target encrypted piece with a predetermined probability is It is determined whether the number is equal to or more than a predetermined number, and when the value is equal to or more than the predetermined number, a random number is generated to generate a symmetric key and a conversion parameter in the same manner as in the above embodiment.
  • the same conversion as in the above-described embodiment may be performed, the converted encrypted piece may be encrypted using the generated symmetric key, and a new encrypted piece may be output.
  • each piece is encrypted by the distribution start node node 50 and then converted using the conversion parameter, and the converted parameter is received by the node 51 that has received the converted and encrypted piece. After being converted using, the symmetric key is made to be encrypted.
  • each of the nodes 50 and 51 may perform only the above-mentioned conversion without encrypting each piece. In this case, each of the nodes 50 and 51 transmits the converted piece to the other node 51 together with the above-described node ID sequence and random number sequence without generating a symmetric key.
  • the key server 53 when the key server 53 receives a key request from the node 51 as in the above-described embodiment, the key server 53 generates aggregation parameters in the same manner as described above without generating a symmetric key, and the decryption information including the aggregation parameters. Is transmitted to the node 51. Then, each node 51 may inverse transform the piece using the aggregation parameter included in the decoding information.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Storage Device Security (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

 データの一部であるピースを送信する通信装置は、他の通信装置によって可逆に変換された第1ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置によって生成された第1一時情報とを受信し、第1ピースと、第1装置識別情報と、第1一時情報とを対応付けて記憶し、当該通信装置に割り当てられた第2装置識別情報を記憶する。通信装置は、その生成毎に異なり得る第2一時情報を生成し、第2一時情報を用いて、第1ピースを変換して、第2ピースを出力し、第2ピースと、第1装置識別情報と、第2装置識別情報と、第1一時情報と、第2一時情報とを送信する。

