Key Information Update System
The key information update system simplifies key updates by using encrypted transmissions between wireless master and slave units, addressing the complexity of existing systems and ensuring reliable updates.
Patent Information
- Application Number
- JP2021136934
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-08-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-08-25
AI Technical Summary
Existing key information management systems require complex configurations and multiple communication methods to handle key updates, especially when multicast communication fails, necessitating a simpler approach for key updates.
A key information update system that uses a wireless master unit and a wireless slave unit to update a session key through encrypted key information transmission, allowing for seamless key updates without the need for separate communication methods.
Enables key updates with a simple configuration, reducing the complexity of communication methods and ensuring reliable key updates even when initial communication fails.
Smart Images

Figure 0007684147000001 
Figure 0007684147000002 
Figure 0007684147000003
Abstract
Description
Technical Field
[0001] The present invention relates to a key information update system, a key information update method, and a key information update program.
Background Art
[0002] Conventionally, a technique has been proposed for encrypting and decrypting a telegram (message) transmitted and received among a plurality of communication devices using a key. In order to maintain secure communication between communication devices, it is recommended that the key used for encrypting and decrypting a telegram be updated regularly. However, the key may not be updated due to non-delivery of a telegram regarding key update or the like.
[0003] Patent Document 1 discloses a key information control device that updates a key by multicast communication with respect to a key used in a network including a plurality of communication devices. When the key update fails, the key information management device disclosed in this Patent Document 1 performs unicast communication with a retransmission function to update the key.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] In the key information management device disclosed in Patent Document 1, when the key update fails, it is necessary to switch to unicast communication with a retransmission function, which has a different communication method from normal multicast communication. That is, the key information management device disclosed in Patent Document 1 needs to separately provide a communication method when the key update fails, and each communication device also needs to support a plurality of communication methods.
[0006] The present invention has been made in view of the problems of such prior art. And an object of the present invention is to provide a key information update system capable of performing key update with a simple configuration.
Means for Solving the Problems
[0007] A key information update system according to an aspect of the present invention is a key information update system that updates a session key used for encryption and decryption of a telegram transmitted and received between a wireless master unit and a wireless slave unit. The wireless master unit includes an update key information transmission unit that transmits, to the wireless slave unit, update key information obtained by encrypting an update-scheduled key stored in the master unit storage unit of the wireless master unit with the session key stored in the master unit storage unit; a master unit information transmission unit that transmits, to the wireless slave unit, master unit information regarding the wireless master unit encrypted with the update-scheduled key; a master unit determination unit that determines whether or not slave unit information regarding the wireless slave unit transmitted from the wireless slave unit has been received; and a master unit key update unit that updates the session key to the update-scheduled key. The wireless slave unit includes an update key information reception unit that receives the update key information transmitted from the wireless master unit, decrypts the update key information with the session key stored in the slave unit storage unit of the wireless slave unit to obtain the update-scheduled key, and stores the update-scheduled key in the slave unit storage unit; a master unit information reception unit that receives the master unit information transmitted from the wireless master unit and decrypts the master unit information with the update-scheduled key; a slave unit determination unit that determines whether or not to transmit the slave unit information to the wireless master unit based on the update key information and the master unit information; and a slave unit information transmission unit that transmits, to the wireless master unit, the slave unit information encrypted with the update-scheduled key when it is determined in the slave unit determination unit that the slave unit information is to be transmitted, and a slave unit key update unit that updates the session key to the update-scheduled key.
[0008] A key information update method according to another aspect of the present invention is a key information update method executed by a computer for updating a session key used for encryption and decryption of a telegram transmitted and received between a wireless master device and a wireless slave device. The method includes: encrypting an update-scheduled key stored in the master device storage unit of the wireless master device with the session key stored in the master device storage unit, and transmitting the encrypted update key information to the wireless slave device; receiving the update key information transmitted from the wireless master device; decrypting the update key information with the session key stored in the slave device storage unit of the wireless slave device to obtain the update-scheduled key, storing the obtained update-scheduled key in the slave device storage unit; encrypting master device information regarding the wireless master device with the update-scheduled key, and transmitting the encrypted master device information to the wireless slave device; receiving the master device information transmitted from the wireless master device, decrypting the received master device information with the update-scheduled key; determining whether to transmit slave device information regarding the wireless slave device to the wireless master device based on the update key information and the master device information; if it is determined to transmit the slave device information, encrypting the slave device information with the update-scheduled key and transmitting the encrypted slave device information to the wireless master device; determining whether the slave device information transmitted from the wireless slave device has been received; if it is determined that the slave device information has been received, updating the session key of the wireless master device to the update-scheduled key; and if the slave device information has been transmitted to the wireless master device, updating the session key of the wireless slave device to the update-scheduled key.
[0009] A key information update program according to another aspect of the present invention is a key information update program for causing a computer to update a session key used for encrypting and decrypting a telegram transmitted and received between a wireless master unit and a wireless slave unit. The program includes steps of: transmitting, to the wireless slave unit, update key information obtained by encrypting an update-scheduled key stored in a master unit storage unit with a session key stored in the master unit storage unit of the wireless master unit; receiving the update key information transmitted from the wireless master unit, decrypting the update key information with the session key stored in a slave unit storage unit of the wireless slave unit to obtain the update-scheduled key, and storing the update-scheduled key in the slave unit storage unit; transmitting, to the wireless slave unit, master unit information regarding the wireless master unit encrypted with the update-scheduled key; receiving the master unit information transmitted from the wireless master unit and decrypting the master unit information with the update-scheduled key; determining whether to transmit slave unit information regarding the wireless slave unit to the wireless master unit based on the update key information and the master unit information; when it is determined to transmit the slave unit information, transmitting the slave unit information encrypted with the update-scheduled key to the wireless master unit; determining whether the slave unit information transmitted from the wireless slave unit has been received; when it is determined that the slave unit information has been received, updating the session key of the wireless master unit to the update-scheduled key; and when the slave unit information has been transmitted to the wireless master unit, updating the session key of the wireless slave unit to the update-scheduled key.
