Communication control system and communication control management device

The communication control system efficiently adapts to new encryption methods by using IC cards for secure key management, ensuring secure data transmission without hardware modifications, addressing the challenge of updating relay devices in existing systems.

JP2025126955APending Publication Date: 2025-09-01KK TOSHIBA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024023359
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-20
Publication Date
2025-09-01

AI Technical Summary

Technical Problem

Existing communication systems face challenges in adapting to new encryption methods, particularly when relay devices do not support Post-Quantum Cryptography, necessitating costly and time-consuming on-site updates or replacements.

Method used

A communication control system with first and second communication control devices and a management device that facilitates the seamless integration of new encryption methods by transmitting necessary information at predetermined timings, utilizing IC cards for secure key and certificate management without hardware modifications.

Benefits of technology

Enables secure and efficient transition to new encryption methods by managing encryption updates remotely, enhancing security without requiring hardware changes or replacements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025126955000001_ABST
    Figure 2025126955000001_ABST
Patent Text Reader

Abstract

To easily adapt a relay device to a new encryption method when the relay device capable of performing encryption and decryption is installed in a device that transmits and receives data via a network communication network.SOLUTION: A communication control system according to an embodiment includes: a first communication control device connected between a client device and a network communication network; a second communication control device connected between a server device and the network communication network; and a communication control management device connected to the first communication control device via the network communication network. The first communication control device stores encryption information used for a mutual authentication processing performed with the second communication control device and a transmission and reception processing of transmitting and receiving information by encryption between the client device and the server device. When it is necessary to set new encryption method information corresponding to a new encryption method in the first communication control device, the communication control management device transmits the new encryption method information to the first communication control device at a predetermined timing.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] An embodiment of the present invention relates to a communication control system and a communication control management device. [Background technology]

[0002] When data is transmitted and received between two devices (computer devices) via a communication network, the data is encrypted using, for example, a key (information) to protect the data from unauthorized access.

[0003] There are various encryption methods, and they are used depending on the situation and purpose, such as the processing speed of the equipment, the level of security, etc. However, there is a possibility that at least some of the encryption methods currently in use will be decrypted with the advent of quantum computers, and new encryption methods are being considered as a solution.

[0004] Specifically, in recent years, research, development, and practical application of PQC (Post-Quantum Cryptography), a new cryptographic method that can maintain security even when sufficiently large quantum computers are put into practical use, has been progressing.

[0005] However, while switching to a new encryption method can sometimes be easy depending on the situation, there are also cases where the change is not possible due to software or hardware constraints on the device, or where the device has a long life cycle and immediate change is practically difficult.

[0006] Furthermore, even if existing encryption methods are currently secure, there are attacks such as the HNDL (Harvest Now, Decrypt Later) attack, which involves collecting data encrypted by existing encryption methods and decrypting it in the future when an environment becomes available for decryption. Therefore, it is desirable to support new encryption methods as early as possible.

[0007] There is also a technology that installs relay devices that can encrypt and decrypt data between devices and the network. This technology enables high information security through encrypted communications without requiring any changes to the devices. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] Patent No. 6644037 [Patent Document 2] Patent No. 7042853 Summary of the Invention [Problem to be solved by the invention]

[0009] However, with the above-mentioned technology, when a relay device that does not support the new encryption method is to be made compatible with the new encryption method, the only methods available are for an operator to connect a PC (Personal Computer) to each relay device on-site and perform an update process to make it compatible with the new encryption method, or to replace the relay device with another relay device that does support the new encryption method, which poses problems in terms of time and cost.

[0010] Therefore, the present invention has been made in consideration of the above circumstances, and aims to provide a communication control system and a communication control management device that can easily adapt to a new encryption method when a relay device capable of performing encryption and decryption is installed on equipment that sends and receives data via a network communication network. [Means for solving the problem]

[0011] A communication control system according to an embodiment includes a first communication control device connected between a client device and a network communication network, a second communication control device connected between a server device and the network communication network, and a communication control management device connected to the first communication control device via the network communication network. The first communication control device stores encryption information used in a mutual authentication process with the second communication control device and a transmission / reception process for transmitting and receiving encrypted information between the client device and the server device. When it becomes necessary to set new encryption method information corresponding to a new encryption method in the first communication control device, the communication control management device transmits the new encryption method information to the first communication control device at a predetermined timing to cause the first communication control device to set the new encryption method. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of a communication control system according to an embodiment. [Figure 2] FIG. 2 is a block diagram illustrating an example of the functional configuration of the client device and the server device according to the embodiment. [Figure 3] FIG. 3 is a block diagram illustrating an example of the functional configuration of the client-side communication control device and the server-side communication control device according to the embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of a hardware configuration of an IC card according to an embodiment. [Figure 5] FIG. 5 is a block diagram illustrating an example of a functional configuration of the IC card according to the embodiment. [Figure 6] FIG. 6 is a block diagram illustrating an example of a functional configuration of a communication control management device and a key management device according to the embodiment. [Figure 7] FIG. 7 is a sequence chart illustrating an example of processing performed by the communication control system according to the embodiment. [Figure 8] FIG. 8 is a flowchart illustrating an example of processing by the client-side communication control device and the communication control management device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments of a communication control system and a communication control management device of the present invention will be described with reference to the accompanying drawings.

