Security systems, security methods, and authentication devices
The security system addresses the vulnerability of electronic key systems to relay attacks by implementing dual authentication and dynamic information transfer to prevent unauthorized use, enhancing security through redundant verification and real-time updates.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-03
AI Technical Summary
Existing countermeasures against relay attacks on vehicles with electronic key systems are not sufficiently robust, allowing for unauthorized access and use.
A security system that performs dual authentication using device-side and other device-side authentication information, transferring this information between multiple devices to ensure it is only present on a specific device, and updating it based on usage status to prevent unauthorized use.
Enhances security by ensuring only legitimate devices can operate, preventing unauthorized access through dual authentication and dynamic information updates, thus improving security against relay attacks.
Smart Images

Figure 2026057922000001_ABST
Abstract
Description
Technical Field
[0005] ,
[0001] The present invention relates to a security system, a security method, and an authentication device.
Background Art
[0002] Conventionally, as disclosed in Patent Document 1, a relay attack is well-known as a method of stealing a vehicle equipped with an electronic key system. A relay attack is an act of illegally unlocking a vehicle door or illegally starting an engine by relaying radio waves communicated between an electronic key and a vehicle using, for example, one or more repeaters.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Although various countermeasures against relay attacks have been proposed so far, there are also various types of theft acts using illegal communication. Therefore, the countermeasures known so far are not perfect, and a countermeasure capable of preventing illegal use of articles such as vehicles equipped with an electronic key system with high accuracy has been required.
Means for Solving the Problems
[0005] A security system that solves the aforementioned problem outputs device-side authentication information registered on a device to other devices, and as at least one condition for permitting the operation of the other devices, it checks whether the other device-side authentication information registered on the other device is matched with the device-side authentication information to confirm the success or failure of the match, and includes an information transfer unit that moves the other device-side authentication information between a first other device, which is one of the other devices, and a second other device, which is another of the other devices, so that the other device-side authentication information exists only on a specific other device among a plurality of other devices. [Effects of the Invention]
[0006] This invention can improve security against unauthorized use. [Brief explanation of the drawing]
[0007] [Figure 1] This is a configuration diagram of a security system according to one embodiment. [Figure 2] This is a schematic diagram of the locking device. [Figure 3] This is a sequence diagram showing the procedure for authenticating a device. [Figure 4] This is a diagram illustrating the configuration of the authentication information transfer function within the security system. [Figure 5] This is an explanatory diagram showing the registration of the first and second other devices. [Figure 6] (a) to (d) are explanatory diagrams showing the flow of actions when going out. [Figure 7] This is an explanatory diagram showing how to update authentication information on the device side and authentication information on other devices. [Figure 8] (a) to (c) are explanatory diagrams showing the flow of actions when returning home. [Modes for carrying out the invention]
[0008] An embodiment of this disclosure is described below. (Security System 1) As shown in Figure 1, the security system 1 includes a device 2 to which unique key information Dk is registered. Device 2 is, for example, a terminal 3 capable of wireless communication. Terminal 3 is, for example, a high-function mobile phone such as a smartphone. Authentication is performed between device 2 and other devices 4 that are to be operated. Other devices 4 are access points used by the user to enter and exit, such as a residence 5 where the user lives or a vehicle 6 used by the user. Preferably, the key information Dk is, for example, a one-time key that is permitted to be used only once or for a limited period of time.
[0009] Device 2 includes a control unit 8 that controls the operation of Device 2, and a memory 9 that stores key information Dk. Device 2's memory 9 stores device-side authentication information Dm, which is authenticated together with the key information Dk. Device-side authentication information Dm is, for example, information linked to the key information Dk and is compared with other device-side authentication information Dt registered in other device 4. Authentication of security system 1 is redundant, consisting of authentication of key information Dk and authentication of device-side authentication information Dm. In this example, authentication of key information Dk is referred to as "primary authentication," and the comparison of device-side authentication information Dm with other device-side authentication information Dt is referred to as "secondary authentication." Device-side authentication information Dm and other device-side authentication information Dt are, for example, random data of arbitrary length.
[0010] The control unit 8 is composed of various elements, such as a microprocessor. In this example, the control unit 8 performs authentication with other device 4 using key information Dk and device-side authentication information Dm. In this example, the operation of other device 4 is permitted or executed only if at least the authentication of key information Dk and the matching of device-side authentication information Dm and other device-side authentication information Dt are successful.
