Transmitting apparatus, transmitting method, receiving apparatus, and receiving method
The described solution for LPWA communication enhances security and reduces power consumption by using a key stream generated from timing-based information to encrypt and modulate transmission data, improving confidentiality and communication tolerance.
Patent Information
- Application Number
- JP2020548329
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2018-09-28
- Filing Date
- 2019-09-06
- Publication Date
- 2025-06-09
- Estimated Expiration
- 2039-09-06
AI Technical Summary
LPWA communication faces challenges in achieving high security and low power consumption, as encryption methods that enhance security increase processing load and power consumption in IoT terminals.
The proposed solution involves a transmission device that generates a key stream using different information as an initial value based on timing, encrypts transmission data, and modulates the encrypted data into different waveform signals in various frequency bands, which are then transmitted at different timings. The receiving device receives these waveform signals, inverts their polarity, and decodes the transmission data.
This approach improves confidentiality and communication tolerance in LPWA communication by reducing power consumption, enhancing security through multi-layer defense, and effectively counteracting replay and forgery attacks.
Smart Images

Figure 0007689826000001 
Figure 0007689826000002 
Figure 0007689826000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a transmission device and a transmission method, and a reception device and a reception method, and more particularly, to a transmission device and a transmission method, and a reception device and a reception method that can improve confidentiality and communication tolerance in LPWA (Low Power Wide Area) communication.
Background Art
[0002] Communication technologies using LPWA (Low Power Wide Area) communication have been proposed (see Patent Document 1).
[0003] Since LPWA communication is a communication that unidirectionally transmits and receives a small amount of Payload data (around 100 bits) with a low bit rate from an IoT terminal (transmission device) to an IoT gateway (reception device), an IoT terminal (transmitter) that performs LPWA communication can achieve communication with low power consumption.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the above-described LPWA communication, in order to achieve high security, if an encryption method using arithmetic processing for solving complex mathematical problems is used, the processing load increases in an IoT terminal that requires low power consumption, and the power consumption becomes large.
[0006] Also, from the perspective of multi-layer defense, by introducing encryption at the physical layer and combining it with encryption processing at layers above the physical layer, further confidentiality can be improved.
[0007] In particular, in wireless communication, a method for enhancing demodulation capabilities is used, which employs waveform synthesis techniques (such as maximum ratio combining and selection combining) at the physical layer.
[0008] In this case, for waveform synthesis, it is necessary to use the same wireless waveform or a waveform that can be easily converted into the same waveform.
[0009] When using the same wireless waveform, since a replay (reflection) attack that captures and retransmits the wireless waveform to attack the IoT gateway (receiver) becomes possible, countermeasures against replay (reflection) attacks are required.
[0010] Furthermore, in a format composed only of linear codes, countermeasures against tampering such as bit flipping are necessary, and countermeasures such as those using CMAC (Cihper-based MAC: Cipher-based Message Authentication Code) are generally adopted.
[0011] However, when using waveform synthesis technology to improve wireless demodulation / decoding performance, a method of changing the CMAC value for each transmission to cope with replay attacks cannot be adopted.
[0012] The present disclosure has been made in view of such a situation, and in particular, it improves the confidentiality and communication tolerance in LPWA communication.
Means for Solving the Problem
[0013] The transmitting device according to the first aspect of the present disclosure At least includes a key stream generation unit that generates a key stream using different information as an initial value according to timing, an encryption unit that converts transmission data into encrypted data using the key stream, and a plurality of different waveform signals obtained by modulating a plurality of different encrypted data obtained by encrypting the transmission data with a plurality of different key streams generated at a plurality of different timings, each in a different frequency band and the predetermined number of a transmission unit that transmits at different timings.
[0014] The transmission method according to the first aspect of the present disclosure is as follows: At least A key stream generation process that generates a key stream using different information as an initial value according to timing, an encryption process that converts transmission data into encrypted data using the key stream, and a predetermined number of different encrypted data obtained by encrypting the transmission data with a predetermined number of different key streams generated at a predetermined number of different timings are modulated into a predetermined number of different waveform signals, each in a different frequency band and the predetermined number of A transmission process of transmitting at different timings.
[0015] In the first aspect of the present disclosure, At least A key stream is generated using different information as an initial value according to timing, the transmission data is converted into encrypted data using the key stream, and a predetermined number of different waveform signals obtained by modulating a predetermined number of different encrypted data obtained by encrypting the transmission data with a predetermined number of different key streams generated at a predetermined number of different timings are each in a different frequency band and the predetermined number of Transmitted at different timings.
[0016] The receiving device according to the second aspect of the present disclosure is configured to receive, from a transmitting device, a predetermined number of different waveform signals that are transmitted in different frequency bands and at different timings, At least wherein the waveform signals are obtained by modulating a predetermined number of different encrypted data obtained by encrypting transmission data with a predetermined number of different key streams generated using different information as an initial value according to the timing, and the key streams are generated at a predetermined number of different timings. The receiving device includes a receiving unit that receives each of the waveform signals in a different frequency band and at different timings, a key stream generation unit that generates a key stream using different information as an initial value according to the timing, a polarity inversion unit that inverts the polarity of the waveform of the waveform signal using the key stream, and a decoding unit that decodes the transmission data by integrating the predetermined number of different waveform signals whose polarities have been inverted. a predetermined number of
[0017] The receiving method according to the second aspect of the present disclosure is to receive, from a transmitting device, at different frequency bands and at different timings, At least a key stream generated with different information as initial values according to the timing, and a predetermined number of different waveform signals obtained by modulating a predetermined number of different encrypted data obtained by encrypting transmission data with a predetermined number of different key streams generated at a predetermined number of different timings, respectively, at the different frequency bands and at the a predetermined number of receiving process of receiving at different timings, a key stream generation process of generating a key stream with different information as initial values according to the timing, a polarity inversion process of inverting the polarity of the waveform of the waveform signal with the key stream, and a decoding process of decoding the transmission data by integrating the predetermined number of different waveform signals whose polarities have been inverted.
[0018] In the second aspect of the present disclosure, from a transmitting device, at different frequency bands and at different timings, At least a key stream generated with different information as initial values according to the timing, and a predetermined number of different waveform signals obtained by modulating a predetermined number of different encrypted data obtained by encrypting transmission data with a predetermined number of different key streams generated at a predetermined number of different timings are received, respectively, at the different frequency bands and at the a predetermined number of different timings, a key stream is generated with different information as initial values according to the timing, the polarity of the waveform of the waveform signal is inverted with the key stream, and the transmission data is decoded by integrating the predetermined number of different waveform signals whose polarities have been inverted.
Brief Description of the Drawings
[0019]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Embodiments for Carrying Out the Invention
[0020] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. In the present specification and the drawings, for components having substantially the same functional configuration, the same reference numerals are given and redundant description is omitted.
[0021] Hereinafter, embodiments for implementing the present technology will be described. The description will be given in the following order. 1. Overview of a communication system using LPWA communication 2. Embodiments of the present disclosure 3. Application examples 4. Examples of execution by software
[0022] <<1. Overview of a one-way communication system using LPWA communication>> With reference to FIG. 1, an overview of a one-way communication system using LPWA (Low Power Wide Area) communication will be described.
[0023] The communication system 1 using LPWA communication in FIG. 1 is composed of IoT (Internet of Things) terminals 11-1 to 11-n, IoT gateways 12-1 to 12-m, and a cloud server 13.
[0024] In addition, when there is no need to particularly distinguish each of the IoT terminals 11-1 to 11-n and the IoT gateways 12-1 to 12-m, they are simply referred to as IoT terminals 11 and IoT gateways 12, respectively, and the same applies to other configurations.
[0025] The IoT terminal 11 is arranged together with various sensors (not shown) provided in various environments or is held by a predetermined user or the like, and in each environment, it acquires sensor data detected by the sensors (not shown) and transmits it to the cloud server 13 via the IoT gateway 12.
[0026] The IoT gateway 12 is controlled in operation by the cloud server 13, relays the sensor data transmitted from the IoT terminal 11, and transmits it to the cloud server 13.
[0027] The cloud server 13 controls the operation of the IoT gateway 12, receives sensor data transmitted from the IoT terminal 11 via the IoT gateway 12, and executes various application programs according to the received sensor data.
[0028] The IoT terminal 11 and the IoT gateway 12 transmit sensor data by LPWA communication. In LPWA communication, sensor data is transmitted unidirectionally from the IoT terminal 11 to the IoT gateway 12.
[0029] In this way, since the IoT terminal 11 only needs to transmit sensor data unidirectionally to the IoT gateway 12 as a small amount of Payload data, communication with low power consumption can be realized.
[0030] More specifically, the IoT terminal 11 includes an encryption unit 31, an encoding unit 32, and an LPWA communication unit 33.
[0031] In the IoT terminal 11, when transmitting sensor data, the encryption unit 31 constitutes the MAC (Media Access Control) layer, and the encoding unit 32 and the LPWA communication unit 33 constitute the PHY (physical) layer.
[0032] The encryption unit 31 generates the Payload of the transmission data sequence based on the sensor data, and further performs CMAC (Cihper-based MAC: cipher-based message authentication code) processing based on the Payload to generate a CMAC tag for verifying the presence of forgery, and outputs the Payload and the CMAC tag to the encoding unit 32.
[0033] The encoding unit 32 creates a plaintext data bit sequence with an error detection / correction code added to the Payload and the CMAC tag, then converts it into an encrypted data bit sequence and transmits it to the LPWA communication unit 33.
[0034] The LPWA communication unit 33 modulates the encrypted data bit sequence of the sensor data to generate a transmission frame waveform and transmits it to the IoT gateway 12 via LPWA communication.
[0035] The IoT gateway 12 includes an LPWA communication unit 51 and a decoding unit 52. In the IoT gateway 12, when receiving a transmission frame waveform composed of sensor data, the LPWA communication unit 51 constitutes the PHY (Physical) layer, and the decoding unit 52 constitutes the MAC layer.
[0036] The LPWA communication unit 51 receives the transmission frame waveform transmitted via LPWA communication, demodulates it as a waveform signal of the encrypted data bit sequence of the sensor data transmitted from the IoT terminal 11, and outputs it to the decoding unit 52.
[0037] The decoding unit 52 decodes the waveform signal of the encrypted data bit sequence into a stream decoded data bit sequence including a Payload composed of sensor data and a CMAC tag, obtains the CMAC tag from the Payload, determines the presence or absence of forgery of the Payload based on comparison with the transmitted CMAC tag, and transmits the sensor data, which is the Payload, to the cloud server 13 together with the determination result.
[0038] The cloud server 13 controls the operation of the IoT gateway 12 and executes various application programs 71-1 to 71-p based on the sensor data transmitted from the IoT terminal 11 via the IoT gateway 12.
[0039] In FIG. 1, the operation state of the application program 71-1 in the cloud server 13 based on the sensor data transmitted from the IoT terminal 11 via the IoT gateway 12 is shown, but other application programs 71 also function in the same manner.
