DETECTION SYSTEM, DETECTION DEVICE, DETECTION METHOD, AND DETECTION PROGRAM
The detection system performs one-to-one integrity verification along a Hamilton cycle, sharing challenge-response pairs, to efficiently check network device integrity with reduced overhead and without a central server, addressing the inefficiencies of conventional attestation technologies.
Patent Information
- Application Number
- JP2023565833
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-10
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2041-12-10
AI Technical Summary
Conventional attestation technologies face challenges in efficiently checking the integrity of all devices in a network due to high communication and calculation costs, particularly when a validation server becomes compromised.
A detection system with a base station and nodes that perform one-to-one integrity verification along a Hamilton cycle, sharing challenge-response pairs, and using hash values to verify node integrity without relying on a central validation server.
This approach allows efficient integrity checks across all network devices with reduced communication and calculation overhead, ensuring high accuracy and efficiency in detecting tampering without the need for a central verification server.
Smart Images

Figure 0007679891000001 
Figure 0007679891000002 
Figure 0007679891000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a detection system, a detection device, a detection method, and a detection program. [Background technology]
[0002] Attestation technology, which detects system tampering, is attracting attention. With attestation technology, digests such as hash values and checksums at a certain point in time when the entire storage of the monitored node can be considered normal are periodically obtained. Then, the obtained digest is compared with the digest of the current storage of the monitored node to confirm the integrity of the monitored node, that is, to check whether tampering has occurred within the node.
[0003] In software-based attestation technology, where all of this processing is done by software, it is assumed that the secret information of each node can always be safely stored in a reliable validation server. Therefore, if the validation server becomes infected, it will no longer be able to correctly detect tampering, and many models will fail.
[0004] In response to this problem, a technique has been disclosed that dispenses with the need for a validation server by distributing secret information and having nodes vote by majority vote (see Non-Patent Document 1). [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] Yi Yang, Xinran Wang, Sencun Zhu, and Guohong Cao, “Distributed Software-based Attestation for Node Compromise Detection in Sensor Networks”, 26th IEEE International Symposium on Reliable Distributed Systems Summary of the Invention [Problem to be solved by the invention]
[0006] However, in the conventional technology, it is difficult to check the integrity of all devices in a network. For example, a large number of communications and a large calculation cost are required to check the integrity of all devices in a network.
[0007] The present invention has been made in view of the above, and has an object to efficiently perform integrity check of all devices present in a network. [Means for solving the problem]
[0008] In order to solve the above-mentioned problems and achieve the object, the detection system of the present invention is a detection system having two or more nodes and a base station that holds information about each node, wherein the base station has a search unit that searches for a round trip path that passes through all nodes in a network only once, a calculation unit that sequentially calculates the same number of hash values as the number of nodes in the network, and a notification unit that notifies each node of its order on the round trip path, a hash value among the calculated hash values that corresponds to the order, and a subsequent node on the round trip path, and the node has a sending unit that sends the notified hash value and a challenge to the subsequent node in the order notified by the notification unit, a hash verification unit that verifies whether the sent hash value matches a value calculated from the notified hash value using a predetermined method, a return unit that returns a response to the sent challenge if the hash values match, and a response verification unit that verifies the returned response. Effect of the Invention
[0009] According to the present invention, it is possible to efficiently check the integrity of all devices present in a network. [Brief description of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram for explaining an overview of the detection system. [Diagram 2] FIG. 2 is a diagram for explaining an overview of the detection system. [Diagram 3] FIG. 3 is a diagram for explaining an outline of the detection system. [Figure 4] FIG. 4 is a schematic diagram illustrating a schematic configuration of the detection system. [Diagram 5] FIG. 5 is a diagram for explaining the processing of the base station. [Figure 6] FIG. 6 is a sequence diagram showing a procedure of the detection process. [Figure 7]FIG. 7 is a diagram illustrating a computer that executes the detection program. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. Note that the present invention is not limited to this embodiment. In addition, in the description of the drawings, the same parts are indicated by the same reference numerals.
