US2015312043A1PendingUtilityA1

Digital signature server and user terminal

Assignee: TOSHIBA KKPriority: Nov 25, 2009Filed: Sep 11, 2014Published: Oct 29, 2015
Est. expiryNov 25, 2029(~3.3 yrs left)· nominal 20-yr term from priority
H04L 9/3247H04L 9/0825H04L 9/14H04L 63/0457
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

To reduce a load on a user terminal imposed when verifying signature data and at the same time reduce a load on a server, a signature key matrix KM includes a plurality of signature keys Ki-j arranged in a matrix structure of m rows and n columns, and is stored in a signature key matrix database 21. A correspondence relationship between a signature key set CK which is an aggregate of any signature keys selected from the n columns respectively and a user terminal 30 is stored in a correspondence relationship information database 22. A signature data generating unit 24 generates signature data having a matrix structure by encrypting a content digest D generated based on content data C by n number of signature keys included in the signature key matrix KM.

Claims

exact text as granted — not AI-modified
1 .- 8 . (canceled) 
     
     
         9 . A user terminal operative to receive, together with content data, signature data indicating that the content data is a certified one, comprising a processor configured to:
 receive from outside, together with the content data, signature data generated by encrypting a content digest by a plurality of signature keys included in a signature key column set which is an aggregate of signature key columns each including a plurality of signature keys, the content digest being generated based on the content data;   receive from outside, a signature key set which is an aggregate of the signature keys selected one by one from the signature key columns of the signature key column set respectively; and   verify the signature data by decrypting the content digest included in the signature data by using the signature keys included in the signature key set, and then comparing this content digest with a content digest obtained from the content data received from outside.   
     
     
         10 . The user terminal according to  claim 9 , wherein the signature data includes a plurality of columns in each of which a signature data key different from signature data keys for the other columns is encrypted by the signature keys. 
     
     
         11 . The user terminal according to  claim 10 , wherein in a first column of the signature data, the content digest and the signature data key for the first column are encrypted by using the signature keys, whereas in a j-th column (j≧2) of the signature data, encrypted data generated by encrypting the content digest and the signature data key for the j-th column by using the signature data key for a (j−1)th column is encrypted by using the signature keys, and
 the processor decrypts the content digest and the signature data key in the first column of the signature data by using the signature keys, and then decrypts the content digest and the signature data key in the j-th column (j≧2) of the signature data by using the signature data key for the (j−1)th column and the signature keys. 
 
     
     
         12 . A method of verifying signature data indicating that the content data is a certified one at a user terminal, the method comprising:
 receiving, from outside, at the user terminal, together with content data, signature data generated by encrypting a content digest by a plurality of signature keys included in a signature key column set which is an aggregate of signature key columns each including a plurality of signature keys, the content digest being generated based on the content data;   receiving, from outside, at the user terminal, a signature key set which is an aggregate of the signature keys selected one by one from the signature key columns of the signature key column set respectively; and   verifying the signature data by decrypting the content digest included in the signature data by using the signature keys included in the signature key set, and then comparing this content digest with a content digest obtained from the content data received from outside.   
     
     
         13 . The method according to  claim 12 ,
 wherein the signature data includes a plurality of columns in each of which a signature data key different from signature data keys for the other columns is encrypted by the signature keys.   
     
     
         14 . The method according to  claim 13 ,
 wherein in a first column of the signature data, the content digest and the signature data key for the first column are encrypted by using the signature keys, whereas in a j-th column (j≧2) of the signature data, encrypted data generated by encrypting the content digest and the signature data key for the j-th column by using the signature data key for a (j−1)th column is encrypted by using the signature keys, and   the processor decrypts the content digest and the signature data key in the first column of the signature data by using the signature keys, and then decrypts the content digest and the signature data key in the j-th column (j≧2) of the signature data by using the signature data key for the (j−1)th column and the signature keys.   
     
     
         15 . A non-transitory computer-readable medium configured to perform a method of verifying signature data indicating that the content data is a certified one at a user terminal, the method comprising:
 receiving, from outside, at the user terminal, together with content data, signature data generated by encrypting a content digest by a plurality of signature keys included in a signature key column set which is an aggregate of signature key columns each including a plurality of signature keys, the content digest being generated based on the content data;   receiving, from outside, at the user terminal, a signature key set which is an aggregate of the signature keys selected one by one from the signature key columns of the signature key column set respectively; and   verifying the signature data by decrypting the content digest included in the signature data by using the signature keys included in the signature key set, and then comparing this content digest with a content digest obtained from the content data received from outside.   
     
     
         16 . The non-transitory computer-readable medium according to  claim 15 ,
 wherein the signature data includes a plurality of columns in each of which a signature data key different from signature data keys for the other columns is encrypted by the signature keys.   
     
