Communication device, communication method, and communication program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-09
- Publication Date
- 2026-04-13
AI Technical Summary
Current IoT technology requires intervention from Internet Service Providers (ISPs) to manage IP addresses, which hinders user experience and convenience when connecting devices to communication networks.
A method involving a device generating a public key based on a private key, creating a hash value, and determining a network address without ISP intervention, using a cryptographic hash function and digital certificates for authentication.
Enables devices to connect to networks autonomously, improving user experience by eliminating the need for ISP management and ensuring secure, direct communication between devices.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing method, an information processing program, an information processing device, and an information processing system. [Background technology]
[0002] Information and communication technology has developed remarkably in recent years, and not only personal computers, smartphones, and tablets, but also all kinds of things, such as automobiles, home appliances, and sensor devices, are being connected to communication networks such as the Internet. Thus, it is predicted that an IoT (Internet of Things) society, in which trillions of devices on the planet will be connected to communication networks, will arrive in the near future (see Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japan Special Publication No. 2016-515328 Summary of the Invention [Problem to be solved by the invention]
[0004] As disclosed in Patent Document 1, in current IoT technology, Internet service providers (ISPs) manage the IP addresses of each device connected to the Internet. For example, when a specific device is connected to the Internet, the ISP assigns an IP address to the specific device. The specific device can then access a web server on the Internet using the IP address assigned by the ISP. Thus, when connecting a device to a communication network such as the Internet, the intervention of a service provider that manages IP addresses, such as an ISP, is required. This leaves room for improvement in terms of improving the user experience or user convenience when connecting to a communication network.
[0005] An object of the present disclosure is to provide an information processing method, an information processing program, an information processing device, and an information processing system that can improve the user experience or user convenience when connecting to a communication network. [Means for solving the problem]
[0006] An information processing method according to one aspect of the present disclosure is executed by a processor of a device, generating a public key for the device based on a private key of the device; generating a hash value based on the public key and a predetermined hash function; determining a network address of the device based on the hash value; Includes.
[0007] The information processing method may further include the step of generating the private key.
[0008] The information processing method may further include the step of transmitting the public key to an external device that is external to the device.
[0009] The information processing method may further include determining whether the hash value satisfies a predetermined condition. If the hash value satisfies the predetermined condition, the network address may be determined based on the hash value.
[0010] The information processing method may further include the step of generating the private key.
[0011] If the hash value does not satisfy the predetermined condition, the steps of generating the private key, generating the public key, and generating the hash value may be repeated until the hash value satisfies the predetermined condition.
[0012] The predetermined condition may include a condition associated with the first two digits of the hash value.
[0013] The predetermined conditions may also include conditions associated with the type of device.
[0014] Additionally, generating the hash value may include generating the hash value based on the public key, a value associated with a predetermined organization, and the predetermined hash function.
[0015] The value associated with the predetermined organization may also be a value associated with a trademark of the predetermined organization.
[0016] The information processing method may further include the step of obtaining a digital certificate associated with the public key from a certificate authority.
[0017] The information processing method may further include the step of transmitting the public key and the digital certificate to an external device that is external to the device.
[0018] The digital certificate may also include information relating to attributes of the device.
[0019] The digital certificate may also include attribute information of a user associated with the device.
[0020] The electronic certificate is: attribute information of the device and / or a user associated with the device; a hash value of the entire attribute information; and may include:
[0021] Also, a part of the attribute information may be hashed.
[0022] Furthermore, the part of the attribute information may be hashed based on the part of the attribute information and a predetermined coefficient.
[0023] The information processing method further comprises: receiving a public key of the external device from an external device external to the device; generating a hash value of the external device based on the public key of the external device and the predetermined hash function; The method may further include determining a network address of the external device based on a hash value of the external device.
[0024] The step of receiving the public key of the external device may include a step of receiving the public key of the external device and a digital certificate associated with the public key. The information processing method may further include a step of determining whether the digital certificate is valid. If the digital certificate is determined to be valid, the external device may be authenticated based on the public key of the external device. A hash value of the device may be generated.
[0025] An information processing method according to one aspect of the present disclosure includes, executed by a processor of a device, determining a network address of the device based on a public key of the device.
[0026] The information processing method may further include a step of performing communication using the network address of the device without going through a server that manages network addresses.
[0027] The information processing method may also be performed in the network layer of the OSI reference model.
[0028] Also provided is an information processing program for causing a computer to execute the information processing method, and a computer-readable storage medium on which the information processing program is stored.
[0029] According to one aspect of the present disclosure, there is provided an information processing device including at least one processor and a memory storing computer-readable instructions, the information processing device being configured to perform the information processing method when the computer-readable instructions are executed by the processor.
[0030] An information processing system according to one aspect of the present disclosure includes a first device and a second device communicatively connected to the first device.
[0031] The first device is generating a first public key of the first device based on a first private key of the first device; generating a first hash value based on the first public key and a predetermined hash function; determining a first network address of the first device based on the first hash value; The first public key is transmitted to the second device.