[0012] [Detection system overview] Figures 1 to 3 are diagrams for explaining the outline of the detection system. First, Figure 1 illustrates one-to-one integrity checking of nodes. In one-to-one integrity checking, one node functions as a verifier and the other node functions as a prover, and a challenge-response procedure is used to thoroughly discover any tampering that has occurred in the information on the prover.
[0013] In the example shown in Fig. 1, the detection system includes node 1, node 2, and a base station, and is configured to be able to communicate securely with each other using common key cryptography or the like. First, as shown in Fig. 1 (1), node 1, which is the verifier, sends a random value (Nonce) as a challenge to node 2, which is the prover. At this time, node 1 expects a correct response to be returned from node 2 within a time limit. Node 2 sets the random value received as the challenge as the seed for its own random number generator.
[0014] Also, as shown in FIGS. 1(2) to (3), node 2 accesses its own storage, performs a random scan using the seed, generates a checksum or hash digest as a response, and sends it back to node 1.
[0015] As shown in Figure 1 (4), node 1 verifies the response. If node 2 is infected, it will not be able to generate a correct response, and node 1 will be able to detect that node 2 is infected. Then, as shown in Figure 1 (5), node 1 notifies the base station of the verification result. This enables the base station to verify the integrity of node 2 under its control.
[0016] Next, Fig. 2 illustrates an example of integrity verification among three or more nodes. In the example shown in Fig. 2, before deployment, each node calculates multiple pairs of challenges to be sent to itself and responses to those challenges, and stores them in memory. Then, as shown in Fig. 2(a), when a node is deployed on the network, it distributes the challenge / response pairs it holds to neighboring nodes and deletes the distributed challenge / response pairs from its own memory. As a result, neighboring nodes hold the challenges to be sent to the target node and the corresponding responses, and secret information is shared.
[0017] As shown in Fig. 2(b), for example, a node selected as a prover using an appropriate voting algorithm receives challenges from all neighboring nodes, calculates a response for each, and replies. The neighboring nodes compare the returned responses with the expected responses they hold, and if there is a discrepancy between the two, they notify the base station that the prover node is infected.
[0018] In the example shown in Figure 2, for the prover node indicated by ●, multiple adjacent nodes each hold a different challenge / response pair, and perform integrity checks on the prover node to determine whether it has been tampered with, for example, by majority vote. In this case, to check the integrity of one prover node, challenge / response communications and calculations occur as many times as the number of adjacent nodes.
[0019] Therefore, the detection system of this embodiment checks whether there is even one infected node in the network, instead of verifying the integrity of one node as a prover. Specifically, as shown in Fig. 3, the detection system 1 calculates a Hamilton cycle, which is a circuit that goes around all nodes in the network only once, and performs one-to-one integrity verification in order, with the previous node as a verifier and the subsequent node as a prover.
[0020] In this case, all integrity checks are successful only when all nodes are normal or when all nodes are infected. Cases where all nodes are infected are considered to be rare and negligible. Therefore, the detection system can perform integrity checks on the entire group of nodes in one process, without performing integrity checks N times on each of the N nodes. This makes it possible to significantly reduce communication overhead, etc., and perform integrity checks while suppressing the number of communications and calculation costs.
[0021] [Detection system configuration] Fig. 4 is a schematic diagram illustrating a schematic configuration of a detection system 1. As illustrated in Fig. 4, the detection system 1 includes a base station 10 and two or more nodes 20, which are configured to be able to communicate securely with each other using common key cryptography or the like.
[0022] The base station 10 holds information such as which node each node 20 in the network is within communication range of and which node's secret information each node 20 holds, and controls one-to-one integrity check between the nodes 20. That is, it calculates a Hamilton circuit for the nodes 20 in the network, and instructs the nodes 20 to perform one-to-one integrity check in the order of the Hamilton circuit. Then, each node 20 performs one-to-one integrity check with each other as a detection device. After that, the base station 10 aggregates the results of the integrity check between the nodes 20.
[0023] [Base Station Configuration] The base station 10 is realized by a CPU (Central Processing Unit), NP (Network Processor), FPGA (Field Programmable Gate Array), etc., and executes a processing program stored in a memory to function as a control unit 11. The base station 10 also has a storage unit 12 realized by a semiconductor memory element such as a Random Access Memory or a Flash Memory. The base station 10 also has a communication control unit (not shown), and communicates with the node 20 and other network devices, etc., via the communication control unit.