Description

通信装置、サーバ、通信方法及びプログラム
 本発明は、通信装置、サーバ、通信方法及びプログラムに関する。
 例えば、P2P(peer to peer)を利用してデータを配信する配信方式(P2P配信という)は、巨大なストレージと大きな通信帯域とを有するデータ配信サーバを必要とせず、コストメリットの大きい配信方式である。また、データの配信を受けるノードにおいては、複数のノードからのデータの供給が期待されるため、ダウンロードやアップロードにおける帯域幅を活かした高速なデータ取得が期待される。このようにP2Pデータ配信には大きなメリットがあるが、一方で、著作権保護などデータセキュリティの観点から安全性に不安があった。P2P配信に限らず、著作権保護などのデータセキュリティを考える上で一般的な前提として次のことを仮定する。全ての端末機器又はノードがハッキングされることはないということである。この前提を否定した場合、端末機器は秘密とすべきデータを保持したり、秘密とすべき処理を行ったりすることができなくなり、殆どのセキュリティ技術やセキュリティ確保の為の工夫が成立しない。
 さて、P2P配信において、暗号化されたデータを配信し、データの配信を受けるノードが当該データ(配信データという)を復号するための復号鍵を取得するコンテンツ配信システムがある。このようなシステムのP2P配信においてデータセキュリティ上の大きな問題点は、配信データと当該配信データを復号するための復号鍵との組み合わせが単一であったり数が少なかったりすることである。この場合、あるノードがハッキングされ、復号鍵が暴露されたとする。この場合、この復号鍵は殆どの配信データを復号するために使用できることになる。この問題を解決する一つの方法は、配信データをノード毎に個別化することである。
 P2P配信において配信データをノード毎に個別化する技術としては、例えば、特許文献1に示されるMarkingの方式が知られている。この方式では、配信データをピースに分割した上で、鍵の行列で暗号化を施して暗号化ピースを生成する。その結果として、行列状に暗号化された暗号化ピースからなるピース群が生成される。そしてこのようなピース群はP2Pネットワークを介して配信される。当該P2Pネットワークに接続される1つのノードは、各ピースについて行列状に暗号化された複数の暗号化ピースの中から1つの暗号化ピースを取得することになる。結果として、配信データを構成する各ピースが各々暗号化された暗号化ピースの組み合わせは、ノード毎に統計的に一意になることが期待される。
USP 7165050
 しかし、上述の特許文献1の技術においては、各暗号化ピースの組み合わせがノード毎に一意であることはあくまで統計的に期待されるだけである。各暗号化ピースの組み合わせをノード毎に一意にすることを実現するには、例えば、以下の2つの方法が考えられる。1つは、暗号化ピースの配信方法に工夫を施すという方法である。また、1つは、各暗号化ピースを復号するための復号鍵を保持する鍵サーバが復号鍵の配信を制限するという方法である。例えば、配信されたピース群をノードは復号するために、各暗号化ピースの組み合わせを鍵サーバに申告して復号鍵を取得するシステムがある。このシステムにおいて、復号鍵の再配信によるリプレイアタックを阻止するためには、既に取得された復号鍵と重複が多い暗号化ピースの組み合わせを、鍵サーバがリジェクトするという方法がある。しかしいずれの方法であっても、暗号化ピースの配信効率を時として著しく低下させ、P2Pネットワークの利点を十分活かすことができなくなる恐れがある。また、前者の方法では、データの保護とデータの配信方法との独立性が損なわれ、そのことがシステム構築上の大きな制約となる恐れがある。
 本発明は、上記に鑑みてなされたものであって、コンテンツ配信システムにおいて配信される各ピースの組み合わせを通信装置毎に一意にすることが可能になると共に、システム構築上の自由度を向上可能であり、通信装置における計算の効率を向上可能な通信装置、サーバ、通信方法及びプログラムを提供することを目的とする。
 上述した課題を解決し、本発明は、データの一部であるピースを送信する通信装置であって、他の通信装置によって可逆に変換された第1ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置によって生成された第1一時情報とを受信する受信手段と、前記第1ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶する第1記憶手段と、当該通信装置に割り当てられた第2装置識別情報を記憶する第2記憶手段と、その生成毎に異なり得る第2一時情報を生成する第1生成手段と、前記第2一時情報を用いて、前記第1ピースを変換して、第2ピースを出力する変換手段と、前記第2ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信手段とを備えることを特徴とする。
 また、本発明は、データの一部であるピースを受信する通信装置であって、当該通信装置に割り当てられている装置識別情報を記憶する第1記憶手段と、他の通信装置によって可逆に変換されたピースと、当該他の通信装置に割り当てられている装置識別情報と、当該他の通信装置によって生成された一時情報とを受信する第1受信手段と、前記ピース、前記装置識別情報及び前記一時情報を対応付けて記憶する第2記憶手段と、前記ピースを逆変換するための復号情報を要求すると共に、当該ピースと対応付けられて記憶された前記装置識別情報及び前記一時情報を対応付けて含む要求を鍵サーバへ送信する送信手段と、前記要求に応じて前記鍵サーバから、前記復号情報を受信する第2受信手段と、受信された前記復号情報を用いて前記ピースを復号する復号手段とを備えることを特徴とする。
 また、本発明は、サーバであって、データの一部であるピースを送信する複数の他の通信装置のそれぞれに割り当てられた秘密情報と、各通信装置に割り当てられた装置識別情報とを各々対応付けて記憶する第1記憶手段と、可逆に変換された前記ピースを逆変換するための復号情報を要求すると共に、前記複数の他の通信装置の前記装置識別情報及び当該複数の他の通信装置が各々生成した情報であってその生成毎に異なり得る一時情報とを対応付けて含む要求を第1通信装置から受信する受信手段と、前記要求に含まれる各前記装置識別情報に対応付けられて記憶されている前記秘密情報と、当該各装置識別情報と対応付けられて前記要求に含まれる各前記一時情報とを用いて、逆変換を行う際に用いる変換パラメータを生成する第1生成手段と、前記変換パラメータを含む前記復号情報を前記第1通信装置に送信する送信手段とを備えることを特徴とする。
 本発明によれば、コンテンツ配信システムにおいて配信される各ピースの組み合わせを通信装置毎に一意にすることが可能になると共に、システム構築上の自由度を向上可能であり、通信装置における計算の効率を向上可能になる。
第1の実施の形態にかかるデータ配信システムの構成を示す図。 ノード50の機能的構成を例示する図。 ノード51の機能的構成を例示する図。 ノード50からノード51Aに送信される情報を模式的に示す図。 ノード51Aからノード51Bに送信される情報を模式的に示す図。 ノード51Bから鍵サーバに送信される情報を模式的に示す図。 鍵サーバ53からノード51Bに送信される復号情報を模式的に示す図。 鍵サーバ53の機能的構成を例示する図。 ノード50が行う配信処理の手順を示すフローチャート。 ノード51が暗号化ピースを受信する受信処理の手順を示すフローチャート。 ノードに受信される情報を模式的に示す図。 配信開始ノード以外のノード51が行う配信処理の手順を示すフローチャート。 ノードが送信する情報を模式的に示す図。 ノード51が暗号化ピースを復号する復号処理の手順を示すフローチャート。 ノードが送信する情報を模式的に示す図。 ノードが受信する対称鍵を模式的に示す図。 鍵サーバ53がノード51からの鍵要求に応じて復号情報を送信する復号情報送信処理の手順を示すフローチャート。
 以下に添付図面を参照して、この発明にかかる通信装置、サーバ、通信方法及びプログラムの一実施の形態を詳細に説明する。
 図1は、本実施の形態にかかるデータ配信システムの構成を示す図である。本実施の形態にかかるデータ配信システムにおいては、複数のノード50,51A~51BがP2PネットワークNTを介して接続されている。図示しないがこの他のノードもP2PネットワークNTを介して接続され得る。また、各ノード50,51A~51Bは鍵サーバ53と接続されている。各ノード50,51A~51Bは、各ノードに一意に割り当てられた装置識別情報であるノードIDと、各ノードに一意に割り当てられた割当情報として秘密鍵を保持している。各ノード50,51A~51Bに割り当てられたノードIDを各々ID#0,ID#1,ID#2とし、秘密鍵を各々s0,s1,s2とする。尚、各ノード50,51A~51Bのうちノード50は、データの配信の基点となる配信開始ノードであり、配信対象のデータ(配信データという)を保持している。配信データは、平文である場合も既に暗号化された暗号文である場合もある。例えば、当該配信データは、暗号化として何らかのDRM (Digital Right Management) Systemによって保護されたビデオデータであっても良い。鍵サーバ53は、各ノード50,51A~51Bに各々割り当てられた秘密鍵を保持している。尚、以降、ノード51A~51Bを各々区別する必要がない場合、単にノード51と記載する。
 ここで、各ノード50,51と、鍵サーバ53との各装置のハードウェア構成について説明する。各装置は各々、装置全体を制御するCPU(Central Processing Unit)等の制御装置と、各種データや各種プログラムを記憶するROM(Read Only Memory)やRAM(Random Access Memory)等の記憶装置と、各種データや各種プログラムを記憶するHDD(Hard Disk Drive)やCD(Compact Disk)ドライブ装置等の外部記憶装置と、これらを接続するバスとを備えており、通常のコンピュータを利用したハードウェア構成となっている。また、各装置には各々、情報を表示する表示装置と、ユーザの指示入力を受け付けるキーボードやマウス等の入力装置と、外部装置の通信を制御する通信I/F(interface)とが有線又は無線により接続される。
 次に、上述したハードウェア構成において、配信開始ノードであるノード50のCPUが記憶装置や外部記憶装置に記憶された各種プログラムを実行することにより実現される各種機能について説明する。図2は、ノード50の機能的構成を例示する図である。ノード50は、固有情報格納部500と、乱数生成部501と、対称鍵生成部502と、ピース暗号化部503と、ピース化部504と、データ送信部505と、送信要求受付部506と、パラメータ生成部507と、変換部508とを有する。尚、固有情報格納部500は、例えばノード50のHDDなどの外部記憶装置に記憶領域として確保されるものである。乱数生成部501と、対称鍵生成部502と、ピース化部504と、ピース暗号化部503と、データ送信部505と、送信要求受付部506と、パラメータ生成部507と、変換部508との実体は、ノード50のCPUのプログラム実行時にRAMなどの記憶装置上に生成されるものである。尚、ノード50の外部記憶装置には、配信データが予め記憶されている。
 固有情報格納部500は、当該ノード50に割り当てられたノードID及び秘密鍵を記憶する。ピース化部504は、配信データを複数のピースに分割する。分割する際のデータサイズは特に限定されないが、予め定められているものとする。送信要求受付部506は、ピース化部504が分割したピースを要求するピース要求を他のノード51から受信する。乱数生成部501は、送信要求受付部506がピース要求を受信した場合、その発生毎に異なり得る一時情報である乱数を3つ生成する。一時情報とは、ノードで生成される度に異なり得る値となれば良く、乱数の他、例えば、タイムスタンプ、通信のシーケンス番号、ノードに固有のカウンタの値、Time Variant Parameterである。Time Variant Parameterについては、例えば文献ISO/IEC 9798-1に記載されている。ここで生成される乱数をr, r0,r'0とする。このうち、乱数r,r0は、後述するように、ピースの暗号化に用いる対称鍵を毎回変化させるために用いられ、乱数r'0は、変換を行う際に用いる変換パラメータを毎回変化させるために用いられる。
 対称鍵生成部502は、乱数生成部501が生成した乱数のうち2つの乱数r,r0と、固有情報格納部500に記憶された秘密鍵s0とを用いて関数Fにより2つの対称鍵k,k0を生成する。これを式により表すと以下のように表される。
k=F(s0,r)
k0=F(s0,r0)
この関数Fは一方向性関数であり、入力値である秘密鍵や乱数を知るものであってもこれらから出力値である対称鍵を推測できないものである。
 尚、対称鍵がユーザにより不正に利用されることを防止するために、対称鍵生成部502は、生成した対称鍵を、ユーザに知られていない暗号鍵で更に暗号化してHDDなどの外部記憶装置に記憶させ、対称鍵の実際の値をユーザに分からせないように秘匿することが望ましい。また、関数Fによる変換のアルゴリズムをユーザが特定できないように秘匿することが望ましい。
 パラメータ生成部507は、乱数生成部501が生成した乱数のうち対称鍵の生成に用いられていない乱数r'0と、秘密鍵s0とを用いて関数Gにより変換パラメータk'0を生成する。これを式により表すと以下のように表される。