[0040] Here, in the communication system 1 of FIG. 1, the communication TRZ11 between the IoT terminal 11 and the IoT gateway 12 is LPWA communication, which is one-way (unidirectional) communication in which only the transmission frame waveform is transmitted from the IoT terminal 11 to the IoT gateway 12. For this reason, since the communication TRZ11 between the IoT terminal 11 and the IoT gateway 12 cannot communicate with each other, for example, confirmation by challenge and response authentication cannot be performed, so countermeasures are required against eavesdropping and tampering.
[0041] On the other hand, regarding the communication TRZ12 between the IoT gateway 12 and the cloud server 13, since it is a communication that enables two-way communication, it is considered that stronger security than the communication TRZ11 can be realized.
[0042] Next, the operation of the communication system 1 of FIG. 1 will be described.
[0043] The encryption unit 31 of the IoT terminal 11 acquires sensor data detected by a sensor (not shown), generates a Payload corresponding to the sensor data, and based on the Payload, performs CAMC processing to generate a CMAC tag, and outputs the Payload and the CMAC tag to the encoding unit 32.
[0044] The encoding unit 32 converts the plaintext data bit string with an error detection / correction code added to the Payload and the CMAC tag into an encrypted data bit string, and outputs it to the LPWA communication unit 33.
[0045] The LPWA communication unit 33 generates a transmission frame waveform signal by modulating the encrypted data bit string, and transmits it to the IoT gateway 12 by LPWA communication.
[0046] The LPWA communication unit 51 of the IoT gateway 12 receives the transmission frame waveform signal transmitted by LPWA communication, demodulates the encrypted data bit string of the sensor data transmitted from the IoT terminal 11 based on the received transmission frame waveform signal, and outputs it to the decoding unit 52.
[0047] The decryption unit 52 decrypts the Payload consisting of sensor data and the CMAC tag from the encrypted data bit sequence, obtains the CMAC tag from the Payload, determines the presence or absence of Payload tampering based on a comparison with the transmitted CMAC tag, and transmits the sensor data, which is the Payload, together with the determination result to the cloud server 13.
[0048] The cloud server 13 controls the operation of the IoT gateway 12 and executes various application programs 71-1 to 71-p based on the sensor data transmitted from the IoT terminal 11 via the IoT gateway 12.
[0049] Through the above series of operations, the sensor data detected by a sensor (not shown) can be transmitted from the IoT terminal 11 via the IoT gateway 12 to the cloud server 13, and the application program 71 managed by the cloud server 13 can be operated. At this time, since the IoT terminal 11 can transmit sensor data to the IoT gateway in one-way communication by LPWA communication, it is possible to realize communication with low power consumption.
[0050] <Method for Converting a Plaintext Data Bit Sequence Containing Payload of Sensor Data and CMAC Tag into an Encrypted Data Bit Sequence> Next, with reference to FIG. 2, a method for converting a plaintext data bit sequence containing Payload of sensor data and the CMAC tag by the encoding unit 32 in FIG. 1 into an encrypted data bit sequence will be described.
[0051] The encoding unit 32 in FIG. 2 includes a keystream generator 91 and an XOR processing unit 92.
[0052] The keystream generator 91 generates a pseudo-random bit sequence (PRBS: Pseudo Random Binary Sequence) as a keystream from the initial value data (NONCE: Number used Once) and the secret key data, and outputs it to the XOR processing unit 92.
[0053] Note that the initial value data (NONCE) is a numerical value that is used only once and is different for each reset.
[0054] The XOR processing unit 92 encrypts the plaintext data bit sequence including the Payload and the CMAC tag by performing exclusive OR (XOR) processing on a bit-by-bit basis using the keystream, and converts it into an encrypted data bit sequence for output.
[0055] Note that in the decoder 52 of the IoT gateway 12, a configuration similar to that of the keystream generator 91 is provided. The decoder 52 generates a keystream by using the same initial value data (NONCE: Number used Once) and the secret key data as those of the keystream generator 91, and decrypts the encrypted data bit sequence into a stream decrypted data bit sequence by performing exclusive OR (XOR) processing on the encrypted data bit sequence by using the generated keystream.
[0056] <Reasons for using the keystream> Here, the reason for using a stream cipher when generating an encrypted data bit sequence in the PHY (physical) layer will be explained.
[0057] There are block encryption performed in units of a predetermined number of bits (block units) and stream ciphers performed in units of an arbitrary number of bits for encryption.
[0058] For example, as shown in the upper part of FIG. 3, instead of the keystream generator 91 and the XOR processing unit 92, the encoding unit 32 includes an encryptor 101 that encrypts in predetermined bit units (block units), for example, an AES (Advanced Encryption Standard) encryptor. Correspondingly, consider the case where the decoding unit 52 is provided with a decryptor 104 that decrypts in block units.
[0059] In FIG. 3, the plaintext data bit sequence is converted into an encrypted data bit sequence by the encryptor 101, and the encrypted data bit sequence is modulated into a transmission frame waveform signal by the modulator 102 of the LPWA communication unit 33 and transmitted to the LPWA communication unit 51 of the IoT gateway 12 via the wireless communication path. Also, in the LPWA communication unit 51, the demodulator 103 demodulates the transmitted transmission frame waveform signal into an encrypted data bit sequence and outputs it to the decoding unit 52.
[0060] In such a case, as shown in the lower part of FIG. 3, consider the case where the secret key is "00112233445566778899aabbccddeeff", the data is "00000000000000000000000000000000", and the encrypted data bit sequence is "fde4fbae4a09e020eff722969f83832b". In such a case, the decrypted data bit sequence will be the same as the data, i.e., "00000000000000000000000000000000".
[0061] Here, noise occurs on the communication path, and due to this noise, for example, the leading bit of the encrypted data bit sequence surrounded by the dotted line is bit-reversed from "f" (= binary "1111") to "7" (binary "0111"), and the encrypted data bit sequence becomes "7de4fbae4a09e020eff722969f83832b". In this case, when this encrypted data bit sequence is converted into a stream decrypted data bit sequence, it becomes "c61abdd4dfa32aa26c2b3ff9933542b1".
[0062] That is, in block encryption, the plaintext data bit sequence when not affected by noise is "00000000000000000000000000000000", but when affected by noise and only the leading bit of the encrypted data bit sequence is bit-reversed, the stream decrypted data bit sequence becomes "c61abdd4dfa32aa26c2b3ff9933542b1", which is converted into a completely different decrypted data bit sequence, making error correction in the subsequent stage difficult.
[0063] In contrast, as shown in the upper part of FIG. 4, consider a configuration in which a key stream generator 91 and an XOR processing unit 92 described with reference to FIG. 2 are provided in each of the encoding unit 32 and the decoding unit 52.
[0064] Here, for example, consider a case where the secret key is "3d62e9b18e5b042f42df43cc7175c96e", the NONCE value is "777cefe4541300c8adcaca8a0b48cd55", the generated key stream is "690f108d84f44ac7bf257bd7e394f6c9", and the plaintext data bit sequence is "00000000000000000000000000000000". In this case, when the plaintext data bit sequence is stream-encrypted using the key stream, the encrypted data bit sequence becomes "690f108d84f44ac7bf257bd7e394f6c9". Here, in the wireless communication path, due to the influence of noise, for example, assume that the leading bit of the encrypted data bit sequence is bit-reversed, so that it changes from "6" (= binary "0110") to "e" (binary "1110") as shown surrounded by the dotted line.
[0065] Due to the influence of this noise, the bit-reversed encrypted data bit sequence becomes "e90f108d84f44ac7bf257bd7e394f6c9", and the stream decrypted data bit sequence decrypted from this encrypted data bit sequence becomes "8000000000000000000000000000000".
[0066] That is, in stream encryption, while the plaintext data bit sequence is "00000000000000000000000000000000", the stream decryption output affected by noise becomes "8000000000000000000000000000000", and only the first character is corrected from "8" to "0".
[0067] Using stream encryption for block encryption in this way makes the influence of errors due to noise local, so the possibility of successful error correction increases.
[0068] Therefore, for these reasons, in the communication system of FIG. 1, it can be considered that stream encryption has higher error tolerance than using block encryption.
[0069] <Replay Attack and Tampering Attack> In the LPWA communication described above, there is a possibility of being attacked by a malicious third party.
[0070] For example, as shown in FIG. 3, consider the case where a transmission frame waveform signal Sign1 is transmitted from the IoT terminal 11 to the IoT gateway 12 by LPWA communication.
[0071] In this case, a communication device 111 operated by a malicious third party intercepts (captures) the transmission frame waveform signal Sign1, copies the captured transmission frame waveform signal to generate a transmission frame waveform signal Sign11, and repeatedly transmits it to the IoT gateway 12 such as transmission frame waveform signals Sign11-1, 11-2, ···.
[0072] With such an operation, the IoT gateway 12 repeatedly receives the transmitted frame waveform signal Sign11 generated by copying the transmitted frame waveform signal Sign1. As a result, it is unable to recognize that the received transmitted frame waveform signal has been forged, leading to an increase in the processing load and a reduction in the operating speed, thus causing a service disruption. In this way, an attack that eavesdrops on the transmitted frame waveform signal by the PHY (Physical) layer, copies the eavesdropped transmitted frame waveform signal, and repeatedly transmits it is called a replay attack.
[0073] Also, a communication device 111 operated by a malicious third party eavesdrops (captures) the transmitted frame waveform signal Sign1, analyzes the format specification to identify the bits to be inverted, inverts the bits corresponding to the change in linear codes such as CRC, and generates and transmits a transmitted frame waveform signal Sign12 consisting of a forged waveform with the waveform part corresponding to the inverted bits having its polarity inverted. An attack that generates and transmits a transmitted frame waveform signal consisting of a forged waveform with the waveform part corresponding to a predetermined bit having its polarity inverted is called a forgery attack.
[0074] More specifically, for example, as shown in the upper right of Figure 6, assume the data bit sequence Payload to be transmitted is "010111...". When this data bit sequence Payload "010111..." is encoded, as shown in the upper middle of Figure 6, a data bit sequence "010111...1101..." with "1101..." added as an ECC (Error Correcting Code or Error Check and Correct) consisting of CRC, convolutional code, and low-density parity-check code, etc. by linear coding processing to the data bit sequence Payload "010111..." is generated.
[0075] For example, when a malicious third party attempts to analyze the format specification of a data bit sequence and invert the leading bit, as shown in the middle left of Figure 6, by encoding a data bit sequence Payload "10000…" which is a code word consisting of a bit sequence where only the leading bit is "1", a data bit sequence "100000…1001…" with "1001…" added as an ECC (error correction / check code) is generated as shown in the middle center of Figure 6.
[0076] At this time, when the data bit sequence "010111…1101…" which is the object of tampering is added to the generated data bit sequence "100000…1001…", a new data bit sequence consisting of the data bit sequence "110111…0100…" is generated as shown in the upper right of Figure 6.
