Communication method, communication device and computer program
The communication method enables cost-effective prevention of unauthorized network intrusions by allowing the first communication device to stop communication with the second device upon detection of specific events, thus addressing the limitations of existing cybersecurity measures.
Patent Information
- Application Number
- JP2023196903
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-20
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2043-11-20
AI Technical Summary
Existing measures to protect enterprise networks from cyberattacks, such as ransomware, are costly and require continuous management, often leading to undetected unauthorized intrusions.
A communication method that allows a first communication device to stop communication with a second communication device when a predetermined event occurs, such as retransmission of data, without relying on network access authentication.
This method effectively prevents unauthorized intrusion into a network at a lower cost without the need for sophisticated intrusion detection or prevention systems.
Smart Images

Figure 2025083166000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a communication method, a communication device, and a computer program.
Background Art
[0002] In order to reduce the damage caused by cyberattacks against enterprises, it is necessary to take appropriate measures. As one of such cyberattacks, in recent years, malware called ransomware has been prevalent worldwide.
[0003] Patent Document 1 discloses a technique for detecting a specific request in the kernel space corresponding to a predetermined request made in the user space, and determining that the device is infected with ransomware when the request is detected at a predetermined frequency.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] In order to protect the enterprise network from cyberattacks, it is necessary to hire IT technicians who are knowledgeable about networks and security, build a security system, introduce a system for detecting unauthorized access and preventing unauthorized intrusion, and check the logs of these systems daily to confirm whether any problems have occurred. However, these measures not only require a large initial installation cost but also continuous management costs, so the reality is that sufficient measures cannot be taken. Many enterprises that cannot protect their networks despite investing a large amount of costs are implementing only network access authentication using user IDs and passwords to protect their networks from cyberattacks. For this reason, even if an unauthorized intrusion occurs in the enterprise network, it often happens that it is not noticed for a long time or over a long period, leaving the enterprise vulnerable to ransomware attacks, causing great damage to the enterprise. Moreover, as a drawback unique to the network society, all enterprises belonging to the supply chain are highly likely to suffer great damage.
[0006] The present invention has been made in view of such circumstances, and an object thereof is to provide a communication method, a communication device, and a computer program capable of preventing unauthorized intrusion into a network.
Means for Solving the Problem
[0007] This application includes a plurality of means for solving the above problems. For example, it adopts a communication method different from the conventional one and solves this problem without relying on network access authentication. The communication method is a communication method between a first communication device and a second communication device. When a predetermined event occurs in which the second communication device is in a communication state with the first communication device and the second communication device needs to retransmit data to the first communication device, the first communication device stops communication with the second communication device in response to the retransmission data transmitted by the second communication device.
Effect of the Invention
[0008] According to the present invention, unauthorized intrusion into a network can be prevented at low cost without introducing, installing, and operating a system such as unauthorized intrusion detection or prevention into the network.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Mode for Carrying Out the Invention
[0010] Hereinafter, embodiments of the present invention will be described. FIG. 1 is a diagram showing an example of unauthorized intrusion into a network that the communication method, communication device, communication system, and computer program of the present embodiment are intended to prevent. A line connection device is provided for an operator (company), and the line connection device is connected to an external terminal device Z. In FIG. 1, only one terminal device Z is illustrated, but there may be a plurality of terminal devices Z. The line connection device assumes a one-to-many connection with a plurality of terminal devices Z. The line connection device is connected to each device (for example, a personal computer, a server, a database, etc.) within the operator. In the example of FIG. 1, an advanced security system such as unauthorized intrusion prevention and unauthorized intrusion detection is not constructed in the line connection device and other devices within the operator, and it is assumed that the terminal device Z is authenticated by the user ID and password input from the terminal device Z.
[0011] If a user ID and password are entered incorrectly and are input from the attacker's terminal device Z', the line connection device will authenticate the terminal device Z' as if a legitimate user ID and password have been entered. As a result, the attacker's terminal device Z' can illegally intrude into the operator's network. After the illegal intrusion, ransomware is executed, and for example, important data is encrypted with the attacker's encryption key. When the important data is encrypted, the users within the operator cannot access the important data, and at this point, they will notice the hacking by the attacker. The attacker demands a large amount of money as compensation for restoring the encrypted important data and to avoid widely disclosing the important data. The operator may suffer significant damage due to the repair or loss of important data and the loss of the brand. In this embodiment, a method for immediately detecting an illegal intrusion by an attacker is provided.
[0012] FIG. 2 shows an example of the configuration of the communication system of this embodiment. The communication system includes a first communication device 50, and a second communication device 20, 40. In the example of FIG. 2, two second communication devices are illustrated, but the number of second communication devices is not limited to two. Also, in the example of FIG. 2, one first communication device 50 is illustrated, but the number of first communication devices 50 is not limited to one. Here, the first communication device and the second communication device are allowed only 1:1 connection on the condition that they hold the same common secret information described later or the same common key (encryption key) in the encryption algorithm. The mechanism that is not allowed will be described later. Note that the secret information in this specification is not the secret key information in the public key cryptography infrastructure. The secret key information itself is used without being changed. For example, the secret key information is used when decrypting what is encrypted with the public key. Or, the secret key information is used to apply an electronic signature to a certain digital data. On the other hand, it is specified that the secret information used in this application is digital data but is not itself an encryption key to be used in an encryption algorithm. The secret information in this application is information for enabling 1:1 VPN communication only when the same secret information is shared between two communication devices. An encryption key is generated from this secret information and used (described later), so 1:1 communication becomes possible. In other words, communication is not possible unless the same secret information is held at both ends communicating. In the example of FIG. 2, when the first communication device 50 is 1:1 connected to the second communication device 20 and the first communication device 50 is communicating with the second communication device 20, the first communication device has two different pieces of secret information corresponding to each of the two second communication devices 20, 40. Also, the secret information in this specification is completely different information from the authentication information and the like when determining whether the terminal device holds predetermined authentication information or not in order to confirm the presence or absence of authentication of the terminal device when remotely operating the terminal device and the like.
[0013] Communication devices such as the first communication device 50, the second communication device 20, 40 include line connection devices such as routers (including not only fixed routers but also managed mobile routers), gateway devices, and terminal devices, which are types of terminal connection devices. Also, direct VPN communication can be performed from IoT devices, PCs, etc. under the line connection device via the line connection device.
[0014] A 1:1 connection between the first communication device and the second communication device can use the Internet VPN (Virtual Private Network). Since a communication network management server (not shown) manages the pairs of global IP addresses and private IP addresses of the first communication device and the second communication device to be managed, the Internet VPN between the first communication device and the second communication device can be constructed with private IP addresses.
[0015] As will be described later, the first communication device and the second communication device can have the same configuration. However, in this specification, the first communication device 50 is a communication device on the side that generates secret information, and the second communication devices 20 and 40 are communication devices on the side that acquire the secret information generated by the first communication device 50 when the following conditions are satisfied.
[0016] The first communication device 50 and the second communication device include, for example, a personal computer, a smartphone, a tablet terminal, a device with a communication function, an electrical device or an electronic device, a communication device such as a router or a gateway device, and the like.
[0017] The first communication device 50 includes a control unit 51 that controls the entire device, a network communication unit 52, a memory 53, a display unit 54, a retransmission data analysis unit 55, a secure communication processing unit 56, and a storage unit 57.
[0018] The storage unit 57 can be configured by, for example, a hard disk or a semiconductor memory, and holds an OS 58, secret information 59, key information 60, and required information. In this specification, "hold" includes "store" and "record".
[0019] The OS 58 is, for example, Windows, Linux, Unix, Android, or iOS (all trademarks), but is not limited thereto.
[0020] The secret information 59 includes unique secret information corresponding to each of the second communication devices 20, 40, … to which the first communication device 50 is connected in a one-to-one manner. For example, it includes the unique secret information used when the first communication device 50 communicates with the second communication device 20, the unique secret information used when the first communication device 50 communicates with the second communication device 40, and the like.
[0021] The key information 60 includes unique common keys corresponding to each of the second communication devices 20, 40, … to which the first communication device 50 is connected in a one-to-one manner. For example, it includes the unique common key used when the first communication device 50 communicates with the second communication device 20, the unique common key used when the first communication device 50 communicates with the second communication device 40, and the like.
[0022] The control unit 51 may be configured by incorporating a required number of CPUs, MPUs, etc. Further, the control unit 51 may be configured by combining an encryption processor, a DSP, an FPGA, etc.
[0023] The network communication unit 52 can perform VPN communication with the second communication devices 20, 40 via the secure communication path 1. The secure communication path is a communication path that can communicate securely using appropriate encryption technology so that the confidentiality of the transmitted data is maintained even if the transmitted data is illegally acquired. Further, when there are devices or equipment connected to the first communication device 50, the network communication unit 52 can communicate with such devices or equipment. The devices include IoT devices.
[0024] The memory 53 can be composed of semiconductor memories such as SRAM (Static Random Access Memory), DRAM (Dynamic Random Access Memory), and flash memory. The required functions of the OS 58 are deployed in the memory 53, and the functions of the OS 58 are executed by the control unit 51.
[0025] The display unit 54 includes a liquid crystal display panel, an organic EL display panel, etc., and can display the results of processing by the first communication device 50 and the like.
[0026] When the retransmission data analysis unit 55 determines that the second communication device 20 or the second communication device 40 is in a communication state with the first communication device 50 and a predetermined event has occurred that requires the second communication device 20 or the second communication device 40 to retransmit data to the first communication device 50, the retransmission data analysis unit 55 analyzes the retransmission data transmitted by the second communication device or the second communication device 40. According to the analysis result of the retransmission data, the first communication device 50 stops (including interruption or termination) the communication with the second communication device 20 or the second communication device 40, or continues the communication with the second communication device 20 or the second communication device 40. In this specification, the stop of communication includes the interruption or termination of communication. The details of the retransmission data analysis method will be described later.
[0027] The secure communication processing unit 56 performs processes such as generation processing of secret information, generation processing of distributed information based on the secret information, generation processing of a common key, and secure communication path establishment processing between the first communication device 50 and the second communication devices 20 and 40. The details of the processes performed by the secure communication processing unit 56 will be described later.
[0028] The control unit 21, network communication unit 22, memory 23, display unit 24, retransmission data analysis unit 25, secure communication processing unit 26, and storage unit 27 of the second communication device 20 are the same as those of the control unit 51, network communication unit 52, memory 53, display unit 54, retransmission data analysis unit 55, secure communication processing unit 56, and storage unit 57 of the first communication device 50, and thus the description thereof is omitted. The storage unit 27 holds the OS 28, secret information 29, key information 30, and required information.
[0029] Next, the 1:1 VPN communication between the first communication device 50 and the second communication device 20 will be described. In 1:1 VPN communication, it is necessary to hold secret information in both communication devices before VPN communication. Only communication devices identified by the same secret information can perform 1:1 VPN communication. If the first communication device 50 is the VPN primary, the second communication device 20 that performs 1:1 VPN communication with this VPN primary is referred to as a VPN client. In the 1:1 VPN communication in this application, communication between VPN clients is not established. The VPN primary is, for example, a communication device that generates secret information, or a communication device that has many devices (including IoT devices) and equipment under its control. In other words, 1:1 VPN communication is possible only between a VPN primary communication device having a function of generating secret information and a VPN client communication device having the same secret information that wants to execute VPN communication with this VPN primary communication device. Even if communication devices have the same secret information, if one of the communication devices is not a device that generates secret information, that is, if it is not a VPN primary, VPN connection is not permitted.