     
         17 . The non-transitory computer-readable medium according to  claim 16 ,
 wherein in a first column of the signature data, the content digest and the signature data key for the first column are encrypted by using the signature keys, whereas in a j-th column (j≧2) of the signature data, encrypted data generated by encrypting the content digest and the signature data key for the j-th column by using the signature data key for a (j−1)th column is encrypted by using the signature keys, and the signature data verifying unit verifying decrypts the content digest and the signature data key in the first column of the signature data by using the signature keys, and then decrypts the content digest and the signature data key in the j-th column (j≧2) of the signature data by using the signature data key for the (j−1)th column and the signature keys.   
     
     
         18 . A method of generating signature data indicating that content data is a certified one, at a server, the method comprising:
 storing, at the server, a signature key column set which is an aggregate of signature key columns each of which is an aggregate of a plurality of signature keys;   storing, at the server, correspondence relationship information indicating a correspondence relationship between a signature key set and a user terminal, the signature key set being an aggregate of any signature keys selected from the signature key columns respectively; and   generating signature data by encrypting a content digest by using the plurality of signature keys included in the signature key column set, the content digest being generated based on the content data.   
     
     
         19 . The method according to  claim 18 , the method further comprising:
 sending the signature data to a content server for providing content data to the user terminal and receive the content digest from the content server.   
     
     
         20 . The method according to  claim 18 , the method further comprising generating a plurality of different signature data keys corresponding to a plurality of columns of the signature data respectively,
 wherein in each of the plurality of columns, the method encrypts the signature data key corresponding to that column by using the signature keys.   
     
     
         21 . The method according to  claim 20 ,
 wherein in a first column of the signature data, the method encrypts the content digest and the signature data key corresponding to the first column by using the signature keys, whereas in a j-th column (j≧2) of the signature data, the cignaturc data method generates encrypted data by encrypting the content digest and the signature data key corresponding to the j-th column by using the signature data key corresponding to a (j−1)th column, and further encrypts the encrypted data by using the signature keys.   
     
     
         22 . The method according to  claim 18 ,
 wherein the method encrypts a verification value used for verifying the signature data by the signature data key.   
     
     
         23 . A non-transitory computer-readable medium configured to perform a method of generating signature data indicating that content data is a certified one, at a server, the method comprising:
 storing, at the server, a signature key column set which is an aggregate of signature key columns each of which is an aggregate of a plurality of signature keys;   storing, at the server, correspondence relationship information indicating a correspondence relationship between a signature key set and a user terminal, the signature key set being an aggregate of any signature keys selected from the signature key columns respectively; and   generating signature data by encrypting a content digest by using the plurality of signature keys included in the signature key column set, the content digest being generated based on the content data.   
     
     
         24 . The medium according to  claim 23 , the method further comprising:
 sending the signature data to a content server for providing content data to the user terminal and receive the content digest from the content server.   
     
     
         25 . The medium according to  claim 23 , the method further comprising generating a plurality of different signature data keys corresponding to a plurality of columns of the signature data respectively,
 wherein in each of the plurality of columns, the method encrypts the signature data key corresponding to that column by using the signature keys.   
     
     
         26 . The medium according to  claim 25 ,
 wherein in a first column of the signature data, the method encrypts the content digest and the signature data key corresponding to the first column by using the signature keys, whereas in a j-th column (j≧2) of the signature data, the method generates encrypted data by encrypting the content digest and the signature data key corresponding to the j-th column by using the signature data key corresponding to a (j−1)th column, and further encrypts the encrypted data by using the signature keys.   
     
     
         27 . The medium according to  claim 23 , wherein the method encrypts a verification value used for verifying the signature data by the signature data key. 
     
     
         28 . A signature data server operative to generate signature data indicating that content data is a certified one, the signature data server comprising:
 a signature key column set database configured to store a signature key column set which is an aggregate of signature key columns each of which is an aggregate of a plurality of signature keys;   a correspondence relationship information database configured to store correspondence relationship information indicating a correspondence relationship between a signature key set and a user terminal, the signature key set being an aggregate of any signature keys selected from the signature key columns respectively; and   a processor configured to generate signature data by encrypting a content digest by using the plurality of signature keys included in the signature key column set, the content digest being generated based on the content data.   
     
     
         29 . The signature data server according to  claim 28 , the processor further being configured to send the signature data to a content server for providing content data to the user terminal and receive the content digest from the content server. 
     
     
         30 . The signature data server according to  claim 28 , the processor further being configured to generate a plurality of different signature data keys corresponding to a plurality of columns of the signature data respectively,
 wherein in each of the plurality of columns, the processor encrypts the signature data key corresponding to that column by using the signature keys.   
     
     
         31 . The signature data server according to  claim 30 ,
 wherein in a first column of the signature data, the processor encrypts the content digest and the signature data key corresponding to the first column by using the signature keys, whereas in a j-th column (j≧2) of the signature data, the processor generates encrypted data by encrypting the content digest and the signature data key corresponding to the j-th column by using the signature data key corresponding to a (j−1)th column, and further encrypts the encrypted data by using the signature keys.   
     
     
         32 . The signature data server according to  claim 28 , wherein the processor encrypts a verification value used for verifying the signature data by the signature data key.

Join the waitlist — get patent alerts

Track US2015312043A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.