Management device, equipment control system, information processing method, and program

A management device generates electronic certificates to simplify control device replacements by sharing session keys, addressing the challenge of re-registration complexity and improving security in equipment management systems.

JP2026079356APending Publication Date: 2026-05-15PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
Filing Date
2024-10-30
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing systems face challenges in simplifying the replacement of control devices for managing equipment, particularly due to the need for re-registration of devices when control devices are replaced.

Method used

A management device that manages user information and generates electronic certificates using a secret key, allowing seamless transition of device registration to new control devices by sharing session keys and certificates.

Benefits of technology

Facilitates simplified replacement of control devices by eliminating the need for re-registration of connected devices, enhancing security and reducing operational complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026079356000001_ABST
    Figure 2026079356000001_ABST
Patent Text Reader

Abstract

The present invention provides a management device that simplifies the replacement of control devices that control equipment. [Solution] The management device 40 manages user information relating to the user of the control device 20 that controls the equipment 30. The management device 40 includes a communication unit 41 that receives a public key generated and transmitted by the control device 20, and an information processing unit 42 that generates a private key and generates a signature for the public key using the generated private key. The information processing unit 42 transmits an electronic certificate including the generated signature to the control device 20 using the communication unit 41.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a management device, a device control system, and the like.

Background Art

[0002] Patent Document 1 discloses an EMS (Energy Management System) controller (control device) capable of controlling registered devices.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] The present invention provides a management device and the like that can simplify the replacement of a control device for controlling a device.

Means for Solving the Problems

[0005] A management device according to an aspect of the present invention is a management device that manages user information regarding a user of a control device for controlling a device, and includes a communication unit that receives a public key generated and transmitted by the control device, and an information processing unit that generates a secret key and generates a signature for the public key using the generated secret key. The information processing unit transmits an electronic certificate including the generated signature to the control device using the communication unit.

[0006] A device control system according to an aspect of the present invention includes the management device, the control device, and the device.

[0007] An information processing method according to one aspect of the present invention is an information processing method performed by a management device that manages user information relating to a user of a control device that controls equipment, and includes the steps of: receiving a public key generated and transmitted by the control device; generating a private key; generating a signature for the public key using the generated private key; and transmitting an electronic certificate including the generated signature to the control device.

[0008] A program according to one aspect of the present invention is a program for causing the management device to execute the information processing method. [Effects of the Invention]

[0009] The management device and the like of the present invention can simplify the replacement of control devices that control equipment. [Brief explanation of the drawing]

[0010] [Figure 1] Figure 1 is a block diagram showing the configuration of the equipment control system according to the embodiment. [Figure 2] Figure 2 is a sequence diagram (first half) of operation example 1 of the equipment control system according to the embodiment. [Figure 3] Figure 3 is a sequence diagram (second half) of operation example 1 of the equipment control system according to the embodiment. [Figure 4] Figure 4 is a sequence diagram of operation example 2 of the equipment control system according to the embodiment. [Modes for carrying out the invention]

[0011] The embodiments will be described in detail below with reference to the drawings. Note that the embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection configurations of components, steps, and the order of steps shown in the following embodiments are examples only and are not intended to limit the present invention. Furthermore, components in the following embodiments that are not described in an independent claim will be described as optional components.

[0012] Please note that each figure is a schematic diagram and not necessarily a strictly accurate representation. Furthermore, in each figure, substantially identical components are denoted by the same reference numerals, and redundant explanations may be omitted or simplified.

[0013] (Embodiment) [composition] First, the configuration of the equipment control system according to the embodiment will be described. Figure 1 is a block diagram showing the configuration of the equipment control system according to the embodiment. As shown in Figure 1, the equipment control system 10 comprises a control device 20, equipment 30, and a management device 40. Note that the equipment control system 10 may include multiple pieces of equipment 30. Each of these devices will be described below.