[0030] In this specification, for convenience, the first communication device 50 is described as the VPN primary, and the second communication devices 20 and 40 are described as VPN clients. Note that the second communication devices 20 and 40 may be the VPN primary, and the first communication device 50 may be the VPN client. Of course, in this case, it is a condition that the second communication devices 20 and 40 generate individual secret information respectively.
[0031] There are the following two limitations in the 1:1 VPN communication that utilizes the secret information in this application. VPN communication is not established unless the communication devices can be encrypted with a common key generated from the same secret information. The reason is that the data encrypted on the sending side during VPN communication cannot be decrypted on the receiving side. The other is that VPN communication is established only between a VPN primary that generates secret information and a VPN client having the same secret information. In 1:1 VPN communication, a method that does not perform key exchange is adopted. This will be described below.
[0032] Figure 3 shows a first example of a method for generating a common key between the first communication device 50 and the second communication device 20. Figure 3 shows a method for preventing endangerment when generating a common key from secret information. The first communication device 50 (hereinafter synonymous with the control unit 51) holds secret information S1 and S2 (S11), and the second communication device 20 holds secret information S1 and S2 (S12). That is, the first communication device 50 and the second communication device 20 have completed sharing the same secret information S1 and S2. Details of the method for sharing secret information and the method for generating secret information will be described later.
[0033] The first communication device 50 generates a common key K1 from the secret information S1 using a predetermined key generation algorithm (S13). The second communication device 20 generates a common key K1 from the secret information S1 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S14). Thereby, without performing key exchange via the network, the common key can be shared at both ends of the first communication device 50 and the second communication device 20. The first communication device 50 and the second communication device 20 open a secure communication channel using the common key K1 (S15). Thereafter, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication.
[0034] Even if the secret information can be securely shared between the first communication device 50 and the second communication device 20, there is a concern that the common key generated from the same secret information may be endangered. Therefore, in the present embodiment, after the secure communication using the common key K1 is started, at a required timing, the first communication device 50 generates a common key K2 from the secret information S2 using a predetermined key generation algorithm (S16), and the second communication device 20 generates a common key K2 from the secret information S2 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S17). Thereby, without performing key exchange via the network, the updated common key can be shared at both ends of the first communication device 50 and the second communication device 20. The first communication device 50 and the second communication The communication device 20 opens a secure communication channel using the common key K2 (S18). After this, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication using the new common key. By stopping the use of the common key K1 at a predetermined timing and applying a predetermined algorithm to the secret information S2 to obtain a new common key K2, the endangerment of the common key can be prevented.
[0035] FIG. 4 shows a second example of a method for generating a common key between the first communication device 50 and the second communication device 20. FIG. 4 also shows a method for preventing endangerment when generating a common key from secret information. The first communication device 50 holds the secret information S (S21), and the second communication device 20 holds the secret information S (S22). That is, the sharing of the same secret information S between the first communication device 50 and the second communication device 20 is completed. The first communication device 50 generates a random number R (S23) and transmits the generated random number R to the second communication device 20 (S24). As a result, the random number R is shared between the first communication device 50 and the second communication device 20. Since the purpose is to share the random number R, there is no problem even in the reverse direction. That is, the second communication device 20 may generate the random number R and transmit the generated random number R to the first communication device 50.
[0036] The first communication device 50 uses a predetermined encryption algorithm to adjust the random number R to a key length suitable for the encryption algorithm, then encrypts the secret information S using this as an encryption key, and generates distributed information Q1, Q2, Q3 obtained by dividing and dispersing this according to a predetermined algorithm (S25). The second communication device 20 uses the same predetermined encryption algorithm as the encryption algorithm used by the first communication device 50 to adjust the random number R to a key length suitable for the encryption algorithm, then encrypts the secret information S using this as an encryption key, and generates distributed information Q1, Q2, Q3 obtained by dividing and dispersing this according to a predetermined algorithm (S26). Note that the number of distributed information to be generated is not limited to three, and may be one, two, or four or more.
[0037] FIG. 5 is a diagram showing an example of a method for generating distributed information. In the method shown in FIG. 5A, secret information S is encrypted by a common key encryption algorithm using a random number R as a cryptographic key to generate encrypted data. As the encryption algorithm, for example, DES (Data Encryption Standard) or AES (Advanced Encryption Standard) can be used. Next, the encrypted data is divided (fragmented) into three pieces of distributed information Q1, Q2, and Q3. How to divide which part of the encrypted data (division method) can be determined in advance. The number of divisions is not limited to 3, and it can be 1, 2, or 4 or more, and can be divided (distributed) into the required number of files.
[0038] When generating the distributed information Q1, Q2, and Q3 from the random number R, the case of adopting the block cipher algorithm was presented above, but a stream cipher may also be utilized. For example, MUGI, Salasa20, etc. can be used.
[0039] Although not mentioned above regarding the byte length of the secret information, as an example of a case where it is necessary to increase the byte length of the secret information according to the number of pieces of distributed information to be obtained, the result obtained by repeating a hash function, for example, SHA-2, for the secret information a predetermined number of times may be used as the secret information. In the first communication device 50 and the second communication device 20, the hash function to be adopted and the number of times of repeatedly hashing are determined in advance and made the same.
[0040] Each of the distributed information Q1, Q2, and Q3 becomes a byte sequence having no meaning. Even if one of the plurality of pieces of distributed information is leaked or illegally acquired, the leaked or illegally acquired distributed information alone is data that has no meaning, and it is impossible to infer other distributed information (not leaked or illegally acquired) from the leaked or illegally acquired divided information. Thereby, the security of the common key used during VPN communication can be improved.
[0041] In the method shown in FIG. 5B, the secret information S is encrypted using a common key encryption algorithm with the random number R as the encryption key, or is distributed to the distributed information Q1, Q2, and Q3 after encryption. As the encryption algorithm, for example, DES or AES of block cipher can be used, but MUGI or Salasa20 of stream cipher may also be used.
[0042] Returning to FIG. 4, the first communication device 50 generates a common key K1 from the distributed information Q1 using a predetermined key generation algorithm (S27). The second communication device 20 generates a common key K1 from the distributed information Q1 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S28). Thereby, the common key can be shared at both ends of the first communication device 50 and the second communication device 20 without performing key exchange via the network. The first communication device 50 and the second communication device 20 open a secure communication channel using the common key K1 (S29). Thereafter, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication. It is important that the common key K1 is not directly generated from the random number R, that is, key exchange is not performed via the network. In the conventional method using PKI, the random number R is encrypted with the private key and transmitted, and on the receiving side, it is decrypted with the public key of the sender and used as the common key itself. That is, key exchange is performed via the network. In other words, the present application clearly states that the common key K1 cannot be generated only from the random number R information exchanged via the network, and thus key exchange is not performed via the network. The common key K1 cannot be generated unless both the random number R and the secret information S are available. Also, the random number R is not essential information. Even without this random number R, the ability to prevent endangerment decreases, but the common key K1 can also be generated by applying the above-described division and distribution method to the secret information S.
[0043] Similar to the case of FIG. 3, in order to prevent the endangerment of the common key, after the start of the secure communication using the common key K1, at the required timing, the first communication device 50 generates a common key K2 from the distributed information Q2 using a predetermined key generation algorithm (S30), and the second communication device 20 generates a common key K2 from the distributed information Q2 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S31). Thereby, without performing key exchange via the network, the common keys updated at both ends of the first communication device 50 and the second communication device 20 can be shared, and the endangerment of the common key can be prevented. The first communication device 50 and the second communication device 20 open a secure communication path using the common key K2 (S32). After this, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication using the new common key.
[0044] As described above, the first communication device 50 holds secret information, and when the second communication device 20 holds the same secret information as the secret information held by the first communication device 50, communication (1:1 VPN communication) between the first communication device 50 and the second communication device 20 is permitted.
[0045] Also, the first communication device 50 holds a common key (key information) generated based on the secret information, and when the second communication device 20 holds the same common key as the common key held by the first communication device 50, which is generated based on the same secret information as the secret information held by the first communication device 50, communication (1:1 VPN communication) between the first communication device 50 and the second communication device 20 can be permitted. Note that one of the communication devices, either the first communication device 50 or the second communication device 20, needs to be the VPN primary.
[0046] Https (encrypted communication) used on a website or the like encrypts the communication between a server with an SSL certificate (electronic certificate) set and a terminal device. The SSL certificate is used for one-to-many connections between one authenticated domain and multiple users (for example, viewers). That is, in one-to-many connection communication, only the server to which multiple user terminal devices are connected is authenticated unidirectionally.
[0047] Generally, in 1:many connection communications, if the ID and password are leaked, an attacker can easily break into the network, and a security incident may occur where the attacker suffers great damage without noticing the intrusion. However, in this embodiment, an attacker (such as a hacker) who does not know the secret information or the common key cannot communicate with the correct encryption key, so a 1:1 VPN communication cannot be established. In other words, in this embodiment, since only 1:1 VPN communication is permitted, additional security solutions such as intrusion detection and intrusion prevention introduced in a 1:many communication environment are not required. Also, there is no need to audit the logs maintained by these security solutions. As a result, operation costs including introduction costs and labor costs can be reduced.
[0048] Also, the presence area of the first communication device 50 when communication with the second communication device 20 is permitted may be held. When the position information of the first communication device 50 based on the GPS included in the first communication device 50 is within the said presence area, communication between the first communication device 50 and the second communication device 20 may be performed. Thereby, for example, when the first communication device 50 performing 1:1 VPN communication is stolen, it can be determined that the position information of the first communication device 50 obtained by the GPS included in the first communication device 50 is not in a legitimate location, so unauthorized use can be prevented. Similarly, the same effect can be obtained by reversing the second communication device 20 and the first communication device 50.
[0049] FIG. 6 is a diagram showing an example of generating distributed information from secret information and generating a plurality of common keys. By the method illustrated in FIG. 5, distributed information Q1, Q2, …, Q(n-1), Qn is generated from secret information S. From each of the distributed information Q1, Q2, …, Q(n-1), Qn, common keys K1, K2, …, K(n-1), Kn are generated. The timing of generating the common keys K1, K2, …, K(n-1), Kn may be simultaneous or may be generated in any order at any time. As shown in FIG. 6, in the present embodiment, among the plurality of generated common keys, a predetermined common key (in the example of FIG. 6, common key Kn) is stored as an encryption key (synonymous with the common key) for encrypting the retransmission data when transmitting the retransmission data, which is agreed upon between the first communication device 50 and the second communication device 20 (that is, the VPN primary and the VPN client). In this specification, "stock" means storing information in advance as a reserve. The timing at which this stocked common key is used will be described later. The common keys other than the common key Kn are used for encrypting data in VPN communication.
