Communication method, communication device and computer program

The communication method addresses the high cost and management challenges of protecting enterprise networks from cyberattacks by using a common key generated from shared secret information to stop unauthorized communication, effectively preventing network intrusions.

JP2025083255APending Publication Date: 2025-05-30矢野 義博 +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023223800
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing measures to protect enterprise networks from cyberattacks, such as ransomware, are costly and require continuous management, often leading to undetected unauthorized intrusions.

Method used

A communication method that allows a first communication device to stop communication with a second communication device based on retransmission data, without relying on network access authentication, by using a common key generated from shared secret information.

Benefits of technology

This method effectively prevents unauthorized intrusion into a network at a lower cost without the need for sophisticated detection or prevention systems, allowing for immediate detection and response to potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025083255000001_ABST
    Figure 2025083255000001_ABST
Patent Text Reader

Abstract

To provide a communication method, communication device and computer program capable of preventing unauthorized intrusion into a network.SOLUTION: A communication method between a first communication device and a second communication device is so configured that when the second communication device is in communication with the first communication device and a predetermined event occurs that requires the second communication device to retransmit data to the first communication device, the first communication device stops communication with the second communication device in response to retransmission data transmitted by the second communication device.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a communication method, a communication device, and a computer program.

Background Art

[0002] In order to reduce the damage caused by cyberattacks on enterprises, it is necessary to take appropriate measures. As one of such cyberattacks, in recent years, malware called ransomware has been popular worldwide.

[0003] Patent Document 1 discloses a technique for detecting a specific request in the kernel space corresponding to a predetermined request performed in the user space, and determining that the device is infected with ransomware when the request is detected at a predetermined frequency.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In order to protect the enterprise network from cyberattacks, it is necessary to hire IT technicians who are knowledgeable about networks and security, build a security system, introduce a system for detecting unauthorized access and preventing unauthorized intrusion, and check the logs of these systems daily to confirm whether any problems have occurred. However, these measures not only require a large initial installation cost but also continuous management costs, so the reality is that sufficient measures cannot be taken. Many enterprises that cannot protect their networks despite investing a large amount of costs are implementing measures to protect their networks from cyberattacks, which only involve network access authentication using user IDs and passwords. For this reason, even if an unauthorized intrusion occurs in the enterprise network, it often happens that it is not noticed for a long time or over a long period, making the enterprise vulnerable to ransomware attacks, causing great damage to the enterprise. Moreover, although it is an adverse effect unique to the network society, there is a high possibility that all enterprises belonging to the supply chain will be severely damaged.

[0006] The present invention has been made in view of such circumstances, and an object thereof is to provide a communication method, a communication device, and a computer program capable of preventing unauthorized intrusion into a network.

Means for Solving the Problem

[0007] This application includes a plurality of means for solving the above problems. For example, it adopts a communication method different from the conventional one and solves this problem without relying on network access authentication. The communication method is a communication method between a first communication device and a second communication device. When the second communication device is in a communication state with the first communication device and a predetermined event occurs that requires the second communication device to retransmit data to the first communication device, the communication with the second communication device is stopped according to the retransmission data transmitted by the second communication device.

Effect of the Invention

[0008] According to the present invention, unauthorized intrusion into a network can be prevented at low cost without introducing, installing, and operating a system such as unauthorized intrusion detection or prevention into the network.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Embodiments for Carrying Out the Invention

[0010] Hereinafter, embodiments of the present invention will be described. FIG. 1 is a diagram showing an example of unauthorized intrusion into a network that the communication method, communication device, communication system, and computer program of the present embodiment are intended to prevent. A line connection device is provided for an operator (company), and the line connection device is connected to an external terminal device Z. In FIG. 1, only one terminal device Z is shown, and there may be a plurality of terminal devices Z. The line connection device assumes a one-to-many connection with a plurality of terminal devices Z. The line connection device is connected to each device (for example, a personal computer, a server, a database, etc.) within the operator. In the example of FIG. 1, an advanced security system such as unauthorized intrusion prevention and unauthorized intrusion detection is not constructed for the line connection device and other devices within the operator, and it is assumed that the terminal device Z is authenticated by the user ID and password input from the terminal device Z.

[0011] If a user ID and password are entered incorrectly and are input from the attacker's terminal device Z', the line connection device will authenticate the terminal device Z' as if a legitimate user ID and password had been entered. As a result, the attacker's terminal device Z' can illegally intrude into the operator's network. After the illegal intrusion, ransomware is executed, and for example, important data is encrypted with the attacker's encryption key. When the important data is encrypted, the users within the operator cannot access the important data, and at this point, they will notice the hacking by the attacker. The attacker demands a large amount of money as compensation for restoring the encrypted important data and to avoid widely disclosing the important data. The operator may suffer significant damage due to the repair or loss of important data and the loss of the brand. In this embodiment, a method for immediately detecting an illegal intrusion by an attacker is provided.

[0012] FIG. 2 shows an example of the configuration of the communication system according to the present embodiment. The communication system includes a first communication device 50 and second communication devices 20 and 40. In the example of FIG. 2, two second communication devices are illustrated, but the number of second communication devices is not limited to two. Also, in the example of FIG. 2, one first communication device 50 is illustrated, but the number of first communication devices 50 is not limited to one. Here, the first communication device and the second communication device are allowed only 1:1 connection on the condition that they hold the same common secret information described later or the same common key (encryption key) in the encryption algorithm. The mechanism that is not allowed will be described later. Note that the secret information in this specification is not the secret key information in the public key cryptography infrastructure. The secret key information itself is used without being changed. For example, the secret key information is used when decrypting something encrypted with the public key. Alternatively, the secret key information is used to apply an electronic signature to certain digital data. On the other hand, it should be noted that the secret information used in the present application is digital data, but is not itself an encryption key to be used in an encryption algorithm. The secret information in the present application is information for enabling 1:1 VPN communication only when the same secret information is shared between two communication devices. An encryption key is generated from this secret information and used (described later), so that 1:1 communication can be performed. In other words, communication cannot be performed unless the same secret information is held at both ends communicating with each other. In the example of FIG. 2, when the first communication device 50 is 1:1 connected to the second communication device 20 and the first communication device 50 communicates with the second communication device 20, the first communication device has two different pieces of secret information corresponding to each of the two second communication devices 20 and 40. Also, the secret information in this specification is completely different information from the authentication information, etc. when determining whether the terminal device holds predetermined authentication information or not in order to confirm the presence or absence of authentication of the terminal device when remotely operating the terminal device, etc.

[0013] Communication devices such as the first communication device 50, the second communication devices 20 and 40 include line connection devices such as routers (for example, including not only fixed routers but also managed mobile routers), gateway devices, and terminal devices, which are types of terminal connection devices. Also, direct VPN communication can be performed from IoT devices, PCs, etc. under the line connection device to the line connection device.

[0014] For the 1:1 connection between the first communication device and the second communication device, an Internet VPN (Virtual Private Network) can be used. Since a communication network management server (not shown) manages the pairs of global IP addresses and private IP addresses of the first communication device and the second communication device to be managed, an Internet VPN between the first communication device and the second communication device can be constructed with private IP addresses.

[0015] As will be described later, the first communication device and the second communication device can have the same configuration. However, in this specification, the first communication device 50 is a communication device on the side that generates secret information, and the second communication devices 20 and 40 are communication devices on the side that acquire the secret information generated by the first communication device 50 when the following conditions are met.

[0016] The first communication device 50 and the second communication device include, for example, personal computers, smartphones, tablet terminals, devices with communication functions, electrical or electronic devices, and communication devices such as routers and gateway devices.

[0017] The first communication device 50 includes a control unit 51 that controls the entire device, a network communication unit 52, a memory 53, a display unit 54, a retransmission data analysis unit 55, a secure communication processing unit 56, and a storage unit 57.

[0018] The storage unit 57 can be configured by, for example, a hard disk or a semiconductor memory, and holds an OS 58, secret information 59, key information 60, and required information. In this specification, "hold" includes "store" and "record".

[0019] OS58 is, for example, Windows, Linux, Unix, Android or iOS (all trademarks), but is not limited thereto.

[0020] The secret information 59 includes unique secret information corresponding to each of the second communication devices 20, 40,... to which the first communication device 50 is connected in a one-to-one manner. For example, it includes the unique secret information used when the first communication device 50 communicates with the second communication device 20, the unique secret information used when the first communication device 50 communicates with the second communication device 40, and the like.

[0021] The key information 60 includes unique common keys corresponding to each of the second communication devices 20, 40,... to which the first communication device 50 is connected in a one-to-one manner. For example, it includes the unique common key used when the first communication device 50 communicates with the second communication device 20, the unique common key used when the first communication device 50 communicates with the second communication device 40, and the like.

[0022] The control unit 51 may be configured by incorporating a required number of CPUs, MPUs, etc. Further, the control unit 51 may be configured by combining a cryptographic processor, DSP, FPGA, etc.

[0023] The network communication unit 52 can perform VPN communication with the second communication devices 20, 40 via the secure communication path 1. The secure communication path is a communication path that can communicate securely using appropriate cryptographic techniques so that the confidentiality of the transmitted data is maintained even if the transmitted data is illegally obtained. Further, when there are devices or apparatuses connected to the first communication device 50, the network communication unit 52 can communicate with such devices or apparatuses. The devices include IoT devices.

[0024] The memory 53 can be composed of semiconductor memories such as SRAM (Static Random Access Memory), DRAM (Dynamic Random Access Memory), and flash memory. The required functions of the OS 58 are deployed in the memory 53, and the functions of the OS 58 are executed by the control unit 51.

[0025] The display unit 54 includes a liquid crystal display panel, an organic EL display panel, etc., and can display the results of processing by the first communication device 50.

[0026] When the second communication device 20 or the second communication device 40 is in a communication state with the first communication device 50 and a predetermined event occurs that requires the second communication device 20 or the second communication device 40 to retransmit data to the first communication device 50, the retransmission data analysis unit 55 analyzes the retransmission data transmitted by the second communication device or the second communication device 40. According to the analysis result of the retransmission data, the first communication device 50 stops (including interrupting or terminating) the communication with the second communication device 20 or the second communication device 40, or continues the communication with the second communication device 20 or the second communication device 40. In this specification, the stop of communication includes the interruption or termination of communication. The details of the retransmission data analysis method will be described later.

[0027] The secure communication processing unit 56 performs processing such as generation processing of secret information, generation processing of distributed information based on the secret information, generation processing of a common key, and secure communication path establishment processing between the first communication device 50 and the second communication devices 20 and 40. The details of the processing by the secure communication processing unit 56 will be described later.

[0028] The control unit 21, network communication unit 22, memory 23, display unit 24, retransmission data analysis unit 25, secure communication processing unit 26, and storage unit 27 of the second communication device 20 are the same as those of the control unit 51, network communication unit 52, memory 53, display unit 54, retransmission data analysis unit 55, secure communication processing unit 56, and storage unit 57 of the first communication device 50, so the description is omitted. The storage unit 27 holds the OS 28, secret information 29, key information 30, and required information.