[0014] The control device 20 is a gateway device installed in a facility such as a residence 70, which communicates with the equipment 30 installed in the same facility to control the equipment 30 and manage the current operating state of the equipment 30 (such as on or off). Specifically, the control device 20 is an EMS (Energy Management System) controller that can manage the power consumption in the facility, but it may be other control devices or gateway devices that do not have a power consumption management function. The control device 20 comprises an operation reception unit 21, a display unit 22, an information processing unit 23, a storage unit 24, a first communication unit 25, and a second communication unit 26.

[0015] The operation reception unit 21 receives operations from residents of the house 70 etc. (hereinafter also referred to as users). The operation reception unit 21 is realized, for example, by a touch panel, but may also be realized by a hardware key or the like.

[0016] The display unit 22 displays an image. The display unit 22 is realized, for example, by a display panel such as a liquid crystal panel or an organic EL (Electro-Luminescence) panel. Note that the display unit 22 may be separate from the control device 20.

[0017] The information processing unit 23 performs display processing etc. for displaying the power consumption etc. in the house 70 on the display unit 22. The information processing unit 23 is realized, for example, by a microcomputer, but may also be realized by a processor. The functions of the information processing unit 23 are realized, for example, by a microcomputer or a processor etc. constituting the information processing unit 23 executing a computer program stored in the storage unit 24.

[0018] The storage unit 24 is a storage device that stores computer programs etc. executed by the information processing unit 23. The storage unit 24 is realized, for example, by a semiconductor memory.

[0019] The first communication unit 25 is a communication circuit for the control device 20 to communicate with the device 30 etc. via a local communication network. The first communication unit 25 is, for example, a wireless communication circuit that performs wireless communication. The communication standard of the communication performed by the first communication unit 25 is not particularly limited. As the communication standard of the communication performed by the first communication unit 25, Matter (registered trademark) is exemplified. In Matter (registered trademark), although the protocol of the physical layer in the communication protocol stack is different, the protocol of the application layer is shared.

[0020] The second communication unit 26 is a communication circuit for the control device 20 to communicate with the management device 40 via a wide - area communication network 80 such as the Internet. The second communication unit 26 is, for example, a wireless communication circuit that performs wireless communication. There is no particular limitation on the communication standard of the communication performed by the second communication unit 26.

[0021] The device 30 is a device provided in the house 70, and is a communication device that can perform wireless communication with the control device 20 (the first communication unit 25) by being registered in the control device 20. Also, the device 30 registered in the control device 20 can be controlled by the control device 20. The device 30 is a lighting device, an air - conditioning device, a ventilation device, an air purifier, an electric shutter, an electric lock, a heat - pump water heater, a fuel - cell power - generation system, a solar - power generation system, a power - storage system, a home delivery box, or a charger for an electric vehicle, etc. Also, the device 30 may include sensors such as a temperature sensor and a humidity sensor.

[0022] The management device 40 is a device that manages information regarding the user of the control device 20. Specifically, the management device 40 is a server device (cloud server) that manages the user ID of the user of the control device 20 and performs authentication processing of the user ID, but it may be a device other than the server device. In the device control system 10, the management device 40 also functions as a certification authority that generates (issues) an electronic certificate. The management device 40 includes a communication unit 41, an information processing unit 42, and a storage unit 43.

[0023] The communication unit 41 is a communication module (communication circuit) for the management device 40 to communicate with the control device 20 via the wide - area communication network 80. The communication performed by the communication unit 41 is, for example, wired communication, but it may also be wireless communication. There is no particular limitation on the communication standard used for the communication.

[0024] The information processing unit 42 performs tasks such as user ID authentication. The information processing unit 42 is implemented by, for example, a microcomputer, but may also be implemented by a processor. The functions of the information processing unit 42 are realized, for example, by the microcomputer or processor constituting the information processing unit 42 executing a computer program stored in the storage unit 43.

[0025] The memory unit 43 is a storage device that stores computer programs executed by the information processing unit 42, as well as various information necessary for the information processing unit 42 to perform the above-mentioned processing. The memory unit 43 is implemented, for example, by an HDD (Hard Disk Drive).

