Machine key operation system, machine key operation method, and machine key operation program

By dividing the device key into an initial key and an activation key and requiring dual requests for calculation, the risk of theft and unauthorized communication with IoT devices is significantly reduced, ensuring secure authentication and communication.

JP7693137B2Active Publication Date: 2025-06-16MITSUBISHI ELECTRIC CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024568964
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-05-12
Publication Date
2025-06-16
Estimated Expiration
2043-05-12

AI Technical Summary

Technical Problem

There is a risk of theft and unauthorized communication with cloud servers if IoT devices are stolen before delivery, and existing technologies do not adequately prevent unauthorized decryption of authentication keys.

Method used

The device key is divided into an initial key and an activation key, with both the user terminal device and the IoT device required to request the calculation of the device key, thereby reducing the risk of theft and leakage.

Benefits of technology

This approach reduces the risk of theft and leakage of the device key by requiring dual requests for key calculation, ensuring secure communication and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007693137000001
    Figure 0007693137000001
  • Figure 0007693137000002
    Figure 0007693137000002
  • Figure 0007693137000003
    Figure 0007693137000003
Patent Text Reader

Abstract

A factory device (100) generates an equipment key, an initial key for calculating the equipment key, and an activation key, transmits the initial key to an equipment device (200), and transmits the activation key to a key activation device (300). The key activation device (300) is provided with an activation permission flag indicating whether or not activation of the activation key is permitted. The key activation device (300), upon receiving, from a user terminal device (500), an activation permission request requesting activation of the activation key, sets the activation permission flag to a permission condition when authentication for a user is successful. The key activation device (300), upon receiving, from the equipment device (200), an activation key acquisition request, transmit the activation key to the equipment device (200) when the activation permission flag is set to the permission condition. The equipment device (200) calculates the equipment key on the basis of the initial key and the activation key received from the key activation device (300).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an equipment key operation system, a factory device, an equipment device, a key activation device, a user terminal device, an equipment key operation method, and an equipment key operation program.

Background Art

[0002] In order to provide cloud services for IoT devices, it is necessary to securely connect the IoT devices and the cloud server. For this purpose, it is necessary to incorporate an equipment key indicating that the IoT device is a legitimate device into the IoT device. IoT is an abbreviation for Internet of Things. It is desired to address the security risks when incorporating the equipment key into the device.

[0003] For example, there is a technology for authenticating IoT devices on the cloud server side using a symmetric key or an asymmetric key between the IoT device and the cloud server and performing secure communication. In order to perform such secure communication, it is necessary to equip the IoT device with an equipment key A and equip the cloud server with the same equipment key A or a key B paired with the equipment key A. The operation of equipping the IoT device with an equipment key is generally performed during the manufacture of the IoT device in the manufacturing factory. Also, in the process of transporting the IoT device from the manufacturing factory to the customer, it may pass through a plurality of external vendors. Under such circumstances, the risk of theft and leakage of the equipment key after the IoT device is shipped is high, and the countermeasure cost for preventing them increases.

[0004] Patent Document 1 discloses a method of using a split encryption key to decrypt an authentication key required for communication between an IC card owned by a user and a communication terminal. IC is an abbreviation for Integrated Circuit.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

SUMMARY OF THE INVENTION

PROBLEMS TO BE SOLVED BY THE INVENTION

[0006] In the conventional method, there is a risk that the IoT device may be stolen before being delivered from the factory to a legitimate user, and the IoT device may fall into the hands of an attacker. Therefore, even if the IoT device is stolen, it is necessary to prevent unauthorized communication with the cloud server, that is, to implement a mechanism that does not allow an attacker to enjoy benefits without risk. In addition, even if key information is extracted from the IoT device, it is necessary to prevent the establishment of communication with the cloud server.

[0007] In the technology of Patent Document 1, a user can decrypt an authentication key even if they do not own the IC card itself as long as they own the IC card information. Therefore, it is impossible to authenticate whether the user who has sent the IC card information from the mobile terminal is a legitimate user who owns the IC card. Therefore, there is a risk that the authentication key may be decrypted by an attacker in the event of theft of the IC card or leakage of IC card information.

