Measurement device, authentication device, information processing device, and authentication method
The token-based authentication system in measuring devices manages function licenses through randomly generated tokens and decryption keys, addressing unauthorized use and ensuring secure activation of extended functions, even in offline conditions.
Patent Information
- Application Number
- JP2024063190
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-10
- Publication Date
- 2025-10-23
AI Technical Summary
Conventional function activation mechanisms for measuring devices allow unauthorized use of extended functions due to ineffective license management, making it difficult to prevent duplication of release keys, especially in offline environments.
A measurement device with a token-based authentication system that includes a storage unit, measurement unit, and data processing control unit to manage function restrictions and decryption keys, using randomly generated tokens and decryption units to authenticate and enable functions, along with an authentication device to manage licenses and generate release keys.
The system effectively manages function licenses, preventing unauthorized use by ensuring legitimate activation of extended functions and maintaining security even in offline environments.
Smart Images

Figure 2025160578000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a measurement device, an authentication device, an information processing device, and an authentication method. [Background technology]
[0002] Conventionally, in measuring devices that measure the electrical characteristics of devices under test (DUTs) such as electrical equipment, batteries, and electronic components, a system has been known in which a user can purchase additional paid options (licenses) to use functions (also called "extended functions") that are not enabled at the time of shipment from among the various functions that the measuring device already has (see, for example, Patent Document 1).
[0003] For example, a user who has purchased a measurement device first purchases a paid option from a service provider such as the manufacturer of the measurement device to enable the extended functions of the measurement device. The service provider issues a release key for enabling the extended functions related to the purchased paid option, writes the release key to a storage medium such as a CD-ROM, and ships the CD-ROM to the user. The user copies the release key written on the received CD-ROM to a storage medium such as a USB memory stick and connects the storage medium to the measurement device. The measurement device reads the release key from the connected storage medium and enables the extended functions specified by the release key, allowing the user to use the extended functions of the measurement device. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 5791414 Summary of the Invention [Problem to be solved by the invention]
[0005] Conventional function activation mechanisms for measuring devices, such as those described in Patent Document 1, make it possible to use desired extended functions later without having to take the time and effort of bringing the purchased measuring device back to the service provider.
[0006] However, with conventional mechanisms for enabling extended functions in measurement devices, once a specific extended function of a measurement device has been enabled, the service provider is unable to effectively manage the license, making it difficult to prevent unauthorized use such as duplication of the release key. For example, it is difficult to prevent unauthorized use such as duplicating the release key and applying it to another measurement device.
[0007] On the other hand, in order to prevent unauthorized use, it is possible to consider a method in which the server that manages licenses on the service provider side and the measurement device are always able to communicate with each other via a wide area network such as the Internet, and the server monitors the license status of the measurement device. However, since measurement devices are often used in offline environments, it is not realistic to keep the measurement device always able to communicate.
[0008] The present invention has been made in view of the above-mentioned problems, and aims to provide a new mechanism for enabling functions provided in a measurement device. [Means for solving the problem]
[0009] A measurement device according to a representative embodiment of the present invention is a measurement device having a plurality of functions, and includes: a storage unit that stores programs for implementing the functions and encryption key information corresponding to a predetermined encryption method; a measurement unit that measures physical quantities related to a measurement object; and a data processing control unit that controls the measurement unit by executing the programs stored in the storage unit and switches between restricting the functions and lifting the restrictions on the functions, wherein the data processing control unit includes a token management unit that randomly generates a first token, which is information related to authentication, and stores it in the storage unit; and a data acquisition unit that acquires a decryption key encrypted based on the predetermined encryption method, the data acquisition unit including at least function identification information, which is information for identifying the functions, of the functions for which lifting of the restriction is permitted, and a second token, which is information related to the authentication. a decryption unit that decrypts the release key acquired by the data acquisition unit based on the encryption key information; a determination unit that determines whether the second token included in the release key decrypted by the decryption unit matches the first token stored in the memory unit; a function management unit that, if it is determined that the second token matches the first token, lifts the restriction on the function identified by the function identification information included in the release key, and, if it is determined that the second token does not match the first token, does not lift the restriction on the function identified by the function identification information included in the release key; and a measurement control unit that controls the measurement unit by executing the program corresponding to the function whose restriction has been lifted and not executing the program corresponding to the function that has been restricted. [Effects of the Invention]
[0010] The measurement device according to the present invention can provide a new mechanism for enabling the functions of the measurement device. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a diagram illustrating a configuration of an authentication system according to an embodiment. [Figure 2]FIG. 1 is a diagram showing a configuration of a measurement device according to an embodiment. [Figure 3A] FIG. 2 is a diagram illustrating a functional block configuration of the authentication device according to the embodiment. [Figure 3B] FIG. 2 is a diagram illustrating a hardware configuration of an authentication device according to an embodiment. [Figure 4A] FIG. 2 is a diagram showing a functional block configuration of the information processing device according to the embodiment. [Figure 4B] 1 is a diagram illustrating a hardware configuration of an information processing device according to an embodiment, and is a diagram illustrating an example of a configuration of a data processing control device in an inspection device according to an embodiment. [Figure 5A] FIG. 2 is a diagram showing a flow of an authentication method performed by the authentication system according to the embodiment. [Figure 5B] FIG. 2 is a diagram showing a flow of an authentication method performed by the authentication system according to the embodiment. [Figure 5C] FIG. 2 is a diagram showing a flow of an authentication method performed by the authentication system according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] 1. Overview of the embodiment First, a typical embodiment of the invention disclosed in this application will be outlined. In the following description, for example, reference numerals in the drawings corresponding to components of the invention are written in parentheses.
[0013] [1] A measurement device (2) according to a representative embodiment of the present invention is a device having multiple functions. The measurement device includes a storage unit (12) that stores a program for realizing the functions and encryption key information (120) corresponding to a predetermined encryption method, a measurement unit (13) that measures a physical quantity related to a device under test (DUT), and a data processing control unit (11) that controls the measurement unit by executing the program stored in the storage unit and switches between restricting the functions and releasing the restrictions on the functions. The data processing control unit includes a token management unit (16) that randomly generates a first token (122) that is information related to authentication and stores it in the storage unit, and a data acquisition unit (17) that acquires a decryption key (301) encrypted based on the predetermined encryption method. The data acquisition unit (17) includes at least function identification information (303) for the functions for which release of the restriction is permitted among function identification information that is information for identifying the functions, and a second token (302) for the authentication. ), a decryption unit (18) that decrypts the decryption key acquired by the data acquisition unit based on the encryption key information, a determination unit (19) that determines whether the second token included in the decryption key decrypted by the decryption unit matches the first token stored in the memory unit, a function management unit (20) that, when it is determined that the second token matches the first token, releases the restriction on the function identified by the function identification information included in the decryption key, and when it is determined that the second token does not match the first token, does not release the restriction on the function identified by the function identification information included in the decryption key, and a measurement control unit (21) that controls the measurement unit by executing the program corresponding to the function whose restriction has been released and not executing the program corresponding to the function that has been restricted.
[0014] [2] In the measurement device described in [1] above, the token management unit may delete the first token stored in the memory unit when the restriction on the function is released based on the release key.
[0015] [3] In the measurement device described in [1] or [2] above, the measurement device may further have a time management unit (22) that manages the time in the measurement device, and the release key includes expiration date information (305) that is information on an expiration date indicating the end of a period during which the restriction on the function can be lifted, and the function management unit may restrict the function whose restriction has been lifted based on the release key when the time managed by the time management unit reaches the expiration date based on the expiration date information.
[0016] [4] In the measurement device described in [3] above, the function management unit may restrict the function that has been released from restriction based on the release key when the time managed by the time management unit is changed.
[0017] [5] In the measurement device described in any one of [1] to [3] above, the release key includes device identification information (304) that is information for identifying the device, the memory unit stores the device identification information (124) that indicates the measurement device itself, the determination unit determines whether the device identification information included in the release key decrypted by the decryption unit matches the device identification information stored in the memory unit, and the function management unit may release the restriction on the function identified by the function identification information included in the release key when it is determined that the device identification information included in the release key matches the device identification information stored in the memory unit and the second token matches the first token.
[0018] [6] In the measurement device described in any one of [1] to [5] above, when the token management unit receives a request to send the first token from an external device, the token management unit may read out the first token stored in the memory unit and output it to the external device. Measuring equipment.