[0026] [Example of operation 1: The operation of registering the device with the control device for the first time] Next, we will describe the operation (operation example 1) when the device 30 is first registered with the control device 20 after the control device 20 has been newly installed in the house 70. Figures 2 and 3 are sequence diagrams of operation example 1 of the device control system 10.

[0027] The user performs a predetermined authentication operation for user authentication, and the operation reception unit 21 of the control device 20 accepts the authentication operation (S11). The authentication operation includes inputting a user ID and password.

[0028] When the information processing unit 23 receives an authentication operation, it sends an authentication request to the management device 40 using the second communication unit 26 (S12). The authentication request includes the user ID and password entered during the authentication operation.

[0029] The communication unit 41 of the management device 40 receives an authentication request. The information processing unit 42 determines that the user ID and password included in the received authentication request are correct, based on the authentication information (information indicating the correct user ID and password) pre-stored in the storage unit 43, and determines that authentication has been successful (S13). When the information processing unit 42 determines that authentication has been successful, it generates a private key A and a public key A, associates them with the user ID, and stores them in the storage unit 43 (S14). The information processing unit 42 also generates a signature A for the public key A using the private key A, generates a root CA (Certification Authority) certificate containing the public key A and signature A, and stores it in the storage unit 43 (S15). The information processing unit 42 also sends an authentication success notification, including the root CA certificate, to the control device 20 using the communication unit 41 (S16).

[0030] The second communication unit 26 of the control device 20 receives the authentication success notification. The information processing unit 23 stores the root CA certificate included in the authentication success notification in the storage unit 24 (S17). Also, as a result of receiving the authentication success notification, the information processing unit 23 becomes capable of accepting new registration of the device 30 (registration of the device 30 is permitted) (S18).

[0031] The user performs a predetermined registration operation to register the device 30, and the operation reception unit 21 of the control device 20 accepts the predetermined registration operation (S19). The registration operation includes inputting (selecting) the device ID of the device 30 to be registered.

[0032] When the registration operation is received, the information processing unit 23 generates a pair of private and public keys for the control device 20 (hereinafter also referred to as private key B and public key B) and stores them in the storage unit 24 (S20). The information processing unit 23 also sends a public key request to the device 30 using the first communication unit 25 to obtain the public key from the device 30 (S21).

[0033] Device 30 receives a public key request. Based on the received public key request, Device 30 generates a pair of private and public keys for Device 30 (hereinafter also referred to as private key C and public key C) and stores it in the storage unit (not shown) of Device 30 (S22). Device 30 also transmits the generated public key C to the control device 20 (S23).

[0034] The first communication unit 25 of the control device 20 receives the public key C. The information processing unit 23 sends a certificate request to the management device 40 using the second communication unit 26 to request the management device 40 to generate an electronic certificate (S24). The certificate request includes the public key B and the public key C.

[0035] The communication unit 41 of the management device 40 receives a certificate request. The information processing unit 42 generates an electronic certificate for the control device 20 and an electronic certificate for the device 30 based on the received certificate request (S25). The information processing unit 42 obtains the public key B included in the certificate request and generates a signature B for the obtained public key B using the private key A. The information processing unit 42 also generates an electronic certificate for the control device 20 that includes the public key B and the signature B. Similarly, the information processing unit 42 obtains the public key C included in the certificate request and generates a signature C for the obtained public key C using the private key A. The information processing unit 42 also generates an electronic certificate for the device 30 that includes the public key C and the signature C.

[0036] The information processing unit 42 transmits the generated electronic certificates for the control device 20 and the electronic certificates for the device 30 to the control device 20 using the communication unit 41 (S26).

[0037] The second communication unit 26 of the control device 20 receives the electronic certificate for the control device 20 and the electronic certificate for the device 30. The information processing unit 23 stores the received electronic certificate for the control device 20 in the storage unit 24 (S27), and transmits the received electronic certificate for the device 30 and the root CA certificate stored in the storage unit 24 in step S17 to the device 30 using the first communication unit 25 (S28).