[0077] On the other hand, by generating a data bit sequence Payload "110111" with the leading bit of the data bit sequence to be transmitted shown in the lower left of Figure 6 inverted and adding an ECC (error correction / check code), a data bit sequence "110111…0100…" as shown in the lower right of Figure 6 can be generated. Since these are the same data bit sequences, the receiving side cannot determine whether the data has been tampered with or not, and there is a possibility of a tampering attack by a tampered transmission frame waveform signal such as the transmission signal sign12 in Figure 5.
[0078] However, the above tampering attack occurs because the ECC (error correction / check code) is a linear operation, and it can be defended by using CMAC.
[0079] However, for a replay attack, since a waveform synthesis method is used in the reception process, it cannot be defended by CMAC.
[0080] By using different transmission frame waveforms for each transmission, it is conceivable to take countermeasures against replay attacks. However, when including transmission information such as timing during CMAC tag generation, the transmission frame waveform signals will differ significantly for each transmission, making waveform synthesis difficult. Thus, in LPWA communication, although CMAC is used to defend against forgery attacks, replay attacks cannot be countered.
[0081] In the communication system of the present disclosure, by realizing effective countermeasures against replay attacks and forgery attacks, the confidentiality and communication tolerance in LPWA (Low Power Wide Area) communication can be improved.
[0082] <<2. Embodiments of the Present Disclosure>> Next, with reference to FIG. 7, a configuration example of the communication system of the present disclosure will be described.
[0083] The communication system 200 of the present disclosure is similar to the communication system 1 in FIG. 1 in its basic configuration. That is, the communication system 200 is composed of transmission devices 201-1 to 201-n, reception devices 202-1 to 202-m, and a cloud server 203.
[0084] The transmission device 201 corresponds to the IoT terminal 11 in FIG. 1, and transmits sensor data detected by a sensor (not shown) to the cloud server 203 via the reception device 202 by LPWA communication. Here, the transmission device 201 acquires GPS time information transmitted together with the position information by GPS (Global Positioning System), uses it as a NONCE together with the TXID which is the unique ID of the transmission device 201, generates a key stream, and uses this key stream to convert the plaintext data bit string into an encrypted data bit string.
[0085] The receiving device 202 has a configuration corresponding to the IoT gateway 12 in FIG. 1, receives the transmission signal transmitted from the transmitting device 201, and transmits it to the cloud server 203. At this time, the receiving device 202 acquires the GPS time information transmitted together with the position information by GPS (Global Positioning System), generates a key stream together with the TXID of the transmitting device 201, and converts the encrypted data bit string into a stream decrypted data bit string.
[0086] Note that the cloud server 203 is equipped with application programs 211-1 to 211-p and is basically the same as the cloud server 13 in FIG. 1, so its description will be omitted.
[0087] That is, in the communication system 200 of FIG. 7, the key stream changes each time it is generated based on the GPS time information. By using this changing key stream to convert the plaintext data bit string into an encrypted data bit string, the encrypted data bit string is modulated, and the generated transmission frame waveform signal also changes each time it is transmitted. Therefore, it becomes an effective countermeasure against replay attacks.
[0088] <Configuration example of the transmitting device> Next, with reference to the block diagram of FIG. 8, a configuration example of the transmitting device 201 will be described.
[0089] The transmitting device 201 is composed of a MAC encryption unit 221, an encoding unit 222, and an LPWA transmission unit 223. In the LPWA communication of the transmitting device 201, the MAC encryption unit 221 constitutes the MAC layer, and the encoding unit 222 and the LPWA transmission unit 223 constitute the PHY (physical) layer, which is a lower layer than the MAC layer.
[0090] The MAC (Media Access Control) encryption unit 221 encrypts (at the MAC layer) a Payload consisting of sensor data (not shown), generates an MSDU (MAC Service Data Unit) consisting of a data bit string storing the encrypted data (or the data of the non-encrypted Payload), generates a CMAC tag corresponding to the MSDU, and outputs it to the encoding unit 222.
[0091] More specifically, the MAC encryption unit 221 includes an MSDU generation unit 231 and a CMAC processing unit 232.
[0092] The MSDU generation unit 231 generates an MSDU (MAC Service Data Unit) consisting of a data bit string storing a Payload (or data obtained by encrypting (at the MAC layer) the Payload) consisting of sensor data (not shown) in the MAC layer above the PHY (Physical) layer, outputs it to the CMAC processing unit 232, causes the CMAC processing unit 232 to generate a CMAC tag, combines the MSDU and the CMAC tag, and outputs them to the encoding unit 222.
[0093] The CMAC (Cipher-based Message Authentication Code) processing unit 232 generates a CMAC tag from the MSDU (MAC Service Data Unit) using a message authentication code algorithm. The CMAC tag is used for authentication and data tampering detection during decryption. Since the CMAC tag has the property that its value differs significantly when the original data, i.e., the MSDU, is tampered with, similar to a hash value, it is possible to determine the presence or absence of tampering by comparing the CMAC tag generated from the received data bit string with the received CMAC tag.
[0094] The encoding unit 222 encodes the combined MSDU and CMAC tag and outputs it to the LPWA transmission unit 223.
[0095] More specifically, the encoding unit 222 includes an error correction code addition unit 251, an XOR processing unit 252, a keystream generator 253, a storage unit 254, a GPS time information acquisition unit 255, a synchronization pattern generation unit 256, and a switch 257.
[0096] The error correction code addition unit 251 generates an error correction code ECC, which is a code for detecting and correcting errors, based on the MSDU and the CMAC tag, and generates a data bit sequence called a PSDU (Physical Layer Service Data Unit) by attaching the ECC to the MSDU and the CMAC tag, and outputs it to the XOR processing unit 252.
[0097] The keystream generator 253 reads out the TXID, which is the unique ID of the transmission device 201 pre-stored in the storage unit 254, uses the time information supplied from the GPS time information acquisition unit 255 as a nonce together, and further uses a secret key to generate a keystream consisting of a PRBS (Pseudo Random Binary Sequence) and outputs it to the XOR processing unit 252.
[0098] The storage unit 254 is composed of a memory or the like, stores the TXID, which is the unique ID of the transmission device 201 pre-stored, and supplies it to the keystream generator 253.
[0099] The GPS time information acquisition unit 255 acquires the GPS time information supplied when acquiring the GPS position information by receiving the satellite wave transmitted from a satellite (not shown) and supplies it to the keystream generator 253.
[0100] The XOR processing unit 252 generates an encrypted data bit sequence by performing exclusive OR (XOR) processing on a plaintext data bit sequence consisting of the data bit sequence of the PSDU in bit units using the keystream and outputs it to the switch 257.
[0101] When the synchronization pattern generation unit 256 receives a transmission frame signal for the receiving device 202, it generates a synchronization pattern SYNC indicating the head position and outputs it to the switch 257.
[0102] The switch 257 switches between the synchronization pattern SYNC supplied from the synchronization pattern generation unit 256 and the encrypted data bit sequence of the PSDU supplied from the XOR processing unit 252, generates a PPDU (PLCP (Physical Layer Convergence Protocol) Protocol Data Unit or Physical Layer Protocol Data Unit), and outputs it to the LPWA transmission unit 223.
[0103] More specifically, the switch 257 can switch the input based on the transmission format, and by switching between the bit output of the synchronization pattern SYMC supplied from the synchronization pattern generation unit 256 connected to the terminal 257a and the encrypted data bit sequence supplied from the XOR processing unit 252 connected to the terminal 257b, it generates a PPDU, which is an encoded signal consisting of a synchronization pattern and an encrypted data bit sequence, and outputs it to the LPWA transmission unit 223.
[0104] The LPWA transmission unit 223 generates a transmission frame waveform signal by modulating the PPDU in which the synchronization pattern SYNC and the encrypted data bit sequence of the PSDU are combined, and transmits it to the receiving device 202 by LPWA communication.
[0105] More specifically, the LPWA transmission unit 223 is composed of a modulation unit 271, a mixer 272, a local oscillator 273, a BPF (Band Pass Filter) 274, an amplifier 275, and an antenna 276.
[0106] The modulation unit 271 modulates the PPDU, which is an encoded signal, generates a transmission frame waveform signal, and outputs it to the mixer 272.
[0107] The mixer 272 synthesizes a local oscillation signal generated by the local oscillator 273 and a transmission frame waveform signal to generate a high-frequency signal, and outputs the high-frequency signal to the BPF 274.
[0108] The BPF 274 extracts a signal in a predetermined frequency band by filtering the high-frequency signal and outputs the signal to the amplifier 275.
[0109] The amplifier 275 amplifies the signal in the predetermined frequency band supplied from the BPF 274 at a predetermined magnification and transmits the signal to the receiving device 202 as a transmission frame waveform signal via the antenna 276.
[0110] Note that the transmitting device 201 repeatedly transmits different transmission frame waveform signals four times in different frequency bands by the above series of operations. Also, although an example in which different transmission frame waveform signals are repeatedly transmitted four times in different frequency bands will be described, the number of repetitions may be any number of times of two or more.
[0111] <Configuration example of receiving device> Next, with reference to the block diagram of FIG. 9, a configuration example of the receiving device 202 will be described.
[0112] The receiving device 202 includes an LPWA receiving unit 321, a decoding unit 322, and a MAC decoding unit 323. In the LPWA communication of the receiving device 202, the LPWA receiving unit 321 and the decoding unit 322 constitute a PHY (physical) layer, and the MAC decoding unit 323 constitutes a MAC layer higher than the PHY (physical) layer.
[0113] The LPWA receiving unit 321 receives, by LPWA communication, a transmission frame waveform signal composed of a PPDU transmitted from the transmitting device 201 by LPWA communication, and outputs a synchronization pattern SYNC included in the PPDU of the transmission frame waveform signal and an encrypted data bit string of the PSDU to the decoding unit 322.
[0114] More specifically, the LPWA receiver unit 321 includes an antenna 331, an amplifier 332, a mixer 333, a local oscillator 334, a BPF 335, a phase correction unit 336, and a synchronization detection unit 337.
[0115] The amplifier 332 receives and amplifies the transmission frame waveform signal transmitted as a high-frequency signal via the antenna 331 and outputs it to the mixer 333.
[0116] The mixer 333 converts it into an intermediate-frequency waveform signal based on the waveform signal in a predetermined frequency band oscillated from the local oscillator 334 and outputs it to the BPF 335.
[0117] The BPF 335 extracts the transmission frame waveform signal corresponding to the PPDU in a predetermined frequency band from the transmission frame waveform signal converted into the intermediate frequency and outputs it to the phase correction unit 336 and the synchronization detection unit 337.
[0118] The synchronization detection unit 337 detects the waveform signal of the synchronization pattern SYNC from the transmission frame waveform signal corresponding to the PPDU and outputs it to the phase correction unit 336.
[0119] The phase correction unit 336 corrects the phase of the transmission frame waveform signal corresponding to the PPDU supplied from the BPF 335 at the timing when the synchronization pattern SYNC is detected by the synchronization detection unit 337 and outputs it to the decoding unit 322.