[0024] The storage unit 12 stores in advance the processing programs for operating the base station 10, data used during the execution of the processing programs, etc., or temporarily stores them each time processing is performed. The storage unit 12 may be configured to communicate with the control unit 11 via a communication control unit.
[0025] In this embodiment, node information 12a used in a detection process described later is stored in the storage unit 12. The node information 12a includes information on which node each node in the network is within its communication range, which node's private information each node holds, and the like.
[0026] The control unit 11 executes a processing program stored in the memory, and functions as a search unit 11a, a calculation unit 11b, a notification unit 11c, and an aggregation unit 11d, as exemplified in Fig. 4. Note that these functional units may be implemented in different hardware, or some of them may be implemented in different hardware. For example, the search unit 11a and the calculation unit 11b, and the notification unit 11c and the aggregation unit 11d may be implemented in different devices. The control unit 11 may also include other functional units.
[0027] The search unit 11a searches for a round route that passes through all nodes in the network only once. Specifically, the search unit 11a calculates a Hamilton cycle for all nodes in the network. The search unit 11a calculates a Hamilton cycle by referring to the communication status of the node 20 in the node information 12a and the sharing status of the challenge-response, which will be described later.
[0028] In the detection process described later, the detection system 1 performs one-to-one integrity verification with the node 20 at the front stage as the Verifier and the node 20 at the rear stage as the Prover, so as to go around the Hamilton circuit in order.
[0029] Here, if a challenge is sent from a normal node 20 to an infected node 20, a correct response will not be generated. Therefore, the integrity check will be successful in all nodes 20 in one go only if all nodes 20 are normal or all nodes 20 are infected. Since it is considered rare for all nodes 20 to be infected, the integrity check of all nodes 20 can be performed by a detection process described later.
[0030] The calculation unit 11b sequentially calculates hash values in the same number as the number N of nodes 20 in the network. Furthermore, the notification unit 11c notifies each node 20 of its order i in the Hamilton loop, the (Ni)th hash value among the calculated hash values corresponding to the order, and the (i+1)th node 20 in the subsequent stage in the Hamilton loop. Specifically, the notification unit 11c notifies each node 20 in the Hamilton loop of the calculated hash values in ascending order of the order in the Hamilton loop, and in descending order of the calculation order. That is, the notification unit 11c notifies the i-th node 20 in the Hamilton loop of the (Ni)th calculated hash value.
[0031] Here, Fig. 5 is a diagram for explaining the processing of the base station. The calculation unit 11b applies a hash function to the initial value X to calculate a hash value X'. Also, the calculation unit 11b applies a hash function to the hash value X' to calculate a hash value X''. As shown in Fig. 5(a), the calculation unit 11b repeats this processing to generate a hash chain consisting of the same number of hash values as the number of nodes 20 in the network.
[0032] Then, the notification unit 11c inverts the hash chain generated by the calculation unit 11b (reverse hash chain) and rearranges the hash values in descending order of the calculation order, as shown in Fig. 5(b).Then, the notification unit 11c notifies each node 20 of the hash values so that the order of the Hamilton cycle corresponds to the rearranged order shown in Fig. 5(b), as shown in Fig. 5(c).
[0033] As a result, a hash verification unit 21b of the node 20, which will be described later, can use the hash value sent from the previous node 20 and the hash value notified to itself to verify whether the previous node 20 is the node 20 expected by the base station 10. For example, when the hash value (e.g., X'') sent from the previous node 20 matches with the hash value (X'') calculated by applying a hash function to the hash value (e.g., X') notified to itself, the hash verification unit 12b can confirm that it is the expected node 20.
[0034] Returning to the explanation of Fig. 4, the aggregation unit 11d aggregates the results of verification by the hash verification unit 21b or the response verification unit 21d of the node 20, which will be described later. This enables the base station 10 to aggregate the verification results, which will be described later, of each node 20. For example, if the verification results of each node 20 include even one abnormal result that is different from an expected value, the aggregation unit 11d issues an alert, assuming that an infected node 20 is present in the network.