[0011] Other device 4 has an authentication device 10 that authenticates device 2. The authentication device 10 is composed of various elements, such as a microprocessor. The authentication device 10 has a memory 11 in which other device-side authentication information Dt is stored. The authentication device 10 may be pre-installed on other device 4 or may be added to other device 4 afterwards. The authentication device 10 performs authentication of key information Dk obtained from device 2 and authenticates device 2 by comparing the device-side authentication information Dm obtained from device 2 with its own other device-side authentication information Dt.
[0012] Communication between device 2 and other device 4 uses, for example, short-range wireless communication. Short-range wireless communication may be a PAN (Personal Area Network) or short-range wireless communication. Examples of personal area network communication include Bluetooth (registered trademark) communication, UWB (Ultra Wide Band) communication, and Wi-Fi (registered trademark) communication. Examples of Bluetooth communication include BLE (Bluetooth Low Energy).
[0013] Other device 4 has a door 13 that can be opened and closed at the entrance to the other device 4 when other device 4 is the target of entry and exit. The door 13 has a locking device 14 for locking the door 13. The authentication device 10 switches between locking and unlocking the door 13 by controlling the locking and unlocking operation of the locking device 14 based on the authentication results of primary and secondary authentication.
[0014] The authentication device 10 switches the locking and unlocking of the door 13 by controlling the locking device 14 based on the authentication result with the device 2 via wireless communication. The locking and unlocking operation of the door 13 may be an automatic type in which locking and unlocking are automatically executed, or a manual type in which locking and unlocking are switched manually. The automatic type includes, for example, a method in which the door 13 is automatically locked when the device 2 moves away from the door 13 and automatically unlocked when the device 2 approaches the door 13. The manual type includes, for example, a method in which locking and unlocking are alternately switched each time a switch provided on the door 13 is operated, or a method in which locking and unlocking are switched by a dedicated locking switch or a dedicated unlocking switch.
[0015] (Locking device 14) As shown in FIG. 2, the locking device 14 of the house 5 has a doorknob 15 that operates the opening and closing of the door 13, and a housing 16 that rotatably supports the base end of the doorknob 15. The doorknob 15 is, for example, a lever-operated type. The housing 16 has, for example, an electrostatic touch part 17 used for inputting a password number required for unlocking, and a biometric detection part 18 that detects the biometric information of the user. The electrostatic touch part 17 is, for example, an electrostatic touch key that detects a touch operation on each number assigned to the surface of the housing 16. Examples of the biometric detection part 18 include a fingerprint sensor 18a that detects the fingerprint of a finger and a camera 18b that photographs a part of the user's body (for example, the face).
[0016] The authentication device 10 authenticates the input information input to the electrostatic touch part 17 and switches the locking and unlocking of the locking device 14 based on the authentication result. In addition, the authentication device 10 inputs the biometric information detected by the biometric detection part 18 and performs biometric authentication based on the biometric information. Then, the authentication device 10 controls the operation of the security system 1 based on the authentication result of the biometric authentication.
[0017] Note that the locking device 14 of the vehicle 6 may have the same configuration as the locking device 14 of the house 5. Further, the locking device 14 of the vehicle 6 may have a doorknob structure different from that of the locking device 14 of the house 5, or may be configured not to include at least one of the electrostatic touch portion 17 and the biometric detection portion 18.
[0018] (Authentication sequence) FIG. 3 is a sequence diagram showing an authentication procedure executed between the device 2 and the other device 4. In step 101, the authentication device 10 repeatedly transmits an advertisement for notifying its presence to the surroundings by short-range wireless communication. The advertisement is, for example, a kind of packet data. The advertisement may be, for example, periodically transmitted or non-periodically transmitted.
[0019] In step 102, when the device 2 receives the advertisement transmitted from the authentication device 10, the device 2 starts a scan process. This scan process is preferably started, for example, when the reception signal strength of the advertisement received by the device 2 becomes a predetermined value or more. The device 2 sets a connection destination by the scan process.
[0020] In step 103, when the scan process is completed, the device 2 transmits a connection request for requesting a transition to a connection state of short-range wireless communication to the authentication device 10. In step 104, when the authentication device 10 receives the connection request transmitted from the device 2, the authentication device 10 shifts the short-range wireless communication with the device 2 that transmitted the connection request to a connection state. That is, the device 2 and the authentication device 10 shift to a communication connection state.