[0008] In the present disclosure, the device key is divided into elements of an initial key and an activation key, and both the user terminal device and the IoT device are required to request the calculation of the device key, with the aim of reducing the risk of theft and leakage of the device key.

MEANS FOR SOLVING THE PROBLEMS

[0009] The device key operation system of the present disclosure is a device key operation system that operates a device key used for authenticating an information transmission device manufactured in a factory, a factory device that is used in the factory and generates the device key, an initial key for calculating the device key, and an activation key; a device device mounted on the information transmission device; a key activation device that manages the activation key; A user terminal device used by a user of the information transmission device and comprises The factory device transmits the device identifier for identifying the information transmission device and the initial key to the device device, and transmits the device identifier and the activation key to the key activation device. The key activation device comprises an activation permission flag indicating whether or not to activate the activation key. When receiving an activation permission request for requesting activation of the activation key from the user terminal device, it authenticates the user. When the authentication of the user is successful, it sets the activation permission flag to permitted. When receiving an activation key acquisition request for requesting acquisition of the activation key from the device device, it refers to the activation permission flag, and if the activation permission flag is permitted, it transmits the activation key to the device device. The device device calculates the device key based on the initial key and the activation key received from the key activation device.

Advantages of the Invention

[0010] In the device key operation system according to the present disclosure, the device key is divided into elements of an initial key and an activation key, and calculation of the device key requires requests from both the user terminal device and the device device. Therefore, according to the device key operation system according to the present disclosure, the risk of theft and leakage of the device key can be reduced.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

[0012] Hereinafter, this embodiment will be described with reference to the drawings. In each figure, the same or corresponding parts are denoted by the same reference numerals. In the description of the embodiment, the description of the same or corresponding parts will be omitted or simplified as appropriate. The arrows in the figures mainly indicate the flow of data or the flow of processing.

[0013] Embodiment 1. ***Description of the Configuration*** FIG. 1 is a diagram showing a configuration example of a device key operation system 800 according to this embodiment. The device key operation system 800 is a system that operates device keys used for authenticating information transmission devices manufactured in a factory. In this embodiment, as an example of an information transmission device manufactured in a factory, an IoT device will be used for explanation. An IoT device is a device that is connected to a network such as the Internet and transmits and receives information. The device key operation system 800 includes a factory device 100, a device device 200, a key activation device 300, an application device 400, and a user terminal device 500. The factory device 100, the device device 200, the key activation device 300, the application device 400, and the user terminal device 500 communicate via a network such as the Internet.

[0014] FIG. 2 is a diagram showing a functional configuration example of each device of the device key operation system 800 according to this embodiment. Hereinafter, each of the factory device 100, the device device 200, the key activation device 300, the application device 400, and the user terminal device 500 may be referred to as each device of the device key operation system 800.

[0015] The factory device 100 is a computer used in a factory that manufactures IoT devices. The factory device 100 is installed, for example, in a factory that manufactures IoT devices. The factory device 100 is used in the factory and generates a device key 30, an initial key 31 for calculating the device key 30, and an activation key 32. The initial key 31 and the activation key 32 are generated so that the device key 30 cannot be inferred alone. The method for generating the device key 30, the initial key 31, and the activation key 32 will be described later. The factory device 100 transmits the device identifier 20 for identifying the IoT device and the initial key 31 to the device device 200, and transmits the device identifier 20 and the activation key 32 to the key activation device 300. The factory device 100 includes, as functional elements, a device key generation unit 110, an activation key generation unit 120, and an initial key generation unit 130.

[0016] The device apparatus 200 is a computer installed in an IoT device. The device apparatus 200 manages an initial key associated with a device identifier for identifying the IoT device. In the following description, the device identifier is abbreviated as the device ID. ID is an abbreviation of IDentifier. The device apparatus 200 includes, as functional elements, an initial key management unit 210, an activation key request unit 220, an activation processing unit 230, and a device key storage unit 240.

