Key management system, key management method, and program

The key management system addresses the challenge of pairing digital keys and locks by using secure elements to generate and verify common password information, enhancing security and reducing productivity losses.

JP2025080980APending Publication Date: 2025-05-27TOPPAN HOLDINGS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023194430
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-15
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Digital key systems face challenges in achieving physical pairing between smartphones and locks, as they are manufactured by different entities, leading to productivity losses and security risks.

Method used

A key management system that utilizes secure elements in both key devices and locks to generate and verify common password information, enabling secure pairing without the need for physical co-manufacturing.

Benefits of technology

This solution reduces productivity losses and security risks by allowing secure and efficient pairing of digital keys and locks, independent of manufacturing locations, while ensuring secure management of key information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025080980000001_ABST
    Figure 2025080980000001_ABST
Patent Text Reader

Abstract

To provide a key management system, key management method, and program capable of reducing productivity deterioration and security risks in pairing between keys and locks.SOLUTION: In a key management system, a key management apparatus generates password information common to all key devices and locks, the key device stores password information distributed from the key management apparatus in a first secure element, generates first verification information obtained by encrypting a first identifier unique to the key device using the password information, and verifies a pairing relationship with a lock on the basis of the first verification information, and the lock stores the password information distributed from the key management apparatus in a second secure element, generates second verification information obtained by encrypting a second identifier unique to the lock using the password information, and verifies a pairing relationship with the key device on the basis of the second verification information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a key management system, a key management method, and a program. [Background technology]

[0002] Traditionally, a key and lock combination should be one-to-one, and the physical key was paired with the lock during the manufacturing process to ensure the correct combination.

[0003] In recent years, digital keys using smartphones are becoming more common. These digital keys also require pairing of the smartphone with the lock, and various techniques for this purpose have been proposed (for example, Patent Document 1 below). [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 6888673 Summary of the Invention [Problem to be solved by the invention]

[0005] However, with digital keys, it is difficult to achieve a physical pair because the smartphone and the lock are manufactured in different places. Although it is not impossible to pair a smartphone and a lock, the smartphone and the lock are manufactured by different manufacturers, so it is not possible to share the physical pair in advance. Sharing the pair would require the management of a huge amount of data, and it would be impossible to manufacture the smartphone until the lock information is received, leading to a decrease in productivity. As an alternative, it would be possible to distribute and have the smartphone application hold common key pattern information, but this is not recommended from the perspective of security risks, such as the application being analyzed and the key pattern information being revealed, or a third party's smartphone being spoofed.

[0006] In view of the above-mentioned problems, an object of the present invention is to provide a key management system, a key management method, and a program that can reduce productivity losses and security risks in key and lock pairing. [Means for solving the problem]

[0007] In order to solve the above-mentioned problems, a key management system according to one embodiment of the present invention has a key management device, a key device having a first secure element, and a lock having a second secure element, wherein the key management device comprises a password information generation unit that generates password information common to all of the key devices and all of the locks, the key device comprises a first memory unit that stores the password information distributed from the key management device in the first secure element, a first encryption processing unit that generates first verification information in which a first identifier unique to the key device is encrypted with the password information, and a first key pair verification unit that verifies a pair relationship with the lock based on the first verification information, and the lock comprises a second memory unit that stores the password information distributed from the key management device in the second secure element, a second encryption processing unit that generates second verification information in which a second identifier unique to the lock is encrypted with the password information, and a second key pair verification unit that verifies the pair relationship with the key device based on the second verification information.

[0008] A key management method according to one embodiment of the present invention is a key management method in a key management system having a key management apparatus, a key device having a first secure element, and a lock having a second secure element, the method including: a password information generation process of the key management apparatus generating password information common to all of the key devices and all of the locks; a first storage process in which a first storage unit of the key device stores the password information distributed from the key management apparatus in the first secure element; and a first encryption processing unit of the key device generating first verification information by encrypting a first identifier unique to the key device with the password information. a first encryption process step in which a first key pair verification unit of the key device verifies the pair relationship with the lock based on the first verification information; a second storage process step in which a second storage unit of the lock stores the password information distributed from the key management device in the second secure element; a second encryption process step in which a second encryption processing unit of the lock generates second verification information by encrypting a second identifier unique to the lock with the password information; and a second key pair verification process in which a second key pair verification unit of the lock verifies the pair relationship with the key device based on the second verification information.

[0009] A program according to one aspect of the present invention is a program for causing a computer to function as a key management system having a key management apparatus, a key device having a first secure element, and a lock having a second secure element, the program comprising: a password information generating means for generating password information common to all of the key devices and all of the locks, the key device having a first secure element, a first storage means for storing the password information distributed from the key management apparatus in the first secure element, and the key device storing a first identifier unique to the key device in the password information generating means. a first cryptographic processing means for generating first verification information encrypted with password information, a first key pair verification means for the key device to verify the pair relationship with the lock based on the first verification information, a second storage means for the lock to store the password information distributed from the key management device in the second secure element, a second cryptographic processing means for the lock to generate second verification information encrypted with a second identifier unique to the lock with the password information, and a second key pair verification means for the lock to verify the pair relationship with the key device based on the second verification information. Effect of the Invention

[0010] According to the present invention, it is possible to reduce productivity losses and security risks in key and lock pairing. [Brief description of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram illustrating an example of a configuration of a key management system according to an embodiment of the present invention. [Diagram 2] 2 is a block diagram showing an example of a functional configuration of a key management device according to the present embodiment. FIG. [Diagram 3] FIG. 2 is a block diagram showing an example of a functional configuration of a lock according to the present embodiment. [Figure 4] FIG. 2 is a block diagram showing an example of a functional configuration of the smartphone according to the embodiment. [Diagram 5]FIG. 2 is a block diagram showing an example of a functional configuration of a smart key according to the present embodiment. [Figure 6] 11 is a sequence diagram showing an example of a flow of a process for storing password information in the smartphone according to the embodiment. FIG. [Figure 7] FIG. 11 is a sequence diagram showing an example of a flow of a process for storing password information in a smart key according to the embodiment. [Figure 8] 11 is a sequence diagram showing an example of the flow of a process for storing password information in a lock according to the present embodiment. FIG. [Figure 9] FIG. 11 is a sequence diagram showing an example of the flow of a key pair verification process according to the embodiment. [Figure 10] 11 is a sequence diagram showing an example of a flow of a shared key use permission process according to the embodiment. FIG. [Figure 11] 11 is a sequence diagram showing an example of the flow of a process for stopping the use of a shared key according to the embodiment. FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0013] <1. Configuration of the key management system> The configuration of a key management system according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an example of the configuration of a key management system according to this embodiment.