[0014] 1 is a diagram showing an example of the configuration of a communication control system 1 according to an embodiment. The communication control system 1 includes client devices 10 (10-1 to 10-N), a server device 20, client-side communication control devices 30 (30-1 to 30-N) (an example of a "first communication control device"), a server-side communication control device 31 (an example of a "second communication control device"), a communication control management device 50, a key management device 51, a network 60, and a gateway 70. In the following description, the network 60 and the gateway 70 connecting the network 60 with the client devices 10 and the like are collectively referred to as a "network NW."

[0015] The client device 10 is connected to the network NW via a client-side communication control device 30. The server device 20 is connected to the network NW via a server-side communication control device 31. The configurations of the client device 10 and the server device 20 will be described in detail later.

[0016] The client-side communication control device 30 is connected between the client device 10 and the network NW, and mediates communication between the client device 10 and the server device 20. The client-side communication control device 30 acquires data transmitted by the client device 10 to the server device 20, and outputs the acquired data to the server device 20. When transmitting the data to the server device 20, the client-side communication control device 30 encrypts the data acquired from the client device 10 and transmits the encrypted data to the server device 20.

[0017] Furthermore, the client-side communication control device 30 acquires data transmitted to the client device 10 by the server device 20, and outputs the acquired data to the client device 10. Here, the data acquired by the client-side communication control device 30 is encrypted data. When outputting data to the client device 10, the client-side communication control device 30 decrypts the data acquired from the server device 20 via the server-side communication control device 31, and outputs the decrypted data to the client device 10.

[0018] The server-side communication control device 31 is connected between the server device 20 and the network NW, and mediates communication between the client device 10 and the server device 20. The server-side communication control device 31 acquires data transmitted by the server device 20 to the client device 10, and transmits the acquired data to the client device 10. When transmitting the data to the client device 10, the server-side communication control device 31 encrypts the data acquired from the server device 20 and transmits the encrypted data to the client device 10.

[0019] Furthermore, the server-side communication control device 31 acquires data transmitted from the client device 10 to the server device 20, and outputs the acquired data to the server device 20. Here, the data acquired by the server-side communication control device 31 is encrypted data. When outputting data to the server device 20, the server-side communication control device 31 decrypts the data acquired from the client device 10 via the client-side communication control device 30, and outputs the decrypted data to the server device 20.

[0020] In this embodiment, data encryption performed by the client-side communication control device 30 and the server-side communication control device 31 is performed using, for example, the SSL (Secure Socket Layer) / TLS (Transport Layer Security) protocol. The client-side communication control device 30 and the server-side communication control device 31 combine, for example, the SSL / TLS protocol with HTTP (HyperText Transfer Protocol) to encrypt data included in HTTP and replace it with HTTPS (HTTP Secure), which has improved security.

[0021] The data encryption performed by the client-side communication control device 30 and the server-side communication control device 31 is not limited to replacing HTTP with HTTPS. The client-side communication control device 30 and the server-side communication control device 31 may replace the SSL / TLS protocol with a secure communication protocol that improves safety by combining it with various communication protocols. For example, the client-side communication control device 30 and the server-side communication control device 31 may replace FTP (File Transfer Protocol) with FTPS (FTP Secure).

[0022] In this embodiment, data encrypted by the client-side communication control device 30 or the server-side communication control device 31 is output to the network NW. In other words, in this embodiment, data flowing through the network NW is encrypted data. This prevents data transmitted and received over the network NW from being maliciously accessed from the outside and intercepted, thereby improving security. Note that intercepting data here refers to the "act of stealing data" or the "act of extracting data."

[0023] The communication control management device 50 is connected to the client-side communication control device 30 and the server-side communication control device 31 via a network NW. The communication control management device 50 issues a client certificate and a private key to the client-side communication control device 30. For example, the communication control management device 50 issues an IC (Integrated Circuit) card that stores the client certificate and the private key. The communication control management device 50 also transmits the client certificate and the private key to be stored in the IC card via the network NW to the client-side communication control device 30 in which the IC card is installed.

[0024] The communication control management device 50 also issues a server certificate and a private key to the server-side communication control device 31. For example, the communication control management device 50 issues an IC card storing the server certificate and the private key. The communication control management device 50 also transmits the server certificate and the private key to be stored in the IC card to the server-side communication control device 31 in which the IC card is inserted, via the network NW. The client certificate, the server certificate, and the private key are each information necessary to determine a common key (session key) to be used when the client-side communication control device 30 and the server-side communication control device 31 perform encrypted communication.

[0025] Next, the configurations of the client device 10 and the server device 20 will be described. The client device 10 and the server device 20 are, for example, components that constitute a social infrastructure system. The social infrastructure is, for example, facilities necessary for establishing a social infrastructure, such as a road traffic network, power generation facilities, power distribution facilities, water treatment facilities, or gas distribution facilities. The social infrastructure system is, for example, a mechanism for monitoring the social infrastructure, grasping changes in the situation, and responding to those changes, thereby ensuring stable operation of the social infrastructure. In the following, the client device 10 and the server device will be described as components of a monitoring system that monitors roads, public facilities, and the like. In this case, the client device 10 is a device (network monitoring camera) that transmits image data capturing images of road conditions, etc., via a network NW. The server device 20 is a device that receives the image data transmitted by the client device 10 via the network NW.