[0017] The key activation device 300 is a computer used to provide a device key operation service in the device key operation system 800. For example, the key activation device 300 manages an activation key associated with a device ID. In addition, the key activation device 300 includes an activation permission flag 321 associated with a device ID and a status flag 322 associated with a device ID. The key activation device 300 includes, as functional elements, an activation key management unit 310 and a flag management unit 320. The flag management unit 320 manages the activation permission flag 321 and the status flag 322. The activation permission flag 321 is a flag indicating whether activation of the activation key is permitted. The activation permission flag 321 indicates whether to permit activation of the activation key corresponding to the device ID. For example, the key activation device 300 includes a correspondence table of the activation key corresponding to the device ID and the activation permission flag 321. The status flag 322 is a flag indicating whether activation of the activation key has been performed or not on the IoT device. For example, the key activation device 300 includes a correspondence table of the activation key corresponding to the device ID and the status flag 322.

[0018] The application device 400 is a computer that provides an application service to an IoT device. The application device 400 is also referred to as an application server. The application device 400 is, for example, a cloud server. The application device 400 includes, as functional elements, a device key management unit 410 and a user management unit 420. Note that the key activation device 300 and the application device 400 may be mounted on the same device.

[0019] The user terminal device 500 is a terminal used by a user of an IoT device. The user terminal device 500 is a computer such as a smartphone, a tablet terminal, or a portable information processing device. The user terminal device 500 includes an activation permission request unit 510 as a functional element.

[0020] FIG. 3 is a diagram showing a hardware configuration example of each device of the device key operation system 800 according to the present embodiment. Here, for the sake of simplicity of explanation, the same reference numerals are given to the hardware common to each device of the device key operation system 800 and are described. However, it is obvious that each device of the device key operation system 800 individually includes hardware.

[0021] Each device of the device key operation system 800 is a computer. Each device of the device key operation system 800 includes a processor 910, and also includes storage devices such as a memory 921 or an auxiliary storage device 922, an input / output interface 930, and other hardware such as a communication interface 950. The processor 910 is connected to other hardware via a signal line 80 and controls these other hardware.

[0022] Each device of the device key operation system 800 includes functional elements as described above. The functional elements of each device of the device key operation system 800 are realized by, for example, software.

[0023] The processor 910 is a device that executes a device key operation program. The device key operation program shall be a program that realizes the functions of each device of the device key operation system 800. Processor 910 is an IC that performs arithmetic processing. Specific examples of the processor 910 are a CPU, a DSP, and a GPU. IC is an abbreviation for Integrated Circuit. CPU is an abbreviation for Central Processing Unit. DSP is an abbreviation for Digital Signal Processor. GPU is an abbreviation for Graphics Processing Unit.

[0024] Memory 921 is a storage device that temporarily stores data. Specific examples of the memory 921 are SRAM or DRAM. SRAM is an abbreviation for Static Random Access Memory. DRAM is an abbreviation for Dynamic Random Access Memory. Auxiliary storage device 922 is a storage device that stores data. A specific example of the auxiliary storage device 922 is an HDD. Also, the auxiliary storage device 922 may be a portable storage medium such as an SD (registered trademark) memory card, a CF, a NAND flash, a flexible disk, an optical disk, a compact disk, a Blu-ray (registered trademark) disk, or a DVD. Note that HDD is an abbreviation for Hard Disk Drive. SD (registered trademark) is an abbreviation for Secure Digital. CF is an abbreviation for CompactFlash (registered trademark). DVD is an abbreviation for Digital Versatile Disk.

[0025] Input / output interface 930 is an interface for connecting input / output devices. Specific examples of the input / output interface 930 are ports for USB and HDMI (registered trademark). USB is an abbreviation for Universal Serial Bus. HDMI (registered trademark) is an abbreviation for High-Definition Multimedia Interface.

[0026] The communication interface 950 is an interface for communicating with an external device. As a specific example, the communication interface 950 is a port of Ethernet (registered trademark) or a device for performing wireless communication.

[0027] The device key operation program is executed in each device of the device key operation system 800. The device key operation program is loaded into the processor 910 and executed by the processor 910. In the memory 921, not only the device key operation program but also the OS is stored. The OS is an abbreviation of Operating System. The processor 910 executes the device key operation program while executing the OS. The device key operation program and the OS may be stored in the auxiliary storage device 922. The device key operation program and the OS stored in the auxiliary storage device 922 are loaded into the memory 921 and executed by the processor 910. Note that part or all of the device key operation program may be incorporated into the OS.