[0014] The key management system 1 shown in Fig. 1 is a system for managing keys using devices with secure elements (SEs) mounted on keys and locks. A secure element is a tamper-resistant IC (Integrated Circuit) chip that has a storage area and encryption functions. By using a secure element, it is possible to safely manage identifiers unique to each device (hereinafter also referred to as "individual identifiers") and perform encryption calculations.

[0015] As shown in Fig. 1, the key management system 1 includes a key management apparatus 10, a lock 20, and a key device 30. As an example of the key device 30, a smartphone 40 and a smart key 50 are shown in Fig. 1.

[0016] (1) Key management device 10 The key management device 10 is a device that manages the lock 20 and the key device 30. The key management device 10 is, for example, one or more servers or PCs (Personal Computers). The key management device 10 is connected to the lock 20 and the smartphone 40 so as to be able to communicate with each other.

[0017] (2) 20 tablets The lock 20 is a device for making an object available or unavailable. The lock 20 is communicatively connected to each of the key management device 10 and the key device 30. As shown in FIG. 1, the lock 20 includes a secure element 21 (second secure element). The secure element 21 stores an individual identifier (second identifier) ​​of the lock 20. The individual identifier of the lock 20 is hereinafter also referred to as the "lock ID." The object is, for example, an object whose unlocked or locked state can be changed physically, or an object whose unlocked or locked state can be controlled electrically. An object whose unlocked or locked state can be changed physically is, for example, a door or other fixture that opens and closes. An object whose unlocked or locked state can be controlled electrically is, for example, an automobile. Note that the object is not limited to these examples.

[0018] (3) Key Device 30 The key device 30 is a device that serves as a key for opening and closing the lock 20. The key device 30 of this embodiment is a device equipped with a secure element (first secure element). The secure element equipped in the key device 30 stores an individual identifier (first identifier) ​​of the key device 30. The individual identifier of the key device 30 is also referred to as a "key ID" below. In this embodiment, we will explain an expensive, high-performance, multi-functional key device 30 and an inexpensive, low-performance, limited-function key device 30. The expensive, high-performance, multi-functional key device 30 may have a function capable of communicating with the key management device 10 in addition to the lock 20. On the other hand, the inexpensive, low-performance, limited-function key device 30 is assumed to be connected so as to be able to communicate only with the lock 20.

[0019] (3-1) Smartphone 40 The smartphone 40 is an example of an expensive, high-performance, and multifunctional key device 30. The smartphone 40 functions as a digital key. As shown in FIG. 1, the smartphone 40 includes a secure element 41 (first secure element). The secure element 41 stores an individual identifier (first identifier) ​​of the smartphone 40. The individual identifier of the smartphone 40 is also referred to as a "key ID" below.

[0020] (3-2) Smart Key 50 The smart key 50 is an example of a key device 30 that is inexpensive, has low performance, and has limited functions. As shown in Fig. 1, the smart key 50 includes a secure element 51 (first secure element). The secure element 51 stores an individual identifier (first identifier) ​​of the smart key 50. The individual identifier of the smart key 50 is also referred to as a "key ID" below.

[0021] <2. Functional configuration of the key management device> The configuration of the key management system 1 according to this embodiment has been described above. Next, the functional configuration of the key management device 10 according to this embodiment will be described with reference to Fig. 2. Fig. 2 is a block diagram showing an example of the functional configuration of the key management device 10 according to this embodiment. As shown in FIG. 2, the key management device 10 includes a communication unit 110, a storage unit 120, and a control unit .

[0022] (1) Communications Department 110 The communication unit 110 has a function of transmitting and receiving various information. For example, the communication unit 110 is communicably connected to the lock 20 and the smartphone 40 of the key device 30, and transmits and receives various information between the lock 20 and the smartphone 40.

[0023] (2) Storage section 120 The storage unit 120 has a function of storing various information. The function of the storage unit 120 is to store various information such as a storage medium provided as hardware in the key management device 10, for example, a hard disk drive (HDD). Drive), SSD (Solid State Drive), flash memory, EEPROM (Electrically Erasable Programmable It may be composed of Read Only Memory (RAM), Random Access read / write Memory (RAM), ROM (Read Only Memory), or any combination of these storage media.

[0024] (3) Control unit 130 The control unit 130 has a function of controlling the overall operation of the key management device 10. The function of the control unit 130 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) provided as hardware in the key management device 10 to execute a program. As shown in FIG. 1, the control unit 130 includes a password information generation unit 131 and a key usage control unit 132.

[0025] (3-1) Password information generation unit 131 The password information generation unit 131 has a function of generating password information. For example, the password information generation unit 131 generates password information common to all locks 20 and all key devices 30. In this embodiment, the method of generating password information is not particularly limited. However, the password information generation unit 131 generates password information having a data length that matches an advantage so as to be compatible with addition and scalar multiplication on an elliptic curve in the processing described below. For example, when NIST-P256 is adopted, the password information generation unit 131 generates password information with a data length of 256 bits=32 bytes.

[0026] The password information generated by the password information generation unit 131 is stored in the secure element of each device when the device is manufactured. When the key device 30 is a smartphone 40, the password information may be transmitted to the smartphone via the communication unit 110.