[0019] [7] A device according to a representative embodiment of the present invention is an authentication device (3) that manages whether or not a function of a measurement device (2) having multiple functions is restricted. The authentication device includes a storage unit (32) that stores device identification information, which is information for identifying a device to be managed, function identification information, which is information assigned to each function for identifying the function, and license information (310, 310_1 to 310_m), which is information in which license information is associated with each function and information assigned to each function indicating whether the function is available or not; a reception unit (33) that receives a release key issuance request (503) for requesting the issuance of a release key (301) for releasing the restriction on the function; the device identification information, which indicates the measurement device whose function restriction is to be released, the function identification information of the function whose restriction is to be released, and a token (122), which is information related to authentication; and a reception unit (33) that receives the release key issuance request (503). The device is characterized by having a license authentication unit (34) that, when a license request is received, determines whether the function identified by the function identification information received by the reception unit is available by referring to the license information corresponding to the measurement device identified by the device identification information received by the reception unit; a release key generation unit (35) that generates the release key by encrypting, based on a predetermined encryption method, a data set including at least the function identification information of the function for which restriction release is permitted and the token received by the reception unit when it is determined that the function is available; and an output unit (36) that outputs the release key generated by the release key generation unit.
[0020] [8] In the authentication device described in [7] above, the license information may include expiration date information (305) that indicates the end of a period during which the function restriction can be lifted, and the data set may further include the expiration date information.
[0021] [9] In the authentication device described in [7] or [8] above, the data set may include the device identification information indicating the measurement device for which the function restriction is to be lifted.
[0022]
[10] A device according to a representative embodiment of the present invention is an information processing device (4) capable of communicating with a measurement device (2) having multiple functions and an authentication device (3) that manages whether or not restrictions are placed on the functions of the measurement device. The information processing device includes a reception unit (33) that receives a function restriction release request for requesting the release of restrictions on a function that is restricted in the measurement device among the multiple functions, a first communication unit (43) that, upon receiving the function restriction release request, transmits a token transmission request (502) to the measurement device that is the target for the function restriction release, requesting the transmission of a token that is information related to authentication, and receives the token transmitted from the measurement device in response to the token transmission request, device identification information that is information for identifying the device, including the device identification information (412) of the measurement device that is the target for the function restriction release, and a function identification information that is assigned to each of the functions and is information for identifying the function. a memory unit (42) that stores the function identification information (411) of the function that is the target of restriction release among other information, and the token received by the first communication unit; a release key issuance request that requests the issuance of a release key (301) for releasing the restriction on the function specified by the function restriction release request; and a second communication unit (44) that transmits the token, the device identification information, and the function identification information stored in the memory unit to the authentication device and receives the release key transmitted from the authentication device in response to the release key issuance request, wherein the first communication unit transmits the release key received by the second communication unit to the measurement device that issued the token.
[0023]
[11] A method according to a representative embodiment of the present invention is an authentication method for determining whether to release restrictions on a function of a measurement device (2) having multiple functions by using an authentication device (3). The authentication device stores license information (310_1 to 310_m) in which device identification information, which is information for identifying a device to be managed, function identification information, which is information assigned to each function for identifying the function, and information assigned to each function indicating whether the function is available are associated with each other. The authentication method includes a first step (S13) in which the measurement device generates a token (122) that is information related to authentication; a second step (S14) in which the authentication device receives a release key issuance request requesting the issuance of a release key (301) for releasing the restriction on the function, the device identification information indicating the measurement device that is the target for releasing the restriction on the function, the function identification information of the function that is the target for releasing the restriction, and the token generated in the first step; a third step (S15) in which the authentication device references the license information of the measurement device identified by the device identification information received in the second step to determine whether the function identified by the function identification information received in the second step is available; and if it is determined in the third step that the function is available, the authentication device performs the release of the restriction. a fourth step (S16) of generating the decryption key by encrypting, based on a predetermined encryption method, a data set including at least the function identification information of the function to be permitted and the token accepted in the second step; a fifth step (S17) of the authentication device outputting the decryption key generated in the fourth step; a sixth step (S18) of the measurement device acquiring the decryption key output from the authentication device in the fifth step; a seventh step (S19) of the measurement device decrypting the decryption key acquired in the sixth step using encryption key information (120) corresponding to the predetermined encryption method; and an eighth step (S20) of the measurement device determining whether the token included in the decryption key decrypted in the seventh step matches the token generated in the first step.The method includes a ninth step (S21) in which the measurement device releases the restriction on the function identified by the function identification information included in the release key when it is determined in the eighth step that the token included in the release key matches the token generated in the first step, and a tenth step (S21) in which the measurement device does not release the restriction on the function identified by the function identification information included in the release key when it is determined in the eighth step that the token included in the release key does not match the token generated in the first step.
[0024] 2. Specific examples of embodiments Hereinafter, specific examples of embodiments of the present invention will be described with reference to the drawings. In the following description, components common to the embodiments will be designated by the same reference numerals, and repeated description will be omitted.
[0025] FIG. 1 is a diagram showing a configuration of an authentication system 1 according to an embodiment.
[0026] 1 is a system for restricting and lifting the functions of a measurement device 2 equipped with multiple functions. The authentication system 1 includes the measurement device 2, an information processing device 4, and an authentication device 3.
[0027] The measuring device 2 is a device for measuring the physical quantities of a device under test (hereinafter also referred to as "DUT"). The measuring device 2 is a device for measuring the electrical characteristics (e.g., voltage value, current value, impedance, etc.) of the DUT, such as an electrical device, a battery, or an electronic component. Examples of the measuring device 2 include various devices such as an LCR meter, an ohmmeter, a battery tester, a winding tester, a memory high-coder, and a power analyzer.
[0028] The measuring device 2 has multiple functions. The functions of the measuring device 2 include, for example, a standard function that is the main function of the measuring device 2, and an extended function. Examples of the extended function include a function that allows the time interval for logging measured values to be changed, and a function that allows special measurements such as high frequency characteristics to be made.
[0029] The standard functions are available for use, for example, from the time of shipment (when manufacturing is completed) of the measurement device 2. On the other hand, the extended functions are unavailable (functions are restricted) when the measurement device 2 is shipped. As will be described in detail later, a user purchases a license to use the extended functions from the service provider that is the manufacturer of the measurement device 2, and the authentication device 3 managed by the service provider issues a release key based on the purchased license. If the measurement device 2 determines that the release key is legitimate, the extended functions based on the purchased license become available in the measurement device 2 (function restrictions are lifted).
[0030] Each of the multiple functions of the measurement device 2 is assigned function identification information, which is information for identifying each function. The function identification information includes a unique value assigned to each function. For example, in this embodiment, it is assumed that the measurement device 2 has n functions (n is an integer equal to or greater than 2), and each function of the measurement device 2 is assigned a function identification information "function ID_1 to ID_n."
[0031] The authentication device 3 is a device that manages whether or not there are functional restrictions (licenses) on the measurement device 2 that has multiple functions. The authentication device 3 manages whether or not there are functional restrictions for each measurement device that it manages. The authentication device 3 is, for example, a program processing device such as a server. As will be described later, the authentication device 3 issues a release key 301 for releasing restrictions on functions (for example, extended functions) in the measurement device 2 in response to a request from a user.
[0032] The information processing device 4 is a device that assists in sending and receiving data between the measurement device 2 and the authentication device 3, and also functions as a user interface for the measurement device 2 and the authentication device 3. The information processing device 4 is, for example, a program processing device such as a personal computer (PC), a mobile terminal, or a tablet terminal. The information processing device 4 performs data communication with the measurement device 2 via wired or wireless communication based on a known communication standard, and also performs data communication with the authentication device 3 via a wide area network 5 such as the Internet based on a known communication standard.
[0033] The specific configurations of the measurement device 2, authentication device 3, and information processing device 4 will be described below with reference to the drawings. First, the configuration of the measurement device 2 will be described.
[0034] FIG. 2 is a diagram showing the configuration of a measurement device 2 according to an embodiment.
[0035] As shown in FIG. 2, the measurement device 2 includes, for example, a data processing control unit 11, a storage unit 12, a measurement unit 13, an operation unit 14, a display unit 15, and a time management unit 22.
[0036] The measurement unit 13 is a functional unit for measuring the physical quantities of the DUT. Based on the control of the data processing control unit 11, the measurement unit 13 applies a measurement signal (voltage or current) to the DUT, measures the electrical parameters (voltage, current, impedance, etc.) of the DUT at that time, and outputs the measurement results to the data processing control unit 11. The measurement unit 13 is composed of, for example, a voltage source or current source that generates the measurement signal (voltage or current), various sensors that measure the voltage or current applied to the DUT, and an A / D converter that converts the measurement signal from the sensor into a digital signal.