[0050] Generally, when performing secure communication, the data transmitted and received is encrypted. The encryption key used at this time is exchanged via the network using a mechanism such as PKI (Public Key Infrastructure). However, when a quantum computer appears, it is said that the method of exchanging the encryption key via the network will cause the PKI to be broken by the quantum computer and the encryption key to be exposed even for encrypted data. However, as described above, in the present embodiment, since key exchange via the network is not performed, it is resistant to quantum computers.
[0051] Next, a method for detecting unauthorized intrusion into the network system by an attacker will be described. Hereinafter, for the sake of convenience, it will be described assuming that the first communication device 50 (VPN primary) is the communication device on the side that detects unauthorized intrusion, and the second communication device 20 (VPN client) is the communication device to be detected for unauthorized intrusion. It is considered that the attacker attacks the first communication device 50, which is the VPN primary with a large amount of asset information to be protected, via the second communication device 20.
[0052] FIG. 7 is a diagram showing a first example of the unauthorized access detection method according to the present embodiment. The first communication device 50 and the second communication device 20 establish a session of 1:1 connected VPN communication (S41), and the VPN communication is being executed (S42). That is, the first communication device 50 and the second communication device 20 are in a communication state. During the VPN communication, the second communication device 20 transmits required data to the first communication device 50 (S43), and the first communication device 50 receives the data (S44). At this time, it is assumed that the first communication device 50 has received the data normally.
[0053] When it is determined that it is the timing for the first communication device 50 to detect the presence or absence of unauthorized access to the second communication device 20, the first communication device 50 does not send a notification indicating that the data has been normally received to the second communication device 20 within a predetermined time despite having normally received the data transmitted by the second communication device 20. Specifically, the first communication device 50 does not send a notification indicating that the data has been normally received to the second communication device 20, or sends it to the second communication device 20 after a predetermined time has elapsed. The event that, despite having normally received the data transmitted by the second communication device 20, a notification indicating that the data has been normally received is not sent to the second communication device 20 within a predetermined time means that a predetermined event has occurred in which the second communication device 20 needs to retransmit the data to the first communication device 50.
[0054] The second communication device 20 cannot receive a notification indicating that the data has been normally received within a predetermined time (S45). When an attacker has decoded the common key generated from the secret information, the second communication device 20 that has been illegally accessed by the attacker generally retransmits the data when it cannot receive a notification indicating that the data has been normally received within a predetermined time. That is, the second communication device 20 retransmits the data (S46).
[0055] When the first communication device 50 receives retransmission data, it analyzes the retransmission data (S47). The analysis of the retransmission data determines whether the retransmission data matches any of the response methods predetermined between the first communication device 50 and the second communication device 20. If the retransmission data transmitted by the second communication device 20 does not conform to the predetermined response method, the first communication device 50 stops the communication with the second communication device 20 (S48). In the present embodiment, "stopping the communication" means a state where no communication is taking place. For example, a state where communication is temporarily stopped for a certain period of time and then resumed is not included.
[0056] As described above, when the second communication device 20 is in a communication state with the first communication device 50 and a predetermined event occurs that requires the second communication device 20 to retransmit data to the first communication device 50, the first communication device 50 can stop the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20. The predetermined event includes, for example, an event where when the first communication device 50 normally receives the data transmitted by the second communication device 20, the first communication device 50 cannot receive a notification indicating that the second communication device 20 has normally received the data within a predetermined time.
[0057] Also, a computer program (for example, OS 58) operating in the first communication device 50 can execute a process of stopping the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20 when the second communication device 20 is in a communication state with the first communication device 50 and the retransmission data analysis unit 55 analyzes (determines) that a predetermined event has occurred that requires the second communication device 20 to retransmit data to the first communication device 50.
[0058] If an attacker illegally obtains secret information and cannot obtain the VPN client program, it may be possible to easily establish 1:1 VPN communication. However, since the common key used for retransmission data is different, the primary can determine that the connection is from an illegal terminal, so the VPN communication can be stopped. The logic in the case of different common keys will be described later.
[0059] If an attacker illegally obtains the secret information and also obtains the VPN client program, the operator takes advantage of the difference. Before any timing or before and after the timing to prompt retransmission of data, the user identification number is requested to determine whether the obtained information is correct. The determination method utilizes the fact that the user identification information is used in the generation of the secret information. The user's Other examples of the identification number include the email address, employee number, and My Number described later.
[0060] If an attacker illegally obtains the secret information and also obtains the VPN client program, the location information during operation takes advantage of the difference. That is, as described above, the existence area of the second communication device 20 when communication with the first communication device 50 is permitted is held, and communication between the first communication device 50 and the second communication device 20 is performed only when the position information of the second communication device 20 based on the GPS included in the second communication device 20 is within the existence area.
[0061] If the first communication device 50 cannot receive a notification that the second communication device 20 illegally invaded by the attacker has normally received data within a predetermined time, it takes time to analyze the cause. When the second communication device 20 cannot continue communication within a specific time, the first communication device 50 may stop communication with the second communication device 20.
[0062] As described above, when the first communication device 50 normally receives the data transmitted by the second communication device 20, by not transmitting a notification to the second communication device 20 that it has been normally received within a predetermined time, the secure communication can be immediately interrupted when an illegal intrusion is detected, so that an illegal intrusion into the network can be prevented.
[0063] Further, when the first communication device 50 stops communication with the second communication device 20, it may notify an external device (for example, a network monitor's device or an email address) that unauthorized access has occurred in the communication by the second communication device 20. Alternatively, a printer existing within the network segment where the VPN primary is installed may be caused to output a printed matter notifying that unauthorized access has occurred. Thereby, unauthorized access to the network and the intrusion location (the corresponding communication device) can be immediately detected.
[0064] In recent years, it has been recognized that large enterprises at the upstream of the supply chain are also suffering damage via small and medium-sized enterprises vulnerable to cyberattacks, and it is necessary to take urgent countermeasures. According to this embodiment, active cyber defense can be realized. Active cyber defense means the ability to penetrate and neutralize a target server etc. in order to prevent cyberattacks against government agencies and critical infrastructure. In this embodiment, for example, before implementing communication stop, since the VPN communication can continue, a deletion command for secret information, a virus, or ransomware may be transmitted to disable and neutralize the attacker's system in the long term. Then, the VPN communication is stopped.
[0065] As described above, before stopping communication with the second communication device 20, the first communication device 50 can transmit a virus or ransomware to the second communication device 20 or another device connected to the second communication device 20 via the second communication device 20 to disable the attacker's system, and then stop communication with the second communication device 20 after transmitting the virus or ransomware.
[0066] FIG. 8 is a diagram showing a second example of the unauthorized access detection method of this embodiment. In FIG. 8, steps S141 to S143 are the same as steps S41 to S43 in FIG. 7. When the first communication device 50 determines that it is the timing to detect the presence or absence of unauthorized access to the second communication device 20, the first communication device 50 reconnects the session (S144). When the second communication device 20 detects that the first communication device 50 has reconnected the session (S145), it retransmits the data (S146).
[0067] When the first communication device 50 receives the retransmission data, it analyzes the retransmission data (S147). The analysis of the retransmission data determines whether the retransmission data matches any of the response methods predetermined between the first communication device 50 and the second communication device 20. When the retransmission data transmitted by the second communication device 20 does not conform to the predetermined response method, the first communication device 50 stops the communication with the second communication device 20 (S148).
[0068] As described above, when the second communication device 20 is in a communication state with the first communication device 50 and a predetermined event occurs in which the second communication device 20 needs to retransmit data to the first communication device 50, the first communication device 50 can stop the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20. The predetermined event includes, for example, the event that the first communication device 50 reconnects to the session again.
[0069] As described above, when unauthorized intrusion is detected by the first communication device 50 reconnecting to the session again, the secure communication can be immediately blocked, so unauthorized intrusion into the network can be prevented.
[0070] FIG. 9 is a diagram showing a third example of the unauthorized intrusion detection method of the present embodiment. In FIG. 9, steps S241 to S243 are the same as steps S41 to S43 in FIG. 7. When the second communication device 20 detects the occurrence of an event (S244), the second communication device 20 retransmits the data (S245). The events detected by the second communication device include, for example, the case where a timeout occurs, the case where a network device such as a router or a switch on the network fails and restarts, and the case where the IP address of the device communicating during the session connection is changed.
[0071] When the first communication device 50 receives retransmission data, it analyzes the retransmission data (S246). The analysis of the retransmission data determines whether the retransmission data matches any of the pre-determined response methods between the first communication device 50 and the second communication device 20. If the retransmission data transmitted by the second communication device 20 does not conform to the predetermined response method, the first communication device 50 stops the communication with the second communication device 20 (S247).
[0072] As described above, when the second communication device 20 is in a communication state with the first communication device 50 and a predetermined event occurs that requires the second communication device 20 to retransmit data to the first communication device 50, the first communication device 50 can stop the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20. The predetermined event includes, for example, any of the events of timeout, restart, and IP address change detected by the second communication device 20. In the example of FIG. 9, the second communication device 20 is configured to detect the occurrence of an event, but it is not limited thereto. For example, the first communication device 50 may detect a timeout (predetermined event) in the same way as the second communication device 20. The timeout detected by the first communication device 50 occurs in the following cases. That is, when the network of the first communication device 50 exceeds the bandwidth for connection requests from a plurality of second communication devices 20 (in one-to-one communication, it may also be connected from a plurality of second communication devices 20), the first communication device 50 generates a timeout. Also, when the upper limit of the number of simultaneous connections is set based on the security policy of the first communication device 50, the first communication device 50 may generate a timeout if there are connections exceeding the upper limit.
[0073] As described above, when an event occurs on the second communication device 20 side or when the first communication device 50 detects a timeout, the confidential communication can be immediately interrupted when unauthorized intrusion is detected, so unauthorized intrusion into the network can be prevented.
[0074] Next, the method for analyzing the retransmission data will be described.
[0075] FIG. 10 is a diagram showing an example of an analysis method for retransmission data. When a predetermined event occurs, the first communication device 50 (VPN primary) analyzes the retransmission data transmitted by the second communication device 20 and performs a predetermined response according to the analysis result. As shown in FIG. 10, when the retransmission data is not the data predetermined in advance (for example, (1) when the retransmission data has at least the same data part as the most recent data), the first communication device 50 stops communicating with the second communication device 20. Hereinafter, in this specification, the most recent data is, for example, the data transmitted by the second communication device 20 immediately before the transmission of the retransmission data by the second communication device 20. It is assumed that no data is transmitted by the second communication device 20 between the transmission of the most recent data and the transmission of the retransmission data, but the time between the transmission of the most recent data and the transmission of the retransmission data is not particularly defined. The data having at least the same data part includes, for example, the case where a response message or the like is incorporated and the data is not exactly the same. Generally, when an attacker selects retransmission of data, the same data is transmitted again. As a predetermined response method, it may be agreed in advance to retransmit data that is different from the most recent data at least in terms of the data part.
[0076] As described above, when the second communication device 20 transmits retransmission data having at least the same data part, the first communication device 50 may stop communicating with the second communication device 20.
[0077] Also, as shown in FIG. 10, when the common key used for transmitting the retransmission data is not the predetermined common key, the first communication device 50 stops communicating with the second communication device 20. The case where the common key is not the predetermined common key includes, for example, (2) when encrypting the retransmission data using the same common key as the common key for encrypting the most recent data, (3) when not encrypting the retransmission data using a common key generated in the past that is older than the common key for encrypting the most recent data, (4) when not encrypting the retransmission data using a predetermined common key among a plurality of pre-generated common keys, and the like.