[0027] (3-2) Key usage control unit 132 The key usage control unit 132 has a function of controlling the use of the common key between the lock 20 and the key device 30. For example, the key usage control unit 132 performs a process of permitting the use of the common key based on the pair information. The pair information is information indicating the pair of the lock 20 and the key device 30. The pair information is information generated as a result of the key pair verification process between the lock 20 and the key device 30, and is transmitted from the lock 20 to the key management device 10. The key usage control unit 132 verifies whether the lock 20 corresponding to the lock ID included in the pair information transmitted from the lock 20 is officially manufactured. If the lock 20 is officially manufactured, the key usage control unit 132 transmits a permission to use the common key to the lock 20 corresponding to the lock ID included in the pair information. The permission to use the common key is transmitted to the lock 20 via the communication unit 110.

[0028] The key usage control unit 132 also performs processing to stop the use of the common key. For example, when a key device 30 that is permitted to use the common key is lost, the key usage control unit 132 stops the use of the common key that can be used by the key device 30. Specifically, when the key usage control unit 132 receives the key ID of the lost key device 30 from the lock 20, it instructs the lock 20 that is paired with the key device 30 corresponding to the key ID to stop using the common key. The instruction to stop using the common key is sent to the lock 20 via the communication unit 110.

[0029] <3. Lock function configuration> The functional configuration of the key management device 10 according to this embodiment has been described above. Next, the functional configuration of the lock 20 according to this embodiment will be described with reference to Fig. 3. Fig. 3 is a block diagram showing an example of the functional configuration of the lock 20 according to this embodiment. As shown in FIG. 2, the lock 20 includes a communication unit 210, a secure element unit 220 (second secure element), and a control unit 230.

[0030] (1) Communications unit 210 The communication unit 210 has a function of transmitting and receiving various information. For example, the communication unit 210 is communicably connected to each of the key management device 10 and the key device 30, and transmits and receives various information to and from each of the key management device 10 and the key device 30.

[0031] (2) Secure element unit 220 The secure element unit 220 has a function of securely managing various information related to the key management system 1. The function of the secure element unit 220 is realized by a secure element 21 that the lock 20 has as hardware. As shown in FIG. 2, the secure element unit 220 includes a cryptographic processing unit 221 (second cryptographic processing unit), a storage unit 222 (second storage unit), and a key pair verification unit 223 (second key pair verification unit).

[0032] (2-1) Encryption processing unit 221 The encryption processing unit 221 has a function of performing encryption processing. For example, the encryption processing unit 221 generates verification information (second verification information) in which the lock ID is encrypted with password information. Hereinafter, the verification information in which the lock ID is encrypted with password information is also referred to as "lock verification information."

[0033] (2-2) Storage section 222 The storage unit 222 has a function of storing various information related to the key management system 1. For example, the storage unit 222 stores password information distributed from the key management device 10. As a result, the password information is stored in the secure element 21 (second secure element).

[0034] (2-3) Key pair verification unit 223 The key pair verification unit 223 has a function of verifying a key pair. Verification of a key pair is to confirm whether or not the pair between the lock 20 and the key device 30 is correct. For example, the key pair verification unit 223 verifies the pair relationship between the lock 20 and the key device 30 based on the lock verification information. Verification of a key pair (key pair generation) is performed using a password authentication method and a key sharing algorithm.

[0035] In verifying the pair relationship between the lock 20 and the key device 30, the key pair verification unit 223 generates a common key that is the same as the common key generated by the key pair verification unit (first key pair verification unit) on the key device 30 side.

[0036] (3) Control unit 230 The control unit 230 has a function of controlling the overall operation of the lock 20. The functions of the control unit 230 are realized, for example, by causing a CPU or GPU that the lock 20 has as hardware to execute a program. As shown in FIG. 2, the control unit 230 includes a communication control unit 231, an information management unit 232, and a lock control unit 233.

[0037] (3-1) Communication control unit 231 The communication control unit 231 has a function of controlling the communication executed by the communication unit 210. For example, the communication control unit 231 controls the transmission of pair information from the lock 20 to the key management device 10. Assume that the pair relationship between the lock 20 and the key device 30 is confirmed to be correct by the key pair verification unit 223. In this case, the communication control unit 231 transmits pair information indicating that the lock 20 and the key device 30 are paired from the communication unit 210 to the key management device 10.

[0038] (3-2) Information Management Department 232 The information management unit 232 has a function of managing information used in the lock 20. For example, the information management unit 232 manages the storage of information received by the communication unit 210 in the secure element 21, the output of information stored in the secure element 21, and the like.

[0039] (3-3) Lock control unit 233 The lock control unit 233 has a function of controlling the state of the lock 20. If a control instruction is received when the lock 20 is in an unlocked state, the lock control unit 233 changes the state of the lock 20 from the unlocked state to the locked state. On the other hand, if a control instruction is received when the lock 20 is in a locked state, the lock control unit 233 changes the state of the lock 20 from the locked state to the unlocked state.

[0040] <4. Smartphone functional configuration> The functional configuration of the lock 20 according to this embodiment has been described above. Next, the functional configuration of the smartphone 40 according to this embodiment will be described with reference to Fig. 4. Fig. 4 is a block diagram showing an example of the functional configuration of the smartphone 40 according to this embodiment. As shown in FIG. 4, the smartphone 40 includes a communication unit 410, a secure element unit 420, a control unit 430, and an output unit 440.

[0041] (1) Communications Department 410 The communication unit 410 has a function of transmitting and receiving various information. For example, the communication unit 410 is communicably connected to the key management device 10 and the lock 20, and transmits and receives various information between the key management device 10 and the lock 20.

[0042] (2) Secure element unit 420 The secure element unit 420 has a function of securely managing various information related to the key management system 1. The function of the secure element unit 420 is realized by a secure element 41 that the smartphone 40 has as hardware. As shown in FIG. 4, the secure element unit 420 includes a cryptographic processing unit 421 (first cryptographic processing unit), a storage unit 422 (first storage unit), and a key pair verification unit 423 (first key pair verification unit).