[0029] Next, 1:1 VPN communication between the first communication device 50 and the second communication device 20 will be described. In 1:1 VPN communication, it is necessary to hold secret information in both communication devices before VPN communication. Only communication devices identified by the same secret information can perform 1:1 VPN communication. If the first communication device 50 is the VPN primary, the second communication device 20 that performs 1:1 VPN communication with this VPN primary is referred to as the VPN client. In the 1:1 VPN communication in the present application, communication between VPN clients is not established. The VPN primary is, for example, a communication device that generates secret information, or a communication device that has many devices (including IoT devices) and equipment under its control. In other words, 1:1 VPN communication is possible only between a VPN primary communication device having a function of generating secret information and a VPN client communication device that holds the same secret information and wants to perform VPN communication with this VPN primary communication device. Even if communication devices hold the same secret information, if one of the communication devices is not a device that generates secret information, that is, if it is not the VPN primary, VPN connection is not permitted.

[0030] In this specification, for convenience, the first communication device 50 is described as the VPN primary, and the second communication devices 20 and 40 are described as VPN clients. Note that the second communication devices 20 and 40 may be the VPN primary, and the first communication device 50 may be the VPN client. Of course, in this case, it is a condition that the second communication devices 20 and 40 respectively generate individual secret information.

[0031] There are the following two limitations in the 1:1 VPN communication that utilizes the secret information in the present application. VPN communication is not established unless the communication devices can be encrypted with a common key generated from the same secret information. The reason is that the data encrypted on the transmission side during VPN communication cannot be decrypted on the reception side. The other is that VPN communication is established only between a VPN primary that generates secret information and a VPN client that has the same secret information. In 1:1 VPN communication, a method that does not perform key exchange is adopted. This will be described below.

[0032] Figure 3 shows a first example of a method for generating a common key between the first communication device 50 and the second communication device 20. Figure 3 shows a method for preventing endangerment when generating a common key from secret information. The first communication device 50 (hereinafter synonymous with the control unit 51) holds the secret information S1 and S2 (S11), and the second communication device 20 holds the secret information S1 and S2 (S12). That is, the first communication device 50 and the second communication device 20 have completed sharing the same secret information S1 and S2. Details of the method for sharing the secret information and the method for generating the secret information will be described later.

[0033] The first communication device 50 generates a common key K1 from the secret information S1 using a predetermined key generation algorithm (S13). The second communication device 20 generates a common key K1 from the secret information S1 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S14). As a result, the common key can be shared at both ends of the first communication device 50 and the second communication device 20 without performing key exchange via the network. The first communication device 50 and the second communication device 20 open a secure communication channel using the common key K1 (S15). After this, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication.

[0034] Even if secret information can be securely shared between the first communication device 50 and the second communication device 20, there is a concern that the common key generated from the same secret information may be jeopardized. Therefore, in the present embodiment, after the start of the secure communication using the common key K1, at a required timing, the first communication device 50 generates a common key K2 from the secret information S2 using a predetermined key generation algorithm (S16), and the second communication device 20 generates a common key K2 from the secret information S2 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S17). Thereby, without performing key exchange via the network, the common keys updated at both ends of the first communication device 50 and the second communication device 20 can be shared. The first communication device 50 and the second communication device 20 open a secure communication path using the common key K2 (S18). Thereafter, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication using the new common key. By stopping the use of the common key K1 at a predetermined timing and applying a predetermined algorithm to the secret information S2 to obtain a new common key K2, the jeopardization of the common key can be prevented.

[0035] Figure 4 shows a second example of a method for generating a common key between the first communication device 50 and the second communication device 20. Figure 4 also shows a method for preventing jeopardization when generating a common key from secret information. The first communication device 50 holds the secret information S (S21), and the second communication device 20 holds the secret information S (S22). That is, the sharing of the same secret information S between the first communication device 50 and the second communication device 20 is completed. The first communication device 50 generates a random number R (S23) and transmits the generated random number R to the second communication device 20 (S24). Thereby, the random number R is shared between the first communication device 50 and the second communication device 20. Since the purpose is to share the random number R, there is no problem in the reverse direction. That is, the second communication device 20 may generate the random number R and transmit the generated random number R to the first communication device 50.

[0036] The first communication device 50 uses a predetermined encryption algorithm to adjust the random number R to a key length suitable for the encryption algorithm, and then uses this as an encryption key to encrypt the secret information S. After that, according to a predetermined algorithm, it generates distributed information Q1, Q2, and Q3 obtained by splitting and distributing this (S25). The second communication device 20 uses the same predetermined encryption algorithm as the encryption algorithm used by the first communication device 50 to adjust the random number R to a key length suitable for the encryption algorithm, and then uses this as an encryption key to encrypt the secret information S. After that, according to a predetermined algorithm, it generates distributed information Q1, Q2, and Q3 obtained by splitting and distributing this (S26). Note that the number of distributed information to be generated is not limited to three, and may be one, two, or four or more.

[0037] FIG. 5 is a diagram showing an example of a method for generating distributed information. In the method shown in FIG. 5A, the secret information S is encrypted by a common key encryption algorithm using the random number R as an encryption key to generate encrypted data. As the encryption algorithm, for example, DES (Data Encryption Standard) or AES (Advanced Encryption Standard) can be used. Next, the encrypted data is split (fragmented) into three pieces of distributed information Q1, Q2, and Q3. How to split which part of the encrypted data (the splitting method) can be determined in advance. The number of splits is not limited to three, and may be one, two, or four or more, and can be split (distributed) into the required number of files.

[0038] When generating the distributed information Q1, Q2, and Q3 from the random number R, although the case of adopting a block encryption algorithm was presented above, a stream cipher may also be utilized. For example, MUGI, Salasa20, etc. can be used.

[0039] So far, the byte length of the secret information has not been mentioned. As an example of a case where it is necessary to increase the byte length of the secret information according to the number of pieces of distributed information to be obtained, if the result obtained by repeatedly applying a hash function, such as SHA-2, to the secret information a predetermined number of times is used as the secret information, that would be sufficient. In the first communication device 50 and the second communication device 20, the hash function to be adopted and the number of times of repeated hashing are determined and made the same.

[0040] Each of the distributed information Q1, Q2, and Q3 is a byte sequence that has no meaning. Even if one piece of distributed information among the plurality of distributed information is leaked or illegally acquired, the leaked or illegally acquired distributed information alone is data that has no meaning, and it is not possible to infer other distributed information (not leaked or illegally acquired) from the leaked or illegally acquired divided information. As a result, the security of the common key used during VPN communication can be improved.

[0041] In the method shown in FIG. 5B, while encrypting the secret information S with a common key encryption algorithm using the random number R as the encryption key, or after encryption, it is distributed to the distributed information Q1, Q2, and Q3. As the encryption algorithm, for example, block ciphers such as DES or AES can be used, but stream ciphers such as MUGI or Salasa20 can also be used.

[0042] Returning to FIG. 4, the first communication device 50 generates a common key K1 from the distributed information Q1 using a predetermined key generation algorithm (S27). The second communication device 20 generates a common key K1 from the distributed information Q1 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S28). Thereby, the first communication device 50 and the second communication device 20 can share a common key at both ends without performing key exchange via the network. The first communication device 50 and the second communication device 20 establish a secure communication channel using the common key K1 (S29). Thereafter, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication. It is important that the common key K1 is not generated directly from the random number R, that is, key exchange is not performed via the network. In the conventional method using PKI, the random number R is encrypted with the private key and transmitted, and on the receiving side, it is decrypted with the public key of the sender and used as the common key itself. That is, key exchange is performed via the network. In other words, the present application states that key exchange is not performed via the network because the common key K1 cannot be generated only from the random number R information exchanged via the network. The common key K1 cannot be generated unless both the random number R and the secret information S are available. Also, the random number R is not essential information. Even without this random number R, the ability to prevent endangerment decreases, but the common key K1 can also be generated by applying the above-described split distribution method to the secret information S.

[0043] Similar to the case of FIG. 3, in order to prevent the endangerment of the common key, after the start of the secure communication using the common key K1, at the required timing, the first communication device 50 generates the common key K2 from the distributed information Q2 using a predetermined key generation algorithm (S30), and the second communication device 20 generates the common key K2 from the distributed information Q2 using the same predetermined key generation algorithm as the key generation algorithm used by the first communication device 50 (S31). Thereby, without performing key exchange via the network, the common keys updated at both ends of the first communication device 50 and the second communication device 20 can be shared, and the endangerment of the common key can be prevented. The first communication device 50 and the second communication device 20 establish a secure communication path using the common key K2 (S32). Thereafter, the first communication device 50 and the second communication device 20 can perform 1:1 VPN communication using the new common key.

[0044] As described above, the first communication device 50 holds the secret information, and when the second communication device 20 holds the same secret information as the secret information held by the first communication device 50, the communication (1:1 VPN communication) between the first communication device 50 and the second communication device 20 is allowed.

[0045] Further, the first communication device 50 holds the common key (key information) generated based on the secret information, and when the second communication device 20 holds the same common key as the common key held by the first communication device 50, which is generated based on the same secret information as the secret information held by the first communication device 50, the communication (1:1 VPN communication) between the first communication device 50 and the second communication device 20 can be allowed. Note that one of the communication devices, either the first communication device 50 or the second communication device 20, needs to be the VPN primary.

[0046] Https (encrypted communication) used on a website or the like encrypts the communication between a server with an SSL certificate (electronic certificate) set and a terminal device. The SSL certificate is used for a 1:many connection between one authenticated domain and a plurality of users (for example, viewers). That is, in a 1:many connection communication, only the server connected from the terminal devices of a plurality of users is authenticated unidirectionally.

[0047] Generally, in one-to-many communication, if the ID and password are leaked, an attacker can easily break into the network, and a security incident may occur where the attacker suffers great damage without realizing the intrusion. However, in this embodiment, an attacker (such as a hacker) who does not know the secret information or the common key cannot communicate with the correct encryption key, so a 1:1 VPN communication cannot be established. In other words, in this embodiment, only 1:1 VPN communication is permitted, so additional security solutions such as intrusion detection and intrusion prevention introduced in a one-to-many communication environment are not required. Also, there is no need to audit the logs maintained by these security solutions. This can reduce the operation costs including the introduction cost and labor cost.

[0048] Also, the presence area of the first communication device 50 when communication with the second communication device 20 is permitted is held. When the position information of the first communication device 50 based on the GPS included in the first communication device 50 is within the said presence area, communication between the first communication device 50 and the second communication device 20 may be performed. Thereby, for example, when the first communication device 50 performing 1:1 VPN communication is stolen, it can be determined that the position information of the first communication device 50 obtained by the GPS included in the first communication device 50 is not in the normal location, so unauthorized use can be prevented. Similarly, the same effect can be obtained by reversing the second communication device 20 and the first communication device 50.

[0049] FIG. 6 is a diagram illustrating an example of generating distributed information from secret information and generating a plurality of common keys. By the method illustrated in FIG. 5, distributed information Q1, Q2, …, Q(n−1), Qn is generated from secret information S. From each of the distributed information Q1, Q2, …, Q(n−1), Qn, common keys K1, K2, …, K(n−1), Kn are generated. The timing of generating the common keys K1, K2, …, K(n−1), Kn may be simultaneous or may be generated in any order at any time. As shown in FIG. 6, in the present embodiment, among the plurality of generated common keys, a predetermined common key (common key Kn in the example of FIG. 6) is stored as an encryption key (synonymous with the common key) for encrypting the retransmission data when transmitting the retransmission data, between the first communication device 50 and the second communication device 20 (that is, the VPN primary and the VPN client). In the present specification, “stock” means storing information in advance as a reserve. The timing at which this stocked common key is used will be described later. The common keys other than the common key Kn are used for encrypting data in VPN communication.