[0078] FIG. 11 is a diagram showing a first example of the analysis result of retransmission data. The first communication device 50 and the second communication device 20 establish secure communication using a common key K1 (S51). Thereafter, VPN communication is executed, and the first communication device 50 and the second communication device 20 continue the secure communication using the common key K1, and then terminate the secure communication using the common key K1 at an arbitrary timing (S52). If the VPN communication itself has not ended, the first communication device 50 and the second communication device 20 establish secure communication using a common key K2 (a common key newer than the common key K1) (S53).
[0079] The second communication device 20 transmits the data encrypted with the common key K2 to the first communication device 50 (S54). When a predetermined event occurs where the first communication device 50 is in a communication state with the second communication device 20 and the second communication device 20 needs to retransmit data to the first communication device 50 (S55), the second communication device 20 transmits the retransmission data encrypted with the common key K2 to the first communication device 50 (S56). When the first communication device 50 can control the timing at which the predetermined event occurs (for example, when the first communication device 50 does not send a notification to the second communication device 20 that it has normally received the data transmitted by the second communication device 20 within a predetermined time, or when the first communication device 50 reconnects to the session again), the first communication device 50 determines the timing. Details of the occurrence timing of the predetermined event will be described later.
[0080] The first communication device 50 analyzes the retransmission data. In the case of FIG. 11, the retransmission data corresponds to the case where the retransmission data is encrypted using the same common key as the common key for encrypting the most recent data shown in FIG. 10, or the case where the retransmission data is not encrypted using a common key generated in the past that is older than the common key for encrypting the most recent data. Therefore, the first communication device 50 stops the communication with the second communication device 20 (S57).
[0081] As described above, when the second communication device 20 transmits retransmission data encrypted using the same common key (key information) as the common key used for encrypting the data transmitted to the first communication device 50, the first communication device 50 stops the communication with the second communication device 20.
[0082] If an attacker decrypted the common key generated from the secret information, the attacker would be considered to send retransmission data using the decrypted common key. Therefore, when the second communication device 20 transmits retransmission data encrypted using the same common key as the common key for encrypting the most recent data, it is possible to detect that the second communication device 20 has been illegally invaded, and it is possible to immediately cut off the secure communication to prevent illegal invasion into the network.
[0083] Also, as described above, the first communication device 50 generates different common keys K1 (the common key K1 corresponds to the stored common key described above) and K2 (newer than K1) at required frequencies based on the secret information. When the second communication device 20 does not transmit retransmission data encrypted using the common key K1 stored older than the common key K2 used between the second communication device 20 and the first communication device 50, the communication with the second communication device 20 may be stopped. Also, the first communication device 50 and the second communication device 20 store the secret information in advance. The first communication device 50 may stop the communication with the second communication device 20 when the second communication device 20 does not retransmit the data encrypted using the key information generated based on the secret information.
[0084] If an attacker decodes a common key generated from secret information and also illegally obtains a VPN application, the attacker is considered to send retransmission data using the decoded common key. In this case, since the attacker has also stolen the VPN application, the attacker will retransmit the data without any particular problem with the retransmission data to be sent. However, the attacker cannot know the common key generated and stored in the past and, of course, has not decoded it. Therefore, if the second communication device 20 encrypts the retransmission data using a common key generated and stored in the past that is older than the common key for encrypting the most recent data, it is possible to detect that the second communication device 20 has been illegally invaded, and it is possible to immediately cut off the secure communication to prevent illegal intrusion into the network. This is based on the fact that the secret information and the VPN application that the attacker can obtain are at a certain point in time, and it is extremely difficult to obtain the common key by going back in time from this point, and the attacker cannot know the location where the key is stored. To supplement, this is because the common key is stored before the attacker (hacker) steals the legitimate VPN application. What is stored is not limited to the common key but may also be secret information. If what is stored is secret information, a common key will be generated from now on. Or, although the security strength will decrease, instead of the stored common key, the common key used in the past or the common key Kn shown in FIG. 6 may be used.
[0085] FIG. 12 is a diagram showing a second example of the analysis result of retransmission data. FIG. 12 shows an example of using a stored common key. The first communication device 50 and the second communication device 20 establish secure communication using the common key K1 (S61), and thereafter, VPN communication is executed. The first communication device 50 and the second communication device 20 continue the secure communication using the common key K1, and then terminate the secure communication using the common key K1 at an arbitrary timing (S62). If the VPN communication itself has not ended, the first communication device 50 and the second communication device 20 establish secure communication using the common key K2 (a common key newer than the common key K1) (S63).
[0086] The second communication device 20 transmits the data encrypted with the common key K2 to the first communication device 50 (S64). When the first communication device 50 is in a communication state with the second communication device 20 and a predetermined event occurs that requires the second communication device 20 to retransmit the data to the first communication device 50 (S65), the second communication device 20 transmits the retransmission data encrypted with a past common key K1 older than the currently used common key K2 to the first communication device 50 (S66). When the first communication device 50 can control the timing of the occurrence of the predetermined event (for example, when the first communication device 50 does not send a notification to the second communication device 20 indicating that the data sent by the second communication device 20 has been normally received within a predetermined time, or when the first communication device 50 reconnects to the session again), the first communication device 50 determines the timing.
[0087] The first communication device 50 analyzes the retransmission data. In this case, the most recent data is encrypted using a common key generated and stored in the past that is older than the common key for encrypting the most recent data, or a common key generated from the stored secret information. Therefore, the first communication device 50 continues the communication (S67), and then, at the required timing, the first communication device 50 and the second communication device 20 end the confidential communication using the common key K2 (S68). If a common key generated and stored in the past that is older than the common key for encrypting the most recent data is not used, or a common key generated from the stored secret information is not used, the first communication device 50 stops the communication.
[0088] FIG. 13 is a diagram showing a third example of the analysis result of retransmission data. The first communication device 50 and the second communication device 20 establish secure communication using the common key K1 (S71). Thereafter, VPN communication is executed, and the first communication device 50 and the second communication device 20 continue the secure communication using the common key K1, and then terminate the secure communication using the common key K1 at an arbitrary timing (S72). If the VPN communication itself has not ended, the first communication device 50 and the second communication device 20 establish secure communication using the common key K2 (a common key newer than the common key K1. The meaning of the new common key here is the meaning of the common key used later in time than the common key K1) (S73).
[0089] The second communication device 20 transmits the data encrypted with the common key K2 to the first communication device 50 (S74). When a predetermined event occurs in which the first communication device 50 is in a communication state with the second communication device 20 and the second communication device 20 needs to retransmit data to the first communication device 50 (S75), the second communication device 20 transmits the retransmission data encrypted with a common key other than the common key Kn to the first communication device 50 (S76). When the first communication device 50 can control the timing at which the predetermined event occurs (for example, when the first communication device 50 does not transmit a notification to the second communication device 20 that it has normally received the data transmitted by the second communication device 20 within a predetermined time, or when the first communication device 50 reconnects to the session again), the first communication device 50 determines the timing.
[0090] The first communication device 50 analyzes the retransmission data. In the case of FIG. 13, since the retransmission data corresponds to the case where the retransmission data is not encrypted using a predetermined common key among the plurality of pre-generated common keys shown in FIG. 10, the first communication device 50 stops the communication with the second communication device 20 (S77).
[0091] As described above, the first communication device 50 generates a plurality of distributed information from the secret information, and generates a plurality of common keys based on each of the generated distributed information. If the second communication device 20 does not retransmit the data encrypted using a predetermined common key Kn (see FIG. 6) among the plurality of generated common keys, the first communication device 50 may stop the communication with the second communication device 20.
[0092] Thereby, a plurality of common keys can be generated at once from one piece of secret information, so that the endangerment of the common key can be prevented, and it is possible to detect that the second communication device 20 has been illegally invaded, and the VPN communication can be immediately blocked to prevent illegal invasion into the network.
[0093] FIG. 14 is a diagram showing an example of the execution environment of the first communication device 50 and the second communication device 20. The first communication device 50 and the second communication device 20 perform network communication using TCP / IP (one of the mainstream communication protocols). TCP / IP defines a communication method divided into four layers. As shown in FIG. 14A, in the first communication device 50 and the second communication device 20, in the application layer, a program (application program) is deployed and executed in the user memory space, and in the transport layer, the VPN program is deployed and executed in the OS memory space.
[0094] When the VPN program of the second communication device 20 transmits the retransmission data to the first communication device 50 , the VPN program that has received the retransmission data in the transport layer executes the analysis of the retransmission data.
[0095] As described above, the first communication device 50 can analyze the retransmission data transmitted by the second communication device 20 using the transport layer. That is, in the present embodiment, the retransmission data is analyzed in the transport layer, and the application layer is configured not to be involved in the analysis of the retransmission data. More specifically, the transport layer of the first communication device 50 is responsible for the data exchange with the transport layer of the second communication device 20, determines whether the communication partner is a legitimate partner, analyzes the data (retransmission data) flowing through the transport layer, and stops the communication according to the analysis result. In this series of processes, one of the features of the present embodiment is that the application layer above the transport layer does not cooperate with the transport layer at all. Note that in TCP / IP, it is called the transport layer, but in protocols other than TCP / IP, the layer corresponding to the transport layer performs this series of processes, and the layer corresponding to the application layer does not perform this series of processes.
[0096] Generally, compared to the number of software engineers who develop programs (the VPN program of the first communication device 50) that are deployed in the OS memory space, use the communication method of the transport layer, and utilize the functions of the OS, the number of engineers who develop application programs that utilize the communication method of the application layer is extremely large. Therefore, currently, the number of people who can hack a VPN program that uses the communication method of the transport layer is extremely small compared to the number of people who can hack an application program. Thus, by using a VPN program that uses the communication method of the transport layer as in this embodiment, a communication system that is relatively resistant to hacking can be constructed. In addition, infiltrating and infecting a malicious program that operates in the transport layer is difficult compared to that in the application layer because it involves directly modifying and transforming the OS. The reason is that when directly modifying and transforming the OS, not only is privilege escalation of the OS required, but also the applications become unavailable when this malicious OS is installed, so the attacked side is likely to notice any abnormalities. Although not shown, the first communication device 50 may receive the retransmission data transmitted from the transport layer of the second communication device 20 at its own transport layer and determine the retransmission data transmitted by the second communication device 20 using its own application layer. Thereby, this embodiment can be implemented even when the source code of the OS is not disclosed (not open source).
[0097] As shown in FIG. 14B, when the first communication device 50 is in a communication state with the second communication device 20 and a predetermined event occurs in which the second communication device 20 needs to retransmit data to the first communication device 50 (S81), the second communication device 20 transmits the retransmission data to the first communication device 50 (S82). The first communication device 50 receives the retransmission data (S83) and decrypts the received retransmission data with a predetermined common key (S84).
