Information processing apparatus and encryption communicating method

US9807084B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9807084-B2
Application numberUS-201514789091-A
CountryUS
Kind codeB2
Filing dateJul 1, 2015
Priority dateJul 16, 2014
Publication dateOct 31, 2017
Grant dateOct 31, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An information processing apparatus for performing encryption communication with an external apparatus by an encryption communication protocol has an inhibition unit for inhibiting use of a set of algorithms which do not satisfy a predetermined condition among a plurality of sets of algorithms used in the encryption communication protocol. The set of algorithms whose use if inhibited is a set of algorithms which need to transmit a message with a signature of the information processing apparatus to the external apparatus at the time of handshake performed with the external apparatus prior to the encryption communication.

First claim

Opening claim text (preview).

What is claimed is: 1. An information processing apparatus for performing encryption communication with an external apparatus in accordance with an encryption communication protocol, comprising: a memory storing instructions; and one or more processors that execute the stored instructions to perform the functions of: a receiving unit configured to receive, from the external apparatus, information including strength of hash available in the external apparatus that is used to sign parameter information in a handshake process, before receiving from the external apparatus the parameter information signed with the hash in the external apparatus, wherein the parameter information is to be used for encrypted communication protocol between the information processing apparatus and the external apparatus; and a control unit configured to control the information processing apparatus not to communicate with the external apparatus, in accordance with the encrypted communication protocol by using the parameter information signed with the hash in the external apparatus, in a case where the external apparatus does not provide the information including the strength of the hash in the external apparatus. 2. The information processing apparatus according to claim 1 , wherein the one or more processors execute the stored instructions to further perform the functions of: a decision unit configured to decide whether or not an algorithm which is used in the encryption communication protocol is an algorithm whose use is limited with respect to each of a plurality of algorithms; and a communication unit configured to perform the handshake process and the encryption communication by using the algorithm whose use is not limited among the plurality of algorithms. 3. The information processing apparatus according to claim 2 , wherein control is performed not to use an algorithm which does not satisfy a predetermined condition among the plurality of algorithms which are used in the encryption communication protocol, in accordance with a setting not to use the encryption communication of a predetermined cipher strength. 4. The information processing apparatus according to claim 2 , wherein with respect to the plurality of algorithms, the decision unit decides whether or not those algorithms are an algorithm which needs to transmit a message with a signature of a server from the server to a client during the handshake process. 5. The information processing apparatus according to claim 4 , wherein: each algorithm used in the encryption communication protocol includes an algorithm for authentication of the information processing apparatus and an algorithm for exchange of the cipher key with the external apparatus; and on the basis of a result of discrimination about a name of the algorithm for authentication of the information processing apparatus and a name of the algorithm for exchange of a cipher key with the external apparatus, the decision unit decides whether or not the algorithm used in the encryption communication protocol is an algorithm whose use is limited. 6. The information processing apparatus according to claim 2 , wherein with respect to the plurality of algorithms, the decision unit further decides whether or not those algorithms satisfy a reference regarding a safety based on a cipher intensity by sequentially selecting the plurality of algorithms. 7. The information processing apparatus according to claim 6 , wherein the each algorithm used in the encryption communication process includes an algorithm for authentication of the information processing apparatus, and the reference regarding the safety based on the cipher intensity includes at least one of a reference regarding a safety of a hash algorithm used for the signature to a certification of the information processing apparatus and a reference regarding a safety of a public key in the certification of the information processing apparatus. 8. The information processing apparatus according to claim 6 , wherein the reference regarding the safety based on the cipher intensity includes at least one of a reference regarding a size of a cipher key which is used in the algorithms constituting the algorithm used in the encryption communication protocol and a reference regarding names of the algorithms constituting the algorithm used in the encryption communication protocol. 9. The information processing apparatus according to claim 2 , wherein: when the information processing apparatus receives, as a server, a connection request from the external apparatus as a client, the decision unit decides whether or not hash algorithms which can be used for the signature to a certification of the information processing apparatus have been presented from the external apparatus as a client; and as a result of the decision, if it is decided that the hash algorithm which can be used for the signature to the certification of the information processing apparatus has been presented, the decision unit does not decide whether or not the algorithm used in the encryption communication protocol is the algorithm whose use is limited. 10. The information processing apparatus according to claim 9 , wherein: if it is decided that the hash algorithms which can be used for the signature to the certification of the information processing apparatus have been presented from the external apparatus as a client, the decision unit decides whether or not a hash algorithm which satisfies a predetermined cipher intensity exists in the presented hash algorithms; and as a result of the decision, if it is decided that the hash algorithm which satisfies the predetermined cipher intensity exists, the decision unit does not decide whether or not the algorithm used in the encryption communication protocol is an algorithm whose use is limited. 11. The information processing apparatus according to claim 10 , wherein if it is decided that the hash algorithm which satisfies the predetermined cipher intensity does not exist, the decision unit decides whether or not the algorithm used in the encryption communication protocol is an algorithm whose use is limited. 12. The information processing apparatus according to claim 2 , wherein: when the information processing apparatus receives, as a server, a connection request from the external apparatus as a client, the decision unit further decides whether or not hash algorithms which can be used for the signature to a certification of the information processing apparatus have been presented from the external apparatus as a client; and as a result of the decision, if it is decided that the hash algorithms which can be used for the signature to the certification of the information processing apparatus are not presented, the decision unit decides whether or not the algorithm used in the encryption communication protocol is the algorithm whose use is limited. 13. The information processing apparatus according to claim 2 , wherein the one or more processors execute the stored instructions to further perform the function of a protocol limitation unit configured to limit use of the encryption communication protocol using a predetermined algorithm among the plurality of encryption communication protocols, and wherein the communication unit performs the encryption communication with the handshake process by using the algorithm whose use is not limited by the decision unit and the protocol limitation unit. 14. The information processing apparatus according to claim 13 , wherein the decision unit decides whether or not the plurality of algorithms which are used in the encryption communication protocol whose use was

Assignees

Inventors

Classifications

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • at the transport layer · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9807084B2 cover?
An information processing apparatus for performing encryption communication with an external apparatus by an encryption communication protocol has an inhibition unit for inhibiting use of a set of algorithms which do not satisfy a predetermined condition among a plurality of sets of algorithms used in the encryption communication protocol. The set of algorithms whose use if inhibited is a set o…
Who is the assignee on this patent?
Canon Kk
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 31 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).