[0050] Generally, when performing secure communication, the data transmitted and received is encrypted. The encryption key used at this time is exchanged via the network using a mechanism such as PKI (public key infrastructure). However, when a quantum computer appears, it is said that the method of exchanging the encryption key via the network will cause the PKI to be broken by the quantum computer and the encryption key to be exposed even for encrypted data. However, as described above, in the present embodiment, since key exchange via the network is not performed, it is resistant to quantum computers.

[0051] Next, a method for detecting unauthorized intrusion into a network system by an attacker will be described. Hereinafter, for convenience, it will be described assuming that the first communication device 50 (VPN primary) is the communication device on the side that detects unauthorized intrusion, and the second communication device 20 (VPN client) is the communication device to be detected for unauthorized intrusion. Note that it is considered that the attacker attacks the first communication device 50, which is the VPN primary having a large amount of asset information to be protected, via the second communication device 20.

[0052] FIG. 7 is a diagram showing a first example of the unauthorized access detection method according to the present embodiment. The first communication device 50 and the second communication device 20 establish a session of 1:1 connection VPN communication (S41), and the VPN communication is being executed (S42). That is, the first communication device 50 and the second communication device 20 are in a communication state. In the process of VPN communication, the second communication device 20 transmits required data to the first communication device 50 (S43), and the first communication device 50 receives the data (S44). At this time, it is assumed that the first communication device 50 can receive the data normally.

[0053] When it is determined that it is the timing for the first communication device 50 to detect the presence or absence of unauthorized access to the second communication device 20, the first communication device 50 does not send a notification indicating that the data has been normally received to the second communication device 20 within a predetermined time despite having normally received the data transmitted by the second communication device 20. Specifically, the first communication device 50 does not send a notification indicating that the data has been normally received to the second communication device 20, or sends it to the second communication device 20 after a predetermined time has elapsed. The event that, despite having normally received the data transmitted by the second communication device 20, a notification indicating that the data has been normally received is not sent to the second communication device 20 within a predetermined time means that a predetermined event has occurred in which the second communication device 20 needs to retransmit the data to the first communication device 50.

[0054] The second communication device 20 cannot receive a notification indicating that the data has been normally received within a predetermined time (S45). When an attacker decodes the common key generated from the secret information, the second communication device 20 that has been illegally accessed by the attacker generally retransmits the data when it cannot receive a notification indicating that the data has been normally received within a predetermined time. That is, the second communication device 20 retransmits the data (S46).

[0055] When the first communication device 50 receives the retransmission data, it analyzes the retransmission data (S47). The analysis of the retransmission data determines whether the retransmission data matches any of the response methods predetermined between the first communication device 50 and the second communication device 20. If the retransmission data transmitted by the second communication device 20 does not conform to the predetermined response method, the first communication device 50 stops the communication with the second communication device 20 (S48). In the present embodiment, "stopping the communication" means a state where no communication is taking place. For example, a state where communication is temporarily stopped for a certain period of time and then resumed is not included.

[0056] As described above, when the second communication device 20 is in a communication state with the first communication device 50 and a predetermined event occurs that requires the second communication device 20 to retransmit data to the first communication device 50, the first communication device 50 can stop the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20. The predetermined event includes, for example, an event where when the first communication device 50 normally receives the data transmitted by the second communication device 20, the first communication device 50 cannot receive a notification from the second communication device 20 that it has been normally received within a predetermined time.

[0057] Also, a computer program (for example, the OS 58) operating in the first communication device 50 can execute a process of stopping the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20 when the second communication device 20 is in a communication state with the first communication device 50 and the retransmission data analysis unit 55 analyzes (determines) that a predetermined event has occurred that requires the second communication device 20 to retransmit data to the first communication device 50.

[0058] If an attacker illegally obtains the secret information and cannot obtain the VPN client program, it may be possible to easily establish a 1:1 VPN communication. However, since the common key used for the retransmission data is different, the primary can determine that the connection is from an illegal terminal, so the VPN communication can be stopped. The logic when the common keys are different will be described later.

[0059] When an attacker illegally obtains confidential information and also obtains the VPN client program, the operator takes advantage of the fact that the users are different. Before any arbitrary timing or before and after the timing that prompts the resending of data, the user identification number is requested to determine whether the obtained information is correct. The determination method makes use of the fact that the user identification information is used in the generation of the confidential information. Other examples of the user identification number include the email address, employee number, and My Number described later.

[0060] When an attacker illegally obtains confidential information and also obtains the VPN client program, the operator takes advantage of the fact that the location information during operation is different. That is, as described above, the area where the second communication device 20 exists when communication with the first communication device 50 is permitted is held, and communication between the first communication device 50 and the second communication device 20 may be performed only when the position information of the second communication device 20 based on the GPS included in the second communication device 20 is within the said area.

[0061] In addition, when the second communication device 20 illegally invaded by the attacker cannot receive a notification that the data has been normally received within a predetermined time, it takes time to analyze the cause. When the second communication device 20 cannot continue communication within a specific time, the first communication device 50 may stop communication with the second communication device 20.

[0062] As described above, when the first communication device 50 normally receives the data transmitted by the second communication device 20, by not transmitting a notification to the second communication device 20 that it has been normally received within a predetermined time, the confidential communication can be immediately interrupted when an illegal intrusion is detected, so that an illegal intrusion into the network can be prevented.

[0063] Further, when the first communication device 50 stops communication with the second communication device 20, it may notify an external device (for example, a network monitor device or an email address) that unauthorized intrusion has occurred in the communication by the second communication device 20. Alternatively, a printer existing within the network segment where the VPN primary is installed may be caused to output a printed matter notifying that unauthorized intrusion has occurred. Thereby, unauthorized intrusion into the network and the intrusion location (the corresponding communication device) can be immediately detected.

[0064] In recent years, it has been recognized that large enterprises at the upstream of the supply chain are also suffering damages via small and medium-sized enterprises vulnerable to cyberattacks, and it is necessary to urgently take countermeasures. According to this embodiment, active cyber defense can be realized. Active cyber defense is the ability to intrude into and neutralize a counterparty server or the like in order to prevent cyberattacks on government agencies and critical infrastructure. In this embodiment, for example, before implementing communication stop, since the VPN communication can continue, a deletion command for secret information, a virus, or ransomware may be transmitted to disable and neutralize the attacker's system in the long term. Then, the VPN communication is stopped.

[0065] As described above, before stopping communication with the second communication device 20, the first communication device 50 can transmit a virus or ransomware to the second communication device 20 or another device connected to the second communication device 20 via the second communication device 20 in order to disable the attacker's system, and stop communication with the second communication device 20 after transmitting the virus or ransomware.

[0066] FIG. 8 is a diagram showing a second example of the unauthorized intrusion detection method of this embodiment. In FIG. 8, steps S141 to S143 are the same as steps S41 to S43 in FIG. 7. When the first communication device 50 determines that it is the timing to detect the presence or absence of unauthorized intrusion into the second communication device 20, the first communication device 50 reconnects the session (S144). When the second communication device 20 detects that the first communication device 50 has reconnected the session (S145), it retransmits the data (S146).

[0067] When the first communication device 50 receives the retransmission data, it analyzes the retransmission data (S147). The analysis of the retransmission data determines whether the retransmission data matches any of the response methods predetermined between the first communication device 50 and the second communication device 20. If the retransmission data transmitted by the second communication device 20 does not conform to the predetermined response method, the first communication device 50 stops the communication with the second communication device 20 (S148).

[0068] As described above, when the second communication device 20 is in a communication state with the first communication device 50 and a predetermined event occurs in which the second communication device 20 needs to retransmit data to the first communication device 50, the first communication device 50 can stop the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20. The predetermined event includes, for example, the event that the first communication device 50 reconnects to the session again.

[0069] As described above, when the first communication device 50 reconnects to the session again and unauthorized intrusion is detected, the secure communication can be immediately interrupted, so unauthorized intrusion into the network can be prevented.

[0070] FIG. 9 is a diagram showing a third example of the unauthorized intrusion detection method of the present embodiment. In FIG. 9, steps S241 to S243 are the same as steps S41 to S43 in FIG. 7. When the second communication device 20 detects the occurrence of an event (S244), the second communication device 20 retransmits the data (S245). The events detected by the second communication device include, for example, the case where a timeout occurs, the case where a network device such as a router or a switch on the network fails and restarts, and the case where the IP address of the device communicating during the session connection is changed.

[0071] When the first communication device 50 receives retransmission data, it analyzes the retransmission data (S246). The analysis of the retransmission data determines whether the retransmission data matches any of the response methods predetermined between the first communication device 50 and the second communication device 20. If the retransmission data transmitted by the second communication device 20 does not conform to the predetermined response method, the first communication device 50 stops the communication with the second communication device 20 (S247).

[0072] As described above, when the second communication device 20 is in a communication state with the first communication device 50 and a predetermined event occurs that requires the second communication device 20 to retransmit data to the first communication device 50, the first communication device 50 can stop the communication with the second communication device 20 according to the retransmission data transmitted by the second communication device 20. The predetermined event includes, for example, any of the events of timeout, restart, and IP address change detected by the second communication device 20. In the example of FIG. 9, the second communication device 20 is configured to detect the occurrence of an event, but it is not limited thereto. For example, the first communication device 50 may detect a timeout (predetermined event) in the same manner as the second communication device 20. The timeout detected by the first communication device 50 occurs in the following cases. That is, when the network of the first communication device 50 exceeds the bandwidth for connection requests from a plurality of second communication devices 20 (even in one-to-one communication, it may be connected from a plurality of second communication devices 20), the first communication device 50 generates a timeout. Also, when the upper limit of the number of simultaneous connections is set based on the security policy of the first communication device 50, the first communication device 50 may generate a timeout if there are connections exceeding the upper limit.

[0073] As described above, when an event occurs on the second communication device 20 side or when the first communication device 50 detects a timeout, the stealth communication can be immediately blocked when unauthorized intrusion is detected, so unauthorized intrusion into the network can be prevented.

[0074] Next, the method for analyzing the retransmission data will be described.

[0075] FIG. 10 is a diagram showing an example of an analysis method for retransmission data. When a predetermined event occurs, the first communication device 50 (VPN primary) analyzes the retransmission data transmitted by the second communication device 20, and performs a predetermined response according to the analysis result. As shown in FIG. 10, when the retransmission data is not predetermined data (for example, (1) when the retransmission data has at least the same data part as the latest data), the first communication device 50 stops communication with the second communication device 20. Hereinafter, in this specification, the latest data is, for example, the data transmitted by the second communication device 20 immediately before the transmission of the retransmission data by the second communication device 20. It is assumed that there is no data transmitted by the second communication device 20 between the transmission of the latest data and the transmission of the retransmission data, but the time between the transmission of the latest data and the transmission of the retransmission data is not particularly defined. The data having at least the same data part includes, for example, the case where a response message or the like is incorporated and the data is not exactly the same. Generally, when an attacker selects retransmission of data, the same data is transmitted again. As a predetermined response method, it may be agreed to retransmit data that is different from the latest data at least in terms of the data part.

[0076] As described above, when the second communication device 20 transmits retransmission data having at least the same data part, the first communication device 50 may stop communication with the second communication device 20.

[0077] Also, as shown in FIG. 10, when the common key used when transmitting the retransmission data is not a predetermined common key, the first communication device 50 stops communication with the second communication device 20. The case where the common key is not a predetermined common key includes, for example, (2) when encrypting the retransmission data using the same common key as the common key for encrypting the latest data, (3) when not encrypting the retransmission data using a common key generated in the past that is older than the common key for encrypting the latest data, (4) when not encrypting the retransmission data using a predetermined common key among a plurality of previously generated common keys, and the like.