[0021] In step 105, after transitioning to a communication connection state, the authentication device 10 performs authentication of device 2. Specifically, the authentication device 10 performs authentication of key information Dk registered in device 2 and authentication of device-side authentication information Dm registered in device 2. When performing authentication of key information Dk, device 2 transmits the key information Dk registered in memory 9 to the authentication device 10. Upon receiving the key information Dk, the authentication device 10 authenticates the key information Dk by, for example, checking whether the key information Dk can be correctly decrypted. If the authentication device 10 can correctly decrypt the key information Dk, it obtains various information contained in the key information Dk. Examples of such information include the validity period of the key information Dk, the session key used for subsequent short-range wireless communication, and the device ID (terminal ID) registered in device 2.
[0022] Furthermore, when the authentication device 10 receives the device-side authentication information Dm, it compares this device-side authentication information Dm with the other device-side authentication information Dt registered in the memory 11. This comparison is successful if the device-side authentication information Dm and the other device-side authentication information Dt are the same.
[0023] The authentication device 10 will proceed to successful authentication if it has successfully authenticated the key information Dk and successfully matched the device-side authentication information Dm with the other device-side authentication information Dt. Therefore, the operation of the other device 4 is permitted or executed. On the other hand, the authentication device 10 will fail authentication if it detects at least one of the following: failure to authenticate the key information Dk, the key information Dk being correctly decrypted but having expired, or failure to match the device-side authentication information Dm with the other device-side authentication information Dt. Therefore, the operation of the other device 4 is not permitted.
[0024] In step 106, once authentication of device 2 is successful, device 2 and authentication device 10 transition to the authentication complete state. The authentication complete state is, for example, a state in which the pair of device 2 and authentication device 10 know each other's common session key and device ID (terminal ID).
[0025] In step 107, after transitioning to the authentication completion state, device 2 and authentication device 10 perform communication to confirm whether the short-range wireless communication connection state is maintained. In this example, device 2 and authentication device 10 transmit periodic radio waves St at a predetermined connection interval and monitor whether they can receive a response to these periodic radio waves St to confirm that the connection state is maintained. This confirmation communication is performed alternately by both device 2 and authentication device 10.
[0026] If device 2 does not receive a response from authentication device 10 for the periodic radio wave St it transmits, it disconnects the communication. Similarly, if authentication device 10 does not receive a response from device 2 for the periodic radio wave St it transmits, it disconnects the communication. Thus, if device 2 moves too far away from authentication device 10, the communication will be disconnected.
[0027] (Sharing of equipment 2 by the first other equipment 4a and the second other equipment 4b) As shown in Figure 4, device 2 is used as a shared device for the first other device 4a and the second other device 4b. That is, when authentication is successful between device 2 and the first other device 4a, the operation of the first other device 4a is permitted or executed, and when authentication is successful between device 2 and the second other device 4b, the operation of the second other device 4b is permitted or executed. In this example, the first other device 4a is a house 5, and the second other device 4b is a vehicle 6. Furthermore, the authentication device 10 of the first other device 4a is designated as the first authentication device 10a, and the authentication device 10 of the second other device 4b is designated as the second authentication device 10b.
[0028] If the first other device 4a is a house 5, when the device 2 held by the user is authenticated by the first authentication device 10a, the locking and unlocking of the house door 13a, which is the door 13, is permitted or executed. Therefore, if the user is in possession of the legitimate device 2 and is located near the house door 13a, the authentication of device 2 will proceed to completion, making it possible to lock and unlock the house door 13a.
[0029] On the other hand, if the second other device 4b is the vehicle 6, when the device 2 held by the user is authenticated by the second authentication device 10b, the locking and unlocking of the vehicle door 13b, which is the door 13, is permitted or executed. Therefore, if the user is in possession of the legitimate device 2 and is located near the vehicle door 13b, the authentication between the device 2 and the second authentication device 10b will proceed to completion, making it possible to lock and unlock the vehicle door 13b.