[0028] Each device of the device key operation system 800 may include a plurality of processors that replace the processor 910. These plurality of processors share the execution of the device key operation program. Each processor is a device that executes the device key operation program in the same manner as the processor 910.

[0029] Data, information, signal values, and variable values used, processed, or output by the device key operation program are stored in the memory 921, the auxiliary storage device 922, or registers or cache memories in the processor 910.

[0030] Each "part" of each device of the device key operation system 800 may be read as "circuit", "process", "procedure", "processing", or "circuitry". The device key operation program causes a computer to execute each process obtained by reading each "part" of each device of the device key operation system 800 as "processing". Each "processing" of each process of each device of the device key operation system 800 may be read as "program", "program product", "computer-readable storage medium storing a program", or "computer-readable recording medium recording a program". Further, the device key operation method is a method performed by each device of the device key operation system 800 executing the device key operation program. The device key operation program may be stored in and provided from a computer-readable recording medium. Further, the device key operation program may be provided as a program product.

[0031] ***Description of Operations***

[0032] Next, the operations of each device of the device key operation system 800 will be described. The operation procedure of each device of the device key operation system 800 corresponds to the device key operation method. Further, the program for realizing the operation of each device of the device key operation system 800 corresponds to the device key operation program.

[0033] FIG. 4 is a sequence diagram showing an operation example of each device of the device key operation system 800 according to the present embodiment. FIG. 5 is a schematic diagram showing steps S101 to S103 of FIG. 4. FIG. 6 is a schematic diagram showing steps S104 to S108 of FIG. 4.

[0034] <Processing of FIG. 5: Steps S101 to S103> The factory device 100 generates a device key 30 indicating that the IoT device is a legitimate device, an initial key 31 for calculating the device key 30, and an activation key 32. Then, the factory device 100 transmits the device ID for identifying the IoT device and the initial key 31 to the device device 200. Also, the factory device 100 transmits the device ID and the activation key 32 to the key activation device 300. Each of the initial key 31 and the activation key 32 is an element that causes no problem even if it leaks alone. Specifically, it is as follows.

[0035] In step S101, the device key generation unit 110 of the factory device 100 generates a different device key 30 for each IoT device using a method such as random number generation. In step S102, the device key generation unit 110 associates the generated device key 30 with the device ID of the target IoT device and sends it to the application device 400. In step S103, the device key management unit 410 of the application device 400 stores the device ID and the device key 30 in the storage device. For example, the device key management unit 410 of the application device 400 stores a correspondence table associating the device ID and the device key 30 in the storage device.

[0036] <Processing of FIG. 6: Steps S104 to S108> In step S104, the activation key generation unit 120 of the factory device 100 generates an activation key 32 by using the initial key 31 which is a fixed value for the device key 30. As an example, a hash value is created for the result of calculating the device key 30 and the initial key 31 to obtain the activation key 32. Note that the initial key 31 and the activation key 32 may be generated from the device key 30 by other methods.

[0037] For example, the device key generation unit 110 may generate the device key 30 as a random number, and the activation key generation unit 120 may generate the activation key 32 as a random number. Then, the initial key generation unit 130 may generate the initial key 31 by encrypting the device key 30 with the activation key 32. Also, for example, the device key generation unit 110 generates a random number for the device key 30, and the initial key generation unit 130 generates a random number for the initial key 31. Then, the activation key generation unit 120 may generate an activation key 32 obtained by encrypting the device key 30 with the initial key 31. Also, for example, the initial key generation unit 130 generates a random number for the initial key 31, and the activation key generation unit 120 generates a random number for the activation key 32. Then, the device key generation unit 110 may generate a device key 30 obtained by encrypting the initial key 31 with the activation key 32. Here, the encryption process is encryption or hashing.

[0038] In step S105, the activation key generation unit 120 associates the generated activation key 32 with the device ID of the target IoT device and sends it to the key activation device 300. In step S106, the activation key management unit 310 of the key activation device 300 stores the device ID and the activation key 32 in the storage device. Also, the flag management unit 320 sets the activation permission flag 321 corresponding to the device ID to "not allowed" and sets the status flag 322 corresponding to the device ID to "not implemented".