[0032] The second device is generating second public keys of the two devices based on a second private key of the second device; generating a second hash value based on the second public key and the predetermined hash function; determining a second network address of the second device based on the second hash value; The second public key is transmitted to the first device.
[0033] The first device is receiving the second public key from the second device; generating the second hash value based on the second public key and the predetermined hash function; The second network address is determined based on the second hash value.
[0034] The second device is receiving the first public key from the first device; generating the first hash value based on the first public key and the predetermined hash function; The first network address is determined based on the first hash value.
[0035] Further, the first device Sending the first public key to a certificate authority; obtaining a first digital certificate associated with the first public key from the certificate authority; The first digital certificate and the first public key may be transmitted to the second device.
[0036] The second device is sending the second public key to the certification authority or another certification authority; obtaining a second digital certificate associated with the second public key from the certification authority or the other certification authority; The second digital certificate and the second public key may be transmitted to the first device.
[0037] The first device is receiving the second public key and the second digital certificate from the second device; It may be determined whether the second digital certificate is valid.
[0038] The second device is receiving the first public key and the first digital certificate from the first device; It may be determined whether the first digital certificate is valid. [Effects of the Invention]
[0039] According to the present disclosure, it is possible to provide an information processing method, an information processing program, an information processing device, and an information processing system that can improve the user experience or user convenience when connecting to a communication network. [Brief explanation of the drawings]
[0040] [Figure 1] 1 is a diagram illustrating an example of a hardware configuration of an information processing device according to an embodiment of the present invention (hereinafter referred to as the present embodiment). [Figure 2] 10 is a flowchart illustrating an example of a process for determining an IP address of an information processing device. [Figure 3] FIG. 1 is a diagram illustrating an information processing device and a server on the Internet. [Figure 4]FIG. 1 is a diagram illustrating an information processing system including two information processing devices. [Figure 5] 10 is a flowchart illustrating an example of a process for determining an IP address of an external device. [Figure 6] 10 is a flowchart illustrating an example of a process for determining the validity of an electronic certificate transmitted from an external device. [Figure 7] FIG. 1 is a diagram illustrating an information processing system including four information processing devices. [Figure 8] 10A and 10B are diagrams illustrating an example of a digital certificate before and after a part of user attribute information is hashed. DETAILED DESCRIPTION OF THE INVENTION
[0041] The present embodiment will be described below with reference to the drawings. First, the hardware configuration of an information processing device 2 according to an embodiment of the present invention (hereinafter simply referred to as "the present embodiment") will be described with reference to FIG.
[0042] Fig. 1 is a diagram showing an example of the hardware configuration of an information processing device 2 according to this embodiment. As shown in Fig. 1, the information processing device 2 (hereinafter simply referred to as "device 2") includes a control unit 20, a storage device 23, a network interface 25, a display unit 26, and an input operation unit 27. These are connected to each other via a bus 29 so as to be able to communicate with each other.
[0043] The device 2 may be, for example, a personal computer, a smartphone, a tablet, or a wearable device (for example, a smart watch or AR glasses) that is attached to the user's body (for example, the arm or head). The device 2 may also be a control device installed in a smart home appliance, a connected automobile, a factory, or the like. In this way, the type of device 2 covers all things that are connected to a communication network such as the Internet using an IP address (an example of a network address) and that have a processor and memory. In this embodiment In the example, the device 2 includes a display unit 26 and an input operation unit 27, but these are not essential components of the device 2.
[0044] The control unit 20 is configured to control the operation of the device 2 and includes a memory and a processor. The memory is configured to store computer-readable instructions (for example, an information processing program). For example, the memory may be configured with a ROM (Read Only Memory) in which various programs are stored and a RAM (Random Access Memory) having multiple work areas in which various programs executed by the processor are stored. The memory may also be configured with a flash memory or the like. The processor may be configured with a CPU, an MPU (Micro Processing Unit), or the like. The CPU may be configured with multiple CPU cores. The GPU may be configured with multiple GPU cores. The processor may be configured to load a specified program from various programs stored in the storage device 23 or ROM onto the RAM and execute various processes in cooperation with the RAM. In particular, the processor is configured to execute the information processing method according to this embodiment by executing the information processing program stored in the memory.
[0045] The storage device 23 is, for example, a storage device such as a hard disk drive (HDD), a solid state drive (SSD), or a flash memory, and is configured to store programs and various data. The information processing program according to this embodiment transmitted from a server on the Internet may be stored in the storage device 23.
[0046] The network interface 25 is configured to connect the device 2 to a communication network. Specifically, the network interface 25 may include various wired connection terminals for communicating with external devices such as a server via the communication network. The network interface 25 may also include various processing circuits and antennas for communicating with a wireless router or a wireless base station. Examples of wireless communication standards include Wi-Fi (registered trademark), Bluetooth (registered trademark), ZigBee (registered trademark), LPWA, or a fifth-generation mobile communication system (5G). The communication network may include at least one of a local area network (LAN), a wide area network (WAN), a radio access network (RAN), and the Internet.