[0026] It should be noted that the client device 10 and the server device 20 are not limited to being components of a monitoring system. For example, the client device 10 and the server device 20 may be components of a system that monitors the power status of power generation facilities or power distribution facilities, or may be components of a system that acquires the delivery status of a logistics center, or a system that acquires the operation status of facilities in a factory or research institute.

[0027] FIG. 2 is a block diagram showing an example of the functional configuration of the client device 10 and the server device 20 according to the embodiment.

[0028] The client device 10 includes a NW (network) communication unit 11, a client control unit 12, and an imaging unit 13. The NW communication unit 11 is, for example, an Ethernet (registered trademark) port of the client device 10. In this embodiment, the NW communication unit 11 is connected to a client-side communication control device 30, and outputs data transmitted from the client device 10 to the server device 20 to the client-side communication control device 30. In a conventional system, the NW communication unit 11 corresponds to a functional unit that is connected to a network NW and communicates with the server device 20 via the network NW.

[0029] The client control unit 12 is, for example, a processor including a CPU (Central Processing Unit) and the like, and performs overall control of the client device 10. For example, under control of the server device 20, the client control unit 12 causes the imaging unit 13 to start or stop imaging, and sets imaging conditions such as the direction of the camera that captures images and the magnification when capturing images for the imaging unit 13.

[0030] The imaging unit 13 captures an image of a scene at a predetermined location in accordance with an instruction from the client control unit 12. The imaging unit 13 outputs the captured data (image data) to the client control unit 12.

[0031] The server device 20 includes a NW (network) communication unit 21, a server control unit 22, and an imaging data storage unit 23. The NW communication unit 21 is, for example, an Ethernet (registered trademark) port of the server device 20. In this embodiment, the NW communication unit 21 is connected to a server-side communication control device 31, and outputs data transmitted from the server device 20 to the client device 10 to the server-side communication control device 31. In a conventional system, the NW communication unit 21 corresponds to a functional unit that is connected to a network NW and communicates with the client device 10 via the network NW.

[0032] The server control unit 22 is, for example, a processor including a CPU and the like, and performs overall control of the server device 20. The server control unit 22 stores, for example, imaging data captured by the client device 10 in the imaging data storage unit 23. The imaging data storage unit 23 stores the imaging data in accordance with instructions from the server control unit 22.

[0033] In a conventional system, when a client device 10 and a server device 20 are connected via each other's NW communication unit and network NW, communication between the client device and the server device 20 uses HTTP, which is a common communication protocol for network surveillance cameras.

[0034] In this case, unencrypted information (so-called plain text) output to the network NW by the client device 10 or the server device 20 flows through the network NW. In this case, if data on the network NW is maliciously obtained from an outside source, there is a risk that the imaging data may be easily intercepted or tampered with. As a countermeasure against such unauthorized attacks, it is conceivable to have the client device 10 encrypt the imaging data before outputting it to the network NW.

[0035] For example, the client control unit 12 of the client device 10 encrypts the captured image data and outputs the encrypted captured image data to the network NW. However, since a processor such as a CPU provided in a surveillance camera is generally used for compressing and encoding the captured image data, it often does not have the resources to perform further encryption processing. In such cases, the CPU originally provided in the client control unit 12 cannot (or has difficulty in) encrypting the captured image data. In order to have the client control unit 12 encrypt the captured image data, it may be necessary to change or replace the hardware configuration of the client control unit 12, for example, by installing an additional processor for encrypting the captured image data in the client control unit 12.

[0036] However, since the client device 10 is a component that constitutes social infrastructure such as a surveillance camera, it is not easy to change or replace the hardware configuration of the client device 10. In view of this situation, it is desirable to encrypt the image data and output it to the network NW without making any changes to the client device 10.

[0037] In this embodiment, a client-side communication control device 30 connected between the client device 10 and the network NW encrypts data transmitted by the client device 10 and outputs the data to the network NW. Also, a server-side communication control device 31 connected between the server device 20 and the network NW encrypts control data transmitted by the server device 20 and outputs the control data to the network NW. This improves the security of imaging data transmitted through the network NW without modifying the client device 10 or the server device 20.

[0038] Next, the configurations of the client-side communication control device 30 and the server-side communication control device 31 will be described with reference to FIG. 3. FIG. 3 is a block diagram showing an example of the functional configuration of the client-side communication control device 30 and the server-side communication control device 31 according to an embodiment. The client-side communication control device 30 and the server-side communication control device 31 have the same functional configuration. Therefore, the following will describe the configuration of one (e.g., the client-side communication control device 30), and will omit a description of the configuration of the other (e.g., the server-side communication control device 31). Furthermore, hereinafter, when there is no need to distinguish between the client-side communication control device 30 and the server-side communication control device 31, they will simply be referred to as the communication control device 30 (31), etc.

[0039] As shown in FIG. 3, the communication control device 30 (31) includes an NW (network) communication unit 32, a control unit 33, a device communication unit , a reader / writer , and an IC card .