[0035] [Node configuration] The node 20 is realized by a CPU, NP, FPGA, or the like, and executes a processing program stored in memory to function as a control unit 21. The node 20 also has a storage unit 22 realized by a semiconductor memory element such as a RAM or a flash memory. The node 20 also has a communication control unit (not shown), and communicates with the base station 10, other network devices, and the like via the communication control unit.
[0036] The storage unit 22 stores in advance the processing programs for operating the node 20, data used during the execution of the processing programs, etc., or temporarily stores them each time processing is performed. The storage unit 22 may be configured to communicate with the control unit 21 via a communication control unit.
[0037] In this embodiment, the storage unit 22 stores storage content information 22a, challenge / response information 22b, etc. The storage content information 22a is referred to when the return unit 21c generates a response to a challenge sent from the previous node 20 in a detection process described later.
[0038] Moreover, the challenge / response information 22b is a combination of a challenge to be sent to each node in the network and a normal response to the challenge. As described above, before being deployed, the node 20 calculates a plurality of challenges to be sent to itself and responses to those challenges.
[0039] Then, when the node 20 is placed in the network, it distributes the challenge / response pairs it holds to the neighboring nodes 20 and deletes the distributed challenge / response pairs from its own memory. As a result, each of the neighboring nodes 20 holds challenge / response information 22b as a response corresponding to the challenge sent to the Prover node. This allows each node in the network to share secret information.
[0040] The control unit 21 executes a processing program stored in the memory, thereby functioning as a sending unit 21a, a hash verification unit 21b, a return unit 21c, and a response verification unit 21d, as illustrated in Fig. 4. The control unit 11 may also include other functional units.
[0041] The sending unit 21a sends the notified hash value and the challenge to the subsequent node 20 in accordance with the order i notified by the notifying unit 11c. Specifically, the sending unit 21a of the i-th node 20 sends to the (i+1)-th node 20 the (Ni)-th hash value notified by the notifying unit 11c and a challenge for the (i+1)-th node 20.
[0042] The sending unit 21a refers to the challenge / response information 22b in the storage unit 22 and sends a challenge corresponding to the (i+1)th node in the subsequent stage to the (i+1)th node in the subsequent stage.
[0043] The hash verification unit 21b verifies whether or not the hash value sent from the i-th node 20 in the previous stage matches a value calculated from the notified hash value using a predetermined method. Specifically, the hash verification unit 21b verifies whether or not the hash value sent from the i-th node 20 in the previous stage matches a hash value calculated from the notified hash value.
[0044] For example, the hash verification unit 21b of the (i+1)th node 20 verifies whether the (Ni)th hash value sent from the previous i-th node 20 matches the hash value obtained by applying a hash function to the (N-(i+1))th hash value notified to the (i+1)th node 20. If they match, it is confirmed that the previous node 20 is the i-th node 20 expected by the base station 10.
[0045] If there is a match, the hash verification unit 21b transfers the process to the return unit 12c described below. If there is a mismatch, the hash verification unit 21b may notify the aggregation unit 11d of the base station 10 of the verification result, for example.
[0046] If the hash values match in the hash verification unit 21b, the return unit 21c returns a response to the challenge sent. Specifically, the return unit 21c extracts the Nonce included in the challenge and sets it as a seed. The return unit 12c then generates a response by referring to the storage content information 22a and returns it to the previous node 20.
[0047] The response verification unit 21d verifies the returned response. Specifically, the response verification unit 21d refers to the challenge / response information 22b in the storage unit 22 and verifies whether the returned response matches a normal response. If they match, the response verification unit 21d determines that the subsequent node 20 is normal, and if they do not match, it determines that the subsequent node 20 is infected.
[0048] Furthermore, the response verification unit 21d notifies the aggregation unit 11d of the base station 10 of the verification result. This enables the base station 10 to aggregate the response verification results at each node 20, as described above. For example, if the response verification results at each node 20 include a determination result that at least one subsequent node 20 is infected, the aggregation unit 11d issues an alert, assuming that an infected node 20 exists in the network.
[0049] Even when the hash verification unit 21b notifies the aggregation unit 11d of the verification result, the aggregation unit 11d issues an alert, assuming that the processing that is not dependent on the order of the Hamilton loop expected by the base station 10 has been executed.