[0037] The operation unit 14 is a functional unit for inputting instructions to the measurement device 2. For example, when a user operates the operation unit 14, the operating conditions of the measurement device 2 and the conditions for the measurement process by the measurement unit 13 are set in the measurement device 2. The operation unit 14 provides a signal corresponding to the input operation to the data processing control unit 11. The operation unit 14 is composed of, for example, switches, buttons, a touch panel, etc.
[0038] The display unit 15 is a functional unit for displaying various types of information. Under the control of the data processing control unit 11, the display unit 15 displays an operating condition setting screen for setting the operating conditions of the measurement device 2, a measurement result display screen for displaying the measurement results obtained by the measurement unit 13, and the like. The display unit 15 is configured, for example, by a liquid crystal display, an organic EL display, or the like.
[0039] The time management unit 22 is a functional unit for managing the time in the measurement device 2. The time management unit 22 stores information about the current time and sequentially updates it. The time management unit 22 is configured by a known time management device such as a real-time clock (RTC) IC, for example.
[0040] The storage unit 12 is a functional unit for storing programs and various data for realizing the functions of the measurement device 2. The storage unit 12 is configured by a storage device having a non-volatile storage area, such as a flash memory or an HDD (Hard Disk Drive).
[0041] The storage unit 12 stores a first token 122 generated by the token management unit 16, which will be described later. The storage unit 12 is configured to be able to output at least the first token 122 to the outside.
[0042] The storage unit 12 stores, for example, a plurality of programs 121_1 to 121_n that respectively correspond to a plurality of functions (function ID_1 to ID_n) possessed by the measurement device 2 and that realize the corresponding functions. Hereinafter, when there is no need to distinguish between the programs 121_1 to 121_n, they will simply be referred to as "programs 121."
[0043] The programs 121_1 to 121_n correspond to the standard functions and extended functions described above, respectively. For example, as will be described later, the data processing control unit 11 executes the program 121_k corresponding to the extended function of the function ID_k, thereby realizing the extended function of the function ID_k in the measurement device 2.
[0044] The storage unit 12 stores encryption key information 120. The encryption key information 120 is information on an encryption key corresponding to a predetermined encryption method. Examples of the predetermined encryption method include a public key method and a common key method. In this embodiment, as an example, the predetermined encryption method is a public key method, and information on a secret key based on the public key method is stored in the storage unit 12 of the measurement device 2 as the encryption key information 120.
[0045] The storage unit 12 stores device identification information, which is information for identifying various devices including the measuring device 2. The device identification information includes a unique value assigned to each device. For example, in this embodiment, as an example, the measuring device 2 is assigned a device ID_j (j is an integer equal to or greater than 1) as a unique value identifying the measuring device 2 itself, and the "device ID_j" is stored in advance in the storage unit 12 as device identification information 124.
[0046] The storage unit 12 may further store function management information 123. The function management information 123 is information about the functions provided in the measurement device 2, and includes information indicating whether each function provided in the measurement device 2 is restricted.
[0047] For example, function management information 123 is information for identifying functions provided in measurement device 2, and includes unique identification information (hereinafter also referred to as "function identification information") assigned to each function provided in measurement device 2. Furthermore, function management information 123 includes, for each function identification information, information indicating whether or not a function related to that function identification information is restricted (whether or not execution of a program corresponding to the function is permitted / prohibited). Furthermore, if an end date (hereinafter also referred to as "expiration date") is set for a period during which the restriction can be lifted for a function provided in measurement device 2, function management information 123 may further include information indicating the expiration date (hereinafter also referred to as "expiration date information"). FIG. 2 shows, as an example, function management information 123 in which, for each of function ID_1 to ID_n corresponding to each function provided in measurement device 2, information indicating whether or not a restriction is restricted (whether or not execution of a program is permitted / prohibited) is associated with the expiration date information of each function.
[0048] The data processing control unit 11 is a functional unit that performs overall control of the measuring device 2. The data processing control unit 11 is realized by, for example, a program processing device. Specifically, the data processing control unit 11 is a program processing device (for example, a microcontroller) having a configuration in which a processor such as a CPU, various storage devices such as RAM and ROM, and peripheral circuits such as a counter (timer), an A / D conversion circuit, a D / A conversion circuit, a clock generation circuit, and an input / output I / F circuit are connected to each other via a bus or dedicated lines.
[0049] The data processing control unit 11 has a measurement control function that controls the measurement unit 13 by executing a program 121 stored in the storage unit 12. Specifically, when a user operates the operation unit 14 to instruct the measurement device 2 to execute a predetermined function among the functions provided by the measurement device 2, the data processing control unit 11 determines whether the predetermined function instructed to be executed is a "restricted function." If the predetermined function instructed to be executed is a "restricted function," the data processing control unit 11 reads out the program 121 corresponding to the predetermined function from the storage unit 12 and controls the measurement unit 13 and the display unit 15 in accordance with the read out program 121, thereby realizing the specified predetermined function. On the other hand, if the data processing control unit 11 determines that the predetermined function instructed to be executed is a "restricted function," it does not execute the program 121 corresponding to the specified function.
[0050] The data processing control unit 11 also has a function management function that switches between restricting and releasing the restriction on each function provided in the measurement device 2. Specifically, before releasing the restriction on a function, the data processing control unit 11 generates in advance a first token 122, which is information related to authentication. When a release key 301 for releasing the restriction on a function is input from outside, the data processing control unit 11 compares the token (second token 302) included in the release key 301 with the first token 122, and determines whether or not to release the restriction on the extended function specified by the release key 301 depending on the comparison result.
[0051] As shown in Figure 2, the data processing control unit 11 has a token management unit 16, a data acquisition unit 17, a decryption unit 18, a judgment unit 19, a function management unit 20, and a measurement control unit 21 as functional blocks for realizing the above-mentioned measurement control function and function management function.
[0052] The token management unit 16 is a functional unit that manages a first token 122, which is information related to authentication. The token management unit 16 randomly generates the first token 122. The first token 122 is, for example, data including a numerical value generated based on a known random number generation technique. The first token 122 may be a so-called one-time password.
[0053] The token management unit 16 stores the generated first token 122 in the storage unit 12. The token management unit 16 deletes the first token 122 stored in the storage unit 12 when a predetermined condition is satisfied.
[0054] Here, the specified conditions include, for example, that the restriction on the function specified by the release key 301 has been lifted based on the release key 301, that the time managed by the time management unit 22 has been changed, that a request to delete the first token 122 has been input to the measurement device 2, and that a request to update the token by deleting an existing token and generating a new token has been input to the measurement device 2.
[0055] As described above, the first token 122 stored in the storage unit 12 can be output to the outside. For example, when the token management unit 16 receives a token transmission request 502 from the outside (e.g., the information processing device 4), the token management unit 16 reads the first token 122 from the storage unit 12 and transmits it to the outside (e.g., the information processing device 4). At this time, if the first token 122 is not stored in the storage unit 12, the token management unit 16 generates a new first token 122 in response to the token transmission request 502, stores it in the storage unit 12, and transmits the generated first token 122 to the outside.
[0056] The data acquisition unit 17 is a functional unit that acquires data input from the outside. For example, the data acquisition unit 17 acquires a request 502 for requesting the transmission of a token (hereinafter also referred to as a "token transmission request") transmitted from the information processing device 4, and provides the request to the token management unit 16. Also, for example, the data acquisition unit 17 acquires the decryption key 301 transmitted from the information processing device 4, and stores the decryption key in the storage unit 12.
[0057] Here, the decryption key 301 is data encrypted based on the above-mentioned predetermined encryption method. The decryption key 301 is generated by the authentication device 3, as will be described in detail later.
[0058] Release key 301 includes, for example, at least function identification information 303 of a function (extended function) for which restriction release is permitted, and second token 302, which is information related to authentication. Release key 301 may also include, for example, expiration date information 305 indicating the expiration date of the function identified by function identification information 303. Release key 301 may also include device identification information 304 of measurement device 2, which is the target for releasing the function restriction. FIG. 2 shows, as an example, a case where release key 301 including second token 302, function ID_k (k is an integer equal to or greater than 1) as function identification information 303, device ID_j as device identification information 304, and expiration date information 305 is stored in storage unit 12.
[0059] The decryption unit 18 is a functional unit for decrypting the encrypted decryption key 301. The decryption unit 18 decrypts the decryption key 301 acquired by the data acquisition unit 17 based on the encryption key information 120 stored in the storage unit 12. The decryption unit 18 stores the information included in the decrypted decryption key 301 (the second token 302, the function identification information 303, the device identification information 304, and the expiration date information 305) in the storage unit 12. At this time, the decryption key 301 before decryption may continue to be held in the storage unit 12, or may be deleted after decryption.