[0030] (Measures against unauthorized use of other devices 4) As shown in Figure 4, the security system 1 includes an authentication information transfer function that moves authentication information Dt from other devices used for authentication between device 2 and other devices 4 between multiple other devices 4. In this case, the first authentication device 10a and the second authentication device 10b are configured to communicate wirelessly. This wireless communication is preferably short-range wireless communication. The first authentication device 10a and the second authentication device 10b preferably use a communication circuit and a communication antenna used for wireless communication with device 2 to perform short-range wireless communication. The authentication information transfer function in this example transfers the authentication information Dt from other devices to another other device 4 to be used next when the use of another device 4 is completed through authentication by device 2, so that the authentication information Dt from other devices does not remain on the other device 4 that has finished being used.
[0031] (Information transfer unit 20) As shown in Figures 1 and 4, the security system 1 includes an information transfer unit 20 that transfers authentication information Dt from other devices 4 between other devices 4. In this example, the information transfer unit 20 is provided on each of the multiple other devices 4. The information transfer unit 20 in this example includes a first information transfer unit 20a provided on the first other device 4a and a second information transfer unit 20b provided on the second other device 4b. When the conditions for transferring authentication information Dt from other devices are met, the information transfer unit 20 transfers the authentication information Dt from other devices to another other device 4 registered as the destination. The conditions for transferring authentication information Dt from other devices are, for example, the completion of the locking operation of the door 13. The information transfer unit 20 transmits the authentication information Dt from other devices to the recipient via short-range wireless communication. In this example, the other device 4 that transmits the authentication information Dt from other devices is the first other device 4a, and the other device 4 that receives the authentication information Dt from other devices is the second other device 4b.
[0032] (Information Update Department 21) As shown in Figure 1, the security system 1 includes an information update unit 21 that updates the device-side authentication information Dm and the other device-side authentication information Dt. In this example, the information update unit 21 includes a first information update unit 21a provided on device 2 and a second information update unit 21b provided on other device 4. Preferably, the information update unit 21 updates the device-side authentication information Dm and the other device-side authentication information Dt based on, for example, changes in the position of device 2 or other device 4, or the elapsed time.
[0033] (Effect of the embodiment) Next, the operation of the security system 1, security method, and authentication device 10 of this embodiment will be described. In the following description, device 2 will be referred to as "terminal 3", the first other device 4a as "house 5", and the second other device 4b as "vehicle 6". Also, the door 13 of the first other device 4a will be referred to as "house door 13a", and the door 13 of the second other device 4b as "vehicle door 13b".
[0034] (Registration process) As shown in Figure 5, the user pre-registers combinations of residences 5 and vehicles 6 that exchange authentication information Dt with other devices. Examples of registration include registering by performing a predetermined registration operation on residence 5 or vehicle 6, or registering by performing a predetermined registration operation on terminal 3. Note that it is not limited to registering only one vehicle 6 per residence 5; for example, multiple vehicles 6 may be registered for a single residence 5.
[0035] (Actions taken when going out) As shown in Figure 6(a), the first authentication device 10a, positioned around the house door 13a, forms a predetermined communication area by periodically transmitting advertisements from a communication antenna (not shown). When terminal 3 enters the communication area of the first authentication device 10a, it begins authentication with the first authentication device 10a. If the correct key information Dk and device-side authentication information Dm are registered in terminal 3, authentication for terminal 3 is completed. When a user leaves the house 5, they take terminal 3 with them and exit the house 5 through the house door 13a.
[0036] As shown in Figure 6(b), the first authentication device 10a monitors the location of terminal 3 after authentication is successful. Specifically, the first authentication device 10a uses periodic radio waves St of short-range wireless communication to monitor whether terminal 3 is inside or outside the house 5, and the distance between terminal 3 and the first authentication device 10a. The distance between terminal 3 and the first authentication device 10a is monitored by short-range wireless communication. When a user leaves the house, they take terminal 3 with them and move away from the house door 13a. When the distance to terminal 3, which is located outside, exceeds a threshold, the first authentication device 10a outputs a lock request to the lock device 14 of the house door 13a. When the lock device 14 of the house door 13a receives a lock request from the first authentication device 10a, it switches to the locked state. Thus, the house door 13a is locked.
[0037] Furthermore, the locking of the residential door 13a may be performed by manual operation by the user. That is, the residential door 13a may be locked by operating a switch provided on the doorknob 15 of the residential door 13a. The switch may be separate switches for locking and unlocking, or it may be a single switch that alternates between locking and unlocking with each operation.