[0120] The decoding unit 322 detects the position of the waveform signal corresponding to the PSDU based on the waveform signal of the synchronization pattern SYNC, generates a key stream in the same manner as the transmission device 201, restores the waveform signal corresponding to the encrypted data bit string, and decodes the data bit string of the PSDU based on the restored waveform signal and outputs it to the MAC decoding unit 323.
[0121] More specifically, the decoding unit 322 includes a switch 351, a polarity inversion unit 352, a demodulator 353, an integration unit 354, a decoder 355, a key stream generator 356, a memory unit 357, a GPS time information acquisition unit 358, and a synchronization signal waveform storage unit 359.
[0122] The switch 351 is controlled by the synchronization detection unit 337, separates the transmission frame waveform signal supplied from the LPWA reception unit 321, and outputs it to the synchronization signal waveform storage unit 359 and the polarity inversion unit 352.
[0123] More specifically, the switch 351 is connected to the terminal 351a at the timing corresponding to the synchronization signal waveform among the waveform signals corresponding to the PPDU, and outputs the waveform signal supplied from the LPWA reception unit 321 to the synchronization signal waveform storage unit 359. Then, at the timing other than the synchronization signal waveform, it is connected to the terminal 351b and outputs the transmission frame waveform signal corresponding to the encrypted PSDU among the PPDUs to the polarity inversion unit 352.
[0124] The polarity inversion unit 352 inversely polarizes the waveform signal corresponding to the PSDU based on the key stream supplied from the key stream generator 356 and outputs it to the demodulator 353. Note that the operation of the polarity inversion unit 352 will be described in detail later with reference to FIGS. 11 and 12.
[0125] Also, the key stream generator 356, the memory unit 357, and the GPS time information acquisition unit 358 are configured to have functions corresponding to the key stream generator 253, the memory unit 254, and the GPS time information acquisition unit 255 of the transmission device 201, so their description is omitted.
[0126] The demodulator 353 demodulates the waveform signal corresponding to the PSDU output from the polarity inversion unit 352, outputs it to the integration unit 354, and integrates and stores it.
[0127] The integration unit 354 integrates and stores the waveform signals corresponding to the same PSDU that has been stream-decoded, and outputs the integrated waveform signal of the PSDU to the decoder 355. Here, an example will be described in which the transmission frame signals generated from the same PSDU are repeated four times in different frequency bands. However, as long as it is two or more times, any other number of times may be used. Therefore, in this example, the addition result of the waveform signals of the PSDU integrated four times is output to the decoder 355.
[0128] The decoder 355 decodes the waveform signal obtained by adding the waveform signals corresponding to the PSDU output from the demodulated and polarity-inverted unit 352 that has been integrated and stored in the integration unit 354, and generates a PSDU consisting of a stream-decoded data bit sequence corresponding to the encrypted data bit sequence, and outputs it to the MAC decoder unit 323.
[0129] The MAC decoder unit 323 MAC-decodes and outputs the Payload corresponding to the sensor data transmitted from the transmission device 201 based on the stream-decoded data bit sequence of the PSDU.
[0130] More specifically, the MAC decoder unit 323 includes an MSDU decoder unit 371 and a CMAC processing unit 372.
[0131] The MSDU decoder unit 371 corrects errors using the error correction code ECC included in the PSDU, then extracts the MSDU and the CMAC tag, decodes the Payload from the MSDU, and outputs it to the CMAC processing unit 372.
[0132] The CMAC processing unit 372 generates a CMAC tag by CMAC processing based on the MSDU, and determines whether there is forgery by comparing it with the CMAC tag added to the MSDU.
[0133] The MSDU decoder unit 371 outputs the Payload, which is the decoding result, together with the information on whether there is forgery.
[0134] <Operation by the communication system of FIG. 7> Next, with reference to FIG. 10, the operation of the communication system 200 in FIG. 7 will be described. In FIG. 10, the left side of the figure shows the flow of signals and waveforms generated by the operation of the transmitting device 201, and the right side of the figure shows the flow of signals and waveforms generated by the operation of the receiving device 202.
[0135] First, starting from the upper left part of the figure, the operation in the transmitting device 201 will be described.
[0136] The MSDU generation unit 231 of the MAC encryption unit 221 in the transmitting device 201 encrypts the payload 401 which is sensor data to generate an MSDU 402, and outputs it to the CMAC processing unit 232.
[0137] The CMAC processing unit 232 performs CMAC processing on the MSDU 402 to generate a CMAC tag 403 for determining the presence or absence of tampering, and outputs it to the MSDU generation unit 231. The MSDU generation unit 231 adds the CMAC tag 403 to the generated MSDU 402 and outputs it to the encoding unit 222.
[0138] Note that the processing until the MSDU 402 is generated and the CMAC tag 403 is added is the processing of the MAC layer, and the subsequent processing is the processing of the PHY (physical) layer.
[0139] The error correction code addition unit 251 of the encoding unit 222 generates an error correction code ECC 412 from the information combining the MSDU 402 and the CMAC tag 403, and combines the error correction code ECC 412 with the information combining the MSDU 402 and the CMAC tag 403 to generate a PSDU 413.
[0140] Also, the keystream generator 253 generates a NONCE based on the GPS time information TIME supplied from the GPS time information acquisition unit 255 and the TXID stored in the storage unit 254, and generates a keystream 414 together with the secret key and outputs it to the XOR processing unit 252.
[0141] The XOR processing unit 252 performs an XOR operation on a bit-by-bit basis on the plaintext data bit sequence PSDU413 and the key stream 414 through stream encryption processing in the PHY (physical) layer, converts the PSDU413 into an encrypted data bit sequence, and outputs it to the switch 257.
[0142] The synchronization pattern generation unit 256 generates a synchronization pattern SYNC411 and outputs it to the switch 257.
[0143] The switch 257 generates a PPDU415 by adding the synchronization pattern SYNC411 to the encrypted data bit sequence of the PSDU413 and outputs it to the LPWA transmission unit 223. More specifically, the switch 257 connects the bit output of the synchronization pattern SYNC411 to the terminal 257a based on the transmission format and receives the input of the synchronization pattern SYNC411. Then, the switch 257 switches and connects to the terminal 257b, receives the input of the encrypted data bit sequence of the PSDU413 from the XOR processing unit 252, generates a PPDU415 including the synchronization pattern SYNC411, and outputs it to the LPWA transmission unit 223.
[0144] In the LPWA transmission unit 223, the modulation unit 271 modulates the PPDU415 to generate a transmission frame waveform 416. Then, the transmission frame waveform 416 is converted into a predetermined high-frequency signal by the mixer 272 and the local oscillator 273, further extracted with a predetermined frequency band by the BPF 274, amplified by the amplifier 275, and transmitted from the antenna 276 to the receiving device 202.
[0145] This concludes the description of the operation of the transmitting device 201. Next, starting from the lower right part of the figure, the operation of the receiving device 202 will be described.
[0146] In the LPWA receiving unit 321, a received frame waveform 421 corresponding to the transmission frame waveform 416 is received via the antenna 331, amplified to a predetermined gain by the amplifier 332, and then converted to an intermediate frequency based on a signal of a predetermined frequency supplied from the local oscillator 334 by the mixer 333 and output to the BFP 335.
[0147] The BPF 335 extracts a signal of a predetermined band from the waveform signal of the received frame waveform 421 that has been converted to an intermediate frequency signal and outputs it to the phase correction unit 336 and the synchronization detection unit 337.
[0148] The synchronization detection unit 337 detects a waveform serving as a synchronization pattern in the received frame waveform 421 and outputs the detection result to the phase correction unit 336.
[0149] The phase correction unit 336 corrects the phase of the received frame waveform 421 from the timing when the synchronization pattern detected by the synchronization detection unit 337 is detected, and outputs it to the decoding unit 322 as the PPDU waveform 422.
[0150] In the decoding unit 322, the switch 351 is connected to the terminal 351a and outputs the waveform signal of the PPDU waveform 422 input from the LPWA receiving unit 321 to the synchronization signal waveform storage unit 359. When the synchronization detection unit 337 detects a signal other than the synchronization signal waveform from the input PPDU waveform 422, it controls the switch 351 to connect it to the terminal 351b. By this operation, the switch 351 outputs the waveform at the PSDU position corresponding to the encrypted data bit string in the PPDU waveform 422 to the polarity inversion unit 352.
[0151] Also, the keystream generator 356 generates a NONCE based on the GPS time information TIME supplied from the GPS time information acquisition unit 358 and the TXID stored in the storage unit 357, and generates a keystream 414 (the same keystream as the keystream generated by the keystream generator 253 of the transmission device 201) together with the secret key and outputs it to the polarity inversion unit 352.
[0152] The polarity inversion unit 352 inverts the polarity of the waveform at the PSDU position corresponding to the encrypted data bit sequence in the PPDU waveform 422 based on the keystream, converts it into the waveform 423 of the PSDU, and outputs it to the demodulator 353.
[0153] Note that the operation of the polarity inversion unit 352 will be described in detail later with reference to FIGS. 11 and 12.
[0154] The demodulator 353 demodulates the waveform 423 of the PSDU corresponding to the data bit sequence obtained by stream decoding, integrates it in the integration unit 354, and stores it.
[0155] The decoder 355 corrects errors in the waveform 423 of the PSDU corresponding to the data bit sequence obtained by stream decoding and stored by integrating it a predetermined number of times in the integration unit 354, using the error correction code ECC, decodes the PSDU 424 (corresponding to the PSDU 413), and outputs it to the MAC decoder unit 323.
[0156] In the MAC decoder unit 323, the MSDU decoder unit 371 extracts the MSDU 431 and the CMAC tag 432 from the PSDU 424 and outputs them to the CMAC processing unit 372.
[0157] The CMAC processing unit 372 performs CMAC processing on the extracted MSDU 431 to generate a CMAC tag, compares it with the CMAC tag 432, determines whether there is forgery in the MSDU 431, and outputs the determination result to the MSDU decoder unit 371.
[0158] The MSDU decoder unit 371 decodes the MSDU 431 to generate the Payload 433 and outputs it together with information indicating whether there is forgery in the MSDU 431.
[0159] Through the LPWA communication between the above-described transmission device 201 and reception device 202, the transmission frame waveform and reception frame waveform, which are PPDU waveforms to be transmitted and received, are generated based on an encrypted data bit sequence using a keystream generated based on GPS time information. As a result, since the encrypted data bit sequence changes according to time changes, it becomes possible to defend against replay attacks.
[0160] Also, since it is possible to realize LPWA communication using CMAC, it is also possible to defend against forgery attacks.
[0161] Furthermore, since it is possible to realize communication adopting a stream encryption method using a keystream, it is possible to reduce the number of bits in which an error occurs when an error or the like occurs in the case of adopting a block encryption method, so that error tolerance can be improved.
[0162] As a result, it becomes possible to defend against replay attacks while defending against forgery attacks by CMAC, and it becomes possible to improve the confidentiality of communication. Also, it is possible to improve error tolerance more than in the case of using block encryption by communication using a stream encryption method.
[0163] <Operation of the polarity inversion section> Next, with reference to FIGS. 11 and 12, the operation of the polarity inversion section 352 will be described.