[0038] Device 30 receives an electronic certificate for device 30 and a root CA certificate, and stores the received electronic certificate for device 30 and root CA certificate in a storage unit (not shown) (S29). Through the processes of steps S19 to S29 described above, the device ID of device 30 is stored in the storage unit 24 of the control device 20 (S30), and device 30 is registered.

[0039] If multiple devices 30 are registered, for example, the process of storing the electronic certificate and root CA certificate for each device 30 in steps S19 to S30 will be repeated for each device 30. In this case, the process of storing the electronic certificate and root CA certificate for the control device 20 in the control device 20 will be performed only once. Alternatively, the electronic certificate and root CA certificate may be stored for multiple devices 30 in a single sequence of steps S19 to S30.

[0040] Subsequently, the control device 20 and the device 30 each generate a session key when communication becomes necessary (for example, when the control device 20 controls the device 30) (S31). In other words, the control device 20 and the device 30 share a session key. When generating a session key, for example, signature verification is performed using the following information in accordance with a predetermined method specified in Matter®, and the session key is securely shared.

[0041] • Root CA certificate • Electronic certificate for control device 20, and electronic certificate for device 30 • Public key B, and private key B • Public key C, and private key C • ID of control device 20, and ID of device 30

[0042] Once a session key is generated, it will continue to be used until the control unit 20 is replaced with a new control unit.

[0043] After the session key is shared, the information processing unit 23 of the control device 20 transmits reconnection information to the management device 40 using the second communication unit 26 (S32). The reconnection information includes the ID of the control device 20 and the ID of the registered device 30.

[0044] The communication unit 41 of the management device 40 receives reconnection information. The information processing unit 42 stores the received reconnection information in the storage unit 43, associating it with the user ID (S33).

[0045] As described above, the management device 40 includes a communication unit 41 that receives public keys B and C generated and transmitted by the control device 20, and an information processing unit 42 that generates a private key A and generates signatures B and C for public keys B and C using the generated private key A. The information processing unit 42 transmits an electronic certificate for the control device 20, including the generated signature B, and an electronic certificate for the device 30, including the generated signature C, to the control device 20 using the communication unit 41. The electronic certificate for the control device 20 is stored in the control device 20, and the electronic certificate for the device 30 is transmitted from the control device 20 to the device 30 and stored in the device 30. The electronic certificate for the control device 20 and the electronic certificate for the device 30 are used in the process (S31) of generating a session key used for communication between the control device 20 and the device 30.

[0046] Such a management device 40 has a function for generating digital certificates in addition to the function for managing user information. As a result, even if the control device 20 is replaced with a new control device 20a, the private key A stored in the management device 40 will not be changed, and the device 30 will be able to continue using the existing digital certificate for the device 30. In that case, the new control device 20a can skip the process of regenerating the digital certificate for the device 30. In other words, the management device 40 can simplify the replacement of the control device 20.

[0047] [Operation Example 2: Operation Example when the control device is replaced] However, the control device 20 may be replaced due to malfunction or other reasons. If the control device 20 stores a secret key corresponding to secret key A in operation example 1, then if the control device 20 malfunctions and is replaced with a new control device, there is a problem in that the registration of the device 30 must be redone.

[0048] In contrast, as in Operation Example 1, if an electronic certificate containing a signature generated using a private key A stored in the management device 40 rather than the control device 20 is delivered to the device 30, and if reconnection information is stored in the management device 40, then when the control device 20 is replaced with a new control device, the new control device can automatically transition to a state where it can communicate with the device 30 (a state where the device 30 is registered with the new control device).

[0049] The following describes an example of operation (Operation Example 2) when the control device 20 is replaced with a new control device. Figure 4 is a sequence diagram of Operation Example 2 of the equipment control system 10. The new control device 20a in Figure 4 is assumed to be equipped with the same components as the control device 20: an operation reception unit 21, a display unit 22, an information processing unit 23, a storage unit 24, a first communication unit 25, and a second communication unit 26.

[0050] The user performs a predetermined authentication operation for user authentication, and the operation reception unit 21 of the new control device 20a accepts the authentication operation (S41). The authentication operation includes inputting a user ID and password.