[0047] The display unit 26 may be a display device such as a liquid crystal display or an organic EL display, or may be a transmissive or non-transmissive head-mounted display that is worn on the operator's head. Furthermore, the display unit 26 may be a projector device that projects an image onto a screen.
[0048] The input operation unit 27 is configured to accept input operations by a user operating the device 2 and to generate instruction signals in response to the input operations. The input operation unit 27 is, for example, a touch panel placed over the display unit 26, operation buttons attached to the housing, a mouse and / or a keyboard, etc. After the instruction signals generated by the input operation unit 27 are transmitted to the control unit 20 via the bus 29, the control unit 20 executes a predetermined operation in response to the instruction signals. The display unit 26 and the input operation unit 27 may be connected to the device 2 via an input / output interface such as a USB.
[0049] Next, the information processing method according to this embodiment will be described below with reference to Fig. 2. Fig. 2 is a flowchart for explaining an example of a process for determining an IP address (for example, a global IP address) of the device 2. As shown in Fig. 2, in step S1, the device 2 The control unit 20 uses a random number generator to generate a private key for the device 2. Here, the random number generator may be realized by an OS program of the device 2, or may be realized as a hardware configuration (logic circuit, etc.) of the device 2. The size of the generated private key is, for example, 512 bits.
[0050] Next, in step S2, the control unit 20 generates a public key for the device 2 based on the generated private key and a predetermined encryption algorithm. Here, the predetermined encryption algorithm is, for example, an elliptic curve encryption algorithm. The size of the generated public key is, for example, 256 bits.
[0051] Next, in step S3, the control unit 20 generates a hash value based on the generated public key and a predetermined hash function. Here, the predetermined hash function is a cryptographic hash function, such as BLAKE. The size of the generated hash value is, for example, 256 bits.
[0052] In step S3, the control unit 20 may generate a hash value based on the generated public key, a value associated with the predetermined organization, and a predetermined hash function. Here, an example of the value associated with the predetermined organization is a value associated with the trademark of the predetermined organization. For example, if the predetermined organization uses trademark X (e.g., "connectFree"), the value of trademark X may be used to generate the hash value. In this case, it is possible to prevent a third party other than the predetermined organization from creating an information processing program for executing the information processing method according to this embodiment without the permission of the predetermined organization.
[0053] Next, the control unit 20 determines whether the generated hash value satisfies a condition associated with the first two digits (the first and second digits) of the hash value displayed in hexadecimal (step S4). In this regard, if the size of the hash value is 256 bits, the hash value is displayed as 64 hexadecimal digits. For example, if the first two digits of the hash value displayed as 64 digits are "FC" (i.e., hash value = FC...), the control unit 20 may determine that the hash value satisfies the determination condition of step S4. If the determination condition of step S4 is YES, the process proceeds to step S5. On the other hand, if the determination condition of step S4 is NO, the process proceeds to step S1. In other words, the processes of steps S1 to S3 are repeatedly executed until the determination condition of step S4 is satisfied.
[0054] Next, in step S5, the control unit 20 determines whether the hash value satisfies the condition associated with the type of device 2 (step S5). At this point, it is assumed that the type of device 2 associated with the IP address can be identified according to the values of the third and fourth digits from the beginning of the IP address expressed in hexadecimal. For example, it is assumed that the values of the third and fourth digits from the beginning of the IP address and the type of device have the following relationship:
[0055] [Table 1]
[0056] Here, if the third and fourth digits of the hash value expressed in hexadecimal match the third and fourth digits from the beginning of the IP address corresponding to the type of device 2, the determination condition of step S5 is met. For example, assume that the type of device 2 is a personal computer. In this case, the third and fourth digits from the beginning of the IP address of device 2 are “00.” Therefore, if the third and fourth digits from the beginning of the hash value expressed in hexadecimal are “00” (i.e., hash value = FC00...), the determination condition of step S5 is met. On the other hand, if the third and fourth digits from the beginning of the hash value are “11” (i.e., hash value = FC11...), the determination condition of step S5 is not met. If the determination condition of step S5 is YES, the process proceeds to step S6. On the other hand, if the determination condition of step S5 is NO, the process proceeds to step S1. In other words, the processes of steps S1 to S3 are repeatedly executed until the determination condition of step S5 is met. Note that step S5 may be omitted.
[0057] Next, the control unit 20 determines the IP address of device 2 based on the hash value that satisfies the determination conditions of steps S4 and S5 (step S6). For example, if the size of the hash value is 256 bits and an IP address (128 bits) corresponding to IPv6 is used as the IP address of device 2, the control unit 20 may determine the first 32 digits of the 64 digit hash value as the IP address of device 2. Alternatively, if the size of the hash value is 128 bits and an IP address (128 bits) corresponding to IPv6 is used as the IP address of device 2, the control unit 20 may determine all values of the 32 digit hash value as the IP address of device 2. Furthermore, if the size of the hash value is 256 bits and an IP address (32 bits) corresponding to IPv4 is used as the IP address of device 2, the control unit 20 may determine the first 8 digits of the 64 digit hash value as the IP address of device 2.