[0164] First, in explaining the operation of the polarity inversion section 352, with reference to FIG. 11, the operations of the keystream generator 91 and XOR processing section 92 in the communication system 1 of FIG. 1 will be described.
[0165] Generally, in stream encryption, as shown in the upper right part of FIG. 11, when a key stream (K) is output from the key stream generator 91 of the encoding unit 32 of the IoT terminal 11 and the plaintext data bit string (P) of the PSDU is input, the XOR processing unit 92 sets each bit value of the plaintext data bit string (P) of the PSDU as P and each bit value of the key stream (K) as K, and as shown in the upper left part of FIG. 11, converts it into the encrypted data bit string C of the PSDU.
[0166] That is, when (P, K) = (0, 0), (1, 1), the XOR processing unit 92 converts the bit C of the encrypted data bit string (C) of the PSDU to 0, and when (P, K) = (1, 0), (0, 1), the XOR processing unit 92 converts the bit C of the encrypted data bit string (C) to 1.
[0167] On the other hand, during decryption, as shown in the lower right part of FIG. 11, when a key stream (K) is output from the key stream generator 91 of the decoding unit 52 of the IoT gateway 12 and the encrypted data bit string (C) of the PSDU is input, the XOR processing unit 92 sets each bit value of the encrypted data bit string (C) of the PSDU as C and each bit value of the key stream (K) as K, and as shown in the lower left part of FIG. 11, converts it into the stream decrypted data bit string (P) of the PSDU.
[0168] That is, when (C, K) = (0, 0), (1, 1), the XOR processing unit 92 converts the bit P of the stream decrypted data bit string (P) of the PSDU to 0, and when (C, K) = (1, 0), (0, 1), the XOR processing unit 92 converts the bit P of the stream decrypted data bit string (P) to 1.
[0169] Also, in the operations of the key stream generator 253 and the XOR processing unit 252 of the transmission device 201 of the communication system 200 in FIG. 7, basically, as shown in the upper left stage and the upper middle stage of FIG. 12, the operations are the same as those of the key stream generator 91 and the XOR processing unit 92 of the IoT terminal 11.
[0170] That is, all of the above processes are performed on the plaintext data bit sequence of the digitized PSDU or the encrypted data bit sequence of the PSDU.
[0171] On the other hand, the process in the polarity inversion unit 352 of the receiving device 202 is a process performed on the PSDU waveform signal (the waveform signal at the position of the PSDU among the waveform signals of the PPUD) in the PPUD waveform signal (the waveform signal modulated by the PPUD) composed of analog signals.
[0172] That is, as shown in the lower center of FIG. 12, when a key stream (K) is output from the key stream generator 356 of the decoder 322 of the receiving device 202, if the bit K of the key stream (K) is 0, +1 is given as a coefficient, and if the bit K of the key stream (K) is 1, -1 is given as a coefficient.
[0173] When a waveform signal corresponding to the encrypted data bit sequence of the PSDU is input, the polarity inversion unit 352 functions as a multiplier, and as shown in the lower left of FIG. 12, by multiplying the coefficient by the polarity of each waveform of the waveform signal corresponding to the encrypted data bit sequence of the PSDU, the polarity is inverted, thereby converting it into a decoded waveform corresponding to the stream decoded data bit sequence of the PSDU.
[0174] That is, when (K, coefficient, polarity of the waveform of the waveform signal corresponding to the encrypted data bit sequence) = (0, +1, -), (1, -1, -), the polarity inversion unit 352 inverts the polarity of the encrypted waveform signal corresponding to the encrypted data bit sequence of the PSDU, and when (K, coefficient, polarity of the waveform of the waveform signal corresponding to the encrypted data bit sequence) = (1, -1, +), (0, +1, +), the polarity inversion unit 352 does not invert the polarity.
[0175] Note that the polarity of the waveform is + for a waveform convex upward and - for a waveform convex downward.
[0176] More specifically, for example, consider the case where the plaintext data bit sequence (P) of the PSDU consisting of "1111110" is input as shown in the upper right part of FIG. 12. In FIG. 12, "1111110" is represented as '1', '1', '1', '1', '1', '1', '0', but in the description of the specification, it is expressed only by adding "“" and "”" to the first and last characters.
[0177] Here, it is assumed that a key stream (K) consisting of "1010100" is generated in the key stream generator 253.
[0178] In this case, the XOR processing unit 252 performs an exclusive OR (XOR) operation to generate an encrypted data bit sequence (C) consisting of "0101010".
[0179] The encrypted data bit sequence (C) of the PSDU consisting of this "0101010" is modulated to generate a transmission frame waveform W1 and transmitted. In the transmission frame waveform W1, '0' in the encrypted data bit sequence C of the PSDU is a downwardly convex waveform, and '1' is an upwardly convex waveform for modulation.
[0180] That is, in the transmission frame waveform W1, '0' in the encrypted data bit sequence C of the PSDU at the first time t1 is a downwardly convex waveform, '1' in the encrypted data bit sequence C of the PSDU at time t2 is an upwardly convex waveform, and '0' in the encrypted data bit sequence C of the PSDU at time t3 is a downwardly convex waveform. Also, '1' in the encrypted data bit sequence C of the PSDU at time t4 is an upwardly convex waveform, and '0' in the encrypted data bit sequence C of the PSDU at time t5 is a downwardly convex waveform. Further, '1' in the encrypted data bit sequence C of the PSDU at time t6 is an upwardly convex waveform, and '0' in the encrypted data bit sequence C of the PSDU at time t7 is a downwardly convex waveform.
[0181] Next, as shown in the lower right part of FIG. 12, in the receiving device 202, this transmission frame waveform W1 is received as a reception frame waveform W11.
[0182] In this case, the key stream generator 356 generates a key stream K consisting of the same "1010100" as the key stream generator 253 of the transmission device 201.
[0183] Here, the polarity inversion unit 352 assigns coefficients to each bit of the key stream (K) consisting of "1010100" as shown in the lower left part of FIG. 12, thereby generating -1, +1, -1, +1, -1, +1, +1 as a coefficient data bit string.
[0184] Then, the polarity inversion unit 352 generates the waveform at the position of the PSDU as a decoded signal waveform W12 from the coefficient data bit string and the reception frame waveform W11.
[0185] That is, at time t1, since the bit K of the key stream (K) is '1', the polarity inversion unit 352 sets the coefficient to -1. Since the waveform is concave downward at time t1 and the polarity is "-", the polarity is set to "+", the waveform is made convex upward, and the polarity is inverted. Note that in the lower right part of FIG. 12, the waveform before the polarity is inverted is shown as a dotted line waveform, and it is shown that at time t1, it becomes a convex upward waveform shown by a solid line due to the inversion.
[0186] Also, at time t2, since the bit K of the key stream (K) is '0', the polarity inversion unit 352 sets the coefficient to +1. Since the waveform is convex upward at time t2 and the polarity is "+", the polarity is not inverted and remains "+",
[0187] Furthermore, at time t3, since the bit K of the key stream (K) is '1', the polarity inversion unit 352 sets the coefficient to -1. Since the waveform is concave downward at time t3 and the polarity becomes "-", the polarity is inverted, the polarity is set to "+", and the waveform is made convex upward.
[0188] Also, at time t4, since the bit K of the key stream (K) is '0', the coefficient is set to +1. Since the waveform is convex upward at time t4 and the polarity is "+", the polarity remains "+", without inverting.
[0189] Furthermore, at time t5, since the bit K of the key stream (K) is '1', the coefficient is set to -1. Since the waveform is convex downward at time t5 and the polarity is "-", the polarity is inverted to "+", and the waveform is made convex upward.
[0190] Also, at time t6, since the bit K of the key stream (K) is '0', the coefficient is set to +1. Since the waveform is convex upward at time t6 and the polarity is "+", the polarity remains "+", without inverting.
[0191] Furthermore, at time t7, since the bit K of the key stream (K) is '0', the coefficient is set to +1. Since the waveform is convex downward at time t7 and the polarity is "-", the polarity remains "-", without inverting.
[0192] Through the above processing, the decoded signal waveform W12 is decoded from the received frame waveform W11 corresponding to the encrypted data bit sequence C of the PSDU.
[0193] After that, based on the waveform of the decoded signal waveform W12, decoding processing is performed to obtain the stream decoded data bit sequence. That is, '111111' is decoded from the convex upward waveforms at times t1 to t6 in the decoded signal waveform W12, '0' is decoded from the convex downward waveform at time t7, and the original PSDU '1111110' is decoded.
[0194] That is, through the above processing, in the transmitting device 201, different keystreams are generated according to the GPS time information, and the PSDU is encrypted by the stream encryption method. In the receiving device 202, the encrypted PSDU is decrypted by generating and encrypting the keystream in the same way, so that it becomes possible to transmit the Payload by LPWA communication.
[0195] In the receiving device 202, in the PHY (physical) layer, the waveform signal of the encrypted PSDU composed of the analog signal can be decrypted by different keystreams according to the GPS time information.
[0196] Through the above processing, it becomes possible to realize stream encryption using the polarity inversion of the waveform polarity in the PHY (physical) layer, and it becomes possible to defend against replay attacks in a low-cost and communication-friendly manner. Also, by combining with CMAC in the MAC layer above the PHY (physical layer), it becomes possible to realize multi-layer defense against replay attacks and forgery attacks.
[0197] <Specific communication method by the communication system> Next, with reference to FIG. 13, a communication method by LPWA communication using a communication system 200 including a transmitting device 201 and a receiving device 202 will be described.
[0198] In the present disclosure, the transmitting device 201 transmits the same PSDU by different transmission frame waveforms at different frequencies and repeatedly transmits it to the receiving device 202. Such transmission of the PSDU is called burst transmission.
[0199] That is, as shown above the dotted line in FIG. 13, at GPS time #1, the transmitting device 201 transmits a transmission frame waveform 416-1 obtained by encrypting the PSDU with a keystream based on GPS time #1 and TXID to the transmitting device 201 at frequency f2.
[0200] Also, at GPS time #2, the transmitting device 201 transmits the transmitted frame waveform 416-2 obtained by encrypting the PSDU with the key stream based on GPS time #2 and TXID to the transmitting device 201 at frequency f1.
[0201] Furthermore, at GPS time #3, the transmitting device 201 transmits the transmitted frame waveform 416-3 obtained by encrypting the PSDU with the key stream based on GPS time #3 and TXID to the transmitting device 201 at frequency f4.
[0202] Also, at GPS time #4, the transmitting device 201 transmits the transmitted frame waveform 416-4 obtained by encrypting the PSDU with the key stream based on GPS time #4 and TXID to the transmitting device 201 at frequency f3.
[0203] Then, in the receiving device 202, as shown below the dotted line in FIG. 13, at GPS time #1, the receiving device 202 performs the above-described polarity inversion process on the signal waveform at the PSDU position from the transmitted frame waveform 416-1 transmitted at frequency f2 with the key stream based on GPS time #1 and TXID.