[0078] FIG. 11 is a diagram showing a first example of the analysis result of retransmission data. The first communication device 50 and the second communication device 20 establish secure communication using a common key K1 (S51), and thereafter, VPN communication is executed. After the first communication device 50 and the second communication device 20 continue secure communication using the common key K1, they end the secure communication using the common key K1 at an arbitrary timing (S52). If the VPN communication itself has not ended, the first communication device 50 and the second communication device 20 establish secure communication using a common key K2 (a common key newer than the common key K1) (S53).

[0079] The second communication device 20 transmits the data encrypted with the common key K2 to the first communication device 50 (S54). When a predetermined event occurs where the first communication device 50 is in a communication state with the second communication device 20 and the second communication device 20 needs to retransmit data to the first communication device 50 (S55), the second communication device 20 transmits the retransmission data encrypted with the common key K2 to the first communication device 50 (S56). When the first communication device 50 can control the timing at which the predetermined event occurs (for example, when the first communication device 50 does not send a notification to the second communication device 20 that it has normally received the data transmitted by the second communication device 20 within a predetermined time, or when the first communication device 50 reconnects to the session again), the first communication device 50 determines the timing. Details of the occurrence timing of the predetermined event will be described later.

[0080] The first communication device 50 analyzes the retransmission data. In the case of FIG. 11, the retransmission data corresponds to the case where the retransmission data is encrypted using the same common key as the common key for encrypting the (2) most recent data shown in FIG. 10, or the case where the retransmission data is not encrypted using a common key generated in the past that is older than the common key for encrypting the most recent data. Therefore, the first communication device 50 stops the communication with the second communication device 20 (S57).

[0081] As described above, when the second communication device 20 transmits retransmission data encrypted using the same common key (key information) as the common key used for encrypting the data transmitted to the first communication device 50, the first communication device 50 stops the communication with the second communication device 20.

[0082] If an attacker has decrypted the common key generated from the secret information, the attacker is considered to send retransmission data using the decrypted common key. Therefore, when the second communication device 20 sends retransmission data encrypted using the same common key as the common key used to encrypt the most recent data, it can be detected that the second communication device 20 has been illegally invaded, and the secure communication can be immediately interrupted to prevent illegal invasion into the network.

[0083] Also, as described above, the first communication device 50 generates different common keys K1 (the common key K1 corresponds to the stored common key described above) and K2 (newer than K1) at required frequencies based on the secret information. When the second communication device 20 does not send retransmission data encrypted using the common key K1 stored older than the common key K2 used between the second communication device 20 and the first communication device 50, the communication with the second communication device 20 may be stopped. Also, the first communication device 50 and the second communication device 20 store the secret information in advance. The first communication device 50 may stop the communication with the second communication device 20 when the second communication device 20 does not retransmit the data encrypted using the key information generated based on the secret information.

[0084] If an attacker deciphers a common key generated from secret information and also illegally obtains the VPN application, the attacker is considered to transmit retransmission data using the deciphered common key. In this case, since the attacker has also stolen the VPN application, the attacker believes that there is no particular problem with the retransmission data to be transmitted and retransmits it. However, the attacker cannot know the common key generated and stored in the past and, of course, has not deciphered it either. Therefore, if the second communication device 20 encrypts the retransmission data using a common key generated and stored in the past that is older than the common key used to encrypt the most recent data, it is possible to detect that the second communication device 20 has been illegally invaded, and it is possible to immediately cut off the secure communication and prevent illegal intrusion into the network. This is based on the fact that the secret information and the VPN application that the attacker can obtain are at a certain point in time, and it is extremely difficult to obtain the common key by going back in time from this point, and the attacker cannot know the location where it is stored. To supplement, this is because it is stored before the attacker (hacker) steals the legitimate VPN application. What is stored is not limited to the common key but may also be secret information. If what is stored is secret information, a common key will be generated from now on. Or, although the security strength will decrease, instead of the stored common key, a common key used in the past or the common key Kn shown in FIG. 6 may be used.

[0085] FIG. 12 is a diagram showing a second example of the analysis result of retransmission data. FIG. 12 shows an example of using a stored common key. The first communication device 50 and the second communication device 20 establish secure communication using the common key K1 (S61), and thereafter, VPN communication is executed. After the first communication device 50 and the second communication device 20 continue the secure communication using the common key K1, the secure communication using the common key K1 is terminated at an arbitrary timing (S62). If the VPN communication itself has not ended, the first communication device 50 and the second communication device 20 establish secure communication using the common key K2 (a common key newer than the common key K1) (S63).

[0086] The second communication device 20 transmits the data encrypted with the common key K2 to the first communication device 50 (S64). When the first communication device 50 is in a communication state with the second communication device 20 and a predetermined event occurs that requires the second communication device 20 to retransmit the data to the first communication device 50 (S65), the second communication device 20 transmits the retransmission data encrypted with a past common key K1 older than the currently used common key K2 to the first communication device 50 (S66). When the first communication device 50 can control the timing of the occurrence of the predetermined event (for example, when the first communication device 50 does not transmit a notification to the second communication device 20 indicating that the data transmitted by the second communication device 20 has been normally received within a predetermined time, or when the first communication device 50 reconnects to the session again), the first communication device 50 determines the timing.

[0087] The first communication device 50 analyzes the retransmission data. In this case, since the retransmission data is encrypted using a common key generated and stored in the past, which is older than the common key encrypting the most recent data, or a common key generated from the stored secret information, the first communication device 50 continues the communication (S67). Then, at the required timing, the first communication device 50 and the second communication device 20 end the confidential communication using the common key K2 (S68). If a common key generated and stored in the past, which is older than the common key encrypting the most recent data, or a common key generated from the stored secret information is not used, the first communication device 50 stops the communication.

[0088] FIG. 13 is a diagram showing a third example of the analysis result of retransmission data. The first communication device 50 and the second communication device 20 establish secure communication using the common key K1 (S71). Thereafter, VPN communication is executed, and the first communication device 50 and the second communication device 20 continue the secure communication using the common key K1, and then terminate the secure communication using the common key K1 at an arbitrary timing (S72). If the VPN communication itself has not ended, the first communication device 50 and the second communication device 20 establish secure communication using the common key K2 (a common key newer than the common key K1. The meaning of the new common key here is the meaning of a common key used later in time than the common key K1) (S73).

[0089] The second communication device 20 transmits the data encrypted with the common key K2 to the first communication device 50 (S74). When a predetermined event occurs in which the first communication device 50 is in a communication state with the second communication device 20 and the second communication device 20 needs to retransmit data to the first communication device 50 (S75), the second communication device 20 transmits the retransmission data encrypted with a common key other than the common key Kn to the first communication device 50 (S76). When the first communication device 50 can control the timing at which the predetermined event occurs (for example, when the first communication device 50 does not transmit a notification to the second communication device 20 that the data transmitted by the second communication device 20 has been normally received within a predetermined time, or when the first communication device 50 reconnects to the session again), the first communication device 50 determines the timing.

[0090] The first communication device 50 analyzes the retransmission data. In the case of FIG. 13, since the retransmission data corresponds to the case where the retransmission data is not encrypted using a predetermined common key among the plurality of pre-generated common keys shown in FIG. 10, the first communication device 50 stops the communication with the second communication device 20 (S77).

[0091] As described above, the first communication device 50 generates a plurality of distributed information from the secret information, and generates a plurality of common keys based on each of the generated distributed information. If the second communication device 20 does not retransmit the data encrypted using a predetermined common key Kn (see FIG. 6) among the plurality of generated common keys, the first communication device 50 may stop the communication with the second communication device 20.

[0092] Thereby, since a plurality of common keys can be generated at once from one piece of secret information, it is possible to prevent the endangerment of the common key, detect that the second communication device 20 has been illegally invaded, and immediately cut off the VPN communication to prevent illegal invasion into the network.

[0093] FIG. 14 is a diagram showing an example of the execution environment of the first communication device 50 and the second communication device 20. The first communication device 50 and the second communication device 20 perform network communication using TCP / IP (one of the mainstream communication protocols). Although TCP / IP defines a communication method divided into four layers, as shown in FIG. 14A, in the first communication device 50 and the second communication device 20, in the application layer, a program (application program) is deployed and executed in the user memory space, and in the transport layer, the VPN program is deployed and executed in the OS memory space.

[0094] When the VPN program of the second communication device 20 transmits the retransmission data to the first communication device 50, the VPN program that has received the retransmission data in the transport layer executes the analysis of the retransmission data.

[0095] As described above, the first communication device 50 can analyze the retransmission data transmitted by the second communication device 20 using the transport layer. That is, in the present embodiment, the analysis of the retransmission data is performed in the transport layer, and the application layer is configured not to be involved in the analysis of the retransmission data. More specifically, the transport layer of the first communication device 50 is responsible for the data exchange with the transport layer of the second communication device 20, determines whether the communication partner is a legitimate partner, analyzes the data (retransmission data) flowing through the transport layer, and stops the communication according to the analysis result. In these series of processes, one of the features of the present embodiment is that the application layer above the transport layer does not cooperate with the transport layer at all. Although it is called the transport layer in TCP / IP, in protocols other than TCP / IP, the layer corresponding to the transport layer performs these series of processes, and the layer corresponding to the application layer does not perform these series of processes.

[0096] Generally, compared to the number of software engineers who develop programs (the VPN program of the first communication device 50) that are deployed in the OS memory space, use the communication method of the transport layer, and utilize the functions of the OS, the number of engineers who develop application programs that use the communication method of the application layer is extremely large. Therefore, currently, the number of people who can hack the VPN program that uses the communication method of the transport layer is extremely small compared to the number of people who can hack the application program. Thus, by using a VPN program that uses the communication method of the transport layer as in the present embodiment, a communication system that is relatively resistant to hacking can be constructed. In addition, invading and infecting a malicious program that operates in the transport layer requires direct modification and transformation of the OS, which is more difficult compared to that for the application layer. The reason is that when directly modifying and transforming the OS, not only is it necessary to elevate the privileges of the OS, but also the applications become unavailable when this malicious OS is installed, so the attacked side is likely to notice any abnormalities. Although not shown in the figure, the first communication device 50 may receive the retransmission data transmitted from the transport layer of the second communication device 20 at its own transport layer and determine the retransmission data transmitted by the second communication device 20 using its own application layer. Thereby, even when the source code of the OS is not disclosed (not open source), the present embodiment can be implemented.

[0097] As shown in FIG. 14B, when the first communication device 50 is in a communication state with the second communication device 20 and a predetermined event occurs that requires the second communication device 20 to retransmit data to the first communication device 50 (S81), the second communication device 20 transmits the retransmission data to the first communication device 50 (S82). The first communication device 50 receives the retransmission data (S83) and decrypts the received retransmission data with a predetermined common key (S84).

[0098] The first communication device 50 determines whether it has successfully decoded the retransmitted data (S85). If the decoding is not successful (NO in S85), that is, if the retransmitted data is not encrypted with the common key predetermined between the first communication device 50 and the second communication device 20, the first communication device 50 determines that the second communication device 20 is not the correct connection device partner and can stop the communication (S86). On the other hand, if the decoding is successful (YES in S85), that is, if the retransmitted data is encrypted with the common key predetermined between the first communication device 50 and the second communication device 20, the first communication device 50 determines that the second communication device is the correct connection device partner and can continue the communication (S87).

