Password protection program using any communication standard
The password protection program addresses the challenge of securing control device passwords in factories by dynamically changing passwords through common number tables and function processing, and by implementing increased waiting times for incorrect attempts, thus enhancing overall security.
Patent Information
- Application Number
- JP2023188977
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-04
- Publication Date
- 2025-05-19
- Estimated Expiration
- 2043-11-04
AI Technical Summary
In factories where unauthorized access is prohibited, control devices for controlling and monitoring other devices or writing data/programs face challenges in securing passwords, especially when connection cables, wireless devices, or monitoring devices are used to attempt unauthorized access or password retrieval.
A password protection program is implemented that dynamically changes the password by using a common number table and function processing to create a communication password, which is then decomposed to extract the original setting password. This program also includes features like increasing waiting times for incorrect password attempts.
The solution significantly enhances password security by making it difficult to steal or guess the password, even when repeatedly trying simple passwords or analyzing communication protocols. The dynamic password changes and increased waiting times for incorrect attempts further secure the system.
Smart Images

Figure 2025077063000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a password protection program that defines a password protection operation of a system having a control device for controlling a controlled device and a control device for monitoring the control device or controlling it by writing data or a program, wherein the control device and the control device communicate with each other according to an arbitrary communication standard.
Background Art
[0002] Conventionally, in a factory, a control device for controlling a controlled device that automates a production process has been used. For example, a programmable logic controller (PLC) that uniformly controls distributed control devices, a touch panel (TP) that diversifies inputs and outputs from a person using the device, a converter, an amplifier that controls a servo motor or an inverter motor, a control device that captures or outputs analog values, etc. are combined to automate the production process. Most of the control devices that control the control device and set parameters, which are attached to most of the control devices for controlling the controlled device, are either independently designed or use a personal computer (PC). They are called engineering tools, support tools, console boxes, parameter units, operation boxes, programmers, numeric keypads, etc., and control the control device for controlling the controlled device or set parameters by methods such as serial communication or LAN (Local Area Network). In a programmable logic controller (PLC), a program, etc., in a touch panel (TP), screen data, etc., and in a converter, an amplifier, and other control devices, some set values such as speed, time, and slope are determined after numerous trials and errors. Since the know-how is not desired to be imitated, many of them make the program, screen data, and set values unreadable with a password, and various security processes are performed. In addition, for those using passwords, a cash card for using an automated teller machine (ATM) such as a bank has been used for a long time. These days with the spread of the Internet, authentication using a user ID (ID, Identification) and a password is also carried out, and the old and simple ones in this system are still being used.
[0003] Among various security processes, for example, Patent Document 1 (Japanese Patent Application No. 2019-224393) has been devised with the problem of providing an information processing apparatus, an authentication system, an information processing method, and an authentication method that can enhance security without impairing the convenience of users. Also, Patent Document 2 (Japanese Patent No. 5874796) has been devised with the problem of maximizing the ability of a user to access and operate a programmable controller (PLC) that is coupled to a programming device by a common bus and controls a controlled device via the input device and display of the programming device. Further, Patent Document 3 (Japanese Patent No. 4238964) has been devised with the problem of enabling only necessary parts in a user program to be surely protected by security without increasing the number of keys (for example, the number of passwords) significantly even when the number of divisions of the user program reaches an enormous number such as several hundreds to several thousands. Also, Patent Document 4 (Japanese Patent No. 6910748) has been devised to provide a password authentication system that can maintain a high security level using a password with a small number of digits. Further, Patent Document 5 (Japanese Patent No. 3455196) has been devised with the problem of improving the security of data and programs in a control device that enables large-scale general networking by performing protocol conversion.
[0004] The invention of Patent Document 1 (Japanese Patent Application No. 2019-224393) is an authentication system in which a large number of users each have a user ID and a password, and all are permitted to authenticate on the server side. It is about what and how to disallow, but it does not mean making the user terminal unusable. Note that irreversible hash functions are well-known technologies.
[0005] In the invention of Patent Document 2 (Patent No. 5874796), although it attempts to change the user's operation authority level that is performed by the system software without stopping the operation of the controlled device, there is almost no need to frequently change the user's operation authority level, and it can be dealt with by another method.
[0006] In the invention of Patent Document 3 (Patent No. 4238964), each program is specified into program blocks, and passwords can be set for the whole, groups, or each of those blocks, reducing the number of keys.
[0007] In the invention of Patent Document 4 (Patent No. 6910748), logical operations are performed using the user password stored in the user's mind and the unique code secretly stored in the terminal device and set for each Web (Web, World Wide Web) site, and a multi-digit operation result is output. The authentication process is performed using the operation result as the authentication password. Therefore, only by the user memorizing a few-digit password in the mind, the authentication process is performed using a multi-digit complex password. Furthermore, different authentication passwords are output for each Web site using one authentication password. That is, it cannot be used without a Web environment. Also, security processing for the Web environment itself is required.
[0008] In the invention of Patent Document 5 (Patent No. 3455196), the input operation is accepted only when the passwords input from other computers match, and the password is in a hierarchical structure, allowing operations corresponding to the operator's level.