[0060] The determination unit 19 is a functional unit that determines whether the second token 302 included in the decryption key 301 is valid. Specifically, the determination unit 19 determines whether the second token 302 included in the decryption key 301 decrypted by the decryption unit 18 matches the first token 122 stored in the storage unit 12, and outputs the determination result. Furthermore, the determination unit 19 may determine whether the device identification information 304 (device ID_j) included in the decryption key 301 matches the device identification information (device ID_j) stored in the storage unit 12, and output the determination result.
[0061] The function management unit 20 is a functional unit that switches between restricting and releasing the function restriction of the measurement device 2. When the determination unit 19 determines that the second token 302 matches the first token 122, the function management unit 20 releases the restriction on the function identified by the function identification information 303 included in the release key 301. Specifically, the function management unit 20 updates information in the function management information 123 stored in the storage unit 12 that indicates whether execution of a program corresponding to the function identified by the function identification information 303 (e.g., function ID_k) is permitted / prohibited (whether or not the function is restricted). For example, the function management unit 20 changes a value in the function management information 123 regarding whether or not execution of the program (function) identified by the function ID_k is permitted from "prohibited" to "permitted."
[0062] On the other hand, if the determination unit 19 determines that the second token 302 does not match the first token 122, the function management unit 20 does not release the restriction on the function identified by the function identification information 303 included in the release key 301. Specifically, the function management unit 20 does not update the information in the function management information 123 stored in the storage unit 12, which indicates whether execution of the program corresponding to the function (for example, function ID_k) identified by the function identification information 303 is permitted / prohibited (whether the function is restricted). In other words, the function management unit 20 maintains the value in the function management information 123 regarding whether execution of the program (function) identified by the function ID_k is permitted / prohibited.
[0063] Note that, when the release key 301 includes device identification information 304 (device ID_j), the function management unit 20 may determine whether to release the restriction on the function based not only on the determination result of the token but also on the determination result of the device identification information. For example, when it is determined that the device identification information 304 included in the release key 301 matches the device identification information 124 stored in the storage unit 12 and that the second token 302 matches the first token 122, the function management unit 20 may release the restriction on the function identified by the device identification information 304 included in the release key 301. On the other hand, when it is determined that at least one of the information of the device identification information 304 included in the release key 301 does not match the device identification information 124 stored in the storage unit 12 and the second token 302 does not match the first token 122, the function management unit 20 does not need to release the restriction on the function identified by the function identification information 303 included in the release key 301.
[0064] Furthermore, when the time managed by time management unit 22 reaches the end of the period specified by expiration date information 305, function management unit 20 restricts the function for which the restriction has been released based on release key 301. For example, when the time managed by time management unit 22 exceeds the expiration date (end) of the extended function specified by function identification information 303 (function ID_k), function management unit 20 changes the value regarding whether or not the program of the extended function specified by function identification information 303 (function ID_k) can be executed from "permitted" to "not permitted."
[0065] Furthermore, when the time managed by the time management unit 22 is changed, the function management unit 20 restricts the function for which the restriction has been released based on the release key 301. For example, when the user operates the operation unit 14 to delay or advance the time managed by the time management unit 22, the function management unit 20 determines that the time managed by the time management unit 22 has been changed. In this case, the function management unit 20 changes the value relating to the execution permission of the program corresponding to the function ID_k in the function management information 123 from "permitted" to "not permitted" for the extended function corresponding to the function ID_k for which the restriction has been released based on the release key 301.
[0066] The measurement control unit 21 is a functional unit that controls the measurement unit 13. The measurement control unit 21 controls the measurement unit 13 by executing a program 121 corresponding to a function for which restriction has been lifted, among a plurality of programs 121_1 to 121_n stored in the storage unit 12, and not executing a program 121 corresponding to a function for which restriction has been lifted. For example, when an instruction to execute an extended function identified by function ID_k is given via the operation unit 14, the measurement control unit 21 refers to function management information 123 stored in the storage unit 12, and determines whether or not the extended function identified by function ID_k is in an unrestricted state (permitted).
[0067] When the extended function identified by function ID_k is not restricted (permitted), measurement control unit 21 reads out program 121_k corresponding to the extended function identified by function ID_k from storage unit 12, and controls measurement unit 13, display unit 15, etc. in accordance with program 121_k. This allows the extended function identified by function ID_k to be realized in measurement device 2. On the other hand, when the extended function identified by function ID_k is restricted (not permitted), measurement control unit 21 reads out program 121_k corresponding to the extended function identified by function ID_k from storage unit 12, and controls measurement unit 13, display unit 15, etc. in accordance with program 121_k. This allows the extended function identified by function ID_k to be realized in measurement device 2.
[0068] On the other hand, if the extended function identified by function ID_k is in a restricted state (not permitted), measurement control unit 21 does not execute program 121_k corresponding to the extended function identified by "function ID_k." In this case, measurement control unit 21 may cause display unit 15 to display information indicating that the extended function identified by function ID_k is not available.
[0069] Next, the authentication device 3 will be described.
[0070] FIG. 3A is a diagram showing a configuration of functional blocks of the authentication device 3 according to the embodiment. FIG. 3B is a diagram showing a hardware configuration of the authentication device 3 according to the embodiment.
[0071] 3A, the authentication device 3 has, as functional blocks, a data processing control unit 31 and a storage unit 32. The data processing control unit 31 includes, for example, a reception unit 33, a license authentication unit 34, a release key generation unit 35, and an output unit 36.
[0072] As shown in FIG. 3B, the authentication device 3 is configured by a program processing device such as a server, as described above, and has a calculation device 101, a storage device 102, an input device 103, an I / F (Interface) device 104, an output device 105, and a bus 106 as its main hardware components.
[0073] The arithmetic device 101 is configured with a processor such as a CPU. The storage device 102 has a storage area for storing programs 1021 for causing the arithmetic device 101 to execute various data processing operations, and data 1022 such as parameters and calculation results used in the data processing by the arithmetic device 101, and is configured with, for example, a ROM (Read Only Memory), a RAM (Random Access Memory), a HDD, a flash memory, etc.
[0074] The input device 103 is a functional unit that detects input of information from the outside, and is composed of, for example, a keyboard, a mouse, a pointing device, buttons, a touch panel, etc. The I / F device 104 is a functional unit that sends and receives information to and from the outside, and is composed of a communication control circuit, an input / output port, an antenna, etc. for wired or wireless communication.
[0075] The output device 105 is a functional unit that outputs information obtained by data processing by the arithmetic device 101, and is composed of, for example, a display device such as an LCD (Liquid Crystal Display) or an organic EL (Electro Luminescence) display, and a display control circuit that controls the display of information on the display. The bus 106 is a functional unit that interconnects the arithmetic device 101, the storage device 102, the input device 103, the I / F device 104, and the output device 105, enabling data exchange between these devices. Note that the output device 105 does not have to be provided within the authentication device 3.
[0076] In the authentication device 3, each functional block shown in Fig. 3A is realized by the hardware resources shown in Fig. 3B working in cooperation with software. That is, the arithmetic device 101 executes calculations in accordance with the program 1021 stored in the storage device 102, and controls the storage device 102, the input device 103, the I / F device 104, the output device 105, and the bus 106, thereby realizing functional blocks such as the data processing control unit 31 (reception unit 33, license authentication unit 34, release key generation unit 35, and output unit 36) and the storage unit 32 shown in Fig. 3A.
[0077] The authentication device 3 may be realized by a single computer as shown in FIG. 3B, or may be realized by multiple computers connected to each other so that they can communicate with each other via wired or wireless communication, and the hardware configuration of the authentication device 3 is not limited to the example of FIG. 3B.
[0078] Each functional block constituting the authentication device 3 will be described below.
[0079] The storage unit 32 is a functional unit that stores license information 310_1 to 310_m (m is an integer equal to or greater than 2) for each device to be managed.
[0080] The license information 310_1 to 310_m is data in which device identification information (device ID_1 to ID_m) of the device to be managed (measurement device 2), function identification information (function ID_1 to ID_n) of each function of the device, and information indicating whether each function is available are associated with each other. Furthermore, if an expiration date is set for the function of the measurement device 2, the license information 310_1 to 310_m may include information on the expiration date.