[0099] In this way, the analysis of the retransmitted data can be performed based on whether it can be decoded with the common key predetermined between the first communication device 50 and the second communication device 20. When it can be decoded, there is no problem. When it cannot be decoded, not only has the authentication information generally exchanged at the application layer at the start of VPN communication been leaked and used, but also secret information, etc. has been leaked, and it can be determined that it is an illegal communication device that has executed an illegal connection, and an illegal intrusion can be detected with a simple configuration. As a result, it is not necessary to employ a security system expert, and the introduction of a sophisticated and complex security system for intrusion detection and prevention is unnecessary. Note that most of the security incidents in general VPN communication occur due to the exposure of authentication information due to an attack on the authentication information (ID and password in authentication using ID and password), or leakage such as a social attack. However, in the present invention, 1:1 communication is the basis, and a common key used for confidential communication is generated with the secret information exchanged in advance. Therefore, even if the authentication information is misused, it has high resistance to security attacks, but the possibility of the secret information being stolen cannot be denied. However, the fact that the security resistance can be maintained even in such a case is an advantage of the present invention.

[0100] Next, a method for determining the occurrence timing of a predetermined event will be described.

[0101] FIG. 15 is a diagram showing an example of the occurrence timing of a predetermined event. As described above, examples of the predetermined event whose occurrence timing can be controlled by the first communication device 50 include, for example, when the first communication device 50 normally receives data transmitted by the second communication device 20, the first communication device 50 does not transmit a notification to the second communication device 20 that it has been normally received within a predetermined time, or an event in which the first communication device 50 reconnects to the session again, etc.

[0102] FIG. 15A changes the time interval (interval) between the occurrence times of predetermined events according to the elapsed time after the communication between the first communication device 50 and the second communication device 20 is established. Specifically, the first communication device 50 can repeat one or more (it may be only once or two or more times) cycles of generating a predetermined event at a point in time when the interval of occurrence of the predetermined event becomes longer according to the elapsed time after the communication with the second communication device 20 is established. For example, the first communication device 50 can repeat one or more cycles of generating a predetermined event at a point in time when the interval of occurrence of the predetermined event becomes longer according to the elapsed time after the communication with the second communication device 20 is established.

[0103] As shown in FIG. 15A, assume that a predetermined event is generated three times in one cycle. In the first cycle, the interval between the communication establishment time and the occurrence time of the first predetermined event is Δt1, the interval between the occurrence time of the first predetermined event and the occurrence time of the second predetermined event is Δt2, and the interval between the occurrence time of the second predetermined event and the occurrence time of the third predetermined event is Δt3. Then, it is set that Δt1 < Δt2 < Δt3. As time passes, the intervals Δt1, Δt2, and Δt3 become longer. The same applies to the second cycle and subsequent cycles.

[0104] Since the transmission interval becomes shorter from Δt3 to Δt1 at the time when the cycle changes, the possibility that the attacker detects a predetermined event at the timing when the attacker is trying to hack and obtain information in the system illegally becomes low, making it difficult to hack and suppressing information leakage.

[0105] As shown in FIG. 15B, a predetermined event can be generated when the amount of data communicated after communication is established between the first communication device 50 and the second communication device 20 reaches a predetermined value. One or more (it may be only once or two or more times) cycles of generating a predetermined event can be repeated when the amount of data reaches predetermined values D1, D2, and D3. For example, the first communication device 50 can repeat one or more cycles of generating a predetermined event when the amount of data communicated after communication establishment with the second communication device 20 exceeds a predetermined amount. The predetermined values D1, D2, and D3 can be set as appropriate. Note that the timing for generating the predetermined event is not limited to the example in FIG. 15, and several methods can be combined.

[0106] In addition, the first communication device 50 can be set as the timing for generating a predetermined event when the VPN connection time exceeds the pre-set connection time, or when, despite the VPN connection not being terminated, the anonymized communication has not started for a longer time than the pre-set time. Regarding the above-mentioned "beforehand", when a VPN communication user or a VPN communication supervisor performs an action before the start of VPN communication, or when the VPN communication user or the VPN communication supervisor has set default values for these values, it is designed and developed to adopt a smaller numerical value in comparison with the pre-set previous values before VPN communication.

[0107] Next, a method for sharing secret information will be described.

[0108] FIG. 16 is a diagram showing a first example of a method for sharing secret information. In the first example of FIG. 16, it is assumed that the first communication device 50 holds secret information S in advance. When the first communication device 50 generates and holds the secret information S by itself, the first communication device 50 becomes the VPN primary. The first communication device 50 has a limited communication area (for example, within the communication range of Wi-Fi (registered trademark), Bluetooth (registered trademark), or local 5G, or within the range where a wired connection connector exists). In the example of FIG. 16A, the second communication device 20 exists outside the limited communication area (hereinafter also referred to as the "communication area").

[0109] As shown in FIG. 16B, when the second communication device 20 enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the second communication device 20. By holding the secret information S, the second communication device 20 can share the secret information S with the first communication device 50. The "communication area" is an area where the wireless connection or wired connection of the first communication device 50 (VPN primary) is physically blocked or monitored, and the entry or access of people to the area is restricted. For example, a gate system that allows only limited or permitted people (collectively also referred to as "authorized people") to enter, or a security guard's monitoring can make a specific area a high-security area (restricted area). As a result, only authorized people can enter the communication area, so the secret information is distributed only to the second communication device 20 carried or owned by the authorized people. In other words, the secret information S is not distributed from the first communication device 50 unless the second communication device 20 is a communication device carried or owned by an authorized person and the authorized person enters the communication area. Also, an employee ID card or the like may be used as information for determining whether entry or access to the communication area is permitted. This means that it is not only difficult for an attacker to know where the secret information S is distributed, but also difficult to enter this place. That is, it means that the attacker cannot obtain the secret information S unless they clear geographical and physical conditions (in the case of Wi-Fi wireless, the SSID and password).

[0110] FIG. 17 is a diagram showing a second example of a method for sharing secret information. In the second example of FIG. 17, it is assumed that the first communication device 50 holds secret information S in advance. The second communication device 20 has a limited communication area. In the example of FIG. 17A, the first communication device 50 exists outside the limited communication area (hereinafter, also referred to as the "communication area").

[0111] As shown in FIG. 17B, when the first communication device 50 enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the second communication device 20. By holding the secret information S, the second communication device 20 can share the secret information S with the first communication device 50. The "communication area" is the same as in the first example. In the case of the second example, since only authorized people can enter the communication area, the secret information is not distributed to the second communication device 20 unless the first communication device 50 carried or owned by the authorized person enters the communication area. In other words, the secret information S is not distributed to the second communication device 20 unless the first communication device 50 is a communication device carried or owned by an authorized person and the authorized person enters the communication area.

[0112] As described above, the first communication device 50 holds secret information. When the first communication device 50 and the second communication device 20 are within the limited communication area of the first communication device 50 or the second communication device 20, the first communication device 50 can transmit the secret information to the second communication device 20 and share the secret information between the first communication device 50 and the second communication device 20.

[0113] With the above configuration, both communication devices, i.e., the first communication device 50 and the second communication device 20, can share the secret information required for 1:1 VPN communication only when they are present or have been present within the limited communication area of the first communication device 50 or the second communication device 20. Thereby, communication based on the conventional 1:many connection can be excluded. Generally, in 1:many connection communication, in order to realize the many connection, the connection is permitted on the premise that the authentication information (ID and password) is correct. However, if this authentication information leaks, an attacker can easily intrude into the network, and it is easy for such an intrusion to go unnoticed for some time. As a result, security incidents such as being vulnerable to significant ransomware damage tend to occur. However, in the present embodiment, in addition to permitting only 1:1 VPN communication between communication devices that possess, own, and hold the same secret information, since the transfer of the secret information as described above is executed, it is extremely difficult for a hacker who cannot know where to go and from which device to obtain the secret information to directly obtain the secret information. Therefore, it is not necessary to introduce additional security solutions such as unauthorized intrusion detection and unauthorized intrusion prevention.

[0114] FIG. 18 is a diagram showing a third example of a method for sharing secret information. In the third example of FIG. 18, it is assumed that the first communication device 50 holds secret information S in advance. The first communication device 50 has a limited communication area. The IC card is a portable medium such as a contact-type IC card or a non-contact-type IC card. Note that instead of the IC card, a device such as a smartphone, a tablet terminal, or a mobile terminal may be used. As shown in FIG. 18A, when the IC card (contact or non-contact) completes a wired connection via R / W or enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the IC card. The IC card holds the secret information S.

[0115] As shown in Fig. 18B, by connecting an IC card storing secret information S to the second communication device 20 through wired communication or wireless communication, the second communication device 20 acquires and stores the secret information from the IC card. In this way, the secret information may be shared between the first communication device 50 and the second communication device 20 via a medium or device such as an IC card. Since the secret information can be transferred via a medium such as an IC card, even for a device with a size or weight that makes it difficult to carry the second communication device 20, the secret information can be shared between the first communication device 50 and the second communication device 20. The "communication area" is the same as in the first example. In the case of the third example, since only authorized persons can enter the communication area, the secret information is not distributed to the second communication device 20 via the IC card unless the IC card carried or owned by the authorized person enters the communication area. In other words, the secret information S is not distributed to the second communication device 20 unless the IC card is carried or owned by an authorized person and the authorized person enters the communication area.

[0116] Although not shown in the figure, the first communication device 50 installed in an area with restricted access may display a type of two-dimensional code storing secret information on the display unit 54, and the second communication device 20 brought into the area with restricted access by an authorized person may read the displayed two-dimensional code and store the secret information. Thereby, the secret information can be shared between the first communication device 50 and the second communication device 20 only when the condition that the second communication device 20 carried or owned by the authorized person is brought into the area and the second communication device 20 approaches the first communication device 50 is satisfied.

[0117] In addition, the first communication device 50 holds the identifier of the second communication device 20 that has shared the secret information. The identifier may be, for example, the device manufacturing number, MAC address, IMEI (terminal identification number of a mobile phone), serial number, or an email address, employee number, or My Number (Social Security number in the United States) associated with the serial number of the second communication device 20. When the first communication device 50 updates the secret information, it may send or deliver as mail a two-dimensional code in which the updated secret information is held to the second communication device 20 that holds the identifier. Thereby, once the first communication device 50 and the second communication device 20 have properly shared the secret information, even when the secret information is updated, the user of the second communication device 20 can share the secret information based on the identifier without having to go to the limited communication area of the first communication device 50, thus improving convenience. On the other hand, it is also a fact that the security strength decreases, so a method of encrypting part or all of the generated secret information with a common key generated from the identifier may be adopted when generating the two-dimensional code. By implementing such an implementation, the security strength can be increased to some extent.

[0118] FIG. 19 is a diagram showing another example of a limited communication area. As shown in FIG. 19, communication areas limited to regions A, B, and C are provided respectively. In region A, the first communication device 50 is installed, and the first communication device 50 holds the secret information S. In each of regions B and C, a relay device is installed, and the relay device holds the secret information S distributed from the first communication device 50. The relay device has a function of transmitting the secret information to the second communication device 20 in the same manner as the first communication device 50. Regions A to B are, for example, the locations of business offices of an operator (company), and may be different prefectures, municipalities, or countries, but are not limited thereto.

[0119] As described above, by providing a plurality of communication areas, a user who possesses a medium such as the second communication device 20 or an IC card can bring the medium such as the second communication device 20 or the IC card into the limited communication area of the first communication device 50 or the relay device in a convenient area among Areas A to C, thereby sharing the secret information S for 1:1 VPN communication and improving the convenience for the user.

