Communication system, and control method for communication system
A communication system using public key cryptography enables secure pairing between Bluetooth devices without human intervention, addressing the inefficiencies and security gaps in existing Bluetooth pairing methods, particularly for devices like underwater detectors.
Patent Information
- Application Number
- JP2024057339
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-03-29
AI Technical Summary
Bluetooth wireless communication requires manual pairing, which is time-consuming and lacks security, especially in devices without display or input functions, and existing methods still require human intervention.
A communication system using public key cryptography for secure pairing, where a first device generates and transmits an advertising signal with signature information, and a second device verifies this information using a pre-stored public key, generating encrypted connection information for secure pairing without human intervention.
Ensures secure pairing between devices without manual input, particularly in devices like underwater detectors, by verifying authenticity and encrypting connection information, thus ensuring security and eliminating the need for human interaction.
Smart Images

Figure 2025154382000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication system connected by Bluetooth (registered trademark). [Background technology]
[0002] Bluetooth (registered trademark) is known as one of the short-range wireless communication technologies. BLE (Bluetooth Low Energy) is also known as one of the Bluetooth extension specifications. BLE is a specification that enables communication over a long period of time with low power consumption. Devices that communicate wirelessly via Bluetooth perform pairing to establish a connection and then perform wireless communication.
[0003] For example, Patent Document 1 describes a wireless communication system in which, when a specified event occurs in a first terminal, the first terminal transmits an advertising packet including identification information, request information, and connection information, and a second terminal that receives the advertising packet initiates pairing with the first terminal.
[0004] Furthermore, Patent Document 2 describes a method for establishing a wireless connection between a first device and a second device by using a link key generated using a partial link key pre-stored in the first device, a first secret key received from a first source, and a second secret key received from a second source. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication WO2019 / 180844 [Patent Document 2] Special Publication No. 2017-502618 Summary of the Invention [Problem to be solved by the invention]
[0006] As mentioned above, Bluetooth wireless communication requires pairing between connected communication devices. Because it is desirable to ensure security during pairing, it is often performed manually, for example, by displaying a six-digit number on one device and entering that number on the other device. This is therefore time-consuming.
[0007] Although the technology described in Patent Document 1 does not involve human intervention, the connection information used for pairing is transmitted in an advertisement packet, and security is not guaranteed at all to begin with.
[0008] Furthermore, in the method described in Patent Document 2, the first source is the user of the first device and the second device. This means that human intervention is ultimately required, which is still time-consuming.
[0009] Furthermore, in the case of devices that do not have display functions, input functions, etc., improvements are required to provide these functions.
[0010] One aspect of the present invention has been made in consideration of the above-mentioned problems, and its purpose is to realize a communication system that enables safe pairing in BLE communication without requiring the above-mentioned effort, equipment modifications, etc. [Means for solving the problem]
[0011] A communication system according to one embodiment of the present invention is a communication system including a first device and a second device connected to each other so that they can communicate with each other via Bluetooth, wherein the first device has a first public key and a first private key of a public key cryptosystem, and a first transmitter that transmits a first advertising signal including signature information generated using a second private key of the public key cryptosystem, an identification signal that identifies the first device, and the first public key; the second device has a receiver that receives the first advertising signal, a verification unit that verifies the validity of the signature information included in the received first advertising signal using a pre-stored second public key of the public key cryptosystem, a generation unit that generates connection information if the verification result by the verification unit is valid, and a second transmitter that transmits a second advertising signal including the connection information encrypted using the first public key; and the first device further includes a pairing unit that decrypts the connection information included in the second advertising signal using the first private key, and pairs with the second device using the decrypted connection information.