[0058] Note that, after the processing of step S6, a step of determining whether the determined IP address of device 2 overlaps with the IP address of another device may be provided. Specifically, after the processing of step S6, device 2 transmits information about the IP address of device 2 to an administration server that manages IP addresses via a communication network. The administration server determines whether the IP address transmitted from device 2 overlaps with one of the IP addresses included in the IP address management table stored in its own storage device. Here, if the IP address of device 2 overlaps with one of the IP addresses included in the IP address management table, the administration server may transmit a message to device 2 stating that registration of the IP address is rejected. In this case, device 2 executes the processing of steps S1 to S6 again and then transmits information about the determined IP address to the administration server again. On the other hand, if the IP address of device 2 does not overlap with any of the IP addresses included in the IP address management table, the administration server may transmit a message to device 2 stating that registration of the IP address is permitted.
[0059] Next, in step S7, the control unit 20 obtains an electronic certificate associated with the generated public key from a certification authority of a predetermined organization. That is, the user of device 2 registers the public key with the certification authority and obtains an electronic certificate associated with the registered public key from the certification authority. More specifically, the control unit 20 transmits the public key and an electronic certificate issuance request (certificate signing request) to the certification authority server via a communications network. Next, in response to the received electronic certificate issuance request, the certification authority server registers the public key and issues an electronic certificate associated with the public key. Thereafter, the certification authority server transmits the electronic certificate to device 2 via the communications network.
[0060] The certification authority of the specified organization may be an intermediate certification authority of the specified organization. Furthermore, payment of a specified fee may be required when obtaining a digital certificate related to the public key from the certification authority.
[0061] According to this embodiment, an IP address unique to the device 2 is determined based on the public key of the device 2. In this way, the device 2 can be connected to a communication network such as the Internet using the IP address determined by the device 2 itself. In particular, the device 2 can connect to the Internet using the IP address determined by the device 2 itself, without going through a service provider (server) that manages global IP addresses, such as an ISP. In this regard, as shown in FIG. 3 , a user U operating the device 2 can access a web server 6 on the Internet 4 by predetermined routing via the wireless LAN router 3, using the IP address determined by the device 2 itself. Furthermore, the device 2 can directly communicate with an external device using the IP address determined by the device 2 itself, without going through a server that manages private IP addresses (e.g., a DHCP server) (details will be described later).
[0062] Therefore, it is possible to provide an information processing method and device 2 that can improve the user experience or user convenience when connecting to a communication network such as the Internet.
[0063] Furthermore, according to this embodiment, it is possible to generate a hash value that satisfies the conditions of steps S4 and S5, that is, it is possible to generate an IP address that is associated with a hash value that satisfies the conditions of steps S4 and S5.
[0064] Specifically, the first two digits of the hash value displayed in hexadecimal can be set to a fixed value (for example, hash value = FC...). In other words, the first two digits of the IP address can be set to a fixed value (for example, IP address = FC...). This allows a third party to determine whether the IP address of device 2 is an IP address determined by device 2 itself.
[0065] Furthermore, in this embodiment, it is possible to generate a hash value according to the type of device 2. In other words, it is possible to generate an IP address according to the type of device 2. Therefore, a third party can identify the type of device 2 based on the IP address of the device 2.
[0066] Furthermore, in this embodiment, hash values are repeatedly generated until the determination conditions in steps S4 and S5 are met, so that an IP address associated with a hash value that meets the conditions in steps S4 and S5 can be reliably generated.
[0067] Furthermore, according to this embodiment, the public key is directly authenticated by the certification authority through the acquisition of the digital certificate, and the IP address determined based on the public key is also indirectly authenticated by the certification authority. In this way, the device 2 can connect to a communication network such as the Internet using an IP address that has been indirectly authenticated by a certification authority.
[0068] In the description of this embodiment, the private key of device 2 is generated using a random number generator of device 2, but the private key of device 2 may be provided by an external device communicatively connected to device 2. The order of the steps shown in Fig. 2 is not particularly limited. For example, the process of step S6 may be executed after the process of step S7.
[0069] Furthermore, the digital certificate associated with the public key may include information (attribute information) related to the attributes of device 2. The attribute information of device 2 may include, for example, at least one of version information of the OS program of device 2 and information related to the serial number of the hardware (e.g., processor, storage device, etc.) that constitutes device 2. Furthermore, the attribute information of device 2 included in the digital certificate may be encrypted using a hash function or the like. In this case, device 2 may send the attribute information of device 2 to the server of the certification authority when sending a request for issuance of a public key and digital certificate (certificate signing request). In this way, since the attribute information of device 2 is included in the digital certificate, it is authenticated that the digital certificate has been issued in accordance with the request of device 2. This effectively prevents devices other than device 2 from using the public key and digital certificate of device 2.