[0081] For example, license information 310_1 to 310_m is stored in storage unit 32 for each piece of device identification information (device ID_1 to ID_m). For example, Fig. 3A shows a case where license information 310_1 to 310_m, in which information indicating whether a function can be used (whether or not program execution is permitted) is associated with information on the expiration date of each function for each function ID_1 to ID_n, is stored in storage unit 32 for each measurement device to be managed. Hereinafter, when there is no need to distinguish between the license information 310_1 to 310_m, they will be referred to as "license information 310."
[0082] For example, if a user has purchased a license for one function (function ID_k) among the extended functions of the measurement device 2 (device ID_j) but has not purchased licenses for the other extended functions, in license information 310_j for the measurement device 2 with device ID_j, the value relating to whether the program corresponding to function ID_k can be executed is set to “Permitted (Can be used),” and the values relating to whether the programs corresponding to the other extended functions can be executed are set to “Not permitted (Cannot be used).” If the permitted function ID_k has an expiration date, the expiration date information (yyyy / mm / dd) is also set.
[0083] Encryption key information 120A corresponding to a predetermined encryption method is stored in the storage unit 32. The encryption key information 120A is information on an encryption key corresponding to the encryption key information 120 stored in the above-mentioned measurement device 2. As described above, when the predetermined encryption method is a public key method, it is assumed that information on a public key and a private key based on the public key method is stored in the storage unit 12 of the measurement device 2 as the encryption key information 120A.
[0084] The reception unit 33 is a functional unit that externally receives requests and various data for the authentication device 3. The reception unit 33 receives a request (referred to as a "release key issuance request") 210, sent from, for example, the information processing device 4, for issuing a release key 301 for releasing restrictions on the functions of the measurement device 2.
[0085] In addition, in relation to the release key issuance request 210, the reception unit 33 receives from an external device (e.g., the information processing device 4) device identification information 412 (device ID_j) indicating the device to be released from the restriction, function identification information (function ID_k) 411 indicating the function to be released from the restriction, and a token (first token 122) which is information regarding authentication.
[0086] Here, if the release key issuance request 210 is legitimate, the token acquired by the reception unit 33 is the first token 122 generated by the measurement device 2 that is the target for lifting restrictions. The above-mentioned device identification information 412, function identification information 411, and token (first token 122) related to the target for lifting restrictions on functions may be included in the release key issuance request 210, or may be input to the authentication device 3 separately from the release key issuance request 210. The reception unit 33 stores the received data, etc. in the storage unit 32.
[0087] The license authentication unit 34 is a functional unit for determining whether a function can be used. When the reception unit 33 receives the release key issuance request 210, the license authentication unit 34 determines whether the function of the measurement device 2 specified in the release key issuance request 210 is available for use. Specifically, the license authentication unit 34 references the license information 310 related to the measurement device 2 identified by the device identification information 412 (e.g., device ID_j) acquired in association with the release key issuance request 210, determines whether the function identified by the function identification information 411 (e.g., function ID_k) acquired in association with the release key issuance request 210 is available for use, and outputs the determination result.
[0088] The release key generation unit 35 is a functional unit that generates a release key 301 based on the determination result by the license authentication unit 34. When it is determined that the function for which release of restrictions is requested by the release key issuance request 210 is available, the release key generation unit 35 generates a release key 301 for permitting the release of restrictions on that function. For example, the release key generation unit 35 generates the release key 301 by encrypting a data set including at least function identification information 303 of the permitted function and a second token 302 based on a predetermined encryption method, and stores the generated release key in the storage unit 32.
[0089] For example, consider a case where the lifting of restrictions on a function identified by function ID_k is permitted in a measurement device 2 identified by device ID_j. In this case, the release key generation unit 35 first reads out from the storage unit 32 the first token 122 previously acquired by the reception unit 33, sets it as the second token 302, and generates a data set including at least the second token 302 (first token 122) and device identification information 304 (function ID_k). Next, the release key generation unit 35 encrypts the generated data set using encryption key information 120A (e.g., a public key) stored in the storage unit 32. Then, the release key generation unit 35 stores the encrypted data set in the storage unit 32 as the release key 301.
[0090] In this case, the data set may include, in addition to the second token 302 and function identification information 303 (function ID_k), device identification information 304 (device ID_j) indicating the device from which the function is to be deactivated, and expiration date information 305 indicating the expiration date of the function to be deactivated.
[0091] The output unit 36 is a functional unit that outputs the release key 301. The output unit 36 reads the release key 301 generated by the release key generation unit 35 from the storage unit 32, and outputs it to an external device (for example, the information processing device 4) as a response to the release key issue request 210.
[0092] Next, the information processing device 4 will be described. FIG. 4A is a diagram showing a functional block configuration of an information processing device 4 according to an embodiment. FIG. 4B is a diagram showing a hardware configuration of information processing device 4 according to the embodiment.
[0093] The information processing device 4 is a device capable of communicating with the measurement device 2 having multiple functions and the authentication device 3 that stores license information 310. As shown in Fig. 4A, the information processing device 4 has a reception unit 41, a first communication unit 43, a storage unit 42, and a second communication unit 44 as functional blocks.
[0094] As shown in FIG. 4B, the information processing device 4 is configured by a program processing device such as a personal computer, a mobile terminal, or a tablet terminal, as described above, and has an arithmetic unit 201, a memory unit 202, an input unit 203, an I / F (Interface) unit 204, an output unit 205, and a bus 206 as its main hardware components.
[0095] The arithmetic device 201 is configured with a processor such as a CPU. The storage device 202 has a storage area for storing programs 2021 for causing the arithmetic device 201 to execute various data processing operations, and data 2022 such as parameters and calculation results used in the data processing by the arithmetic device 201, and is configured with, for example, a ROM (Read Only Memory), a RAM (Random Access Memory), a HDD, a flash memory, etc.
[0096] The input device 203 is a functional unit that detects input of information from the outside, and is composed of, for example, a keyboard, a mouse, a pointing device, buttons, a touch panel, etc. The I / F device 204 is a functional unit that sends and receives information to and from the outside, and is composed of a communication control circuit, an input / output port, an antenna, etc. for wired or wireless communication.
[0097] The output device 205 is a functional unit that outputs information obtained by data processing by the arithmetic unit 201, and is composed of, for example, a display device such as an LCD or organic EL, and a display control circuit that controls the display of information on the display. The bus 206 is a functional unit that interconnects the arithmetic unit 201, the storage device 202, the input device 203, the I / F device 204, and the output device 205, enabling data to be exchanged among these devices.
[0098] In the information processing device 4, each functional block shown in Fig. 4A is realized by the hardware resources shown in Fig. 4B working in cooperation with software. That is, the arithmetic device 101 executes calculations in accordance with the program 2021 stored in the storage device 102, and controls the storage device 202, the input device 203, the I / F device 204, the output device 205, and the bus 206, thereby realizing functional blocks such as the reception unit 41, the first communication unit 43, the storage unit 42, and the second communication unit 44 shown in Fig. 4A.
[0099] Here, examples of the program 2021 include a dedicated application program and a web browser for causing the information processing device 4 to function as a user interface device for the measurement device 2 and the authentication device 3. Furthermore, the functional blocks constituting the information processing device 4 may be realized using an API (Application Programming Interface) in addition to the above-mentioned program 2021.
[0100] Hereinafter, each functional block constituting the information processing device 4 will be described.
[0101] The reception unit 41 is a functional unit that externally receives requests and various data for the information processing device 4. The reception unit 41 receives, for example, a request (also referred to as a “function restriction release request”) 501 for requesting that restrictions on functions that are restricted in the measurement device 2 be lifted.
[0102] Furthermore, the reception unit 41 receives information related to the function restriction release request 501 along with the function restriction release request 501. The information related to the function restriction release request 501 includes, for example, device identification information (device ID_j) 412 indicating the measurement device 2 that is the target for releasing the function restriction, and function identification information (function ID_k) 411 indicating the function that is the target for releasing the restriction. The reception unit 41 stores the received device identification information 412 and function identification information 411 in the storage unit 42.
[0103] The data of the function restriction release request 501, device identification information 412, and function identification information 411 are input to the information processing device 4, for example, by the user operating the input device 203. For example, information about the measuring device and information about the functions (extended functions) provided by the measuring device are displayed in a selectable manner on a display device serving as the output device 205 of the information processing device 4. Then, the user operates the input device 203 to select the measuring device and function for which the release of the function restriction is requested from the displayed information, and when an instruction to release the restriction on the selected function is input, the function restriction release request 501 and information related to the function restriction release request 501 are input to the reception unit 41.