[0012] A communication method according to one embodiment of the present invention is a control method for a communication system including a first device and a second device connected to each other so that they can communicate with each other via Bluetooth, wherein the first device has a first public key and a first private key of a public key cryptosystem, and the first device includes: a first transmission step of transmitting, in the first device, a first advertising signal, in which specific information identifying the first device is generated using a second private key of the public key cryptosystem, an identification signal that identifies the first device, and the first public key; a reception step of receiving, in the second device, the first advertising signal; a verification step of verifying the validity of the signature information included in the received first advertising signal using a pre-stored second public key of the public key cryptosystem; a generation step of generating connection information if the verification result in the verification step is positive; and a second transmission step of transmitting, in the first device, a second advertising signal including the connection information encrypted using the first public key; and a pairing step of decrypting, in the first device, the connection information included in the second advertising signal using the first private key, and pairing with the second device using the decrypted connection information. [Effects of the Invention]
[0013] According to one aspect of the present invention, pairing between a first device and a second device can be achieved without human intervention, with an appropriate partner device and security being ensured. [Brief explanation of the drawings]
[0014] [Figure 1] 1 is a diagram illustrating an overview of a communication system according to an embodiment of the present invention. [Figure 2] FIG. 1 is a functional block diagram showing a configuration of a main part of a communication system. [Figure 3] FIG. 1 is a sequence diagram showing a processing flow in a communication system. [Figure 4] FIG. 10 is a sequence diagram showing a flow of a pairing process in the communication system. [Figure 5] FIG. 10 is a diagram illustrating an overview of a communication system according to another embodiment. [Figure 6] FIG. 10 is a functional block diagram showing the configuration of a main part of a communication system according to another embodiment. [Figure 7] FIG. 10 is a functional block diagram showing a processing flow in a communication system according to another embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0015] [Embodiment 1] 〔overview〕 An embodiment of the present invention will be described in detail below. A communication system 1 according to this embodiment includes a first device (central) and a second device (peripheral), which are paired and connected to each other so that they can communicate with each other via Bluetooth Low Energy (BLE). Note that BLE is just an example, and a communication method other than BLE may be used as long as they are configured to communicate with each other via Bluetooth. Furthermore, this embodiment will be described taking an example in which one first device is paired with one second device, but one first device may be paired with multiple second devices.
[0016] [Communication System 1] In this embodiment, an example of a communication system 1 will be described in which a signal converter 10 is used as the first device and a detector 20 is used as the second device.
[0017] The detector 20 is a device used underwater to measure water quality. In other words, the detector 20 is an underwater device. The water quality to be measured is not particularly limited, and the detector may measure, for example, turbidity, color, chlorine concentration, oxygen concentration, liquid pH, the presence or absence of microplastics, etc.
[0018] The signal converter 10 converts one or more signals received from the detector 20 into one or more signals and outputs them. For example, the signal converter 10 may convert a digital signal received from the detector 20 into an analog signal and output it to an external recorder. Alternatively, the signal converter 10 may output a relay contact signal to an external control panel when the level of the signal received from the detector 20 exceeds an alarm trigger. The signal converter 10 may also include a display unit (not shown) that numerically displays the signal level of the signal received from the detector 20, the measurement conditions of the detector 20, etc.
[0019] FIG. 1 shows an example of a situation in which a signal converter 10 and a detector 20 are used. As shown in FIG. 1, in a communication system 1, a detector 20 disposed underwater and the signal converter 10 are connected to each other so that they can communicate via wireless communication. As shown in FIG. 1, the detector 20 is disposed underwater, making it difficult for a user to directly operate the detector 20 or to display information on the detector 20 for the user to confirm. Therefore, it is difficult to perform operations and display connection information when performing pairing, as in the prior art. Therefore, the communication system 1 according to this embodiment has the following features, which enable pairing between the signal converter 10 and the detector 20 in a secure manner without requiring the user to perform operations or confirmations.
[0020] The communication system 1 will be described in detail with reference to Fig. 2. Fig. 2 is a functional block diagram showing the configuration of the main parts of the communication system 1. As shown in Fig. 2, the communication system 1 includes a signal converter 10 and a detector 20.
[0021] The signal converter 10 is produced in a production jig 30 in a factory or the like. The production jig 30 includes a signature information generation unit 301 and a storage unit 302, and a second secret key 61 is stored in the storage unit 302. The second secret key 61 is a secret key in a public key cryptosystem and is used in combination with a second public key 62, which will be described later. A file encrypted with the second public key 62 can only be decrypted with the second secret key 61. The reverse process is also possible; a file encrypted with the second secret key 61 can only be decrypted with the second public key 62. Since the signature information is generated by the signature information generation unit 301 of the production jig 30, the production jig 30 can be called a signature information generation device.
[0022] When a plurality of signal converters 10 are produced using the production jig 30, the second private key 61 may be different for each signal converter 10, or may be the same for each signal converter 10. Furthermore, when the second private key 61 is different for each signal converter 10 and the detector 20 can be paired with a plurality of signal converters 10, the detector 20 may have a second public key 62 for each pairable signal converter 10.