k'0=G(s0,r'0)
この関数Gは一方向性関数であり、出力値である変換パラメータと入力値である乱数を知るものであっても、これらから入力値である秘密鍵を推測できないものである。
 尚、変換パラメータがユーザにより不正に利用されることを防止するために、パラメータ生成部507は、生成した変換パラメータを、ユーザに知られていない暗号鍵で暗号化してHDDなどの外部記憶装置に記憶させ、変換パラメータの実際の値をユーザに分からせないように秘匿することが望ましい。
 ピース暗号化部503は、対称鍵生成部502が生成した対称鍵のうち1つの対称鍵kを用いてピースを暗号化して、暗号化ピースを出力する。尚、ピースPが対称鍵kで暗号化された暗号化ピースを、E(k)Pと表記する。また、ピース暗号化部503は、以下に説明する変換部508が暗号化ピースE(k)Pを変換したものを、対象鍵k_0を用いて更に暗号化して、新たな暗号化ピースを出力する。変換した暗号化ピースをL(k'0)E(k)Pと表記すると、これを、対象鍵k0を用いて暗号化した暗号化ピースをE(k0)L(k'0)E(k)Pと表記する。
 変換部508は、ピース暗号化部503が出力した暗号化ピースE(k)Pを、パラメータ生成部507が生成した変換パラメータk'0を用いて関数Lにより変換する。変換した暗号化ピースを、L(k'0)E(k)Pと表記する。この関数Lによる変換は、各変換パラメータを1つの値に集約した変換パラメータ(集約パラメータ)を用いて変換を行った結果と、各変換パラメータを用いて重ねて変換を行った結果とが同一となり且つ集約パラメータを用いて逆変換が可能である可逆な変換である。このような変換には例えば線形変換があるが、これに限るものではない。尚、関数Lによる変換のアルゴリズムをユーザが特定できないように秘匿することが望ましい。関数L及び逆変換を行うための関数(関数L-1とする)の詳細については後述する。
 データ送信部505は、ピース要求を送信した他のノード51に対して、固有情報格納部500に記憶されているノードIDと、乱数生成部501が生成した3つの乱数r,r0,r'0と、ピース暗号化部503が出力した新たな暗号化ピースE(k0)L(k'0)E(k)Pとを送信する。また、データ送信部505は、これらとは別に、対称鍵生成部502が生成した対称鍵のうち、変換された暗号化ピースの暗号化に用いられた対称鍵k0を、ピース要求を送信した他のノード51に対して送信する。尚、対称鍵については、データ送信部505はSSL(Secure Socket Layer)などのプロトコルを利用して暗号化して送信することが望ましい。
 次に、配信開始ノード以外であるノード51のCPUが記憶装置や外部記憶装置に記憶された各種プログラムを実行することにより実現される各種機能について説明する。図3は、ノード51の機能的構成を例示する図である。ノード51は、固有情報格納部510と、乱数生成部511と、対称鍵生成部512と、ピース暗号化部513と、データ受信部514と、データ送信部515と、送信要求受付部516と、データ格納部517と、送信要求送信部518と、鍵要求送信部519と、ピース復号部520と、変換部521と、逆変換部522と、パラメータ生成部523とを有する。尚、固有情報格納部510とデータ格納部517とは、例えばノード51のHDDなどの外部記憶装置に記憶領域として確保されるものである。乱数生成部511と、対称鍵生成部512と、ピース暗号化部513と、データ送信部515と、送信要求受付部516と、データ受信部514と、鍵要求送信部519と、ピース復号部520と、変換部521と、逆変換部522と、パラメータ生成部523との実体は、ノード51のCPUのプログラム実行時にRAMなどの記憶装置上に生成されるものである。
 固有情報格納部510は、当該ノード51に割り当てられたノードID及び秘密鍵を記憶する。送信要求受付部516の構成は上述のノード50の有する送信要求受付部506の構成と同様である。送信要求送信部518は、ピースを要求するピース要求をノード50又は他のノード51に対して送信する。データ受信部514は、送信要求送信部518がピース要求を送信した相手であるノード50又は他のノード51から、変換され暗号化されたピースである暗号化ピースと、当該暗号化ピースの送信を仲介した少なくとも1つの他のノード50,51に割り当てられた各ノードIDを含むノードID列と、当該他のノード50,51が各々生成した乱数を含む乱数列とを受信する。また、データ受信部514は、これらとは別に、送信要求送信部518がピース要求を送信した相手であるノード50又は他のノード51が生成した対称鍵を受信する。データ格納部517は、データ受信部514が受信したノードID列、乱数列、暗号化ピース及び対称鍵を対応付けて記憶する。尚、受信した対称鍵を、上述したようにユーザに知られていない暗号鍵で更に暗号化してHDDなどの外部記憶装置に記憶させるなどして秘匿することが望ましい。
 乱数生成部511は、一時情報である乱数を2つ生成する。1つの乱数は、暗号化ピースの暗号化に用いる対称鍵を毎回変化させるために用いられ、もう1つの乱数は、変換を行う際に用いる変換パラメータを毎回変化させるために用いられる。
 対称鍵生成部512は、乱数生成部511が生成した乱数のうち1つの乱数と、固有情報格納部510に記憶された秘密鍵とを用いて上述した関数Fにより対称鍵を生成する。ノード51においても対称鍵生成部512は、生成した対称鍵を上述したように秘匿することが望ましい。
 パラメータ生成部523は、乱数生成部511が生成した乱数のうち対称鍵の生成に用いられていない乱数と、秘密鍵とを用いて上述の関数Gにより変換パラメータを生成する。ノード51においてもパラメータ生成部523は、生成した変換パラメータを上述したように秘匿することが望ましい。
 ピース暗号化部513は、データ格納部517に暗号化ピースと対応付けられて記憶された対称鍵を用いて当該暗号化ピースを復号する。ここで復号された暗号化ピースを説明の便宜上、半復号ピースという。ピース暗号化部513は、以下に説明する変換部521が変換した半復号ピースを、対称鍵生成部512が生成した対称鍵を用いて暗号化して、新たな暗号化ピースを出力する。
 変換部521は、ピース暗号化部513が復号して得た半復号ピースを、パラメータ生成部523が生成した変換パラメータを用いて上述の関数Lにより変換する。
 データ送信部515は、ピース要求を送信した他のノード51に対して、固有情報格納部510に記憶されているノードIDと、乱数生成部511が生成した2つの乱数と、ピース暗号化部513が出力した新たな暗号化ピースとを送信する。また、データ送信部515は、これらとは別に、対称鍵生成部512が生成した対称鍵を、ピース要求を送信した他のノード51に対して送信する。
 ここで、ノード50,51から送信されるノードID列、乱数列、暗号化ピース及び対称鍵について具体的に説明する。尚、ノード50から1つの暗号化ピースに対してこれと共に送信されるノードIDは1つであるが、ここでは説明の便宜上、これらをノード列と記載する場合がある。暗号化ピースの配信経路としてここではノード50からノード51A、更にノード51Aからノード51Bに暗号化ピースを送信し、ノード51Bから鍵サーバ53に鍵要求を送信する場合について説明する。例えば、あるピースPについてノード51Aからのピース要求に応じて、ノード50が、上述したように、乱数r,r0と秘密鍵s0とを用いて対称鍵k,k0を各々生成し、対称鍵kを用いてピースPを暗号化して暗号化ピースE (k)Pを出力する。そして、ノード50が、乱数r'0と秘密鍵s0とを用いて変換パラメータk'0を生成し、変換パラメータk'0を用いて暗号化ピースE(k)Pを変換し、変換した暗号化ピースL(k'0)E(k)Pを、対称鍵k0を用いて暗号化して新たな暗号化ピースE(k0)L(k'0)E(k)Pを出力する。そして、ノード50が、当該暗号化ピース(k0)L(k'0)E(k)PをノードIDID#0及び乱数r,r0,r'0と共にノード51Aに送信し、これらとは別に対称鍵k0をノード51Aに送信したとする。図4は、ノード50からノード51Aに送信される情報を模式的に示す図である。当該ノード51Aは、これらのノードIDID#0、乱数r,r0r'0、暗号化ピースE(k0)L(k'0)E(k)P及び対称鍵k_0を対応付けてデータ格納部517に記憶することになる。尚、データ格納部517は、ノードIDと当該ノードIDが割り当てられたノードが生成した乱数との対応関係を保持した状態で各ノードID列及び各乱数列を記憶する。
 そして、当該ノード51Aが、ノード51Bからのピース要求に応じてピースPに対する暗号化ピースを送信する場合、乱数r1,r'1を生成し、乱数r1と秘密鍵s1とを用いて対称鍵k1を生成し、乱数r'1と秘密鍵s_1とを用いて変換パラメータk'1を生成する。また、ノード51Aが、データ格納部517に暗号化ピースE(k0)L(k'0)E(k)Pと対応付けられて記憶された対称鍵k0を用いて当該暗号化ピースを復号する。この結果、半復号ピースL(k'0)E(k)Pが得られる。そして、ノード51Aが、変換パラメータk'_1を用いて、半復号ピースL(k'0)E(k)Pを変換する。この結果、変換された半復号ピースL(k'1)L(k'0)E(k)Pが得られる。そして、ノード51Aが、変換した半復号ピースL(k'1)L(k'0)E(k)Pを、自身が生成した対称鍵k1を用いて暗号化して、新たな暗号化ピースE(k1)L(k'1)L(k'0)E(k)Pを出力したとする。このとき、ノード51Aは、ノード51Bに対して、データ格納部517に記憶されている、ノード50に割り当てられたノードIDID#0に加え固有情報格納部510に記憶されている、自身に割り当てられたノードIDID#1と、データ格納部517に記憶されている乱数r0に加え自身が生成した乱数r1,r'1と、新たな暗号化ピースE(k1)L(k'1)L(k'0)E(k)Pとを送信する。また、ノード51Aは、これらとは別に、自身が生成した対称鍵k1をノード51Bに対して送信する。図5は、ノード51Aからノード51Bに送信される情報を模式的に示す図である。ノード51Bは、これらのノードID列ID#0,ID#1、乱数列r,r0,r'0,r1, r'1、暗号化ピースE(k1)L(k'1)L(k'0)E(k)P及び対称鍵k_1を対応付けてデータ格納部517に記憶する。
 このように、暗号化ピースは、配信開始ノードであるノード50により最初に暗号化された状態で、当該暗号化ピースの送信を仲介した各ノード51によって変換が重ねて行われ、当該暗号化ピースを最後に送信したノード51によって最後に暗号化された状態となって、当該暗号化ピースを受信したノード51で記憶される。
 図3の説明に戻る。鍵要求送信部519は、データ格納部517に記憶された暗号化ピースを逆変換し復号するための復号情報を要求する鍵要求を鍵サーバ53に送信する。ここで鍵要求送信部519は、当該暗号化ピースに対応してデータ格納部517に記憶されているノードID列及び乱数列を鍵要求に含めて鍵サーバ53に送信する。例えば、ノード51Bが、図5に示した暗号化ピースE(k1)L(k'1)L(k'0)E(k)Pに対する鍵要求を鍵サーバ53に送信する場合、ノード51Bの鍵要求送信部519は、ノードID列ID#0,ID#1と、乱数列r,r0,r'0,r1, r'1とを含む鍵要求を送信する。図6は、ノード51Bから鍵サーバ53に送信される情報を模式的に示す図である。このように、ノード51は、暗号化ピースを逆変換し復号するための復号情報を鍵サーバ53に要求する際に、当該暗号化ピースの配信経路を示すものとして、配信開始ノードであるノード50を基点として当該暗号化ピースの送信を仲介した各ノード50,51の各ノードIDを含むノードID列及び当該各ノード50,51が生成した乱数を含む乱数列を鍵サーバ53に送信する。尚、これらの送信に際し、鍵要求送信部519は、各ノードIDと当該各ノードIDが割り当てられたノードが出力した乱数との対応関係を保持した状態で送信する。
 ピース復号部520は、鍵要求送信部519が送信した鍵要求に応じて鍵サーバ53から送信された2つの対称鍵と変換パラメータとを含む復号情報を受信する。尚、2つの対称鍵とは、配信開始ノードであるノード50が生成した対称鍵のうちピースの暗号化に最初に用いた対称鍵と、当該ノード51に対して暗号化ピースを最後に送信したノード51(最終ノードという)が生成して暗号化に用いた対称鍵とである。また、ここで受信する変換パラメータは、当該暗号化ピースの送信を仲介した各ノードが生成した各変換パラメータを1つの値に集約した変換パラメータ(集約パラメータという)である。集約パラメータの詳細については後述する。図7は、鍵サーバ53からノード51Bに送信される復号情報を模式的に示す図である。同図に示されるように、ノード51Bは、図6に示したノードID列及び乱数列を含む鍵要求に応じて鍵サーバ53から送信された対称鍵k,k_1と、集約パラメータk'*_1とを含む復号情報を受信する。
 そして、ピース復号部520は、まず、受信した対称鍵のうち、最終ノードが生成した対称鍵を用いて、暗号化ピースを復号する。この結果半復号ピースが得られる。次いで、ピース復号部520は、得られた半復号ピースに対して、集約パラメータを用いて関数L-1により逆変換を逆変換部522に行わせ、逆変換を行った半復号ピースを、受信した対称鍵のうち配信開始ノードであるノード50が生成した対称鍵を用いて復号する。この結果、利用可能なピースが得られる。