[0040] The NW communication unit 32 is connected to the network NW and communicates with the other communication control device 30 (31) via the network NW.

[0041] The control unit 33 is, for example, a processor including a CPU and the like, and performs overall control of the communication control device 30 (31). The control unit 33 transmits commands to the IC card 40 and receives responses from the IC card 40, for example, via the reader / writer 35. The control unit 33 also transmits information based on the responses received from the IC card 40 to the other communication control device 30 (31) via the NW communication unit 32. The control unit 33 also transmits commands to the IC card 40 based on information received from the other communication control device 30 (31) via the NW communication unit 32.

[0042] The device communication unit 34 is connected to a device (client device 10 or server device 20) and communicates with the device. Specifically, the device communication unit 34 of the client-side communication control device 30 is connected to the client device 10, acquires imaging data from the client device 10, and outputs decoded control data to the client device 10. Meanwhile, the device communication unit 34 of the server-side communication control device 31 is connected to the server device 20, acquires control data from the server device 20, and outputs decoded imaging data to the server device 20.

[0043] The reader / writer 35 communicates with the IC card 40 via the contact section 36 of the IC card 40 .

[0044] The IC card 40 is formed by mounting an IC module 41 on, for example, a plastic card substrate. That is, the IC card 40 includes the IC module 41 and the card substrate in which the IC module 41 is embedded. The IC card 40 is detachably attached to the communication control device 30 (31) and can communicate with the communication control device 30 (31) via a contact portion 36.

[0045] For example, the IC card 40 receives a command (processing request) transmitted by the communication control device 30 (31) via the contact unit 36 ​​and executes processing (command processing) according to the received command. Then, the IC card 40 transmits a response (processing response) that is the execution result of the command processing to the communication control device 30 (31) via the contact unit 36.

[0046] The IC module 41 includes a contact section 36 and an IC chip 42. The contact section 36 has terminals for various signals necessary for the operation of the IC card 40. Here, the terminals for various signals include terminals for receiving power supply voltage, clock signals, reset signals, etc. from the communication control device 30 (31), and serial data input / output terminals (SIO terminals) for communicating with the communication control device 30 (31). The IC chip 42 is, for example, an LSI (Large Scale Integration) such as a one-chip microprocessor.

[0047] Next, the hardware configuration of the IC card 40 will be described with reference to Fig. 4. Fig. 4 is a diagram showing an example of the hardware configuration of the IC card 40 according to the embodiment.

[0048] The IC card 40 includes an IC module 41 having a contact section 36 and an IC chip 42. The IC chip 42 includes a UART (Universal Asynchronous Receiver Transmitter) 43, a CPU 44, a ROM (Read Only Memory) 45, a RAM (Random Access Memory) 46, and an EEPROM (Electrically Erasable Programmable ROM) 47. The components 43 to 47 are connected via an internal bus BS.

[0049] The UART 43 performs serial data communication with the communication control device 30 (31) via the above-mentioned SIO terminal. The UART 43 outputs data (e.g., 1-byte data) obtained by converting a serial data signal received via the SIO terminal into parallel data to the internal bus BS. The UART 43 also converts data acquired via the internal bus BS into serial data and outputs the serial data to the communication control device 30 (31) via the SIO terminal. The UART 43 receives, for example, a command from the communication control device 30 (31) via the SIO terminal. The UART 43 also transmits a response to the communication control device 30 (31) via the SIO terminal.

[0050] The CPU 44 executes programs stored in the ROM 45 or the EEPROM 47 to perform various processes of the IC card 40. The CPU 44 executes command processing in response to a command received by the UART 43 via the contact unit 36, for example.

[0051] The ROM 45 is a nonvolatile memory such as a mask ROM, and stores data such as programs and command tables for executing various processes of the IC card 40. The RAM 46 is a volatile memory such as a static RAM (SRAM), and temporarily stores data used when performing various processes of the IC card 40. The EEPROM 47 is an electrically rewritable nonvolatile memory. The EEPROM 47 stores various data used by the IC card 40. The EEPROM 47 stores, for example, information used for various services (applications) using the IC card 40.

[0052] Next, an example of the functional configuration of IC card 40 will be described with reference to Fig. 5. Fig. 5 is a block diagram showing an example of the functional configuration of IC card 40 according to an embodiment. IC card 40 includes a communication unit 400, a control unit 401, and a storage unit 404. Here, each unit of IC card 40 shown in Fig. 5 is realized using the hardware of IC card 40 shown in Fig. 4.

[0053] The communication unit 400 is realized by, for example, the UART 43, the CPU 44, and a program stored in the ROM 45, and transmits and receives commands and responses to, for example, the communication control device 30 (31) via the contact unit 36. That is, the communication unit 400 receives a command (processing request) requesting a predetermined process from the communication control device 30 (31), and transmits a response (processing response) to the command to the communication control device 30 (31). The communication unit 400 stores received data received from the communication control device 30 (31) via the UART 43 in the RAM 46. In addition, the communication unit 400 transmits transmission data stored in the RAM 46 to the communication control device 30 (31) via the UART 43.

