Device, system, method for controlling a device, method for controlling a system, and control program for a device.

The system with encrypted application distribution and split decryption keys secures IoT devices in unattended environments by ensuring secure authentication and decryption, addressing the challenge of unauthorized access and theft.

JP2026088705APending Publication Date: 2026-05-29BIPROGY INC

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
BIPROGY INC
Filing Date
2024-11-19
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing IoT devices in unattended environments lack effective protection against unauthorized access and theft, particularly in scenarios where user operation is not feasible.

Method used

A system comprising a management server, kitting machine, and IoT device with beacon communication, utilizing encrypted application distribution and split decryption keys, ensures secure authentication and decryption of applications in unattended environments.

Benefits of technology

Enhances protection of IoT devices by preventing unauthorized access and theft by ensuring secure authentication and decryption, even in unattended settings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026088705000001_ABST
    Figure 2026088705000001_ABST
Patent Text Reader

Abstract

The goal is to improve the protection of devices in unattended environments. [Solution] The device of the present invention is characterized in that, when it receives beacon information from a beacon, it uses the decryption logic obtained from the management server to decrypt the encrypted application obtained from the kitting machine using the decryption logic obtained from the management server, which is obtained by restoring the first decryption key fragment obtained from the kitting machine and the second decryption key fragment obtained from the management server, and then executes the decrypted application to operate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a device, a system, a method for controlling a device, a method for controlling a system, and a control program for a device.

Background Art

[0002] Conventionally, devices that can communicate information and control via the Internet, such as so-called IoT devices, are known. IoT is an abbreviation for Internet of Things. Examples of such devices include surveillance cameras and various sensors.

[0003] Recently, with the high functionality of devices and the high performance of hardware, edge computing that incorporates codes of various applications and AI models into devices has become possible. AI is an abbreviation for Artificial Intelligence. Codes, models, etc. incorporated into such devices are, so to speak, intellectual property, and it is important to prevent leakage to third parties. However, such devices may be installed and operated in an unmanned environment such as a surveillance camera, etc., and there is a high risk of theft of the device.

[0004] In Patent Document 1, a technique is disclosed for enhancing the tamper resistance of a secret key of an IC card by encrypting a secret key required for communication between an Internet-connected communication terminal and an IC card with an encryption key and dividing and holding the encryption key between the communication terminal and a terminal management server.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] In Patent Document 1, a user obtains one of the split encryption keys from a terminal management server using a mobile terminal they carry, and then transmits this key from the mobile terminal to a communication terminal. The communication terminal uses the one split encryption key received from the mobile terminal and the other split encryption key it possesses to reconstruct the encryption key and decrypt the confidential key of the IC card. For this reason, a user carrying a mobile terminal is required to operate the communication terminal as an IoT device, and the operation of the device in an unattended environment was not considered.

[0007] Therefore, there has traditionally been room for improvement in protecting devices in unattended environments.

[0008] This invention was made to solve the above-mentioned problems and aims to improve the protection of devices in unattended environments. [Means for solving the problem]

[0009] To solve the above problems, the device of the present invention is characterized by comprising: application acquisition means for acquiring an encrypted encryption application; first key acquisition means for acquiring a first decryption key fragment, which is one of the divided fragments of a decryption key for decrypting the encryption application; beacon detection means for receiving beacon information that can identify the beacon from the beacon; device information storage means for storing device information including a device ID that can identify the device itself; system authentication request transmission means for transmitting system authentication information, which includes the beacon information received by the beacon detection means and the device information stored by the device information storage means, to a management server to receive system authentication; second key acquisition means for acquiring a second decryption key fragment, which is the other of the divided fragments of a decryption key for decrypting the encryption application, from the management server in accordance with the result of the system authentication by the management server; decryption logic acquisition means for acquiring decryption logic for decrypting the encryption application from the management server in accordance with the result of the system authentication by the management server; and decryption means for decrypting the encryption application using the decryption key obtained by restoring the first decryption key fragment and the second decryption key fragment. [Effects of the Invention]

[0010] According to the present invention, improvements can be made to the protection of devices in unattended environments. [Brief explanation of the drawing]