[0104] The first communication unit 43 is a functional unit for transmitting and receiving data to and from the measurement device 2. As described above, the first communication unit 43 performs data communication with the measurement device 2 via wired or wireless communication based on a known communication standard. Here, the communication between the first communication unit 43 and the measurement device 2 may be, for example, wired communication based on a known communication standard using a USB cable, a LAN cable, or the like, or may be known short-range wireless communication such as Wi-Fi or Bluetooth (registered trademark), and the communication method, etc., is not particularly limited.
[0105] When the receiving unit 41 receives the function restriction release request 501, the first communication unit 43 transmits a token transmission request 502 to the measurement device 2 that is the target for function restriction release. The first communication unit 43 also receives the first token 122 transmitted from the measurement device 2 as a response to the token transmission request 502, and stores it in the storage unit 42.
[0106] Furthermore, the first communication unit 43 transmits the release key 301 received by the second communication unit 44 (described later) to the measurement device 2 that issued the first token 122.
[0107] The storage unit 42 is a functional unit that stores various data. As described above, the storage unit 42 stores the first token 122 received by the first communication unit 43, the device identification information 412, and the function identification information 411.
[0108] The storage unit 42 may also store information (hereinafter also referred to as "device management information") related to the licenses of the measurement devices 2 registered as management targets of the information processing device 4. For example, when the information processing device 4 manages measurement devices 2_1 to 2_p (p is an integer of 2 or more), the storage unit 42 may store device management information 415_1 to 415_p generated for each of the device IDs ID_1 to ID_p.
[0109] The device management information 415_1 to 415_p may include the same information as the license information 310 stored in the authentication device 3. The device management information 415_1 to 415_p may be stored in the storage unit 42 by the information processing device 4 accessing the authentication device 3 and receiving the license information 310 (or a part of the license information 310) from the authentication device 3.
[0110] The second communication unit 44 is a functional unit for transmitting and receiving data to and from the authentication device 3. As described above, the second communication unit 44 performs data communication with the measurement device 2 based on a known communication standard via a wide area network 5 such as the Internet.
[0111] The second communication unit 44 transmits to the authentication device 3 a release key issue request 503 requesting the issuance of a release key 301 for releasing the restriction on the function specified by the function restriction release request 501 .
[0112] Furthermore, in response to the transmission of the release key issuance request 503, the second communication unit 44 reads from the storage unit 42 the device identification information 412, function identification information 411, and first token 122 related to the measurement device 2 for which function release is specified by the function restriction release request 501, and transmits them to the authentication device 3. Note that the device identification information 412, function identification information 411, and first token 122 may be included in the release key issuance request 503, or may be transmitted to the authentication device 3 separately from the release key issuance request 503.
[0113] The second communication unit 44 further receives the release key 301 transmitted from the authentication device 3 in response to the release key issue request 503. The second communication unit 44 stores the received release key 301 in the storage unit 42.
[0114] Next, the flow of the authentication method by the authentication system 1 will be described.
[0115] 5A to 5C are diagrams showing the flow of the authentication method by the authentication system 1 according to the embodiment.
[0116] In the following description, as an example, it is assumed that a dedicated application program (program 2021) is pre-installed in the storage device 202 of the information processing device 4, and that when a user operates the information processing device 4 to execute the dedicated application program, the information processing device 4 functions as a user interface device for performing license authentication for the measurement device 2. Furthermore, as a prerequisite, it is assumed that the user has purchased a license for an extended function identified by function ID_k among the functions possessed by the measurement device 2 identified by device ID_j.
[0117] 5A to 5C show the flow of processing when an extended function (function ID_k), which is one of the functions of the measurement device 2 (device ID_j), is made available to the measurement device 2.
[0118] First, for example, a user operates the information processing device 4 to input a function restriction release request 501 to the information processing device 4 (step S11). The function restriction release request 501 includes at least, for example, device identification information 412 (device ID_j) of the measuring device 2 that is the target of function restriction release, and function identification information 411 (function ID_k) that indicates the function that is the target of function restriction release. For example, the receiving unit 41 receives the function restriction release request 501 input to the information processing device 4, and stores the device identification information 412 (device ID_j) and function identification information 411 (function ID_k) included in the function restriction release request 501 in the storage unit 42.
[0119] In response to receiving the function restriction release request 501, the information processing device 4 transmits a token transmission request 502 to the measurement device 2 (step S12). Specifically, the first communication unit 43 transmits the token transmission request 502 to the measurement device 2 identified by the device identification information 412 (device ID_j) included in the function restriction release request 501.
[0120] Upon receiving the token transmission request 502, the measurement device 2 issues a token (step S13). Specifically, in the measurement device 2, the token manager 16 generates the first token 122 by the above-described method, stores the first token 122 in the storage unit 12, and transmits the first token 122 to the information processing device 4. At this time, the measurement device 2 may transmit its own device identification information 124 (device ID_j) to the information processing device 4 in addition to the first token 122.
[0121] Next, the information processing device 4 transmits a release key issuance request 503 to the authentication device 3 (step S14). Specifically, first, in the information processing device 4, the first communication unit 43 receives the first token 122 transmitted from the measurement device 2 in step S13 and stores it in the storage unit 42. Next, the second communication unit 44 transmits to the authentication device 3 the release key issuance request 503, which includes, for example, the device identification information 412 (device ID_j) of the measurement device 2 specified in the function restriction release request 501, the function identification information 411 (function ID_k) of the function specified in the function restriction release request 501, and the first token 122 stored in the storage unit 42.
[0122] When the authentication device 3 receives the release key issuance request 503 transmitted from the information processing device 4 in step S14, the authentication device 3 executes authentication processing (step S15). Specifically, in the authentication device 3, first, the reception unit 33 receives the release key issuance request 503 and stores the device identification information 412 (device ID_j), function identification information 411 (function ID_k), and first token 122 included in the release key issuance request 503 in the storage unit 32. Next, the license authentication unit 34 refers to the license information 310_j corresponding to the measurement device 2 identified by the device identification information 412 (device ID_j) stored in the storage unit 32, using the method described above, and determines whether the function identified by the function identification information 411 (function ID_k) stored in the storage unit 32 is available for use.
[0123] If the function identified by the function identification information (function ID_k) is not available, the output unit 36 in the authentication device 3 transmits data indicating that the decryption key cannot be issued to the information processing device 4 as a response to the decryption key issuance request 503.
[0124] On the other hand, if the function identified by the function identification information (function ID_k) is available, the authentication device 3 executes a process for generating the release key 301 (step S16). Specifically, in the authentication device 3, the release key generation unit 35 encrypts a data set including the device identification information 412 (device ID_j) and function identification information 411 (function ID_k) included in the release key issue request 503, the second token 302, and the expiration date information 305 set in the license information 310_j, using the method described above, and stores the encrypted data set in the storage unit 32 as the release key 301. At this time, the release key generation unit 35 generates the data set using the first token 122 transmitted from the information processing device 4 to the authentication device 3 in step S14 as the second token 302.
[0125] Next, the authentication device 3 transmits the release key 301 to the information processing device 4 (step S17). For example, in the authentication device 3, the output unit 36 reads out the release key 301 from the storage unit 32 and transmits it to the information processing device 4 as a response to the release key issue request 503.
[0126] The information processing device 4 transfers the release key 301 sent from the authentication device 3 in step S17 to the measurement device 2 (step S18). Specifically, in the information processing device 4, the second communication unit 44 receives the release key 301 from the authentication device 3 and stores it in the memory unit 42. Next, the first communication unit 43 reads out the release key 301 stored in the memory unit 42 and sends it to the measurement device 2.
[0127] Here, the transfer of the release key 301 to the measuring device 2 may be performed immediately after the second communication unit 44 receives the release key 301, or may be performed after the second communication unit 44 receives the release key 301 and when the user instructs the information processing device 4 to transfer the release key in response to an operation signal input to the information processing device 4.
[0128] The measurement device 2 decrypts the received decryption key 301 (step S19). Specifically, in the measurement device 2, the decryption unit 18 decrypts the encrypted decryption key 301 using the encryption key information 120 stored in the storage unit 12, thereby reading out the second token 302, function identification information (function ID_k) 303, device identification information (device ID_j) 304, and expiration date information 305 included in the decryption key 301, and stores them in the storage unit 12.
[0129] Next, the measurement device 2 performs token verification (step S20). Specifically, in the measurement device 2, the determination unit 19 compares the second token 302 extracted from the release key 301 in step S19 with the first token 122 stored in the storage unit 12, and determines whether the second token 302 and the first token 122 match. At this time, the determination unit 19 may determine whether the device identification information 304 included in the release key 301 matches the device identification information 124 stored in the storage unit 12, as described above.
