Communication system, communication method, and program

The communication system addresses the challenge of limited storage in IoT devices by using a management device to verify server certificates and transmit public keys, enabling secure communication without the need for large-capacity storage in devices.

JP7687031B2Active Publication Date: 2025-06-03TOPPAN HOLDINGS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021068326
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-04-14
Publication Date
2025-06-03
Estimated Expiration
2041-04-14

AI Technical Summary

Technical Problem

In IoT systems, devices face challenges in storing large-capacity information like client certificates due to limited storage and memory capacity, leading to increased costs when using high-capacity memory solutions.

Method used

A communication system where a management device verifies the validity of a server certificate and transmits the server public key to a device, allowing the device to authenticate the server without storing the client certificate, thus reducing storage and memory requirements.

Benefits of technology

Enables secure communication between devices and servers without the need for large-capacity storage in devices, reducing costs and power consumption while maintaining security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007687031000001
    Figure 0007687031000001
  • Figure 0007687031000002
    Figure 0007687031000002
  • Figure 0007687031000003
    Figure 0007687031000003
Patent Text Reader

Abstract

To allow a device apparatus and a server apparatus to perform secure communication even without causing the device apparatus to store a large amount of information.SOLUTION: A server device that stores a server private key generates a key pair, which is a pair of a temporary server public key and a temporary server private key to be used temporarily, generates a server signature, which is an electronic signature of the temporary server public key, using the server private key, and transmits the temporary server public key and the server signature to a device apparatus. The device apparatus that stores the server public key verifies the server signature using the server public key, and when determining that the server signature is generated using the temporary server public key and the server private key, determines that the server apparatus is a valid apparatus.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a communication system, a communication method, and a program.

Background Art

[0002] In an IoT (Internet of Things) system, secure communication is achieved by mutual authentication between a device device and a server device (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, most device devices keep the capacity of the storage and memory they mount very small in order to reduce the device cost. Information on the order of several kilobytes, such as a client certificate for mutual authentication, is also large-capacity information for the device device. For this reason, it is difficult for the device device to store the client certificate. As a countermeasure, there has been a problem that mounting an expensive large-capacity memory on the device device increases the product cost.

[0005] In view of the above problems, an object of the present invention is to provide a communication system, a communication method, and a program that enable a device device and a server device to perform secure communication without storing large-capacity information such as a client certificate in the device device.

Means for Solving the Problems

[0006] A communication system according to an aspect of the present invention includes a device device and a server deviceThe management device and In a communication system comprising When the management device determines that the server certificate that proves the server public key is a valid certificate, it transmits the server public key included in the server certificate to the device device, the device device, In the communication with the server device, the using the server public key 、 determines that the server device is a legitimate device Whether or not characterized by.

[0007] A communication method according to an aspect of the present invention is a communication method in a communication system including a device device and a server device, The management device and comprising a device control step in which the device device determines that the server device is a legitimate device using a server public key. When the management device determines that the server certificate that proves the server public key is a valid certificate, the step of transmitting the server public key included in the server certificate to the device device; wherein the device device, In the communication with the server device, the using the server public key 、 determines that the server device is a legitimate device Whether or not including.

[0008] A program according to an aspect of the present invention is a program for causing a computer of A management device that substitutes for the processing performed by the device device to achieve secure communication between the device device and the server device to execute the step of When it is determined that the server certificate that proves the server public key is a valid certificate, the server public key included in the server certificate is transmitted to the device device doing.

[0009] A program according to an aspect of the present invention is a program for causing a computer of A management device that substitutes for the processing performed by the device device to achieve secure communication between the device device and the server device to execute the step of Create a device certificate by transmitting the device public key among the key pair of the device public key and the device private key in the device device to the second certification authority that proves the device device, and transmit the device certificate generated by the second certification authority to the server device doing and.

Effect of the Invention

[0010] According to the present invention, the device device and the server device can perform secure communication without storing a large amount of information in the device device.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Embodiments for Carrying Out the Invention

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0013] FIG. 1 is a schematic configuration diagram of a communication system S1 according to the present embodiment. The communication system S1 includes a device device 1, a server device 2, and a management device 3. The device device 1 is a terminal device that serves as a client with respect to the server device 2. For example, the device device 1 is a sensor device provided with a sensor such as a camera. The server device 2 is a server device that communicates with the device device 1 via a network. The management device 3 is a server device of a certificate / key management system that manages the certificate and key of the device device 1. The device device 1, the server device 2, and the management device 3 are communicably connected via a network.

[0014] Here, terms will be explained. For communication with the device device 1, a device public key (pub_B), a device private key (priv_B), a device certificate (cert_B), a temporary device public key (e_pub_B), a temporary device private key (e_priv_B), and a device signature (sig_B) are used.

[0015] The device public key (pub_B) and the device private key (priv_B) are keys that form a pair in the authentication with the device apparatus 1. For example, a device that communicates with the device apparatus 1 verifies information signed using the device private key (priv_B) using the device public key (pub_B). The device certificate (cert_B) is information in which the device public key (pub_B) is described and signed by a certification authority. The temporary device public key (e_pub_B) and the temporary device private key (e_priv_B) are a key pair temporarily generated by the device apparatus 1 in order to share a session key. The device signature (sig_B) is a signature that can be attached when the device apparatus 1 proves that a message transmitted from the device apparatus 1 is the message it transmits. The device certificate (cert_B) is information in which the device public key (pub_B) is signed by a certification authority. The device signature (sig_B) is generated using the device private key (priv_B).

[0016] For communication with the server apparatus 2, the server public key (pub_A), the server private key (priv_A), the server certificate (cert_A), the temporary server public key (e_pub_A), the temporary server private key (e_priv_A), and the server signature (sig_A) are used.

[0017] The server public key (pub_A) and the server private key (priv_A) are keys that form a pair in the authentication with the server device 2. For example, a device communicating with the server device 2 verifies information signed using the server private key (priv_A) using the server public key (pub_A). The server certificate (cert_A) is information in which the server public key (pub_A) is described and signed by a certification authority. The temporary server public key (e_pub_A) and the temporary server private key (e_priv_A) are a key pair temporarily generated by the server device 2 to share a session key. The server signature (sig_A) is a signature that can be attached when the server device 2 proves that a message it sends is a message sent from the server device 2. The server certificate (cert_A) is information in which the server public key (pub_A) is signed by a certification authority. The server signature (sig_A) is generated using the server private key (priv_A).