[0011] [Figure 1] This is a block diagram showing the system configuration related to a subset of aluminum. [Figure 2] Figure 1 is a block diagram showing the hardware configurations of the management server 11, kitting machine 12, device 14, and beacon 16. [Figure 3] Figure 1 is a block diagram showing the functional configuration of the management server 11. [Figure 4] Figure 1 is a block diagram showing the functional configuration of the kitting machine 12. [Figure 5] This block diagram shows the functional configuration of device 14 as shown in Figure 1. [Figure 6] Figure 1 is a block diagram showing the functional configuration of the beacon 16. [Figure 7] Figure 1 shows the processing flow by the management server 11, kitting machine 12, device 14, and beacon 16. [Modes for carrying out the invention]

[0012] Embodiments of the present invention will be described in detail below with reference to the drawings. The embodiments described below are specific examples of the system according to the present invention, and may be subject to various limitations in accordance with general hardware and software configurations. However, the technical scope of the present invention is not limited to these embodiments unless otherwise specified. Furthermore, the components in the embodiments described below can be replaced with existing components as appropriate, and various variations are possible, including combinations with other existing components. Therefore, the description of the embodiments below does not limit the content of the invention as described in the claims.

[0013] Figure 1 is a block diagram showing the configuration of a system according to one embodiment of the present invention. System 10 is configured by connecting a management server 11, a kitting machine 12, and a device 14 via a network 13. System 10 also has a beacon 16 that is connected to the device 14 via short-range communication 15. Network 13 is a communication network such as the Internet. Network 13 may include LANs or WANs, and may be wired or wireless. It is preferable that communication between the management server 11, the kitting machine 12, and the device 14 takes place over a logical closed network communication created on the Internet.

[0014] The management server 11 and the kitting machine 12 are, for example, server machines with computers. Device 14 is an IoT device. Device 14 is a device with a computer that executes programs, and is, for example, a surveillance camera or various sensors. Beacon 16 is, for example, a BLE beacon. BLE is an abbreviation for Bluetooth Low Energy, which is an energy-saving wireless communication standard. Short-range communication 15 is, for example, BLE. The communication range of BLE is short-range, about 50 to 100m, and beacon 16 communicates with device 14 at short range.

[0015] Figure 2 is a block diagram showing the hardware configurations of the management server 11, kitting machine 12, device 14, and beacon 16 shown in Figure 1. Each of the management server 11, kitting machine 12, device 14, and beacon 16 has an information processing device (computer).

[0016] Each of the management server 11, kitting machine 12, device 14, and beacon 16 includes a control unit 102 that controls the entire system, an input / output unit 103 that receives input from users and outputs to users, a storage unit 101 that stores programs and various data executed by the control unit 102, and a communication unit 104 that communicates with other devices. The control unit 102 is, for example, a CPU. The storage unit 101 is, for example, RAM, ROM, HDD, etc. The input / output unit 103 is, for example, a keyboard, mouse, various switches, touch panel, display, etc. The communication unit 104 of the management server 11, kitting machine 12, and device 14 includes communication means for communicating with other devices via at least the network 13. The communication unit 104 of device 14 and beacon 16 includes communication means for communicating with other devices via at least short-range communication 15. These configurations are not essential for the management server 11, the kitting machine 12, the device 14, and the beacon 16, and in particular, the device 14 and the beacon 16 may be configured without an input / output unit 103.

[0017] Figure 3 is a block diagram showing the functional configuration of the management server 11 shown in FIG. 1. The management server 11 includes a system authentication information registration unit 111, a system authentication information storage unit 112, a system authentication request reception unit 113, a system authentication unit 114, a second key registration unit 115, a second key storage unit 116, a second key provision unit 117, a decryption logic registration unit 118, a decryption logic storage unit 119, and a decryption logic provision unit 120. These configurations are realized by the control unit 102 of the management server 11 executing a program stored in the storage unit 101 and controlling the input / output unit 103, the communication unit 104, and the like.

[0018] The system authentication information registration unit 111 performs registration of system authentication information for authenticating the device 14 in the management server 11. The system authentication information storage unit 112 stores the system authentication information registered by the system authentication information registration unit 111. The system authentication information includes a combination of beacon information that can identify the beacon 16 and a device ID that can identify the device 14. The system authentication information registration unit 111 pre-registers the system authentication information for the device 14 used in the system 10 via the input / output unit 103 and the communication unit 104. The system authentication information storage unit 112 stores the system authentication information as a hashed whitelist. As the device ID that can identify the device 14, the IP address or MAC address of the device 14 may be used.