[0043] (2-1) Encryption processing unit 421 The encryption processing unit 421 has a function of performing encryption processing. For example, the encryption processing unit 421 generates verification information (first verification information) in which the key ID is encrypted with password information. Hereinafter, the verification information in which the key ID is encrypted with password information is also referred to as "key verification information."

[0044] (2-2) Storage section 422 The storage unit 422 has a function of storing various information related to the key management system 1. For example, the storage unit 422 stores password information distributed from the key management device 10. As a result, the password information is stored in the secure element 41 (first secure element).

[0045] (2-3) Key pair verification unit 423 The key pair verification unit 423 has a function of verifying a key pair. For example, the key pair verification unit 423 verifies the pair relationship between the lock 20 and the key device 30 based on the key verification information. Verification of the key pair (key pair generation) is performed using a password authentication method and a key sharing algorithm.

[0046] In verifying the pair relationship between the lock 20 and the key device 30, the key pair verification unit 423 generates a common key that is the same as the common key generated by the key pair verification unit (second key pair verification unit) on the lock 20 side.

[0047] (3) Control unit 430 The control unit 430 has a function of controlling the overall operation of the smartphone 40. The function of the control unit 430 is realized, for example, by causing a CPU or a GPU that the smartphone 40 has as hardware to execute a program. As shown in FIG. 4, the control unit 430 includes a communication control unit 431, an information management unit 432, and a password information acquisition unit 433.

[0048] (3-1) Communication control unit 431 The communication control unit 431 has a function of controlling the communication executed by the communication unit 410. For example, the communication control unit 431 controls communication for a password information acquisition unit 433 (described later) to acquire password information from the key management device 10, and communication for a key pair verification unit 423 to verify the key pair with the lock 20.

[0049] (3-2) Information management department 432 The information management unit 432 has a function of managing information used in the smartphone 40. For example, the information management unit 432 manages the storage of information received by the communication unit 410 in the secure element 41, the output of information stored in the secure element 41, and the like.

[0050] (3-3) Password information acquisition unit 433 The password information acquisition unit 433 has a function of acquiring password information. For example, the password information acquisition unit 433 transmits a request for acquiring password information to the key management device 10 via the communication unit 410, and acquires the password information from the key management device 10.

[0051] (4) Output unit 440 The output unit 440 has a function of outputting various information. The output unit 440 is configured by, for example, an output device that the smartphone 40 has as hardware, for example, a display device such as a display device or a touch screen (touch panel), or an audio output device such as a speaker.

[0052] <5. Functional configuration of smart keys> The functional configuration of the smartphone 40 according to this embodiment has been described above. Next, the functional configuration of the smart key 50 according to this embodiment will be described with reference to Fig. 5. Fig. 5 is a block diagram showing an example of the functional configuration of the smart key 50 according to this embodiment. As shown in FIG. 5, the smart key 50 includes a communication unit 510, a secure element unit 520, and a control unit 530.

[0053] (1) Communications Unit 510 The communication unit 510 has a function of transmitting and receiving various information. For example, the communication unit 510 is communicably connected to the lock 20, and transmits and receives various information to and from the lock 20.

[0054] (2) Secure element unit 520 The secure element unit 520 has a function of securely managing various information related to the key management system 1. The function of the secure element unit 520 is realized by a secure element 51 that the smart key 50 has as hardware. As shown in FIG. 5, the secure element unit 520 includes a cryptographic processing unit 521 (first cryptographic processing unit), a storage unit 522 (first storage unit), and a key pair verification unit 523 (first key pair verification unit).

[0055] (2-1) Encryption processing unit 521 The encryption processing unit 521 has a function of performing encryption processing. For example, the encryption processing unit 521 generates key verification information (first verification information) by encrypting a key ID with password information.

[0056] (2-2) Storage section 522 The storage unit 522 has a function of storing various information related to the key management system 1. For example, the storage unit 522 stores password information distributed from the key management device 10. As a result, the password information is stored in the secure element 51 (first secure element).

[0057] (2-3) Key pair verification unit 523 The key pair verification unit 523 has a function of verifying a key pair. For example, the key pair verification unit 523 verifies the pair relationship between the lock 20 and the key device 30 based on the key verification information. Verification of the key pair (key pair generation) is performed using a password authentication method and a key sharing algorithm.

[0058] In verifying the pair relationship between the lock 20 and the key device 30, the key pair verification unit 523 generates a common key that is the same as the common key generated by the key pair verification unit (second key pair verification unit) on the lock 20 side.

[0059] (3) Control unit 530 The control unit 530 has a function of controlling the overall operation of the smart key 50. The function of the control unit 530 is realized, for example, by causing a CPU or a GPU provided as hardware in the smart key 50 to execute a program. As shown in FIG. 5, the control unit 530 includes a communication control unit 531 and an information management unit 532.

[0060] (3-1) Communication control unit 531 The communication control unit 531 has a function of controlling the communication executed by the communication unit 510. For example, the communication control unit 531 controls the communication for the key pair verification unit 523 to verify the key pair with the lock 20.

[0061] (3-2) Information management department 532 The information management unit 532 has a function of managing information used in the smart key 50. For example, the information management unit 532 manages the storage of information received by the communication unit 510 in the secure element 51, the output of information stored in the secure element 51, and the like.

[0062] <6. Processing flow> The above describes the functional configuration of the smart key 50 according to this embodiment. Next, the process flow according to this embodiment will be described. Note that, in the following, the process flow will be described using an example in which the target object is a door.

[0063] (1) Flow of storing password information on a smartphone The flow of a process for storing password information in the smartphone 40 according to the present embodiment will be described with reference to Fig. 6. Fig. 6 is a sequence diagram showing an example of the flow of a process for storing password information in the smartphone 40 according to the present embodiment. FIG. 6 shows an example of the flow of a process for storing password information in the secure element 41 of the smartphone 40 when the key device 30 is the smartphone 40.