[0023] In the production jig 30, when the signal converter 10 is produced, the signature information generation unit 301 generates signature information 31 using a unique ID and the second secret key 61 to identify the signal converter 10. The unique ID can be said to be identification information for identifying the signal converter 10. The generated signature information 31 is then stored in the storage unit 104 of the signal converter 10. Since the signature information 31 is generated not inside the signal converter 10 but in the production jig 30 that produces the signal converter 10 and stored in the signal converter 10, the signal converter 10 cannot be masqueraded as another device.
[0024] In other words, the signature information 31 is generated by a production jig 30 (signature information generating device) different from the signal converter 10. This eliminates the need to store the second secret key 61 in the signal converter 10. Therefore, even if the signal converter 10 is stolen or the like, the risk of the second secret key 61 being leaked can be reduced.
[0025] The signal converter 10 includes a first advertising signal generation unit 101, a first transmission unit 102, a pairing unit 103, and a storage unit 104. The detector 20 includes a reception unit 201, a verification unit 203, a second advertising signal generation unit 204, a second transmission unit 205, a pairing unit 206, and a storage unit 207.
[0026] The first advertising signal generating unit 101 generates a first advertising signal including a converter ID (identification signal) for identifying the signal converter 10 , signature information 31 , and a first public key 52 .
[0027] The first transmission unit 102 advertises and transmits the first advertising signal generated by the first advertising signal generation unit 101.
[0028] The pairing unit 103 performs pairing processing with the detector 20. Details of the pairing processing will be described later.
[0029] The storage unit 104 is a storage device that stores the signature information 31, the first private key 51, and the first public key 52. The first private key 51 and the first public key 52 are a private key and a public key in a public key cryptosystem, similar to the second private key 61 and the second public key 62 described above. A file encrypted with the second public key 62 can only be decrypted with the second private key 61.
[0030] The first private key 51 and the first public key 52 may be generated within the signal converter 10, or may be generated by a device external to the signal converter 10 and written to the signal converter 10.
[0031] The receiving unit 201 receives the first advertising signal transmitted from the signal converter 10. The verifying unit 203 verifies the signature information 31 included in the first advertising signal received by the receiving unit 201 using the second public key 62 stored in the storage unit 207. Specifically, the verifying unit 203 verifies whether a digest value calculated from the converter ID matches a digest value obtained from the signature information 31 using the second public key 62, and if they match, the signature is deemed to be valid. A valid signature means that the converter ID indicated by the signature information 31 matches the converter ID included in the first advertising signal, indicating that the signal converter 10 that sent the first advertising signal is legitimate.
[0032] If the verification result by the verification unit 203 is valid, the second advertising signal generation unit 204 generates connection information to be used for pairing, encrypts the generated connection information using the first public key 52 received from the signal converter 10, and generates a second advertising signal including the encrypted connection information and the received converter ID. The connection information may be generated anew each time pairing is performed. In other words, the second advertising signal generation unit 204 may generate connection information with different content each time. Note that the second advertising signal generation unit 204 can be said to be a generation unit that generates connection information.
[0033] The second transmitting unit 205 advertises and transmits the second advertising signal generated by the second advertising signal generating unit 204. Since the first private key 51 for decrypting the connection information is stored only in the signal converter 10, even if the second advertising signal is intercepted by another device, the connection information is not leaked and is safe.
[0034] The pairing unit 206 performs pairing processing with the signal converter 10. Details of the pairing processing will be described later.
[0035] The storage unit 207 is a storage device that stores the second public key 62. The second public key 62 is stored in the detector 20 when the detector 20 is manufactured.
[0036] [Processing flow in communication system 1] Next, the flow of processing in the communication system 1 will be described with reference to Fig. 3 and Fig. 4. Fig. 3 is a sequence diagram showing the flow of processing in the communication system 1.
[0037] As shown in FIG. 3, the signal converter 10 stores in advance signature information 31 generated using the second private key 61. When the signal converter 10 receives a pairing start operation (S101), the first advertisement signal generation unit 101 generates a first advertisement signal (S102). As described above, the first advertisement signal includes the generated signature information 31, the converter ID, and the second public key 62. Then, the first transmission unit 102 starts advertisement transmission of the first advertisement signal (S103, first transmission step). Meanwhile, when the detector 20 receives a pairing start operation (S201), it starts scanning (S202). The pairing start operation in the detector 20 may be performed by a button or the like (not shown) provided on the detector 20 and the user pressing the button, or the detector 20 may not necessarily be directly operated by the user. For example, the detector 20 may be equipped with an acceleration sensor, and when the detector 20 detects that it is placed in water, it may be determined that a pairing start operation has occurred. Alternatively, the pairing start operation may be performed by a remote indicator that includes an infrared receiving element and emits infrared rays.