 逆変換部522は、ピース復号部520の制御の下、ピース復号部520が得た半復号ピースに対して、集約パラメータを用いて関数L-1により逆変換を行う。
 尚、ノード51が、複数のピースのそれぞれについてどのような順番やタイミングでどのノードから取得するかは特に限定されないが、以上のようにして、ノード51は、複数のピースのそれぞれが暗号化された各暗号化ピースをピース要求によって他のノード50,51から取得する。また、ノード51は、各暗号化ピースについて鍵要求によって各対称鍵及び集約パラメータを含む復号情報を鍵サーバ53から受信し、各暗号化ピースを復号することにより、上述の配信データを得る。
 次に、鍵サーバ53のCPUが記憶装置や外部記憶装置に記憶された各種プログラムを実行することにより実現される各種機能について説明する。図8は、鍵サーバ53の機能的構成を例示する図である。鍵サーバ53は、秘密鍵格納部530と、データ受信部531と、パラメータ生成部532と、対称鍵生成部533と、データ送信部534とを有する。尚、秘密鍵格納部530は、例えば鍵サーバ53のHDDなどの外部記憶装置に記憶領域として確保されるものである。データ受信部531と、パラメータ生成部532と、対称鍵生成部533と、データ送信部534との実体は、鍵サーバ53のCPUのプログラム実行時にRAMなどの記憶装置上に生成されるものである。
 秘密鍵格納部530は、各ノード50,51に割り当てられた秘密鍵を、各ノード50,51に割り当てられたノードIDと対応付けて記憶する。データ受信部531は、暗号化ピースを逆変換し復号するための復号情報を要求すると共に上述したノードID列及び乱数列を含む鍵要求をノード51から受信する。
 パラメータ生成部532は、データ受信部531が受信した鍵要求に含まれるノードID列のうち、ピースを最初に暗号化した配信開始ノードであるノード50及び鍵要求を送信したノード51に対して暗号化ピースを最後に暗号化して送信したノード51(最終ノード)に各々対応付けられて秘密鍵格納部530に記憶されている秘密鍵を読み出しこれと、当該鍵要求に含まれる乱数列に含まれる、ノード50が生成した乱数のうちピースに対する最初の暗号化に用いた対称鍵の生成に用いた乱数及び最終ノードが生成した乱数のうち対称鍵の生成に用いた乱数を用いて関数Fにより2つの対称鍵を生成する。例えば、鍵要求を送信したノード51のノードIDがID#(j)であり、鍵要求に含まれるノードID列に含まれる各ノードIDがID#0,…,ID#(j-1)であり、各ノードIDID#m(0≦m≦j)にrm,smが各々対応しているものとする。配信開始ノードであるノード50の秘密鍵はs0であり、最終ノードの秘密鍵はsj-1である。また、ノード50が生成した乱数のうち対称鍵の生成に用いた乱数の1つは、rである。最終ノードが生成した乱数のうち対称鍵の生成に用いた乱数は、rj-1である。この場合、対称鍵生成部533は、以下の式により表される2つの対称鍵k,kj-1を生成する。この結果、ピースに対する最初の暗号化に用いられた対称鍵kと、最後の暗号化に用いられた対称鍵kj-1との2つが得られる。
k=F(s0,r)
kj-1=F(sj-1,rj-1)
 また、パラメータ生成部532は、データ受信部531が受信した鍵要求に含まれるノードID列に含まれる各ノードIDに対応付けられている秘密鍵と、鍵要求に含まれる、各ノードIDに対応する乱数列とを用いて、上述の関数Gにより変換パラメータをノードID毎に各々生成する。各m(0≦m≦j)についての変換パラメータは以下の式により表される。
k'm=G(sm,r'm)
 そして、パラメータ生成部532は、生成した全ての変換パラメータを用いて、関数Hによりこれらの変換パラメータを1つの値に集約する。このようにしてパラメータ生成部532は集約パラメータを生成する。尚、関数Hは、集約パラメータを用いて変換を行った結果と、各変換パラメータを用いて各変換を重ねて行った結果とが同一となるような変換において、複数の変換パラメータを1つの変換パラメータ(集約パラメータ)に集約するための関数である。即ち、k1,k2を任意のパラメータとすると、関数L及び関数Hについては以下の式が成り立つ。
L(k2)L(k1)=L(H(k1,k2))
 ここで、本実施の形態にかかる集約パラメータをk'*j-1とすると、k'*j-1は以下の式により表される。
k'*j-1=H(k'0, k'1,…, k'j-1)
 データ送信部534は、対称鍵生成部533が生成した対称鍵及びパラメータ生成部532が生成した集約パラメータとを含む復号情報を、データ受信部531が受信した鍵要求を送信したノード51に対して送信する。
 例えば、鍵サーバ53は、図6に示されるノードID列及び乱数列を含む鍵要求に応じて、乱数r,r1から各々対称鍵k,k1を得て、変換パラメータk'0, k'1を集約した変換パラメータをk'*1を得て、図7に示されるように、これらを含む復号情報をノード51Bに対して送信する。
 ここで、関数L,L-1について説明する。関数Lについては、例えば、以下の(aー1)~(a-4)に示される各関数が考えられる。
(a-1)排他的論理和
L(k)P=P+k
L(k1)L(k2) =L(k1+k2)
H(k1,k2) =k1+k2
(aー2)有限体上の乗算
k=k(1)|k(2)|…|k(m)
P=P(1)|P(2)|…|P(m)
k,Pはm個のnビットの要素に等分されるとする。ここで、|は連接を表す。
各k(i),P(i)を有限体GF(2n)上の要素とみなし、乗算を*で表す。
k(i)は逆元を持つと仮定する。
L(k)P=k(1)*P(1)|k(2)*P(2)|…|k(m)*P(m)
L(k2)L(k1)P=k1(1)*k2(1)*P(1)|k1(2)*k2(2)*P(2)|…|k1(m)*k2(m)*P(m)
H(k1,k2)= k1(1)*k2(1)|k1(2)*k2(2)|…|k1(m)*k2(m)
H(k1,k2,k3) =k1(1)*k2(1)*k3(1)|k1(2)*k2(2)*k3(2)|…|k1(m)*k2(m)*k3(m)
(a-3)剰余加算
k=k(1)|k(2)|…|k(m)
P=P(1)|P(2)|…|P(m)
各k(i),P(i)を剰余類2nZ/Z (Z2 nとも書く)の要素とみなし、加算を+で表す。
(注:正式には、P(i)+k(i) mod(2n)などと書く。)
L(k)P=k(1)+P(1)|k(2)+P(2)|…|k(m)+P(m)
L(k2)L(k1) =k1(1)+k2(1)|k1(2)+k2(2)|…|k1(m)+k2(m)
H(k1,k2) =k1(1)+k2(1)|k1(2)+k2(2)|…|k1(m)+k2(m)
H(k1,k2,k3) =k1(1)+k2(1)+k3(1)|k1(2)+k2(2)+k3(2)|…|k1(m)+k2(m)+k3(m)
(a-4)有限体上の乗算と加算の組合せ
L(k,q)P=k(1)*P(1)+q(1)|k(2)*P(2)+q(2)|…|k(m)*P(m)+q(m)
L(k2,q2)L(k1, q1)P=k2(1)*[k1(1)*P1(1)+q1(1)]+q2(1)|…
=k1(1)*k2(1)*P(1)+[k2(1)*q1(1)+q2(1)]|…
L(k2,q2)L(k1,q1)=L(k1*k2,k2*q1+q2)
H(k1,q1,k2,q2) =(k1*k2,k2*q1+q2)
 また、関数L-1については、例えば、以下の(bー1)~(b-4)に示す各条件を満たす関数が考えられる。
(b-1)排他的論理和
L-1(k)=L(k)
即ち、関数Lと関数L-1とは同一の関数である。
この場合、
L-1(k)L(k)P=L(k)L(k)P=L(k)(P+k)= (P+k)+k=P+k+k=P+0=P
(b-2)有限体上の乗算
k=k(1)|k(2)|…|k(m)
P=P(1)|P(2)|…|P(m)
k(i)の逆元をk(i)-1とする。つまり、k(i)-1*k(i) =k(i)*k(i)-1=1
ここで、k-1を次のように定義する。
k-1=k(1)-1|k(2)-1|…|k(m)-1
このとき、
L-1(k) =L(k-1)
即ち、
L-1(k)L(k)P=L(k-1)[k(1)*P(1)|k(2)*P(2)|…|k(m)*P(m)]
=k(1)-1*k(1)*P(1)|k(2)-1*k(2)*P(2)|…|k(m)-1*k(m)*P(m)
=P(1)|P(2)|…|P(m)
(b-3)剰余加算
k=k(1)|k(2)|…|k(m)
P=P(1)|P(2)|…|P(m)
L-1(k) =L(2n-k)
(注: L(-k)としても良いが、値を0~2n-1の範囲にするために2nを足した。)
即ち、
L-1(k)L(k)P=L(2n-k)[P(1)+k(1)|P(2)+k(2)|…|P(m)+k(m)]
=P(1)+k(1)+2n-k(1)|P(2)+k(2)+2n-k(2)|…|P(m)+k(m)+2n-k(m)
=P(1)+2n|P(2)+2n|…|P(m)+2n
=P(1)|P(2)|…|P(m)
(b-4)有限体上の乗算と加算の組合せ
L(k,q)P=k(1)*P(1)+q(1)|k(2)*P(2)+q(2)|…|k(m)*P(m)+q(m)
L-1(k,q) =L(k-1, 2n-k-1*q)
即ち、
L-1(k,q)L(k,q)P=L(k-1,2n-k-1*q)[k(1)*P(1)+q(1)|…]
=k(1)-1[k(1)*P(1)+q(1)]+(2n-k(1)-1*q(1))|…
=P(1)+k(1)-1*q(1)+2n-k(1)-1*q(1)|…
=P(1)+2n|…
=P(1)|…=P
 次に、本実施の形態にかかるデータ配信システムで行われる処理の手順について説明する。まず、配信開始ノードであるノード50が行う配信処理の手順について図9を用いて説明する。ノード50は、配信データを複数のピースに分割する(ステップS1)。そして、ノード50は、ピースを要求するピース要求を他のノード51から受信すると(ステップS2:YES)、乱数r,r0,r'0を生成する(ステップS3)。次いで、ノード50は、ステップS3で生成した乱数r,r0と固有情報格納部500に記憶された秘密鍵s0とを用いて関数Fにより対称鍵k,k0を生成する(ステップS4)。次いで、ノード50は、ステップS3で生成した乱数r'0と秘密鍵s0とを用いて関数Gにより変換パラメータk'0を生成する(ステップS5)。そして、ノード50は、ステップS4で生成した対称鍵kを用いて、送信対象となるピースPを暗号化する(ステップS6)。尚、送信対象となるピースをどのように決定するかは特に限定されない。次いで、ノード50は、暗号化したピース(暗号化ピース)E(k)Pに対して、ステップS5で生成した変換パラメータk'0を用いて関数Lにより暗号化ピースE(k)Pを変換する(ステップS7)。その後、ノード50は、ステップS7で変換した暗号化ピースL(k'0)E(k)Pを、対称鍵k0を用いて暗号化して新たな暗号化ピースE(k0)L(k'0)E(k)Pを出力する(ステップS8)。そして、ノード50は、ステップS2で受信されたピース要求を送信した他のノード51に対して、例えば図4に示されるように、固有情報格納部500に記憶されているノードIDID#0と、ステップS3で生成した乱数r,r0,r'0と、ステップS8で出力した暗号化ピースE(k0)L(k'0)E(k)Pとを送信する(ステップS9)。また、ノード50は、これらとは別に、ステップS4で生成した対称鍵k0を当該他のノード51に対して送信する(ステップS10)。その後ステップS2に戻り、ノード50は、新たなピース要求の受信を待機する。尚、ステップS2で受信されるピース要求は、同一のノード51であるとは限らず、当該ピース要求によって要求されるピースPは、同一のピースであるとは限らない。また、ステップS3で生成する乱数は基本的にステップS3の処理毎に異なる。
 次に、ノード51がノード50又は他のノード51から暗号化ピースを受信する受信処理の手順について図10を用いて説明する。ノード51は、ピースを要求するピース要求をノード50又は他のノード51に対して送信する(ステップS20)。次いで、ノード51は、ステップS20でピース要求を送信した相手であるノード50又は他のノード51から、ノードID列と、乱数列と、暗号化ピースとを受信し(ステップS21)、これらとは別に対称鍵を受信する(ステップS22)。そして、ノード51は、ステップS21で受信したノードID列、乱数列及び暗号化ピースと、ステップS22で受信した対称鍵とを対応付けて記憶する(ステップS23)。
 尚、ノード51がノード50にピース要求を送信した場合は、ステップS21ではピースPについて図4に示されるノードID列と、乱数列と、暗号化ピースとを受信する。ここで、図示はしないが、P2PネットワークNTに接続されるノードであって、fを1以上の整数として、f番目にピースPを受信するノードについて一般化して説明する。説明の便宜上、当該ノードのノードIDをID#fとする。ノードIDID#fが割り当てられたノードは、(f-1)番目のノードIDID#(f-1)が割り当てられたノードから、図11に示されるように、ピースPについて、ノードID列ID#0,…, ID#(f-1)と、乱数r,r0,r'0,…, r'f-1,rf-1と、暗号化ピースE(kf-1)L(k'f-1)…L(k'0)E(k)Pとを受信する。