[0070] The digital certificate may also include attribute information of a user associated with the device 2 (e.g., the user who owns the device 2). Examples of user attribute information include the user's name, identification number, contact information, age, gender, address, or credit card information. Since the user's attribute information is included in the digital certificate, it is possible to effectively prevent a third party other than the user from using the public key and digital certificate of the device 2. Furthermore, when the device 2 transmits the digital certificate including the user's attribute information to a web server, the web server can verify the user attribute information included in the digital certificate. Therefore, the user of the device 2 can use online services (e.g., e-commerce sites) provided by the web server without registering user information, etc. In other words, the user of the device 2 can be freed from the hassle of managing login information (login ID and login password) for each online service, thereby providing the user with a rich online experience.
[0071] The digital certificate may also include a hash value of the attribute information of device 2 and / or the attribute information of the user (hereinafter, sometimes simply referred to as "attribute information"). The hash value is generated based on the attribute information and a cryptographic hash function. In this case, if the attribute information in the digital certificate is tampered with by a third party, the hash value will change, making it possible to detect tampering of the attribute information based on the hash value. For example, when device 2 transmits the digital certificate to an external device, the external device calculates a hash value of the attribute information in the digital certificate and determines whether the calculated hash value matches the hash value indicated in the digital certificate. If the calculated hash value matches the hash value indicated in the digital certificate, the external device determines that the attribute information in the digital certificate has not been tampered with. On the other hand, if the calculated hash value does not match, the external device determines that the attribute information in the digital certificate has been tampered with.
[0072] The digital certificate may also contain a hash value of all of the contents of the digital certificate. In this case, if a part of the contents of the digital certificate is tampered with by a third party, the hash value will change, and it will be possible to detect that the contents of the digital certificate have been tampered with by a third party based on the hash value.
[0073] As described above, the digital certificate includes attribute information of the device 2 and / or attribute information of the user. In this case, all of the attribute information written in the digital certificate may be transmitted to the external device. Alternatively, some of the attribute information described in the digital certificate may not be transmitted to the external device. That is, some of the attribute information described in the digital certificate may be hashed using a hash function. For example, as shown in FIG. 8, a user can hash the address, credit card information, and other information included in the user attribute information 40 described in the digital certificate 8 through an input operation on the device 2. In this way, the external device that receives the digital certificate 8 from the device 2 cannot identify the address and credit card information included in the user attribute information 40 described in the digital certificate 8, but can identify the user attribute information 40 other than the address and credit card information.
[0074] 8, the hash value of all attribute information when all attribute information is in a displayed state matches the hash value of all attribute information when some attribute information is in a hidden (hashed) state. Similarly, the hash value of all content described in the digital certificate when all attribute information is in a displayed state matches the hash value of all content described in the digital certificate when some attribute information is in a hidden (hashed) state. In other words, even if some attribute information is hashed, the hash value of all attribute information or the hash value of all content described in the digital certificate does not change, so tampering of the digital certificate by a third party can be easily detected based on the hash value.
[0075] Furthermore, hiding (hashing) part of the attribute information may be preset by the user or may be changeable in response to a request from an external device. It is anticipated that the original attribute information may be ascertained based on the hash value of the attribute information by referencing a database that indicates the relationship between the hash value and the original information. To prevent such a situation, the original attribute information may be hashed based on a predetermined coefficient and the original attribute information. In this case, the predetermined coefficient may be a constant or a variable that changes based on predetermined information (e.g., date information of a digital certificate, etc.).
[0076] Next, an information processing system 30 according to this embodiment will be described below, mainly with reference to Figures 4 and 5. Figure 4 is a diagram showing the information processing system 30 including an information processing device 2A (hereinafter simply referred to as "device 2A") and an information processing device 2B (hereinafter simply referred to as "device 2B"). Figure 5 is a flowchart illustrating an example of a process for determining the IP address of an external device.
[0077] In the information processing system 30 of this embodiment, for the sake of simplicity, the number of information processing devices connected to each other so as to be able to communicate with each other is set to two, but the number of information processing devices connected to each other so as to be able to communicate with each other may be three or more. Also, each of the devices 2A and 2B is assumed to have the hardware configuration of the device 2 shown in FIG.
[0078] Furthermore, it is assumed that each of devices 2A and 2B has already executed the process of determining the IP address shown in FIG. 2. That is, it is assumed that device 2A has already executed the process of determining the IP address of device 2A. Therefore, it is assumed that device 2A has already generated a public key 7A associated with the IP address of device 2A, as shown in FIG. 4, and has already obtained a digital certificate 8A associated with public key 7A from a certification authority. Similarly, it is assumed that device 2B has already executed the process of determining the IP address of device 2B. Therefore, it is assumed that device 2B has already generated a public key 7B associated with the IP address of device 2B, as shown in FIG. 4, and has already obtained a digital certificate 8B associated with public key 7B from a certification authority.