[0064] As shown in FIG. 6, first, the password information generating unit 131 of the key management device 10 generates password information (hereinafter, also referred to as [w]) (step S101). In response to a user operation on the smartphone 40, the smartphone 40 installs an application for using the smartphone 40 as a digital key (hereinafter, also referred to as a "key application") (step S102). In response to a user operation on the key application, the password information acquisition unit 433 of the smartphone 40 transmits an acquisition request for the password information [w] to the key management device 10 (step S103). The acquisition request is transmitted from the communication unit 410 to the key management device 10 under the control of the communication control unit 431. When the communication unit 110 of the key management device 10 receives the request to acquire the password information [w] from the smartphone 40, the communication unit 110 distributes the password information [w] to the smartphone 40 (step S104).

[0065] The information management unit 432 of the smartphone 40 stores the password information [w] received by the communication unit 410 from the key management device 10 in the storage unit 422 of the secure element unit 420 (step S105). Next, the encryption processing unit 421 of the smartphone 40 encrypts the key ID (hereinafter also referred to as [ID_device]) of the smartphone 40 using the password information [w] as a key (hereinafter also referred to as [Kw]) (step S106). Next, the encryption processing unit 421 stores the ciphertext obtained by encrypting the key ID [ID_device] with the key [Kw] as key verification information (hereinafter, also indicated as [x]) in the storage unit 422 (step S107). Kw (ID_device).

[0066] (2) Flow of storing password information in a smart key The flow of a process for storing password information in the smart key 50 according to this embodiment will be described with reference to Fig. 7. Fig. 7 is a sequence diagram showing an example of the flow of a process for storing password information in the smart key 50 according to this embodiment. FIG. 7 shows an example of the flow of a process for storing password information in the secure element 51 of the smart key 50 when the key device 30 is a smart key 50.

[0067] As shown in FIG. 7, first, the password information generating unit 131 of the key management device 10 generates password information [w] (step S201). After generation, the password information generation unit 131 distributes the password information [w] to the manufacturing factory FC1 of the smart key 50 via the communication unit 110 (step S202). At the manufacturing factory FC1, the password information [w] distributed from the key management device 10 is stored in the secure element 51 of the smart key 50 during the manufacturing process (step S203).

[0068] The storage unit 522 of the secure element unit 520 of the smart key 50 stores the password information [w] stored during the manufacturing process (step S204). Next, the encryption processing unit 521 of the smart key 50 encrypts the key ID [ID_device] of the smart key 50 using the password information [w] as a key [Kw] (step S205). Next, the encryption processing unit 521 stores the ciphertext obtained by encrypting the key ID [ID_device] with the key [Kw] as the key verification information [x] in the storage unit 522 (step S206). Note that the key verification information [x] of the smart key 50 is stored in the Encryption Kw (ID_device).

[0069] (3) Flow of storing password information in a lock The flow of processing for storing password information in the lock 20 according to this embodiment will be described with reference to Fig. 8. Fig. 8 is a sequence diagram showing an example of the flow of processing for storing password information in the lock 20 according to this embodiment.

[0070] As shown in FIG. 8, first, the password information generating unit 131 of the key management device 10 generates password information [w] (step S301). After generation, the password information generation unit 131 distributes the password information [w] to the manufacturing factory FC2 of the lock 20 via the communication unit 110 (step S302). At the manufacturing factory FC2, the password information [w] distributed from the key management device 10 is stored in the secure element 21 of the lock 20 during the manufacturing process (step S303).

[0071] The storage unit 222 of the secure element unit 220 of the lock 20 stores the password information [w] that is stored during the manufacturing process (step S304). Next, the encryption processing unit 221 of the lock 20 encrypts the lock ID of the lock 20 (hereinafter also referred to as [ID_door]) using the password information [w] as a key [Kw] (step S305). Next, the encryption processing unit 221 stores the encrypted text obtained by encrypting the lock ID [ID_door] with the key [Kw] in the storage unit 222 as lock verification information (hereinafter, also referred to as [y]) (step S306). Kw (ID_door).

[0072] (4) Key pair verification process The flow of the key pair verification process according to this embodiment will be described with reference to Fig. 9. Fig. 9 is a sequence diagram showing an example of the flow of the key pair verification process according to this embodiment. The key pair verification process shown in Fig. 9 is common to all key devices 30. As an example, a process flow will be described in which the smart key 50 performs key pair verification process with the lock 20. The key pair verification process shown in Fig. 9 is a process that uses SPAKE2+, which combines password authentication and a key sharing algorithm. In the equation used in the key pair verification process shown in Figure 9, w0 and w1 are the same information as the password information [w], G is the base point of the elliptic curve, M and N are advantageous points (fixed values) of the elliptic curve, * represents scalar multiplication, and + represents addition (the same as the four basic arithmetic operations). Furthermore, X and Y are the advantageous points of the elliptic curve that are calculated and temporarily exchanged during pairing between the smart key 50 and the lock 20. X and Y are information that may be made public and that does not affect security even if they are exposed by eavesdropping or the like. Furthermore, Z and V are advantages of a secret elliptic curve calculated by the secure element (SE) of each of the smart key 50 and the lock 20 during pairing between the smart key 50 and the lock 20. Z and V are secret information that must not be revealed by eavesdropping or the like. Furthermore, L is the advantage point of the elliptic curve that can be calculated from the password information w1.

[0073] 9, first, the key pair verification unit 523 of the smart key 50 calculates [X] from the key verification information [x] (step S401). [X] is calculated by the following formula (1). X = x * G + w0 * M (1)

[0074] The key pair verification unit 523 of the smart key 50 transmits the calculated [X] to the lock 20 (step S402). In the following, it is assumed that the information transmitted from the key pair verification unit 523 to the lock 20 is transmitted from the communication unit 510 to the lock 20 under the control of the communication control unit 531.