[0038] When the detector 20 receives a first advertising signal transmitted from the signal converter 10 during scanning (S203, receiving step), the verification unit 203 uses the second public key 62 to verify the validity of the signature information 31 included in the first advertising signal (S204, verification step). If the signature information 31 is valid (YES in S205), the second advertising signal generation unit 204 generates a second advertising signal (S207, generation step). As described above, the second advertising signal includes encrypted connection information and the converter ID. Then, the second transmission unit 205 starts advertising transmission of the second advertising signal (S208, second transmission step).
[0039] After starting the advertising transmission of the first advertising signal, the signal converter 10 periodically repeats advertising and scanning. Then, the signal converter 10 starts scanning (S104). When the signal converter 10 receives a second advertising signal transmitted from the detector 20 during scanning (S105), the signal converter 10 decrypts the connection information using the first private key 51 (S106). Then, using the decrypted connection information, the pairing unit 103 performs a pairing process with the pairing unit 206 of the detector 20 (S107, S209, pairing step).
[0040] (Details of the pairing process) Next, the flow of the pairing process between the signal converter 10 and the detector 20 will be described with reference to Fig. 4. Fig. 4 is a sequence diagram showing the flow of the pairing process.
[0041] As shown in FIG. 4, in the pairing process, first, the signal converter 10 confirms that the second advertising signal received by the detector 20 includes its own converter ID. If it is confirmed that the converter ID is included, the pairing unit 103 sends a pairing request to the sender of the second advertising signal (S301). The pairing unit 206 of the detector 20 that has received the pairing request requests connection information from the pairing unit 103 of the signal converter 10 (S302). The pairing unit 103 that has received the connection information request transmits the connection information decoded in step S106 to the pairing unit 206 (S303). If the pairing unit 206 confirms that the connection information transmitted from the pairing unit 103 is correct, it performs pairing with the pairing unit 103 (S304). That is, the signal converter 10 and the detector 20 are paired. This pairing method is a so-called Passkey Entry method, and the connection information corresponds to a Passkey.
[0042] In the detector 20, when the second advertising signal generating unit 204 generates connection information with different contents each time, the detector 20 may pair with the signal converter 10 only when it receives a pairing request using the latest connection information from the signal converter 10. This makes it possible to enhance security because only the latest connection information is valid.
[0043] The above is the flow of processing in the communication system 1.
[0044] Note that advertising and scanning in the signal converter 10 and the detector 20 may be performed alternately and repeatedly, or advertising and scanning may be performed in parallel. Furthermore, the interval between advertising and scanning in the signal converter 10 may be different from the interval between advertising and scanning in the detector 20. This makes it possible to reduce the risk that the intervals between advertising and scanning in the signal converter 10 and the detector 20 will match, causing the detector 20 to be unable to receive the first advertising signal transmitted from the signal converter 10 or the second advertising signal transmitted from the detector 20.
[0045] As described above, according to communication system 1, detector 20 verifies the authenticity of signal converter 10 by using signature information 31 decrypted using pre-stored second public key 62. If the verification results in authenticity of signal converter 10, detector 20 encrypts connection information used for pairing with signal converter 10 using first public key 52 and transmits the encrypted connection information to signal converter 10. Only signal converter 10 possesses first private key 51 for decrypting the connection information. Therefore, when detector 20 receives a pairing request using the connection information from signal converter 10, detector 20 can recognize that signal converter 10, which is the sender of the pairing request, is a legitimate device as a device with which to connect. This allows pairing between signal converter 10 and detector 20 to be achieved without human intervention, with security guaranteed and with an appropriate device as the other device.
[0046] In BLE 5.0 and later, the advertisement data length has been extended to 255 bytes. Furthermore, by using elliptic curve cryptography (ECC) for the information included in the first advertisement signal and the second advertisement signal (signature information 31, second public key 62, connection information, converter ID, etc.), the data length can be shortened. This allows for the generation of advertisement signals with sufficient encryption strength that fit within the advertisement data length limit.