[0098] The first communication device 50 determines whether it has successfully decoded the retransmitted data (S85). If the decoding is not successful (NO in S85), that is, if the retransmitted data is not encrypted with the common key predetermined between the first communication device 50 and the second communication device 20, the first communication device 50 determines that the second communication device 20 is not the correct connection device partner and can stop the communication (S86). On the other hand, if the decoding is successful (YES in S85), that is, if the retransmitted data is encrypted with the common key predetermined between the first communication device 50 and the second communication device 20, the first communication device 50 determines that the second communication device is the correct connection device partner and can continue the communication (S87).
[0099] In this way, the analysis of the retransmitted data can be performed based on whether it can be decoded with the common key predetermined between the first communication device 50 and the second communication device 20. When it can be decoded, there is no problem However, if it cannot be decoded, not only has the authentication information generally exchanged at the application layer at the start of VPN communication been leaked and used, but also secret information and the like have been leaked, and it can be determined that it is an illegal communication device that has executed an illegal connection, and an intrusion can be detected with a simple configuration. As a result, it is not necessary to employ a security system professional engineer, and it is not necessary to introduce a high-level and complex security system for intrusion detection and prevention. Note that most of the security incidents in general VPN communication occur due to the exposure of authentication information due to an attack on the authentication information (ID and password in authentication using ID and password) or leakage similar to a social attack. However, in the present invention, 1:1 communication is the basis, and a common key used for secure communication is generated with the secret information exchanged in advance. Therefore, even if the authentication information is misused, it has high resistance to security attacks. However, the possibility of the secret information being stolen cannot be denied. However, the fact that the security resistance can be maintained even in such a case is an advantage of the present invention.
[0100] Next, a method for determining the occurrence timing of a predetermined event will be described.
[0101] FIG. 15 is a diagram showing an example of the occurrence timing of a predetermined event. As described above, examples of the predetermined event whose occurrence timing can be controlled by the first communication device 50 include an event in which when the first communication device 50 normally receives data transmitted by the second communication device 20, the first communication device 50 does not transmit a notification to the second communication device 20 indicating that it has been normally received within a predetermined time, or an event in which the first communication device 50 reconnects to the session again.
[0102] FIG. 15A changes the time interval (interval) between the occurrence times of a predetermined event according to the elapsed time after communication is established between the first communication device 50 and the second communication device 20. Specifically, the first communication device 50 can repeat one or more (it may be only once or two or more times) cycles in which the predetermined event is generated at a time when the interval of the occurrence of the predetermined event becomes longer according to the elapsed time after communication is established with the second communication device 20. For example, the first communication device 50 can repeat one or more cycles in which the predetermined event is generated at a time when the interval of the occurrence of the predetermined event becomes longer according to the elapsed time after communication is established with the second communication device 20.
[0103] As shown in FIG. 15A, it is assumed that the predetermined event is generated three times in one cycle. In the first cycle, the interval between the communication establishment time and the occurrence time of the first predetermined event is Δt1, the interval between the occurrence time of the first predetermined event and the occurrence time of the second predetermined event is Δt2, and the interval between the occurrence time of the second predetermined event and the occurrence time of the third predetermined event is Δt3. Then, Δt1 < Δt2 < Δt3. As time elapses, the intervals Δt1, Δt2, and Δt3 become longer. The same applies to the second cycle and subsequent cycles.
[0104] Since the transmission interval becomes shorter from Δt3 to Δt1 at the time when the cycle changes, the possibility that the attacker detects the predetermined event at the timing when the attacker tries to hack and illegally obtain information in the system becomes lower, making it difficult to hack and suppressing information leakage.
[0105] As shown in FIG. 15B, a predetermined event can be generated when the amount of data communicated after communication is established between the first communication device 50 and the second communication device 20 reaches a predetermined value. One or more (it may be only once or two or more times) cycles of generating a predetermined event can be repeated when the amount of data reaches predetermined values D1, D2, D3. For example, the first communication device 50 can repeat one or more cycles of generating a predetermined event when the amount of data communicated after communication is established with the second communication device 20 exceeds a predetermined amount. The predetermined values D1, D2, D3 can be set as appropriate. Note that the timing for generating the predetermined event is not limited to the example of FIG. 15, and several methods can be combined. It may also be combined.
[0106] In addition, the first communication device 50 can be set as the timing for generating a predetermined event when the VPN connection time exceeds the previously set connection time, or when, despite the VPN connection not being terminated, the encrypted communication has not started for a longer time than the previously set time. Also, for the "previously" mentioned above, when a VPN communication user or a VPN communication supervisor performs an action before the start of VPN communication, or when the VPN communication user or the VPN communication supervisor sets default values for these values, it is designed and developed to adopt a smaller numerical value compared to the previously set values before VPN communication.
[0107] Next, a method for sharing secret information will be described.
[0108] FIG. 16 is a diagram showing a first example of a method for sharing secret information. In the first example of FIG. 16, it is assumed that the first communication device 50 holds secret information S in advance. When the first communication device 50 generates and holds the secret information S by itself, the first communication device 50 becomes the VPN primary. The first communication device 50 has a limited communication area (for example, within the communication range of Wi-Fi (registered trademark), Bluetooth (registered trademark), or local 5G, or within the range where a connection connector for a wired connection exists). In the example of FIG. 16A, the second communication device 20 exists outside the limited communication area (hereinafter also referred to as the "communication area").
[0109] As shown in FIG. 16B, when the second communication device 20 enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the second communication device 20. By holding the secret information S, the second communication device 20 can share the secret information S with the first communication device 50. The "communication area" is an area where the wireless connection or wired connection of the first communication device 50 (VPN primary) is physically blocked or monitored, and the entry or access of people to the area is restricted. For example, a gate system that allows only limited or permitted people (collectively also referred to as "authorized people") to enter, or the monitoring by security guards can make a specific area a high-security area (restricted area). As a result, only authorized people can enter the communication area, so the secret information is distributed only to the second communication device 20 carried or owned by the authorized people. In other words, the secret information S is not distributed from the first communication device 50 unless the second communication device 20 is a communication device carried or owned by an authorized person and the authorized person enters the communication area. Also, as information for determining whether entry or access to the communication area is permitted, an employee ID card or the like may be used. This means that it is not only difficult for an attacker to know where the secret information S is being distributed, but also difficult to enter this place. That is, it means that the attacker cannot obtain the secret information S unless they clear other geographical and physical conditions (in the case of Wi-Fi wireless, the SSID and password).
[0110] FIG. 17 is a diagram showing a second example of a method for sharing secret information. In the second example of FIG. 17, it is assumed that the first communication device 50 holds secret information S in advance. The second communication device 20 has a limited communication area. In the example of FIG. 17A, the first communication device 50 exists outside the limited communication area (hereinafter also referred to as the "communication area").
[0111] As shown in FIG. 17B, when the first communication device 50 enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the second communication device 20. By holding the secret information S, the second communication device 20 can share the secret information S with the first communication device 50. The "communication area" is the same as in the first example. In the case of the second example, since only authorized persons can enter the communication area, the secret information is not distributed to the second communication device 20 unless the first communication device 50 carried or owned by the authorized person enters the communication area. In other words, unless the first communication device 50 is a communication device carried or owned by an authorized person and unless the authorized person enters the communication area, the secret information S is not distributed to the second communication device 20.
[0112] As described above, the first communication device 50 holds secret information. When the first communication device 50 and the second communication device 20 are present within the limited communication area of the first communication device 50 or the second communication device 20, the first communication device 50 can transmit the secret information to the second communication device 20 and share the secret information between the first communication device 50 and the second communication device 20.
[0113] With the above configuration, both communication devices, i.e., the first communication device 50 and the second communication device 20, can share the secret information that is required only when they are present or were present within the limited communication area of the first communication device 50 or the second communication device 20 for 1:1 VPN communication. Thereby, communication based on the conventional 1:multiple connections can be excluded. Generally, in communication with 1:multiple connections, in order to realize multiple connections, the connection is permitted on the premise that the authentication information (ID and password) is correct. However, if this authentication information leaks, an attacker can easily break into the network, and it is easy for such an incident that the intrusion is not noticed immediately to occur. As a result, a security incident is likely to occur in which it is easy to suffer serious ransomware damage. However, in this embodiment, in addition to permitting only 1:1 VPN communication between communication devices that possess, own, and hold the same secret information, since the transfer of the secret information as described above is executed, it is extremely difficult for a hacker who cannot know where to go and from which device to obtain the secret information to directly obtain the secret information. Therefore, it is not necessary to introduce additional security solutions such as intrusion detection and intrusion prevention.
[0114] FIG. 18 is a diagram showing a third example of a method for sharing secret information. In the third example of FIG. 18, it is assumed that the first communication device 50 holds secret information S in advance. The first communication device 50 has a limited communication area. The IC card is a portable medium such as, for example, a contact-type IC card or a non-contact-type IC card. Note that instead of the IC card, a device such as a smartphone, a tablet terminal, or a mobile terminal may be used. As shown in FIG. 18A, when the IC card (contact or non-contact) completes a wired connection via R / W or enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the IC card. The IC card holds the secret information S.
[0115] As shown in FIG. 18B, by connecting an IC card storing secret information S to the second communication device 20 through wired communication or wireless communication, the second communication device 20 acquires and stores the secret information from the IC card. In this way, the secret information may be shared between the first communication device 50 and the second communication device 20 via a medium or device such as an IC card. Since the secret information can be transferred via a medium such as an IC card, even for a device with a size or weight that makes it difficult to carry the second communication device 20, the secret information can be shared between the first communication device 50 and the second communication device 20. The "communication area" is the same as in the first example. In the case of the third example, since only authorized persons can enter the communication area, the secret information is not distributed to the second communication device 20 via the IC card unless the IC card carried or owned by the authorized person enters the communication area. In other words, the secret information S is not distributed to the second communication device 20 unless the IC card is carried or owned by an authorized person and the authorized person does not enter the communication area.
[0116] Although not shown, the first communication device 50 installed in an area with restricted access displays a type of two-dimensional code storing secret information on the display unit 54, and the second communication device 20 brought into the area with restricted access by an authorized person reads the displayed two-dimensional code and stores the secret information. Thereby, the second communication device 20 carried or owned by the authorized person is brought into the area, and the secret information can be shared between the first communication device 50 and the second communication device 20 only when the condition that the second communication device 20 approaches the first communication device 50 is satisfied. 0 is satisfied.
[0117] In addition, the first communication device 50 holds the identifier of the second communication device 20 that has shared the secret information. The identifier may be, for example, the device manufacturing number, MAC address, IMEI (terminal identification number of a mobile phone), serial number, or an email address, employee number, or My Number (Social Security number in the United States) associated with the serial number of the second communication device 20. When the first communication device 50 updates the secret information, it may send or deliver by mail a two-dimensional code holding the updated secret information to the second communication device 20 that holds the identifier. Thus, once the first communication device 50 and the second communication device 20 have properly shared the secret information, even when the secret information is updated, the user of the second communication device 20 can share the secret information based on the identifier without having to go to the limited communication area of the first communication device 50, improving convenience. On the other hand, it is also a fact that the security strength decreases, so a method of encrypting some or all of the generated secret information with a common key generated from the identifier may be adopted when generating the two-dimensional code. By implementing such an implementation, the security strength can be increased to some extent.