[0079] 5, in step S10, the device 2A (specifically, the control unit 20 of the device 2A) transmits (broadcasts) the public key 7A and the digital certificate 8A associated with the public key 7A to the outside of the device 2A. 2A receives the public key 7A and electronic certificate 8A broadcast from device 2A. Also, in step S11, device 2B (specifically, control unit 20 of device 2B) transmits (broadcasts) the public key 7B and the electronic certificate 8B associated with the public key 7B to the outside of device 2B. Thereafter, device 2A receives the public key 7B and electronic certificate 8B broadcast from device 2B. Note that the processing of step S11 may be performed simultaneously with the processing of step S10, or may be performed before the processing of step S10.
[0080] Next, in step S12, device 2B determines whether or not the digital certificate 8A broadcast from device 2A is valid. Here, the process of determining the validity of digital certificate 8A (i.e., the process of step S12) will be described below with reference to FIG.
[0081] As shown in FIG. 6, in step S20, device 2B determines the integrity of digital certificate 8A. Specifically, device 2B checks owner information, issuer information, and the issuer's digital signature of digital certificate 8A. Next, in step S21, device 2B determines the expiration date of digital certificate 8A. After that, in step S22, device 2B determines the trustworthiness of the issuer of digital certificate 8A. In particular, if the certification authority that issued digital certificate 8A is an intermediate certification authority, device 2B identifies the root certification authority of the intermediate certification authority that issued digital certificate 8A and determines whether the identified root certification authority is trustworthy. For example, if the identified root certification authority is included in information about multiple root certification authorities stored in the memory of device 2B, device 2B determines that the issuer of digital certificate 8A is trustworthy.
[0082] 5, when device 2B determines that digital certificate 8A is valid, it generates a hash value based on public key 7A and a predetermined hash function (step S13). Here, as already explained, the predetermined hash function is a cryptographic hash function such as BLAKE. In this embodiment, it is assumed that the hash function used by device 2B and the hash function used by device 2A are the same.
[0083] Next, in step S14, device 2B determines the IP address of device 2A based on the generated hash value. For example, as already explained, if the size of the hash value is 256 bits and an IP address (128 bits) corresponding to IPv6 is used as the IP address of device 2A, device 2B may determine the first 32 digits of the 64 digit hash value as the IP address of device 2A.
[0084] Meanwhile, in step S15, device 2A determines whether digital certificate 8B broadcast from device 2B is valid. The specific processing content of step S15 is as shown in FIG. 6. Next, if device 2A determines that digital certificate 8B is valid, it generates a hash value based on public key 7B and a predetermined hash function (step S16). As already explained, the hash function used by device 2A is the same as the hash function used by device 2B.
[0085] Thereafter, in step S17, device 2A determines the IP address of device 2B based on the generated hash value. As in the process of step S14, if the size of the hash value is 256 bits and an IP address (128 bits) corresponding to IPv6 is used as the IP address of device 2B, device 2A may determine the first 32 digits of the 64 digit hash value as the IP address of device 2B.
[0086] In this way, the device 2A can know the IP addresses of the devices 2A and 2B, and the device 2B can know the IP addresses of the devices 2A and 2B. Therefore, the devices 2A and 2B can be directly connected to each other without going through a server that manages IP addresses (i.e., (This allows P2P communication between devices 2A and 2B to be realized without going through a VPN server.) In particular, since it is not necessary to connect devices 2A and 2B via a virtual private network (VPN) server, the power consumption required for a direct connection between devices 2A and 2B can be significantly reduced. Furthermore, since it is not necessary to connect three or more devices directly via a VPN server, the power consumption required for a direct connection between three or more devices can be significantly reduced.
[0087] For example, device 2A can send a message to device 2B without going through a mail server or the like, which makes it possible to prevent a situation in which a message from device 2A is grasped by a third party (e.g., a server administrator, etc.). Furthermore, device 2A can send image data showing the screen of device 2A to device 2B without going through a VPN server. Meanwhile, device 2B can send an operation signal for operating the screen of device 2A to device 2A without going through a VPN server. In this way, the user of device 2B can remotely operate device 2A. Furthermore, devices 2A and 2B can share electronic files with each other without going through a file exchange server. This makes it possible to prevent a situation in which a shared electronic file is grasped by a third party.
[0088] Furthermore, when device 2A sends a message to device 2B (or when device 2B sends a message to device 2A), the message (packet) to be sent may be encrypted. For example, the message to be sent may be encrypted using a common key generated based on public key 7A of device 2A and public key 7B of device 2B. Furthermore, the common key may be changed every time a session between device 2A and device 2B is established. In this way, it is possible to achieve secure communication between device 2A and device 2B.