[0047] In the above-described embodiment, the pairing mode is entered, i.e., advertising and scanning are initiated, after a pairing start operation is received. However, the present invention is not limited to this. For example, both the signal converter 10 and the detector 20 may enter pairing mode when they are powered on. That is, when they are powered on, the signal converter 10 may enter the process of step S103 shown in FIG. 3, and the detector 20 may enter the process of step S202. This allows pairing with the signal converter 10 while ensuring security, even if the detector 20 is installed far from the signal converter 10, simply by powering on the detector 20. Furthermore, if the signal converter 10 is powered on, pairing between the signal converter 10 and the detector 20 can be achieved simply by powering on the detector 20. Therefore, for example, even if the signal converter 10 is operating, i.e., has already been paired with another detector 20, pairing with the signal converter 10 can be achieved simply by powering on the detector 20 to be paired. However, this is limited to the case where there is one signal converter 10, that is, one master unit.
[0048] [Embodiment 2] Other embodiments of the present invention will be described below. For ease of explanation, the same reference numerals will be used to designate components having the same functions as those described in the above embodiment, and the description thereof will not be repeated.
[0049] In this embodiment, an example will be described in which a mobile terminal is used as the first device and a sensor is used as the second device in the communication system 1A.
[0050] An overview of a communication system 1A according to this embodiment is shown in Fig. 5. In the communication system 1A, a mobile terminal 50 and a sensor 60 communicate with each other wirelessly using BLE.
[0051] Fig. 6 is a functional block diagram showing the configuration of the main parts of the communication system 1A. As shown in Fig. 6, the functions are similar to those of the signal converter 10 and the detector 20 included in the above-described communication system 1. That is, the signal converter 10 corresponds to the mobile terminal 50, and the detector 20 corresponds to the sensor 60.
[0052] The signature server 70 generates signature information including a terminal ID for identifying the mobile terminal 50 based on an instruction from the mobile terminal 50, using the second private key 61. Although it differs from the production jig 30 described above in that it generates signature information based on an instruction from the mobile terminal 50, it performs similar processing functionally.
[0053] FIG. 7 is a sequence diagram showing a processing flow in the communication system 1A. As shown in FIG. 7, in the communication system 1A, first, the mobile terminal 50 accepts a pairing start operation (S501). The mobile terminal 50 that has accepted the pairing start operation reads its own terminal ID (S502) and transmits a signature information generation request together with the terminal ID to the signature server 70 (S503). The mobile terminal 50 may be configured to be able to request the generation of signature information by an application executed on the mobile terminal. The application may be able to request the generation of the signature described above by logging in to the signature server 70. In this case, the user may be required to input a user ID and password when logging in.
[0054] The signature server 70, which has received the request to generate signature information, generates signature information using the terminal ID and the second private key 61 (S701). Then, the generated signature information 31 is transmitted to the mobile terminal 50. Upon receiving the signature information 31 from the signature server 70, the mobile terminal 50 generates a first advertise signal including the terminal ID, the first public key 52, and the signature information 31.
[0055] On the other hand, when the sensor 60 receives a pairing start operation (S601), it starts scanning (S602).
[0056] The subsequent steps are the same as the flow from step S203 onwards described above with reference to Fig. 3. That is, when a first advertising signal transmitted from the mobile terminal 50 is received during scanning by the sensor 60 (S603), the verification unit 203 verifies the validity of the signature information 31 included in the first advertising signal using the second public key 62 (S604). If the signature information 31 is valid (YES in S605), the second advertising signal generation unit 204 generates a second advertising signal (S607). As described above, the second advertising signal includes encrypted connection information and a terminal ID. Then, the second transmission unit 205 starts advertising transmission of the second advertising signal (S608).
[0057] After starting the advertising transmission of the first advertising signal, the mobile terminal 50 periodically repeats advertising and scanning. Then, when the mobile terminal 50 receives a second advertising signal transmitted from the sensor 60 during scanning (S506) (S507), the mobile terminal 50 decrypts the connection information using the first private key 51 (S508). Then, using the decrypted connection information, the pairing unit 103 performs pairing processing with the pairing unit 206 of the sensor 60 (S509, S609).
[0058] The contents of the pairing process are the same as those described above with reference to FIG.
[0059] As described above, even when the mobile terminal 50 is used as the first device and the sensor 60 is used as the second device, pairing between the mobile terminal 50 and the sensor 60 can be achieved without troubling the user while ensuring security.