[0204] Also, at GPS time #2, the receiving device 202 performs the above-described polarity inversion process on the signal waveform at the PSDU position from the transmitted frame waveform 416-2 transmitted at frequency f1 with the key stream based on GPS time #2 and TXID.
[0205] Furthermore, at GPS time #3, the receiving device 202 performs the above-described polarity inversion process on the signal waveform at the PSDU position from the transmitted frame waveform 416-3 transmitted at frequency f4 with the key stream based on GPS time #3 and TXID.
[0206] Also, at GPS time #4, the receiving device 202 performs the above-described polarity inversion process on the signal waveform at the PSDU position from the transmitted frame waveform 416-4 transmitted at frequency f3 with the key stream based on GPS time #4 and TXID.
[0207] Then, the receiving device 202 decodes the transmission frame waveform 416-11 obtained by adding (integrating) the signal waveforms of the 4 frames of PSDU demodulated from the transmission frame waveforms 416-1 to 416-4.
[0208] As described above, at different transmission timings, different keystreams are generated by different GPS time information. Therefore, each frame waveform transmitted by stream encryption in the transmission process has a different shape each time, while by stream (cipher) decoding in the reception process, each frame waveform can be made into the same shape. Furthermore, on the receiving side, waveform synthesis for adding (integrating) waveforms becomes possible, and not only the resistance to replay attacks but also the demodulation / decoding performance can be improved.
[0209] Also, since a CMAC tag is given to the signal waveform at the PSDU position repeatedly transmitted, it is also possible to defend against forgery attacks.
[0210] As a result, it is possible to improve the demodulation / decoding performance while defending against replay attacks and forgery attacks simultaneously and multi-layerly.
[0211] <Transmission Process> Next, with reference to the flowchart of FIG. 14, as an example, the transmission process by the transmission device 201 that transmits 4 frames per burst at intervals of 5 seconds will be described.
[0212] In step S11, the transmission device 201 returns from its sleep state.
[0213] In step S12, the transmission device 201 initializes the transmission count counter Cs to 1.
[0214] In step S13, the keystream generator 253 reads the TXID as the ID for identifying the transmission device 201 stored in the storage unit 254.
[0215] In step S14, the keystream generator 253 acquires the GPS time information TIME supplied from the GPS time information acquisition unit 255.
[0216] In step S15, the keystream generator 253 truncates the acquired GPS time information TIME in units of 5 seconds. That is, in step S13, for example, if the supplied GPS time information TIME is 00:15:21 (00 hours 15 minutes 21 seconds), the GPS time information TIME becomes 00:15:20 (00 hours 15 minutes 20 seconds) after being truncated in units of 5 seconds.
[0217] In step S16, the keystream generator 253 generates the initial value NONCE of the keystream based on the TXID and the GPS time information TIME.
[0218] In step S17, the keystream generator 253 generates a keystream based on the initial value NONCE and the secret key, and outputs it to the XOR processing unit 252.
[0219] In step S18, an encoding process is performed on the Payload consisting of sensor data. More specifically, the MSDU generation unit 231 performs an encryption process on the Payload to generate an MSDU, and outputs it to the CMAC processing unit 232. The CMAC processing unit 232 performs a CMAC process on the MSDU to generate a CMAC tag, and outputs it to the MSDU generation unit 231. The MSDU generation unit 231 combines the MSDU and the CMAC tag and outputs them to the encoding unit 222. The error correction code addition unit 251 of the encoding unit 222 obtains an error correction code ECC from the MSDU and the CMAC tag, adds it, generates a PSDU consisting of a plaintext data bit string, and outputs it to the XOR processing unit 252.
[0220] In step S19, the XOR processing unit 252 performs stream encryption on the PSDU consisting of the plaintext data bit sequence by performing an exclusive OR (XOR) on each bit value of the keystream on a bit-by-bit basis, converts it into a PSDU consisting of an encrypted data bit sequence, and outputs it to the switch 257.
[0221] In step S20, the synchronization pattern generation unit 256 generates a synchronization pattern and outputs it to the terminal 257a of the switch 257. Also, the XOR processing unit 252 outputs the encrypted data bit sequence to be output to the terminal 257b. The switch 257 switches and outputs the input based on the transmission format, generates a PPDU including the synchronization pattern and the encrypted data bit sequence, and outputs it to the LPWA transmission unit 223.
[0222] In step S21, the LPWA transmission unit 223 modulates the PPDU and transmits it to the receiving device 202 in a frequency band corresponding to the counter Cs indicating the number of transmissions.
[0223] In step S22, the transmission device 201 determines whether the counter Cs indicating the number of transmissions is 4. If it is not 4, the process proceeds to step S23.
[0224] In step S23, the transmission device 201 increments the counter Cs indicating the number of transmissions by 1, and the process returns to step S14.
[0225] That is, until the counter Cs becomes 4, the processes of steps S14 to S23 are repeated, and a transmission frame waveform composed of a PPDU including a PSDU that has been stream-encrypted using the keystream based on the GPS time information and TXID corresponding to each transmission timing at different frequencies according to the counter Cs is transmitted to the receiving device 202.
[0226] Then, in step S22, it is considered that the counter Cs indicating the number of transmissions is 4, and when the transmission frame waveforms for 4 frames are transmitted, the process ends.
[0227] <Reception processing> Next, with reference to the flowchart of FIG. 15, the reception processing by the receiving device 202 that transmits 4 frames per burst at intervals of 5 seconds as an example will be described in the same manner.
[0228] In step S31, the key stream generator 356 identifies the TXID of the transmitting device 201 that is the target of reception processing.
[0229] In step S32, the receiving device 202 initializes the counter Cr of the number of receptions to 1.
[0230] In step S33, the key stream generator 356 acquires the GPS time information TIME supplied from the GPS time information acquisition unit 358.
[0231] In step S34, the key stream generator 356 truncates the acquired GPS time information TIME in units of 5 seconds.
[0232] In step S35, the key stream generator 356 generates the initial value NONCE of the key stream based on the TXID and the GPS time information TIME.
[0233] In step S36, the key stream generator 356 generates a key stream based on the initial value NONCE and the secret key, and outputs it to the polarity inversion unit 352.
[0234] In step S37, the LPWA reception unit 321 receives the transmitted frame waveform transmitted at a predetermined frequency as a received frame waveform, performs synchronization detection, and outputs it to the decoding unit 322. The decoding unit 322 acquires the waveform at the PSDU position.
[0235] More specifically, the amplifier 332 of the decoding unit 322 receives and amplifies the transmission signal transmitted as a high-frequency signal via the antenna 331, and outputs it to the mixer 333.
[0236] The mixer 333 converts the waveform signal in a predetermined frequency band oscillated from the local oscillator 334 into a waveform signal of an intermediate frequency and outputs it to the BPF 335.
[0237] The BPF 335 extracts the waveform signal in a predetermined frequency band from the waveform signal converted to the intermediate frequency and outputs it to the phase correction unit 336 and the synchronous detection unit 337.
[0238] The phase correction unit 336 corrects the phase of the waveform signal supplied from the BPF 335 at the timing when the synchronous pattern SYNC is detected by the synchronous detection unit 337 and outputs it to the decoding unit 322.
[0239] The switch 351 of the decoding unit 322 receives the output of the phase correction unit 336 and separates the synchronous signal waveform and the signal waveform corresponding to the PSDU encrypted by the timing signal from the synchronous detection unit 337. A synchronous signal waveform storage unit 359 is connected to the tip of the terminal 351a of the switch 351 to output the synchronous signal waveform, and a polarity inversion unit 352 is connected to the tip of the terminal 351b to output the waveform signal at the PSDU position corresponding to the encrypted data bit string.
[0240] In step S38, as described with reference to FIG. 12, the polarity inversion unit 352 performs stream decoding in the PHY (physical) layer by inverting the polarity of the waveform signal at the PSDU position using the key stream generated by the key stream generator 356, converts it into the waveform of the PSDU, and outputs it to the demodulator 353.
[0241] In step S39, the demodulator 353 integrates and accumulates the waveform of the PSDU corresponding to the stream decoded data bit string with respect to the waveform accumulated in the integration unit 354.
[0242] In step S40, the receiving device 202 determines whether or not the counter Cr indicating the number of receptions is 4. In step S38, if the counter Cr is not 4, the process proceeds to step S41.
[0243] In step S41, a counter Cr indicating the number of receptions is incremented by 1, and the process returns to step S33.
[0244] That is, the processes of steps S33 to S41 are repeated until four frames of the transmission frame waveforms repeatedly transmitted at different frequencies are received.
[0245] Then, in step S40, when four frames of the transmission frame waveforms are received and, in the integration unit 354, the waveforms of the PSDUs corresponding to the four-stream decoded data bit strings are added and accumulated, and it is determined that the counter Cr is 4, the process proceeds to step S42.
[0246] In step S42, the decoder 355 corrects errors using the error correction code ECC based on the waveform obtained by integrating the waveforms of the four PSDUs accumulated in the integration unit 354, then decodes the data bit string of the PSDU, and outputs it to the MAC decoder unit 323.
[0247] Then, the MSDU decoder unit 371 of the MAC decoder unit 323 extracts the MSDU and the CMAC tag included in the PSDU, outputs them to the CMAC processing unit 372, and decodes the Payload from the MSDU.
[0248] The CMAC processing unit 372 generates a CMAC tag by CMAC processing based on the MSDU, determines whether there is forgery by comparing it with the CMAC tag added to the MSDU, and outputs the determination result to the MSDU decoder unit 371.
[0249] The MSDU decoder unit 371 outputs the Payload, which is the decoding result, together with the information on whether there is forgery.
[0250] Through the above series of transmission processes and reception processes, a transmission frame waveform composed of a PPDU including a PSDU that has been stream-encrypted using a key stream based on GPS time information and a TXID corresponding to each transmission timing at different frequencies is transmitted to the receiving device 202.
[0251] Through this process, the transmission frame waveform is such that a PPDU containing a PSDU that is stream-encrypted using a keystream generated based on different GPS time information and TXID corresponding to each transmission timing is transmitted as a different transmission frame waveform. Therefore, it becomes possible to defend against replay attacks. Also, since CMAC is included in the PSDU, it becomes possible to defend against forgery attacks.
[0252] As a result, it becomes possible to realize multi-layer defense against replay attacks in the PHY (physical) layer and forgery attacks in the MAC layer.
[0253] Also, since the same PSDU is repeatedly transmitted, at the receiving device 202, it is possible to demodulate using the integrated result of the repeated transmissions, so it becomes possible to improve the demodulation / decoding performance.
[0254] Note that in the above, the TXID and GPS time information were used to generate the keystream for each transmission frame waveform, but as additional information, the same numerical values predetermined by the transmitting device 201 and the receiving device 202 may be included.
[0255] That is, by increasing the amount of information used as the nonce, it becomes possible to improve the resistance to replay attacks.
[0256] Also, in the above, GPS time information was used for each transmission frame waveform, but for the first transmission frame, a keystream generated based on the GPS time information is used, while for the keystream of subsequent transmission frame waveforms, it may be generated using an initial value obtained by a conversion process that uses the count value of the number of transmission frame waveforms for the GPS time information of the first transmission frame.