Effect of the Invention
[0010] According to the present invention, it is possible to provide a key information update system capable of performing key update with a simple configuration.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Mode for Carrying Out the Invention
[0012] Hereinafter, the key information update system according to the present embodiment will be described in detail with reference to the drawings. Note that the dimensional ratios in the drawings are exaggerated for convenience of explanation and may be different from the actual ratios. In the following description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.
[0013] FIG. 1 is a diagram showing the configuration of a wireless communication system 1 to which the key information update system according to the present embodiment is applied. As shown in FIG. 1, the wireless communication system 1 includes a metering network 10, a management device 30, and a network 40.
[0014] In this embodiment, the metering network 10 is configured to include a plurality of meters 20, and mutual communication between the meters 20 is enabled by wireless devices provided in the meters 20. In this embodiment, the meter 20 is, for example, a meter that measures water, gas, electricity, etc. installed in a house. Also, as the communication standard in the metering network 10, for example, "U-bus air" used in a wireless telemetering system is applied. This "U-bus air" is a communication method that enables communication between wireless devices provided in the meter 20, uses the 920 MHz band, and is a short-range wireless communication method that realizes ultra-low power consumption.
[0015] The plurality of meters 20 included in the metering network 10 include a master meter 20a and a plurality of slave meters 20b connected to the master meter 20a. Hereinafter, when there is no need to distinguish between the master meter 20a and the slave meter 20b, they are simply referred to as "meter 20".
[0016] The slave meter 20b is provided with an MT wireless device 200 (meter wireless device) as a wireless device of the slave unit. Note that the MT wireless device 200 corresponds to a wireless slave unit.
[0017] Also, the master meter 20a is provided with a GW wireless device 100 that performs wireless communication with each of the plurality of MT wireless devices 200 and further communicates with the management device 30 via the network 40. Note that the GW wireless device 100 corresponds to a wireless master unit.
[0018] The management device 30 is a communication center (central monitoring center) that manages information of each meter 20 included in the metering network 10. For example, the management device 30 sends a telegram (message) of a metering data request to each meter 20 via the GW wireless device 100, and the GW wireless device 100 and the MT wireless device 200 that have received the telegram of the metering data request return the metering data of the meter 20 to the management device 30. A part of the information managed by this management device 30 is provided to gas companies, water companies, etc.
[0019] In this embodiment, the network 40 is a wide-area communication network in which the management device 30 and the GW radio 100 can communicate with each other, and is constituted by, for example, a carrier network such as a mobile phone network or the Internet. That is, the GW radio 100 has a function as a gateway that relays different wireless standards between the network 40 and the metering network 10. Note that the communication standards of the network 40 and the metering network 10 may be the same communication standard.
[0020] (Configuration of the key information update system) Next, the configurations of the GW radio 100 and the MT radio 200 provided in the key information update system will be described. FIG. 2 is a block diagram showing the configurations of the GW radio 100 and the MT radio 200. Since the configuration of the MT radio 200 is the same as that of the GW radio 100, the configuration of the GW radio 100 will be described below.
[0021] The GW radio 100 includes a control unit 110, a storage unit 120, an input / output IF 130, and a communication IF 140.
[0022] The control unit 110 may be configured as, for example, a general-purpose microcomputer. In this case, a computer program for functioning as the GW radio 100 may be installed in the microcomputer. By executing the computer program, the microcomputer functions as a plurality of information processing circuits provided in the GW radio 100. Further, the control unit 110 may implement a plurality of information processing circuits provided in the GW radio 100 by software, or may prepare dedicated hardware to constitute the information processing circuits. Further, a plurality of information processing circuits may be constituted by individual hardware.
[0023] The storage unit 120 stores the master key information 121 and / or the session key information 122, which will be described later, as data. Note that the storage unit 120 for storing each of these data may be one or plural. For example, for one storage unit 120, it may be configured to store data in divided areas. Alternatively, the data may be distributed and stored in a plurality of storage devices installed at physically separated locations. Note that the storage unit 120 of the GW radio 100 corresponds to the master unit storage unit, and the storage unit 220 of the MT radio 200 corresponds to the slave unit storage unit.
[0024] The input / output IF 130 is, for example, a component (Interface) for the user to exchange data with the GW radio 100. The user can set the meter 20 or the GW radio 100 via the input / output IF 130. Also, the input / output IF 130 can display the information of the meter 20 or the GW radio 100 via a display unit (not shown) provided in or connected to the meter 20 or the GW radio 100. The user can obtain the information of the meter 20 or the GW radio 100 displayed on the display unit via the input / output IF 130.
[0025] The communication IF 140 of the GW radio 100 is an interface for enabling communication between the GW radio 100 and the MT radio 200 via the communication IF 240 of the MT radio 200. Also, the communication IF 140 of the GW radio 100 has a function for enabling communication with the management device 30 via the network 40.
[0026] (Functions of the key information update system) Next, the functions of the key information update system will be described. FIG. 3A is a functional block diagram showing the functions provided in the GW radio 100. Also, FIG. 3B is a functional block diagram showing the functions provided in the MT radio 200. Hereinafter, the functions of the key information update system shown in FIGS. 3A and 3B will be described using the sequence diagram shown in FIG. 4.