[0120] FIG. 20 is a diagram showing a fourth example of a method for sharing secret information. In the fourth example of FIG. 20, it is assumed that the first communication device 50 holds the secret information S in advance. The first communication device 50 has a limited communication area. As shown in FIG. 20A, when the second communication device 20 enters the communication area, the first communication device 50 transmits (outputs) the secret information S to the second communication device 20. The second communication device 20 holds the secret information S and can share the secret information between the first communication device 50 and the second communication device 20.

[0121] Next, as shown in FIG. 20B, the second communication device 20 has a limited communication area. When the third communication device 43 enters the communication area, the second communication device 20 transmits (outputs) the secret information S to the third communication device 43. The third communication device 43 holds the secret information S.

[0122] As described above, the second communication device 20 holds the secret information. When the third communication device 43 and the second communication device 20 are present within the limited communication area of the third communication device 43 or the second communication device 20, the second communication device 20 transmits the secret information to the third communication device 43, and the secret information can be shared between the second communication device 20 and the third communication device 43.

[0123] As a result, the first communication device 50 can share secret information with the second communication device 20 and can also share secret information with the third communication device 43. That is, 1:1 VPN communication can be performed between the first communication device 50 and the second communication device 20, and 1:1 VPN communication can be performed between the first communication device 50 and the third communication device 43. At this time, it is important to implement the 1:1 VPN communication so that it cannot be performed between the second communication device 20 and the third communication device 43. This secret information is generated by the first communication device which is the VPN primary. The 1:1 VPN communication in the present invention means VPN communication between the VPN primary and the VPN client. That is, the VPN primary is a terminal (communication device) that can generate / generates secret information. However, in an organization that performs management in one place, a mechanism for identifying the terminal that becomes the VPN primary when distributing secret information to the terminal may be introduced. For example, there are methods such as having the VPN primary terminal hold a special identifier in a predetermined place, or processing and holding the primary identifier and the terminal identifier in the secret information itself.

[0124] FIG. 21 is a diagram showing a fifth example of a method for sharing secret information. In the fifth example of FIG. 21, the first communication device 50 has previously generated and held secret information P. That is, the first communication device 50 is the VPN primary that generates the secret information P. The first communication device 50 has a limited communication area. As shown in FIG. 21A, when the second communication device 20 which is a VPN client enters the communication area, the first communication device 50 transmits (outputs) the secret information P to the second communication device 20. The second communication device 20 holds the secret information P and can share the secret information P with the first communication device 50.

[0125] As described above, in one aspect, the second communication device 20 becomes a VPN client, but in another aspect, it may also become a VPN primary. That is, as shown in FIG. 21B, the second communication device 20 has previously generated and holds secret information T. The secret information T is different from the secret information P. That is, the second communication device 20 is also a VPN primary that generates the secret information T. The second communication device 20 has a limited communication area. As shown in FIG. 21B, when the fourth communication device 44, which is a VPN client, enters the communication area, the second communication device 20 transmits (outputs) the secret information T to the fourth communication device 44. The fourth communication device 44 holds the secret information T and can share the secret information T between the second communication device 20 and the fourth communication device 44.

[0126] The case shown in FIG. 21 is used, for example, for telework between a company and a home. The GW (gateway device) installed at home corresponds to the second communication device 20 shown in FIG. 21A, and this GW device is also equipped with a function to generate secret information. For example, when various IoT devices in a smart home are securely controlled by the GW device, the GW device installed in the home generates secret information and distributes the secret information to the smartphones of the people living in the smart home. The GW device installed in the home becomes a VPN client in the VPN communication with the company and becomes a VPN primary in the VPN communication with the smartphones of family members.

[0127] As described above, the second communication device 20 generates and holds secret information. When the second communication device and another communication device different from the first communication device are present within the limited communication area of the second communication device or another communication device, the second communication device transmits the secret information generated and held by it to the other communication device, and the secret information can be shared between the second communication device and the other second communication device.

[0128] FIG. 22 is a diagram showing a sixth example of a method for sharing secret information. In the sixth example of FIG. 22, a method for sharing secret information by a private blockchain 100 is shown. A blockchain is a distributed system using a P2P network, and nodes (computers) on the P2P network share the same data (ledger). A blockchain is a technology for sharing and managing a ledger in a distributed manner. The administrator terminal 150, participant terminals 121, 122, and 123 shown in FIG. 22 can constitute nodes. The administrator terminal 150, participant terminals 121, 122, and 123 may be a PC, or may be a smartphone or a tablet terminal or the like.

[0129] In addition to the aforementioned ledger (also referred to as a "distributed ledger" or "block"), the private blockchain 100 includes technical elements such as encryption and smart contracts. Encryption ensures the validity and confidentiality of transactions (transactions), for example, by an electronic signature function and an authentication function. A smart contract holds the execution code and variables of a program deployed on the private blockchain 100 and is held in the block held by each node.

[0130] Each block of the private blockchain 100 includes information such as the hash value of the previous block, transaction data, state data, and nonce. A hash value is a fixed-length value obtained by a predetermined operation from the original input data, and the information included in the previous block is used as the input data for the operation. In the present embodiment, the transaction data includes secret information. The state data includes information such as the identification code (ID) of the participants managed within the private blockchain 100, authentication information and access rights required for participation. The state data includes smart contracts (program codes, etc.) for all participants. The nonce is a value used to calculate a hash value based on the information in the current block when adding the next block. When the value of the nonce is determined, the current block is hashed, and the hash value is held in the next block.

[0131] The private blockchain 100 is a type of blockchain technology and, unlike public blockchains, has the following characteristics. That is, the private blockchain 100 is operated by a limited number of participants and is constructed in a private environment. Participants in the private blockchain 100 are usually composed of members of a limited organization, but even if they are not members of the organization, they can participate as members if permitted by the administrator. Also, access control is implemented for the participating members. That is, participants in the private blockchain 100 cannot participate in the network without obtaining specific approval.

[0132] In this embodiment, the secret information is shared (distributed) by taking advantage of the characteristics of this private blockchain 100 (being difficult to be attacked by third-party hackers). Assume that the administrator uses the administrator terminal device 150, and the participants P1, P2, and P3 use the participant terminal devices 121, 122, and 123, respectively. Hereinafter, the method of sharing the secret information will be described in order. (1) The administrator checks and then registers as a participant in the private blockchain 100 a person who is permitted for 1:1 VPN communication. In this embodiment, the administrator is the person who manages the communication device that serves as the VPN primary. Note that one administrator may manage multiple communication devices that serve as VPN primaries. For example, if the first communication device 50 is a gateway device and is installed in a certain department of a certain company, the administrator of this gateway device will be the person responsible for IT management of the department. This administrator will grant permission to participate in the private blockchain 100 and access rights to employees who are allowed to use VPN communication in the department. (2) After granting permission to participate and access rights, for each participant, the administrator generates secret information for each participant using the VPN primary (for example, the first communication device 50), and writes the generated secret information to the private blockchain 100 as transaction data. (3) After participants have passed the authentication of the private blockchain 100, they download their own confidential information. Here, the mechanism that prevents other participants from downloading their confidential information may be implemented through their own access management to the private blockchain 100, or a common key may be issued for each participant. If you do not want to newly issue a common key, you can generate a common key using the participant's identification code and part or all of the authentication information required when participating in the private blockchain 100, encrypt the confidential information with the generated common key, and write it as transaction data to the private blockchain 100. In this way, only the participant can decrypt their own confidential information.

[0133] In the example of FIG. 22, the confidential information Sp1 encrypted with the common key Kp1 for the participant P1 is written as transaction data to the block, the confidential information Sp2 encrypted with the common key Kp2 for the participant P2 is written as transaction data to the block, and the confidential information Sp3 encrypted with the common key Kp3 for the participant P3 is written as transaction data to the block. The participant Sp1 can decrypt the confidential information Sp1 using the common key Kp1 held by himself / herself, but other participants cannot obtain the confidential information Sp1 because they do not have the common key Kp1. The same applies to other participants P2 and P3.

[0134] In the above example, employees of a certain department are mentioned, but it is not limited to this. For example, it may be an organization such as a neighborhood association in a certain area. With such an implementation, confidential information can be distributed only to those recognized as correct by the administrator.

[0135] Since the administrator can write different secret information from the previously written secret information to the private blockchain 100 as new transaction data, participants can easily receive the latest version of the secret information. Also, by preparing and registering a smart contract that operates when an event occurs that a participant has received the secret information, it is possible to operate in such a way that the administrator can know that the participant has received the secret information at the timing when the participant has received the secret information.

[0136] Next, a method for generating secret information will be described.

[0137] FIG. 23 is a diagram showing an example of a method for generating secret information. FIG. 23A shows a case where the first communication device 50 holds unique information. The unique information can be, for example, an identifier of the first communication device 50 (e.g., serial number, etc.), employee number, company identifier, location identifier, a predetermined random number, etc., but is not limited thereto. The first communication device 50 holds unique information (S101) and generates secret information using the unique information (S102). Generation of the secret information may be information obtained as a result of performing an operation on the unique information by a predetermined algorithm. The first communication device 50 transmits the generated secret information to the second communication device 20 (S103) by the method exemplified in FIGS. 16 to 20, etc., and the secret information can be shared.

[0138] FIG. 23B shows a case where the second communication device 20 holds unique information. The unique information can be, for example, an identifier of the second communication device 20 (e.g., serial number, etc.), employee number, company identifier, location identifier, a predetermined random number, etc., but is not limited thereto. The second communication device 20 holds unique information (S111), and the first communication device 50 acquires the unique information from the second communication device 20 (S112). The first communication device 50 generates secret information using the unique information (S113). The first communication device 50 transmits the generated secret information to the second communication device 20 (S114) by the method exemplified in FIGS. 16 to 20, etc., and the secret information can be shared.

[0139] Figure 23C shows a case where no unique information is held. The first communication device 50 generates unique information (S121) and generates secret information using the unique information (S122). The generation of the secret information may be information obtained as a result of performing an operation on the unique information using a predetermined algorithm. The first communication device 50 transmits the generated secret information to the second communication device 20 (S123) by the method illustrated in FIGS. 16 to 20 and the like, and the secret information can be shared.

[0140] As described above, the first communication device 50 can hold first unique information regarding the first communication device 50, or acquire second unique information regarding the second communication device 20 from the second communication device 20, hold it, and generate secret information using the first unique information or the acquired second unique information.

[0141] When secret information is generated using unique information such as an employee number, by holding the correspondence between the unique information and the secret information, it is possible to easily identify who owns the secret information. This can solve the security problem caused by the inability to determine whose secret information it is. Also, when secret information is generated using unique information such as a company identifier, the secret information can be classified by company or organization, so a mechanism for realizing 1:1 VPN communication for many companies and organizations can be constructed.

[0142] By using the mechanism, which is one of the features of this embodiment, of holding the same secret information and allowing 1:1 VPN communication only between VPN primary VPN clients, a data diode-like usage method can also be easily realized.

[0143] For example, in the transport layer of the first communication device 50, an implementation that only allows received data and discards all transmitted data may be installed. By providing such an implementation, the second communication device 20 can transmit data to the first communication device 50, and the first communication device 50 can receive the data. On the other hand, a configuration where data does not reach the second communication device 20 from the first communication device 50 can be easily implemented. The roles of the first communication device 50 and the second communication device 20 may be changed. This can be implemented regardless of whether it is a VPN primary or not. In this example, an implementation example of a data diode via the Internet is shown, but it is also possible to install the first communication device 50 and the second communication device 20 in one housing and provide them as one system.