[0118] FIG. 19 is a diagram showing another example of a limited communication area. As shown in FIG. 19, communication areas limited to regions A, B, and C are provided. In region A, the first communication device 50 is installed, and the first communication device 50 holds the secret information S. In each of regions B and C, a relay device is installed, and the relay device holds the secret information S distributed from the first communication device 50. The relay device has a function of transmitting the secret information to the second communication device 20 in the same manner as the first communication device 50. Regions A to B are, for example, the locations of business offices of an operator (company), and may be different prefectures, municipalities, or countries, but are not limited thereto.
[0119] As described above, by providing a plurality of communication areas, a user who possesses a medium such as the second communication device 20 or an IC card can bring the medium such as the second communication device 20 or the IC card into the limited communication area of the first communication device 50 or the relay device in a convenient area among areas A to C, thereby sharing the secret information S for 1:1 VPN communication, and improving the convenience of the user.
[0120] FIG. 20 is a diagram showing a fourth example of a method for sharing secret information. In the fourth example of FIG. 20, it is assumed that the first communication device 50 holds the secret information S in advance. The first communication device 50 has a limited communication area. As shown in FIG. 20A, when the second communication device 20 enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the second communication device 20. The second communication device 20 holds the secret information S and can share the secret information with the first communication device 50.
[0121] Next, as shown in FIG. 20B, the second communication device 20 has a limited communication area. When the third communication device 43 enters the communication area, the second communication device 20 transmits (outputs) the secret information S to the third communication device 43. The third communication device 43 holds the secret information S.
[0122] As described above, the second communication device 20 holds the secret information, and when the third communication device 43 and the second communication device 20 are present in the limited communication area of the third communication device 43 or the second communication device 20, the second communication device 20 transmits the secret information to the third communication device 43, and the secret information can be shared between the second communication device 20 and the third communication device 43.
[0123] Thereby, the first communication device 50 can share the secret information with the second communication device 20 and can also share the secret information with the third communication device 43. That is, 1:1 VPN communication between the first communication device 50 and the second communication device 20 can be performed. At the same time, 1:1 VPN communication can be performed between the first communication device 50 and the third communication device 43. At this time, it is important to note that 1:1 VPN communication cannot be implemented between the second communication device 20 and the third communication device 43. This secret information is generated by the first communication device, which is the VPN primary. In the 1:1 VPN communication in the present invention, it means VPN communication between the VPN primary and the VPN client. That is, the VPN primary is a terminal (communication device) that can generate / generates secret information. In an organization that performs management in one place, a mechanism for identifying the terminal that becomes the VPN primary when distributing secret information to the terminal may be introduced. For example, there are methods such as having the VPN primary terminal hold a special identifier in a predetermined place, or processing and holding the primary identifier and the terminal identifier in the secret information itself.
[0124] FIG. 21 is a diagram showing a fifth example of a method for sharing secret information. In the fifth example of FIG. 21, the first communication device 50 has previously generated and held secret information P. That is, the first communication device 50 is the VPN primary that generates the secret information P. The first communication device 50 has a limited communication area. As shown in FIG. 21A, when the second communication device 20, which is a VPN client, enters the communication area, the first communication device 50 transmits (outputs) the secret information P to the second communication device 20. The second communication device 20 holds the secret information P and can share the secret information P with the first communication device 50.
[0125] As described above, in one aspect, the second communication device 20 becomes a VPN client, but in another aspect, it may also become a VPN primary. That is, as shown in FIG. 21B, the second communication device 20 generates and holds secret information T in advance. The secret information T is different from the secret information P. That is, the second communication device 20 is also a VPN primary that generates the secret information T. The second communication device 20 has a limited communication area. As shown in FIG. 21B, when the fourth communication device 44, which is a VPN client, enters the communication area, the second communication device 20 transmits (outputs) the secret information T to the fourth communication device 44. The fourth communication device 44 holds the secret information T and can share the secret information T with the second communication device 20 and the fourth communication device 44.
[0126] In the case shown in FIG. 21, for example, the GW (gateway device) installed at home used for telework between a company and home corresponds to the second communication device 20 shown in FIG. 21A, and this GW device is also equipped with a function to generate secret information. For example, when various IoT devices in a smart home are securely controlled by the GW device, the GW device installed at home generates secret information and distributes the secret information to the smartphones of people living in the smart home. The GW device installed at home becomes a VPN client in the VPN communication with the company and becomes a VPN primary in the VPN communication with the smartphones of family members.
[0127] As described above, the second communication device 20 generates and holds secret information. When the second communication device and another communication device different from the first communication device exist within the limited communication area of the second communication device or the other communication device, the second communication device transmits the secret information generated and held by it to the other communication device, and the secret information can be shared between the second communication device and the other second communication device.
[0128] FIG. 22 is a diagram showing a sixth example of a method for sharing secret information. In the sixth example of FIG. 22, a method for sharing secret information by a private blockchain 100 is shown. A blockchain is a distributed system using a P2P network, and nodes (computers) on the P2P network share the same data (ledger). A blockchain is a technology for sharing and managing a ledger in a distributed manner. The administrator terminal 150, participant terminals 121, 122, and 123 shown in FIG. 22 can constitute nodes. The administrator terminal 150, participant terminals 121, 122, and 123 may be a PC, or may be a smartphone or a tablet terminal or the like.
[0129] In addition to the aforementioned ledger (also referred to as a "distributed ledger" or "block"), the private blockchain 100 has technical elements such as encryption and smart contracts. Encryption ensures the legitimacy and confidentiality of transactions (transactions), for example, by means of an electronic signature function and an authentication function. A smart contract holds the execution code and variables of a program deployed on the private blockchain 100 and is held in the blocks held by each node.
[0130] Each block of the private blockchain 100 includes information such as the hash value of the previous block, transaction data, state data, and nonce. A hash value is a fixed-length value obtained by a predetermined operation from the original input data, and the information included in the previous block is used as the input data for the operation. In the present embodiment, the transaction data includes secret information. The state data includes information such as the identification code (ID) of the participants managed within the private blockchain 100, authentication information and access rights required for participation. The state data includes smart contracts (program codes, etc.) for all participants. The nonce is a value used to calculate a hash value based on the information in the current block when adding the next block. When the value of the nonce is determined, the current block is hashed, and the hash value is held in the next block.
[0131] The private blockchain 100 is a type of blockchain technology and has the following characteristics different from public blockchains. That is, the private blockchain 100 is operated by limited participants and is constructed in a private environment. Participants in the private blockchain 100 are usually composed of members of limited organizations, but even if they are not members of the organization, they can participate as members if permitted by the administrator. Also, access control is implemented for the participating members. That is, participants in the private blockchain 100 cannot participate in the network without obtaining specific approval.
[0132] In this embodiment, the characteristics of this private blockchain 100 (difficult to be attacked by third - party hackers) are utilized to share (distribute) secret information. Assume that the administrator uses the administrator terminal device 150, and the participants P1, P2, and P3 use the participant terminal devices 121, 122, and 123 respectively. Hereinafter, the method of sharing secret information will be described in order. (1) The administrator confirms and then registers as a participant in the private blockchain 100 a person who is permitted for 1:1 VPN communication. In this embodiment, the administrator is the person who manages the communication device that serves as the VPN primary. Note that one administrator may manage multiple communication devices that serve as VPN primaries. For example, if the first communication device 50 is a gateway device installed in a certain department of a certain company, the administrator of this gateway device will be the person responsible for department IT management. This administrator will grant permission to participate in the private blockchain 100 and access rights to employees who are allowed to use VPN communication in the department. (2) After granting permission to participate and access rights, for each participant, the administrator generates secret information for each participant using the VPN primary (for example, the first communication device 50), and writes the generated secret information into the private blockchain 100 as transaction data. (3) After a participant passes the authentication of the private blockchain 100, the participant downloads their own secret information. Here, a mechanism that prevents other participants from downloading their secret information may be implemented through their own access management to the private blockchain 100, or a common key may be issued for each participant. If you do not want to issue a new common key, a common key can be generated using the participant's identification code and part or all of the authentication information required when participating in the private blockchain 100. The generated common key is used to encrypt the secret information, and the encrypted secret information is written as transaction data to the private blockchain 100, so that only the participant can decrypt their own secret information. If written as transaction data to the private blockchain 100, the participant can decrypt only their own secret information.
[0133] In the example of FIG. 22, the secret information Sp1 encrypted with the common key Kp1 for the participant P1 is written as transaction data to the block, the secret information Sp2 encrypted with the common key Kp2 for the participant P2 is written as transaction data to the block, and the secret information Sp3 encrypted with the common key Kp3 for the participant P3 is written as transaction data to the block. The participant Sp1 can decrypt the secret information Sp1 using the common key Kp1 they possess, but other participants do not have the common key Kp1, so they cannot obtain the secret information Sp1. The same applies to the other participants P2 and P3.
[0134] In the above example, employees of a certain department were mentioned, but it is not limited to this. For example, it may be an organization such as a neighborhood association in a certain area. With such an implementation, the administrator can distribute the secret information only to those recognized as correct.
[0135] Since the administrator can write different secret information from the previously written secret information to the private blockchain 100 as new transaction data, participants can easily receive the latest version of the secret information. Also, by preparing and registering a smart contract that operates by triggering an event when a participant receives the secret information, it becomes possible to operate in such a way that the administrator can know that the participant has received the secret information at the timing when the participant receives the secret information.
[0136] Next, a method for generating secret information will be described.
[0137] FIG. 23 is a diagram showing an example of a method for generating secret information. FIG. 23A shows a case where the first communication device 50 holds unique information. The unique information can be, for example, an identifier of the first communication device 50 (e.g., serial number, etc.), employee number, company identifier, location identifier, a predetermined random number, etc., but is not limited thereto. The first communication device 50 holds the unique information (S101) and generates secret information using the unique information (S102). The generation of the secret information may be information obtained as a result of performing an operation on the unique information by a predetermined algorithm. The first communication device 50 transmits the generated secret information to the second communication device 20 (S103) by the method exemplified in FIGS. 16 to 20, etc., and the secret information can be shared.
[0138] FIG. 23B shows a case where the second communication device 20 holds unique information. The unique information can be, for example, an identifier of the second communication device 20 (e.g., serial number, etc.), employee number, company identifier, location identifier, a predetermined random number, etc., but is not limited thereto. The second communication device 20 holds the unique information (S111), and the first communication device 50 acquires the unique information from the second communication device 20 (S112). The first communication device 50 generates secret information using the unique information (S113). The first communication device 50 transmits the generated secret information to the second communication device 20 (S114) by the method exemplified in FIGS. 16 to 20, etc., and the secret information can be shared.
[0139] FIG. 23C shows a case where no unique information is held. The first communication device 50 generates unique information (S121) and generates secret information using the unique information (S122). The generation of the secret information may be information obtained as a result of performing an operation on the unique information using a predetermined algorithm. The first communication device 50 transmits the generated secret information to the second communication device 20 (S123) by the method exemplified in FIGS. 16 to 20 and the like, and the secret information can be shared.
[0140] As described above, the first communication device 50 holds first unique information regarding the first communication device 50 or acquires second unique information regarding the second communication device 20 from the second communication device 20, and can generate secret information using the held first unique information or the acquired second unique information.