 次に、配信開始ノード以外のノード51が行う配信処理の手順について図12を用いて説明する。ノード51は、ピースを要求するピース要求を他のノード51から受信すると(ステップS30:YES)、乱数を2つ生成する(ステップS31)。次いでノード51は、ステップS31で生成した乱数のうち1つと、固有情報格納部510に記憶された秘密鍵とを用いて関数Fにより対称鍵を生成する(ステップS32)。次いで、ノード51は、ステップS31で生成した乱数のうち対称鍵の生成に用いていない乱数と、秘密鍵とを用いて上述の関数Gにより変換パラメータを生成する(ステップS33)。また、ノード51は、データ格納部517に暗号化ピースと対応付けられて記憶された対称鍵を用いて当該暗号化ピースを復号する(ステップS34)。この結果半復号ピースが得られる。その後、ノード51は、ステップS34で得た半復号ピースを、ステップS33で生成した変換パラメータを用いて変換する(ステップS35)。そして、ノード51は、ステップS35で変換した半復号ピースを、ステップS32で生成した対称鍵を用いて暗号化して、新たな暗号化ピースを出力する(ステップS36)。その後ノード51は、ステップS30で受信されたピース要求を送信した他のノード51に対して、送信対象である暗号化ピースに対応付けられてデータ格納部517に記憶されたノードIDに加え固有情報格納部510に記憶されたノードIDを含む新たなノードID列と、当該暗号化ピースに対応付けられてデータ格納部517に記憶された乱数列に加えステップS31で生成した乱数を含む新たな乱数列と、ステップS36で出力した新たな暗号化ピースとを送信する(ステップS37)。また、ノード51は、これらとは別に、ステップS32で生成した対称鍵を当該他のノード51に対して送信する(ステップS38)。
 例えば、上述したノードIDID#fが割り当てられたノードは、ステップS36では、(f+1)番目となるノードIDID#(f+1)が割り当てられたノードに対して、図13に示されるように、ピースPについて、ノードID列ID#0,…, ID#(f-1),ID#fと、乱数列r,r0,r’0,…, rf-1,r’f-1,rf,r’fと、暗号化ピースE(kf)L(k'f)L(k'f-1)…L(k'0)E(k)Pとを送信する。
 次に、ノード51が鍵サーバ53から復号鍵を取得しこれを用いて暗号化ピースを復号する復号処理の手順について図14を用いて説明する。ノード51は、データ格納部517に記憶された暗号化ピースに対応付けられているノードID列及び乱数列を読み出し(ステップS40)、当該暗号化ピースを逆変換し復号するための復号情報を要求すると共に、当該ノードID列及び乱数列を含む鍵要求を鍵サーバ53に送信する(ステップS41)。次いで、ノード51は、ステップS40で送信された鍵要求に応じて鍵サーバ53から送信された2つの対称鍵及び集約パラメータを含む復号情報を受信する(ステップS42)。2つの対称鍵とは、上述したように、ノード50が生成した対称鍵のうちピースの暗号化に最初に用いられた対称鍵と、最終ノードが生成した対称鍵であり最後の暗号化に用いられた対称鍵とである。ノード51は、まず、受信した対称鍵のうち、最終ノードが生成した対称鍵を用いて、暗号化ピースを復号する(ステップS43)。この結果半復号ピースが得られる。次いで、ノード51は、ステップS43で得た半復号ピースに対して、ステップS42で受信した集約パラメータを用いて関数L-1により逆変換を行う(ステップS44)。その後、ノード51は、ステップS44で逆変換を行った半復号ピースを、ステップS43で受信した対称鍵のうち、ノード50が生成した対称鍵を用いて復号する(ステップS45)。この結果、利用可能なピースが得られる。
 例えば、上述したノードIDID#(f+1)が割り当てられたノードは、鍵サーバ53に対して、図15に示されるように、ピースPについて、ノードID列ID#0,…,ID#(f-1),ID#fと、乱数列r,r0, r'0,…,rf-1, r'f-1,rf,r'fとを送信する。そして、当該ノードは、鍵サーバ53から、図16に示されるように、ピースPについて、対称鍵k,…,kf-1及び集約パラメータ「k'*f-1=H(k'f-1,…,k'0)」を含む復号情報を受信し、これを用いて暗号化ピースE(kf)L(k'f)L(k'f-1)…L(k'0)E(k)Pを復号して、ピースPを得る。このようにして、各ノード51は、複数のピースのそれぞれが暗号化された各暗号化ピースについて鍵要求によって各対称鍵及び集約パラメータを含む復号情報を鍵サーバ53から受信し、各暗号化ピースを復号することにより、上述の配信データを得ることができる。
 次に、鍵サーバ53がノード51からの鍵要求に応じて復号情報を送信する復号情報送信処理の手順について図17を用いて説明する。鍵サーバ53は、暗号化ピースを逆変換し復号するための復号情報を要求すると共に、ノードID列及び乱数列を含む鍵要求をノード51から受信すると(ステップS50:YES)、受信した鍵要求に含まれるノードID列に含まれる各ノードIDに対応付けられて秘密鍵格納部530に記憶されている秘密鍵をノードID毎に読み出す(ステップS51)。そして、鍵サーバ53は、配信開始ノードであるノード50が生成した乱数のうち最初の暗号化に用いた対称鍵の生成に用いた乱数及び最終ノードが生成した乱数のうち対称鍵の生成に用いた乱数を用いて関数Fにより2つの対称鍵を生成する(ステップS52)。2つの対称鍵とは、上述したように、ノード50が生成した対称鍵のうちピースの暗号化に最初に用いられた対称鍵と、最終ノードが生成した対称鍵であり最後の暗号化に用いられた対称鍵とである。そして鍵サーバ53は、ノードID列に含まれる各ノードIDに対応付けられている秘密鍵と、鍵要求に含まれる、各ノードIDに対応する乱数列とを用いて、上述の関数Gにより変換パラメータをノードID毎に各々生成する(ステップS53)。次いで、鍵サーバ53は、ステップS53で生成した全ての変換パラメータを用いて、関数Hによりこれらの変換パラメータを1つの値に集約して、集約パラメータを生成する(ステップS54)。その後、鍵サーバ53は、ステップS52で生成した対称鍵及びステップS54で生成した集約パラメータを含む復号情報を、ステップS50で受信した鍵要求を送信したノード51に対して送信する(ステップS55)。
 例えば、鍵サーバ53は、上述したノードIDID#(f+1)が割り当てられたノードに対して、ピースPについて、図15に示されるようなノードID列及び乱数列を含む鍵要求に応じて、図16に示されるような対称鍵k,kf-1及び集約パラメータH(k'f-1,…,k'0)を送信する。
 以上のような構成によって、各ノード50,51がピースを送信する度に、当該ピースに基本的に一度限りの対称鍵を用いて暗号化を行うが、暗号化を単純に重ねるのではなく、ピースに対する最後の暗号化に用いられた対称鍵を用いて、暗号化を一旦解いてから、一時的に生成した変換パラメータを用いて変換を行い、新たに生成した対称鍵を用いて暗号化を行う。即ち、あるノード51が取得した暗号化ピースは、配信開始ノードが最初に行った暗号化と、当該暗号化ピースの送信を仲介したノード51が各々重ねて行った変換と、当該ノードに当該暗号化ピースを最後に暗号化して送信した最後ノードが行った暗号化とが行われた状態となる。暗号化ピースが送信される過程で各ノード50,51により各々重ねて行われる変換のシーケンスは、配信経路に応じて様々なものとなる。また、複数のピースのそれぞれが暗号化された全ての暗号化ピースの組み合わせについてみれば、暗号化ピースが異なれば配信経路が各々異なる可能性が高いため、各暗号化ピースにおいて行われている変換のシーケンスも各々異なっている可能性が高い。また、異なる暗号化ピースの配信経路が同じ場合、各暗号化ピースに対応付けられるノードIDの組み合わせは同じになるが、各ノードで暗号化に用いる対称鍵はその都度異なり得る。このため、配信経路が仮に同一であっても、暗号化を解くための対称鍵は各々異なり得る。以上のように、ノード毎及びピース毎に配信経路は異なり得るため、あるノードが取得する暗号化ピースの組み合わせは配信経路と配信時期とに固有のものとなり、確実に一意となり得る。また、いずれのノード51であっても、ピースに対する最初の暗号化及び最後の暗号化を解くための復号2回と、集約パラメータを用いた逆変換1回との計算で暗号化ピースを利用可能な状態に復号することができ、復号及び逆変換にかかる計算量を一定にすることができる。従って、ノード51の処理負担を軽減させることができる。また、暗号化に用いる対称鍵を、乱数を用いて生成することで基本的に一度限りのものとするため、対称鍵の漏洩による影響を低減することができる。
 従って、以上のような構成によれば、P2P配信において配信方法に関する特別な工夫をしなくても、各ノードが取得する各暗号化ピースの組み合わせについてノード毎の一意性を確実に高めることができ、安全性を向上させることができる。更に、データの保護とデータの配信方法との独立性を維持することが可能になり、システム構築上の自由度を向上させることが可能になり、更に、通信装置における計算の効率を向上可能になる。
[変形例]
 なお、本発明は前記実施形態そのままに限定されるものではなく、実施段階ではその要旨を逸脱しない範囲で構成要素を変形して具体化できる。また、前記実施形態に開示されている複数の構成要素の適宜な組み合わせにより、種々の発明を形成できる。例えば、実施形態に示される全構成要素から幾つかの構成要素を削除してもよい。さらに、異なる実施形態にわたる構成要素を適宜組み合わせてもよい。また、以下に例示するような種々の変形が可能である。
 上述した実施の形態において、各ノード50で実行される各種プログラムを、インターネット等のネットワークに接続されたコンピュータ上に格納し、ネットワーク経由でダウンロードさせることにより提供するように構成しても良い。また当該プログラムを、インストール可能な形式又は実行可能な形式のファイルでCD-ROM、フレキシブルディスク(FD)、CD-R、DVD(Digital Versatile Disk)等のコンピュータで読み取り可能な記録媒体に記録して提供するように構成しても良い。この場合には、プログラムは、各ノード50において上記記録媒体から読み出して実行することにより主記憶装置(例えばRAM)上にロードされ、上記機能的構成において説明した各部が主記憶装置上に生成される。鍵サーバ53で実行される各種プログラムについても同様である。
 また、上述した実施の形態において、各ノード50の機能的構成において説明した各部のうち全部又は一部をハードウェアにより構成しても良い。鍵サーバ53の機能的構成において説明した各部のうち全部又は一部についても同様である。
 上述した実施の形態において、ノードIDは、各ノードを一意に識別可能な情報であれば良く、例えば、各ノードのIPアドレスや、MACアドレスや、URLなどであっても良い。
 上述した実施の形態のデータ配信システムにおいては、配信開始ノードの数は複数であっても良い。また、P2PネットワークNTに接続されるこの他のノードの数も特に限定されない。
 上述の実施の形態においては、1つのピース要求によって複数のピースが要求されるようにしても良い。この場合、ノード50,51は、複数のピースのそれぞれについて上述したように暗号化ピース、ノードID列及び乱数列の組を、ピース要求を送信した他のノード51に送信すれば良い。
 また、上述の実施の形態においては、ノード50,51は、ピース要求に応じて暗号化ピースを送信する構成としたが、これに限らず、ピース要求を受信しなくとも、他のノード51に暗号化ピースと共にIDノード列及び乱数列を送信するようにしても良い。
 上述の実施の形態においては、ノード51は、配布データを構成する全てのピースについて暗号化ピースが取得されデータ格納部517に記憶された場合に、各暗号化ピースを逆変換し復号するための各復号情報を要求する鍵要求を鍵サーバ53に送信するようにしても良い。又は、ノード51は、配布データを構成する全てのピースについて暗号化ピースが取得されていない場合であっても、データ格納部517に記憶された暗号化ピースに対する鍵要求を鍵サーバ53に送信するようにしても良い。また、ノード51は、1つの鍵要求によって、1つの暗号化ピースを逆変換し復号するための復号情報を要求するようにしても良いし、複数の暗号化ピースを各々逆変換し復号するための各復号情報を要求するようにしても良い。
 上述の実施の形態においては、ピースの暗号化には、暗号鍵でもあり、暗号化を復号するための復号鍵でもある対称鍵を用いた。しかし、ピースの暗号化に用いる暗号鍵と、暗号化ピースに対して行われている暗号化を復号するための復号鍵とは各々別であるとしても良い。
 また、上述の実施の形態においては、ノード50,51は、データ格納部517に記憶された暗号化ピースを他のノード51に送信する場合、その都度、乱数を生成するようにした。しかし、ノード50,51は、乱数をその都度生成するのではなく、例えば、暗号化ピースの送信回数に応じて発生させるようにしても良い。例えば、ノード50,51は、暗号化ピースの送信を所定の回数(例えば5回)行う毎に新たな乱数を生成するようにしても良い。また、ノード50,51が乱数を生成するタイミングは、他のノード51からピース要求を受信したときであっても良いし、所定の時間毎であっても良い。
 また、上述の実施の形態においては、ノード51は、データ格納部517に記憶された暗号化ピースを暗号化して他のノード51に送信する場合、当該暗号化ピースのデータの全部ではなく一部のデータについて暗号化するようにしても良い。この場合、当該暗号化ピースの配信を仲介する各ノード51が暗号化するデータが、同じく当該暗号化ピースの配信を仲介する他のノード51が暗号化するデータと重複部分が生じるように、各ノード51は当該暗号化ピースの一部のデータを暗号化するようにすれば良い。このような構成によれば、各ノード51が行う暗号化に関する処理負担を軽減させることができると共に、暗号化部分を重複させることにより、復号鍵が暴露された場合の影響を抑制することが可能になる。