[0018] As shown in the figure, the device device 1 includes a device communication unit 11, a device storage unit 12, and a device control unit 13. The device communication unit 11 communicates with the server device 2 or the management device 3.

[0019] The device storage unit 12 stores the device private key (priv_B) and the server public key (pub_A). That is, in the present embodiment, the device storage unit 12 does not store the server certificate (cert_A).

[0020] The device storage unit 12 includes a volatile storage unit 121 that stores information when power is supplied, and a non-volatile storage unit 122 that stores information even when power is not supplied. The volatile storage unit 121 is, for example, a memory such as a RAM (Random Access Memory). The non-volatile storage unit 122 is, for example, a storage composed of a flash memory or the like.

[0021] The device control unit 13 performs authentication to determine whether the communication destination device is a legitimate device. For example, the device control unit 13 receives a temporary server public key (e_pub_A) and a server signature (sig_A) from the server device 2. Here, the received server signature (sig_A) is information signed using the server private key (priv_A) with the temporary server public key (e_pub_A). The device control unit 13 verifies the server signature (sig_A) using the server public key (pub_A). Specifically, the device control unit 13 verifies the server signature (sig_A) using the server public key (pub_A). More specifically, the device control unit 13 uses the temporary server public key (e_pub_A) and the server public key (pub_A) received from the server device 2 to verify whether the server signature (sig_A) was generated using the temporary server public key (e_pub_A) and the server private key (priv_A). If the device control unit 13 can confirm as a result of the verification that the server signature (sig_A) received from the server device 2 was generated using the temporary server public key (e_pub_A) and the server private key (priv_A), it determines that the server device 2 is a legitimate device and that the temporary server public key (e_pub_A) received from the server device 2 is information generated by the server device 2.

[0022] Also, the device control unit 13 generates a key pair that is a pair of a temporary device public key (e_pub_B) and a temporary device private key (e_priv_B) in order to have its own device 1 authenticated. Further, the device control unit 13 generates a device signature (sig_B) that is an electronic signature of the temporary device public key (e_pub_B) using the device private key (priv_B). Then, the device control unit 13 transmits the generated temporary device public key (e_pub_B) and the device signature (sig_B) to the server device 2.

[0023] Further, when the device control unit 13 determines that the server device 2 is a legitimate device, it generates a first session key for communication with the server device 2 using the temporary server public key (e_pub_A) and the temporary device private key (e_priv_B). The device control unit 13 stores the generated first session key in the non-volatile memory unit 122. In subsequent communication with the server device 2, the device control unit 13 performs encrypted communication using the first session key stored in the non-volatile memory unit 122.

[0024] In this embodiment, the first session key is stored in the non-volatile memory unit 122. Therefore, the first session key can be stored even when the power is not supplied. Thus, not only the session performed while the power is on, but also encrypted communication using the first session key can be performed any number of times until the first session key is updated thereafter. As a result, it is not necessary to authenticate each time communication with the server device 2 is started after the power is turned on, and it is possible to reduce the processing load of the device device 1.

[0025] Note that in order to suppress a possible decrease in security caused by reusing the first session key, the device device 1 or the server device 2 may update the session key at a predetermined timing. The timing for updating the session key may be arbitrarily set. The update of the session key is executed when the device device 1 and the server device 2 perform mutual authentication as described above.

[0026] Specifically, in a state where the device control unit 13 already stores the first session key, it receives the temporary server public key (e_pub_A) and the server signature (sig_A) from the server device 2. In this case, the temporary server public key (e_pub_A) is a key temporarily created by the server device 2 and is information indicating a different value each time it is generated.

[0027] The device control unit 13 verifies the server signature (sig_A) using the server public key (pub_A). When the device control unit 13 can confirm that the server signature (sig_A) was generated using the temporary server public key (e_pub_A) and the server private key (priv_A) by using the temporary server public key (e_pub_A) and the server public key (pub_A) received from the server device 2, it determines that the server device 2 is a legitimate device.

[0028] Then, the device control unit 13 generates a second session key for communication with the server device 2 using the temporary server public key (e_pub_A) received from the server device 2 and the temporary device private key (e_priv_B) generated by the device 1. Here, the temporary server public key (e_pub_A) is newly received from the server device 2 this time while the first session key is stored, and is a value different from the value used for generating the previous first session key.

[0029] Also, the temporary device private key (e_priv_B) used for generating the second session key here is also a value different from the value used for generating the previous first session key. For example, when the device control unit 13 determines that the server device 2 is a legitimate device, it generates a key pair (a pair of the temporary device public key (e_pub_B) and the temporary device private key (e_priv_B)) in order for the server device 2 to authenticate its own device 1. Alternatively, when the update condition for updating the session key is satisfied, such as when a predetermined time has elapsed since the first session key was generated, the device control unit 13 generates a key pair (a pair of the temporary device public key (e_pub_B) and the temporary device private key (e_priv_B)). The device control unit 13 transmits the temporary device public key (e_pub_B) of the generated key pair to the server device 2. Since the key pair of the temporary device public key (e_pub_B) and the temporary device private key (e_priv_B) has different values each time it is generated, the key pair created this time has a value different from the value used for generating the previous first session key.

[0030] Therefore, the second session key generated by the device control unit 13 has a value different from that of the first session key. As a result, the session key is updated to a second session key with a value different from that of the first session key.

[0031] The device control unit 13 stores the second session key in the non-volatile memory unit 122 and performs encrypted communication using the second session key in subsequent communications with the server device 2.

[0032] The server device 2 includes a server communication unit 21, a server storage unit 22, and a server control unit 23.

[0033] The server communication unit 21 communicates with the device device 1 or the management device 3. The server storage unit 22 stores, for example, a server public key (pub_A), a server key pair that is a pair of a server private key (priv_A), a device certificate (cert_B), a server certificate (cert_A), a certificate of the first certification authority, and a certificate of the second certification authority. The first certification authority is a certification authority that certifies the server device 2. The second certification authority is a certification authority that certifies the device device 1. The server certificate (cert_A) includes a server public key signed by the first certification authority.