[0141] When secret information is generated using unique information such as an employee number, by maintaining the correspondence between the unique information and the secret information, it is possible to easily identify who owns the secret information. This can solve the security problem caused by the inability to determine whose secret information it is. Also, when secret information is generated using unique information such as a company identifier, the secret information can be classified by company or organization, so a mechanism for realizing 1:1 VPN communication for many companies and organizations can be constructed.
[0142] Using the mechanism, which is one of the features of this embodiment, of holding the same secret information and allowing 1:1 VPN communication only between VPN primary VPN clients, a data diode-like usage method can also be easily realized.
[0143] For example, in the transport layer of the first communication device 50, an implementation that only allows received data and discards all transmitted data may be installed. By providing such an implementation, the second communication device 20 can transmit data to the first communication device 50, and the first communication device 50 can receive the data. On the other hand, a configuration in which data does not reach the second communication device 20 from the first communication device 50 can be easily implemented. The roles of the first communication device 50 and the second communication device 20 may be changed. This can be implemented regardless of whether it is a VPN primary. In this example, an implementation example of a data diode via the Internet is shown, but it is also possible to install the first communication device 50 and the second communication device 20 in one housing and provide them as one system.
[0144] A specific example of the above-described data diode-like usage method will be described. Let the communication devices be A, B, and C. Also, let the secret information be A, B, and C. First, when only one-way communication from A to B (A→B) is allowed, a case may occur where communication such as C→B→A needs to be realized. For example, in a case where A has important IoT devices under its control and only the observation data observed by the IoT devices is transmitted from A and collected by B. Here, one-way communication is used to prevent attacks on A. In such a case, when a case occurs where a control command must be output from C to the IoT device under the control of A, the control command can be output by using the secret information of this embodiment. This will be specifically described below.
[0145] A and B hold the same secret information A. This is represented as A(A), B(A). The content in () indicates the secret information. As described above, since only one-way communication from A(A) to B(A) is allowed, data transmission from B is completely blocked, but data can be transmitted from B to A when a certain specific condition is satisfied. Hereinafter, a certain specific condition will be described.
[0146] Party A holds confidential information A, B, and C. Party B holds confidential information A and B. Party C holds confidential information A, B, and C. That is, C (A, B, C) → B (A, B) → A (A, B, C). Since Party B exchanges data with Party A, it holds confidential information A. Since it exchanges data with Party C, it holds confidential information B. At this time, in order to deliver the data X sent from Party C to Party A, the condition is to send from Party C to Party B the data encrypted with the common key generated from confidential information B, like (B (A (C (X)))). At Party B, when decrypting the received data with the common key generated from confidential information B, the data (A (C (X))) can be obtained. Party B directly sends the decrypted data (A (C (X))) to Party A.
[0147] Here, normally, in the data exchange between Party A and Party B, at Party B, there is a step of encrypting the data with the common key generated from confidential information A. However, since the data (A (C (X))) received by Party B from Party C has already been encrypted with the common key generated from confidential information A, there is no need to perform this step. The fact that there is no need to perform this step is one of the features of this embodiment. In order to be able to convey to Party A that this step is omitted, for example, data can be generated by changing 4 bits of the version information in the data part of TCP / IP from "0100" to "0110" and sent to Party A. At Party A, although it has an agreement to discard all data from Party B, when decrypting the data received from Party B with the common key generated from confidential information A, not only is the decrypted data in the form of (C (X)), but also 4 bits of the version information in the data part of TCP / IP are "0110". Thus, a mechanism can be constructed to decrypt with the common key generated from confidential information C and receive the data X from Party C.
[0148] On the other hand, in the case of data reception from B instead of from C, since B encrypts the data with a common key generated from the secret information A (processing by the aforementioned omitted steps), and since it is not necessary to convey to A from B that the said step is omitted, the version information is "0100" and not "0110", so A discards the data from B. Thus, by using the secret information of the present embodiment, in a situation where only one-way communication from A to B is permitted, a mechanism can be constructed such that A can receive data from C through B.
[0149] As the Internet has been widely used, individuals have become able to transmit information. However, in order for individuals to transmit information, they had no choice but to use the platforms provided by large enterprises. On the other hand, as a device for accessing the Internet, smartphones have come to be used more than ever, and at the same time, such smartphones have come to have a speed and memory that exceed those of low-cost PCs several years ago. By using the technology of the present embodiment, since the P2PVPN communication function can also be used, a personally-owned smartphone can be made to function like the cloud server of an EC shopping site. That is, there is no need to use the platform provided by a large enterprise, and there is no need for an expensive device such as a cloud server compared to a smartphone, so the operating cost can be reduced. Also, while carrying a smartphone, no matter where one moves or even while moving, it can be operated with high security and low cost as if operating an EC site on a cloud server. Although Web3 advocates non-centralized elements, by precisely using the present invention, since it does not require the power of a platform that includes centralized elements, Web3-like services can be provided to both users and service providers.
[0150] As described above, the first communication device 50 can perform P2P VPN communication with the second communication device 20. In P2P VPN communication, a virtual private network that operates like a physical network, that is, an Internet VPN (Virtual Private Network), is constructed between the first communication device 50 and the second communication device 20, and the first communication device 50 and the second communication device 20 can perform P2P communication via the Internet using private IP addresses managed by a communication network management server (not shown).
[0151] In this embodiment, the first communication device 50 and the second communication device 20 perform VPN communication between private IP addresses without using global IP addresses and perform P2P communication, thereby further improving security. As a result, each time the base station changes, a smartphone whose global IP address changes can be used as a cloud server (Web server).
[0152] (Appendix 1) The communication method is a communication method between a first communication device and a second communication device. When the second communication device is in a communication state with the first communication device and a predetermined event occurs in which the second communication device needs to retransmit data to the first communication device, the first communication device stops communication with the second communication device in response to the retransmission data transmitted by the second communication device.
[0153] (Appendix 2) In Appendix 1, the predetermined event includes an event in which the first communication device cannot receive a notification indicating normal reception within a predetermined time when the first communication device normally receives the data transmitted by the second communication device.
[0154] (Appendix 3) In Appendix 1 or Appendix 2, the predetermined event includes an event in which the first communication device reconnects to the session.
[0155] (Appendix 4) In any one of Appendices 1 to 3, the communication method is such that the predetermined event includes any one of the following events detected by the second communication device or the first communication device: timeout, restart, and IP address change (such as a case where the IP address changes when the base station to which the mobile terminal is connected changes as a result of the mobile terminal moving).
[0156] (Appendix 5) In any one of Appendices 1 to 4, the communication method repeats one or more cycles of generating the predetermined event when the elapsed time of the communication state between the first communication device and the second communication device exceeds a predetermined time.
[0157] (Appendix 6) In any one of Appendices 1 to 5, the communication method repeats one or more cycles of generating the predetermined event when the amount of data communicated between the first communication device and the second communication device exceeds a predetermined amount.
[0158] (Appendix 7) In any one of Appendices 1 to 6, the communication method is such that when the second communication device transmits retransmission data with at least the same data part, the first communication device stops communication with the second communication device.
[0159] (Appendix 8) In any one of Appendices 1 to 7, the communication method is such that when the second communication device retransmits data encrypted using the same key information as the key information used for encrypting the data transmitted to the first communication device, the first communication device stops communication with the second communication device.
[0160] (Appendix 9) In any one of Appendices 1 to 8, the communication method is such that the first communication device generates different key information at a required frequency based on secret information, and when the second communication device does not retransmit data encrypted using key information older than the key information used between the second communication device and the first communication device, the first communication device stops communication with the second communication device.
[0161] (Supplementary Note 10) In any one of Supplementary Notes 1 to 9, for the communication method, the first communication device and the second communication device hold a common secret information in advance. When the first communication device determines that the second communication device does not retransmit data encrypted using key information generated based on the secret information, the first communication device stops communication with the second communication device.
[0162] (Supplementary Note 11) In any one of Supplementary Notes 1 to 10, for the communication method, the first communication device generates a plurality of distributed information from the secret information, and generates a plurality of key information based on each of the generated distributed information. When the second communication device does not retransmit data encrypted using predetermined key information among the plurality of generated key information, the first communication device stops communication with the second communication device.
[0163] (Supplementary Note 12) In any one of Supplementary Notes 1 to 11, for the communication method, the first communication device holds the secret information. When the second communication device holds the same secret information as the secret information, communication between the first communication device and the second communication device is permitted.
[0164] (Supplementary Note 13) In any one of Supplementary Notes 1 to 12, for the communication method, the first communication device holds key information generated within the first communication device based on the secret information. Communication between the first communication device and the second communication device is permitted only when the second communication device holds the same key information as the key information generated within the second communication device based on the same secret information.
[0165] (Supplementary Note 14) In any one of Supplementary Notes 1 to 13, for the communication method, the first communication device holds the secret information. When the first communication device and the second communication device are present within a limited communication area of the first communication device or the second communication device, the first communication device transmits the secret information to the second communication device, and shares the secret information between the first communication device and the second communication device.
[0166] (Appendix 15) In the communication method described in Appendix 14, the first communication device holds first unique information related to the first communication device, or acquires second unique information related to the second communication device from the second communication device and holds it, and generates the secret information using at least one of the held first unique information and the acquired second unique information.
[0167] (Appendix 16) In the communication method described in Appendix 15, the first communication device acquires third unique information that is different from both the first unique information and the second unique information, and generates the secret information using the third unique information in addition to the first unique information and the second unique information.
[0168] (Appendix 17) In the communication method described in Appendix 14, the communication area is a specific area that only authorized personnel can enter.
[0169] (Appendix 18) In any one of Appendices 1 to 17, the first communication device holds secret information. When the first communication device and a portable recording medium are within the limited communication area of the first communication device, the first communication device transmits the secret information to the recording medium, the second communication device receives the secret information from the recording medium outside the communication area, and the secret information is shared between the first communication device and the second communication device.
[0170] (Appendix 19) In any one of Appendices 14 to 18, a plurality of communication areas are provided.
[0171] (Appendix 20) In any one of Appendices 1 to 19, one of the first communication device and the second communication device is a VPN primary and the other is a VPN client. The VPN primary holds secret information. When the VPN primary and the VPN client are within the limited communication area of the VPN primary or the VPN client, the VPN primary transmits the secret information to the VPN client, and the secret information is shared between the VPN primary and the VPN client.
[0172] (Appendix 21) In any one of Appendices 1 to 20, the communication method is such that the first communication device is installed in an area where access is restricted, displays a two-dimensional code in which secret information is held, the second communication device is brought into the area where access is restricted, reads the displayed two-dimensional code to hold the secret information, and shares the secret information between the first communication device and the second communication device.
[0173] (Appendix 22) In Appendix 21, the first communication device holds an identifier specific to the second communication device that has shared the secret information, and when updating the secret information, transmits a two-dimensional code in which the updated secret information is held to the second communication device that holds the identifier.
[0174] (Appendix 23) In any one of Appendices 1 to 22, the first communication device, which is the administrator of the private blockchain, writes the secret information as transaction data to the private blockchain, the second communication device, which is a participant registered to participate in the private blockchain, acquires the secret information written to the private blockchain from the private blockchain, and shares the secret information between the first communication device and the second communication device.
[0175] (Appendix 24) In any one of Appendices 1 to 23, the first communication device or the second communication device holds the existence area of the second communication device or the first communication device in each case where communication with the other is permitted, and when the location information of the second communication device or the first communication device is within the existence area, communication is performed between the first communication device and the second communication device.