[0027] As shown in FIG. 3A, the control unit 110 of the GW radio 100 includes an update key information transmission unit 111, a master unit information transmission unit 112, a determination unit 113, and a session key update unit 115 as functions. Further, the storage unit 120 of the GW radio 100 stores master key information 121 and session key information 122. Note that the determination unit 113 of the GW radio 100 corresponds to a master unit determination unit. Also, the session key update unit 115 of the GW radio 100 corresponds to a master unit key update unit.
[0028] In the present embodiment, the master key is key information used when generating, replicating, or processing a key, and is used, for example, when generating a session key. Also, in the present embodiment, the session key is key information used for encrypting and decrypting a telegram transmitted and received in communication between the GW radio 100 and the MT radio 200.
[0029] Also, as shown in FIG. 3B, the control unit 210 of the MT radio 200 includes an update key information reception unit 211, a master unit information reception unit 212, a determination unit 213, a slave unit information transmission unit 214, and a session key update unit 215 as functions. Note that the determination unit 213 of the MT radio 200 corresponds to a slave unit determination unit. Also, the session key update unit 215 of the MT radio 200 corresponds to a slave unit key update unit.
[0030] Further, the storage unit 220 of the MT radio 200 stores session key information 222. Note that in the example shown in FIG. 3B, an example in which the storage unit 220 does not include an area related to master key information is shown, but this configuration does not limit the configuration of the present embodiment, and the storage unit 220 of the MT radio 200 may be configured to include an area related to master key information.
[0031] In the session key information 122 and the session key information 222 shown in FIG. 4, two areas, a C area (Current area) and an N area (Next area), are provided, and session keys are stored in the C area and / or the N area, respectively. The C area stores a session key used for the messages transmitted and received between the current GW radio 100 and the MT radio 200. Also, the N area stores an update-scheduled key to be updated in the next session key update. In this embodiment, the session key, which is the update-scheduled key stored in the N area, is also used for a part of the messages transmitted and received between the current GW radio 100 and the MT radio 200. Details of the application of the session key stored in this N area will be described later.
[0032] At the start of the process shown in FIG. 4, an example is shown where the session key S1 is stored as the currently used session key in the C area of the session key information 122. Also, in the example shown in FIG. 4, an example is shown where the session key S2 is stored as the update-scheduled key to be updated in the next key update process in the N area of the session key information 122.
[0033] Similarly, at the start of the process shown in FIG. 4, an example is shown where the session key S1 is stored as the currently used session key in the C area of the session key information 222. On the other hand, at the start of the process shown in FIG. 4, an example is shown where no update-scheduled key to be updated in the next update process is stored in the N area of the session key information 222.
[0034] An example of a telegram transmitted and received between the GW radio 100 shown in FIG. 4 and the MT radio 200 is shown in FIG. 5. In the present embodiment, as telegrams related to key setting or key update, "update key information" transmission, "parent device information" transmission, and "child device information" transmission are included. Further, as telegrams related to data transmission and reception performed between the GW radio 100 and the MT radio 200, for example, telegrams such as "needle inspection data request" and "needle inspection data response" are included. Note that the "session key (C area)" and the "key to be updated (N area)" described in the column of "encryption / decryption key information" in FIG. 5 are information related to the key used to encrypt the telegram and the key used to decrypt the telegram, respectively. In the present embodiment, information related to the key corresponding to this telegram is assumed to be stored in the header of each telegram, and the radio device on the receiving side of the telegram decrypts the telegram based on the information related to the key stored in this header.
[0035] The update key information transmission unit 111 of the GW radio 100 transmits "update key information" to be updated to the MT radio 200. Specifically, the update key information transmission unit 111 encrypts the key to be updated stored in the N area of the session key information 122 with the session key stored in the C area of the session key information 122 in the storage unit 120 of the GW radio 100, and transmits the encrypted update key information to the MT radio 200. The process of the update key information transmission unit 111 transmitting the "update key information" corresponds to step S401 in the example of FIG. 4.
[0036] Specifically, in step S401, the GW radio 100, which is the parent device, transmits a telegram (message) of "update key information" to the MT radio 200, which is the child device. Here, it is assumed that the "update key information" includes information related to the session key S2. Further, the "update key information" is information encrypted by the session key S1 and is a telegram that can be decrypted by the session key S1.
[0037] Note that in FIG. 4, the messages transmitted and received between the GW radio 100 and the MT radio 200 are indicated by parentheses around the keys for encryption and decryption. That is, in the example shown in FIG. 4, each message is a message encrypted by the session key S1 or the session key S2 corresponding to the key (S1 or S2) in parentheses and is a message that can be decrypted.
[0038] The update key information receiving unit 211 of the MT radio 200 receives the "update key information" transmitted from the GW radio 100. Specifically, the update key information receiving unit 211 receives the "update key information" transmitted from the GW radio 100, decrypts the "update key information" with the session key stored in the C area of the session key information 222 to obtain the key scheduled for update, and further stores the decrypted key scheduled for update in the N area of the session key information 222 in the storage unit 220. The process of the update key information receiving unit 211 receiving the "update key information" corresponds to step S402 in the example shown in FIG. 4.
[0039] Specifically, in step S402, the update key information receiving unit 211 of the MT radio 200 receives the "update key information" transmitted from the GW radio 100 and stores it in the location of the session key information 222 in the storage unit 220. In the example shown in FIG. 4, the MT radio 200 decrypts the "update key information" including information related to the session key S2 with the session key S1 based on the information set in the header of the "update key information" message and stores it in the N area of the session key information 222. In the example shown in FIG. 4, the session key S2, which is the key scheduled for update, is stored in the N area of this session key information 222.