[0019] The system authentication request reception unit 113 receives a system authentication request from the device 14. The system authentication request includes the system authentication information of the device 14. The system authentication unit 114 checks whether the system authentication information included in the system authentication request received by the system authentication request reception unit 113 matches the system authentication information stored in the system authentication information storage unit 112, and if it matches, the authentication is successful.

[0020] The second key registration unit 115 receives and registers the second decryption key fragment, which will be described later, from the kitting machine 12. The second key storage unit 116 stores the second decryption key fragment registered by the second key registration unit 115. The second key providing unit 117 transmits the second decryption key fragment stored in the second key storage unit 116 to the device 14 in response to successful authentication by the system authentication unit 114.

[0021] The decryption logic registration unit 118 receives and registers the decryption logic, which will be described later, from the kitting machine 12. The decryption logic storage unit 119 stores the decryption logic registered by the decryption logic registration unit 118. The decryption logic providing unit 120 transmits the decryption logic stored in the decryption logic storage unit 119 to the device 14 in response to successful authentication by the system authentication unit 114.

[0022] FIG. 4 is a block diagram showing the functional configuration of the kitting machine 12 shown in FIG. 1. The kitting machine 12 includes a device information registration unit 121, a device information storage unit 122, a device information acquisition unit 123, a device authentication unit 124, an application registration unit 125, an application storage unit 126, a key generation unit 127, a key splitting unit 128, a first key providing unit 129, a second key providing unit 130, an encryption unit 131, an application providing unit 132, and a decryption logic providing unit 133. These configurations are realized by the control unit 102 of the kitting machine 12 executing a program stored in the storage unit 101 and controlling the input / output unit 103, the communication unit 104, and the like.

[0023] The device information registration unit 121 registers device information for authenticating the device 14 in the kitting machine 12. The device information storage unit 122 stores the device information registered by the device information registration unit 121. The device information includes a device ID that can identify the device 14. The device information registration unit 121 pre-registers the device information about the device 14 used in the system 10 via the input / output unit 103 and the communication unit 104. The device information storage unit 122 stores the device information as a hashed white list.

[0024] The device information acquisition unit 123 receives device information from device 14. The device authentication unit 124 checks whether the device ID included in the device information received by the device information acquisition unit 123 matches the device ID stored in the device information storage unit 122, and if they match, authentication is successful. In this embodiment, the kitting machine 12 authenticates device 14 by device ID, but the present invention is not limited to this, and authentication may be performed by device ID and beacon information.

[0025] The application registration unit 125 registers applications to be executed using the device ID. The application storage unit 126 stores the applications registered by the application registration unit 125. The application registration unit 125 pre-registers applications via the input / output unit 103 and the communication unit 104. The applications stored in the application storage unit 126 include code and data for various applications running on the device 14, AI models, and all data that should be protected as intellectual property.

[0026] The key generation unit 127 generates a key to encrypt the application stored in the application storage unit 126. In this embodiment, a symmetric key scheme is adopted, and the key generated by the key generation unit 127 is the key used for encryption and decryption. The key splitting unit 128 splits the key generated by the key generation unit 127 into a first key and a second key. The splitting method by the key splitting unit 128 can be any method, as long as the key before splitting can be restored using the first key and the second key. The method for restoring the key before splitting may be sent from the kitting machine 12 to the management server 11, similar to the decryption logic for decrypting the encrypted application, and then sent from the management server 11 to the device 14 upon successful system authentication. The first key split by the key splitting unit 128 is an example of a first decryption key fragment. The second key split by the key splitting unit 128 is an example of a second decryption key fragment.

[0027] Furthermore, it is desirable for the key generation unit 127 to delete the original key before splitting after the key splitting unit 128 has split the key.

[0028] The first key provider 129 transmits the first key to the device 14 upon successful authentication by the device authentication unit 124. The second key provider 130 transmits the second key to the management server 11.

[0029] The encryption unit 131, for example, upon successful authentication by the device authentication unit 124, encrypts the application stored in the application storage unit 126 with the key generated by the key generation unit 127 to obtain an encrypted application. The encryption unit 131 may also obtain an encrypted application by encrypting the application stored in the application storage unit 126 with the key generated by the key generation unit 127 without waiting for successful authentication by the device authentication unit 124.

[0030] The application provider unit 132 sends the encrypted application encrypted by the encryption unit 131 to the device 14 in response to successful authentication by the device authentication unit 124. The decryption logic provider unit 133 sends the decryption logic, which is the logic for decrypting the encrypted application encrypted by the encryption unit 131, to the management server 11.