[0130] If second token 302 and first token 122 match, measurement device 2 releases the restriction on the function specified by release key 301 (step S21). Specifically, in measurement device 2, function management unit 20 changes a value relating to whether or not to allow execution of a program corresponding to a function identified by function identification information 303 (function ID_k) included in release key 301, among the functions set in function management information 123 stored in storage unit 12, from "not permitted" to "permitted." This allows the user to execute extended function program 121_k identified by function ID_k in measurement device 2.
[0131] On the other hand, if the second token 302 and the first token 122 do not match, the measurement device 2 does not release the restriction on the function (function ID_k) specified by the release key 301, and sends information to the information processing device 4 indicating that the release of the function restriction is not permitted.
[0132] Next, the measurement device 2 deletes the token (step S22). Specifically, in the measurement device 2, the token manager 16 deletes the first token 122 stored in the storage unit 12. At this time, the decryption key 301 may also be deleted.
[0133] Thereafter, for example, suppose that the user operates the measurement device 2 and changes the information on the time managed by the time management unit 22 (step S23). In this case, the measurement device 2 again restricts the function (function ID_k) for which restriction was released in step S21 (step S24). Specifically, when the function management unit 20 determines that the time managed by the time management unit 22 has been changed, it changes the value in the function management information 123 regarding whether or not to execute the program corresponding to the function (function ID_k) for which restriction was released in step S21 from "permitted" to "not permitted." At this time, if the first token 122 is stored in the storage unit 12 of the measurement device 2, the token management unit 16 deletes the first token 122 stored in the storage unit 12 (step S25).
[0134] As described above, according to the measuring device 2 of the embodiment, when lifting the restriction on a specific function among the multiple functions that the measuring device 2 has, the measuring device 2 compares the second token 302 included in the release key 301 for lifting the restriction on the specific function, which is input from outside, with the first token 122 that the measuring device 2 randomly generated in advance, and lifts the restriction on the specific function if the second token 302 matches the first token 122.
[0135] As described above, when a user has officially purchased a license for an extended function of the measurement device 2, the authentication device 3 issues a release key 301 using a unique first token 122 generated by the measurement device 2 that is the subject of the license. Therefore, when the legitimate release key 301 is applied to the measurement device 2, the second token 302 (=first token 122) included in the release key 301 matches the first token 122 generated by the measurement device 2, and the restriction on the extended function related to the license purchased in the measurement device 2 can be released. On the other hand, for example, when the release key 301 is applied to another measurement device that has the same type of function as the measurement device 2, or when a duplicated release key 301 is applied to another measurement device, the first token 122 generated by the other measurement device does not match the first token 122 included in the release key 301, and therefore the restriction on the extended function will not be released in the other measurement device.
[0136] In this way, according to the measurement device 2 of the embodiment, restrictions on the extended functions can be lifted only for legitimate products for which a license has been purchased, making it possible to prevent unauthorized use of licenses related to the extended functions.
[0137] Furthermore, according to the measurement device 2, the functions newly added to the measurement device 2 to prevent the above-mentioned fraudulent use (for example, issuing and storing the first token 122 and decrypting the release key, etc.) are limited, so there is no need for high-performance microcontrollers as hardware resources or complex programs as software, and the cost of the measurement device 2 can be kept from increasing.
[0138] Furthermore, when the restriction on the function is released based on the release key 301, the measurement device 2 deletes the first token 122 stored in the storage unit 12. This makes it possible to more reliably prevent unauthorized use. This will be explained in detail below. If the first token 122 is not deleted, the following type of fraudulent use may occur. For example, a user may copy the release key 301 generated using the first token 122 within the validity period and store it on a PC or other device owned by the user. Subsequently, the user may perform some fraudulent operation, causing the measurement device 2 to revert from a state in which the restriction on the extended function was released to a state in which the extended function was restricted. In this case, if the first token 122 is not deleted, the measurement device 2 may reuse the copied release key 301 to release the restriction on the extended function again. Therefore, the measurement device 2 according to this embodiment deletes the first token 122 from the storage unit 12 when the restriction on the function is released based on the release key 301. This makes it possible to prevent the above-mentioned fraudulent use.
[0139] Furthermore, when the time managed by the time management unit 22 reaches the expiration date based on the expiration date information 305, the measurement device 2 restricts the functions for which the restriction has been released based on the release key 301. This allows the measurement device 2 to independently control the restriction and release of functions based on the expiration date, even if the measurement device 2 is not in a state where it can communicate with the authentication device 3.
[0140] Furthermore, when the time managed by the time management unit 22 is changed, the measurement device 2 again restricts the functions that have been released from restriction based on the release key 301. This makes it possible to prevent fraudulent use, such as extending the effective usage period of an extended function by turning back the time in the measurement device 2 before the expiration date.
[0141] Furthermore, when it is determined that the device identification information 304 included in the release key 301 matches the device identification information 124 stored in the storage unit 12 and that the second token 302 matches the first token 122, the measurement device 2 releases the restriction on the function identified by the function identification information 303 included in the release key 301. This allows the restriction on the function to be released not only when the tokens match but also when the device identification information matches, making it possible to more reliably prevent unauthorized use.
[0142] When the authentication device 3 according to the embodiment receives a release key issuance request 503 requesting the issuance of a release key 301 for releasing restrictions on a function of the measurement device 2, device identification information 412 indicating the measurement device 2 for which the function restrictions are to be released, function identification information 411 indicating the function for which the restrictions are to be released, and a token (first token 122) that is information related to authentication, the authentication device 3 references license information 310 corresponding to the measurement device 2 identified by the received device identification information 412, and determines whether the function identified by the received function identification information 411 is available for use. This allows the authentication device 3 to manage licenses for the measurement device 2.
[0143] Furthermore, when the authentication device 3 references the license information 310 and determines that the specified function is available, it generates the decryption key 301 by encrypting, based on a predetermined encryption method, a data set that includes at least function identification information 303 indicating the function for which removal of restrictions is permitted and the first token 122, which is the accepted token. This makes it possible to issue the decryption key 301 that corresponds only to a measurement device 2 that has legitimately purchased a license for the extended function. Furthermore, by outputting the encrypted data set as the decryption key 301, it is possible to improve security in the transmission and reception of the decryption key 301.
[0144] As described above, according to the authentication method using the authentication system 1 including the measurement device 2 and the authentication device 3, the authentication device 3 can manage the licenses for the extended functions for each measurement device 2, while the measurement device 2 can control the restriction and release of the extended functions. Therefore, even if the authentication device 3 and the measurement device 2 are not able to communicate at all times, it is possible to manage licenses and prevent unauthorized use.
[0145] Furthermore, when an information processing device 4 capable of communicating with the measurement device 2 and the authentication device 3 receives a function restriction release request 501 for a measurement device 2 that is to be managed in response to a user operation, the information processing device 4 transmits a token transmission request 502 to the measurement device 2 that is the target for function restriction release, and receives a first token 122 transmitted from the measurement device 2 in response to the token transmission request 502. The information processing device 4 transmits to the authentication device 3 a release key issuance request 503 requesting the issuance of a release key 301 for releasing the restriction on the function specified in the function restriction release request 501, along with the first token 122, device identification information 304, and function identification information 303 received from the measurement device 2, and receives the release key 301 transmitted from the authentication device 3 in response to the release key issuance request 503. The information processing device 4 transmits the received release key 301 to the measurement device 2 that is the issuer of the first token 122.
[0146] In this way, with the information processing device 4, even if the measurement device 2 and the authentication device 3 cannot directly communicate data with each other, the first token 122 can be issued, the release key 301 can be issued, and the release key 301 can be transferred by using a personal computer or tablet terminal owned by the user. In other words, the information processing device 4 can be used as a user interface for the measurement device 2 and the authentication device 3, thereby improving the ease of use for the user regarding license authentication of the measurement device 2.
[0147] <<Extension of Embodiment>> The invention made by the inventor of the present application has been specifically described above based on an embodiment, but it goes without saying that the present invention is not limited thereto and can be modified in various ways without departing from the spirit of the invention.
[0148] For example, in the above embodiment, the case where communication between the measurement device 2 and the authentication device 3 is realized via the information processing device 4 has been exemplified, but this is not limiting. For example, if the measurement device 2 and the authentication device 3 can communicate with each other via the wide area network 5, the information processing device 4 does not need to be used. In this case, it is sufficient to provide at least the reception unit 41, the second communication unit 44, and the storage unit 42 provided in the information processing device 4 within the measurement device 2.