[0075] When the communication unit 210 receives [X] from the smart key 50, the key pair verification unit 223 of the lock 20 calculates [Y] from the lock verification information [y] (step S403). [Y] is calculated by the following formula (2). Y = y * G + w0 * N (2)

[0076] Next, the key pair verification unit 223 calculates [Z] from [y] and [X] (step S404). [Z] is calculated by the following formula (3). Z = y * (X - w0 * M) (3)

[0077] Next, the key pair verification unit 223 calculates [V] from [y] (step S405). [V] is calculated by the following formula (4). In formula (4), L=w1*G. V = y * L (4)

[0078] Next, the key pair verification unit 223 calculates [K] from [X], [Y], [Z], and [V] (step S406). [K] is calculated by the following formula (5). K=SHA-256(len(X)||X||len(Y)||Y||len(Z)||Z||len(V)||V||len(w0)||w0) ···(5)

[0079] Next, the key pair verification unit 223 calculates [K1] from [K] using a key derivation function (step S407).

[0080] Next, the key pair verification unit 223 calculates [M1] from [K1] and [X] (step S408). [M1] is calculated by the following formula (6). M1 = CMAC(K1,X) (6)

[0081] The key pair verification unit 223 transmits the calculated [Y] and [M1] to the smart key 50 (step S409). In the following, it is assumed that the information transmitted from the key pair verification unit 223 to the smart key 50 is transmitted from the communication unit 210 to the smart key 50 under the control of the communication control unit 231.

[0082] When the communication unit 510 receives [Y] and [M1] from the lock 20, the key pair verification unit 523 of the smart key 50 calculates [Z] from [x] and [Y] (step S410). [Z] is calculated by the following formula (7). Z = x * (Y - w0 * N) (7)

[0083] Next, the key pair verification unit 523 calculates [V] from [Y] (step S411). [V] is calculated by the following formula (8). V = w1 * (Y - w0 * N) (8)

[0084] Next, the key pair verification unit 523 calculates [K] from [X], [Y], [Z], and [V] (step S412). [K] is calculated by the above-mentioned formula (5).

[0085] Next, the key pair verification unit 523 calculates [K1] from [K] using a key derivation function (step S413).

[0086] Next, the key pair verification unit 523 calculates [M1'] from [K1] and [X] (step S414). [M1'] is calculated by the following formula (9). M1' = CMAC(K1,X) (9)

[0087] Next, the key pair verification unit 523 compares [M1] received from the lock 20 with the calculated [M1'] (step S415). If the comparison result shows that [M1] and [M1'] match, the process proceeds to step S416. On the other hand, if [M1] and [M1'] do not match, the process ends. When the process ends, X, Y, Z, V, K, etc. calculated in the process so far are discarded.

[0088] If the process proceeds to step S416, the key pair verification unit 523 calculates [K2] from [K] using a key derivation function (step S416).

[0089] Next, the key pair verification unit 523 calculates [M2] from [K2] and [Y] (step S417). [M2] is calculated by the following formula (10). M2 = CMAC(K2,Y) (10)

[0090] The key pair verification unit 523 transmits the calculated [M2] to the lock 20 (step S418).

[0091] When the communication unit 210 receives [M2] from the smart key 50, the key pair verification unit 223 of the lock 20 calculates [K2] from [K] using a key derivation function (step S419).

[0092] Next, the key pair verification unit 223 calculates [M2'] from [K2] and [Y] (step S420). [M2'] is calculated by the following formula (11). M2' = CMAC(K2,Y) (11)

[0093] Next, the key pair verification unit 223 compares [M2] received from the smart key 50 with the calculated [M2'] (step S421). If the comparison result shows that [M2] and [M2'] match, the process proceeds to step S422. On the other hand, if [M2] and [M2'] do not match, the process ends. When the process ends, X, Y, Z, V, K, etc. calculated in the process so far are discarded.

[0094] If the process proceeds to step S422, the key pair verification unit 223 notifies the smart key 50 that the key pair generation has been successful (step S422).

[0095] [Z] calculated by the key pair verification unit 223 of the lock 20 in step S404 and [V] calculated in step S405 can be expanded as follows. Z=y*(X-w0*M) =y*((x*G+w0*M)-w0*M) =y*(x*G)=y*x*G=x*y*G V=y*L =y*(w1*G) =w1*y*G

[0096] Moreover, [Z] calculated in step S410 by the key pair verification unit 523 of the smart key 50 and [V] calculated in step S411 can be expanded as follows. Z=x*(Y-w0*N) =x*((y*G+w0*N)-w0*N) =x*(y*G)=x*y*G V=w1*(Y-w0*N) =w1*((y*G+w0*N)-w0*N) =w1*(y*G) =w1*y*G

[0097] As described above, the key pair verification unit 223 of the lock 20 and the key pair verification unit 523 of the smart key 50 can calculate a common [K] (common key) because they can expand the [Z] and [V] calculated by each unit in the same way.

[0098] Furthermore, in this embodiment, [X] calculated by the key pair verification unit 523 of the smart key 50 in step S401 is transmitted from the smart key 50 to the lock 20 in step S402. In this embodiment, [X] is calculated using an encryption algorithm that allows decryption from [X] to [x].

[0099] (5) Flow of the shared key usage permission process The flow of a process for granting permission to use a shared key according to this embodiment will be described with reference to Fig. 10. Fig. 10 is a sequence diagram showing an example of the flow of a process for granting permission to use a shared key according to this embodiment.

[0100] As shown in FIG. 10, first, the key pair verification unit 223 of the lock 20 calculates key verification information [x] from [X] received from the smart key 50 in the above-mentioned step S402 (step S501).

[0101] Next, the key pair verification unit 223 calculates the key ID [ID_device] from the key verification information [x] (step S502). The key ID [ID_device] is calculated by the following formula (12). ID_device=Dec Kw (x) ...(12)

[0102] Next, the key pair verification unit 223 of the lock 20 transmits the pair information to the key management device 10 (step S503). The pair information is information including the key ID [ID_device] and the lock ID [ID_door].