[0031] Figure 5 is a block diagram showing the functional configuration of device 14 shown in Figure 1. Device 14 includes a device information storage unit 141, a device information transmission unit 142, a beacon detection unit 143, a system authentication request transmission unit 144, an application acquisition unit 145, a first key acquisition unit 146, a second key acquisition unit 147, a decryption logic acquisition unit 148, a decryption unit 149, an application storage unit 150, and an application execution unit 151. These configurations are realized by the control unit 102 of device 14 executing a program stored in the storage unit 101 and controlling the input / output unit 103, the communication unit 104, etc.

[0032] The device information storage unit 141 pre-stores device information, including a device ID that can identify device 14. The device information transmission unit 142 transmits the device information stored in the device information storage unit 141 to the kitting machine 12 for authentication of device 14 at the kitting machine 12.

[0033] The beacon detection unit 143 receives beacon information from beacon 16. The system authentication request transmission unit 144 includes system authentication information, which includes the beacon information received by the beacon detection unit 143 and the device information stored in the device information storage unit 141, in the system authentication request for the authentication of device 14 at the management server 11, and transmits the system authentication request to the management server 11.

[0034] The application acquisition unit 145 receives and acquires the encrypted application transmitted from the kitting machine 12 in response to successful authentication by the device authentication unit 124. The first key acquisition unit 146 receives and acquires the first key transmitted from the kitting machine 12 in response to successful authentication by the device authentication unit 124.

[0035] The second key acquisition unit 147 receives and acquires the second key transmitted from the management server 11 in response to successful authentication by the system authentication unit 114. The decryption logic acquisition unit 148 receives and acquires the decryption logic transmitted from the management server 11 in response to successful authentication by the system authentication unit 114.

[0036] The decryption unit 149 uses the first key obtained by the first key acquisition unit 146 and the second key obtained by the second key acquisition unit 147 to restore the key for decrypting the encrypted application obtained by the application acquisition unit 145. The decryption unit 149 also uses the restored key and the decryption logic obtained by the decryption logic acquisition unit 148 to decrypt the encrypted application obtained by the application acquisition unit 145 and obtain the application.

[0037] The application storage unit 150 stores the application decrypted by the decryption unit 149. The application execution unit 151 executes the application stored in the application storage unit 150 and operates the device 14.

[0038] Figure 6 is a block diagram showing the functional configuration of the beacon 16 shown in Figure 1. The beacon 16 has a beacon information storage unit 161 and a beacon information transmission unit 162. These configurations are realized when the control unit 102 of the beacon 16 executes a program stored in the storage unit 101 and controls the input / output unit 103, the communication unit 104, etc.

[0039] The beacon information storage unit 161 stores in advance beacon information that can identify beacon 16. The beacon information transmission unit 162 transmits the beacon information stored in the beacon information storage unit 161. The transmission of beacon information by the beacon information transmission unit 162 does not necessarily have to specify a destination, and may be directed to device 14 as the destination.

[0040] Next, the processing flow of system 10 will be explained. Figure 7 is a diagram showing the processing flow by the management server 11, kitting machine 12, device 14, and beacon 16 shown in Figure 1.

[0041] Device 14 is placed in a location suitable for its operation. Device 14 is, for example, an unmanned surveillance camera. Beacon 16 is placed near device 14 and within range of device 14 where beacon information transmitted from beacon information transmission unit 162 can reach device 14. The range of beacon information transmitted from beacon information transmission unit 162 is, for example, within a radius of 100m. Beacon 16 is fixed in place, so if device 14 is stolen or taken away, beacon information transmitted from beacon information transmission unit 162 will no longer reach device 14.

[0042] In step S71 of Figure 7, beacon 16 continues to transmit beacon information. When device 14 is powered on, it continues to receive beacon information from beacon 16. Device 14 continuously receives beacon information from beacon 16, and may stop operation and issue an alert if it can no longer receive beacon information from beacon 16. If device 14 is able to receive beacon information from beacon 16, it executes the processes from step S72 onwards.

[0043] In step S72, device 14 transmits its device information to the kitting machine 12 via the device information transmission unit 142. Multiple kitting machines 12 may be provided in the system 10, and device 14 shall pre-register the addresses of its communication partners, such as kitting machines 12.