[0054] The control unit 401 is realized by, for example, the CPU 44, the RAM 46, and the ROM 45 or the EEPROM 47, and performs overall control of the IC card 40. The control unit 401 includes a command processing unit 402 and an encryption / decryption unit 403.

[0055] Here, the processing performed by the command processing unit 402 is an example of "authentication processing."

[0056] The command processing unit 402 executes various command processes. For example, the command processing unit 402 performs an SSL / TLS handshake as command processing for requesting an HTTPS request, which will be described later. The SSL / TLS handshake exchanges key information and the like required for encrypted communication, and performs mutual authentication with the communication destination device. Here, mutual authentication is an authentication process in which the client-side communication control device 30 and the server-side communication control device 31 mutually confirm that they are legitimately authenticated devices before communicating with each other.

[0057] The encryption / decryption unit 403 executes a process of encrypting data and a process of decrypting encrypted data. The encryption / decryption unit 403 encrypts data output from a device (client device 10 or server device 20) acquired via the communication unit 400. The encryption / decryption unit 403 also decrypts encrypted data acquired from the network NW via the communication unit 400.

[0058] The storage unit 404 is a storage unit configured, for example, by the EEPROM 47, and includes a certificate information storage unit 405 and a secret information storage unit 406. The certificate information storage unit 405 stores a certificate issued by the communication control management device 50 for a device (client device 10 or server device 20). Specifically, the certificate information storage unit 405 of the IC card 40 attached to the client-side communication control device 30 stores information indicating a client certificate. Furthermore, the certificate information storage unit 405 of the IC card 40 attached to the server-side communication control device 31 stores information indicating a server certificate.

[0059] The secret information storage unit 406 stores a private key for a device (client device 10 or server device 20) issued by the communication control management device 50. Specifically, the secret information storage unit 406 of the IC card 40 attached to the client-side communication control device 30 stores information indicating the private key issued to the client-side communication control device 30. Furthermore, the certificate information storage unit 405 of the IC card 40 attached to the server-side communication control device 31 stores information indicating the private key issued to the server-side communication control device 31.

[0060] Next, the configuration of the communication control management device 50 and the key management device 51 will be described with reference to Fig. 6. Fig. 6 is a block diagram showing an example of the functional configuration of the communication control management device 50 and the key management device 51 according to the embodiment. The communication control management device 50 includes, for example, an NW (network) communication unit 500, a control unit 501, and a storage unit 506.

[0061] The NW communication unit 500 is connected to the network NW and communicates with the communication control device 30 (31) via the network NW.

[0062] The control unit 501 is, for example, a processor including a CPU, and performs overall control of the communication control management device 50. The control unit 501 mainly functions as a private certification authority that certifies the legitimacy of the communication control device 30 (31). The control unit 501 includes a key generation unit 502, a certificate issuance unit 503, a certificate update unit 504, a certificate management unit 505, and a management unit 509.

[0063] The key generation unit 502 issues a private key corresponding to a public key included in a certificate, which will be described later, based on an authentication request from the communication control device 30 (31), for example. The certificate issuing unit 503 issues a certificate that recognizes the legitimacy of the communication control device 30 (31) based on, for example, an authentication request from the communication control device 30 (31). The certificate includes a public key and information indicating the owner of the communication control device 30 (31).

[0064] The certificate update unit 504 updates the certificate by setting a new expiration date for the certificate whose expiration date has passed. For example, based on an update request from the communication control device 30 (31), the certificate update unit 504 issues a certificate with an extended expiration date of the certificate originally issued to the communication control device 30 (31) and transmits the issued certificate to the communication control device 30 (31). Information indicating the issued certificate is received by the communication control device 30 (31) and stored in the certificate information storage unit 405 of the IC card 40 of the communication control device 30 (31), thereby extending the expiration date of the certificate of the communication control device 30 (31).

[0065] The certificate management unit 505 manages certificates that have already been issued. For example, if the IC card 40 attached to the communication control device 30 (31) is tampered with or stolen, and the authenticity of both parties cannot be proven in mutual authentication, the certificate management unit 505 performs processing to invalidate the certificate issued to the communication control device 30 (31). Furthermore, the certificate management unit 505 may respond to an inquiry from the communication control device 30 (31) by informing the certificate management unit 505 whether the certificates issued to the communication control device 30 (31) and other communication devices were issued by the certificate management unit 505. Furthermore, the certificate management unit 505 may periodically check whether issued certificates are being used by legitimate communication control devices 30 (31).

[0066] The management unit 509 manages the communication control device 30 (31). For example, the management unit 509 remotely controls the mutual authentication performed by the communication control device 30 (31) via the network NW.

[0067] The storage unit 506 stores various types of information.

[0068] The key management device 51 is, for example, a hardware security module (HSM), and includes a processing unit 52 and a storage unit 53. The processing unit 52 executes various information processes, such as a process for responding to an access from the communication control management device 50.

[0069] The storage unit 53 includes a key information storage unit 531 and a certificate information storage unit 532. The key information storage unit 531 stores, for example, information indicating an already issued public key or private key. The certificate information storage unit 532 stores, for example, information indicating an already issued certificate. The key information storage unit 531 and the certificate information storage unit 532 are referenced, for example, when the key generation unit 502 issues a private key or when the certificate issuance unit 503 issues a certificate.