[0060] [Software implementation example] The functions of the signal converter 10 and detector 20 (hereinafter referred to as "each device") included in the communication system 1 can be realized by a program for causing a computer to function as each device, and a program for causing a computer to function as each control block of each device (in particular, the first advertisement signal generation unit 101, the pairing unit 103, the verification unit 203, the second advertisement signal generation unit 204, and the pairing unit 206).
[0061] In this case, each of the above devices includes a computer having at least one control device (e.g., a processor) and at least one storage device (e.g., a memory) as hardware for executing the above program. The functions described in each of the above embodiments are realized by executing the above program using the control device and storage device.
[0062] The program may be non-transitory and may be recorded on one or more computer-readable recording media. The recording media may or may not be included in the device. In the latter case, the program may be supplied to the device via any wired or wireless transmission medium.
[0063] Furthermore, some or all of the functions of the control blocks can be realized by logic circuits. For example, an integrated circuit in which a logic circuit that functions as each of the control blocks is formed is also included in the scope of the present invention. In addition, the functions of the control blocks can also be realized by, for example, a quantum computer.
[0064] Furthermore, each process described in each of the above embodiments may be executed by AI (Artificial Intelligence). In this case, the AI may run on the control device or on another device (for example, an edge computer or a cloud server).
[0065] 〔summary〕 A communication system according to a first aspect of the present invention is a communication system including a first device and a second device connected to each other so that they can communicate with each other via Bluetooth, wherein the first device has a first public key and a first private key of a public key cryptosystem, and a first transmitting unit that transmits a first advertising signal including signature information generated using a second private key of the public key cryptosystem, an identification signal that identifies the first device, and the first public key, and the second device has a receiving unit that receives the first advertising signal, a verification unit that verifies the validity of the signature information included in the received first advertising signal using a pre-stored second public key of the public key cryptosystem, a generation unit that generates connection information if the verification result by the verification unit is valid, and a second transmitting unit that transmits a second advertising signal including the connection information encrypted using the first public key, and the first device further includes a pairing unit that decrypts the connection information included in the second advertising signal using the first private key, and pairs with the second device using the decrypted connection information.
[0066] According to the above configuration, the second device can verify the authenticity of the signature information using a pre-stored second public key. If the verification results in authenticity, the second device encrypts connection information used for pairing with the first device using the first public key and transmits the encrypted connection information to the first device. Only the first device has the first private key for decrypting the connection information. Therefore, when the second device receives a pairing request using the connection information from the first device, it can recognize that the first device, which is the sender of the pairing request, is a legitimate device as a device with which to connect. This allows pairing between the first device and the second device to be achieved without human intervention, with security guaranteed and with an appropriate device as the other device.
[0067] A communication system according to Aspect 2 of the present invention is similar to Aspect 1, except that the signature information is generated by a signature information generation device different from the first device. With the above configuration, the signature information is generated by a signature information generation device different from the first device, so there is no need to store the second private key in the first device. Therefore, even if the first device is stolen, the risk of the second private key being leaked can be reduced.
[0068] In a communication system according to a third aspect of the present invention, in the first or second aspect, the generator generates the connection information with different content each time, and the second device pairs with the first device only when it receives a pairing request from the first device using the latest connection information. With this configuration, only the latest connection information is valid, thereby improving security.
[0069] A communication system according to a fourth aspect of the present invention is any of the first to third aspects, wherein the first and second devices alternate between advertising and scanning, and the interval between advertising and scanning of the first device is different from the interval between advertising and scanning of the second device. With this configuration, the intervals between advertising and scanning of the first and second devices match, reducing the risk that the second device will not be able to receive an advertising signal transmitted from the first device, or that the first device will not be able to receive an advertising signal transmitted from the second device.
[0070] A communication system according to a fifth aspect of the present invention is any of the first to fourth aspects, wherein at least one of the first device and the second device performs advertising and scanning in parallel. This configuration can reduce the risk that the second device cannot receive an advertising signal transmitted from the first device, or the first device cannot receive an advertising signal transmitted from the second device.
[0071] A communication system according to a sixth aspect of the present invention is any of the first to fifth aspects, wherein the second device is an underwater device used underwater, and the first device is a signal converter for data obtained by the water quality device. For devices used underwater, it is difficult to operate them directly with human hands or to display data for human confirmation. With the above configuration, the underwater device and the signal converter can be paired without human intervention while ensuring security.