[0038] As shown in Figure 6(c), when the terminal 3 is outside the house 5 and the house door 13a is locked, the first information transfer unit 20a of the first authentication device 10a transmits the authentication information Dt for other devices, which is registered in the memory 11 of the first authentication device 10a, to the second authentication device 10b of the vehicle 6. Specifically, the first information transfer unit 20a switches the short-range wireless communication between the first authentication device 10a and the second authentication device 10b, which is paired with the first authentication device 10a, to a communication connection state, and then transmits the authentication information Dt for other devices to the second authentication device 10b. The first information transfer unit 20a transmits the authentication information Dt for other devices to the second authentication device 10b, for example, by Bluetooth communication or Wi-Fi communication.
[0039] When the second authentication device 10b receives the authentication information Dt from the first authentication device 10a via its communication antenna (not shown), it writes the received authentication information Dt to the memory 11 and stores it. Therefore, the first authentication device 10a does not have the authentication information Dt from the other device, while the second authentication device 10b does.
[0040] As shown in Figure 6(d), when a user possessing terminal 3 wants to board vehicle 6, they approach vehicle 6. At this time, the user operates the unlock button (not shown) located on the handle of the vehicle door 13b. When the second authentication device 10b detects the operation of the unlock button on the handle, it starts transmitting an advertisement and then performs authentication of terminal 3 via wireless communication. When the second authentication device 10b confirms that the authentication of key information Dk is successful and that the matching of device-side authentication information Dm with other device-side authentication information Dt is successful, it unlocks the vehicle door 13b. Therefore, the user is permitted to board, and vehicle 6 can be driven.
[0041] Furthermore, after the authentication information Dt from the other device is transferred from the house 5 to the vehicle 6, there may be cases where the user wants to return to the house 5 immediately, such as to retrieve something forgotten inside the house. For example, if the first authentication device 10a detects that an operation to unlock the house door 13a has been performed within a specified time after the authentication information Dt from the other device has been transferred, it will perform biometric authentication to confirm whether the person who performed the unlocking operation is a legitimate user, for example, by obtaining biometric information from the biometric detection unit 18. If the person who performed the unlocking operation is a legitimate user, the first information transfer unit 20a sends a return request to the second authentication device 10b, and the second authentication device 10b returns the authentication information Dt from the other device. This enables the first authentication device 10a to perform secondary authentication verification, making it possible to unlock the house door 13a. Thus, it is possible to respond to actions such as returning to retrieve something forgotten.
[0042] Here, suppose that while the user is away from home, a third party attempts to illegally unlock the house door 13a using key information Dk and device-side authentication information Dm, which were stolen through unauthorized communication such as wiretapping. However, in this example, the first authentication device 10a of house 5 does not have the authentication information Dt from another device, so it cannot proceed to successful authentication. Therefore, it becomes impossible for a third party to illegally unlock the house door 13a, thus ensuring security against unauthorized intrusion into house 5.
[0043] (Travel to the destination in vehicle 6) As shown in Figure 7, while the vehicle 6 is moving, the device-side authentication information Dm registered in the control unit 8 of the terminal 3 and the other device-side authentication information Dt registered in the second authentication device 10b of the vehicle 6 are updated sequentially. In this example, the device-side authentication information Dm and the other device-side authentication information Dt are updated sequentially based on the detection signal of the measuring device 23, which measures the information necessary to update them. The measuring device 23 may be provided in the terminal 3, the vehicle 6, or the second authentication device 10b.
[0044] The measuring device 23 is, for example, a GPS (Global Positioning System) that detects the vehicle's position from satellite data. When the measuring device 23 is a GPS, the coordinate data output from the GPS is irreversibly encrypted and salted. Salting is, for example, a process of adding data to increase the strength of the hash value of the irreversible transformation. It is preferable to then quantify the encrypted and salted coordinate data and obtain updated data for the device-side authentication information Dm and the authentication information Dt of other devices from the quantified data. Furthermore, it is preferable to distinguish between when the vehicle is moving and when the vehicle is stationary, and encrypt each using a method appropriate for that situation.
[0045] When the device-side authentication information Dm and the other device-side authentication information Dt are updated sequentially, they are updated based on information corresponding to the distance to the destination when the destination is reached. Therefore, even if the device-side authentication information Dm and the other device-side authentication information Dt are stolen through communication interception before the start of travel, this information will not be used to operate the house 5 or vehicle 6. Thus, this contributes to further improving security against unauthorized use of the house 5 and vehicle 6.