[0050] [Detection process] Next, the detection process by the detection system 1 according to the present embodiment will be described with reference to Fig. 6. Fig. 6 is a sequence diagram showing the procedure of the detection process. The sequence in Fig. 6 starts, for example, when an operation input is made to instruct the start of the detection process.
[0051] First, the notification unit 11c of the base station 10 notifies each node 20 of the order i in the Hamilton loop, the (Ni)th hash value among the calculated hash values according to the order, and the (i+1)th node 20 in the succeeding stage in the Hamilton loop (step S1).
[0052] First, in the first node 20, the sending unit 21a sends to the second node 20 the (N-1)th hash value notified by the notifying unit 11c and a challenge for the second node 20 (step S10).
[0053] Specifically, the sending unit 21a refers to the challenge / response information 22b in the storage unit 22 and sends a challenge corresponding to the second node to the second node in the subsequent stage.
[0054] The hash verification unit 21b of the second node 20 verifies whether or not the (N-1)th hash value sent from the first node 20 in the previous stage matches the hash value obtained by applying a hash function to the (N-2)th hash value notified to itself (step S11).
[0055] If the hash values match in the hash verification unit 21b, the return unit 21c of the second node 20 returns a response to the challenge sent (step S12). Specifically, the return unit 21c extracts the nonce included in the challenge and sets it as a seed. Then, the return unit 21c generates a response by referring to the storage content information 22a, and returns it to the first node 20.
[0056] The response verification unit 21d of the first node 20 verifies the returned response (step S13). Specifically, the response verification unit 21d refers to the challenge / response information 22b in the storage unit 22, and verifies whether the returned response matches a normal response. If they match, the response verification unit 21d determines that the second node 20 is normal, and if they do not match, it determines that the second node 20 is infected.
[0057] Moreover, the response verification unit 21d notifies the aggregation unit 11d of the base station 10 of the verification result (step S14).
[0058] Similarly, in the second node 20, the sending unit 21a sends to the third node 20 the (N-2)th hash value notified by the notifying unit 11c and a challenge for the third node 20 (step S20).
[0059] The hash verification unit 21b of the third node 20 verifies whether or not the (N-2)th hash value sent from the second node 20 in the previous stage matches the hash value obtained by applying a hash function to the (N-3)th hash value notified to itself (step S21).
[0060] If the hash values match in the hash verification unit 21b, the return unit 21c of the third node 20 returns a response to the sent challenge (step S22).
[0061] The response verification unit 21d of the second node 20 verifies whether the returned response matches a normal response (step S23). If they match, the response verification unit 21d determines that the third node 20 is normal, and if they do not match, it determines that the third node 20 is infected.
[0062] Moreover, the response verification unit 21d notifies the aggregation unit 11d of the base station 10 of the verification result (step S24).
[0063] Similarly, in the i-th node 20, the sending unit 21a sends to the (i+1)-th node 20 the (Ni)-th hash value notified by the notifying unit 11c and a challenge for the (i+1)-th node 20.
[0064] Specifically, the sending unit 21a sends a challenge corresponding to the (i+1)th node in the subsequent stage to the (i+1)th node in the subsequent stage by referring to the challenge / response information 22b in the memory unit 22.
[0065] The hash verification unit 21b of the (i+1)th node 20 verifies whether or not the (Ni)th hash value sent from the previous i-th node 20 matches the hash value obtained by applying a hash function to the (N-(i+1))th hash value notified to itself.
[0066] If the hash values match in the hash verification unit 21b, the return unit 21c of the (i+1)th node 20 returns a response to the sent challenge.
[0067] The response verification unit 21d refers to the challenge / response information 22b in the storage unit 22 and verifies whether the returned response matches a normal response. If they match, the response verification unit 21d determines that the subsequent node 20 is normal, and if they do not match, it determines that the subsequent node 20 is infected. The response verification unit 21d also notifies the aggregation unit 11d of the base station 10 of the verification result.
[0068] In the detection system 1, the same process as above is repeated until the process between the Nth node 20 and the first node 20 is reached.