[0103] When the communication unit 110 receives the pair information from the lock 20, the key usage control unit 132 of the key management device 10 verifies the lock ID [ID_door] included in the pair information (step S504).

[0104] If the lock ID [ID_door] is correct (step S505 / YES), the process proceeds to step S506. On the other hand, if the lock ID [ID_door] is incorrect (step S505 / NO), the process proceeds to step S510.

[0105] If the process proceeds to step S506, key usage control unit 132 registers (stores) the pair information in storage unit 120 (step S506). After registration, the key usage control unit 132 transmits permission to use the common key [K] to the lock 20 via the communication unit 110 (step S507).

[0106] When the communication unit 210 of the lock control unit 233 of the lock 20 receives permission to use the common key [K] from the key management device 10, the lock control unit 233 starts encrypted communication with the key device 30 (step S508). Depending on the result of the encrypted communication, the lock control unit 233 controls the locked or unlocked state of the lock 20 (step S509). When the process proceeds to step S510, the key management device 10 notifies the lock 20 of an error (step S510).

[0107] (6) Procedure for suspending use of the shared key The flow of the process of suspending the use of the shared key according to this embodiment will be described with reference to Fig. 11. Fig. 11 is a sequence diagram showing an example of the flow of the process of suspending the use of the shared key according to this embodiment. The following describes a case where the user has lost the key device 30. Note that the user who has lost the key device 30 can input a notice of this fact from the lock 20.

[0108] As shown in FIG. 11, first, when the lock control unit 233 of the lock 20 receives an input from the user that the key device 30 has been lost, the lock control unit 233 notifies the key management apparatus 10 of the loss (step S601).

[0109] The key usage control unit 132 of the key management apparatus 10 searches for the key ID [ID_device] of the lost key device 30 from among the registered pair information (step S602). Next, the key usage control unit 132 extracts the lock ID [ID_door] that pairs with the searched key ID [ID_device] (step S603). Next, the key usage control unit 132 pushes a command to stop the use of the common key [K] to the lock 20 corresponding to the extracted lock ID [ID_door] (step S604).

[0110] When the communication unit 210 receives a push from the key management device 10 to stop using the common key [K], the lock control unit 233 of the lock 20 discards the specified common key [K] (step S605). As a result, the key device 30 lost by the user cannot be used to open the lock 20. This makes it possible to prevent the key device 30 lost by the user from being used illegally.

[0111] As described above, the key management system 1 according to this embodiment includes a key management apparatus 10, a key device 30 (smartphone 40 or smart key 50) equipped with a first secure element (secure element 41 or 51), and a lock 20 equipped with a second secure element (secure element 21). The key management apparatus 10 includes a password information generation unit 131 that generates password information common to all key devices 30 and all locks 20. The key device 30 includes a first memory unit (memory unit 422 or 522) that stores password information distributed from the key management apparatus 10 in the first secure element, and a first secure element specific to the key device 30. The lock 20 is equipped with a first encryption processing unit (encryption processing unit 421 or 521) that generates first verification information in which an identifier is encrypted with password information, and a first key pair verification unit (key pair verification unit 423 or 523) that verifies the pair relationship with the lock 20 based on the first verification information. The lock 20 is equipped with a second memory unit (memory unit 222) that stores password information distributed from the key management device 10 in a second secure element, a second encryption processing unit (encryption processing unit 221) that generates second verification information in which a second identifier unique to the lock 20 is encrypted with the password information, and a second key pair verification unit (key pair verification unit 223) that verifies the pair relationship with the key device 30 based on the second verification information.

[0112] With this configuration, even if the key and the lock are manufactured in different places, key generation can be performed during pairing of the key and the lock, and the key and the lock are not limited by the manufacturing place. Also, since the key and the lock are not limited by the manufacturing place, pairing can be performed at the time of delivery at the store, and a decrease in productivity can be avoided. Furthermore, information related to key generation is managed by the secure element of each device, so security risks can be avoided. Therefore, the key management system 1 according to this embodiment makes it possible to reduce the decrease in productivity and security risks in pairing keys and locks.

[0113] In addition, when using the smartphone 40 as the key device 30, it was necessary to prepare a spare physical key device 30 in case the smartphone 40 runs out of charge or breaks down. In the key management system 1 according to the present embodiment, a pair with the lock 20 can be generated and the lock 20 can be opened regardless of the price, performance, or function of the key device 30. Therefore, a smart key 50, which is inexpensive, has low performance, and has limited functions, can be used as the key device 30 as a spare for the smartphone 40. This allows the user to easily prepare a spare key device 30.

[0114] Furthermore, as with conventional keys, if the key device 30 is lost, it is necessary to invalidate the lost key device 30. In the key management system 1 according to this embodiment, the fact that the key device 30 is lost can be notified to the key management apparatus 10 via the lock 20. This allows the key management apparatus 10 to invalidate the pair between the key device 30 and the lock 20 based on the pair information of the lost key device 30. This makes it possible to prevent the lost key device 30 from being used fraudulently.

[0115] <7. Variations> An embodiment of the present invention has been described. Next, modified examples of the embodiment of the present invention will be described. The modified examples described below may be applied alone to the embodiment of the present invention, or may be applied in combination to the embodiment of the present invention. The modified examples may be applied in place of the configuration described in the embodiment of the present invention, or may be applied in addition to the configuration described in the embodiment of the present invention.

[0116] In the above embodiment, an example in which [x] is obtained from [X] at the lock 20 has been described, but the present invention is not limited to such an example. [X] may be transmitted from the lock 20 to the key management device 10, and [x] may be obtained from [X] at the key management device 10.