[0034] The server control unit 23 performs authentication to determine whether the communication destination device is a legitimate device. For example, the server control unit 23 generates a key pair that is a pair of a temporary server public key (e_pub_A) and a temporary server private key (e_priv_A) in order to have the server device 2 authenticated. The server control unit 23 generates a server signature (sig_A) that is an electronic signature of the temporary server public key (e_pub_A) using the server private key (priv_A). The server control unit 23 transmits the generated temporary server public key (e_pub_A) and the server signature (sig_A) to the device device 1.

[0035] Also, the server control unit 23 receives a temporary device public key (e_pub_B) and a device signature (sig_B) from the device device 1. The server control unit 23 verifies the device signature (sig_B) using the device public key (pub_B) included in the device certificate (cert_B) stored in the server storage unit 22. The server control unit 23 verifies the device signature (sig_B) by determining whether the device signature (sig_B) was generated using the temporary device public key (e_pub_B) and the device private key (priv_B) using the temporary device public key (e_pub_B) and the device public key (pub_B). If the server control unit 23 can confirm as a result of the verification that the device signature (sig_B) was generated using the temporary device public key (e_pub_B) and the device private key (priv_B), it determines that the device device 1 is a legitimate device.

[0036] Also, when the server control unit 23 determines that the device device 1 is a legitimate device, it generates a first session key for communication with the device device 1 using the temporary device public key (e_pub_B) and the temporary server private key (e_priv_A). When communicating with the device device 1 thereafter, the server control unit 23 performs encrypted communication using the first session key.

[0037] Also, the server control unit 23 transmits the server certificate (cert_A) to the management device 3. This is to have the management device 3 perform part of the mechanism that has conventionally achieved secure communication by storing it in the device device 1. The details of the processing performed by the management device 3 will be described below.

[0038] First, a general TLS (Transport Layer Security) sequence that has been conventionally performed will be described. The device stores in advance a certificate of a certification authority issued by a certification authority it trusts. When the device receives a server certificate from a server device that is its communication destination, it determines whether the received server certificate is signed by the above-mentioned certification authority. If the received server certificate is signed by the above-mentioned certification authority, the device determines that the received server certificate is valid. Then, when the device receives a server signature from the server device, it verifies whether the received server signature is a valid server signature generated by the server private key using the server public key included in the server certificate determined to be valid as described above. If the device can verify that the received server signature is a valid signature generated using the server private key held only by the server device, it determines that the server device is a valid device.

[0039] When attempting to apply the conventionally performed general TLS to this embodiment, it is necessary to have the device 1 store the certificate of the first certification authority in advance, and the server certificate (cert_A) itself should be transmitted from the server device 2 to the device 1 each time authentication is performed. In this case, the device 1 must store the certificate of the first certification authority. The storage and memory capacities installed in the device are limited.

[0040] For example, while the storage capacity of a general PC (Personal Computer) is several hundred GB or more, the storage capacity of a general device is about several hundred KB. Also, while the memory capacity of a general PC is several GB or more, the memory capacity of a general device is about several KB. And a general electronic certificate is often information of several KB or more. Therefore, it is a heavy burden for the device 1 to store the certificate of the first certification authority, which is a large capacity for it.

[0041] Also, when attempting to apply the conventional general TLS to this embodiment, each time authentication is performed, the device 1 must receive a server certificate (cert_A). In the device 1, in order to suppress power consumption and enable long-distance wireless communication, for example, a communication method such as LPWA (Low Power Wide Area) is applied. In such a communication method, the communication speed is made low to suppress power consumption.

[0042] For example, in IEEE802.11n which defines the communication standard of Wireless LAN (Local Area Network) used as a general PC communication method, the communication speed is set to be about 300 [Mbps]. On the other hand, in ZETA (registered trademark), which is one of the LPWA standards, the communication speed is about 100 [bps] to 50 [kbps]. Also, there is a difference in the size of data that can be transmitted and received in one communication. With an Ethernet standard cable used in a general PC, data of about 1500 [Byte] can be transmitted and received in one communication. On the other hand, in ZETA (registered trademark), the data that can be transmitted and received in one communication is 8 [byte], or 50 [byte]. Therefore, in an operation where the device 1 receives a large-capacity electronic certificate each time authentication is performed, the burden on the device 1 is large and not realistic.

[0043] Also, a general device may be used for a long period of time in an environment such as outdoors where power cannot be ensured, and is often designed to be battery-powered such as with dry batteries. In order to enable long-term use with battery power, it is preferably operated so as not to consume power as much as possible.

[0044] That is, in the conventional general TLS, authentication assuming a device with a small storage capacity and memory capacity like the device 1 and a low communication speed is not defined. Therefore, it has been difficult for the device 1 to perform secure communication using the conventional general TLS.

[0045] As a countermeasure, in the present embodiment, even if the device apparatus 1 does not store the certificate of the first certification authority in advance, and even if the device apparatus 1 does not receive the server certificate (cert_A) each time verification is performed, the server signature (sig_A) can be verified.

[0046] Specifically, the management apparatus 3 stores the certificate of the first certification authority in advance and verifies whether the server certificate (cert_A) is a legitimate certificate. Then, when the management apparatus 3 determines that the server certificate (cert_A) is legitimate, the management apparatus 3 transmits the server public key (pub_A) included in the server certificate (cert_A) to the device apparatus 1. The device apparatus 1 verifies the server signature (sig_A) using the server public key (pub_A) received from the management apparatus 3.

[0047] The management apparatus 3 includes a management communication unit 31, a management storage unit 32, and a management control unit 33. The management communication unit 31 communicates with the device apparatus 1 or the server apparatus 2. The management storage unit 32 stores the first certification authority certificate, which is the certificate of the first certification authority that certifies the server apparatus 2.

[0048] The management control unit 33 determines whether the server certificate (cert_A) received from the server apparatus 2 is definitely that of the server apparatus 2 and is a legitimate certificate, using the first certification authority certificate. The management control unit 33, for example, verifies the server certificate (cert_A) using the first certification authority certificate and determines whether the server certificate (cert_A) is a legitimate certificate signed by the first certification authority. When the management control unit 33 determines that the server certificate (cert_A) is a legitimate certificate, the management control unit 33 acquires the server public key (pub_A) from the server certificate (cert_A) and transmits the acquired server public key (pub_A) to the device apparatus 1. Thereby, the device apparatus 1 can acquire the server public key (pub_A) without storing the server certificate (cert_A) in its own storage unit (device storage unit 12).