 上述の実施の形態においては、ノード51が他のノード51に暗号化ピースと共に送信するノードID列及び乱数列は、図5,11,13に示される形態に限らない。例えば、(ID#0,r0),(ID#1,r1)…(ID#f,rf)などのように、ノードIDと当該ノードIDに対応する乱数との組をノードID毎に示す形態であっても良い。
 上述の実施の形態においては、各ノード50,51に一意に割当られた秘密情報として秘密鍵を用いたが、これに限らない。
 また、上述の実施の形態においては、秘密鍵は、各ノード50,51に一意に割当られているとしたが、これに限らない。例えば、各ノード50,51のうち一部のノードに同一の秘密鍵が割り当てられるようにしても良い。
 上述の実施の形態においては、上述した暗号化ピース、ノードID列及び乱数列をパッケージ化したパッケージデータの形態で配布されるように構成しても良い。この場合、パッケージデータはコンピュータで読み取り可能な記録媒体に記録されてノードに提供されるようにしても良いし、サーバを介してノードにダウンロードされるように構成しても良い。当該パッケージデータを取得したノードは、ピース要求に応じて、上述の実施の形態と同様にして、当該パッケージデータに含まれる暗号化ピースに対して暗号化を選択的に行った暗号化ピースと、パッケージデータに含まれるノードID及び自身のノードIDと、パッケージデータに含まれる乱数列及び自身が生成した乱数とを他のノードに送信すれば良い。
 上述した実施の形態においては、ID列、乱数列及び暗号化ピースの送信と、対称鍵の送信とを分けるようにしたが、ノード50,51は、これらを同時に送信するようにしても良い。
 上述した実施の形態においては、変換パラメータの生成に用いる乱数と、対称鍵の生成に用いる乱数とを異なるようにした。しかし、ノード50,51は、変換パラメータ及び対称鍵を同一の乱数を用いて生成しても良い。
 上述した実施の形態においては、鍵サーバ53は、集約パラメータと、ピースに対する最初の暗号化に用いられた対称鍵と、最後の暗号化に用いられた対称鍵とを含む復号情報をノード51に送信するようにした。しかし、鍵サーバ53は、最後の暗号化に用いられた対称鍵を含まず、集約パラメータと、ピースに対する最初の暗号化に用いられた対称鍵とを含む復号情報をノード51に送信するようにしても良い。
 上述の実施の形態においては、コンテンツを構成する各ピースに対しては、1回又は2回の暗号化が行われている状態にしたが、3回以上の暗号化が多重に行われている状態にするコンテンツ配信システムに本実施の形態を適用にするようにしても良い。
 ここでまず、ピースを複数の暗号鍵で3回以上多重に暗号化するコンテンツ配信システムについて説明する。各ノード50,51には、上述の実施の形態と同様に秘密鍵及びノードIDが各々割り当てられており、ノード50,51は、例えば、自身に割り当てられた秘密鍵を暗号鍵として用いて、自身が分割したピース又は他のノード50,51から受信した暗号化ピースを暗号化して、暗号化したものをその他のノード51に送信する。このように、暗号化ピースが各ノード50,51から送信される度に暗号化が施されるようにする。具体的には、例えば、配信開始ノードであるノード50は、他のノード51からピース要求を受信すると、秘密鍵を用いてピースを暗号化した後、暗号化ピースと自身に割り当てられたノードIDとを当該他のノード51に送信する。ノード51は、暗号化ピース及びノードIDを対応付けて記憶する。そして、ノード51は、他のノード51からピース要求を受信すると、自身に割り当てられた秘密鍵を用いて暗号化ピースを更に暗号化して新たな暗号化ピースを出力し、当該暗号化ピースと対応付けて記憶したノードID及び自身に割り当てられたノードIDと新たな暗号化ピースを他のノード51に送信する。他のノード51においても同様にピース要求を受信した場合には、送信対象の暗号化ピースに対して更なる暗号化を行って、当該暗号化ピースと対応付けて記憶したノードID及び自身に割り当てられたノードIDと新たな暗号化ピースとを送信する。
 尚、ノード50,51に割り当てられた秘密鍵SA自体を、暗号化ピースを暗号化するための暗号鍵として用いる必要は必ずしもなく、例えば、ノード50,51が生成した乱数RAを用いて、ハッシュ値H(SA||RA)を計算してこれを暗号鍵としても良いし、関数により暗号鍵F(SA,RA)を計算しても良い。この場合、ノード50,51は、暗号鍵の計算に用いた乱数RAも、ピース要求を送信した他のノード51に送信する。当該他のノード51は、暗号化ピースを更に暗号化してその他のノード51に送信する場合、当該暗号化ピースと共に受信した乱数と自身が生成した乱数とをあわせてその他のノード51に送信する。
 また、ノード50,51は暗号化ピース全体を暗号化する必要は必ずしもなく、暗号化ピースの一部分のみを暗号化しても良い。この場合、ノード50,51は、暗号化ピースのどの部分を暗号化したかに関する情報(例えば、暗号化ピースの先頭(0番目のデータとする)から32バイト分のデータを暗号化した場合には(0,31))を他のノード51に送信する。当該他のノード51は、暗号化ピースを更に暗号化してその他のノード51に送信する場合、当該暗号化ピースと共に受信した、暗号化ピースのどの部分を暗号化したかに関する情報と自身が暗号化ピースのどの部分を暗号化したかに関する情報をあわせてその他のノード51に送信する。この際、暗号化ピースに暗号化を行ったノード50,51の順番が分かるように、例えば、ノード51Aの次にノード51Bが暗号化したことが分かるように、暗号化ピースのどの部分を暗号化したかに関する情報を順番に並べていく。ここで、例えば、ピースの長さを128バイトとして、配信開始ノードであるノード50はピース全体(例えば128バイト分のデータ)を暗号化し、次に暗号化ピースを受信したノード51Aは先頭から16バイト分のデータを暗号化し、ノード51Aから暗号化ピースを受信したノード51Bは先頭から16バイト飛ばした次の16バイトのデータを暗号化する、というように暗号化ピースを受信した順番によってデータのどの部分を暗号化するかを予め定めるようにしても良い。この場合、暗号化ピースのどの部分を暗号化したかに関する情報に代えて、暗号化ピースがいくつのノードを経由してきたかに関する情報を用いれば良い。この情報は、ノード51が暗号化ピースを受信したノードが、例えば配信開始ノードである場合‘0’であり、ノード51Aである場合‘1’、ノード51Bである場合‘2’である。例えば、ノード51Bは、ノード51Aから暗号化ピースを受信すると、この情報を‘1’から‘2’に上書きする。
 また、ピースを複数の暗号鍵で多重に暗号化する場合、ノード50,51が鍵サーバ53へ送信する上述の要求メッセージには、暗号化ピースが経由してきた全てのノードのノードIDを含ませる。また、上述のように暗号鍵の生成に乱数を用いる場合、上述の要求メッセージには暗号化ピースが経由してきた全てのノードの乱数を含ませる。同様に、暗号化ピースのどの部分を暗号化したかに関する情報が含まれていても良いし、暗号化ピースがいくつのノードを経由してきたかに関する情報を含んでいても良い。
 一方、ピースを複数の暗号鍵で多重に暗号化する場合の鍵サーバ53は以下の通りである。鍵サーバ53は、上述の実施の形態と同様に、各ノード50,51に割り当てられた秘密鍵を保持している。鍵サーバ53は、ノード51から要求メッセージを受信すると、暗号化ピースが経由してきた全てのノード50,51のノードIDから、暗号化ピースが経由してきた各ノード50,51に割り当てられた秘密鍵を検索し、これらを鍵束として取得する。上述のように暗号鍵の生成に乱数を用いる場合、鍵サーバ53は、暗号化ピースが経由してきた各ノード50,51に割り当てられた秘密鍵と、それに対応するノードの乱数とを用いて復号鍵を各々計算し(上述の例においてはH(SA||A)又はF(SA, RA)である)、計算結果を鍵束として取得する。尚、鍵サーバ53が各ノード50,51に割り当てられた秘密鍵を保持している必要は必ずしもなく、例えば、ノード50,51(ノードIDの値をLIDAとする)に割り当てられた秘密鍵が‘SA=H(Kmaster||LIDA)又はSA=F(Kmaster,LIDA)’と定められている場合、鍵サーバ53はKmasterの値と関数H又はFのアルゴリズムのみを知っていれば良く、要求メッセージに含まれているLIDからそのノードIDの対応するノード50,51に割り当てられた秘密鍵を計算することができる。
 次に、このようなコンテンツ配信システムの構成において、本実施の形態にかかる構成を適用する例について説明する。例えば、ノード51は、他のノード51からピース要求を受信すると、送信対象の暗号化ピースに対して行われた暗号化の回数が所定回数以上である場合に、当該暗号化ピースに対して上述の変換を行い1回の暗号化を行った後に当該暗号化ピースを他のノード51に送信する。具体的には、ノード51は、送信対象の暗号化ピースと対応付けて記憶したノードIDの数が所定数以上であるか否かを判定し、当該ノードIDの数が所定数以上である場合に、上述の実施の形態と同様にして乱数を生成して対称鍵及び変換パラメータを生成し、当該暗号化ピースに対して上述の実施形態と同様の変換を行い、生成した対称鍵を用いて、変換後の暗号化ピースを暗号化して、新たな暗号化ピースを出力する。そして、ノード51は、当該暗号化ピースと対応付けて記憶したノードID及び自身に割り当てられたノードIDと、自身が生成した乱数と、新たな暗号化ピースとを他のノード51に送信し、これらとは別に、自身が生成した対称鍵を他のノード51に送信する。一方、他のノード51は、受信した暗号化ピースをノードID、乱数及び対称鍵と対応付けて記憶する。当該他のノード51がその他のノード51に暗号化ピースを送信する場合には、当該他のノード51は、上述の実施の形態と同様にして乱数を生成して対称鍵及び変換パラメータを生成し、当該暗号化ピースと対応付けられて記憶された対称鍵を用いて当該暗号化ピースを1回復号し、復号した暗号化ピースに対して上述の実施形態と同様の変換を行い、生成した対称鍵を用いて、変換後の暗号化ピースを暗号化して、新たな暗号化ピースを出力する。そして、当該他のノード51は、当該暗号化ピースと対応付けて記憶したノードID及び自身に割り当てられたノードIDと、自身が生成した乱数と、新たな暗号化ピースとをその他のノード51に送信し、これらとは別に、自身が生成した対称鍵をその他のノード51に送信する。
 以上のような構成によれば、ピースの暗号化を3回以上重ねて行うコンテンツ配信システムにおいて、暗号化の回数を一定の回数以下に抑えることができるため、ピースの復号の際の復号の回数も一定の回数以下に抑えることができる。従って、多重に暗号化することによる安全性の向上と、復号の際の計算の効率の向上とを両立させることができる。
 尚、ピースを3回以上多重に暗号化する場合、ノード50,51から送信される度にではなく、各ノード50,51において、暗号化ピースに暗号化を重ねるか否かが所定の確率に従って決定されて、当該暗号化ピースについての更なる暗号化が選択的に行われるようにしても良い。このようなコンテンツ配信システムに本実施の形態にかかる構成を適用する場合、例えば、ノード51は、送信対象の暗号化ピースと対応付けて記憶したノードIDの数に所定の確率を乗算した値が所定数以上であるか否かを判定し、当該値が所定数以上である場合に、上述の実施の形態と同様にして乱数を生成して対称鍵及び変換パラメータを生成し、当該暗号化ピースに対して上述の実施形態と同様の変換を行い、生成した対称鍵を用いて、変換後の暗号化ピースを暗号化して、新たな暗号化ピースを出力すれば良い。
 上述の実施の形態においては、各ピースは、配信開始ノードであるノード50によって暗号化された後、変換パラメータを用いて変換され、変換され暗号化されたピースを受信したノード51によって、変換パラメータを用いて変換された後、対称鍵を用いて暗号化されるようにした。しかし、各ノード50,51は、各ピースを暗号化せずに上述の変換のみ行うようにしても良い。この場合、各ノード50,51は、対称鍵を生成することなく、変換したピースを、上述のノードID列及び乱数列と共に他のノード51に送信する。また、鍵サーバ53は、上述の実施形態と同様に鍵要求をノード51から受信すると、対称鍵を生成することなく、上述と同様にして集約パラメータを生成して、当該集約パラメータを含む復号情報を当該ノード51に対して送信する。そして、各ノード51は、復号情報に含まれる集約パラメータを用いて、ピースを逆変換すれば良い。
50,51,51A,51B ノード
53 鍵サーバ
500 固有情報格納部
501 乱数生成部
502 対称鍵生成部
503 ピース暗号化部
504 ピース化部
505 データ送信部
506 送信要求受付部
507 パラメータ生成部
508 変換部
510 固有情報格納部
511 乱数生成部
512 対称鍵生成部
513 ピース暗号化部
514 データ受信部
515 データ送信部
516 送信要求受付部
517 データ格納部
518 送信要求送信部
519 鍵要求送信部
520 ピース復号部
521 変換部
522 逆変換部
523 パラメータ生成部
530 秘密鍵格納部
531 データ受信部
532 パラメータ生成部
533 対称鍵生成部
534 データ送信部