Prior Art Documents
Patent Documents
[0009]
Patent Document 1
Patent Document 2
Patent Document 3
[0010] The problem to be solved is that in a factory where unauthorized entry is prohibited, for a control device for controlling a controlled device and a control device for monitoring the control device or writing data or a program to control it, a connection cable connecting to a wireless device, or a device for monitoring the communication status between a wireless device and the control device, and attempting to obtain the password first transmitted from the control device.
[0011] Furthermore, the problem to be solved is that without hesitation to newly prepare the same control device and controlled device, while subtly changing a simple password, successively setting new passwords, analyzing the file structure, or using a device for monitoring the communication status to analyze the communication protocol and attempt to obtain the password.
[0012] Furthermore, the problem to be solved is that in a factory where unauthorized entry is prohibited, using a personal computer or the like to automatically repeat all combinations of passwords to attempt to obtain the password. [Means for Solving the Problems]
[0013] A first aspect of the present invention is a password protection program that defines a password protection operation for a system having a control device for controlling a controlled device and a control device for monitoring the control device or controlling by writing data or a program, wherein the control device and the control device communicate with each other according to an arbitrary communication standard, Regarding the setting password set in the control device to restrict access to the control device, each time the control device and the communication are performed by either the control device newly setting the setting password in the control device or requesting the control device for the already set setting password, an arbitrary first argument is set, function processing is performed using the data corresponding to the first argument from a common number table provided in both the control device and the control device and the setting password, and communication is performed by creating a communication password obtained by adding the number of digits of the first argument other than the number of digits of the setting password to the result of the function processing. When the control device or the control device has a function to output data whose access is restricted to the outside, each time the data when the access to the control device is restricted by the setting password is newly set and output to the outside, or each time the setting password is changed and output to the outside, an arbitrary second argument is set, function processing is performed using the data corresponding to the second argument in the number table used for creating the communication password or a new number table and the setting password, and the result of the function processing used in creating the communication password or the result of a new function processing and the setting password are replaced with an output password obtained by adding the number of digits of the second argument other than the number of digits of the setting password and output to the outside. The communication password communicated to the control device or the control device or the input output password is decomposed into the arguments and the result of the function processing used in creating the communication password or the output password, and the system is made to perform reverse function processing from the time of creation using the data corresponding to the arguments decomposed in the number table and the result of the function processing to extract the setting password. This is a password protection program.
[0014] The second aspect of the present invention is a password protection program according to the first aspect of the present invention, which further causes the system to execute the following for the setting password set in the control device to restrict access to the control device: when the control device is restricted by the setting password and the control device authenticates the setting password, if the setting password does not match, after a waiting time, re-entry is enabled, and if the setting password further does not match, the waiting time is made longer than the previous waiting time.
[0015] The third aspect of the present invention is a password protection program according to the second aspect of the present invention, which further causes the system to execute the following for the setting password set in the control device to restrict access to the control device: when the control device is restricted by the setting password and the control device authenticates the setting password, if the setting password does not match, the control device communicates the next waiting time or the number of times of non-match to the control device, and if the setting password matches, the control device communicates the next waiting time or the number of times of non-match to the initial value to the control device.
[0016] The fourth aspect of the present invention is a password protection program according to the third aspect of the present invention, which further causes the system to execute the following: when the control device is restricted by the setting password and the waiting time or the number of times of non-match is not the initial value, in the first communication with the control device, the control device communicates the waiting time or the number of times of non-match to the control device.
[0017] The fifth aspect of the present invention is a password protection program that defines the password protection operation of a system having a control device for controlling a controlled device and a control device for monitoring the control device or controlling it by writing data or a program, wherein the control device and the control device communicate with each other according to an arbitrary communication standard. Regarding the setting password set in the control device to restrict access to the control device, when the control device is restricted by the setting password and the control device authenticates the setting password, if the setting password does not match, after a waiting period, re-entry is allowed, and if the setting password still does not match, the system is made to execute a longer waiting period than the previous waiting period. This is a password protection program that causes the system to execute this.
[0018] A sixth aspect of the present invention is regarding the setting password set in the control device to restrict access to the control device. When the control device is restricted by the setting password and the control device authenticates the setting password, if the setting password does not match, the control device communicates the next waiting period or the number of mismatches to the control device, and if the setting password matches, the control device communicates the next waiting period or the number of mismatches to the initial value to the control device. This is the password protection program according to the fifth aspect of the present invention that further causes the system to execute this.
[0019] A seventh aspect of the present invention is that when the control device is restricted by the setting password and the waiting period or the number of mismatches is not the initial value, in the first communication to the control device, the control device communicates the waiting period or the number of mismatches to the control device. This is the password protection program according to the sixth aspect of the present invention that further causes the system to execute this.
Advantages of the Invention
[0020] The effect of the present invention is that by installing a device for monitoring the communication status between a connection cable connecting a control device and a control device or a wireless device, subtly changing a simple password, and repeatedly setting the same password, the entire password changes greatly. Also, even if a simple same password is repeatedly set alternately, although it depends on the size of the number table, it is difficult to become the same password, so it is impossible to easily steal the password or structure.
[0021] Furthermore, if the set password is simply replaced without using an argument with a common table or number table for the control device and the control device, and a simple same password is repeatedly set alternately, there is little change and it is easy to steal the password or structure. Therefore, by adding an argument, it is impossible to steal the password or structure.