[0072] A control method for a communication system according to a seventh aspect of the present invention is a control method for a communication system including a first device and a second device connected to each other so as to be able to communicate via Bluetooth, wherein the first device has a first public key and a first private key of a public key cryptosystem, and the first device includes a first transmission step of transmitting a first advertising signal in the first device, the first advertising signal including signature information generated using a second private key of a public key cryptosystem, an identification signal that identifies the first device, and the first public key; a reception step of receiving the first advertising signal in the second device; a verification step of verifying the validity of the signature information included in the received first advertising signal using a pre-stored second public key of the public key cryptosystem; if the verification result in the verification step is positive, a generation step of generating connection information; and a second transmission step of transmitting a second advertising signal including the connection information encrypted using the first public key; and further includes a pairing step in the first device of decrypting the connection information included in the second advertising signal using the first private key, and pairing with the second device using the decrypted connection information.
[0073] The communication system according to each aspect of the present invention may be realized by a computer. In this case, the control program for the communication system that causes the computer to operate as each part (software element) of the communication system to realize the communication system, and the computer-readable recording medium on which the program is recorded, also fall within the scope of the present invention.
[0074] The present invention is not limited to the above-described embodiments, and various modifications are possible within the scope of the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. Furthermore, new technical features can be formed by combining the technical means disclosed in each embodiment. [Explanation of symbols]
[0075] 1. 1A Communication System 10 Signal Converter 101 First advertising signal generation unit 102 First Transmission Unit 103 Pairing Section 104 Storage section 20 detectors 201 Receiving unit 203 Verification Department 204 Second advertising signal generation unit 205 Second Transmission Unit 206 Pairing Section 207 Memory section 30 Production jig (signature information generating device) 50 mobile devices 60 sensors 70 Signature Server
Claims
1. A communication system including a first device and a second device communicatively connected to each other by Bluetooth (registered trademark), The first device is a first public key and a first private key of a public key cryptosystem; a first transmitting unit configured to transmit a first advertising signal including signature information generated by using a second private key of a public key cryptosystem, an identification signal for identifying the first device, and the first public key; The second device is A receiving unit that receives the first advertising signal; a verification unit that verifies the authenticity of the signature information included in the received first advertising signal by using a second public key of a public key cryptosystem that is stored in advance; a generating unit that generates connection information when a result of the verification by the verifying unit is valid; a second transmitting unit that transmits a second advertising signal including the connection information encrypted by the first public key, Further, the first device includes a pairing unit that uses the first private key to decrypt the connection information included in the second advertisement signal and uses the decrypted connection information to perform pairing with the second device.
2. The communication system according to claim 1 , wherein the signature information is generated by a signature information generating device different from the first device.
3. the generation unit generates the connection information with different content each time the connection information is generated; The communication system according to claim 1 , wherein the second device performs pairing with the first device only when a pairing request is received from the first device using the latest connection information.
4. the first device and the second device alternate between advertising and scanning; The communication system of claim 1 , wherein an interval between advertising and scanning of the first device is different from an interval between advertising and scanning of the second device.
5. The communication system according to claim 1 , wherein at least one of the first device and the second device performs advertising and scanning in parallel.
6. the second device is an underwater device used underwater, The communication system of claim 1 , wherein the first device is a signal converter for data obtained by the underwater device.
7. A control method for a communication system including a first device and a second device communicably connected to each other via Bluetooth, comprising: the first device has a first public key and a first private key of a public key cryptosystem; a first transmitting step in which, in the first device, a first advertising signal is transmitted, the first advertising signal including signature information generated using a second private key of a public key cryptosystem as identification information for identifying the first device, an identification signal for identifying the first device, and the first public key; In the second device, a receiving step of receiving the first advertising signal; a verification step of verifying the authenticity of the signature information included in the received first advertising signal by using a second public key of a public key cryptosystem that is stored in advance; a generating step of generating connection information if the verification result in the verifying step is positive; a second transmitting step of transmitting a second advertising signal including the connection information encrypted by the first public key; The method for controlling a communication system further includes a pairing step in which, in the first device, the connection information included in the second advertising signal is decrypted using the first private key, and the decrypted connection information is used to pair with the second device.
Citation Information
Patent Citations
Method and system for controlling access to wireless devices
JP2017502618A
Wireless communication system, terminal device, and wireless connection method
WO2019180844A1