Claims (25)

  1.  データの一部であるピースを送信する通信装置であって、
     他の通信装置によって可逆に変換された第1ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置によって生成された第1一時情報とを受信する受信手段と、
     前記第1ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶する第1記憶手段と、
     当該通信装置に割り当てられた第2装置識別情報を記憶する第2記憶手段と、
     その生成毎に異なり得る第2一時情報を生成する第1生成手段と、
     前記第2一時情報を用いて、前記第1ピースを変換して、第2ピースを出力する変換手段と、
     前記第2ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信手段とを備える
    ことを特徴とする通信装置。
  2.  前記第2一時情報を用いて、変換を行う際に用いる変換パラメータを生成する第2生成手段を更に備え、
     前記変換手段は、各変換パラメータを1つの値に集約した変換パラメータを用いて変換を行った結果と、各変換パラメータを用いて重ねて変換を行った結果とが同一となり且つ集約された変換パラメータを用いて逆変換が可能である可逆な変換を、復号された前記第1暗号化ピースに対して、前記第2生成手段が生成した前記変換パラメータを用いて行う
    ことを特徴とする請求項1に記載の通信装置。
  3.  前記変換手段は、
     各変換パラメータがk1,…,km(m:2以上の自然数)であり、各変換パラメータk1,…,kmが関数Hにより1つの値に集約され、集約された変換パラメータがH(k1,…,km)であるとき、
    L(k1)…L(km)=L(H(k1,…,km))
    を満たす関数Lにより変換を、前記第1ピースに対して、前記第2生成手段が生成した前記変換パラメータki(1≦i≦m)を用いて行う
    ことを特徴とする請求項2に記載の通信装置。
  4.  前記第1ピースは、前記他の通信装置によって可逆に変換され且つ暗号化されており、
     前記受信手段は、前記第1ピースと、前記第1装置識別情報と、前記第1一時情報と、前記第1一時情報を用いて生成され前記第1ピースの暗号化に用いられた第1対称鍵とを受信し、
     前記第1記憶手段は、前記第1ピースと、前記第1装置識別情報と、前記第1一時情報と、前記第1対称鍵とを対応付けて記憶し、
     前記第2一時情報を用いて、第2対称鍵を生成する第3生成手段と、
     前記第1ピースと対応付けられて記憶された前記第1対称鍵を用いて、当該第1ピースを復号する第1復号手段と、
     前記第2一時情報を用いて、復号された前記第1暗号化ピースを変換する変換手段と、
     変換された前記第1ピースを、前記第2対称鍵を用いて暗号化して、前記第2ピースを出力する暗号化手段とを更に備え、
     前記送信手段は、前記第2ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報と、前記第2対称鍵とを送信する
    ことを特徴とする請求項2又は3に記載の通信装置。
  5.  前記第1生成手段は、2つの前記第2一時情報を生成し、
     前記第2生成手段は、2つの前記第2一時情報のうち他方を用いて、前記変換パラメータを生成し、
     前記第3生成手段は、2つの前記第2一時情報のうち一方を用いて、前記第2対称鍵を生成する
    ことを特徴とする請求項3又は4に記載の通信装置。
  6.  前記第2記憶手段は、当該通信装置に一意に割り当てられている秘密情報を更に記憶し、
     前記第3生成手段は、前記第2一時情報と前記秘密情報とを用いて前記対称鍵を生成する
    ことを特徴とする請求項4に記載の通信装置。
  7.  前記第2生成手段は、前記第2一時情報と前記秘密情報とを用いて前記変換パラメータを生成する
    ことを特徴とする請求項5に記載の通信装置。
  8.  前記受信手段は、前記第1ピース、前記第1装置識別情報及び前記第1一時情報と、前記第1対称鍵とを異なるタイミングで受信する
    ことを特徴とする請求項4乃至7のいずれか一項に記載の通信装置。
  9.  前記変換パラメータを暗号化して第3記憶手段に記憶させる第1記憶制御手段を更に備える
    ことを特徴とする請求項2乃至8のいずれか一項に記載の通信装置。
  10.  前記第1対称鍵を暗号化して、前記第1ピース、前記第1装置識別情報及び前記第1一時情報とを対応付けて前記第1記憶手段に記憶させること及び前記第2対称鍵を暗号化して第4記憶手段に記憶させることのうち少なくとも一方を行う第2記憶制御手段を更に備える
    ことを特徴とする請求項4乃至9のいずれか一項に記載の通信装置。
  11.  前記ピースを要求するピース要求を受信する要求受信手段を更に備え、
     前記第1生成手段は、前記ピース要求が受信された場合に、前記第2一時情報を生成する
    ことを特徴とする請求項1乃至10のいずれか一項に記載の通信装置。
  12.  データの一部であるピースを受信する通信装置であって、
     当該通信装置に割り当てられている装置識別情報を記憶する第1記憶手段と、
     他の通信装置によって可逆に変換されたピースと、当該他の通信装置に割り当てられている装置識別情報と、当該他の通信装置によって生成された一時情報とを受信する第1受信手段と、
     前記ピース、前記装置識別情報及び前記一時情報を対応付けて記憶する第2記憶手段と、
     前記ピースを逆変換するための復号情報を要求すると共に、当該ピースと対応付けられて記憶された前記装置識別情報及び前記一時情報を対応付けて含む鍵要求を鍵サーバへ送信する送信手段と、
     前記鍵要求に応じて前記鍵サーバから、前記復号情報を受信する第2受信手段と、
     受信された前記復号情報を用いて前記ピースを逆変換する逆変換手段とを備える
    ことを特徴とする通信装置。
  13.  前記ピースは、可逆に変換され且つ暗号化されており、
     前記第1受信手段は、前記他の通信装置によって、前記一時情報を用いて生成された変換パラメータを用いて変換された後、前記一時情報を用いて生成された対称鍵を用いて暗号化された前記ピースと、前記装置識別情報と、前記一時情報とを受信する
    ことを特徴とする請求項12に記載の通信装置。
  14.  前記一時情報は、前記他の通信装置によって2つ生成され、
     前記第1受信手段は、前記他の通信装置によって、2つの前記一時情報のうち一方を用いて生成された変換パラメータを用いて変換された後、2つの前記一時情報のうち他方を用いて生成された対称鍵を用いて暗号化された前記ピースと、前記装置識別情報と、2つの前記一時情報とを受信する
    ことを特徴とする請求項13に記載の通信装置。
  15.  前記ピースは、ピースを最初に暗号化するその他の通信装置によって、第1対称鍵を用いて暗号化された後、第1変換パラメータを用いて変換され、前記他の通信装置によって、第2変換パラメータを用いて変換された後、第2対称鍵を用いて暗号化されており、
     前記暗号化ピースに対して行われた変換は、各変換パラメータを1つの値に集約した変換パラメータを用いて変換を行った結果と、各変換パラメータを用いて重ねて変換を行った結果とが同一となり且つ集約された変換パラメータを用いて逆変換が可能なものであり、
     前記第1受信手段は、前記ピースと、前記その他の通信装置の前記装置識別情報及び前記他の通信装置の前記装置識別情報と、前記その他の通信装置が生成した前記一時情報及び前記他の通信装置が生成した前記一時情報と、前記第2対称鍵とを受信し、
     前記第2受信手段は、前記第1変換パラメータ及び前記第2変換パラメータが集約された変換パラメータと、前記第1対称鍵とを含む前記復号情報を前記鍵サーバから受信する
    ことを特徴とする請求項13又は14に記載の通信装置。
  16.  前記第2受信手段は、前記第2対称鍵を更に含む前記復号情報を前記鍵サーバから受信する
    ことを特徴とする請求項15に記載の通信装置。
  17.  前記逆変換手段は、
     前記第1対称鍵を用いて、前記ピースを復号する第1ピース復号手段と、
     前記復号情報に含まれる前記変換パラメータを用いて、復号された前記ピースを逆変換するピース逆変換手段と、
     前記第2対称鍵を用いて、逆変換された前記ピースを復号する第2ピース復号手段とを有する
    ことを特徴とする請求項15又は16に記載の通信装置。
  18.  データの一部であるピースを送信する複数の他の通信装置のそれぞれに割り当てられた秘密情報と、各通信装置に割り当てられた装置識別情報とを各々対応付けて記憶する第1記憶手段と、
     可逆に変換された前記ピースを逆変換するための復号情報を要求すると共に、前記複数の他の通信装置の前記装置識別情報及び当該複数の他の通信装置が各々生成した情報であってその生成毎に異なり得る一時情報とを対応付けて含む要求を第1通信装置から受信する受信手段と、
     前記要求に含まれる各前記装置識別情報に対応付けられて記憶されている前記秘密情報と、当該各装置識別情報と対応付けられて前記要求に含まれる各前記一時情報とを用いて、逆変換を行う際に用いる変換パラメータを生成する第1生成手段と、
     前記変換パラメータを含む前記復号情報を前記第1通信装置に送信する送信手段とを備える
    ことを特徴とするサーバ。
  19.  前記ピースに対して行われた変換は、各変換パラメータを1つの値に集約された変換パラメータを用いて変換を行った結果と、各変換パラメータを用いて重ねて変換を行った結果とが同一となり且つ集約された変換パラメータを用いて逆変換が可能なものであり、
     前記第1生成手段は、
     前記要求に含まれる各前記装置識別情報に対応付けられて記憶されている前記秘密情報と、当該各装置識別情報と対応付けられて前記要求に含まれる各前記一時情報とを用いて、前記変換パラメータを前記装値識別情報毎に各々生成する第1パラメータ生成手段と、
     生成された各前記変換パラメータを、当該各変換パラメータを用いて各変換を重ねて行った結果と、当該各変換パラメータを1つの値に集約した変換パラメータを用いて変換を行った結果とが同一となるように、1つの値に集約する集約手段とを有し、
     前記送信手段は、集約された前記変換パラメータを含む前記復号情報を前記第1通信装置に送信する
    ことを特徴とする請求項18に記載のサーバ。
  20.  前記ピースは、可逆に変換され且つ暗号化されており、
     前記複数の他の通信装置のうち前記ピースを最初に暗号化した第2通信装置が生成した前記一時情報と、当該第2の通信装置に対応する前記秘密情報とを用いて、第1対称鍵を生成する第2生成手段を更に備え、
     前記送信手段は、前記変換パラメータ及び前記第1対称鍵を含む前記復号情報を前記第1通信装置に送信する
    ことを特徴とする請求項18又は19に記載のサーバ。
  21.  前記複数の他の通信装置のうち前記ピースを最後に暗号化した第3通信装置が生成した前記一時情報及び当該第3通信装置に対応する前記秘密情報を用いて、第2対称鍵を生成する第3生成手段を更に備え、
     前記送信手段は、前記変換パラメータ、前記第1対称鍵及び前記第2対称鍵を含む前記復号情報を前記第1通信装置に送信する
    ことを特徴とする請求項20に記載のサーバ。
  22.  前記一時情報は、前記複数の他の通信装置毎に各々複数生成され、
     前記複数の他の通信装置の各々において、前記一時情報のうち1つを用いて前記対称鍵が生成され、
     前記複数の他の通信装置の各々において、前記一時情報のうち前記対称鍵の生成に用いられていない一時情報を用いて前記変換パラメータが生成され、
     前記第1生成手段は、前記要求に含まれる各前記装置識別情報に対応付けられて記憶されている前記秘密情報と、当該各装置識別情報と対応付けられて前記要求に含まれる前記一時情報のうち前記変換パラメータの生成に用いられた前記一時情報とを用いて、逆変換を行う際に用いる変換パラメータを生成し、
     前記第2生成手段は、前記第2通信装置が前記第1対称鍵の生成に用いた前記一時情報と、当該第2の通信装置に対応する前記秘密情報とを用いて、前記第1対称鍵を生成する
    ことを特徴とする請求項20又は21に記載のサーバ。
  23.  データの一部であるピースを送信する通信装置で実行される通信方法であって、
     他の通信装置によって可逆に変換された第1ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置によって生成された第1一時情報とを受信する受信ステップと、
     前記第1ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶手段に記憶させる記憶制御ステップと、
     その生成毎に異なり得る第2一時情報を生成する生成ステップと、
     前記第2一時情報を用いて、前記第1ピースを変換して、第2ピースを出力する変換ステップと、
     前記第2ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信ステップとを含む
    ことを特徴とする通信方法。
  24.  データの一部であるピースを送信する通信装置の有するコンピュータに実行させるためのプログラムであって、
     他の通信装置によって可逆に変換された第1ピースと、当該他の通信装置に割り当てられた第1装置識別情報と、当該他の通信装置によって生成された第1一時情報とを受信する受信ステップと、
     前記第1ピースと、前記第1装置識別情報と、前記第1一時情報とを対応付けて記憶手段に記憶させる記憶制御ステップと、
     その生成毎に異なり得る第2一時情報を生成する生成ステップと、
     前記第2一時情報を用いて、前記第1ピースを変換して、第2ピースを出力する変換ステップと、
     前記第2ピースと、前記第1装置識別情報と、前記第2装置識別情報と、前記第1一時情報と、前記第2一時情報とを送信する送信ステップとをコンピュータに実行させるプログラム。
  25.  データの一部であるピースを送信する複数の他の通信装置のそれぞれに割り当てられた秘密情報と、各通信装置に割り当てられた装置識別情報とを各々対応付けて記憶するサーバの有するコンピュータに実行させるためのプログラムであって、
     可逆に変換された前記ピースを逆変換するための復号情報を要求すると共に、前記複数の他の通信装置の前記装置識別情報及び当該複数の他の通信装置が各々生成した情報であってその生成毎に異なり得る一時情報とを対応付けて含む要求を第1通信装置から受信する受信ステップと、
     前記要求に含まれる各前記装置識別情報に対応付けられて記憶されている前記秘密情報と、当該各装置識別情報と対応付けられて前記要求に含まれる各前記一時情報とを用いて、逆変換を行う際に用いる変換パラメータを生成する生成ステップと、
     前記変換パラメータを含む前記復号情報を前記第1通信装置に送信する送信ステップとをコンピュータに実行させるプログラム。
PCT/JP2009/065664 2008-12-09 2009-09-08 通信装置、サーバ、通信方法及びプログラム Ceased WO2010067650A1 (ja)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2008-313346 2008-12-09
JP2008313346A JP2010141408A (ja) 2008-12-09 2008-12-09 通信装置、サーバ、通信方法及びプログラム