[0144] A specific example of the above-described data diode-like usage method will be described. Let the communication devices be A, B, and C. Also, let the secret information be A, B, and C. First, when only one-way communication from A to B (A→B) is allowed, a case may occur where communication such as C→B→A needs to be realized. For example, it is a case where A has important IoT devices under its control, and only the observation data observed by the IoT devices is transmitted from A and collected by B. Here, one-way communication is used to prevent an attack on A. In such a case, when a case occurs where a control command must be output from C to the IoT device under the control of A, the control command can be output by using the secret information of this embodiment. This will be specifically described below.

[0145] A and B hold the same secret information A. This is represented as A(A), B(A). () indicates the secret information. As described above, since only one-way communication from A(A) to B(A) is allowed, data transmission from B is completely blocked, but when a certain specific condition is satisfied, data can be transmitted from B to A. Hereinafter, a certain specific condition will be described.

[0146] Party A holds confidential information A, B, and C, Party B holds confidential information A and B, and Party C holds confidential information A, B, and C. That is, C (A, B, C) → B (A, B) → A (A, B, C). Since Party B exchanges data with Party A, it holds confidential information A, and since it exchanges data with Party C, it holds confidential information B. At this time, in order to deliver the data X sent from Party C to Party A, the condition is to send from Party C to Party B the data encrypted with the common key generated from confidential information B, like (B (A (C (X)))). At Party B, when decrypting the received data with the common key generated from confidential information B, the data of (A (C (X))) can be obtained. Party B directly sends the decrypted data (A (C (X))) to Party A.

[0147] Here, normally, in the data exchange between Party A and Party B, at Party B, there is a step of encrypting the data with the common key generated from confidential information A. However, since the data (A (C (X))) received by Party B from Party C has already been encrypted with the common key generated from confidential information A, there is no need to perform this step. The fact that there is no need to perform this step is one of the features of this embodiment. In order to be able to convey to Party A that this step is omitted, for example, data can be generated by changing 4 bits of the version information in the data part of TCP / IP from "0100" to "0110" and sent to Party A. At Party A, although it has an agreement to discard all data from Party B, when decrypting the data received from Party B with the common key generated from confidential information A, not only is the decrypted data in the form of (C (X)), but also 4 bits of the version information in the data part of TCP / IP are "0110". Thus, a mechanism can be constructed to decrypt with the common key generated from confidential information C and receive the data X from Party C.

[0148] On the other hand, in the case of data reception from B instead of from C, since B encrypts the data with the common key generated from the secret information A (processing by the aforementioned omitted steps), and since it is not necessary to convey to A from B that the step is omitted, the version information is "0100" and not "0110", so A discards the data from B. Thus, by using the secret information of this embodiment, in a situation where only one-way communication from A to B is permitted, a mechanism can be constructed in which A can receive data from C through B.

[0149] As the Internet has been widely used, individuals have been able to transmit information. However, in order for individuals to transmit information, the only option was to use the platforms provided by large companies. On the other hand, as a device for accessing the Internet, smartphones have come to be used more than ever, and at the same time, such smartphones have come to have a speed and memory that exceed those of low-cost PCs several years ago. By using the technology of this embodiment, since the P2P VPN communication function can also be used, a personal smartphone can be made into something like a cloud server of an EC shopping site. That is, it becomes unnecessary to use the platforms provided by large companies, and it also becomes unnecessary to use expensive devices such as cloud servers compared to smartphones, so the operation cost can be reduced. Also, as long as one has a smartphone, one can operate at high security and low cost as if operating an EC site on a cloud server wherever one moves and even while moving. Although Web3 touts non-centralized elements, by using the present invention, since it is not necessary to rely on the power of platforms that incorporate centralized elements, Web3-like services can be provided to both users and service providers.

[0150] As described above, the first communication device 50 can perform P2P VPN communication with the second communication device 20. In P2P VPN communication, a virtual private network that operates like a physical network, that is, an Internet VPN (Virtual Private Network), is constructed between the first communication device 50 and the second communication device 20, and the first communication device 50 and the second communication device 20 can perform P2P communication via the Internet using private IP addresses managed by a communication network management server (not shown).

[0151] In this embodiment, the first communication device 50 and the second communication device 20 perform VPN communication between private IP addresses without using global IP addresses and perform P2P communication, thereby further improving security. As a result, a smartphone whose global IP address changes each time the base station changes can be used as a cloud server (Web server).

[0152] (Appendix 1) The communication method is a communication method between a first communication device and a second communication device. When the second communication device is in a communication state with the first communication device and a predetermined event occurs in which the second communication device needs to retransmit data to the first communication device, the first communication device stops communication with the second communication device according to the retransmission data transmitted by the second communication device.

[0153] (Appendix 2) In Appendix 1, the predetermined event includes an event in which the first communication device cannot receive a notification indicating normal reception within a predetermined time when the first communication device normally receives the data transmitted by the second communication device.

[0154] (Appendix 3) In Appendix 1 or Appendix 2, the predetermined event includes an event in which the first communication device reconnects to the session.

[0155] (Appendix 4) In any one of Appendices 1 to 3, the communication method is such that the predetermined event includes any one of an event of timeout, restart, and IP address change (such as a case where the IP address changes when the base station to which the mobile terminal is connected changes as a result of the mobile terminal moving) detected by the second communication device or the first communication device.

[0156] (Appendix 5) In any one of Appendices 1 to 4, the communication method repeats one or more cycles of generating the predetermined event when the elapsed time of the communication state between the first communication device and the second communication device becomes longer than a predetermined time.

[0157] (Appendix 6) In any one of Appendices 1 to 5, the communication method repeats one or more cycles of generating the predetermined event when the amount of data communicated between the first communication device and the second communication device becomes more than a predetermined amount.

[0158] (Appendix 7) In any one of Appendices 1 to 6, the communication method is such that the first communication device stops communication with the second communication device when the second communication device transmits retransmission data having at least the same data part.

[0159] (Appendix 8) In any one of Appendices 1 to 7, the communication method is such that the first communication device stops communication with the second communication device when the second communication device retransmits data encrypted using the same key information as the key information used for encrypting the data transmitted to the first communication device.

[0160] (Appendix 9) In any one of Appendices 1 to 8, the communication method is such that the first communication device generates different key information at a required frequency based on secret information, and stops communication with the second communication device when the second communication device does not retransmit data encrypted using key information older than the key information used between the first communication device and the second communication device.

[0161] (Appendix 10) In any one of Appendices 1 to 9, for the communication method, the first communication device and the second communication device hold a common secret information in advance. When the first communication device determines that the second communication device does not retransmit the data encrypted using the key information generated based on the secret information, the first communication device stops the communication with the second communication device.

[0162] (Appendix 11) In any one of Appendices 1 to 10, for the communication method, the first communication device generates a plurality of distributed information from the secret information, generates a plurality of key information based on each of the generated distributed information. When the second communication device does not retransmit the data encrypted using the predetermined key information among the plurality of generated key information, the first communication device stops the communication with the second communication device.

[0163] (Appendix 12) In any one of Appendices 1 to 11, for the communication method, the first communication device holds the secret information. When the second communication device holds the same secret information as the secret information, the first communication device allows the communication with the second communication device.

[0164] (Appendix 13) In any one of Appendices 1 to 12, for the communication method, the first communication device holds the key information generated in the first communication device based on the secret information. The first communication device allows the communication with the second communication device only when the second communication device holds the same key information as the key information generated in the second communication device based on the same secret information.

[0165] (Appendix 14) In any one of Appendices 1 to 13, for the communication method, the first communication device holds the secret information. When the first communication device and the second communication device are present within the limited communication area of the first communication device or the second communication device, the first communication device transmits the secret information to the second communication device and shares the secret information between the first communication device and the second communication device.

[0166] (Appendix 15) In the communication method according to Appendix 14, the first communication device holds first unique information related to the first communication device, or acquires second unique information related to the second communication device from the second communication device and holds it, and generates the secret information using at least one of the held first unique information and the acquired second unique information.

[0167] (Appendix 16) In the communication method according to Appendix 15, the first communication device acquires third unique information different from both the first unique information and the second unique information, and generates the secret information using the third unique information in addition to the first unique information and the second unique information.

[0168] (Appendix 17) In the communication method according to Appendix 14, the communication area is a specific area that only authorized personnel can enter.

[0169] (Appendix 18) In any one of Appendices 1 to 17, the first communication device holds secret information. When the first communication device and the portable recording medium are within the limited communication area of the first communication device, the first communication device transmits the secret information to the recording medium, and the second communication device receives the secret information from the recording medium outside the communication area, sharing the secret information between the first communication device and the second communication device.

[0170] (Appendix 19) In any one of Appendices 14 to 18, a plurality of communication areas are provided.

[0171] (Appendix 20) In any one of Appendices 1 to 19, one of the first communication device and the second communication device is a VPN primary, and the other is a VPN client. The VPN primary holds secret information. When the VPN primary and the VPN client are within the limited communication area of the VPN primary or the VPN client, the VPN primary transmits the secret information to the VPN client, sharing the secret information between the VPN primary and the VPN client.

[0172] (Appendix 21) In any one of Appendices 1 to 20, the communication method is such that the first communication device is installed in an area where access is restricted, displays a two-dimensional code in which secret information is held, the second communication device is brought into the area where access is restricted, reads the displayed two-dimensional code to hold the secret information, and shares the secret information between the first communication device and the second communication device.

[0173] (Appendix 22) In Appendix 21, the first communication device holds an identifier unique to the second communication device that has shared the secret information, and when updating the secret information, transmits a two-dimensional code in which the updated secret information is held to the second communication device in which the identifier is held.

[0174] (Appendix 23) In any one of Appendices 1 to 22, the first communication device, which is the administrator of the private blockchain, writes the secret information as transaction data to the private blockchain, and the second communication device of the participant registered to participate in the private blockchain acquires the secret information written to the private blockchain from the private blockchain, and shares the secret information between the first communication device and the second communication device.

[0175] (Appendix 24) In any one of Appendices 1 to 23, the first communication device or the second communication device holds the existence area of the second communication device or the first communication device in each case where communication with the other is permitted, and when the position information of the second communication device or the first communication device is within the existence area, communication is performed between the first communication device and the second communication device.

[0176] (Appendix 25) In any one of Appendices 1 to 24, the first communication device performs P2PVPN communication with the second communication device.

[0177] (Appendix 26) In any one of Appendices 1 to 25, the communication method is such that the first communication device receives the retransmission data transmitted from the transport layer of the second communication device at its own transport layer, and determines the retransmission data transmitted by the second communication device using its own transport layer.

[0178] (Appendix 27) In any one of Appendices 1 to 26, the communication method is such that the first communication device receives the retransmission data transmitted from the transport layer of the second communication device at its own transport layer, and determines the retransmission data transmitted by the second communication device using its own application layer.

[0179] (Appendix 28) In any one of Appendices 1 to 27, when the first communication device stops communication with the second communication device, it notifies an external device that unauthorized intrusion has occurred in the communication by the second communication device.

[0180] (Appendix 29) In any one of Appendices 1 to 28, before stopping communication with the second communication device, the first communication device transmits a virus or ransomware to the second communication device or another device connected to the second communication device via the second communication device in order to disable the attacker's system.