[0039] In step S107, the initial key generation unit 130 associates the generated initial key 31 with the device ID of the target IoT device and sends it to the device 200. In step S108, the initial key management unit 210 of the device 200 stores the device ID and the initial key 31 in the storage device.

[0040] FIG. 7 is a sequence diagram showing an operation example of each device of the device key operation system 800 according to the present embodiment. FIG. 8 is a schematic diagram showing steps S109 to S111 of FIG. 7. FIG. 9 is a schematic diagram showing steps S112 to S116 of FIG. 7. FIG. 10 is a schematic diagram showing steps S117 to S118 of FIG. 7. FIG. 11 is a schematic diagram showing steps S119 to S121 of FIG. 7.

[0041] When the key activation device 300 receives an activation permission request 33 for requesting activation of the activation key 32 from the user terminal device 500, it performs user authentication. When the user authentication is successful, the key activation device 300 sets the activation permission flag 321 to "permitted". In addition, when the key activation device 300 receives an activation key acquisition request 34 for requesting acquisition of the activation key from the device device 200, it refers to the activation permission flag 321. If the activation permission flag 321 is "permitted", the key activation device 300 transmits the activation key 32 to the device device 200. Specifically, it is as follows.

[0042] <Processing of FIG. 8: Steps S109 to S111> The user terminal device 500 transmits to the key activation device 300 the activation permission request 33 including user information and a device ID used for user authentication. This is a process in which a user of an IoT device performs user registration in the application device 400 using a user terminal device 500 such as a smartphone.

[0043] In step S109, the activation permission request unit 510 of the user terminal device 500 receives the device ID input by the user and user information such as the user's name and email address. In step S110, the activation permission request unit 510 transmits an activation permission request 33 including the device ID and user information received from the user to the key activation device 300. The activation permission request 33 requests activation of the activation key 32 corresponding to the device ID. In step S111, the key activation device 300 receives the activation permission request 33.

[0044] <Processing of FIG. 9: Steps S112 to S116> The key activation device 300 performs user authentication using the user information, and when the user authentication is successful, sets the activation permission flag 321 to "permitted". The key activation device 300 queries the user information included in the activation permission request 33 against the user information pre-held in the application device 400. As a result of the query, if the user authentication is successful, the activation permission flag 321 corresponding to the device ID included in the activation permission request 33 is rewritten to "permitted". Specifically, it is as follows.

[0045] In step S112, the activation key management unit 310 sends an authentication request for the user information included in the activation permission request 33 to the application device 400. In step S113, the user management unit 420 of the application device 400 queries the user information included in the activation permission request 33 against the user information pre-held. In step S114, the user management unit 420 sends the query result to the key activation device 300 as an authentication response to the authentication request. In step S115, the activation key management unit 310 receives the authentication response. When the user authentication is successful, in step S116, the activation key management unit 310 rewrites the activation permission flag 321 corresponding to the device ID included in the activation permission request 33 to "permitted". Although not shown in the figure, if the user authentication fails, the activation key management unit 310 sends an error notification indicating that the user authentication has failed to the user terminal device 500.

[0046] <Processing of FIG. 10: From step S117 to step S118> The device 200 sends the device ID included in the activation key acquisition request 34 to the key activation device 300. Specifically, it is as follows.

[0047] In step S117, the activation key request unit 220 of the device 200 sends an activation key acquisition request 34 including the device ID to the key activation device 300. Note that the activation key request unit 220 may include device authentication information generated based on the initial key 31 in the activation key acquisition request 34. In step S118, the key activation device 300 receives an activation key acquisition request 34.

[0048] <Processing of FIG. 11: Steps S119 to S121> When the key activation device 300 receives the activation key acquisition request 34, it refers to the activation permission flag 321. If the activation permission flag 321 is "permitted", the key activation device 300 transmits the activation key 32 to the device device 200. Specifically, it is as follows.