[0044] In step S73, the kitting machine 12 authenticates the received device information with the device authentication unit 124. If authentication is successful, in step S74, the kitting machine 12 sends the first key to the device 14 using the first key provision unit 129 and the encryption application to the device 14 using the application provision unit 132. At this time, the kitting machine 12 has already obtained the first key, the second key, the decryption logic, and the encryption application, as described above. The kitting machine 12 may also send an alert to the device 14 if authentication by the device authentication unit 124 is unsuccessful.

[0045] In step S75, device 14, using the system authentication request transmission unit 144, includes system authentication information, including its own device information and the beacon information of beacon 16, in the system authentication request and sends it to the management server 11. Multiple management servers 11 may be provided in the system 10, and device 14 shall pre-register the addresses of its communication partners, such as management servers 11.

[0046] In step S76, the management server 11 authenticates the received system authentication information with the system authentication unit 114. If authentication is successful, in step S77, the management server 11 sends the second key to the device 14 using the second key provision unit 117, and sends the decryption logic to the device 14 using the decryption logic provision unit 120. At this time, as described above, the management server 11 has already obtained the second key and decryption logic from the kitting machine 12. The management server 11 may also send an alert to the device 14 if authentication by the system authentication unit 114 is unsuccessful.

[0047] In step S78, the device 14 uses the decryption unit 149 to decrypt the encrypted application obtained by the application acquisition unit 145, using the first key obtained by the first key acquisition unit 146, the second key obtained by the second key acquisition unit 147, and the decryption logic obtained by the decryption logic acquisition unit 148, thereby obtaining the application. In step S79, the device 14 executes the application obtained in the process of step S78.

[0048] If device 14 is activated in an area where beacon information from beacon 16 cannot be received, the system authentication information sent to the management server 11 will not include the beacon information. As a result, authentication by the system authentication unit 114 will fail, and the second key and decryption logic cannot be obtained. This prevents a third party who moves device 14 from decrypting the encryption of the application, which is intellectual property, thus protecting the information.

[0049] Furthermore, when device 14 is powered off while in operation, at least the application used to decrypt the encrypted application, the second key, and the decryption logic are erased from the device's storage unit 101. As a result, even when device 14 is powered off, a third party cannot decrypt the encrypted application, which is intellectual property, thus protecting the information.

[0050] Furthermore, if device 14 is moved to an area where beacon information from beacon 16 cannot be received while in operation, it will erase at least the application used to decrypt the encrypted application, the second key, and the decryption logic from the storage unit 101 of device 14. This prevents a third party who moves device 14 from decrypting the application, which is intellectual property, thus protecting the information.

[0051] As described above, device 14 performs kitting in steps S71 to S74 (referred to as the kitting phase), and operates in steps S71, S75 to S79 ​​(referred to as the device operation phase). After device 14 stores the first key and encryption application in the kitting phase, it retains the memory of the first key and encryption application even when the power is turned off. After the power to device 14 is turned off and it is installed at the operation location, the device operation phase is executed when device 14 is started up.

[0052] Although embodiments of the present invention have been described above, the present invention is not limited to the embodiments described above. The object of the present invention can also be achieved by supplying a storage medium containing program code (computer program) that realizes the functions of the embodiments described above to a system or device, and by the computer of the supplied system or device reading and executing the program code stored in the storage medium. In this case, the program code read from the storage medium itself realizes the functions of the embodiments described above, and the storage medium that stores the program code constitutes the present invention. Furthermore, in the embodiments described above, each component functions by a computer executing a program, but some or all of the processing may be configured by dedicated electronic circuits (hardware). The present invention is not limited to the specific embodiments described above, and various modifications and changes are possible within the scope of the spirit of the present invention as described in the claims. [Explanation of symbols]

[0053] 10 Systems 11 Management Server 12 Kitting machines 13 Networks 14 devices 15 Near field communication 16 beacons

Claims

1. An application acquisition means for acquiring an encrypted application, which is an encrypted application, A first key acquisition means for acquiring a first decryption key fragment, which is one of the divided fragments of a decryption key used to decrypt the encryption application; A beacon detection means that receives beacon information that can identify the beacon from the beacon, A device information storage means that stores device information including a device ID that can identify the machine, A system authentication request transmission means that transmits system authentication information, including the beacon information received by the beacon detection means and the device information stored in the device information storage means, to a management server to receive system authentication, A second key acquisition means that, in accordance with the result of the system authentication by the management server, obtains a second decryption key fragment from the management server, which is the other half of the divided fragment of the decryption key used to decrypt the encryption application; A decryption logic acquisition means that, in accordance with the result of system authentication by the management server, acquires decryption logic for decrypting the encryption application from the management server, A decryption means that decrypts the encryption application using the decryption logic, using the decryption key obtained by restoring the first decryption key fragment and the second decryption key fragment, A device characterized by having the following features.