[0070] In conventional technology, when a communication control device 30 (31) that does not support the new encryption method is made compatible with the new encryption method, the only methods available are for an operator to connect a PC to each communication control device 30 (31) on-site and perform an update process to make it compatible with the new encryption method, or to replace it with another communication control device 30 (31) that supports the new encryption method, which poses problems in terms of effort and cost.

[0071] Therefore, the following describes a technique for easily making a communication control device 30 (31) that does not support the new encryption method compatible with the new encryption method. First, a case where a client-side communication control device 30 that does not support the new encryption method is made compatible with the new encryption method will be described.

[0072] As described above, the client-side communication control device 30 stores encryption information (private key, client certificate) used for the mutual authentication process with the server-side communication control device 31 and the transmission / reception process for transmitting and receiving encrypted information between the client device 10 and the server device 20.

[0073] When it becomes necessary to set information for a new encryption method corresponding to the new encryption method in the client-side communication control device 30, the communication control management device 50 sends the information for the new encryption method (including a program and private key corresponding to the new encryption method) to the client-side communication control device 30 at a predetermined timing to cause the information to be set.

[0074] In this case, for example, the communication control management device 50 acquires a communication log from the client-side communication control device 30 and determines the predetermined timing based on the communication log. In this case, for example, the communication control management device 50 determines, from the communication log, a date and time when it is highly likely that the client-side communication control device 30 is not performing communication processing as the predetermined timing. The process of making the client-side communication control device 30 compatible with the new encryption method will be described later with reference to FIG. 8.

[0075] Next, the flow of processing performed by the communication control system 1 will be described with reference to Fig. 7. Fig. 7 is a sequence chart showing an example of processing performed by the communication control system 1 of the embodiment.

[0076] When transmitting imaging data to the server device 20, the client device 10 first transmits an HTTP request to the server device 20 (step S1). The HTTP request transmitted by the client device 10 is acquired by the client-side communication control device 30 (step S2).

[0077] When the client-side communication control device 30 receives the HTTP request sent by the client device 10, it sends an HTTPS request (ClientHello) to the server-side communication control device 31 (step S3), which starts a handshake between the client-side communication control device 30 and the server-side communication control device 31 (step S4).

[0078] Specifically, the ClientHello sent by the client-side communication control device 30 includes, for example, information indicating the TLS version and the type of encryption method and list of algorithms used in communication. The server-side communication control device 31 sends an HTTPS response (ServerHello) to the client-side communication control device 30 in response to the ClientHello. The ServerHello sent by the server-side communication control device 31 includes, for example, information selected by the server device 20 from the options presented in the ClientHello. In other words, the specific encryption algorithm for communication is determined by the server-side communication control device 31 making a selection in response to the option presented by the client-side communication control device 30.

[0079] Then, the server-side communication control device 31 transmits information necessary for the common key to be used for encrypted communication. The information necessary for the common key includes, for example, information indicating the public key and its certificate issued to the server device 20, and information requesting transmission of the public key and its certificate of the client device 10. The client-side communication control device 30 transmits to the server-side communication control device 31 the public key and its certificate issued to itself, and information necessary for the common key to be used for encrypted communication.

[0080] Mutual authentication between the client-side communication control device 30 and the server-side communication control device 31 is performed, for example, as follows: The client-side communication control device 30 generates a signature from the ServerHello and other messages it has received so far, and transmits it to the server-side communication control device 31. The server-side communication control device 31 verifies the signature received from the client-side communication control device 30 based on the certificate received from the client-side communication control device 30. If the verification is successful, the server-side communication control device 31 determines that the certificate definitely belongs to the client-side communication control device 30.

[0081] The server-side communication control device 31 also generates a signature from the ClientHello and other messages it has received so far, and transmits the signature to the client-side communication control device 30. The client-side communication control device 30 verifies the signature received from the server-side communication control device 31 based on the certificate received from the server-side communication control device 31. If the verification is successful, the client-side communication control device 30 determines that the certificate is definitely that of the server-side communication control device 31.

[0082] When mutual authentication between the client-side communication control device 30 and the server-side communication control device 31 is successfully completed, the client-side communication control device 30 and the server-side communication control device 31 each generate and exchange a common key to be used for encryption.

[0083] When the handshake with the client-side communication control device 30 is established, the server-side communication control device 31 transmits an HTTP request to the server device 20 (step S5). The HTTP request is the HTTP request transmitted from the client device 10 in step S1.

[0084] The HTTP request transmitted by the server-side communication control device 31 is received by the server device 20 (step S6). At this time, the server device 20 recognizes that the HTTP request has been made by the client device 10. Therefore, the server device 20 sends an HTTP response to the client device 10 (step S7). The HTTP response transmitted by the server device 20 is acquired by the server-side communication control device 31 (step S8).

[0085] The server-side communication control device 31 encrypts the acquired HTTP response from the server device 20 using the common key determined in the handshake of step S4 (step S9). The HTTP response encrypted by the server-side communication control device 31 is received by the client-side communication control device 30 via the network NW (step S10).