[0040] Next, the master unit information transmitting unit 112 transmits a message of "master unit information" from the GW radio 100 to the MT radio 200. Specifically, the master unit information transmitting unit 112 transmits the "master unit information" regarding the GW radio 100 encrypted with the "key scheduled for update" stored in the N area of the session key information 122 to the MT radio 200. The process of the master unit information transmitting unit 112 transmitting the "master unit information" corresponds to step S403.
[0041] Specifically, in step S403, the master unit information transmission unit 112 of the GW radio 100 transmits "master unit information" to the MT radio 200. In the example shown in FIG. 4, it is assumed that the "master unit information" transmitted in step S403 is encrypted with the session key S2, which is the key scheduled for update. Also, the "master unit information" transmitted in step S403 is information regarding the GW radio 100, which is the master unit. For example, it is information for identifying the GW radio 100.
[0042] Also, in step S403, the master unit information reception unit 212 of the MT radio 200 receives the "master unit information" transmitted from the GW radio 100. Specifically, the master unit information reception unit 212 receives the "master unit information" transmitted from the GW radio 100 and decrypts it using the "key scheduled for update" stored in the N area of the session key information 222. As shown in FIG. 5, the key for decrypting the "master unit information" is the session key S2 of the key scheduled for update stored in the N area. In the example shown in FIG. 4, at the timing when the master unit information reception unit 212 receives the "master unit information" transmitted from the GW radio 100 in step S403, the session key S2 is stored in the N area of the session key information 222. Therefore, in step S403, the master unit information reception unit 212 of the MT radio 200 decrypts the "master unit information" using the session key S2 in the N area and obtains the "master unit information", which is information regarding the GW radio 100.
[0043] The determination unit 113 of the GW wireless device 100 determines whether it has received the "slave device information" transmitted from the MT wireless device 200 in step S404 described later. Also, the determination unit 213 of the MT wireless device 200 determines whether to transmit the "slave device information" to the GW wireless device 100 based on the transmission status of the "update key information" and the "master device information" transmitted from the GW wireless device 100 in steps S401 and S403. In the present embodiment, the determination unit 213 of the MT wireless device 200 determines to transmit the "slave device information" to the GW wireless device 100 when it has received the "update key information" and the "master device information", or when it has received the "update key information" at least twice. The details of the processing of the determination unit 113 and the determination unit 213 will be described in Processing Examples 1 to 3 of the key information update system described later.
[0044] Based on the determination result of the determination unit 213, the slave device information transmission unit 214 of the MT wireless device 200 transmits the "slave device information" to the GW wireless device 100. Specifically, when the determination unit 213 determines to transmit the "slave device information", the slave device information transmission unit 214 transmits the "slave device information" encrypted with the "key to be updated" stored in the N area of the session key information 222 to the GW wireless device 100. The process of the slave device information transmission unit 214 transmitting the "slave device information" to the GW wireless device 100 corresponds to step S404 in the sequence diagram of FIG. 4.
[0045] Specifically, in step S404, the slave device information transmission unit 214 of the MT wireless device 200 encrypts and transmits the "slave device information" to the GW wireless device 100. In the example shown in FIG. 4, it is assumed that the "slave device information" transmitted in step S404 is encrypted with the session key S2, which is the key to be updated. Also, the "slave device information" transmitted in step S404 is information regarding the MT wireless device 200, which is a slave device, for example, information for identifying the MT wireless device 200.
[0046] Also, in step S404, the slave unit information receiving unit 114 of the GW radio 100 receives the "slave unit information" transmitted from the MT radio 200. The slave unit information receiving unit 114 of the GW radio 100 decrypts the "slave unit information" encrypted with the update-scheduled key using the session key S2, which is the update-scheduled key in the N area of the session key information 122, and obtains the "slave unit information", which is information about the MT radio 200.
[0047] The session key updating unit 115 of the GW radio 100 updates the session key in the C area of the session key information 122 to the session key in the N area. Specifically, when the determination unit 113 determines that the "slave unit information" has been received, the session key updating unit 115 updates the session key in the C area of the session key information 122 to the "update-scheduled key" stored in the N area. The process related to the key update of this session key updating unit 115 corresponds to step S405.
[0048] Specifically, in step S405, the session key updating unit 115 of the GW radio 100 performs the session key update. In the example shown in FIG. 4, the session key stored in the C area of the session key information 122 is updated from the session key S1 to the session key S2.
[0049] Also, the session key updating unit 215 of the MT radio 200 updates the session key information 222. Specifically, when the slave unit information transmitting unit 214 transmits the "slave unit information" to the GW radio 100, the session key updating unit 215 updates the session key in the C area of the session key information 222 to the update-scheduled key in the N area. The process related to the key update of this session key updating unit 215 corresponds to step S406.
[0050] Specifically, in step S406, the session key update unit 215 of the MT radio 200 updates the session key. In the example shown in FIG. 4, the session key stored in the C area of the session key information 222 is updated from the session key S1 to the session key S2. The update process of the session key of the MT radio 200 in this step S406 is performed based on the transmission process of the "slave unit information" in step S404.
[0051] In step S407, the GW radio 100 transmits a "needle inspection data request" message to the MT radio 200. This "needle inspection data request" message is encrypted by the session key S2. Also, in step S407, the MT radio 200 receives the "needle inspection data request" message. Information indicating decryption with the key stored in the C area is stored in the header of this "needle inspection data request" message. The MT radio 200 decrypts the "needle inspection data request" using the session key S2 stored in the C area in step S406 based on the header information. As described above, in step S406, since the key in the C area of the session key information 222 has been updated from the session key S1 to the session key S2, the message related to the "needle inspection data request" can be decrypted without problems. In the example shown in FIG. 4, the description of the normal message transmission and reception between the GW radio 100 and the MT radio 200 after the "needle inspection data request" is omitted.