[0049] In step S119, the activation key management unit 310 refers to the activation permission flag 321 corresponding to the device ID included in the activation key acquisition request 34. In step S120, if the activation permission flag 321 is "permitted", the activation key management unit 310 transmits the activation key 32 corresponding to the device ID to the device device 200. Although not shown, if the activation permission flag 321 is "not permitted", the activation key management unit 310 transmits an error notification indicating that the activation key 32 cannot be transmitted to the device device 200 or the user terminal device 500. In step S121, the device device 200 receives the activation key 32.

[0050] FIG. 12 is a sequence diagram showing an operation example of each device of the device key operation system 800 according to the present embodiment. FIG. 13 is a schematic diagram showing step S122 of FIG. 12. FIG. 14 is a schematic diagram showing steps S123 to S128 of FIG. 12.

[0051] <Processing of FIG. 13: Step S122> The device device 200 calculates the device key 30 based on the initial key 31 and the activation key 32 received from the key activation device 300. Specifically, it is as follows.

[0052] In step S122, the activation processing unit 230 of the device apparatus 200 generates a device key from the received activation key 32 and the initial key 31 held in the storage device. For example, the activation processing unit 230 calculates the device key by encrypting (encrypting or hashing) the initial key 31 with the activation key 32. Alternatively, the activation processing unit 230 calculates the device key by decrypting the initial key 31 with the activation key 32. The method for calculating the device key is determined by the generation methods of the device key, the initial key, and the activation key. The activation processing unit 230 holds the calculated device key in the storage device.

[0053] <Processing of FIG. 14: Steps S123 to S128> The device apparatus 200 transmits a device key authentication request 35 requesting authentication of whether the calculated device key is legitimate to the application apparatus 400. The device key authentication request 35 includes the calculated device key and the device ID. The application apparatus 400 authenticates whether the device key included in the device key authentication request 35 is legitimate based on the device ID and the device key previously stored in the storage device. Specifically, it is as follows.

[0054] In step S123, the activation processing unit 230 of the device apparatus 200 transmits a device key authentication request 35 including the calculated device key and the device ID to the application apparatus 400. The device key authentication request 35 is a request for inquiring whether the calculated device key is legitimate. In step S124, the application apparatus 400 receives the device key authentication request 35. In step S125, the device key management unit 410 of the application apparatus 400 inquires about the device ID and the device key previously stored in the storage device and the device ID and the device key included in the device key authentication request 35.

[0055] If the device key included in the device key authentication request 35 is legitimate, in step S126, the device key management unit 410 transmits a device key authentication confirmation notice 36 notifying that the device key is legitimate to the key activation device 300 and the device device 200. The device key authentication confirmation notice 36 includes the device ID corresponding to the calculated device key. Although not shown in the figure, if the device key is not legitimate, the device key management unit 410 transmits a notice to the device device 200 or the user terminal device 500 indicating that the device key included in the device key authentication request 35 is not legitimate.

[0056] In step S127, the key activation device 300 receives the device key authentication confirmation notice 36. In step S128, when the flag management unit 320 of the key activation device 300 receives the device key authentication confirmation notice 36, it sets the activation permission flag 321 corresponding to the device ID to "not allowed". Also, the flag management unit 320 sets the status flag 322 corresponding to the device ID to "completed". Then, the key activation device 300 writes the user information sent in step S111 to the storage device of the application device 400 in association with the device ID. Also, the key activation device 300 may notify the user terminal device 500 that the activation of the device key 30 has been completed based on the user information corresponding to the device ID.

[0057] Through the above processing, when it is authenticated that the device key is legitimate, communication between the device device 200 and the application device 400 becomes possible.

[0058] ***Other configurations*** <Modification Example 1> As a first modification example of the present embodiment, the key activation device 300 may determine whether an activation key acquisition request 34 is received within a certain period from the time when the activation permission request 33 is received. Then, the key activation device 300 proceeds with the process only for the activation key acquisition request 34 received within the certain period as a valid activation key acquisition request 34. When the key activation device 300 receives the activation key acquisition request 34 after the elapse of the certain period, it transmits an error notification to the device device 200 or the user terminal device 500. The error notification is displayed on the display device of the device device 200 or the display device of the user terminal device 500. According to the first modification example of the present embodiment, the security in the activation of the device key is improved.