[0046] (Actions taken upon returning home) As shown in Figure 8(a), when a user returns home in vehicle 6, they stop the engine of vehicle 6 and exit by opening and closing the vehicle door 13b. The second authentication device 10b installed in vehicle 6 detects the user's exit and periodically transmits an advertisement, thereby forming a predetermined communication area for short-range wireless communication. As a result, authentication between terminal 3 located outside the vehicle and the second authentication device 10b is initiated. If the correct key information Dk and device-side authentication information Dm are registered in terminal 3, authentication of terminal 3 is completed.
[0047] The second authentication device 10b monitors the location of terminal 3 after authentication is successful. Specifically, the second authentication device 10b monitors the location of terminal 3 outside the vehicle. When a user who has exited the vehicle wants to lock the vehicle door 13b, for example, they operate a lock button provided on the handle of the vehicle door 13b. When the second authentication device 10b detects that the vehicle door 13b has been locked while authentication of terminal 3 is successful, it switches the vehicle door 13b to the locked position.
[0048] Furthermore, the locking of the vehicle door 13b may be performed automatically when the user moves a certain distance away from the vehicle 6. In other words, the locking of the vehicle door 13b is not limited to being performed by the user's manual operation, but may also be performed automatically when the terminal 3 moves away from the vehicle door 13b.
[0049] As shown in Figure 8(b), when the terminal 3 is outside the vehicle 6 and the vehicle door 13b is locked, the second information transfer unit 20b of the second authentication device 10b transmits the authentication information Dt for other devices, which is registered in the memory 11 of the second authentication device 10b, to the first authentication device 10a in the house 5. Specifically, the second information transfer unit 20b switches the short-range wireless communication between the second authentication device 10b and the first authentication device 10a, which is paired with the second authentication device 10b, to a communication connection state, and then transmits the authentication information Dt for other devices to the first authentication device 10a. The second information transfer unit 20b transmits the authentication information Dt for other devices to the first authentication device 10a, for example, via Bluetooth communication or Wi-Fi communication. Therefore, the second authentication device 10b does not have the authentication information Dt for other devices, while the first authentication device 10a has the authentication information Dt for other devices.
[0050] As shown in Figure 8(c), when a user possessing terminal 3 approaches the house 5 to enter the interior of the house 5, the first authentication device 10a periodically sends advertisements. Therefore, when a user possessing terminal 3 approaches the house door 13a, authentication of terminal 3 is initiated. If terminal 3 is legitimate, authentication of terminal 3 is successful. Consequently, the house door 13a is unlocked when the switch on the doorknob 15 of the house door 13a is operated or when terminal 3 enters the communication area of the first authentication device 10a. Thus, the user can enter the interior of the house 5.
[0051] Now, suppose that after the user returns home and leaves vehicle 6, a third party attempts to illegally unlock the vehicle door 13b using key information Dk and device-side authentication information Dm, which were stolen through illegal communication such as intercepting communications. However, in this example, the second authentication device 10b of vehicle 6 does not contain the authentication information Dt from the other device, so it cannot proceed to successful authentication. Therefore, it becomes impossible for a third party to illegally unlock the vehicle door 13b, thus ensuring security against unauthorized use of vehicle 6.
[0052] (Effects of the embodiment) According to the configuration of the above embodiment, the following effects can be obtained. (1) The security system 1 of this disclosure outputs the device-side authentication information Dm registered in device 2 to other device 4, and as at least one condition for permitting the operation of other device 4, it checks the success or failure of the check by comparing the other device-side authentication information Dt registered in other device 4 with the device-side authentication information Dm. The information transfer unit 20 of the security system 1 moves the other device-side authentication information Dt between a first other device 4a, which is one of the other devices 4, and a second other device 4b, which is another of the other devices 4, so that the other device-side authentication information Dt exists only in a specific other device 4 among the multiple other devices 4.
[0053] In this configuration, in the first and second other devices 4a and 4b, whose operation is permitted or executed on the condition that legitimate device 2 exists, only one of them possesses the other device authentication information Dt. Therefore, even if a third party attempts to illegally operate other device 4, which does not possess the other device authentication information Dt, the authentication cannot proceed to completion because the other device authentication information Dt does not exist, and other device 4 will not operate. Thus, the security against unauthorized use of other device 4 can be improved.