[0049] In addition to verifying whether the server certificate (cert_A) is a legitimate certificate, the management device 3 may perform a verification to determine whether the server device 2 is a legitimate device. In this case, verification using the existing TLS mechanism is possible. In this case, for example, the management device 3 receives a server signature (sig_A) from the server device 2. The server signature (sig_A) is an electronic signature generated using the server private key (priv_A). The management device 3 verifies the server signature (sig_A) received from the server device 2 using the server public key (pub_A) included in the server certificate (cert_A).

[0050] Here, generally, the server certificate (cert_A) describes the expiration date of the server public key (pub_A). Since the device device 1 of the present embodiment does not store the server certificate (cert_A), it is difficult to grasp the expiration date of the server public key (pub_A) and take measures such as updating.

[0051] As a countermeasure, the management device 3 manages the expiration date of the server public key (pub_A). Specifically, the management control unit 33 receives a newly generated server certificate (cert_A) from the server device 2, for example, before the expiration date arrives, according to the expiration date of the server public key (pub_A). The management control unit 33 verifies the server certificate (cert_A) using the first certification authority certificate and determines whether the server certificate (cert_A) is a legitimate certificate, as in the case before the update. When it is determined that the server certificate (cert_A) is a legitimate certificate, the management control unit 33 acquires the server public key (pub_A) from the server certificate (cert_A) and transmits the acquired server public key (pub_A) to the device device 1. Thereby, the server public key (pub_A) is updated.

[0052] In addition, the management control unit 33 generates a device key pair, which is a pair of a device public key (pub_B) and a device private key (priv_B), instead of the device device 1. The management control unit 33 transmits the device public key (pub_B) of the generated device key pair to the second certification authority and issues a notice (CSR, Certificate Signing Request) requesting generation of a device certificate (cert_B) including the device public key (pub_B). The management control unit 33 acquires the device certificate (cert_B) from the second certification authority. The management control unit 33 transmits the acquired device certificate (cert_B) to the server device 2. In addition, the management control unit 33 transmits the device private key (priv_B) of the generated device key pair to the device device 1.

[0053] In addition, the management control unit 33 generates a device key pair of a new device public key (pub_B) and a device private key (priv_B) according to the expiration date of the device certificate (cert_B), for example, before the expiration date arrives. The management control unit 33 transmits the device public key (pub_B) of the newly generated device key pair to the second certification authority and issues a notice (CSR, Certificate Signing Request) requesting generation of a device certificate (cert_B) including the newly generated device public key (pub_B), thereby updating the device certificate (cert_B). The management control unit 33 acquires the updated device certificate (cert_B) from the second certification authority and transmits the acquired device certificate (cert_B) to the server device 2. Thereby, the device certificate (cert_B) is updated. In addition, the management control unit 33 transmits the device private key (priv_B) of the newly generated device key pair to the device device 1. Thereby, the device private key (priv_B) is updated.

[0054] FIG. 2 is a sequence diagram showing the operation of preprocessing the communication between the device device 1 and the server device 2 according to the present embodiment. As a premise for explaining this figure, the management device 3 prestores, as held data, a first CA certificate that is a certificate of the first certification authority that certifies the server device 2. Further, the server device 2 prestores, as held data, a server key pair and a server certificate (cert_A) signed by the first certification authority. For example, the server device 2 executes the processing shown in this figure before first communicating with the device device 1, such as at the time of shipment or startup of the device device 1. Alternatively, the server device 2 executes the processing shown in this figure when updating the expiration date of the server certificate (cert_A).

[0055] Step S100: First, the server device 2 and the management device 3 execute preprocessing shown in steps S101 to S103. Step S101: The server control unit 23 of the server device 2 transmits the server certificate (cert_A) to the management device 3 via the server communication unit 21. The management control unit 33 of the management device 3 receives the server certificate (cert_A) via the management communication unit 31. Step S102: The management control unit 33 of the management device 3 verifies the server certificate (cert_A) using the first CA certificate. Step S103: When the management control unit 33 determines that the server certificate (cert_A) is a valid certificate based on the verification result, it acquires the server public key (pub_A) from the server certificate (cert_A).

[0056] Step S110: Subsequently, the management device 3 and the device device 1 execute a process of downloading the server public key (pub_A) that causes the device device 1 to download the server public key (pub_A), shown in steps S111 to S113. Step S111: The management control unit 33 of the management device 3 transmits authentication data for the device device 1 to authenticate the management device 3 to the device device 1 via the management communication unit 31. The authentication data is, for example, an ID and a password. The device control unit 13 of the device device 1 receives the authentication data via the device communication unit 11. Step S112: The device control unit 13 of the device 1 authenticates the management device 3 using the received authentication data, and determines whether the authentication is successful. If the device control unit 13 fails in the authentication (Step S112: No), the process ends. On the other hand, if the device control unit 13 succeeds in the authentication (Step S112: Yes), it transmits data notifying the fact to the management device 3 and advances the process to Step S113. Step S113: The management control unit 33 of the management device 3 transmits the server public key (pub_A) to the device 1 via the management communication unit 31. The device control unit 13 of the device 1 receives the server public key (pub_A) via the device communication unit 11, and writes the received server public key (pub_A) into the non-volatile memory unit 122 of the device storage unit 12. Thereby, the non-volatile memory unit 122 stores the server public key (pub_A). Then, the process ends.

[0057] FIG. 3 is a sequence diagram showing the operation of the process of associating the device certificate (cert_B) with the server device 2 according to the present embodiment. The server device 2 stores in advance, as held data, a second certification authority certificate which is a certificate of the second certification authority that certifies the device 1. The management device 3 executes the process shown in this figure before the server device 2 and the device 1 first communicate, for example, before and after the above-described preprocessing of the communication. Alternatively, the management device 3 executes the process shown in this figure when updating the expiration date of the device certificate (cert_B).