Publications (1)

Publication Number Publication Date
WO2010067650A1 true WO2010067650A1 (ja) 2010-06-17

Family

ID=42242643

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2009/065664 Ceased WO2010067650A1 (ja) 2008-12-09 2009-09-08 通信装置、サーバ、通信方法及びプログラム

Country Status (2)

Country Link
JP (1) JP2010141408A (ja)
WO (1) WO2010067650A1 (ja)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2010004269A (ja) * 2008-06-19 2010-01-07 Toshiba Corp 通信装置、鍵サーバ及びデータ
FR3004561A1 (fr) * 2013-04-15 2014-10-17 Banque Accord Methode et systeme d'amelioration de la securite des transactions electroniques

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008192129A (ja) * 2007-01-09 2008-08-21 Docomo Technology Inc ネットワークデータ分散共有システム

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008192129A (ja) * 2007-01-09 2008-08-21 Docomo Technology Inc ネットワークデータ分散共有システム

Non-Patent Citations (5)

* Cited by examiner, † Cited by third party
Title
TATSUYUKI MATSUSHITA ET AL.: "JetJigsaw ni Okeru Piece Kaizan Kenchi Hoho no Teian", IEICE TECHNICAL REPORT, vol. 108, no. 473, 2 March 2009 (2009-03-02), pages 1 - 6 *
TORU KANBAYASHI ET AL.: "JetJigsaw: P2P o Riyo shita Chosakuken Hogo Hoshiki no Shin Teian", NEN SYMPOSIUM ON CRYPTOGRAPHY AND INFORMATION SECURITY (SCIS2009), vol. 1B2, - 20 January 2009 (2009-01-20), pages 1B2-2 *
YUICHI JINNO ET AL.: "P2P Network ni Okeru Joho no Ryutsu Kanshi Hoshiki no Teian", PROCEEDINGS OF THE 67TH (HEISEI 17 NENDO) IEICE GENERAL CONFERENCE, vol. 6K-4, - 2 March 2005 (2005-03-02), pages 3-99 - 3-100 *
YUTA OKAMOTO ET AL.: "Bunsan Meta P2P Storage 'DiMPS' ni yoru Contents Haishin System no Jitsugen", THE INSTITUTE OF ELECTRONICS, INFORMATION AND COMMUNICATION ENGINEERS DAI 19 KAI DATA KOGAKU WORKSHOP RONBUNSHU, 07 APRIL 2008, vol. 12, 7 April 2008 (2008-04-07), pages 1 - 6 *
YUTA OKAMOTO ET AL.: "P2P File Kyoyu Network o Riyo shita Daikibo Bunsan Storage no Jitsugen", PROCEEDINGS OF THE 69TH (HEISEI 19 NEN) NATIONAL MEETING OF INFORMATION PROCESSING SOCIETY OF JAPAN, vol. 1W-1, - 6 March 2007 (2007-03-06), pages 3-297 - 3-298 *

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2010004269A (ja) * 2008-06-19 2010-01-07 Toshiba Corp 通信装置、鍵サーバ及びデータ
US8548169B2 (en) 2008-06-19 2013-10-01 Kabushiki Kaisha Toshiba Communication apparatus, key server, and data
FR3004561A1 (fr) * 2013-04-15 2014-10-17 Banque Accord Methode et systeme d'amelioration de la securite des transactions electroniques
WO2014170561A1 (fr) * 2013-04-15 2014-10-23 Banque Accord Methode et systeme d'amelioration de la securite des transactions electroniques
CN104303198A (zh) * 2013-04-15 2015-01-21 阔达银行 提高电子交易安全性的方法与系统

Also Published As

Publication number Publication date
JP2010141408A (ja) 2010-06-24

Similar Documents

Publication Publication Date Title
JP5395372B2 (ja) 通信装置、鍵サーバ及びデータ
JP6017501B2 (ja) 暗号システム
KR101312910B1 (ko) 다양한 콘텐트 유형의 디지털 미디어 보호
EP3157225B1 (en) Encrypted ccnx
JP5861220B2 (ja) テンプレートモードにおける短期暗号期間用の効果的な支援のためのシステム及び方法
JP5955285B2 (ja) 暗号化システム、暗号化方法及びコンピュータプログラム
TW200828936A (en) Encryption processor, encryption processing method, and computer program
US12225106B2 (en) File sharing method and system, electronic device and readable storage medium
CN108604984B (zh) 用于内容中心网络中的兴趣加密的方法和系统
JP4596256B2 (ja) 送受信システムおよび方法、送信装置および方法、受信装置および方法、並びにプログラム
JP2010004390A (ja) 通信装置、鍵サーバ及びデータ
CN102187617A (zh) 密码系统
WO2010067660A1 (ja) 通信装置、通信方法及びプログラム
CN112954388B (zh) 一种数据文件的获取方法、装置、终端设备和存储介质
JP2010124071A (ja) 通信装置、通信方法及びプログラム
JP2009272927A (ja) 通信装置、サーバ、及びプログラム
CN104753870A (zh) 一种数据传输方法和系统
KR101812311B1 (ko) 사용자 단말 및 속성 재암호 기반의 사용자 단말 데이터 공유 방법
Lei et al. Towards efficient re-encryption for secure client-side deduplication in public clouds
JP2010141408A (ja) 通信装置、サーバ、通信方法及びプログラム
JP2007041756A (ja) 情報処理装置および方法、プログラム、並びに、セキュリティチップ
CN104092537A (zh) 一种实现密钥信息编解码的装置及其工作方法
JP2010141619A (ja) 通信装置、サーバ装置、通信プログラム、及びデータ
JP2014017763A (ja) 暗号更新システム、暗号更新要求装置、暗号更新装置、復号装置、暗号更新方法、および、コンピュータ・プログラム
JP2005354496A (ja) 復号情報生成装置及びそのプログラム、配信用コンテンツ生成装置及びそのプログラム、並びに、コンテンツ復号装置及びそのプログラム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09831756

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09831756

Country of ref document: EP

Kind code of ref document: A1