[0149] Furthermore, while the above embodiment illustrates the case where restriction and release of extended functions of the measurement device 2 are controlled, the above-mentioned method may also be used to restrict and release standard functions of the measurement device 2. For example, when the time managed by the time management unit 22 is changed, the function management unit 20 of the measurement device 2 may control the restriction of some or all of the standard functions in addition to the extended functions whose restrictions have been released by the release key 301.
[0150] The above sequence diagram shows an example for explaining the operation, and is not limited to this. In other words, each step shown in the sequence diagram is a specific example, and is not limited to this flow. For example, the order of some processes may be changed, other processes may be inserted between each process, or some processes may be performed in parallel. [Explanation of symbols]
[0151] 1...authentication system, 2...measurement device, 3...authentication device, 4...information processing device, 5...wide area network, 11...data processing control unit, 12...storage unit, 13...measurement unit, 14...operation unit, 15...display unit, 16...token management unit, 17...data acquisition unit, 18...decryption unit, 19...judgment unit, 20...function management unit, 21...measurement control unit, 22...time management unit, 31...data processing control unit, 32...storage unit, 33...reception unit, 34...license authentication unit, 35...release key generation unit, 36...output unit, 41...reception unit, 42...storage unit, 43...first communication unit, 44...second communication unit, 1 20...Encryption key information, 120A...Encryption key information, 121, 121_1 to 121_n...Program, 122...First token, 123...Function management information, 124...Device identification information, 210...Release key issuance request, 301...Release key, 303...Function identification information, 304...Device identification information, 305...Expiration date information, 310, 310_1 to 310_m...License information, 411...Function identification information, 412...Device identification information, 415_1 to 415_p...Device management information, 501...Request to release function restriction, 502...Token transmission request, 503...Release key issuance request.
Claims
1. A multi-function measuring device, a storage unit that stores a program for realizing the function and encryption key information corresponding to a predetermined encryption method; a measurement unit that measures a physical quantity related to a measurement object; a data processing control unit that controls the measurement unit by executing the program stored in the storage unit and switches between limiting the function and releasing the function restriction, The data processing control unit a token management unit that randomly generates a first token, which is information related to authentication, and stores the first token in the storage unit; a data acquisition unit that acquires a decryption key encrypted based on the predetermined encryption method, the decryption key including at least function identification information for the function for which derestriction is permitted to be released, which is information for identifying the function, and a second token, which is information related to the authentication; a decryption unit that decrypts the decryption key acquired by the data acquisition unit based on the encryption key information; a determination unit that determines whether the second token included in the decryption key decrypted by the decryption unit matches the first token stored in the storage unit; a function management unit that, when it is determined that the second token matches the first token, releases the restriction on the function identified by the function identification information included in the release key, and, when it is determined that the second token does not match the first token, does not release the restriction on the function identified by the function identification information included in the release key; a measurement control unit that controls the measurement unit by executing the program corresponding to the function whose restriction has been released and not executing the program corresponding to the function that has been restricted. Measuring device.
2. 2. The measuring device according to claim 1, The token management unit deletes the first token stored in the storage unit when the restriction on the function is released based on the release key. Measuring device.
3. 3. The measuring device according to claim 2, a time management unit that manages the time in the measurement device; the release key includes expiration date information that indicates the end of a period during which the restriction on the function can be released, The function management unit restricts the function whose restriction has been released based on the release key when the time managed by the time management unit reaches the expiration date based on the expiration date information. Measuring device.
4. 4. The measuring device according to claim 3, The function management unit restricts the function whose restriction has been released based on the release key when the time managed by the time management unit is changed. Measuring device.
5. 2. The measuring device according to claim 1, the decryption key includes device identification information that is information for identifying the device, the storage unit stores the device identification information that identifies the measuring device itself; the determination unit determines whether the device identification information included in the decryption key decrypted by the decryption unit matches the device identification information stored in the storage unit; The function management unit releases the restriction on the function identified by the function identification information included in the release key when it is determined that the device identification information included in the release key matches the device identification information stored in the storage unit and that the second token matches the first token. Measuring device.
6. 2. The measuring device according to claim 1, When receiving a request to transmit the first token from an external device, the token management unit reads out the first token stored in the storage unit and outputs the first token to the external device. Measuring device.
7. An authentication device that manages whether or not a function of a measurement device having multiple functions is restricted, a storage unit that stores device identification information, which is information for identifying a device to be managed, function identification information, which is information assigned to each function for identifying the function, and license information, which is information assigned to each function and indicating whether the function is available, in association with each other; a receiving unit that receives a release key issuance request for issuing a release key for releasing the restriction on the function, the device identification information indicating the measurement device that is the target for releasing the restriction on the function, the function identification information of the function that is the target for releasing the restriction, and a token that is information related to authentication; a license authentication unit that, when the reception unit receives the release key issuance request, references the license information corresponding to the measurement device identified by the device identification information received by the reception unit and determines whether the function identified by the function identification information received by the reception unit is available; a decryption key generation unit that generates the decryption key by encrypting, based on a predetermined encryption method, a data set that includes at least the function identification information of the function for which restriction release is permitted and the token accepted by the acceptance unit when it is determined that the function is available for use; an output unit that outputs the decryption key generated by the decryption key generation unit; Authentication device.
8. 8. The authentication device according to claim 7, the license information includes expiration date information that indicates the end of a period during which the restriction on the function can be lifted, The data set further includes the expiration date information. Authentication device.
9. 9. The authentication device according to claim 8, The data set includes the device identification information that indicates the measuring device for which the function restriction is to be released. Authentication device.
10. An information processing device capable of communicating with a measurement device having a plurality of functions and an authentication device that manages whether or not the functions of the measurement device are restricted, a receiving unit that receives a function restriction release request for requesting release of a function that is restricted in the measurement device among the plurality of functions; a first communication unit that, when receiving the function restriction release request, transmits a token transmission request to the measurement device that is the target for function restriction release, requesting transmission of a token that is information related to authentication, and receives the token transmitted from the measurement device in response to the token transmission request; a storage unit that stores the device identification information of the measuring device that is the target for lifting the restriction on the function among device identification information that is information for identifying a device, the function identification information of the function that is the target for lifting the restriction among function identification information that is information assigned to each function and for identifying the function, and the token received by the first communication unit; a second communication unit that transmits a release key issuance request for requesting the issuance of a release key for releasing the restriction on the function specified by the function restriction release request, and the token, the device identification information, and the function identification information stored in the storage unit to the authentication device, and receives the release key transmitted from the authentication device in response to the release key issuance request; The first communication unit transmits the decryption key received by the second communication unit to the measurement device that issued the token. Information processing device.
11. A license authentication method for determining whether or not to release restrictions on functions in a measurement device having a plurality of functions, using an authentication device and the measurement device, wherein the authentication device stores license information in which device identification information, which is information for identifying a device to be managed, function identification information, which is information assigned to each function for identifying the function, and information assigned to each function indicating whether the function is available are associated with each other; a first step in which the measurement device generates a token that is information related to authentication; a second step in which the authentication device receives a release key issuance request for issuing a release key for releasing the restriction on the function, the device identification information indicating the measurement device whose function restriction is to be released, the function identification information of the function whose restriction is to be released, and the token generated in the first step; a third step in which the authentication device refers to the license information of the measurement device identified by the device identification information received in the second step and determines whether the function identified by the function identification information received in the second step is available; a fourth step in which, when it is determined in the third step that the function is available, the authentication device generates the decryption key by encrypting, based on a predetermined encryption method, a data set including at least the function identification information of the function for which restriction release is permitted and the token accepted in the second step; a fifth step in which the authentication device outputs the decryption key generated in the fourth step; a sixth step in which the measurement device acquires the decryption key output from the authentication device in the fifth step; a seventh step in which the measurement device decrypts the decryption key acquired in the sixth step using encryption key information corresponding to the predetermined encryption method; an eighth step in which the measurement device determines whether the token included in the decryption key decrypted in the seventh step matches the token generated in the first step; a ninth step in which, when it is determined in the eighth step that the token included in the release key matches the token generated in the first step, the measurement device releases the restriction on the function identified by the function identification information included in the release key; a tenth step in which, when it is determined in the eighth step that the token included in the release key does not match the token generated in the first step, the measurement device does not release the restriction on the function identified by the function identification information included in the release key. License activation method.
Citation Information
Patent Citations
Detecting apparatus of liquid volume
JP1982091414A