[0022] Furthermore, by outputting the data of the control device restricted by the set password, using the function for storing or copying the data via an external storage medium, subtly changing a simple password, or repeatedly setting the same password alternately, repeating the output and input, and analyzing the data with a bitmap or the like, the entire password changes greatly. Also, even if a simple same password is repeatedly set alternately and output, although it depends on the size of the number table, it is difficult to become the same password, so it is impossible to steal the password or structure.
[0023] Furthermore, even if it is understood that the password of this invention is formed in a structure that uses a reversible function process with an argument that is a key extracted by a random number operation or a random number table and a number table, since a person using this invention can arbitrarily create a number table and select an arbitrary function process, and also since it is arbitrary how to combine the argument that is a key extracted by a random number operation or a random number table and the created value, even when using this invention, the function of confidentiality can be sufficiently fulfilled.
[0024] Furthermore, by generating arguments using random number operations or random number tables, incorporating number tables, and performing reversible function processing, the present invention can be utilized. Therefore, if it is incorporated into a conventional password program during communication and output, the secrecy function can be improved without significantly changing the functions, configurations, or characteristics of the conventional password program.
[0025] Furthermore, if the passwords do not match, the waiting time until input becomes increasingly longer. Therefore, if all combinations of passwords are automatically repeated, it would require an enormous amount of time, making it difficult to obtain the password. Naturally, when trying them in order, there may be cases where they match probabilistically, but depending on the number of digits, it cannot be easily obtained within about 100 times. Also, in a factory that prohibits unauthorized entry, it is not possible to sacrifice normal production. As long as the waiting time is increased exponentially, it can be adequately addressed. Note that the control device is not used by an unspecified large number of people like an automated teller machine (ATM), so although it is simple, this function is very important. However, simply waiting does not allow for differentiation from malfunctions. Therefore, to inform the user that the previous password did not match, it is preferable to display the waiting time and the remaining waiting time. Furthermore, by displaying this, although approximately, it is possible to infer how many times the password did not match.
[0026] Furthermore, if the passwords do not match, the waiting time until input becomes increasingly longer. Therefore, attempts are made to perform a reset or turn off the power and start over to reduce the increased waiting time and number of attempts, or to make them the same as the previous ones. By storing the waiting time and number of attempts and sharing them between the control device and the control equipment through communication, even if a reset or power off is performed and started over, since the structure that continues to increase further is maintained, it is impossible to easily steal the password or the structure.
Brief Description of the Drawings
[0027]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Embodiments for Carrying Out the Invention
[0028] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. FIG. 1 is a relationship diagram of a cable or wireless device that communicates according to an arbitrary communication standard, a control device that controls a controlled device, and a control device that monitors the control device or controls writing of data or a program, in an apparatus and equipment according to an embodiment of the present invention. The "user" in 1 uses the "control device" in 4 that controls the controlled device connected by the "communication cable or radio" in 3, and monitors, sets parameters, writes programs, outputs the set data to the "storage medium" in 5, inputs from the "storage medium" in 5, and in the case of a movable control device, also tests the movement using the "control device" in 2 that controls the control device. Note that the "control device" in 2 that controls the control device performs all processes including password processing with the "program of the conventional control device" in 8, and the "control device" in 4 that controls the controlled device also performs all processes including password processing with the "program of the conventional control device" in B. Also, the "communication cable or radio" in 3 can be a parallel connection of a multi-core cable, a LAN (Local Area Network) cable, a USB (Universal Serial Bus) cable, etc., and is carried out in various standards. In the conventional password processing, since the "communication password" in J or K, the output password in "data output with output password" in G, and the output password in "data reading with output password" in H are all set passwords, the "communication / output password conversion program" in 6, the "set password conversion programs" in 7 and 9, and the "communication password conversion program" in A are unnecessary. A program is added only to convert the set password into a communication / output password or to convert the communication / output password into a set password. Note that the "communication / output password conversion program" in 6 and the "communication password conversion program" in A are the same program, and similarly, the "set password conversion program" in 7 and the "set password conversion program" in 9 are also the same program. When the "Communication / Output Password Conversion Program" and the "Communication Password Conversion Program" of 6 or A send the set password to the "Control Device" of 4, or to the "Control Equipment" of 2, or output it to the "Storage Medium" of 5, they are converted into a communication password or an output password according to the instructions of the "Program of Conventional Control Equipment" of 8 or the "Program of Conventional Control Device" of B. Similarly, the "Set Password Conversion Program" of 7 or 9 also converts the received communication password or the input output password into a set password according to the instructions of the "Program of Conventional Control Equipment" of 8 or the "Program of Conventional Control Device" of B. To convert the "Set Password" of N or K into the "Communication / Output Password" of U or the "Communication Password" of s, any "Arguments" of P or m are used, and the "Functionization" is