[0117] Furthermore, the key ID [ID_device] in the above-described embodiment may be assigned information other than the key ID. For example, the key ID [ID_device] may be assigned an Identifier, Date, Algorithm, ServiceID, UserID, etc. The Identifier is a pure individual identifier of the key (12 bytes). The Date is an expiration date (8 bytes). The Algorithm is an encryption function (4 bytes) that the key can use. The ServiceID is a door lock service flag (4 bytes) for which the key can be registered. The UserID is an administrator ID of the key (4 bytes).

[0118] In the above-described embodiment, the key device 30 functioning as a digital key is the smartphone 40, but is not limited to this example. For example, the key device 30 functioning as a digital key may be a tablet terminal or a wearable device.

[0119] The above describes the modified embodiment of the present invention. Note that some or all of the functions of the key management system 1, the key management device 10, the lock 20, the key device 30, the smartphone 40, and the smart key 50 in the above-mentioned embodiment may be realized by a computer. In that case, a program for realizing this function may be recorded in a computer-readable recording medium, and the program recorded in the recording medium may be read into a computer system and executed to realize the function. Note that the "computer system" here includes hardware such as an OS and peripheral devices. In addition, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, an optical magnetic disk, a ROM, a CD-ROM, and a storage device such as a hard disk built into a computer system. Furthermore, the "computer-readable recording medium" may include a medium that dynamically holds a program for a short period of time, such as a communication line when a program is transmitted via a network such as the Internet or a communication line such as a telephone line, and a medium that holds a program for a certain period of time, such as a volatile memory inside a computer system that is a server or client in that case. Furthermore, the above program may be for realizing part of the functions described above, or may be capable of realizing the functions described above in combination with a program already recorded in a computer system, or may be realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0120] Although the embodiment of the present invention has been described in detail above with reference to the drawings, the specific configuration is not limited to the above, and various design changes, etc. are possible within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]

[0121] 1...key management system, 10...key management device, 20...lock, 21...secure element, 30...key device, 40...smartphone, 41...secure element, 50...smart key, 51...secure element, 110...communication unit, 120...storage unit, 130...control unit, 131...password information generation unit, 132...key usage control unit, 210...communication unit, 220...secure element unit, 221...encryption processing unit, 222...storage unit, 223...key pair verification unit, 230...control unit, 231 ...Communication control unit, 232...information management unit, 233...lock control unit, 410...communication unit, 420...secure element unit, 421...encryption processing unit, 422...storage unit, 423...key pair verification unit, 430...control unit, 431...communication control unit, 432...information management unit, 433...password information acquisition unit, 440...output unit, 510...communication unit, 520...secure element unit, 521...encryption processing unit, 522...storage unit, 523...key pair verification unit, 530...control unit, 531...communication control unit, 532...information management unit

Claims

1. A system including a key management apparatus, a key device having a first secure element, and a lock having a second secure element, The key management device a password information generating unit for generating password information common to all of the key devices and all of the locks; Equipped with The key device is a first storage unit that stores the password information distributed from the key management device in the first secure element; a first encryption processing unit that generates first verification information by encrypting a first identifier unique to the key device with the password information; a first key pair verification unit that verifies a pair relationship with the lock based on the first verification information; Equipped with The tablet comprises: a second storage unit that stores the password information distributed from the key management device in the second secure element; a second encryption processor that generates second verification information by encrypting a second identifier unique to the lock with the password information; a second key pair verification unit that verifies a pair relationship with the key device based on the second verification information; 1. A key management system comprising:

2. The tablet comprises: a communication control unit that transmits pair information indicating that the key device and the lock are paired to the key management device when the verification of the pair relationship confirms that the pair relationship between the key device and the lock is correct; Further comprising: The key management system of claim 1 .

3. The key management device a key usage control unit that verifies whether the lock corresponding to the second identifier included in the pair information transmitted from the lock is an officially manufactured lock, and if the lock is an officially manufactured lock, transmits a usage permission for a common key to the lock corresponding to the second identifier included in the pair information; Further comprising: The key management system of claim 2 .

4. When the key usage control unit receives the first identifier of the lost key device from the lock, the key usage control unit instructs the lock that is paired with the key device corresponding to the first identifier to stop using the common key. The key management system of claim 3 .

5. The first key pair verification unit generates a common key in verifying a pair relationship with the lock, the second key pair verification unit generates the same common key as that generated by the first key pair verification unit in verifying the pair relationship with the key device; The key management system of claim 1 .

6. A key management method in a key management system having a key management apparatus, a key device having a first secure element, and a lock having a second secure element, comprising: a password information generating process of the key management device for generating password information common to all of the key devices and all of the locks; a first storage step in which a first storage unit of the key device stores the password information distributed from the key management device in the first secure element; a first encryption processing step in which a first encryption processing unit of the key device generates first verification information by encrypting a first identifier unique to the key device with the password information; a first key pair verification step in which a first key pair verification unit of the key device verifies a pair relationship with the lock based on the first verification information; a second storage step in which a second storage unit of the lock stores the password information distributed from the key management device in the second secure element; a second encryption process in which a second encryption unit of the lock generates second verification information by encrypting a second identifier unique to the lock with the password information; a second key pair verification step in which a second key pair verification unit of the lock verifies a pair relationship with the key device based on the second verification information; 1. A computer implemented key management method comprising:

7. A program for causing a computer to function as a key management system having a key management apparatus, a key device having a first secure element, and a lock having a second secure element, the program comprising: The computer, a password information generating means for generating password information common to all of the key devices and all of the locks; a first storage means for storing the password information distributed from the key management device in the first secure element of the key device; a first encryption processing means for generating first verification information by encrypting a first identifier unique to the key device with the password information; a first key pair verification means for verifying a pair relationship between the key device and the lock based on the first verification information; a second storage means for storing the password information distributed from the key management device in the second secure element; a second encryption processing means for generating second verification information by encrypting a second identifier unique to the lock with the password information; a second key pair verification means for verifying a pair relationship between the lock and the key device based on the second verification information; A program to function as a

Citation Information

Patent Citations

  • Systems and methods for authenticating and authorizing devices

    JP6888673B2