[0257] That is, for example, in the first transmission frame, a key stream is generated using the secret key, TXID, and GPS time information. In the next transmission frame, the value of a counter corresponding to the elapsed time from the timing when the first key stream was generated is added to the GPS time information used when generating the first key stream to generate a key stream, and the key stream may be generated in the same way for subsequent transmission frames.
[0258] Furthermore, in the above, an example has been described in which the GPS time information truncated in units of 5 seconds is used as the NONCE. However, since it is only necessary to be able to distinguish the transmission frame waveforms, for example, when the transmission interval of the transmission frame waveforms is determined in units of milliseconds, the GPS time information in units of milliseconds corresponding to the transmission interval may be used as the NONCE.
[0259] Also, in the above, GPS time information has been used as the NONCE for generating the key stream together with the TXID. However, any other information may be used as long as it is information that changes according to the timing of generating the key stream. For example, time information such as UTC (Universal Time Coordinated), GMT (Greenwich Mean Time), or JST (Japan Standard Time) may be used, or the value of a counter counted at a predetermined time interval (which may be an equal time interval or a non-equal time interval) may be used.
[0260] Furthermore, in the above, an example has been described in which the transmission frame waveforms for four frames are set as one set for transmitting the same PSDU. However, as long as a plurality of transmission frame waveforms for the same PSDU are transmitted as one set, the number of frames of the transmission frame waveforms for one set may be two frames or more, or any other number of frames.
[0261] In the above description, an example has been described in which, when generating a keystream, a NONCE (initial value) is changed and combined with a secret key to generate a keystream. However, since parameters required for generating the keystream may be changed, each time a keystream is generated, the secret key may be changed and the NONCE (initial value) may be set to a fixed value.
[0262] <<3. Application Example>> In the above, an example has been described in which, in the receiving device 202, a keystream generator used for a so-called stream cipher is used based on the GPS time information and the TXID to generate a keystream.
[0263] However, a keystream generator can also be configured by combining a block cipher with a specific cipher usage mode, and this can also be used.
[0264] For example, as shown in Case C1 of FIG. 16, each time a keystream is generated, a block cipher that increments the NONCE by a predetermined value may be used.
[0265] That is, the block cipher 401 generates, for example, at the first timing, a keystream K1 of a fixed number of bits using a NONCE consisting of c59bcf35…00000000 and a secret key Key. The XOR processing unit 402 multiplies the plaintext data bit string by XOR bit by bit using the keystream K1 to convert it into an encrypted data bit string.
[0266] At the next timing, the block cipher 401 generates, for example, a NONCE consisting of c59bcf35…00000001 obtained by incrementing the immediately preceding NONCE by 1, and generates a keystream K2 by using it together with the secret key Key. The XOR processing unit 402 multiplies the plaintext data bit string by XOR bit by bit using the keystream K2 to convert it into an encrypted data bit string.
[0267] Furthermore, at the next timing, the block cipher 401 generates a NONCE consisting of, for example, c59bcf35…00000002 with the immediately previous NONCE incremented by 1, and generates a key stream K3 by using it together with the secret key Key. The XOR processing unit 402 performs XOR bit by bit on the plaintext data bit string using the key stream K3 to convert it into an encrypted data bit string.
[0268] In this way, each time the key stream is generated, the NONCE changes, and thus the key stream also changes, making it possible to defend against replay attacks.
[0269] Also, as shown in case C2 of FIG. 16, the initial value used as the NONCE may be the key stream generated immediately before.
[0270] That is, the block cipher 411 first generates a key stream K11 using the initial value and the secret key Key, and the XOR processing unit 412 performs XOR bit by bit on the plaintext data bit string using the key stream K11 to convert it into an encrypted data bit string.
[0271] At the next timing, the block cipher 411 generates a key stream K12 by using, for example, the immediately previous key stream K11 as the initial value and using it together with the secret key Key, and the XOR processing unit 412 performs XOR bit by bit on the plaintext data bit string using the key stream K12 to convert it into an encrypted data bit string.
[0272] Furthermore, at the next timing, the block cipher 411 generates a key stream K13 by using, for example, the immediately previous key stream K12 as the initial value and using it together with the secret key Key, and the XOR processing unit 402 performs XOR bit by bit on the plaintext data bit string using the key stream K13 to convert it into an encrypted data bit string.
[0273] In this way, every time a key stream is generated, the initialization value changes, which causes the key stream to change as well. Therefore, it becomes possible to defend against replay attacks.
[0274] Furthermore, as shown in Case C3 of FIG. 16, the initialization value serving as the NONCE may be an encrypted data bit string generated immediately before.
[0275] That is, for example, the block cipher 411 first generates a key stream K21 based on the initialization value and the secret key Key. Then, the XOR processing unit 412 performs XOR bit by bit on the plaintext data bit string using the key stream to convert it into an encrypted data bit string E1.
[0276] At the next timing, for example, the block cipher 411 uses the immediately previous encrypted data bit string E1 as the initialization value and, together with the secret key Key, generates a key stream K22. Then, the XOR processing unit 412 performs XOR bit by bit on the plaintext data bit string using the key stream K22 to convert it into an encrypted data bit string E2.
[0277] Furthermore, at the next timing, for example, the block cipher 411 uses the immediately previous encrypted data bit string E2 as the initialization value and, together with the secret key Key, generates a key stream K23. Then, the XOR processing unit 402 performs XOR bit by bit on the plaintext data bit string using the key stream K23 to convert it into an encrypted data bit string E3.
[0278] In this way, every time a key stream is generated, the initialization value changes, which causes the key stream to change as well. Therefore, it becomes possible to defend against replay attacks.
[0279] As described above, in the communication system of the present disclosure, since the stream cipher in the PHY (physical) layer is used, in the receiving apparatus, by inverting the polarity of the transmission frame waveform, it becomes possible to decode the waveform of the PSDU, and each transmission frame waveform can be easily deformed into the same shape, enabling waveform synthesis.
[0280] Also, by changing the key stream for each frame transmission based on time, the transmission frame waveforms are different each time, making it possible to improve the resistance to replay attacks, and also making it possible to improve the demodulation / decryption performance by the waveform synthesis method even when the encrypted transmission waveforms are different.
[0281] Furthermore, by stream encryption, an arbitrary-length plaintext data bit string can be converted into an encrypted data bit string.
[0282] <<Example of Execution by Software>> Incidentally, the above-described series of processes can be executed by hardware, but can also be executed by software. When the series of processes are executed by software, the program constituting the software is installed from a recording medium into a computer incorporating a dedicated hardware or, for example, a general-purpose computer capable of executing various functions by installing various programs.
[0283] FIG. 17 shows a configuration example of a general-purpose computer. This personal computer incorporates a CPU (Central Processing Unit) 1001. An input / output interface 1005 is connected to the CPU 1001 via a bus 1004. A ROM (Read Only Memory) 1002 and a RAM (Random Access Memory) 1003 are connected to the bus 1004.
[0284] The input / output interface 1005 is connected to an input unit 1006 composed of input devices such as a keyboard and a mouse for the user to input operation commands, an output unit 1007 for outputting the processing operation screen and the image of the processing result to a display device, a storage unit 1008 composed of a hard disk drive for storing programs and various data, etc., a communication unit 1009 composed of a LAN (Local Area Network) adapter, etc., which executes communication processing via a network represented by the Internet. Also, a drive 1010 for reading and writing data to / from a removable storage medium 1011 such as a magnetic disk (including a flexible disk), an optical disk (including a CD-ROM (Compact Disc-Read Only Memory), a DVD (Digital Versatile Disc)), a magneto-optical disk (including an MD (Mini Disc)), or a semiconductor memory is connected.
[0285] The CPU 1001 reads a program stored in the ROM 1002 or a removable storage medium 1011 such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, installs it in the storage unit 1008, and executes various processes according to the program loaded from the storage unit 1008 to the RAM 1003. The RAM 1003 also appropriately stores data and the like necessary for the CPU 1001 to execute various processes.
[0286] In the computer configured as described above, the CPU 1001 loads and executes a program stored in the storage unit 1008 via the input / output interface 1005 and the bus 1004 into the RAM 1003, thereby performing the above-described series of processes.
[0287] The program executed by the computer (CPU 1001) can be recorded and provided, for example, on a removable storage medium 1011 as a package medium or the like. Also, the program can be provided via a wired or wireless transmission medium such as a local area network, the Internet, or digital satellite broadcasting.
[0288] In a computer, a program can be installed in the storage unit 1008 via the input / output interface 1005 by attaching the removable storage medium 1011 to the drive 1010. Also, the program can be received by the communication unit 1009 via a wired or wireless transmission medium and installed in the storage unit 1008. Additionally, the program can be pre-installed in the ROM 1002 or the storage unit 1008.
[0289] Note that the program executed by the computer may be a program whose processing is performed in time series according to the order described in this specification, or a program whose processing is performed in parallel or at a necessary timing such as when a call is made.
[0290] In addition, the CPU 1001 in FIG. 17 realizes the functions of the encoding unit 222 in FIG. 8 and the decoding unit 322 in FIG. 9.
[0291] Also, in this specification, a system means a collection of a plurality of components (devices, modules (parts), etc.), and it does not matter whether all the components are in the same housing. Therefore, a plurality of devices housed in separate housings and connected via a network, and a single device in which a plurality of modules are housed in one housing are both systems.
[0292] Note that the embodiments of the present disclosure are not limited to the above-described embodiments, and various changes can be made without departing from the gist of the present disclosure.
[0293] For example, the present disclosure can take a configuration of cloud computing in which one function is shared and jointly processed by a plurality of devices via a network.
[0294] Also, each step described in the above flowchart can be executed by one device or can be shared and executed by a plurality of devices.
[0295] Furthermore, when a single step includes a plurality of processes, the plurality of processes included in that single step can be executed by a single device or can be executed in cooperation by a plurality of devices.
[0296] Note that the present disclosure can also adopt the following configurations.