performed with the "Extracted Value" of R or p specified by the argument from the "Number List" of Q or n and the "Set Password" of N or k, and the "Functionization Value" of T or r and any "Arguments" of P or d are combined to form the "Communication / Output Password" of U or the "Communication Password" of s. Also, to convert the "Communication / Output Password" of V or the "Communication Password" of c into the "Set Password" of b or j, the communication / output password is decomposed into the "Arguments" of W or d and the "Functionization Value" of X or e, and the "Functionization" is performed with the "Extracted Value" of Z or g specified by a random number from the "Number List" of Y or f and the "Functionization Value" of X or e to form the "Set Password" of b or j. When creating the "Communication / Output Password" of U or the "Communication Password" of s, the "Arguments" of P or m obtain a random number through calculation and correspond to the "Number Lists" of Q, Y, f, and m for creation. However, if there is no random number function, a random number table may also be used. Also, a simple order may be used. Note that although the output is borne by the "Control Equipment" of 2, it may also be performed by the "Control Device" of 4. By the above method, the setting password, the communication password, and the output password are different from each other. Each time the setting password is set and communicated, or when the control device is already restricted by the setting password, or each time the control device requests and communicates with the setting password, or each time it is first connected, or each time a new setting password is set and output, or each time the setting password is changed and output, the communication password or the output password is changed. Furthermore, even if the password is set to one character, for those who try to search for it in the communication data or output data, all the characters change, which can conversely cause confusion. Also, if version information is added to the above communication / output password, it is possible to support control devices that continue to operate for decades. Furthermore, by consciously changing the number table, function, and combination method, the password can be made even stronger. Note that the functions of the "communication / output password conversion program" for 6 or A and the "setting password conversion program" for 7 or 9 must have an invertible relationship. That is, if the function used in the "communication / output password conversion program" is addition, the function used in the "setting password conversion program" is subtraction. Furthermore, when using a password for anti-tampering purposes or when wanting to simplify the program on the control device side, the communication password itself can be used as the password within the control device, but extremely, it will become a vulnerable password. Incidentally, simplifying the program on the control device side deviates from the gist of the present invention and thus cannot be done.
[0029] Figure 2 is a flowchart diagram of password authentication including the communication between a control device that controls a controlled device according to an embodiment and a control device that controls the control device. 20 is a control device that controls a control unit, and 21 is a control unit that controls a device to be controlled. Since the "control device" of 20 and the "control unit" of 21 mostly communicate through processes other than password authentication, from "start password authentication" at 22 to "end password authentication" at 2B is a flowchart for performing password authentication. First, on the "control unit" side of 21, "communication password conversion" at 23 is performed, and either the waiting time or the number of mismatches, the version of the number list, and the communication password are sent to the "control device" of 20. Select "version check" at 24 based on the version of the number list sent. If the selection result is "match", proceed to "configured password conversion" at 26; if the selection result is "mismatch", send the latest version of the number list and the data of the latest number list to the "control unit" of 21 and proceed to the selection of "receive version" at 25. Select "receive version" at 25 when the latest version of the number list and the data of the latest number list are sent. If the selection result is "no", proceed to the selection of "status of waiting time or number of mismatches" at 2D; if the selection result is "yes", proceed to "communication password conversion" at 23 for repeated merging. When "receive version" at 25 is selected and the selection result is "no", select "status of waiting time or number of mismatches" at 2D. If the selection result is "initial value", the control unit side proceeds to "end password authentication" at 2E and ends password authentication. If the selection result is "not the initial value", proceed to "communication password conversion" at 23 for re-merging and perform repeated processing. On the control device side, select "version check" at 24. When the selection result is "match", perform "configured password conversion" at 26 and select "status of waiting time or number of mismatches" at 27. If the selection result is "not the initial value", it proceeds to 28, "Consume the waiting time or the time corresponding to the number of mismatches". If the selection result is "the initial value", it proceeds to 29, "Password input", in order to merge. Select the "waiting time or number of mismatches status" of 25. When the selection result becomes "the initial value", it proceeds to 29, "Password input", in order to merge. Select the "waiting time or number of mismatches status" of 27. When the selection result becomes "not the initial value", perform 28, "Consume the waiting time or the time corresponding to the number of mismatches", perform 29, "Password input", and select 2A, "Authentication with the set password". If the selection result is "match", it proceeds to 2C, "Initialization of the waiting time or the number of mismatches". If the selection result is "mismatch", it proceeds to 2B, "Add the waiting time or the number of mismatches". Select 2A, "Authentication with the set password". When the selection result becomes "mismatch", in order to merge, it proceeds to the communication process of sending either the waiting time or the number of mismatches to 21, "Control device". Select 2A, "Authentication with the set password". When the selection result becomes "match", perform 2C, "Initialization of the waiting time or the number of mismatches", send either the waiting time or the number of mismatches to 21, "Control device". The control device side proceeds to 2E, "End password authentication", and ends the password authentication.