[0176] (Appendix 25) In any one of Appendices 1 to 24, the first communication device performs P2PVPN communication with the second communication device.
[0177] (Supplementary Note 26) In any one of Supplementary Notes 1 to 25, the communication method is such that the first communication device receives, at its own transport layer, the retransmission data transmitted from the transport layer of the second communication device, and determines the retransmission data transmitted by the second communication device using its own transport layer.
[0178] (Supplementary Note 27) In any one of Supplementary Notes 1 to 26, the communication method is such that the first communication device receives, at its own transport layer, the retransmission data transmitted from the transport layer of the second communication device, and determines the retransmission data transmitted by the second communication device using its own application layer.
[0179] (Supplementary Note 28) In any one of Supplementary Notes 1 to 27, when the first communication device stops communication with the second communication device, the first communication device notifies an external device that unauthorized intrusion has occurred in the communication by the second communication device.
[0180] (Supplementary Note 29) In any one of Supplementary Notes 1 to 28, before stopping communication with the second communication device, the first communication device transmits a virus or ransomware to the second communication device or another device connected to the second communication device via the second communication device in order to disable the attacker's system.
[0181] (Supplementary Note 30) In any one of Supplementary Notes 1 to 29, the second communication device holds secret information, and when the third communication device and the second communication device are within a limited communication area of the third communication device or the second communication device, the second communication device transmits the secret information to the third communication device and shares the secret information between the second communication device and the third communication device.
[0182] (Appendix 31) In any one of Appendices 1 to 30, the communication method is such that when the first communication device encrypts data encrypted with a first shared key generated based on first secret information shared between the first communication device and another communication device with a second shared key generated based on second secret information shared between the first communication device and the second communication device, and further encrypts the data encrypted with a third shared key generated based on third secret information shared between the first communication device and the second communication device and then transmits the data to the second communication device in a state where only one-way communication from the first communication device to the second communication device is permitted through P2PVPN communication, the second communication device decrypts the received data with the third shared key, transmits the decrypted data to the first communication device, and the first communication device decrypts the received data with the second shared key and then decrypts the decrypted data with the first shared key to enable reception of data from the other communication device.
[0183] (Appendix 32) The communication device includes a control unit. When the control unit is in a communication state with another communication device and a predetermined event that requires retransmission of data occurs in the other communication device, the control unit stops communication with the other communication device in response to the retransmission data transmitted by the other communication device.
[0184] (Appendix 33) The computer program is a computer program that operates on a first communication device. When the second communication device is in a communication state with the first communication device and a predetermined event that requires retransmission of data to the first communication device occurs in the second communication device, the computer program causes the computer to execute a process of stopping communication with the second communication device in response to the retransmission data transmitted by the second communication device.
[0185] The matters described in each embodiment can be combined with each other. Also, the independent claims and dependent claims described in the claims can be combined with each other in all possible combinations regardless of the citation form. Furthermore, the claims use a form (multi-claim form) of describing claims that cite two or more other claims, but it is not limited to this. A form of describing a multi-claim (multi-multi-claim) that cites at least one multi-claim may be used.
Explanation of Signs
[0186] 1 Covert communication path 20, 40 Second communication device 50 First communication device 21, 51 Control unit 22, 52 Network communication unit 23, 53 Memory 24, 54 Display unit 25, 55 Retransmission data analysis unit 26, 56 Covert communication processing unit 27, 57 Storage unit 28, 58 OS 29, 59 Secret information 30, 60 Key information
Claims
1. A communication method between a first communication device and a second communication device, wherein the first communication device when the second communication device is in a communication state with the first communication device and a predetermined event occurs in which the second communication device needs to retransmit data to the first communication device, stops communication with the second communication device according to the retransmission data transmitted by the second communication device. Communication method.
2. The predetermined event includes an event in which, when the first communication device normally receives the data transmitted by the second communication device, a notification indicating normal reception cannot be received from the first communication device within a predetermined time. The communication method according to claim 1.
3. The predetermined event includes an event in which the first communication device reconnects to the session again. The communication method according to claim 1.
4. The predetermined event includes any one of an event of timeout, restart, and IP address change detected by the second communication device or the first communication device. The communication method according to claim 1.
5. When the elapsed time of the communication state between the first communication device and the second communication device becomes longer than a predetermined time, repeat one or more cycles of generating the predetermined event. The communication method according to claim 1.
6. When the amount of data communicated between the first communication device and the second communication device becomes larger than a predetermined amount, repeat one or more cycles of generating the predetermined event. The communication method according to claim 1.
7. The first communication device when the second communication device transmits retransmission data having at least the same data part, stops communication with the second communication device. The communication method according to any one of claims 1 to 6.
8. The first communication device when the second communication device retransmits data encrypted using the same key information as the key information used for encrypting the data transmitted to the first communication device, stops communication with the second communication device. The communication method according to any one of claims 1 to 6.
9. The first communication device generates different key information at a required frequency based on secret information, when the second communication device does not retransmit data encrypted using key information older than the key information used between the second communication device and the first communication device, stops communication with the second communication device. The communication method according to any one of claims 1 to 6.
10. The first communication device and the second communication device hold a common secret information in advance. The first communication device when the second communication device does not retransmit the data encrypted using the key information generated based on the secret information, stops communication with the second communication device The communication method according to any one of claims 1 to 6
11. The first communication device generates a plurality of pieces of distributed information from the secret information, generates a plurality of pieces of key information based on each of the generated pieces of distributed information, when the second communication device does not retransmit the data encrypted using predetermined key information among the plurality of generated pieces of key information, stops communication with the second communication device The communication method according to any one of claims 1 to 6
12. The first communication device holds the secret information, when the second communication device holds the same secret information as the secret information, permits communication between the first communication device and the second communication device The communication method according to any one of claims 1 to 6
13. The first communication device holds the key information generated within the first communication device based on the secret information, permits communication between the first communication device and the second communication device only when the second communication device holds the same key information as the key information generated within the second communication device based on the same secret information as the secret information The communication method according to any one of claims 1 to 6
14. The first communication device holds the secret information, when the first communication device and the second communication device are present within a limited communication area of the first communication device or the second communication device, transmits the secret information to the second communication device, shares the secret information between the first communication device and the second communication device The communication method according to any one of claims 1 to 6
15. The first communication device holds first unique information regarding the first communication device, or acquires second unique information regarding the second communication device from the second communication device, generates the secret information using at least one of the held first unique information and the acquired second unique information The communication method according to claim 14
16. The first communication device acquires third unique information different from both the first unique information and the second unique information, generates the secret information using the third unique information in addition to the first unique information and the second unique information The communication method according to claim 15
17. The communication area is a specific area that only authorized personnel can enter. The communication method according to claim 14.
18. The first communication device holds secret information. When the first communication device and the portable recording medium are within the limited communication area of the first communication device, the secret information is transmitted to the recording medium. The second communication device. Receives the secret information from the recording medium outside the communication area. Shares the secret information between the first communication device and the second communication device. The communication method according to any one of claims 1 to 6.
19. A plurality of the communication areas are provided. The communication method according to claim 14.
20. One of the first communication device and the second communication device is a VPN primary, and the other is a VPN client. The VPN primary holds secret information. When the VPN primary and the VPN client are within the limited communication area of the VPN primary or the VPN client, the secret information is transmitted to the VPN client. Shares the secret information between the VPN primary and the VPN client. The communication method according to any one of claims 1 to 6.
21. The first communication device. Is installed in an area with restricted access and displays a two-dimensional code holding secret information. The second communication device. Is brought into the area with restricted access, reads the displayed two-dimensional code, and holds the secret information. Shares the secret information between the first communication device and the second communication device. The communication method according to any one of claims 1 to 6.
22. The first communication device. Holds an identifier unique to the second communication device that has shared the secret information. When updating the secret information, a two-dimensional code holding the updated secret information is transmitted to the second communication device holding the identifier. The communication method according to claim 21.
23. The first communication device, which is the administrator of the private blockchain. Writes the secret information as transaction data to the private blockchain. The second communication device, which is a participant registered to participate in the private blockchain. Obtains the secret information written to the private blockchain from the private blockchain. Shares the secret information between the first communication device and the second communication device. The communication method according to any one of claims 1 to 6.
24. Holding the presence area of the second communication device or the first communication device in each case where communication with the first communication device or the second communication device is permitted, When the location information of the second communication device or the first communication device is within the presence area, performing communication between the first communication device and the second communication device. The communication method according to any one of claims 1 to 6.
25. The first communication device Performs P2P VPN communication with the second communication device The communication method according to any one of claims 1 to 6.
26. The first communication device Receives retransmission data transmitted from the transport layer of the second communication device at its own transport layer, Determines retransmission data transmitted by the second communication device using its own transport layer. The communication method according to any one of claims 1 to 6.
27. The first communication device Receives retransmission data transmitted from the transport layer of the second communication device at its own transport layer, Determines retransmission data transmitted by the second communication device using its own application layer. The communication method according to any one of claims 1 to 6.
28. The first communication device When stopping communication with the second communication device, notifies an external device that unauthorized intrusion has occurred in the communication by the second communication device. The communication method according to any one of claims 1 to 6.
29. The first communication device Before stopping communication with the second communication device, transmits a virus or ransomware to the second communication device or another device connected to the second communication device via the second communication device to disable the attacker's system. The communication method according to any one of claims 1 to 6.
30. The second communication device holds secret information, When the third communication device and the second communication device are present within a limited communication area of the third communication device or the second communication device, transmits the secret information to the third communication device, Shares the secret information between the second communication device and the third communication device. The communication method according to any one of claims 1 to 6.
31. The first communication device is in a state where only one-way communication to the second communication device is permitted through P2P VPN communication. Data encrypted with a first shared key generated based on first secret information shared between another communication device and the first communication device is encrypted with a second shared key generated based on second secret information shared between the first communication device and the second communication device, and further encrypted with a third shared key generated based on third secret information shared between the second communication device and the second communication device. When the encrypted data is transmitted to the second communication device, the second communication device decrypts the received data with the third shared key, transmits the decrypted data to the first communication device, the first communication device decrypts the received data with the second shared key and decrypts the decrypted data with the first shared key, enabling reception of data from the other communication device. The communication method according to any one of claims 1 to 6.
32. Comprising a control unit, the control unit is in a communication state with another communication device, and when a predetermined event occurs in which the other communication device needs to retransmit data, in response to the retransmission data transmitted by the other communication device, the other communication device stops communication with. Communication device.
33. A computer program operating on a first communication device, wherein the second communication device is in a communication state with the first communication device, and when a predetermined event occurs in which the second communication device needs to retransmit data to the first communication device, in response to the retransmission data transmitted by the second communication device, the communication with the second communication device is stopped. A computer program that causes a computer to execute the process.
Citation Information
Patent Citations
Vehicle-mounted communication system and repeating device
JP2004193903A
Restoration method for restoring system of client device, wireless connection device, and computer program
JP2014044548A
Network device and data transmission reception system
JP2014146868A
Validity determination method, validity determination program and validity determination device
JP2014183479A
Unauthorized device detection apparatus and method
JP2020065153A