[0181] (Appendix 30) In any one of Appendices 1 to 29, the second communication device holds secret information, and when the third communication device and the second communication device are within a limited communication area of the third communication device or the second communication device, the second communication device transmits the secret information to the third communication device and shares the secret information between the second communication device and the third communication device.

[0182] (Appendix 31) In any one of Appendices 1 to 30, when the communication method is such that only one-way communication from the first communication device to the second communication device is permitted through P2PVPN communication, the first communication device encrypts data encrypted with a first shared key generated based on first secret information shared between the first communication device and another communication device with a second shared key generated based on second secret information shared between the first communication device and the second communication device, and further encrypts the data encrypted with a third shared key generated based on third secret information shared between the first communication device and the second communication device and then transmits the data to the second communication device. The second communication device decrypts the received data with the third shared key, transmits the decrypted data to the first communication device, and the first communication device decrypts the received data with the second shared key and then decrypts the decrypted data with the first shared key to be able to receive data from the other communication device.

[0183] (Appendix 32) The communication device includes a control unit. When the control unit is in a communication state with another communication device and a predetermined event occurs where the other communication device needs to retransmit data, the control unit stops communication with the other communication device according to the retransmission data transmitted by the other communication device.

[0184] (Appendix 33) The computer program is a computer program that operates on a first communication device. When the second communication device is in a communication state with the first communication device and a predetermined event occurs where the second communication device needs to retransmit data to the first communication device, the computer program causes the computer to execute a process of stopping communication with the second communication device according to the retransmission data transmitted by the second communication device.

[0185] The matters described in each embodiment can be combined with each other. Also, the independent claims and dependent claims described in the claims can be combined with each other in all possible combinations regardless of the citation form. Further, the claims use a form (multi-claim form) of describing claims that cite two or more other claims, but it is not limited thereto. A form of describing a multi-claim (multi-multi-claim) that cites at least one multi-claim may be used.

Explanation of Signs

[0186] 1 Covert communication path 20, 40 Second communication device 50 First communication device 21, 51 Control unit 22, 52 Network communication unit 23, 53 Memory 24, 54 Display unit 25, 55 Retransmission data analysis unit 26, 56 Covert communication processing unit 27, 57 Storage unit 28, 58 OS 29, 59 Secret information 30, 60 Key information

Claims

1. A communication method between a first communication device and a second communication device, wherein the first communication device when a predetermined event in which the second communication device is in a communication state with the first communication device and the second communication device needs to retransmit data to the first communication device, and the predetermined event includes an event in which the first communication device reconnects to the session, occurs in the first communication device or the second communication device, stops communicating with the second communication device according to the retransmission data transmitted by the second communication device. Communication method.

2. A communication method between a first communication device and a second communication device, when the communication between the first communication device and the second communication device is established and a predetermined event in which the second communication device needs to retransmit data to the first communication device has not occurred, each time the occurrence interval of the predetermined event becomes longer than a predetermined time according to the elapsed time after the communication establishment between the first communication device and the second communication device, repeat a cycle of generating the predetermined event a plurality of times. Communication method.

3. A communication method between a first communication device and a second communication device, when the communication between the first communication device and the second communication device is established and a predetermined event in which the second communication device needs to retransmit data to the first communication device has not occurred, each time the amount of data communicated between the first communication device and the second communication device becomes more than a predetermined amount, repeat a cycle of generating the predetermined event a plurality of times. Communication method.

4. The predetermined event includes an event in which, when the first communication device normally receives the data transmitted by the second communication device, a notification indicating normal reception cannot be received from the first communication device within a predetermined time. The communication method according to any one of Claims 1 to 3.

5. The predetermined event includes any one of an event of timeout, restart, and IP address change detected by the second communication device or the first communication device. The communication method according to any one of Claims 1 to 3.

6. The first communication device when the second communication device retransmits data encrypted using the same key information as the key information used for encrypting the data transmitted to the first communication device, stops communicating with the second communication device. The communication method according to Claim 1.

7. The first communication device generates different key information at required frequencies based on secret information, When the second communication device does not retransmit data encrypted using key information older than the key information used between the second communication device and the first communication device, communication with the second communication device is stopped. The communication method according to claim 1.

8. The first communication device and the second communication device hold common secret information in advance, The first communication device When the second communication device does not retransmit data encrypted using key information generated based on the secret information, communication with the second communication device is stopped. The communication method according to claim 1.

9. The first communication device generates a plurality of pieces of distributed information from the secret information, generates a plurality of pieces of key information based on each of the generated pieces of distributed information, When the second communication device does not retransmit data encrypted using predetermined key information among the plurality of generated key information, communication with the second communication device is stopped. The communication method according to claim 1.

10. The first communication device holds secret information, When the second communication device holds the same secret information as the secret information, communication between the first communication device and the second communication device is permitted. The communication method according to any one of claims 1, 6 to 9.

11. The first communication device holds key information generated within the first communication device based on secret information, Communication between the first communication device and the second communication device is permitted only when the second communication device holds the same key information as the key information generated within the second communication device based on the same secret information as the secret information. The communication method according to any one of claims 1, 6 to 9.

12. The first communication device holds secret information, When the first communication device and the second communication device are present within a limited communication area of the first communication device or the second communication device, the secret information is transmitted to the second communication device, The secret information is shared between the first communication device and the second communication device. The communication method according to any one of claims 1, 6 to 9.

13. The first communication device holds first unique information related to the first communication device, or acquires second unique information related to the second communication device from the second communication device, generates the secret information using at least one of the held first unique information and the acquired second unique information. The communication method according to claim 12.

14. The first communication device Obtain third unique information different from both the first unique information and the second unique information, Generate the secret information using the third unique information in addition to the first unique information and the second unique information, The communication method according to claim 13.

15. The communication area is a specific area where only authorized persons can enter. The communication method according to claim 12.

16. The first communication device holds secret information, When the first communication device and the portable recording medium are within the limited communication area of the first communication device, transmit the secret information to the recording medium, The second communication device, Receive the secret information from the recording medium outside the communication area, Share the secret information between the first communication device and the second communication device, The communication method according to any one of claims 1, 6 to 9.

17. Provide a plurality of the communication areas, The communication method according to claim 12.

18. One of the first communication device and the second communication device is a VPN primary, and the other is a VPN client, The VPN primary holds secret information, When the VPN primary and the VPN client are within the limited communication area of the VPN primary or the VPN client, transmit the secret information to the VPN client, Share the secret information between the VPN primary and the VPN client, The communication method according to any one of claims 1, 6 to 9.

19. The first communication device, Is installed in an area with restricted access and displays a two-dimensional code holding secret information, The second communication device, Is brought into the area with restricted access, reads the displayed two-dimensional code, and holds the secret information, Share the secret information between the first communication device and the second communication device, The communication method according to any one of claims 1, 6 to 9.

20. The first communication device, Holds an identifier unique to the second communication device that has shared the secret information, When updating the secret information, transmit a two-dimensional code holding the updated secret information to the second communication device holding the identifier, The communication method according to claim 19.

21. The first communication device, which is the administrator of the private blockchain, Write the secret information as transaction data to the private blockchain, The second communication device of the participant whose participation in the private blockchain is registered, obtains the secret information written in the private blockchain from the private blockchain, and shares the secret information between the first communication device and the second communication device. The communication method according to any one of claims 1 and 6 to 9.

22. holds the presence area of the second communication device or the first communication device in each case where communication with the first communication device or the second communication device is permitted, when the location information of the second communication device or the first communication device is within the presence area, communication is performed between the first communication device and the second communication device. The communication method according to any one of claims 1 and 6 to 9.

23. The first communication device performs P2P VPN communication with the second communication device. The communication method according to any one of claims 1 and 6 to 9.

24. The first communication device receives retransmission data transmitted from the transport layer of the second communication device at its own transport layer, and determines the retransmission data transmitted by the second communication device using its own transport layer. The communication method according to any one of claims 1 and 6 to 9.

25. The first communication device receives retransmission data transmitted from the transport layer of the second communication device at its own transport layer, and determines the retransmission data transmitted by the second communication device using its own application layer. The communication method according to any one of claims 1 and 6 to 9.

26. The first communication device when stopping communication with the second communication device, notifies an external device that unauthorized intrusion has occurred in the communication by the second communication device. The communication method according to any one of claims 1 and 6 to 9.

27. The first communication device before stopping communication with the second communication device, transmits a virus or ransomware to the second communication device or another device connected to the second communication device via the second communication device to disable the attacker's system. The communication method according to any one of claims 1 and 6 to 9.

28. The second communication device holds secret information, and when the third communication device and the second communication device are present within the limited communication area of the third communication device or the second communication device, the second communication device transmits the secret information to the third communication device. Sharing the secret information between the second communication device and the third communication device The communication method according to any one of claims 1 and 6 to 9

29. In a state where the first communication device allows only one-way communication to the second communication device through P2P VPN communication When the data encrypted with the first shared key generated based on the first secret information shared between another communication device and the first communication device is encrypted with the second shared key generated based on the second secret information shared between the first communication device and the second communication device, and further encrypted with the third shared key generated based on the third secret information shared between the second communication device and the first communication device, and the encrypted data is transmitted to the second communication device The second communication device Decrypts the received data with the third shared key, transmits the decrypted data to the first communication device The first communication device Receives the received data by decrypting it with the second shared key and decrypting the decrypted data with the first shared key, enabling the reception of data from the other communication device The communication method according to any one of claims 1 and 6 to 9

30. Comprising a control unit The control unit When in a communication state with another communication device, and a predetermined event in which the other communication device needs to retransmit data, including an event of reconnecting a session, occurs in the other communication device or the communication device of the control unit itself, stops the communication with the other communication device according to the retransmission data transmitted by the other communication device Communication device

31. Comprising a control unit The control unit When the communication with another communication device is established and a predetermined event in which the other communication device needs to retransmit data has not occurred, repeatedly executes a cycle of generating the predetermined event each time the occurrence interval of the predetermined event becomes longer than a predetermined time according to the elapsed time after the establishment of communication with the other communication device Communication device

32. Comprising a control unit The control unit When the communication with another communication device is established and a predetermined event in which the other communication device needs to retransmit data has not occurred, repeatedly executes a cycle of generating the predetermined event each time the amount of data communicated with the other communication device exceeds a predetermined amount Communication device

33. A computer program operating on a first communication device When the second communication device is in a communication state with the first communication device and a predetermined event that requires the second communication device to retransmit data to the first communication device, including the event that the first communication device reconnects to the session, occurs, the communication with the second communication device is stopped according to the retransmission data transmitted by the second communication device. A computer program that causes a computer to execute a process.

34. A computer program that operates on a first communication device, When the communication between the first communication device and the second communication device is established and a predetermined event that requires the second communication device to retransmit data to the first communication device has not occurred, each time the occurrence interval of the predetermined event becomes longer than a predetermined time according to the elapsed time after the communication establishment between the first communication device and the second communication device, a cycle of generating the predetermined event is repeated a plurality of times. A computer program that causes a computer to execute a process.

35. A computer program that operates on a first communication device, When the communication between the first communication device and the second communication device is established and a predetermined event that requires the second communication device to retransmit data to the first communication device has not occurred, each time the amount of data communicated between the first communication device and the second communication device becomes more than a predetermined amount, a cycle of generating the predetermined event is repeated a plurality of times. A computer program that causes a computer to execute a process.

Citation Information

Patent Citations

  • Program and information processing device

    JP2023053359A