[0069] Then, when the response verification results of each node 20 include a determination result that at least one subsequent node 20 is infected, the aggregation unit 11d issues, for example, an alert, assuming that an infected node 20 exists in the network. This completes a series of detection processes.
[0070] [effect] As described above, in the detection system 1, in the base station 10, the search unit 11a searches for a round trip path that passes through all nodes in the network only once. The calculation unit 11b calculates hash values in the same number as the number of nodes in the network in order. The notification unit 11c notifies each node of its order in the round trip path, a hash value among the calculated hash values corresponding to the order, and a node in the subsequent stage in the round trip path. In the node 20, the sending unit 21a sends the notified hash value and a challenge to the node in the subsequent stage according to the order notified by the notification unit 11c. The hash verification unit 21b verifies whether or not the hash value sent from the node in the previous stage matches a value calculated from the notified hash value by a predetermined method. The return unit 21c returns a response to the challenge sent when the hash values match. The response verification unit 21d verifies the returned response.
[0071] This allows the detection system 1 to perform integrity checks on the entire node group in a single process. This allows communication overhead to be significantly reduced, and integrity checks can be performed while suppressing the number of communications and calculation costs. In this way, it is possible to efficiently perform integrity checks on all devices in the network without the need for a verification server that can safely store the secret information of each node.
[0072] Furthermore, the storage unit 22 of the node 20 stores a combination of a challenge to be sent to each node in the network and a normal response to the challenge. In this case, the sending unit 21a refers to the storage unit 22 and sends a challenge corresponding to the subsequent node as a challenge to the subsequent node. Furthermore, the response verification unit 21d refers to the storage unit 22 and verifies whether or not the returned response matches a normal response. This makes it possible for the node 20 as a detection device to perform highly accurate and efficient integrity verification of all the nodes 20 present in the network without the need for a verification server that can safely store the confidential information of each node.
[0073] The notification unit 11c notifies each node on the round trip of the calculated hash values in ascending order of the order on the round trip, and in descending order of the order of the calculation. In this case, the hash verification unit 21b verifies whether the sent hash value matches the hash value calculated from the notified hash value. This makes it possible to efficiently verify the integrity of the node 20 according to the specified round trip route.
[0074] In addition, in the base station 10, the aggregation unit 11d aggregates the results of the verification by the hash verification unit 21b or the response verification unit 21d. This makes it possible to determine that even one subsequent node 20 is infected. Therefore, the detection system 1 can easily check whether or not an infected node 20 exists in the network.
[0075] [program] A program in which the process executed by the detection system 1 according to the above embodiment is written in a language executable by a computer can also be created. As an embodiment, the base station 10 and the node 20 can be implemented by installing a detection program that executes the above detection process as package software or online software on a desired computer. For example, the above detection program can be executed by an information processing device, causing the information processing device to function as the base station 10 and the node 20. In addition, the information processing device also includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone System), and further slate terminals such as PDA (Personal Digital Assistant). The functions of the base station 10 and the node 20 may be implemented in a cloud server.
[0076] 7 is a diagram showing an example of a computer that executes a detection program. The computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0077] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1031. The disk drive interface 1040 is connected to a disk drive 1041. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041. The serial port interface 1050 is connected to a mouse 1051 and a keyboard 1052, for example. The video adapter 1060 is connected to a display 1061, for example.
[0078] Here, the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. Each piece of information described in the above embodiments is stored in the hard disk drive 1031 or memory 1010, for example.
[0079] The detection program is stored in the hard disk drive 1031 as, for example, a program module 1093 in which instructions to be executed by the computer 1000 are written. Specifically, the hard disk drive 1031 stores the program module 1093 in which the processes to be executed by the base station 10 and the node 20 described in the above embodiment are written.
[0080] Furthermore, data used for information processing by the detection program is stored as program data 1094, for example, in the hard disk drive 1031. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the hard disk drive 1031 into the RAM 1012 as necessary, and executes each of the above-mentioned procedures.
[0081] The program module 1093 and program data 1094 related to the detection program are not limited to being stored in the hard disk drive 1031, and may be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1041 or the like. Alternatively, the program module 1093 and program data 1094 related to the detection program may be stored in another computer connected via a network such as a LAN (Local Area Network) or a WAN (Wide Area Network), and read by the CPU 1020 via the network interface 1070.