[0051] When the information processing unit 23 receives an authentication request, it sends an authentication request to the management device 40 using the second communication unit 26 (S42). The authentication request includes the user ID and password entered during the authentication operation.

[0052] The communication unit 41 of the management device 40 receives an authentication request. The information processing unit 42 determines that the user ID and password included in the received authentication request are correct, based on the authentication information (information indicating the correct user ID and password) previously stored in the storage unit 43, and determines that authentication has been successful (S43). In addition, the ID of the new control device 20a included in the authentication request is different from the ID of the control device 20 included in the reconnection information stored in association with the user ID (i.e., the reconnection information stored in step S33). For this reason, the information processing unit 42 determines that the control device 20 has been replaced (changed) with a new control device 20a (S44).

[0053] When the information processing unit 42 determines that authentication has been successful and that the control device 20 has been replaced with a new control device 20a, it sends an authentication success notification to the new control device 20a using the communication unit 41 (S45). In addition, when the information processing unit 42 determines that the control device 20 has been replaced with a new control device 20a, it also adds the ID of the new control device 20a to the reconnection information (or replaces the ID of the old control device 20).

[0054] If it is determined that the control device 20 has been replaced with a new control device 20a, the authentication success notification will include the device ID contained in the reconnection information stored in the storage unit 43 in association with the user ID (i.e., the reconnection information stored in step S33). The authentication success notification will also include the root CA certificate stored in the storage unit 43 in step S15.

[0055] The second communication unit 26 of the new control device 20a receives an authentication success notification. The information processing unit 23 stores the device ID included in the authentication success notification in the storage unit 24 (S46). As a result, the device 30 that was registered with the old control device 20 is automatically registered with the new control device 20a. Furthermore, if the private key A for creating an electronic certificate (signature) exists in the storage unit 43 of the management device 40 after the replacement with the new control device 20a, it can be confirmed that the registration status of the device 30 has been transferred. The information processing unit 23 also stores the root CA certificate included in the authentication success notification in the storage unit 24 (S47).

[0056] Next, the information processing unit 23 generates a new set of private and public keys for the control device 20a (hereinafter also referred to as private key D and public key D) and stores it in the storage unit 24 (S48). The information processing unit 23 transmits a certificate request containing the public key D to the management device 40 using the second communication unit 26, requesting the management device 40 to generate an electronic certificate for the new control device 20a (S49).

[0057] The communication unit 41 of the management device 40 receives a certificate request. The information processing unit 42 generates a new digital certificate for the control device 20a based on the received certificate request (S50). The information processing unit 42 obtains the public key D included in the certificate request and generates a signature D for the obtained public key D using the private key A. The information processing unit 42 also generates a new digital certificate for the control device 20a that includes the public key D and the signature D. The information processing unit 42 transmits the generated new digital certificate for the control device 20a to the new control device 20a using the communication unit 41 (S51).

[0058] The second communication unit 26 of the new control device 20a receives an electronic certificate for the new control device 20a. The information processing unit 23 stores the received electronic certificate for the new control device 20a in the storage unit 24 (S52).

[0059] Subsequently, the new control device 20a and device 30 each generate a session key when communication becomes necessary (S53). In other words, the new control device 20a and device 30 share the session key.

[0060] When generating a session key, for example, the signature is verified using the following information in accordance with a predetermined method defined in Matter (registered trademark), and the session key is securely shared. The difference from step S31 is that public key B and private key B are replaced with public key D and private key D.

[0061] Once a session key is generated, it will continue to be used until the new control unit 20a is replaced with another control unit.

[0062] As explained above, when the information processing unit 42 of the management device 40 determines that the control device 20 has been replaced with a new control device 20a, it transmits the ID of the device 30 included in the reconnection information to the new control device 20a using the communication unit 41. This allows the device control system 10 to easily transfer the registration status of the device 30 in the control device 20 to the new control device 20a.