[0052] Next, with reference to FIGS. 6 to 8, the processing when a failure occurs in any of the messages transmitted and received between the GW radio 100 and the MT radio 200 is shown. In the following examples of FIGS. 6 to 8, the description of the processing similar to that shown in the sequence diagram of FIG. 4 is omitted or simplified. In the present embodiment, a message failure means a situation where a message transmitted from the transmitting side of the radio cannot be received at the receiving side due to some reason. Also, the cause of the failure is due to various factors such as a fixed failure, a temporary intermittent failure, or a single-occurrence failure in the radio or the communication path.
[0053] (Processing Example 1 of Key Information Update System) FIG. 6 shows an example of processing when a failure occurs in the telegram of "updated key information" transmitted from the GW radio 100 to the MT radio 200.
[0054] In step S601, it indicates the case where the telegram of "updated key information" transmitted from the GW radio 100 to the MT radio 200 fails and the updated key information receiving unit 211 of the MT radio 200 cannot receive the "updated key information". In this case, in the MT radio 200, the information of the session key S2 is not stored in the N area of the session key information 222.
[0055] In step S602, "parent device information" is transmitted from the GW radio 100 to the MT radio 200. Here, since the session key S2 is not stored in the N area of the session key information 222 of the MT radio 200, the parent device information receiving unit 212 of the MT radio 200 cannot decrypt the "parent device information". Therefore, the determination unit 213 of the MT radio 200 determines not to transmit "child device information" to the GW radio 100 based on the transmission status of the "updated key information" and "parent device information" transmitted from the GW radio 100.
[0056] In step S603, the determination unit 113 of the GW radio 100 determines whether it has received "child device information" transmitted from the MT radio 200. In the example shown in FIG. 6, as described above, the "updated key information" fails, and the determination unit 213 of the MT radio 200 determines not to transmit the "child device information". Therefore, at the timing of step S603 in FIG. 6, the "child device information" from the MT radio 200 is not transmitted, and the GW radio 100 does not receive the "child device information". If the GW radio 100 does not receive the "child device information" for a predetermined period in step S603, the updated key information transmission unit 111 of the GW radio 100 retransmits the "updated key information" to the MT radio 200 (step S604). Also, the parent device information transmission unit 112 retransmits the "parent device information" (step S606).
[0057] Here, in the example shown in FIG. 6, when the "update key information" from the GW radio 100 to the MT radio 200 remains undelivered, a loop L6 in which the processes from step S603 to step S606 are repeatedly performed is executed. This loop L6 is assumed to be a predetermined number of times. For example, 10 loops are executed. Note that the number of loops of this loop does not limit the configuration of the present embodiment, and the number of loops may be less than 10 times or more than 10 times.
[0058] For example, if some fixed failure occurs in the MT radio 200 and the state where the telegram of the "update key information" remains undelivered continues, after the predetermined number of loops of loop L6 is executed, the process of the sequence shown in FIG. 6 ends. Then, the GW radio 100 performs the process from step S601 on other MT radios 200 that are key update targets included in the metering network 10.
[0059] On the other hand, if the telegram of the "update key information" is transmitted to the MT radio 200 in a smaller number of loops than the predetermined 10 times due to a single (intermittent) communication failure or the like, the processes from step S605 to step S609 are performed, and the session key is updated. Note that the processes from step S607 to step S610 are the same as the processes from step S404 to step S407 shown in FIG. 4, and thus the description thereof is omitted. Also, in the example shown in FIG. 6, the description of the normal telegram transmission and reception between the GW radio 100 and the MT radio 200 after the "metering data request" is omitted.
[0060] In this way, in the key information update system, even when the telegram of the "update key information" is undelivered, if the occurrence of the undeliverability is single (intermittent), the telegram of the "update key information" is transmitted again, and the key information is updated without problems.
[0061] (Example of processing of key information update system 2) FIG. 7 shows an example of processing when undeliverability occurs in the telegram of the "parent device information" transmitted from the GW radio 100 to the MT radio 200.
[0062] In step S701 shown in FIG. 7, unlike step S601 shown in FIG. 6, a telegram of "update key information" is transmitted from GW radio 100 to MT radio 200. Therefore, the update key information receiving unit 211 of MT radio 200 receives the "update key information" from GW radio 100 and stores the update-scheduled key in the N area of the session key information 222.
[0063] The example shown in FIG. 7 shows an example where the telegram of "parent device information" in step S703 fails to be delivered. Since the telegram of "parent device information" in step S703 fails to be delivered, the determination unit 213 of MT radio 200 determines not to transmit the "child device information" based on the situation where the telegram of "parent device information" fails to be delivered. Therefore, a telegram of "child device information" is not transmitted from MT radio 200 in response to the failure of step S703.
[0064] In step S704, the determination unit 113 of GW radio 100 determines whether a telegram of "child device information" has been transmitted from MT radio 200. In the example shown in FIG. 7, at the timing of step S704, the "child device information" from MT radio 200 is not transmitted. Therefore, the update key information transmitting unit 111 and the parent device information transmitting unit 112 of GW radio 100 transmit the "update key information" and the "parent device information" to MT radio 200 (steps S705 and S706).