[0058] Step S201: The management control unit 33 of the management device 3 generates a device key pair of a device public key (pub_B) and a device private key (priv_B). Step S202: The management control unit 33 requests the second certification authority to generate a device certificate (cert_B) and obtains the device certificate (cert_B).

[0059] Step S203: The management control unit 33 transmits, via the management communication unit 31, authentication data for the device device 1 to authenticate the management device 3 to the device device 1. The device control unit 13 of the device device 1 receives the authentication data via the device communication unit 11. Step S204: The device control unit 13 of the device device 1 authenticates the management device 3 using the received authentication data and determines whether the authentication is successful. If the device control unit 13 fails the authentication (Step S204: No), the process ends. On the other hand, if the device control unit 13 succeeds in the authentication (Step S204: Yes), it transmits data notifying the fact to the management device 3 and advances the process to Step S205.

[0060] Step S205: The management control unit 33 of the management device 3 transmits, via the management communication unit 31, the device private key (priv_B) to the device device 1. The device control unit 13 of the device device 1 receives the device private key (priv_B) via the device communication unit 11 and writes the received device private key (priv_B) to the non-volatile memory unit 122 of the device storage unit 12. As a result, the non-volatile memory unit 122 stores the device private key (priv_B). Step S206: The management control unit 33 transmits, via the management communication unit 31, the device certificate (cert_B) to the server device 2. The server control unit 23 of the server device 2 receives the device certificate (cert_B) via the server communication unit 21. Step S207: The server control unit 23 of the server device 2 verifies the device certificate (cert_B) using the second certification authority certificate. If the server control unit 23 determines, based on the verification result, that the device certificate (cert_B) is a valid certificate, it writes the device certificate (cert_B) to the server storage unit 22. As a result, the server storage unit 22 stores the device certificate (cert_B). Then, the process ends.

[0061] Note that in the process shown in this figure, the management device 3 generates the device key pair. However, this is not the only case. The device device 1 may generate the device key pair, send only the public key of the generated device key to the management device 3, and store the private key of the device key in the device storage unit 12.

[0062] Figure 4 is a sequence diagram showing the operation of the mutual authentication and session key sharing process between the device device 1 and the server device 2 according to this embodiment. The server device 2 pre-stores the server private key (priv_A) and the device certificate (cert_B) as the held data. Also, the device device 1 pre-stores the server public key (pub_A) and the device private key (priv_B) as the held data. The device device 1 or the server device 2 newly generates a session key to be used for encrypted communication and executes the process shown in this figure when updating the session. For example, the timing for newly generating the session key is when the usage period of the session key reaches a certain period (for example, a period longer than the usage period of a session key used in general encrypted communication such as one month or three months), when the number of times the session key is used reaches a certain number of times, or when there is an explicit instruction from the operator of the server device 2 or the device device 1.

[0063] Step S301: The server control unit 23 of the server device 2 generates a temporary server key pair, which is a pair of a temporarily used temporary server public key (e_pub_A) and a temporary server private key (e_priv_A). Step S302: The server control unit 23 generates a server signature (sig_A), which is an electronic signature of the temporary server public key (e_pub_A) using the server private key (priv_A). Step S303: The server control unit 23 sends the temporary server public key (e_pub_A) and the server signature (sig_A) to the device device 1 via the server communication unit 21. The device control unit 13 of the device device 1 receives the temporary server public key (e_pub_A) and the server signature (sig_A) via the device communication unit 11.

[0064] Step S304: The device control unit 13 of the device apparatus 1 verifies the server signature (sig_A) using the server public key (pub_A), and determines that the server apparatus 2 is a legitimate device when it is determined that the server signature (sig_A) is generated using the temporary server public key (e_pub_A) and the server private key (priv_A). Step S305: When the device control unit 13 determines that the server apparatus 2 is a legitimate device, it generates a temporary device key pair, which is a pair of a temporary device public key (e_pub_B) and a temporary device private key (e_priv_B) to be temporarily used. Step S306: The device control unit 13 generates a device signature (sig_B), which is an electronic signature of the temporary device public key (e_pub_B), using the device private key (priv_B). Step S307: The device control unit 13 transmits the temporary device public key (e_pub_B) and the device signature (sig_B) to the server apparatus 2 via the device communication unit 11. The server control unit 23 of the server apparatus 2 receives the temporary device public key (e_pub_B) and the device signature (sig_B) via the server communication unit 21.

[0065] Step S308: The server control unit 23 of the server apparatus 2 verifies the device signature (sig_B) using the device public key (pub_B) included in the device certificate (cert_B), and determines that the device apparatus 1 is a legitimate device when it is determined that the device signature (sig_B) is generated using the temporary device public key (e_pub_B) and the device private key (priv_B). Step S309: When the server control unit 23 determines that the device apparatus 1 is a legitimate device, it generates a session key to be used for communication with the device apparatus 1 using the temporary device public key (e_pub_B) and the temporary server private key (e_priv_A). Step S311: The device control unit 13 of the device 1 generates a session key for communication with the server device 2 using the temporary server public key (e_pub_A) and the temporary device private key (e_priv_B). For example, the device control unit 13 and the server control unit 23 generate a session key by ECDH (Elliptic curve Diffie-Hellman key exchange). Step S312: The device control unit 13 writes the session key to the non-volatile memory unit 122 of the device storage unit 12. As a result, the non-volatile memory unit 122 stores the session key. Step S313: The device 1 and the server device 2 perform encrypted communication using the session keys generated by each of them.

[0066] Note that in the process shown in this figure, the process starts by transmitting the temporary server public key (e_pub_A) and the server signature (sig_A) from the server device 2, but it is not limited to this. The process may also start by transmitting the temporary device public key (e_pub_B) and the device signature (sig_B) from the device 1. For example, the device 1 stores the number of times the session key is used, and when the number of uses reaches a certain number, it may transmit the temporary device public key (e_pub_B) and the device signature (sig_B) to the server device 2 to start the mutual authentication and session key sharing process. Alternatively, when the number of times the session key is used reaches a certain number, the device 1 may request the server device 2 to update the session key and start the mutual authentication and session key sharing process from the server device 2.