[0054] (2) Device 2 and other devices 4 communicate wirelessly. Multiple other devices 4 communicate wirelessly with each other. The information transfer unit 20 transfers the other device authentication information Dt by transmitting the other device authentication information Dt from the first other device 4a to the second other device 4b via wireless communication. With this configuration, even if a third party intercepts the communication between Device 2 and other devices 4 when they communicate wirelessly and illegally obtains the other device authentication information Dt, the other device authentication information Dt can be transferred to another other device 4 as the user transitions between using other devices 4. Therefore, even if a third party obtains the other device authentication information Dt, they cannot force the targeted other device 4 to complete authentication, thus preventing the unauthorized use of other devices 4. In this way, security against the unauthorized use of other devices 4 can be maintained.
[0055] (3) Device 2 and other device 4 perform primary authentication, which is a condition for allowing the operation of other device 4, by verifying the success or failure of authentication of key information Dk, which is different from the device-side authentication information Dm registered in device 2. The matching of device-side authentication information Dm and other device-side authentication information Dt is secondary authentication linked to primary authentication. The conditions for the operation of other device 4 include at least the success of primary authentication and the success of secondary authentication. With this configuration, authentication between device 2 and other device 4 is dual authentication of primary and secondary authentication, which further contributes to ensuring security against unauthorized use of other device 4.
[0056] (4) The information update unit 21 of the security system 1 updates the device-side authentication information Dm and the other device-side authentication information Dt according to the usage status of at least one of the device 2 and the other device 4. With this configuration, since the device-side authentication information Dm and the other device-side authentication information Dt are updated according to the usage status, it becomes impossible to use past information. Therefore, this further contributes to ensuring security against unauthorized use of the other device 4.
[0057] (5) After the information transfer unit 20 has transferred the authentication information Dt from the first other device 4a to the second other device 4b, if the conditions for returning the authentication information Dt are met in the first other device 4a, the unit outputs the authentication information Dt registered in the second other device 4b to the first other device 4a, thereby restoring the first other device 4a to a state where the authentication information Dt is registered in it. With this configuration, for example, even if a user wants to use the first other device 4a again immediately after the authentication information Dt has been transferred from the first other device 4a to the second other device 4b, it is possible to return the authentication information Dt from the second other device 4b to the first other device 4a. Therefore, even when the authentication information Dt is transferred between multiple other devices 4, it is less likely to cause inconvenience when using the other devices 4.
[0058] (Other embodiments) This embodiment can be implemented with the following modifications. This embodiment and the following modifications can be combined with each other to the extent that they do not contradict each other technically.
[0059] The transfer of authentication information Dt from other devices is not limited to being performed directly by the first authentication device 10a and the second authentication device 10b; for example, it may be performed via device 2 (terminal 3). If multiple devices 2 (terminals 3) are registered to one other device 4, the authentication device 10 may register multiple authentication information Dt from other devices for each device 2.
[0060] The authentication information Dt from the other device may be sent to the other party, for example, a predetermined time after the door 13 enters the locked state. The timing of the transfer of authentication information Dt from the other device is not limited to the timing when the door 13 is locked. For example, when a user gets into vehicle 6 when going out, the authentication information Dt from the other device may be transferred from the house 5 to vehicle 6 at the time the unlock operation is performed using the handle of the vehicle door 13b.
[0061] Device 2 and other devices 4 are not limited to being connected wirelessly; they may also be connected by wire. The authentication of the device-side authentication information Dm and the authentication information Dt of the other device-side can be verified using various authentication methods, such as challenge-response authentication, one-time key authentication, public key authentication, and symmetric key authentication.
[0062] Authentication is not limited to performing both authentication of key information Dk and verification of device-side authentication information Dm; for example, authentication may only perform verification of device-side authentication information Dm. The object to which operation is permitted upon successful authentication is not limited to the door 13, but may be changed to various components of the house 5 or vehicle 6.
[0063] Device 2 and other device 4 may be, for example, microprocessors such as ECUs. • The key information Dk is not limited to a one-time key; it can also be an ID code whose registered value remains unchanged.
[0064] Depending on the situation, the first other device 4a may become a vehicle 6, and the second other device 4b may become a house 5. • As used in this disclosure, the phrase "at least one" means "one or more" of the desired options. For example, as used in this disclosure, "at least one" means "only one option" or "both of the two options" if there are two options. As another example, as used in this disclosure, "at least one" means "only one option" or "any combination of two or more options" if there are three or more options.