[0059] <Modification Example 2> As a second modification example of the present embodiment, the application device 400 may store the expiration date of the device key in the storage device together with the device ID and the device key transmitted from the factory device 100. When transmitting the device ID and the device key to the application device 400, the factory device 100 also transmits the expiration date of the device key. Based on the device ID, the device key, and the expiration date stored in the storage device, the application device 400 authenticates whether the calculated device key included in the device key authentication request 35 is legitimate. Specifically, the application device 400 has a correspondence table of the device ID, the device key, and the expiration date, and also checks the expiration date when authenticating whether the device key is legitimate. According to the second modification example of the present embodiment, the verification accuracy of the device key is improved and the security is enhanced.

[0060] <Modification Example 3> As a third modification example of the present embodiment, a mode of reissuing the device key of the IoT device will be described. The reissuance of the device key of the IoT device is effective when the IoT device is transferred or diverted. The factory device 100 acquires a device key reissue request for reissuing the device key of the IoT device corresponding to the device ID from the user terminal device 500. When the factory device 100 acquires the device key reissue request, it sends a device key invalidation notice corresponding to the device ID to the device device 200 or the user terminal device 500. The factory device 100 manages an invalidation flag. Then, the factory device 100 regenerates the device key and the activation key corresponding to the device ID. Here, it is assumed that the initial key is a fixed value. The regeneration method is the same as the method for generating the device key and the activation key described above. The application device 400 stores the device ID and the regenerated device key transmitted from the factory device 100 in a storage device. The key activation device 300 stores the device ID and the regenerated activation key transmitted from the factory device 100 in a storage device. Then, the key activation device 300 sets the status flag 322 of the regenerated activation key corresponding to the device ID from "completed" to "not implemented". After that, the activation process of the activation key is performed in the same manner as in the above-described Embodiment 1. According to Modification Example 3 of the present embodiment, the device key operation process can be implemented in the same manner as in Embodiment 1 using the regenerated activation key.

[0061] Note that the device key reissue request may be sent from the user terminal device 500 to the key activation device 300 or the application device 400. Then, the key activation device 300 or the application device 400 that has received the device key reissue request requests the factory device 100 for the device key reissue request. By making a device key reissue request from the user terminal device 500 to the key activation device 300 or the application device 400, user authentication can be performed by the key activation device 300 or the application device 400. Also, at that time, the invalidation flag is managed by the key activation device 300 or the application device 400.

[0062] Alternatively, the device key reissue request may be sent from the device device 200 to the key activation device 300 or the application device 400. For example, when operating and initializing the device device 200, communication with the key activation device 300 or the application device 400 can be performed, and the process of invalidating and reissuing the device key can be simultaneously implemented.

[0063] <Modification Example 4> As a modification example 4 of the present embodiment, an aspect of performing an invalidation process of the device key of the IoT device will be described. The invalidation process of the device key of the IoT device can improve the security at the time of discarding the IoT device. The key activation device 300 receives a device key invalidation request for invalidating the device key of the IoT device corresponding to the device ID from the user terminal device 500. When the key activation device 300 receives the device key invalidation request, it sets an invalidation flag corresponding to the device ID. Further, the key activation device 300 transmits an invalidation notification of the device key corresponding to the device ID to the device device 200 and the application device 400. In this way, when the key activation device 300 manages the invalidation of the device key, the key activation device 300 shall be provided with an invalidation flag. For example, two pieces of information such as "invalidating" and "issuing" are set in the invalidation flag, indicating whether the device key can be used. According to the modification example 4 of the present embodiment, the security at the time of device discard can be improved.

[0064] <Modification Example 5> As a modification example 5 of the present embodiment, the user terminal device 500 includes information indicating that the communication is by the same network as the device device 200 in the activation permission request 33 transmitted to the key activation device 300. For example, the user terminal device 500 includes information indicating that it is the same LAN as the device device 200 in the activation permission request 33. When the key activation device 300 receives the activation key acquisition request 34 from the device device 200, it checks whether it is the same LAN communication as the user terminal device 500. If the networks are different, an error notification is transmitted to the user terminal device 500 or the device device 200. According to Modification Example 5 of the present embodiment, security is improved for confirming whether the IoT device is owned by the user.