[0067] As described above, according to this embodiment, in the communication system S1 including the device apparatus 1 and the server apparatus 2, the device apparatus 1 includes a device communication unit 11 that communicates with the server apparatus 2, a device storage unit 12 that stores a device private key (priv_B) and a server public key (pub_A), and a device control unit 13 that performs authentication to determine whether the device at the communication destination is a legitimate device. Further, the server apparatus 2 includes a server communication unit 21 that communicates with the device apparatus 1, a server storage unit 22 that stores a server private key (priv_A) and a device certificate (cert_B), and a server control unit 23 that performs authentication to determine whether the device at the communication destination is a legitimate device. Then, the server control unit 23 generates a temporary server key pair that is a pair of a temporarily used temporary server public key (e_pub_A) and a temporary server private key (e_priv_A), generates a server signature (sig_A) that is an electronic signature of the temporary server public key (e_pub_A) using the server private key (priv_A), and transmits the temporary server public key (e_pub_A) and the server signature (sig_A) to the device apparatus 1. The device control unit 13 verifies the server signature (sig_A) using the server public key (pub_A), and when it is determined that the server signature (sig_A) is generated using the temporary server public key (e_pub_A) and the server private key (priv_A), determines that the server apparatus 2 is a legitimate device.

[0068] With such a configuration, the device 1 can authenticate the server device 2 by storing only the server public key (pub_A). That is, the device 1 can authenticate the server device 2 without storing a large amount of information such as the server certificate (cert_A) or the first CA certificate including the first CA public key. Therefore, the device 1 can perform secure communication with the server device 2 with at least the storage capacity of the non-volatile storage unit 122. That is, secure communication can be performed between the device 1 and the server device 2 without storing a large amount of information in the device 1. Also, since the authentication data transmitted by the server device 2 for authentication is only the temporary server public key (e_pub_A) and the server signature (sig_A), the size of the communication data can be reduced. Thereby, even for the device 1 with a small size of data that can be transmitted and received in one communication and a slow communication speed, the server device 2 can be authenticated.

[0069] In addition, the device control unit 13 generates a temporary device key pair, which is a pair of a temporary device public key (e_pub_B) and a temporary device private key (e_priv_B) used temporarily, generates a device signature (sig_B), which is an electronic signature of the temporary device public key (e_pub_B) using the device private key (priv_B), and transmits the temporary device public key (e_pub_B) and the device signature (sig_B) to the server device 2. Also, the server control unit 23 verifies the device signature (sig_B) using the device public key (pub_B) included in the device certificate (cert_B), and determines that the device 1 is a legitimate device when it is determined that the device signature (sig_B) is generated using the temporary device public key (e_pub_B) and the device private key (priv_B).

[0070] In the embodiment, the verification of the device certificate (cert_B) is exemplified by being performed in steps S206 and S207 shown in FIG. 3. However, it is not limited to this. For example, between steps S307 and S308 shown in FIG. 4, the server device 2 may verify the device certificate (cert_B) using the second certification authority certificate. Verifying the device certificate (cert_B) is, for example, a consistency check to verify whether the device certificate (cert_B) is a legitimate certificate and a check of the expiration date of the device certificate (cert_B). Thereby, every time the device device 1 and the server device 2 authenticate each other (execute the process of FIG. 4), it is possible to confirm whether the expiration date of the device certificate (cert_B) has expired. If the expiration date has expired, an authentication error can be set and the process after step S309 can be prevented from being executed.

[0071] With such a configuration, if the device device 1 stores only the device private key (priv_B), the server device 2 can authenticate the device device 1. That is, the device device 1 does not need to store the device certificate (cert_B) including the device public key (pub_B) in order to be authenticated by the server device 2. Thereby, even a device device 1 with a small storage capacity of the non-volatile storage unit 122 can perform secure communication with the server device 2. Therefore, even if a large amount of information is not stored in the device device 1, the device device 1 and the server device 2 can perform secure communication. In addition, since the authentication data transmitted by the device device 1 for authentication is only the temporary device public key (e_pub_B) and the device signature (sig_B), the size of the communication data can be reduced. Thereby, even a device device 1 with a small data size that can be transmitted and received in one communication and a slow communication speed can be authenticated by the server device 2.

[0072] In addition, the device 1 and the server 2 can perform mutual authentication and session key sharing by simply transmitting and receiving each other's authentication data once. That is, the temporary server public key (e_pub_A) and the server signature (sig_A) serve both as authentication data for authenticating the server 2 and as generation data for the device 1 to generate a session key. Also, the temporary device public key (e_pub_B) and the device signature (sig_B) serve both as authentication data for authenticating the device 1 and as generation data for the server 2 to generate a session key. Therefore, the device 1 and the server 2 can reduce the number of communication times for mutual authentication and session key sharing. As a result, even for the device 1 with a low communication speed or a small data size that can be transmitted and received in one communication, secure communication with the server 2 can be achieved.

[0073] In addition, the device storage unit 12 includes a volatile storage unit 121 that stores information when power is supplied, and a non-volatile storage unit 122 that stores information even when power is not supplied. When the device control unit 13 determines that the server 2 is a legitimate device, it generates a first session key for communication with the server 2 using the temporary server public key (e_pub_A) and the temporary device private key (e_priv_B), stores the first session key in the non-volatile storage unit 122, and performs encrypted communication with the server 2 using the first session key. By storing the first session key in the non-volatile storage unit 122 in this way, the first session key can be used for a long time. As a result, the device 1 and the server 2 do not need to perform communication for mutual authentication and session key sharing each time. Thereby, the number of communication times can be reduced, and the power consumed for communication can be reduced. Also, the power consumed for processing for mutual authentication and session key sharing can be reduced. Therefore, even for the device 1 that requires low-speed communication and power saving, secure communication with the server 2 can be achieved.

[0074] Also, when the device control unit 13 receives the temporary server public key (e_pub_A) and the server signature (sig_A) from the server device 2, it verifies the server signature (sig_A) using the server public key (pub_A). When it is determined that the server signature (sig_A) is generated using the temporary server public key (e_pub_A) and the server private key (priv_A), it determines that the server device is a legitimate device. Then, using the temporary server public key (e_pub_A) and the temporary device private key (e_priv_B), it generates a second session key for communication with the server device 2, stores the second session key in the non-volatile memory unit 122, and performs encrypted communication with the server device using the second session key. Thus, when the server device 2 transmits the temporary server public key (e_pub_A) and the server signature (sig_A) to the device 1 again at an arbitrary timing, the mutual authentication and session key sharing process can be executed again to update the session key. This can prevent the adverse effects of using the session key for a long time, such as eavesdropping on communication due to leakage of the session key, and enables flexible response according to the level of security requirements.