[0065] Here, in the example shown in FIG. 7, assume again that the message of "parent device information" in step S706 fails to be delivered. The determination unit 213 of the MT radio 200 determines to transmit "child device information" to the GW radio 100 triggered by receiving the second "update key information" in the state of having received the first "update key information". That is, the determination unit 213 of the MT radio 200 determines to transmit "child device information" to the GW radio 100 when the "update key information" is received at least twice. In step S702, since the session key S2 is stored in the N area of the session key information 222, there is no problem in communication with the GW radio 100 even if the key information in the C area is updated to the session key S2. That is, in the example shown in FIG. 7, even if the "parent device information" from the GW radio 100 remains undelivered, the session key update process will be performed without problems.
[0066] Regarding the processing from step S708 to step S711, since it is the same as steps S404 to S407 in the sequence shown in FIG. 4, the description is omitted. Also, in the example shown in FIG. 7, the description of the normal message transmission and reception between the GW radio 100 and the MT radio 200 after the "metering data request" is omitted.
[0067] In the example shown in FIG. 7, an example where the message of "parent device information" in step S706 remains undelivered is shown. Here, for example, even when the message of "update key information" in step S705 fails to be delivered and the message of "parent device information" in step S706 is transmitted, the session key can be updated without problems. That is, in the example shown in FIG. 7, the MT radio 200 has transmitted the message of "update key information" in step S701. Therefore, in the MT radio 200, when the message of "update key information" in step S705 fails to be delivered and the message of "parent device information" in step S706 is transmitted, upon receiving the "parent device information" in step S706, processing equivalent to the normal protocol is performed.
[0068] Thus, in the key information update system according to this embodiment, even when the telegram of "parent device information" fails to be delivered, regardless of whether the occurrence of the failure of the telegram of "parent device information" is permanent or single-occurrence (intermittent), it is possible to update the session key information.
[0069] (Processing Example 3 of Key Information Update System) FIG. 8 shows an example of processing when a failure occurs in the telegram of "child device information" transmitted from the MT radio 200 to the GW radio 100.
[0070] Regarding the processing from step S801 to step S803, since it is the same as the processing from step S401 to step S403 shown in FIG. 4, the description is omitted here.
[0071] In the example shown in FIG. 8, step S804 shows an example where the telegram of "child device information" from the MT radio 200 fails to be delivered.
[0072] In step S805, the determination unit 113 of the GW radio 100 determines whether it has received the "child device information" transmitted from the MT radio 200. At the timing of step S805 in FIG. 8, the "child device information" from the MT radio 200 is not transmitted. If the GW radio 100 does not receive the "child device information" for a predetermined period in step S805, the update key information transmission unit 111 of the GW radio 100 retransmits the "update key information" to the MT radio 200 (step S806). Also, the parent device information transmission unit 112 retransmits the "parent device information" (step S807).
[0073] Here, in the example shown in FIG. 8, when the "slave unit information" from the MT radio 200 to the GW radio 100 remains undelivered, a loop L8 in which the processes from step S804 to step S807 are repeatedly performed is executed. This loop L8 is assumed to be a predetermined number of times. For example, 10 loops are executed. Note that the number of loops in this embodiment is not limited to 10, and a number of loops less than 10 or more than 10 may be used as the number of loops.
[0074] For example, if some fixed failure occurs in the MT radio 200 and the state where the telegram of the "slave unit information" remains undelivered continues, after a predetermined number of loops of loop L8 are executed, the processing of the sequence shown in FIG. 8 ends. Then, the GW radio 100 performs the processing from step S801 on other MT radios 200 that are key update targets included in the metering network 10.
[0075] On the other hand, if the telegram of the "slave unit information" is transmitted to the GW radio 100 in a number of loops less than a predetermined 10 times due to a single (intermittent) communication failure or the like, the processes from step S808 to step S810 are performed, and the session key is updated. Note that the processes from step S808 to step S811 are the same as the processes from step S404 to step S407 shown in FIG. 4, and thus the description thereof is omitted. Also, in the example shown in FIG. 8, the description of the normal telegram transmission and reception between the GW radio 100 and the MT radio 200 after the "metering data request" is omitted.
[0076] Thus, in the key information update system according to the present embodiment, even when the telegram of the "slave unit information" is undelivered, if the occurrence of the undeliverability is single (intermittent), the telegram of the "slave unit information" is transmitted again, and the key information is updated without problems.
[0077] As described above, the key information update system in the present embodiment is a key information update system that updates a session key used for encrypting and decrypting a telegram transmitted and received between a wireless master unit and a wireless slave unit. The wireless master unit of the key information update system includes an update key information transmission unit 111 and a master unit information transmission unit 112. The wireless slave unit includes an update key information reception unit 211, a master unit information reception unit 212, and a slave unit determination unit. The update key information transmission unit 111 transmits, to the wireless slave unit, update key information obtained by encrypting an update-scheduled key stored in the master unit storage unit of the wireless master unit with the session key stored in the master unit storage unit. The master unit information transmission unit 112 transmits, to the wireless slave unit, master unit information regarding the wireless master unit encrypted with the update-scheduled key. The slave unit determination unit determines whether to transmit slave unit information regarding the wireless slave unit to the wireless master unit based on the update key information and the master unit information transmitted from the wireless master unit.
[0078] Thereby, even when a telegram regarding key update fails to reach, it is not necessary to separately provide a communication method related to key update, and a key information update system capable of performing key update with a simple configuration can be realized. Note that the wireless master unit corresponds to the GW wireless device 100. The wireless slave unit corresponds to the MT wireless device 200. The slave unit determination unit corresponds to the determination unit 213.
[0079] Further, the slave unit determination unit of the key information update system may determine to transmit the slave unit information to the wireless master unit when it receives the update key information and the master unit information, or when it receives the update key information at least twice. Thereby, in the key information update system, even when the telegram of the "master unit information" fails to reach, regardless of whether the failure of the telegram of the "master unit information" is permanent or single-occurrence (intermittent), it is possible to update the session key information.