[0030] Based on the above flowchart, further explanations are provided. The process involving this communication increases the waiting time until the next input if the password does not match. Even if someone who does not know the password tries authentication randomly, by increasing the time logarithmically, it is designed to make them give up trying authentication. Furthermore, by checking the version of the number list, the number list can be intentionally updated, further improving confidentiality. The following are the details of each symbol, etc. The "control device" of 20 controls the control apparatus and sets parameters. If the control apparatus is the main one, it is not necessarily required, so it has a subordinate role. The "control device" of 21 is controlled by a control device. The "communication password conversion" of 23 is a process of converting the set password into a communication password, which is described in detail in FIG. 5. The selection of "version check" of 24 is a selection of whether the number lists match. The selection of "receive version" of 25 means that if received, the number list is rewritten and a determination is made as to whether to resend it. The "set password conversion" of 26 is a process of converting the communication password into a set password, which is described in detail in FIG. 6. The selection of the "waiting time or number of mismatches status" of 27 is a determination of whether to "consume the waiting time or the time corresponding to the number of mismatches" of 28. The "consume the waiting time or the time corresponding to the number of mismatches" of 28 means that the waiting time is actually consumed. The "password input" of 29 means that the set password is input. The selection of the "authentication with the set password" of 2A is the final selection of whether to end this set password authentication or repeat it. The "add waiting time or number of mismatches" of 2B means that time is added as a penalty due to a mismatch. The "initialization of waiting time or number of mismatches" of 2C means that the time as a penalty is initialized due to a match. The selection of the "waiting time or number of mismatches status" of 2D is a determination of whether to "end password authentication" of 2E or repeat it.
[0031] FIG. 3 is a flowchart diagram of the output when a password is added in a control device that controls a control device according to an embodiment of the present invention. 30 is a control device that controls the control device. Since processes other than data output with an output password are performed in the "control device" of 30, from "start output with output password" of 31 to "end output with output password" of 35 is a flowchart for outputting data with an output password. When it starts, it performs "Output Password Conversion" of 32, performs "Execute Output" of 33, and then ends. This output process only converts the set password into the output password and outputs the output password and all data. The following are the details of each symbol, etc. "Output Password Conversion" of 32 is a process of converting the set password into the output password, and the details are described in FIG. 5. "Execute Output" of 33 is a process of outputting all data. Note that although this process is assumed to be performed on the control device side, it may also be performed on the control apparatus side via communication. Also, it may all be performed on the control apparatus side.
[0032] FIG. 4 is a flowchart diagram of the input when a password is added in a control device that controls a control apparatus according to an embodiment of the present invention. First, it performs "Execute Reading" of 42, performs "Set Password Conversion" of 43, and selects "Waiting Time or Number of Mismatch Times State" of 44. If the selection result is "not the initial value", it shifts to "Consume Time for Waiting Time or Number of Mismatch Times" of 45. If the selection result is "initial value", in order to merge, it shifts to "Password Input" of 46 and performs "Password Input" of 46. Select "Waiting Time or Number of Mismatch Times State" of 44. When the selection result becomes "not the initial value", it performs "Consume Time for Waiting Time or Number of Mismatch Times" of 45, performs "Password Input" of 46, and selects "Authentication with Set Password" of 47. If the selection result is "match", it shifts to "Initialization of Waiting Time or Number of Mismatch Times" of 4B. If the selection result is "mismatch", it shifts to "Add Waiting Time or Number of Mismatch Times" of 48. Select "Authentication with Set Password" of 47. When the selection result becomes "mismatch", it performs "Add Waiting Time or Number of Mismatch Times" of 48 and selects "Forced Termination" of 49. If the selection result is "do", it proceeds to "Discard read data" in 4A. If the selection result is "do not", it proceeds to the selection of "Waiting time or number of mismatches status" in 44 for merging. Select "Force termination" in 49. When the selection result is "do", it performs "Discard read data" in 4A and proceeds to "Initialize waiting time or number of mismatches" in 4B for merging. Select "Authentication with set password" in 47. When the selection result is "match", it performs "Initialize waiting time or number of mismatches" in 4B and proceeds to "End read with output password" in 4C to end the read with output password.
[0033] Based on the above flowchart, further explanations are provided. Regarding the processing associated with this data reading, if the passwords do not match, it performs a process of increasing the waiting time until the next input. Even if someone who does not know the password tries authentication blindly, by increasing the time logarithmically, it is designed to make them give up trying authentication. Also, when canceling the read, it performs a process of discarding the read data. The following are the details of each symbol, etc. "Control device" in 40 controls the control device and sets parameters. If the control device is the main one, it is not necessarily required, so it has a subordinate role. "Execute input" in 42 performs the input of all data. "Convert set password" in 43 is a process of converting the communication password to the set password, which is described in detail in Figure 6. The selection of "Waiting time or number of mismatches status" in 44 determines whether to "Consume time for waiting time or number of mismatches" in 26 or not. "Consume time for waiting time or number of mismatches" in 45 actually consumes the waiting time. "Password input" in 46 allows the set password to be input. The selection of "authentication with the set password" in 47 is the final choice of whether to end or repeat this input with the output password. "Adding waiting time or the number of mismatches" in 48 means that time is added as a penalty due to a mismatch. The selection of "forced termination" in 49 is the choice of whether to end or continue this input with the output password without inputting. "Discarding input data" in 4A means that the input data is discarded because "authentication with the set password" in 47 was performed and forced termination occurred. "Initializing waiting time or the number of mismatches" in 4B means that the time as a penalty is initialized due to a match. Note that although this process is assumed to be performed on the control device side, it may also be performed on the control apparatus side via communication. Also, all operations may be performed on the control apparatus side.