[0075] Furthermore, it further includes a management device 3 that transmits a server public key (pub_A) to the device 1. The management device 3 stores a first CA certificate, which is a certificate of a first certification authority that certifies the server device 2. The server storage unit 22 stores a key pair of a server public key (pub_A) and a server private key (priv_A), and a server certificate (cert_A) that includes an electronic signature of the server public key (pub_A) signed by the first certification authority. The server control unit 23 transmits the server certificate (cert_A) to the management device 3. When the management device 3 determines that the server certificate is valid based on the verification result of verifying the server certificate (cert_A) using the first CA certificate, it acquires the server public key (pub_A) from the server certificate (cert_A) and transmits the acquired server public key (pub_A) to the device 1. With such a configuration, since the management device 3 can verify the server certificate (cert_A) in advance processing, the device 1 can acquire the server public key (pub_A) of a legitimate device without executing the process of verifying the server certificate (cert_A) of the server device 2. As a result, the device 1 does not need to verify the validity of the server public key (pub_A) every time it authenticates the server device 2. Therefore, without storing the first CA certificate in the device 1 and without the device 1 receiving the server certificate (cert_A), a security function equivalent to the chain verification of the server signature (sig_A) using the first CA certificate and the server certificate (cert_A) can be realized.

[0076] In addition to verifying whether the server certificate is valid, the management device 3 may perform verification to determine whether the server device 2 is a legitimate device. In this case, verification using the existing TLS mechanism is possible.

[0077] Further, a management device 3 is further provided that transmits a device private key (priv_B) to the device 1 and transmits a device certificate (cert_B) to the server device 2. The server storage unit 22 stores a second certification authority certificate that is a certificate of the second certification authority for certifying the device 1. The management device 3 generates a key pair of a device public key (pub_B) and a device private key (priv_B), and requests the second certification authority to generate a device certificate (cert_B) including the device public key (pub_B) among the generated key pairs, and obtains the device certificate (cert_B) from the second certification authority, transmits the device private key (priv_B) to the device 1, and transmits the device certificate (cert_B) to the server device 2. With such a configuration, since the management device 3 obtains the device certificate (cert_B) from the second certification authority, the device 1 does not need to execute a process of obtaining the device certificate (cert_B). Further, since the management device 3 that can communicate with the server device 2 at high speed transmits the device certificate (cert_B) to the server device 2, the device certificate (cert_B) can be transmitted to the server device 2 even if the communication speed of the device 1 is low.

[0078] Also, the management device 3 generates a key pair of a new device public key (pub_B) and a device private key (priv_B) before the expiration date arrives according to the expiration date of the device certificate (cert_B), and requests the second certification authority to generate a device certificate (cert_B) including the device public key (pub_B) among the newly generated key pairs, obtains a new device certificate (cert_B) from the second certification authority, transmits the newly generated device private key (priv_B) to the device 1, and transmits the newly obtained device certificate (cert_B) to the server device 2. With such a configuration, the management device 3 manages the expiration date of the device certificate and can update the device certificate (cert_B) before the expiration date arrives. Therefore, even if the device 1 does not store the device certificate (cert_B), the expiration date management of the device certificate (cert_B) can be performed.

[0079] All or part of the communication system S1 in the above-described embodiment may be implemented by a computer. In that case, a program for realizing this function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to realize it. Here, the "computer system" is assumed to include hardware such as an OS and peripheral devices. Also, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, etc., and a storage device such as a hard disk built into a computer system. Furthermore, the "computer-readable recording medium" refers to something that dynamically holds a program for a short time, like a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, and may also include something that holds a program for a certain period of time, like a volatile memory inside a computer system that serves as a server or a client in that case. Also, the above program may be for realizing a part of the aforementioned functions, and may further be realizable in combination with a program already recorded in the computer system for the aforementioned functions, and may also be realized using a programmable logic device such as an FPGA.

[0080] As described above, the embodiments of the present invention have been described in detail with reference to the drawings. However, the specific configuration is not limited to this embodiment, and designs and the like within the scope not departing from the gist of the present invention are also included.

Description of Reference Numerals

[0081] S1... communication system, 1... device device, 11... device communication section, 12... device storage section, 121... volatile storage section, 122... non-volatile storage section, 13... device control section, 2... server device, 21... server communication section, 22... server storage section, 23... server control section, 3... management device, 31... management communication section, 32... management storage section, 33... management control section

Claims

1. In a communication system comprising a device apparatus, a server apparatus, and a management apparatus, when the management apparatus determines that a server certificate that proves a server public key is a valid certificate, the management apparatus transmits the server public key included in the server certificate to the device apparatus, and in communication with the server apparatus, the device apparatus determines whether the server apparatus is a valid apparatus by using the server public key received from the management apparatus. A communication system characterized by the above.

2. The management apparatus verifies the server certificate by using a first certification authority certificate that is a certificate for proving the server apparatus. When the management apparatus determines that the server certificate is a valid certificate, the management apparatus acquires the server public key from the server certificate and transmits the acquired server public key to the device apparatus. The device apparatus verifies a server signature that is an electronic signature using a server private key corresponding to the server public key notified from the server apparatus by using the server public key received from the management apparatus. When the device apparatus determines that the server signature is generated by using the server private key, the device apparatus determines that the server apparatus is a valid apparatus. The communication system according to Claim 1.