[0065] The information transfer unit 20 and the information update unit 21 may be composed of [1] one or more processors operating according to a computer program (software), or [2] a combination of such processors and one or more dedicated hardware circuits, such as application-specific integrated circuits (ASICs), that perform at least some of the various processes. The processor includes a CPU and memory such as RAM and ROM, and the memory stores program code or instructions configured to cause the CPU to execute the processes. The memory (computer-readable medium) includes any available medium that can be accessed by a general-purpose or dedicated computer. Alternatively, instead of a computer including the above-mentioned processor, a processing circuit composed of one or more dedicated hardware circuits that perform all of the various processes may be used.
[0066] The information transfer unit 20 and the information update unit 21 may be composed of independent processors, or a portion of their functions may be built from a shared processor. Thus, the information transfer unit 20 and the information update unit 21 are not limited to independent functional blocks, but may be composed of a single functional block, or may be composed of a functional block with a portion of its functions shared.
[0067] This disclosure is described in accordance with the embodiments, but it is understood that this disclosure is not limited to such embodiments or structures. This disclosure also includes various modifications and variations within the scope of equivalence. In addition, various combinations and forms, as well as other combinations and forms that include only one, more, or less of those elements, fall within the scope and concept of this disclosure. [Explanation of symbols]
[0068] 1...Security system, 2...Equipment, 4...Other equipment, 4a...First other equipment, 4b...Second other equipment, 10...Authentication device, 20...Information transfer unit, 21...Information update unit, Dm...Equipment-side authentication information, Dt...Other equipment-side authentication information, Dk...Key information.
Claims
1. A security system that outputs device-side authentication information registered on a device to another device, and as at least one condition for permitting the operation of the other device, checks the success or failure of the check by comparing the other device-side authentication information registered on the other device with the device-side authentication information, A security system comprising an information transfer unit that transfers the authentication information on the other device side between a first other device, which is one of the aforementioned other devices, and a second other device, which is another of the aforementioned other devices, thereby causing the authentication information on the other device side to exist only on a specific other device among a plurality of aforementioned other devices.
2. The aforementioned device and the aforementioned other device communicate wirelessly. The aforementioned multiple other devices communicate with each other wirelessly, The security system according to claim 1, wherein the information transfer unit transfers the authentication information from the other device to the second other device by wireless communication.
3. The aforementioned device and the aforementioned other device perform a primary authentication that confirms the success or failure of authentication of key information different from the device-side authentication information registered in the aforementioned device, as one condition for permitting the operation of the aforementioned other device. The matching of the authentication information on the aforementioned device and the authentication information on the aforementioned other device is a secondary authentication linked to the primary authentication. The security system according to claim 1, wherein the execution conditions for the operation of the other devices include at least the completion of the primary authentication and the completion of the secondary authentication.
4. The security system according to claim 1, further comprising an information update unit that updates the authentication information of the device and the authentication information of the other device according to the usage status of at least one of the aforementioned device and the other device.
5. The security system according to claim 1, wherein the information transfer unit transfers the authentication information from the other device to the second other device, and then, when the condition for returning the authentication information from the other device is met in the first other device, outputs the authentication information from the other device registered in the second other device to the first other device, thereby returning the first other device to a state in which the authentication information from the other device is registered.
6. A security method that outputs device-side authentication information registered on a device to another device, and as at least one condition for permitting the operation of the other device, checks whether the other device-side authentication information registered on the other device is matched with the device-side authentication information to confirm the success or failure of the match, A security method that enables matching of the device-side authentication information with the other device-side authentication information only between a specific other device among a plurality of other devices, by transferring the authentication information of the other device-side from a first other device, which is one of the aforementioned other devices, to a second other device, which is another of the aforementioned other devices.
7. An authentication device provided in another device that communicates with the device, which compares the device-side authentication information obtained from the device with the other device-side authentication information registered in its memory, An authentication device comprising an information transfer unit that transfers the authentication information on the other device side between a first other device, which is one of the aforementioned other devices, and a second other device, which is another of the aforementioned other devices, thereby causing the authentication information on the other device side to exist only in a specific other device among a plurality of aforementioned other devices.
Citation Information
Patent Citations
Keyless entry system
JP2010185186A