[0089] Furthermore, according to this embodiment, when the digital certificate transmitted from the external device is determined to be valid, a hash value of the external device is generated based on the public key of the external device. Then, the IP address of the external device is determined based on the hash value of the external device (here, device 2B is the external device from the perspective of device 2A, while device 2A is the external device from the perspective of device 2B). In this way, device 2A can confirm that the received public key 7B is the public key of device 2B. Furthermore, device 2A can confirm that the IP address generated based on public key 7B is the IP address of device 2B. Therefore, device 2A can reliably acquire the IP address of device 2B and can reliably communicate with device 2B using the IP address of device 2B.
[0090] On the other hand, device 2B can confirm that the received public key 7A is the public key of device 2A. Furthermore, device 2B can confirm that the IP address generated based on public key 7A is the IP address of device 2A. Therefore, device 2B can reliably obtain the IP address of device 2A and can reliably communicate with device 2A using the IP address of device 2A.
[0091] Furthermore, as described above, the information processing system according to this embodiment may have three or more information processing devices. For example, as shown in FIG. 7, assume that the information processing system 30A has four information processing devices 2A to 2D (hereinafter simply referred to as "devices 2A to 2D"). Here, each of the devices 2A to 2D has the hardware configuration of the device 2 shown in FIG. 1. In this case, each of the devices 2A to 2D executes the processes executed by the device 2A or device 2B shown in FIG. 5.
[0092] In this regard, device 2A broadcasts its public key and digital certificate to the outside world, and receives public keys and digital certificates from each of devices 2B to 2D located near device 2A. Device 2B broadcasts its public key and digital certificate to the outside world, and receives public keys and digital certificates from each of devices 2A, 2C, and 2D. Device 2C broadcasts its public key and digital certificate to the outside, and receives the public key and digital certificate from each of devices 2A, 2B, and 2D. Device 2D broadcasts its public key and digital certificate to the outside, and receives the public key and digital certificate from each of devices 2A to 2C.
[0093] Thereafter, device 2A determines IP addresses for devices 2B to 2D. Device 2B determines IP addresses for devices 2A, 2C, and 2D. Device 2C determines IP addresses for devices 2A, 2B, and 2D. Device 2D determines IP addresses for devices 2A to 2C. In this way, each of devices 2A to 2D can be directly connected to three external devices using the IP addresses of devices 2A to 2D. In other words, a mesh network can be configured by devices 2A to 2D. Furthermore, connection between devices 2A to 2D may be via predetermined routing in the communication network. Devices 2A to 2D can be connected to each other by forming an optimal route.
[0094] Furthermore, in the information processing system 30A shown in FIG. 7, the devices 2A to 2D each use the same hash function, and therefore a mesh network is configured by the devices 2A to 2D, but the present embodiment is not limited to this.
[0095] For example, devices 2A and 2B may use a first hash function, while devices 2C and 2D may use a second hash function that is different from the first hash function. In this case, devices 2A and 2B are communicatively connected to each other, and devices 2C and 2D are communicatively connected to each other. On the other hand, devices 2A and 2B are not communicatively connected to devices 2C and 2D. In this way, by using two different hash functions, two communication network groups can be constructed within information processing system 30A.
[0096] Furthermore, to realize the device 2 according to this embodiment by software, an information processing program may be pre-installed in the storage device 23 or ROM. Alternatively, the information processing program may be stored in a computer-readable storage medium such as a magnetic disk (e.g., HDD, floppy disk), optical disk (e.g., CD-ROM, DVD-ROM, Blu-ray (registered trademark) disk), magneto-optical disk (e.g., MO), or flash memory (e.g., SD card, USB memory, SSD). In this case, the information processing program stored in the computer-readable storage medium may be installed in the storage device 23. Furthermore, the information processing program installed in the storage device 23 may be loaded into RAM, and the processor may execute the information processing program loaded into RAM. In this way, the information processing method according to this embodiment is executed by the device 2.
[0097] The information processing program may also be stored in a storage medium (e.g., HDD) of a server on a communication network such as the Internet. In this case, the information processing program may be downloaded from the server via the network interface 25. In this case, the downloaded information processing program may also be installed in the storage device 23.
[0098] Furthermore, the information processing program (information processing method) according to this embodiment is executed by the network layer of the OSI (Open Systems Interconnection) reference model, which enables secure communications in the transport, session, presentation, and application layers of the OSI reference model, and also makes it possible to apply existing application programs and physical infrastructures as they are.
[0099] Although the embodiments of the present invention have been described above, the technical scope of the present invention should not be interpreted as being limited by the description of the present embodiments. The present embodiments are merely examples, and it is understood by those skilled in the art that various modifications of the embodiments are possible within the scope of the invention described in the claims. The technical scope of the present invention should be determined based on the scope of the invention described in the appended claims and their equivalents.
[0100] For example, in the process of step S7 shown in Figure 2, device 2 may obtain digital certificates associated with the public key of device 2 from the certification authorities of multiple organizations. The digital certificates may also include information related to the organizational attributes of the certification authorities. For example, if the digital certificate is issued by the certification authority of organization X, the digital certificate may include information related to the attributes of organization X.