[0034] FIG. 5 is a flowchart diagram of communication or output password conversion performed by a control apparatus for controlling a controlled device according to an embodiment and a control device for controlling the control apparatus. This conversion process consists of four processes and is simply performed in order. However, since the process and password security are greatly influenced by the specification of the password, first, the password specification, which is the basic premise, will be described. The number of possible passwords is 10 for a 1 - digit number, 100 for a 2 - digit number, and the security increases as the number of digits increases. Also, including alphabets, hiragana, katakana, Chinese characters, upper and lower cases, half - width and full - width characters, etc. further increases the security, but it requires an input device other than the numeric keypad and becomes more complicated. Among control devices that control general control devices, those without programmable control often use only 4 - digit numbers, and for those with programmable control, in the Q - series programmable logic controller (PLC) manufactured by Mitsubishi Electric Corporation, at least 6 digits and at most 32 digits of alphanumeric characters in half - width are used. Here, for the sake of an example of conversion, 5 digits of alphanumeric characters (including symbols) in half - width (from the "space" at 20(H) to the "tilde (~)" at 7E(H) in the ASCII (American Standard Code for Information Interchange) table) are set as the password specification. Simply put, there are 735091890625 possibilities. Assume the number of the number list is 1000. Also, for the function processing, each digit character is replaced with the ASCII (American Standard Code for Information Interchange) number, and addition and subtraction are performed for each digit (addition for communication or output - password conversion, subtraction for setting - password conversion). The combined result of the arguments and the function result becomes the communication or output - password. Note that the password does not necessarily need to be processed by ASCII (American Standard Code for Information Interchange). Furthermore, any reversible function can be used. Also, although the global generality is reduced, the ASCII (American Standard Code for Information Interchange) can be extended to include katakana. If the setting password is set to "Y5f7$", In the case of "generating a random number" for 51, since there are 1000 five - digit meaningless numbers arranged in the number list, a random number from 0 to 999 is obtained. As an example, the argument is set to "85". In "extracting a value from a number table using the generated random number as an argument" in step 52, since there are 1000 five-digit meaningless numbers arranged in the number table, if, for example, the 84th number is "15724(H)", the 85th number is "E38A0(H)", and the 86th number is "41227(H)", and the argument is "85", then "E38A0(H)" is extracted. Note that since it is five digits, it is a 32-bit number table. "Performing function processing using the set password and the value of the extracted number sequence" in step 53 means that here, addition is performed digit by digit. For the first digit of the set password, "$" has an ASCII (American Standard Code for Information Interchange) number of "24(H)", and even if "0" is added, it remains "24(H)", i.e., "$". For the second digit of the set password, "7" has an ASCII number of "37(H)", and when "A" is added, it becomes "41(H)", i.e., "A". For the third digit of the set password, "f" has an ASCII number of "66(H)", and when "4" is added, it becomes "6A(H)", i.e., "j". For the fourth digit of the set password, "5" has an ASCII number of "35(H)", and when "8" is added, it becomes "3D(H)", i.e., "=". For the fifth digit of the set password, "Y" has an ASCII number of "46(H)", and when "E" is added, it becomes "67(H)", i.e., "g". That is, "Y5f7$" becomes "g=nA$". "Combining the function result and the argument" in step 54 means that if the number table is shared, the combination is performed to identify the set password. Here, the combination is performed in the order of the argument and the function result. Therefore, the communication or output password is "85g=nA$". Note that the numerical values in the number list vary in a width of 16 and are in hexadecimal, but this is meaningless. Although the variation width becomes smaller, decimal numbers can also be used. Conversely, if developed, considering the characters from "space" (20(H)) to "tilde" (7E(H)) in the ASCII (American Standard Code for Information Interchange) table as numbers, it becomes a 95 - digit number system, and all of the ASCII (American Standard Code for Information Interchange) table can be covered. That is, if "space" (20(H)) is considered as 0 and "tilde" (7E(H)) is considered as 94, the data can also be five arbitrary ASCII (American Standard Code for Information Interchange) characters.
[0035] Also, since the set password is calculated digit by digit, a 32 - bit numerical value corresponding to the set password is arranged in the number list, but this is just one way. As another method, the number list can be considered as a container for arranging digits. In one data, if it is hexadecimal, 4 digits can be arranged. If there are 100 digits, it will be 25 data. Each data can be an arbitrary numerical value. By selecting the leading digit according to an argument and determining the remaining digits based on that digit, in this case, not much memory is required. Note that if a digit overflows, it just returns to the beginning. For example, for …ED387EA09…, if the E after … is the 85th digit, and the rest are the numerical values of the digits obtained by adding prime digits (2, 3, 5, 7) from that digit, when the argument is 85, it becomes E38E0(H).