[0063] [Differentiation] In the device control system 10, the management device 40 manages the user IDs of multiple users, including the user mentioned above, and other users can access the management device 40 using other control devices. In this case, the secret key (secret key A) generated for the user of the control device 20 is different from the secret key generated for the user of the other control device. In other words, the information processing unit 42 of the management device 40 generates a secret key individually for the user of the control device 20. The information processing unit 42 also manages multiple user IDs, including the user ID of the user of the control device 20, and stores each of the multiple user IDs with a different secret key associated with them in the storage unit 43.

[0064] This allows the device control system 10 to limit the scope of impact when a secret key is leaked to a per-user basis. In other words, security is improved.

[0065] Furthermore, the information processing unit 42 may generate a common secret key for multiple users, including the user of the control device 20. In this case, the amount of information (secret key) managed by the information processing unit 42 is reduced, and there is an advantage in that it is no longer necessary to store the secret key in association with the user ID.

[0066] Furthermore, in the above embodiment, the private key A was generated immediately after successful authentication of the user ID, triggered by successful authentication of the user ID. However, the timing of the generation of the private key A is not particularly limited. The private key A may be generated at any time before the signature is generated.

[0067] Furthermore, in the above embodiment, it was explained that the secret key A is stored in the storage unit 43 immediately after the user ID authentication is successful for the first time. However, the timing at which the secret key A is stored is not limited to this timing. Here, "stored" means to be stored (permanently) in a non-volatile memory area, and can be rephrased as "save" or similar.

[0068] For example, the secret key A may be stored in the storage unit 43 when the registration of the first device 30 is completed. Specifically, the information processing unit 42 of the management device 40 temporarily stores the secret key A in the volatile storage area of ​​the storage unit 43 immediately after successfully authenticating the user ID. Subsequently, the information processing unit 42 may store the secret key A in the non-volatile storage area of ​​the storage unit 43 when it receives notification from the control device 20 that the registration of the first device 30 has been completed (for example, immediately after step S30).

[0069] In this case, even if the registration of the second and subsequent devices 30 fails, the private key A can still be used, which has the advantage of only requiring the re-registration of the failed devices 30.

[0070] Furthermore, if multiple devices 30 are registered with the control device 20, the secret key A may be stored in the storage unit 43 when the registration of all multiple devices 30 is complete. Specifically, the information processing unit 42 temporarily stores the secret key A in the volatile storage area of ​​the storage unit 43 immediately after successfully authenticating the user ID. Subsequently, the information processing unit 42 may store the secret key A in the non-volatile storage area of ​​the storage unit 43 when it receives notification from the control device 20 that the registration of all devices 30 is complete (for example, immediately after step S30).

[0071] In this case, if the registration of device 30 fails, the private key will be regenerated, and the registration of device 30 will have to be restarted from the beginning, but this has the advantage of reducing the risk of hacking.

[0072] [Effects, etc.] The following describes examples of inventions that can be obtained from the disclosures in this specification, and explains the effects and other benefits that can be obtained from these examples.

[0073] Invention 1 is a management device 40 for managing user information relating to a user of a control device 20 that controls a device 30, comprising a communication unit 41 that receives a public key generated and transmitted by the control device 20, and an information processing unit 42 that generates a private key and generates a signature for the public key using the generated private key, wherein the information processing unit 42 transmits an electronic certificate including the generated signature to the control device 20 using the communication unit 41.

[0074] Such a management device 40, in addition to a user information management function, also has a function for generating electronic certificates. This means that even if the control device 20 is replaced with a new control device 20a, the process of regenerating the electronic certificate for the device 30 can be omitted. In other words, the management device 40 can simplify the replacement of the control device 20.

[0075] Invention 2 is a management device 40 of Invention 1, in which the public key includes a first public key and a second public key, the information processing unit 42 generates a first signature, which is a signature to the first public key, and a second signature, which is a signature to the second public key, using the generated private key, the information processing unit 42 transmits a first certificate, which is an electronic certificate containing the generated first signature, and a second certificate, which is an electronic certificate containing the generated second signature, to the control device 20 using the communication unit 41, the first certificate is stored in the control device 20, the second certificate is transmitted from the control device 20 to the device 30 and stored in the device 30, and the first certificate and the second certificate are used in the process (S31) of generating a session key used for communication between the control device 20 and the device 30. The public key B, public key C, private key A, signature A, signature B, digital certificate for control device 20, and digital certificate for device 30 in the above embodiment are examples of a first public key, second public key, private key, first signature, second signature, first certificate, and second certificate.