[0086] The client-side communication control device 30 decrypts the received HTTP response using the common key (step S11). The HTTP response decrypted by the client-side communication control device 30 is transmitted to the client device 10 (step S12). The client device 10 receives the decrypted HTTP response (step S13). At this time, the client device 10 recognizes that an HTTP response has been sent from the server device 20. Therefore, the client device 10 transmits imaging data to the server device 20 (step S14).

[0087] The imaging data transmitted by the client device 10 is acquired by the client-side communication control device 30 (step S15). The client-side communication control device 30 encrypts the imaging data transmitted by the client device 10 using a common key (step S16). The imaging data encrypted by the client-side communication control device 30 is received by the server-side communication control device 31 via the network NW (step S17).

[0088] The server-side communication control device 31 decrypts the received imaging data using the common key (step S18). The imaging data decrypted by the server-side communication control device 31 is acquired by the server device 20 (step S19). The server device 20 receives the decrypted imaging data (step S20). At this time, the server device 20 recognizes that it has received imaging data from the client device 10.

[0089] In step S4 of the above flowchart, if mutual authentication between the client-side communication control device 30 and the server-side communication control device 31 is not performed correctly, the client-side communication control device 30 does not permit communication with the communication destination. Specifically, the client-side communication control device 30 does not output information transmitted from the communication destination to the client device 10. This is because, if mutual authentication is not performed correctly, there is a possibility that the communication destination is an unauthorized communication device disguised as the server-side communication control device 31. In this case, the client-side communication control device 30 may transmit, for example, a communication record of when mutual authentication was not performed correctly to the communication control management device 50. This allows the communication control management device 50 to acquire the communication record of when mutual authentication was not performed correctly, and by understanding the pattern and frequency of unauthorized communications to the client-side communication control device 30 under its management, it is possible to monitor network abnormalities.

[0090] Next, a process for making a client-side communication control device 30 that does not support a new encryption method compatible with the new encryption method will be described with reference to Fig. 8. Fig. 8 is a flowchart showing an example of the process performed by the client-side communication control device 30 and the communication control management device 50 according to the embodiment. Here, it is assumed that, for example, a new encryption method, which is one of the PQCs, has been completed, and it has become necessary to set new encryption method information (including a program and a private key compatible with the new encryption method) compatible with the new encryption method in the client-side communication control device 30.

[0091] First, in step S31, the communication control management device 50 requests the client-side communication control device 30 for a communication log.

[0092] In response to this, the client-side communication control device 30 transmits the communication log to the communication control management device 50 in step S32.

[0093] Next, in step S33, the communication control management device 50 sets the date and time when it is highly likely that the client-side communication control device 30 is not performing communication processing as the update date and time to the new encryption method, based on the acquired communication log.

[0094] Next, in step S34, the communication control management device 50 notifies the client-side communication control device 30 of the update date and time.

[0095] Next, in step S35, client-side communication control device 30 determines whether or not communication is scheduled for the updated date and time. If Yes, the process proceeds to step S36, and if No, the process proceeds to step S37.

[0096] In step S36, since the current update date and time is inconvenient, client-side communication control device 30 requests resetting of the update date and time to communication control management device 50. After step S36, client-side communication control device 30 ends the process.

[0097] In step S37, client-side communication control unit 30 determines whether the update date and time has arrived, and if Yes, proceeds to step S41, and if No, returns to step S35.

[0098] After step S34, in step S38, the communication control management device 50 determines whether or not it has received a request to reset the update date and time from the client-side communication control device 30; if Yes, it terminates the processing (and then returns to step S31 and executes the update date and time resetting process, etc. in subsequent processing); if No, it proceeds to step S39.

[0099] In step S39, the communication control management device 50 determines whether the update date and time has arrived, and if Yes, the process proceeds to step S40, and if No, the process returns to step S38.

[0100] In step S40, the communication control management device 50 transmits update data (information for the new encryption method including a program compatible with the new encryption method and a secret key) to the client-side communication control device 30.

[0101] Next, in step S41, client-side communication control unit 30 updates encryption information (including program and secret key) based on the received update data.

[0102] Next, in step S42, the client-side communication control device 30 notifies the communication control management device 50 that the update has been successful.

[0103] As described above, according to the communication control system S of this embodiment, when a new encryption method is to be introduced into the client-side communication control device 30, the communication control management device 50 can transmit information for the new encryption method (including a program and a private key compatible with the new encryption method) to the client-side communication control device 30 to set the new encryption method, making the introduction easy. In other words, unlike the prior art, it is no longer necessary for an operator to connect a PC on-site to each client-side communication control device 30 to perform an update process to make it compatible with the new encryption method, or to replace it with another client-side communication control device 30 that is compatible with the new encryption method, thereby significantly reducing the effort and cost.

[0104] Furthermore, by determining the timing for sending and setting information for the new encryption method (including a program and private key corresponding to the new encryption method) from the communication control management device 50 to the client-side communication control device 30 based on the communication log of the client-side communication control device 30, the possibility of disrupting the normal communication processing of the client-side communication control device 30 can be reduced.

[0105] The communication control management device 50 can make the server-side communication control device 31, which does not support the new encryption method, compatible with the new encryption method, just as in the case of the client-side communication control device 30. Specifically, this is as follows.