[0101] 4, device 2A acquires multiple digital certificates 8A from certification authorities of multiple different organizations, and device 2B acquires multiple digital certificates 8B from certification authorities of multiple different organizations. In this case, device 2A transmits public key 7A and multiple digital certificates 8A to device 2B in step S10. Device 2B transmits public key 7B and multiple digital certificates 8B to device 2A in step S11. Furthermore, in step S12, after determining whether each of the multiple digital certificates 8A is valid, device 2B may determine whether at least one of the organizations of the multiple certification authorities that issued the multiple digital certificates 8A is included in an organization list indicating the organizations of the multiple certification authorities stored in the memory of device 2B. Specifically, device 2B may determine whether at least one of the organizations of the multiple certification authorities that issued the multiple digital certificates 8A is included in the organization list based on information related to the organization attributes included in the digital certificate 8A and the organization list. The device 2B may execute the processes of steps S13 and S14 when at least one of the organizations of the certification authorities that have issued the digital certificates 8A is included in the organization list.
[0102] Similarly, in step S15, after determining whether each of the multiple digital certificates 8B is valid, device 2A may determine whether at least one of the organizations of the multiple certification authorities that issued the multiple digital certificates 8B is included in an organization list indicating multiple organizations stored in the memory of device 2A. Specifically, device 2A may determine whether at least one of the organizations of the multiple certification authorities that issued the multiple digital certificates 8B is included in the organization list, based on information related to the attributes of the organization included in digital certificate 8B and the organization list. Device 2A may perform the processes of steps S16 and S17 when at least one of the organizations that issued the multiple digital certificates 8B is included in the organization list.
[0103] In this way, when the organization that issued the digital certificate for public key 7A is included in the list of organizations stored in device 2B and the organization that issued the digital certificate for public key 7B is included in the list of organizations stored in device 2A, device 2A and device 2B can be directly connected to each other. In other words, it is possible to select a communication partner according to conditions related to the organization that issued the digital certificate, and to configure multiple communication network groups within the information processing system.
[0104] In the above example, devices 2A and 2B acquire multiple digital certificates, but even when devices 2A and 2B acquire a single digital certificate, processing related to a determination condition related to the organization that issued the digital certificate may be applied. For example, if the organization of the certification authority that issued the digital certificate of device 2A is different from the organization of the certification authority that issued the digital certificate of device 2B, the processing of steps S13 and S14 (steps S16 and S17) may not be performed.
[0105] In this embodiment, an IP address, which is a network address corresponding to the Internet Protocol, is described as an example of the network address of the devices 2A and 2B, but the network address is not limited to an IP address. For example, the network addresses of the devices 2A and 2B may be network addresses corresponding to a predetermined communication protocol other than the Internet Protocol.
[0106] This application incorporates as appropriate the contents disclosed in a Japanese patent application (Patent Application No. 2018-166429) filed on September 5, 2018.
Claims
1. A communication device capable of communicating with other communication devices, A means of generating a private key, A means for determining whether the hash value generated based on the public key that forms the pair of the generated private key satisfies the conditions for being used as a network address, A means for repeating the generation of the private key until the above conditions are met, A communication device comprising means for determining the network address of the communication device based on a public key that satisfies the above conditions.
2. The communication device according to claim 1, wherein the condition includes a condition associated with the first two digits of the hash value, or a condition that the hash value includes a value associated with the type of communication device.
3. The means for generating the secret key includes a random number generator, as described in claim 1 or 2.
4. The communication device according to any one of claims 1 to 3, further comprising means for generating a public key that is a pair of the generated private key based on the generated private key and a predetermined cryptographic algorithm.
5. The communication device according to any one of claims 1 to 4, further comprising means for determining whether the determined network address overlaps with the network address of any other communication device.
6. The communication device according to any one of claims 1 to 5, further comprising means for providing the other communication device with a public key that satisfies the above conditions.
7. The communication device according to any one of claims 1 to 6, further comprising means for determining the network address of the other communication device based on the obtained second public key and the predetermined hash function, upon obtaining a second public key from the other communication device.
8. The communication device according to any one of claims 1 to 7, further comprising means for obtaining an electronic certificate associated with a public key that satisfies the aforementioned conditions.
9. A communication method for communicating with other communication devices, The steps to generate a private key, The steps include determining whether the hash value generated based on the public key that forms the pair of the generated private key satisfies the conditions for being used as a network address, The steps include repeating the generation of the private key until the above conditions are met, A communication method comprising the step of determining the network address of the communication device based on a public key that satisfies the above conditions.
10. A communication program for communicating with other communication devices, which is installed on a computer. The steps to generate a private key, The steps include determining whether the hash value generated based on the public key that forms the pair of the generated private key satisfies the conditions for being used as a network address, The steps include repeating the generation of the private key until the above conditions are met, A communication program that performs the step of determining the network address of the communication device based on a public key that satisfies the above conditions.