[0082] Although the embodiment to which the invention made by the present inventor is applied has been described above, the present invention is not limited by the description and drawings which form a part of the disclosure of the present invention according to the present embodiment. In other words, other embodiments, examples, operation techniques, etc. made by those skilled in the art based on the present embodiment are all included in the scope of the present invention. [Explanation of symbols]
[0083] 1. Detection System 10 Base Station 11, 21 Control section 11a Search Department 11b Calculation part 11c Notification Department 11d Consolidation section 12, 22 Storage section 12a Node Information 20 nodes (detection devices) 21a Sending Section 21b Hash verification section 21c Return Department 21d Response verification section 22a Storage Content Information 22b Challenge / Response Information
Claims
1. 1. A sensing system having two or more nodes and a base station that maintains information about each node, comprising: The base station a search unit that searches for a round route that passes through all nodes in the network only once; A calculation unit that sequentially calculates the same number of hash values as the number of nodes in the network; a notification unit configured to notify each node of a sequence on the round trip path, a hash value corresponding to the sequence among the calculated hash values, and a subsequent node on the round trip path, The node: a sending unit that sends the notified hash value and challenge to a subsequent node in the order notified by the notifying unit; a hash verification unit that verifies whether the transmitted hash value matches a value calculated from the notified hash value using a predetermined method; a response unit that returns a response to the challenge sent when the hash values match; a response verification unit that verifies the returned response; A detection system comprising:
2. The node further includes a storage unit that stores a combination of a challenge to be sent to each node in the network and a normal response to the challenge, the sending unit sends, to the subsequent node, a challenge corresponding to the subsequent node by referring to the storage unit; The response verification unit refers to the storage unit and verifies whether the returned response matches a normal response. The detection system of claim 1 .
3. the notification unit notifies each node on the round trip path of the calculated hash values in ascending order of the order on the round trip path, and in descending order of the order in which the hash values were calculated; The hash authentication unit verifies whether the transmitted hash value matches a hash value calculated from the notified hash value. The detection system of claim 1 .
4. 2. The detection system of claim 1, wherein the base station further comprises an aggregator that aggregates a result of the verification by the hash verification unit or the response verification unit.
5. a storage unit that stores a combination of a challenge to be sent to each detection device in the network and a normal response to the challenge; a sending unit that refers to the storage unit and sends a challenge corresponding to a subsequent detection device to the subsequent detection device according to a predetermined circular route that passes through all detection devices in the network only once; A response unit that returns a response to the challenge sent; a response verification unit that refers to the storage unit and verifies whether the returned response matches a normal response; A detection device comprising:
6. 1. A method of detection implemented by a detection system having two or more nodes and a base station maintaining information about each node, comprising: a searching step of searching for a round trip route that passes through all nodes in the network exactly once; A calculation step of sequentially calculating the same number of hash values as the number of nodes in the network; a notification step of notifying each node of its order on the round trip path, a hash value corresponding to the order among the calculated hash values, and a subsequent node on the round trip path; a sending step of sending the notified hash value and the challenge to a subsequent node in the order notified in the notifying step; a hash verification step of verifying whether the transmitted hash value matches a value calculated from the notified hash value using a predetermined method; a returning step of returning a response to the challenge sent when the hash values match; a response verification step of verifying the returned response; A detection method comprising:
7. a searching step of searching for a circular route that passes through all nodes in the network exactly once; A calculation step of sequentially calculating the same number of hash values as the number of nodes in the network; a notification step of notifying each node of its order on the round trip path, a hash value corresponding to the order among the calculated hash values, and a subsequent node on the round trip path; a sending step of sending the notified hash value and the challenge to a subsequent node in accordance with the order notified in the notifying step; a hash verification step of verifying whether the transmitted hash value matches a value calculated from the notified hash value using a predetermined method; a returning step of returning a response to the challenge sent when the hash values match; a response verification step of verifying the returned response; A detection program for causing a computer to execute the above.
Citation Information
Patent Citations
Authentication system of on-vehicle control device and authentication method of on-vehicle control device
JP2013219710A