[0036] FIG. 6 is a flowchart diagram of the set password conversion performed by a control device for controlling a controlled device according to an embodiment and a control device for controlling the control device. This conversion process consists of three processes and is just performed in order. Here, the password specification is as shown in Figure 5. That is, the password specification is five digits of alphanumeric characters (from 'Space' at 20(H) to 'Tilde (~)' at 7E(H) in the ASCII (American Standard Code for Information Interchange) table) including half-width symbols. The last column of the number table is set to 1000. Also, for the function processing, each digit character is replaced with its ASCII (American Standard Code for Information Interchange) number, and addition and subtraction are performed for each digit (addition for communication or output password conversion, subtraction for setting password conversion). The concatenation of the argument and the function result in that order is used as the communication or output password. Suppose the communication or output password is '85g=nA$'. This is created using the one in Figure 5 and is being used. The 'Decomposition of communication / output password' in 61 means decomposing it into the argument and the function result. Since they are concatenated in the order of the argument and the function result, it is done considering the number of digits of the password. Here, since '85g=nA$' is the communication or output password, '85' is the argument and 'g=nA$' is the function result. In 'Extract a value from the number table using the decomposed value as the argument' in 62, since there are 1000 five-digit meaningless numbers arranged in the number table, although hypothetically,..., if the 84th is '15724(H)', the 85th is 'E34A0(H)', and the 86th is '41227(H)', and the random number is '85', then 'E38A0(H)' is extracted. What is meant by "performing inverse function processing using the decomposed function result and the value of the extracted number sequence" here is that since subtraction, which is the inverse of addition, is performed digit by digit, for the first digit of the function result, "$" has an ASCII (American Standard Code for Information Interchange) number of "24(H)", and even when subtracting "0", it remains unchanged as "24(H)", i.e., "$". For the second digit of the function result, "A" has an ASCII number of "41(H)", and when subtracting "A", it becomes "37(H)", i.e., "7". For the third digit of the function result, "j" has an ASCII number of "6A(H)", and when subtracting "4", it remains "6A(H)", i.e., "f". For the fourth digit of the function result, "=" has an ASCII number of "3D(H)", and when subtracting "8", it becomes "35(H)", i.e., "5". For the fifth digit of the function result, "g" has an ASCII number of "67(H)", and when subtracting "E", it becomes "37(H)", i.e., "Y". That is, the function result "g=nA$" becomes the set password "Y5f7$".
[0037] Although described in the explanation of FIG. 5, other methods are also possible. Consider the number list as a container for arranging digits. With one piece of data, if it is in hexadecimal, 4 digits can be arranged, and if there are 100 digits, it will be 24 pieces of data. Each piece of data can be any numerical value. By specifying an argument, the first digit can be selected, and the remaining digits can be determined based on this digit. In this case, not much memory is required. Note that if a digit overflows, it can return to the beginning. For example, for...E328DEA09..., if the E after... is the 85th digit, and the rest are numerical values obtained by adding prime digits (2, 3, 5, 7) from that digit, when the argument is 85, it becomes E38E0(H).
[0038] Incidentally, the numerical values often used at the production factory site are either 1 digit (in recent years, there has been an increasing number of restrictions such as 4 digits or more), or the same number. As a reference example, assuming the same argument "85", the results are arranged. The left side is the set password, and the right side is the password for communication / output. "0" (assuming the upper 4 remaining digits are 20(H)) is "85.#(*0", 「1」(with the upper 4 remaining digits being 20(H)) is "85.#(*1", 「2」(with the upper 4 remaining digits being 20(H)) is "85.#(*2", 「3」(with the upper 4 remaining digits being 20(H)) is "85.#(*3", 「4」(with the upper 4 remaining digits being 20(H)) is "85.#(*4", 「5」(with the upper 4 remaining digits being 20(H)) is "85.#(*5", 「6」(with the upper 4 remaining digits being 20(H)) is "85.#(*6", 「7」(with the upper 4 remaining digits being 20(H)) is "85.#(*7", 「8」(with the upper 4 remaining digits being 20(H)) is "85.#(*8", 「9」(with the upper 4 remaining digits being 20(H)) is "85.#(*9", 「00000」 is "85E38A0", 「11111」 is "85F49B1", 「22222」 is "85G5:C2", 「33333」 is "85H6;D3", 「44444」 is "85I7<E4", 「55555」 is "85J8=F5", 「66666」 is "85K9>G6", 「77777」 is "85L:?H7", 「88888」 is "85M;@I8", 「99999」 becomes "85N<AJ9". Note that since the arguments change each time, it is necessary to consider that it will become even more complex.
Industrial Applicability
[0039] In recent years, in all industries, many things are done by electric control. Among them, in programmable control, the data is important and it is common to protect it with a password. It can be used not only for manufacturing machines and plants but also for vehicles and home appliances. In vehicles, CAN (Controller Area Network) is often used. Due to its vulnerable security, it can be used as an anti-theft measure if it is only added to the network newly. It can also be used in IoT (Internet of Things) used in home appliances, etc., where the user may be identified.