[0297] <1> A key stream generation unit that generates a key stream using different information as an initial value according to timing, An encryption unit that converts transmission data into encrypted data using the key stream, A transmission unit that transmits a waveform signal obtained by modulating the encrypted data and including a transmission device. <2> The different information according to the timing is time information The transmission device according to <1>. <3> The time information includes GPS (Global Positioning System) time information, UTC (Universal Time Coordinated) time information, GMT (Greenwich Mean Time), JST (Japan Standard Time) time information, and a value of a counter counted at a predetermined equal time interval or non-equal time interval. The transmission device according to <2>. <4> The key stream generation unit generates the key stream based on information obtained by truncating the time information in predetermined time units. The transmission device according to <2>. <5> The key stream generation unit uses, in addition to the time information, an ID unique to the transmission device as the initial value, and further generates the key stream using a secret key. The transmission device according to <2>. <6> The different information according to the timing is the key stream generated immediately before or the encrypted data generated immediately before. The transmission device according to <1>. <7> An MSDU generation unit that generates an MSDU (MAC (Media Access Control) Service Data Unit) from the Payload, further includes a CMAC processing unit that generates a CMAC tag by CMAC (Cihper-based MAC: Cipher-based Message Authentication Code) processing from the MSDU, the transmission data includes the MSDU and the CMAC tag, and an error correction code ECC (Error Correcting Code or Error Check and Correct) generated from the MSDU and the CMAC tag <1> The transmission device according to any one of <6>. <8> The transmission unit repeatedly transmits a waveform signal obtained by modulating encrypted data obtained by encrypting the same transmission data at different timings. <1> The transmission device according to any one of <7>. <9> A key stream generation process that generates a key stream using different information as an initial value according to timing, an encryption process that converts transmission data into encrypted data using the key stream, and a transmission process that transmits a waveform signal obtained by modulating the encrypted data. A transmission method including. <10> A receiving unit that receives a waveform signal obtained by modulating encrypted data obtained by encrypting transmission data using a key stream generated using different information as an initial value according to timing transmitted from a transmission device, a key stream generation unit that generates a key stream using different information as an initial value according to the timing, a polarity inversion unit that inverts the polarity of the waveform of the waveform signal using the key stream, and a decoding unit that decodes the transmission data based on the waveform signal whose polarity has been inverted. A receiving device including. <11> The different information according to the timing is time information. <10> The receiving device according to. <12>The time information includes GPS (Global Positioning System) time information, UTC (Universal Time Coordinated) time information, GMT (Greenwich Mean Time), JST (Japan Standard Time) time information, and the value of a counter counted at a predetermined equal time interval or non-equal time interval. <11>The receiving device according to <11>. <13>The key stream generation unit generates the key stream based on the information obtained by truncating the time information in predetermined time units. <11>The receiving device according to <11>. <14>In addition to the time information, the key stream generation unit uses the ID unique to the transmitting device as the initial value and further generates the key stream using a secret key. <11>The receiving device according to <11>. <15>The information that varies according to the timing is the key stream generated immediately before or the encrypted data generated immediately before. <10>The receiving device according to <10>. <16>The transmission data includes an MSDU (MAC (Media Access Control) Service Data Unit) generated based on the Payload, a CMAC tag generated by CMAC (Cihper-based MAC: Cipher-based Message Authentication Code) processing from the MSDU, and an error correction code ECC (Error Correcting Code or Error Check and Correct) obtained from the MSDU and the CMAC tag. From the transmission data, an MSDU decoding unit that performs error correction using the error correction code ECC to decode the MSDU and the CMAC tag. It further includes a CMAC processing unit that generates a CMAC tag by CMAC (Cihper-based MAC: Cipher-based Message Authentication Code) processing from the MSDU, compares it with the CMAC tag decoded by the MSDU decoding unit, and determines whether the transmission data has been tampered with. The receiving device according to any one of <10> to <15>. <17>The receiving unit receives, from the transmitting device, at different timings, a waveform signal obtained by modulating encrypted data obtained by encrypting the same transmission data repeatedly transmitted. The receiving device according to any one of <10> to <16>. <18>The receiving device further includes an integration storage unit that integrates and stores a waveform obtained by inverting a waveform of a waveform signal obtained by modulating encrypted data obtained by encrypting the same transmission data repeatedly transmitted from the transmitting device with a key stream at the polarity inversion unit. The decoding unit decodes the transmission data based on the waveform signal with the inverted polarity integrated and stored in the integration storage unit. The receiving device according to <17>. <19>The polarity inversion unit inverts the polarity of the waveform of the waveform signal by multiplying the polarity of the waveform of the waveform signal by a coefficient set by the key stream. The receiving device according to any one of <10> to <18>. <20>A receiving process of receiving a waveform signal obtained by modulating encrypted data obtained by encrypting transmission data with a key stream generated with different information as an initial value according to timing transmitted from a transmitting device, A key stream generation process of generating a key stream with different information as an initial value according to the timing, A polarity inversion process of inverting the polarity of the waveform of the waveform signal with the key stream, And a decoding process of decoding the transmission data based on the waveform signal with the inverted polarity. A receiving method including the above.
Explanation of symbols
[0298] 200 Communication System, 201 Transmitter, 202 Receiver, 203 Cloud Server, 211, 211-1, 211-2 Application Program, 221 MAC Encryption Unit, 222 Encoding Unit, 223 LPWA Transmitting Unit, 231 MSDU Generation Unit, 232 CMAC Processing Unit, 251 Error Correction Code Addition Unit, 252 XOR Processing Unit, 253 Keystream Generator, 254 Memory Unit, 255 GPS Time Information Acquisition Unit, 256 Synchronization Pattern Generation Unit, 257 Switch, 257a, 257b Terminals, 271 Modulation Unit, 272 Mixer, 273 Local Oscillator, 274 BPF, 275 Amplifier, 276 Antenna, 321 LPWA Receiving Unit, 322 Decoding Unit, 323 MAC Decoding Unit, 331 Antenna, 332 Amplifier, 333 Mixer, 334 Local Oscillator, 335 BPF, 336 Phase Correction Unit, 337 Synchronization Detection Unit, 351 Switch, 351a, 351b Terminals, 352 Polarity Inversion Unit, 353 Demodulator, 354 Integration Unit, 355 Composite Machine, 356 Keystream Generator, 357 Memory Unit, 358 GPS Time Information Acquisition Unit, 359 Synchronization Signal Waveform Storage Unit, 371 MSDU Generation Unit, 372 CMAC Processing Unit
Claims
1. A key stream generation unit that generates a key stream using at least different information as an initial value according to timing, an encryption unit that converts transmission data into encrypted data using the key stream, a transmission unit that transmits, in different frequency bands and at the different timings, a predetermined number of different waveform signals obtained by modulating a predetermined number of different encrypted data obtained by encrypting the transmission data with a predetermined number of different key streams generated at a predetermined number of different timings A transmission device comprising:
2. The information that varies according to the timing is time information The transmission device according to claim 1.
3. The time information includes GPS (Global Positioning System) time information, UTC (Universal time coordinated) time information, GMT (Greenwich Mean Time), JST (Japan Standard Time) time information, and a value of a counter counted at predetermined equal time intervals or unequal time intervals The transmission device according to claim 2.
4. The time information is truncated in predetermined time units The transmission device according to claim 2.
5. The key stream generation unit uses, in addition to the time information, an ID unique to the transmission device as the initial value, and further generates the key stream using a secret key The transmission device according to claim 2.
6. The information that varies according to the timing is the key stream generated immediately before, or the encrypted data generated immediately before The transmission device according to claim 1.
7. an MSDU generation unit that generates an MSDU (MAC (Media Access Control) Service Data Unit) from a Payload, further comprising a CMAC processing unit that generates a CMAC tag by CMAC (Cihper-based MAC) processing from the MSDU, The transmission data includes the MSDU and the CMAC tag, and an error correction code ECC (Error Correcting Code or Error Check and Correct) generated from the MSDU and the CMAC tag The transmission device according to claim 1.
8. The transmitting unit repeatedly transmits waveform signals obtained by modulating encrypted data obtained by encrypting the same transmission data at different timings. The transmission device according to claim 1.
9. A key stream generation process for generating a key stream using at least different information as an initial value according to timing, an encryption process for converting transmission data into encrypted data using the key stream, transmission processing for transmitting, in different frequency bands and at the different timings, a predetermined number of different waveform signals obtained by modulating a predetermined number of different encrypted data obtained by encrypting the transmission data with a predetermined number of different key streams generated at a predetermined number of different timings A transmission method including the above.
10. A receiving unit that receives, in different frequency bands and at different timings, at least a key stream generated using different information as an initial value according to timing, and a predetermined number of different waveform signals obtained by modulating a predetermined number of different encrypted data obtained by encrypting transmission data with a predetermined number of different key streams generated at a predetermined number of different timings, from a transmission device, a key stream generation unit that generates a key stream using different information as an initial value according to the timing, a polarity inversion unit that inverts the polarity of the waveform of the waveform signal using the key stream, a decoding unit that decodes the transmission data by integrating the predetermined number of different waveform signals whose polarities have been inverted A receiving device including the above.
11. The different information according to the timing is time information. The receiving device according to claim 10.
12. The time information includes GPS (Global Positioning System) time information, UTC (Universal Time Coordinated) time information, GMT (Greenwich Mean Time), JST (Japan Standard Time) time information, and values of a counter counted at predetermined equal time intervals or non-equal time intervals. The receiving device according to claim 11.
13. The time information is truncated in predetermined time units. The receiving device according to claim 11.
14. In addition to the time information, the key stream generation unit uses the ID unique to the transmission device as the initial value, and further generates the key stream using a secret key. The receiving device according to claim 11.
15. The different information according to the timing is the key stream generated immediately before, or the encrypted data generated immediately before. The receiving device according to claim 10.
16. The transmission data includes an MSDU (MAC (Media Access Control) Service Data Unit) generated based on the Payload, a CMAC tag generated by CMAC (Cihper-based MAC: Cipher-based Message Authentication Code) processing from the MSDU, and an error correction code ECC (Error Correcting Code or Error Check and Correct) obtained from the MSDU and the CMAC tag. From the transmission data, an MSDU decoding unit that performs error correction by the error correction code ECC and decodes the MSDU and the CMAC tag. It further includes a CMAC processing unit that generates a CMAC tag by CMAC (Cihper-based MAC: Cipher-based Message Authentication Code) processing from the MSDU, compares it with the CMAC tag decoded by the MSDU decoding unit, and determines whether the transmission data has been tampered with. The receiving device according to claim 10.
17. The receiving unit receives, from the transmission device, a waveform signal modulated with encrypted data obtained by encrypting the same transmission data repeatedly transmitted at different timings. The receiving device according to claim 10.
18. It further includes an integration storage unit that integrates and stores a waveform obtained by inverting the waveform of a waveform signal modulated with encrypted data obtained by encrypting the same transmission data repeatedly transmitted from the transmission device, by using the key stream at the polarity inversion unit. The decoding unit decodes the transmission data based on the waveform signal with the inverted polarity integrated and stored in the integration storage unit. The receiving device according to claim 17.
19. The polarity inversion unit inverts the waveform polarity of the waveform signal by multiplying the waveform polarity of the waveform signal by a coefficient set by the key stream. The receiving device according to claim 10.
20. At least a key stream generated with different information corresponding to the timing as an initial value, which is transmitted from a transmission device in different frequency bands and at different timings, and a plurality of different encrypted data obtained by encrypting transmission data with a plurality of different key streams generated at a plurality of different timings are modulated into a plurality of different waveform signals, and the plurality of different waveform signals are received in the different frequency bands and at the plurality of different timings, respectively, and a reception process; A key stream generation process for generating a key stream with different information corresponding to the timing as an initial value; A polarity inversion process for inverting the polarity of the waveform of the waveform signal by the key stream; A decoding process for decoding the transmission data by integrating the plurality of different waveform signals with the inverted polarity; A receiving method including the above.
Citation Information
Patent Citations
Production apparatus of fiber of heat softening material
JP1987059550A