[0076] Such a management device 40 can provide electronic certificates to the control device 20 and the equipment 30.

[0077] Invention 3 is a management device 40 of Invention 1 or 2, wherein the communication unit 41 receives the ID of the device 30 registered with the control device 20, transmitted by the control device 20, the information processing unit 42 stores the received ID of the device 30 in the storage unit 43, and when it is determined that the control device 20 has been replaced with a new control device 20a, it transmits the ID of the device 30 to the new control device 20a using the communication unit 41.

[0078] Such a management device 40 can transfer the IDs of the devices 30 that were registered in the control device 20 to a new control device 20a, thereby simplifying the replacement of the control device 20.

[0079] Invention 4 is a management device 40 of any of Inventions 1 to 3, in which the information processing unit 42 generates a private key individually for each user of the control device 20.

[0080] Such a management device 40 can limit the scope of impact when a private key is leaked to a per-user basis. In other words, the management device 40 can improve security.

[0081] Invention 5 is a management device 40 of Invention 4, wherein the information processing unit 42 manages multiple user IDs, including the user ID of a user, and associates each of the multiple user IDs with a different secret key and stores them in the storage unit 43.

[0082] Such a management device 40 can manage multiple user IDs.

[0083] Invention 6 is a management device 40 according to any of Inventions 1 to 3, in which the information processing unit 42 generates a common secret key for multiple users, including the user of the control device 20.

[0084] Such a management device 40 can reduce the number of private keys to manage and eliminate the process of associating and storing private keys with user IDs.

[0085] Invention 7 is a management device 40 according to any of Inventions 1 to 6, wherein the device 30 is the device that is initially registered with the control device 20, and the information processing unit 42 stores the generated secret key in the storage unit 43 when the registration of the device 30 is completed.

[0086] With such a management device 40, even if the registration of the second and subsequent devices 30 fails, the private key A can still be used, and only the failed devices 30 need to be re-registered, which is an advantage.

[0087] Invention 8 is a management device 40 according to any of Inventions 1 to 6, wherein a control device 20 has a plurality of devices 30, including device 30, registered, and an information processing unit 42 stores the generated secret key in a storage unit 43 when the registration of the plurality of devices 30 is completed.

[0088] Such a management device 40 offers the advantage of reducing the risk of hacking.

[0089] Invention 9 is an equipment control system 10 comprising a management device 40, a control device 20, and equipment 30, all of which are according to Inventions 1 to 8.

[0090] Such a device control system 10 can provide an electronic certificate to the control device 20 using a management device 40.

[0091] Invention 10 is an information processing method performed by a management device 40 that manages user information relating to a user of a control device 20 that controls a device 30, and includes the steps of: receiving a public key generated and transmitted by the control device 20; generating a private key in step S14; generating a signature for the public key using the generated private key in step S25; and transmitting an electronic certificate including the generated signature to the control device 20 in step S26.

[0092] Such an information processing method can provide an electronic certificate to the control device 20.

[0093] Invention 11 is a program for causing the management device 40 to execute the information processing method of Invention 10.

[0094] According to such a program, the management device 40 can provide the control device 20 with an electronic certificate.

[0095] (Other embodiments) Although embodiments have been described above, the present invention is not limited to the embodiments described above.

[0096] For example, in the above embodiment, the equipment control system was implemented by multiple devices, but it may also be implemented as a single device. For example, the equipment control system may be implemented as a single device corresponding to a management device. When the equipment control system is implemented by multiple devices, the components of the equipment control system may be distributed among the multiple devices in any way.

[0097] Furthermore, the communication method between devices in the above embodiment is not particularly limited. In addition, a relay device (not shown) may be interposed in the communication between devices.