3. The device apparatus includes a device communication unit that communicates with the server apparatus, a device storage unit that stores a device private key and the server public key received from the management apparatus, and a device control unit that performs authentication to determine whether a communication destination apparatus is a valid apparatus. The device apparatus has the above components. The server apparatus includes a server communication unit that communicates with the device apparatus, a server storage unit that stores a server private key and a device certificate, and a server control unit that performs authentication to determine whether a communication destination apparatus is a valid apparatus. The server apparatus has the above components. The server control unit generates a key pair that is a pair of a temporary server public key and a temporary server private key to be temporarily used, generates a server signature that is an electronic signature of the temporary server public key by using the server private key, and transmits the temporary server public key and the server signature to the device apparatus. When the device control unit verifies the server signature by using the server public key received from the management apparatus and determines that the server signature is generated by using the temporary server public key and the server private key, the device control unit determines that the server apparatus is a valid apparatus. The management device stores a first CA certificate, which is a certificate of the first certification authority that certifies the server device. The server storage unit stores a key pair of the server public key and the server private key, and a server certificate including an electronic signature of the server public key signed by the first certification authority. The server control unit transmits the server certificate to the management device. When the management device determines that the server certificate is a valid certificate based on the verification result of verifying the server certificate using the first CA certificate, the management device acquires the server public key from the server certificate and transmits the acquired server public key to the device device. The communication system according to claim 1.

4. In a communication system including a device device, a server device, and a management device, the management device creates a device certificate by transmitting the device public key of the key pair of the device public key and the device private key in the device device to a second certification authority that certifies the device device, and transmits the device certificate generated by the second certification authority to the server device. In communication with the device device, the server device determines whether the device device is a valid device using the device certificate received from the management device. Communication system.

5. The management device generates a key pair of the device public key and the device private key, and transmits the device private key to the device device. The device device transmits a device signature, which is an electronic signature using the device private key received from the management device, to the server device. In communication with the device device, the server device determines whether the device device is a valid device by verifying the device signature notified from the device device using the device public key. The communication system according to claim 4.

6. The device device includes a device communication unit that communicates with the server device, a device storage unit that stores the device private key received from the management device and the server public key, a device control unit that performs authentication to determine whether a communication destination device is a valid device, and has The server device includes a server communication unit that communicates with the device device, a server storage unit that stores a server private key and the device certificate received from the management device. A server control unit that performs authentication to determine whether the communication destination device is a legitimate device, having The server control unit generates a key pair that is a pair of a temporary server public key and a temporary server private key to be temporarily used, generates a server signature that is an electronic signature of the temporary server public key using the server private key, and transmits the temporary server public key and the server signature to the device device. The device control unit verifies the server signature using the server public key, and determines that the server device is a legitimate device when it is determined that the server signature is generated using the temporary server public key and the server private key. The server storage unit stores a second certification authority certificate that is a certificate of the second certification authority. The management device generates a key pair of the device public key and the device private key, requests the second certification authority to generate the device certificate including the device public key of the generated key pair, obtains the device certificate from the second certification authority, transmits the device private key to the device device, and transmits the device certificate to the server device. The communication system according to claim 4.

7. The device control unit generates a key pair that is a pair of a temporary device public key and a temporary device private key to be temporarily used, generates a device signature that is an electronic signature of the temporary device public key using the device private key, and transmits the temporary device public key and the device signature to the server device. The server control unit verifies the device signature using the device public key included in the device certificate, and determines that the device device is a legitimate device when it is determined that the device signature is generated using the temporary device public key and the device private key. The communication system according to claim 3 or claim 6.

8. The device storage unit includes a volatile storage unit that stores information when power is supplied, and a non-volatile storage unit that stores information even when power is not supplied. The device control unit generates a key pair, which is a pair of a temporary device public key and a temporary device private key for temporary use. When it is determined that the server device is a legitimate device, a first session key for communication with the server device is generated using the temporary server public key and the temporary device private key. The first session key is stored in the non-volatile storage unit, and encrypted communication is performed with the server device using the first session key. The communication system according to claim 3 and claim 6.

9. When the device control unit receives the temporary server public key and the server signature from the server device, it verifies the server signature using the server public key. When it is determined that the server signature is generated using the temporary server public key and the server private key, it is determined that the server device is a legitimate device. A second session key for communication with the server device is generated using the temporary server public key and the temporary device private key. The second session key is stored in the non-volatile storage unit, and encrypted communication is performed with the server device using the second session key. The communication system according to claim 8.

10. The management device generates a key pair of a new device public key and the device private key before the expiration date arrives according to the expiration date of the device certificate. It requests the second certification authority to generate a device certificate including the device public key of the newly generated key pair and obtains a new device certificate from the second certification authority. The newly generated device private key is transmitted to the device device, and the newly obtained device certificate is transmitted to the server device. The communication system according to claim 4.

11. The management device obtains a new server certificate from the server device before the expiration date arrives according to the expiration date of the server certificate. The new server certificate is verified using the first certification authority certificate, which is the certificate of the first certification authority that certifies the server device. When it is determined that the new server certificate is a legitimate certificate, the server public key is obtained from the new server certificate, and the obtained server public key is transmitted to the device device. The communication system according to claim 1.

12. A communication method in a communication system including a device device, a server device, and a management device, When the management device determines that the server certificate that proves the server public key is a valid certificate, a step of transmitting the server public key included in the server certificate to the device device; A device control step in which the device device determines whether the server device is a legitimate device by using the server public key received from the management device in communication with the server device; A communication method including the above.

13. A communication method in a communication system including a device device, a server device, and a management device, The management device transmits the device public key among the key pair of the device public key and the device private key in the device device to a second certification authority that proves the device device to create a device certificate, and the second certification authority transmits the generated device certificate to the server device; A server control step in which the server device determines whether the device device is a legitimate device by using the device certificate received from the management device in communication with the device device; A communication method including the above.

14. For a computer of a management device that substitutes for processing performed by the device device to achieve secure communication between the device device and the server device, When it is determined that the server certificate that proves the server public key is a valid certificate, a step of transmitting the server public key included in the server certificate to the device device, A program for causing the above to be executed.

15. For a computer of a management device that substitutes for processing performed by the device device to achieve secure communication between the device device and the server device, A step of creating a device certificate by transmitting the device public key among the key pair of the device public key and the device private key in the device device to a second certification authority that proves the device device, and transmitting the device certificate generated by the second certification authority to the server device; A program for causing the above to be executed.

Citation Information

Patent Citations

  • Information processor, and cipher communication system and method provided with the processor

    JP2001251297A

  • Security function substitution method in data communication and its system, and recording medium

    JP2002082907A

  • Cryptographic communication system and authentication method used therefor

    JP2002244557A

  • Information processing device and control program thereof

    JP2020202500A

  • Update program and method, and management program and method

    WO2015193945A1