2. When the power of the device is turned off, and when the beacon detection means stops receiving the beacon information, at least the second decryption key fragment, the decryption logic, and the application decrypted by the decryption means are erased. The device according to feature 1.

3. A system including beacons, a management server, and devices, Means for transmitting an encrypted application, which is an encrypted application, to the device, Means for dividing the decryption key used to decrypt the aforementioned encryption application into a first decryption key fragment and a second decryption key fragment, Means for transmitting the first decryption key fragment to the device, Means for transmitting the second decryption key fragment to the management server, means for sending decryption logic for decrypting the encryption application to the management server, A means for transmitting beacon information that can identify the beacon from the beacon to the device, A system authentication request transmission means for transmitting system authentication information, consisting of the beacon information and device information including a device ID that can identify the device, from the device to the management server to receive system authentication, Means for transmitting the second decryption key fragment and the decryption logic from the management server to the device in accordance with the result of the system authentication by the management server, The device includes a decryption means that uses the decryption key obtained by restoring the first decryption key fragment and the second decryption key fragment from the management server to decrypt the encryption application using the decryption logic from the management server, A system characterized by having the following features.

4. The application acquisition process involves obtaining an encrypted application, which is an encrypted application. A first key acquisition step of obtaining a first decryption key fragment, which is one of the divided fragments of the decryption key used to decrypt the encryption application; A beacon detection process that receives beacon information that can identify the beacon from the beacon, A device information storage step that stores device information including a device ID that can identify the machine, A system authentication request transmission step involves transmitting system authentication information, including the beacon information received in the beacon detection step and the device information stored in the device information storage step, to a management server to receive system authentication. A second key acquisition step, in which, in accordance with the result of the system authentication by the management server, a second decryption key fragment, which is the other half of the divided fragment of the decryption key used to decrypt the encryption application, is obtained from the management server; A decryption logic acquisition step in which, in accordance with the result of system authentication by the management server, decryption logic for decrypting the encryption application is acquired from the management server, A decryption step in which the decryption logic decrypts the encryption application using the decryption key obtained by restoring the first decryption key fragment and the second decryption key fragment, A method for controlling a device, characterized by having the following features.

5. A method for controlling a system including beacons, a management server, and devices, The process of sending an encrypted application, which is an encrypted application, to the device, The process involves dividing the decryption key used to decrypt the aforementioned encryption application into a first decryption key fragment and a second decryption key fragment, The steps include transmitting the first decryption key fragment to the device, The steps include sending the second decryption key fragment to the management server, The process includes sending decryption logic for decrypting the encryption application to the management server, A step of transmitting beacon information that can identify the beacon from the beacon to the device, A system authentication request transmission step in which the device transmits system authentication information, consisting of the beacon information and device information including a device ID that can identify the device, to the management server to receive system authentication, The process involves transmitting the second decryption key fragment and the decryption logic from the management server to the device in accordance with the result of the system authentication by the management server. The decryption step involves using the device to recover the first decryption key fragment and the second decryption key fragment from the management server to obtain the decryption key, and then using the decryption logic from the management server to decrypt the encryption application; A method for controlling a system characterized by having the following features.

6. Computers, An application acquisition means for acquiring an encrypted application, which is an encrypted application. A first key acquisition means for acquiring a first decryption key fragment, which is one of the divided fragments of a decryption key used to decrypt the encryption application; A beacon detection means that receives beacon information that can identify the beacon from the beacon. Device information storage means that stores device information including a device ID that can identify the machine, A system authentication request transmission means that transmits system authentication information, including the beacon information received by the beacon detection means and the device information stored in the device information storage means, to a management server to receive system authentication. A second key acquisition means that, in accordance with the result of the system authentication by the management server, obtains a second decryption key fragment from the management server, which is the other half of the divided fragment of the decryption key used to decrypt the encryption application. Decryption logic acquisition means that, in accordance with the result of system authentication by the management server, acquires decryption logic for decrypting the encryption application from the management server, and Decryption means that decrypts the encryption application using the decryption logic, using the decryption key obtained by restoring the first decryption key fragment and the second decryption key fragment. A control program for a device characterized by its ability to function as such.