[0098] Furthermore, in the above embodiment, a processing unit that is executed by a specific processing unit may be executed by another processing unit. For example, in the above embodiment, a server device may execute some or all of the processing that is executed by the information terminal. Also, the order of multiple processing units may be changed, or multiple processing units may be executed in parallel.

[0099] Furthermore, in the above embodiment, each component may be realized by executing a software program suitable for each component. Each component may also be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0100] Furthermore, each component may be implemented by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or they may be separate circuits. Also, each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0101] Furthermore, general or specific embodiments of the present invention may be implemented as a system, apparatus, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM. Alternatively, they may be implemented as any combination of a system, apparatus, method, integrated circuit, computer program, and recording medium.

[0102] For example, the present invention may be implemented as an equipment control system, a control device, and a management device, etc., as described in the above embodiments. The present invention may be implemented as a method executed by a computer such as an equipment control system, a control device, and a management device, or as a program (computer program product) for causing a computer to execute such a method. The present invention may also be implemented as a computer-readable non-temporary recording medium on which these programs are recorded.

[0103] Furthermore, the present invention also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art could conceive, or forms realized by arbitrarily combining the components and functions of each embodiment without departing from the spirit of the present invention. [Explanation of Symbols]

[0104] 10. Equipment control system 20, 20a Control device 21 Operation Reception Section 22 Display section 23, 42 Information Processing Unit 24, 43 Storage section 25. First Communications Department 26. Second Communications Department 30 equipment 40 Management device 41 Communications Department 70 Housing 80 Wide-area telecommunications network

Claims

1. A management device that manages user information relating to users of a control device that controls equipment, A communication unit that receives the public key generated and transmitted by the control device, The system includes an information processing unit that generates a private key and generates a signature for the public key using the generated private key, The information processing unit transmits the generated electronic certificate, including the signature, to the control device using the communication unit. Management device.

2. The aforementioned public key includes a first public key and a second public key. The aforementioned information processing unit, The first signature, which is the signature for the first public key, and the second signature, which is the signature for the second public key, are each generated using the generated private key. The first certificate, which is the electronic certificate containing the generated first signature, and the second certificate, which is the electronic certificate containing the generated second signature, are transmitted to the control device using the communication unit. The first certificate is stored in the control device, The aforementioned second certificate is transmitted from the control device to the device and stored in the device. The first certificate and the second certificate are used in the process of generating a session key used for communication between the control device and the device. The control device according to claim 1.

3. The communication unit receives the ID of the device registered with the control device, which has been transmitted by the control device. The aforementioned information processing unit, The ID of the received device is stored in the storage unit. When it is determined that the control device has been replaced with a new control device, the ID of the device is transmitted to the new control device using the communication unit. The control device according to claim 1.

4. The information processing unit generates the secret key individually for each user of the control device. The control device according to claim 1.

5. The aforementioned information processing unit, Manage multiple user IDs, including the user ID of the aforementioned user. Each of the aforementioned user IDs is associated with a different secret key and stored in the memory unit. The control device according to claim 4.

6. The information processing unit generates a common secret key for multiple users, including the user of the control device. The control device according to claim 1.

7. The aforementioned device is the device that is initially registered with the control device, The information processing unit stores the generated secret key in the storage unit when the registration of the device is completed. The control device according to claim 1.

8. Multiple devices, including the aforementioned device, are registered in the control device. The information processing unit stores the generated secret key in the storage unit when the registration of the multiple devices is completed. The control device according to claim 1.

9. A control device according to any one of claims 1 to 8, The control device and, The equipment includes the aforementioned device Equipment control system.

10. An information processing method performed by a management device that manages user information relating to a user of a control device that controls equipment, The steps include receiving the public key generated and transmitted by the control device, The steps to generate a private key, A step of generating a signature for the public key using the generated private key, The step includes transmitting the generated digital certificate containing the signature to the control device. Information processing methods.

11. A program for causing the management device to execute the information processing method described in claim 10.