[0080] In addition, when the update key information transmission unit 111 of the key information update system determines in the master device determination unit that it has not received slave device information, it may transmit the update key information to the wireless slave device again. As a result, in the key information update system, even when the telegram of "slave device information" fails to be delivered, if the occurrence of the failure is single (intermittent), the telegram of "slave device information" will be transmitted again, enabling the key information to be updated without problems.
[0081] (Other Embodiments) Although the embodiments have been described in detail with reference to the drawings, the present embodiments are not limited to the content described in the above embodiments. In addition, the constituent elements described above include those that can be easily assumed by those skilled in the art and those that are substantially the same. Furthermore, the configurations described above can be combined as appropriate. Also, various omissions, substitutions, or changes in the configuration can be made without departing from the gist of the embodiments.
[0082] As an example of the configuration of the key information update system according to the present embodiment, as shown in FIG. 1, an example in which a telegram is transmitted and received between one GW radio 100 and a plurality of MT radios 200 is shown, but this configuration does not limit the embodiment. For example, the slave meter 20b may be configured to be connected to another slave meter 20b via the MT radio 200. That is, the key information update system may be configured by multi-hop in which the MT radio 200 can relay a telegram (message) transmitted and received between the GW radio 100 of the master meter 20a and the MT radio 200 of another slave meter 20b. By realizing the key information update system in a multi-hop configuration, it becomes possible to expand the communication area efficiently and eliminate the dead zone due to obstacles, etc., for the metering network 10.
[0083] In addition, a computer program (key information update program) that causes a computer to execute the processing (key information update method) in the above-described key information update system, and a computer-readable recording medium on which the program is recorded are included in the scope of the present embodiment. Here, the type of the computer-readable recording medium is arbitrary. Further, the computer program is not limited to that recorded on the recording medium, and may be transmitted via an electric communication line, a wireless or wired communication line, a network typified by the Internet, or the like.
[0084] The features of the key information update system, the key information update method, and the key information update program will be described below.
[0085] The key information update system according to the first aspect is a key information update system that updates a session key used for encryption and decryption of a telegram transmitted and received between a wireless master unit and a wireless slave unit. The wireless master unit includes an update key information transmission unit 111 that transmits, to the wireless slave unit, update key information obtained by encrypting a key to be updated stored in the master unit storage unit of the wireless master unit with the session key stored in the master unit storage unit. The wireless master unit also includes a master unit information transmission unit 112 that transmits, to the wireless slave unit, master unit information regarding the wireless master unit encrypted with the key to be updated. The wireless master unit further includes a master unit determination unit that determines whether or not it has received slave unit information regarding the wireless slave unit transmitted from the wireless slave unit. The wireless master unit also includes a master unit key update unit that updates the session key to the key to be updated when the master unit determination unit determines that the slave unit information has been received. The wireless slave unit includes an update key information reception unit 211 that receives the update key information transmitted from the wireless master unit, decrypts the update key information with the session key stored in the slave unit storage unit of the wireless slave unit to obtain the key to be updated, and stores it in the slave unit storage unit. The wireless slave unit also includes a master unit information reception unit 212 that receives the master unit information transmitted from the wireless master unit and decrypts it with the key to be updated. The wireless slave unit further includes a slave unit determination unit that determines whether or not to transmit the slave unit information to the wireless master unit based on the update key information and the master unit information. The wireless slave unit also includes a slave unit information transmission unit 214 that transmits, to the wireless master unit, the slave unit information encrypted with the key to be updated when the slave unit determination unit determines that the slave unit information is to be transmitted. Furthermore, the wireless slave unit includes a slave unit key update unit that updates the session key to the key to be updated when the slave unit information transmission unit 214 transmits the slave unit information to the wireless master unit.
[0086] According to the above configuration, even when a telegram regarding key update is not delivered, the key information update system does not need to separately provide a communication method related to key update, and can perform key update with a simple configuration.
[0087] The slave unit determination unit of the key information update system according to the second aspect may determine to transmit the slave unit information to the wireless master unit when it receives the update key information and the master unit information, or when it receives the update key information at least twice.
[0088] According to the above configuration, even when the telegram of the "parent device information" fails to be transmitted, the key information update system can update the session key information regardless of whether the failure of the telegram of the "parent device information" is permanent or single-occurrence (intermittent).
[0089] In the key information update system according to the third aspect, when the parent device determination unit determines that the child device information has not been received, the update key information transmission unit 111 may transmit the update key information to the wireless child device again.
[0090] According to the above configuration, even when the telegram of the "child device information" fails to be transmitted, if the occurrence of the failure is single-occurrence (intermittent), the key information can be updated without problems by transmitting the telegram of the "child device information" again.
[0091] The wireless child device of the key information update system according to the fourth aspect may be capable of relaying the telegrams transmitted and received between the wireless parent device and other wireless child devices.
[0092] According to the above configuration, the key information update system can expand the communication area efficiently and eliminate the insensitive area due to obstacles or the like for the metering network 10.