Explanation of Signs
[0040] 1 User 2 Control device 3 Communication cable or wireless device 4 Control device 5 Storage medium 6 Communication / output password conversion program 7 Setting password conversion program 8 Program of conventional control device 9 Setting password conversion program A Communication password conversion program B Program of conventional control device C Other instructions D Input, etc. E Password setting / verification instruction F Setting password input G Output data with output password output H Output data with output password reading J Communication password K Communication password L Reading / monitoring value, etc. M Other instructions / writing N Setting password P Argument Q Number list R Extracted value S Functionization T Functionized value U Communication / output password V Communication / output password W Argument X Functionized value Y Number list Z Extracted value a Functionization b Set password c Communication password d Argument e Function value f Number list g Extracted value h Functionization j Set password k Set password m Argument n Number list p Extracted value q Functionization r Function value s Communication password
[0041] 20 Control device 21 Control device 22 Start password authentication 23 Communication password conversion 24 Version check 25 Receive version 26 Set password conversion 27 Waiting time or number of mismatch status 28 Consume time for waiting time or number of mismatches 29 Password input 2A Authentication with set password 2B Add waiting time or number of mismatches 2C Initialize waiting time or number of mismatches 2D Waiting time or number of mismatch status 2E End password authentication
[0042] 30 Control device 31 Start output with output password 32 Output password conversion 33 Execute output 34 End output with output password
[0043] 40 Control device 41 Start input with output password 42 Execute input 43 Set password conversion 44 Status of waiting time or number of mismatches 45 Consume time corresponding to the waiting time or number of mismatches 46 Password input 47 Authentication with the set password 48 Add the waiting time or number of mismatches 49 Force termination 4A Discard the input data 4B Initialize the waiting time or number of mismatches 4C End the output password - attached input
[0044] 50 Start communication / output password conversion 51 Generate a random number 52 Extract a value from the number table using the generated random number as an argument 53 Perform function processing using the set password and the value of the extracted number sequence 54 Combine the function result and the argument 55 Complete communication / output password conversion
[0045] 60 Start set password conversion 61 Decompose the communication / output password 62 Extract a value from the number table using the decomposed value as an argument 63 Perform inverse function processing using the decomposed function result and the value of the extracted number sequence 64 Complete set password conversion
Claims
1. A password protection program that specifies a password protection operation of a system that includes a control device for controlling a controlled device and a control device that monitors the control device or controls the control device by writing data or a program therein, and the control device and the control device communicate with each other according to an arbitrary communication standard, Regarding a set password set in the control device to restrict access to the control device, each time the control device newly sets the set password in the control device or requests the control device for the set password that has already been set, an arbitrary first argument is set, a function process is performed between the set password and data corresponding to the first argument from a common sequence table provided in both the control device and the control device, and a communication password is created by adding the number of digits of the first argument to the number of digits of the set password, and then the communication is performed. When the control device or the control equipment has a function of outputting data whose access is restricted to the outside, each time the set password is newly set and output to the outside, or each time the set password is changed and output to the outside, an arbitrary second argument is set for data in which access to the control device is restricted by the set password, and the function processing is performed using the set password and data corresponding to the second argument in the sequence table used in creating the communication password or a new sequence table, and the result of the function processing used in creating the communication password or the result of the new function processing is replaced with an output password obtained by adding the number of digits of the second argument to the number of digits of the set password, and outputting the result to the outside. A password protection program that causes the system to execute the following: decomposing the communication password communicated to the control device or the control device, or the input output password, into arguments and the results of function processing used in creating the communication password or the output password, and performing function processing in the reverse direction to that used at the time of creation using the data corresponding to the arguments obtained by decomposition in the sequence table and the results of the function processing, thereby extracting the set password.
2. The password protection program of claim 1, further comprising: a password protection program for controlling a control device that is configured to restrict access to the control device; when the control device is restricted by the set password and the control device authenticates the set password, if the set password does not match, a waiting time is passed before re-entry is allowed, and if the set password again does not match, a waiting time is extended beyond the previous waiting time.
3. The password protection program of claim 2, further comprising the step of causing the system to execute the following: when the control device is restricted by a set password set in the control device to restrict access to the control device and the control device authenticates the set password, if the set password does not match, the control device communicates to the control device the next waiting time or the number of times that it does not match, and if the set password matches, the control device communicates to the control device that the next waiting time or the number of times that it does not match has been reset to its initial value.
4. The password protection program of claim 3, further causing the system to execute the following: when the control device is restricted by the set password and the waiting time or number of mismatches is not an initial value, the control device communicates to the control device the waiting time or number of mismatches in the first communication to the control device.
5. A password protection program that specifies a password protection operation of a system that includes a control device for controlling a controlled device and a control device that monitors the control device or controls the control device by writing data or a program therein, and the control device and the control device communicate with each other according to an arbitrary communication standard, A password protection program which causes the system to execute the following: when the control device is restricted by a setting password which is set in the control device to restrict access to the control device and the control device authenticates the setting password, if the setting password does not match, a waiting time has elapsed before re-entry is allowed, and if the setting password still does not match, a waiting time which is longer than the previous waiting time is set.
6. The password protection program of claim 5, further comprising: a password protection program for controlling a control device that is configured to restrict access to the control device, the password protection program further comprising: when the control device is restricted by a set password set in the control device to restrict access to the control device and the control device authenticates the set password, if the set password does not match, the control device communicates to the control device the next waiting time or the number of times that the set password does not match, and when the set password matches, the control device communicates to the control device that the next waiting time or the number of times that the set password does not match has been reset to its initial value.
7. The password protection program of claim 6, further causing the system to execute the following: when the control device is restricted by the set password and the waiting time or number of mismatches is not an initial value, the control device communicates to the control device the waiting time or number of mismatches in the first communication to the control device.
Citation Information
Patent Citations
Programmable controller and controlling method therefor
JP2002229608A
Password authentication circuit and method
JP2013142917A
Programmable controller
JP2013171513A
Portable electronic device, program, processing system, terminal and IC card
JP2018101218A
System and Method for Secure Remote Control of a Medical Device
US20210136048A1