[0106] As described above, the server-side communication control device 31 stores encryption information (private key, server certificate) used for the mutual authentication process with the client-side communication control device 30 and the transmission / reception process for transmitting and receiving encrypted information between the server device 20 and the client device 10.

[0107] When it becomes necessary to set information for a new encryption method corresponding to the new encryption method in the server-side communication control device 31, the communication control management device 50 sends the information for the new encryption method (including a program and private key corresponding to the new encryption method) to the server-side communication control device 31 at a predetermined timing to have the information set.

[0108] In this case, for example, the communication control management device 50 acquires a communication log from the server-side communication control device 31 and determines the predetermined timing based on the communication log. In this case, for example, the communication control management device 50 determines, from the communication log, a date and time when it is highly likely that the server-side communication control device 31 is not performing communication processing as the predetermined timing.

[0109] Although an embodiment of the present invention has been described, this embodiment is presented as an example and is not intended to limit the scope of the invention. This embodiment can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. This embodiment and its modifications are included within the scope and spirit of the invention, as well as the invention described in the claims and their equivalents.

[0110] For example, the case where a new encryption method is introduced (added) to the communication control device 30 (31) is not limited to when PQC is introduced. Alternatively, for example, it may be the case where the current encryption method of the communication control device 30 (31) is determined to have a vulnerability, and a new encryption method other than PQC is introduced. In this case, the communication control management device 50 may issue a warning to the user of the client device 10 or the server device 20, for example, about the device using the vulnerable encryption method.

[0111] Also, in Figure 1, the client device 10 is not limited to a computer device such as a general PC, but can also be any device capable of communication via a network NW, such as an IC card with communication functions or a reader / writer connected to an IC card.

[0112] The update date and time may be determined by the communication control management device 50 based on the communication log from the communication control device 30 (31), or may be specified by the administrator of the communication control management device 50.

[0113] Furthermore, when the client-side communication control device 30 communicates with other devices (such as the server device 20) during the update process in step S41 of FIG. 8, the communication may be performed using, for example, an existing encryption method, or may be performed without encryption. [Explanation of symbols]

[0114] 1...Communication control system, 10...Client device, 11...NW communication unit, 12...Client control unit, 13...Imaging unit, 20...Server device, 21...NW communication unit, 22...Server control unit, 23...Imaging data storage unit, 30...Client side communication control device, 31...Server side communication control device, 32...NW communication unit, 33...Control unit, 34...Device communication unit, 35...Reader / writer, 36...Contact unit, 40...IC card, 42...IC chip, 43...UART, 44...CPU, 45...ROM, 46...RAM, 47... EEPROM, 50...communication control management device, 51...key management device, 52...processing unit, 53...storage unit, 60...network, 70...gateway, 400...communication unit, 401...control unit, 402...command processing unit, 403...encryption / decryption unit, 404...storage unit, 405...certificate information storage unit, 406...private information storage unit, 500...NW communication unit, 501...control unit, 502...key generation unit, 503...certificate issuance unit, 504...certificate update unit, 505...certificate management unit, 506...storage unit, 509...management unit, S...communication control system

Claims

1. a first communication control device connected between the client device and the network; a second communication control device connected between the server device and the network; a communication control management device connected to the first communication control device via the network; Equipped with the first communication control device stores encryption information used in a mutual authentication process performed with the second communication control device and a transmission / reception process for transmitting and receiving encrypted information between the client device and the server device; When it becomes necessary to set information for a new encryption method corresponding to a new encryption method in the first communication control device, the communication control management device transmits the information for the new encryption method to the first communication control device at a predetermined timing to cause the first communication control device to set the information. Communications control system.

2. 2. The communication control system according to claim 1, wherein when it becomes necessary to set information for a new encryption method corresponding to a new encryption method in the first communication control device, the communication control management device acquires a communication log from the first communication control device and determines the specified timing based on the communication log.

3. 2. The communication control system according to claim 1, wherein said information for the new encryption method includes a program and a secret key compatible with said new encryption method.

4. a first communication control device connected between the client device and the network; a second communication control device connected between the server device and the network; a communication control management device connected to the second communication control device via the network; Equipped with the second communication control device stores encryption information used in a mutual authentication process with the first communication control device and a transmission / reception process for transmitting and receiving encrypted information between the server device and the client device; When it becomes necessary to set new encryption method information corresponding to the new encryption method in the second communication control device, the communication control management device transmits the new encryption method information to the second communication control device at a predetermined timing to cause the second communication control device to set the new encryption method. Communications control system.

5. a first communication control device connected between the client device and the network; a second communication control device connected between the server device and the network; a communication control management device connected to the first communication control device via the network communication network, the first communication control device stores encryption information used in a mutual authentication process performed with the second communication control device and a transmission / reception process for transmitting and receiving encrypted information between the client device and the server device; When it becomes necessary to set information for a new encryption method corresponding to a new encryption method in the first communication control device, the communication control management device transmits the information for the new encryption method to the first communication control device at a predetermined timing to cause the first communication control device to set the information. Communications control management device.

Citation Information

Patent Citations

  • Communication Control System

    JP6644037B2

  • Client-side communication control device and server-side communication control device

    JP7042853B2