[0093] The key information update method according to the fifth aspect is a key information update method that is executed by a computer and updates a session key used for encryption and decryption of a telegram transmitted and received between a wireless master device and a wireless slave device. The key information update method encrypts an update-scheduled key stored in the master device storage unit of the wireless master device with the session key stored in the master device storage unit, and transmits the encrypted update key information to the wireless slave device. Further, the key information update method receives the update key information transmitted from the wireless master device, decrypts the update key information with the session key stored in the slave device storage unit of the wireless slave device to obtain the update-scheduled key, and stores it in the slave device storage unit. Further, the key information update method transmits to the wireless slave device the master device information regarding the wireless master device encrypted with the update-scheduled key. Further, the key information update method receives the master device information transmitted from the wireless master device and decrypts it with the update-scheduled key. Further, the key information update method determines whether to transmit slave device information regarding the wireless slave device to the wireless master device based on the update key information and the master device information. Further, when it is determined that the slave device information is to be transmitted, the key information update method transmits the slave device information encrypted with the update-scheduled key to the wireless master device. Further, the key information update method determines whether the slave device information transmitted from the wireless slave device has been received. Further, when it is determined that the slave device information has been received, the key information update method updates the session key of the wireless master device to the update-scheduled key. Further, when the slave device information is transmitted to the wireless master device, the key information update method updates the session key of the wireless slave device to the update-scheduled key.
[0094] According to the above configuration, even if a telegram regarding key update fails to reach, there is no need to separately provide a communication method related to key update, and key update can be performed with a simple configuration.
[0095] The key information update program according to the sixth aspect is a key information update program for causing a computer to update a session key used for encrypting and decrypting a telegram transmitted and received between a wireless master unit and a wireless slave unit. The key information update program includes a step of transmitting, to the wireless slave unit, update key information obtained by encrypting an update-scheduled key stored in the master unit storage unit of the wireless master unit with the session key stored in the master unit storage unit. Further, the key information update program includes a step of receiving the update key information transmitted from the wireless master unit, decrypting the update key information with the session key stored in the slave unit storage unit of the wireless slave unit to obtain the update-scheduled key, and storing the obtained update-scheduled key in the slave unit storage unit. Further, the key information update program includes a step of transmitting, to the wireless slave unit, master unit information regarding the wireless master unit encrypted with the update-scheduled key. Further, the key information update program includes a step of receiving the master unit information transmitted from the wireless master unit and decrypting the received master unit information with the update-scheduled key. Further, the key information update program includes a step of determining whether to transmit slave unit information regarding the wireless slave unit to the wireless master unit based on the update key information and the master unit information. Further, when it is determined that the slave unit information is to be transmitted, the key information update program includes a step of transmitting, to the wireless master unit, the slave unit information encrypted with the update-scheduled key. Further, the key information update program includes a step of determining whether the slave unit information transmitted from the wireless slave unit has been received. Further, when it is determined that the slave unit information has been received, the key information update program includes a step of updating the session key of the wireless master unit to the update-scheduled key. Further, when the slave unit information is transmitted to the wireless master unit, the key information update program includes a step of updating the session key of the wireless slave unit to the update-scheduled key.
[0096] According to the above configuration, even if a telegram regarding key update fails to reach due to the key information update program, it is not necessary to separately provide a communication method related to key update, and key update can be performed with a simple configuration.
Description of Signs
[0097] 1 Wireless communication system 10 Metering network 20 Meter 30 Management device 40 Network 100 GW radio device 110, 210 control unit 200 MT radio device 111 Update key information transmission unit 112 Parent device information transmission unit 113, 213 Judgment unit 114 Sub-device information reception unit 115, 215 Session key update unit 120, 220 Memory unit 211 Update key information reception unit 212 Parent device information reception unit 214 Sub-device information transmission unit
Claims
1. A key information update system that updates a session key used for encrypting and decrypting a telegram transmitted and received between a wireless master unit and a wireless slave unit, comprising: The wireless master unit: An update key information transmission unit that transmits, to the wireless slave unit, update key information obtained by encrypting an update-scheduled key stored in the master unit storage unit with the session key stored in the master unit storage unit; A master unit information transmission unit that transmits, to the wireless slave unit, master unit information regarding the wireless master unit encrypted with the update-scheduled key; A master unit determination unit that determines whether or not to receive slave unit information regarding the wireless slave unit transmitted from the wireless slave unit; A master unit key update unit that updates the session key to the update-scheduled key when it is determined in the master unit determination unit that the slave unit information has been received; and The wireless slave unit: An update key information reception unit that receives the update key information transmitted from the wireless master unit, decrypts the update key information with the session key stored in the slave unit storage unit of the wireless slave unit to obtain the update-scheduled key, and stores the update-scheduled key in the slave unit storage unit; A master unit information reception unit that receives the master unit information transmitted from the wireless master unit and decrypts the master unit information with the update-scheduled key; A slave unit determination unit that determines whether or not to transmit the slave unit information to the wireless master unit based on the update key information and the master unit information; A slave unit information transmission unit that transmits, to the wireless master unit, the slave unit information encrypted with the update-scheduled key when it is determined in the slave unit determination unit that the slave unit information is to be transmitted; A slave unit key update unit that updates the session key to the update-scheduled key when the slave unit information is transmitted to the wireless master unit in the slave unit information transmission unit; and A key information update system.
2. The slave unit determination unit determines that the slave unit information is to be transmitted to the wireless master unit when the update key information and the master unit information are received, or when the update key information is received at least twice. The key information update system according to Claim 1.
3. The update key information transmission unit transmits the update key information to the wireless slave unit again when it is determined in the master unit determination unit that the slave unit information has not been received. The key information update system according to Claim 1 or 2.
4. The wireless slave unit is capable of relaying a telegram transmitted and received between the wireless master unit and another wireless slave unit. The key information update system according to any one of Claims 1 to 3.
Citation Information
Patent Citations
Vehicle communication lock system, vehicle, slave machine and master machine of vehicle communication lock system
JP2007085007A
Network device, network system, and key updating method
JP2007104310A
Communication system, and key updating method
JP2011087013A
Key information controller, key information update device, program and recording medium, key information update method, key information update system
JP2015133589A