[0065] <Modification Example 6> In the present embodiment, the functions of each part of each device of the device key operation system 800 are realized by software. As a modification example, the functions of each device of the device key operation system 800 may be realized by hardware. Specifically, each device of the device key operation system 800 includes an electronic circuit 909 instead of a processor 910.

[0066] FIG. 15 is a diagram showing a hardware configuration example of each device of the device key operation system 800 according to a modification example of the present embodiment. The electronic circuit 909 is a dedicated electronic circuit that realizes the functions of each part of each device of the device key operation system 800. Specifically, the electronic circuit 909 is a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, a logic IC, a GA, an ASIC, or an FPGA. GA is an abbreviation for Gate Array. ASIC is an abbreviation for Application Specific Integrated Circuit. FPGA is an abbreviation for Field-Programmable Gate Array.

[0067] The functions of each part of each device of the device key operation system 800 may be realized by one electronic circuit or may be distributed and realized by a plurality of electronic circuits.

[0068] As another modification example, some of the functions of each part of each device of the device key operation system 800 may be realized by an electronic circuit, and the remaining functions may be realized by software. Also, some or all of the functions of each part of each device of the device key operation system 800 may be realized by firmware.

[0069] Each of the processor and the electronic circuit is also called a processing circuit. That is, the functions of each device of the device key operation system 800 are realized by the processing circuit.

[0070] ***Explanation of the Effects of this Embodiment*** In the device key operation system according to this embodiment, the device key given to the IoT device is divided into an initial key that is not a problem even if it leaks alone and elements of an activation key, and they are delivered through different routes. Then, only the initial key is given to the IoT device, and the activation key is given to the key activation device. Furthermore, it is possible to calculate the device key from the initial key and the activation key divided into two according to requests from both the user terminal device used by the user of the IoT device and the device device mounted on the IoT device. Specifically, it is possible to restore the device key by activating the initial key with the activation key.

[0071] In this way, according to the device key operation system according to this embodiment, by dividing the device key into two elements and delivering them through different routes, it is possible to reduce the risk of theft and leakage during key delivery. Also, according to the device key operation system according to this embodiment, by introducing a mechanism in which the user requests the activation of the activation key from the user terminal device, the risk of the device key being stolen is reduced. Also, when activating the activation key, a user authentication function (confirmation that the user owns the IoT device) is performed, so the risk of theft of the IoT device is also reduced, and it is ensured that the device key of the installed IoT device is secure. Also, according to the device key operation system according to this embodiment, it is possible to expect a reduction in countermeasure costs due to the reduction in the risk of theft and leakage of the device key.

[0072] In the above Embodiment 1, each part of each device of the device key operation system 800 has been described as an independent functional block. However, the configuration of each device of the device key operation system 800 does not have to be the configuration as in the above-described embodiment. As long as the functional blocks of each device of the device key operation system 800 can realize the functions described in the above-described embodiment, any configuration may be used. Also, each device of the device key operation system 800 may be not a single device but a system composed of a plurality of devices. Moreover, in Embodiment 1, a plurality of parts may be combined and implemented. Alternatively, one part of this embodiment may be implemented. In addition, this embodiment may be implemented in any combination, either as a whole or partially. That is, in Embodiment 1, free combination of parts of the embodiment, or deformation of any component of the embodiment, or omission of any component in the embodiment is possible.

[0073] Note that the above-described embodiments are essentially preferred examples and are not intended to limit the scope of the present disclosure, the scope of the application of the present disclosure, and the scope of the use of the present disclosure. The above-described embodiments can be variously modified as necessary. For example, the procedures described using a flowchart or a sequence diagram may be modified as appropriate.

Description of Reference Numerals

[0074] 20 Device identifier, 30 Device key, 31 Initial key, 32 Activation key, 33 Activation permission request, 34 Activation key acquisition request, 35 Device key authentication request, 36 Device key authentication confirmation notice, 100 Factory device, 110 Device key generation unit, 120 Activation key generation unit, 130 Initial key generation unit, 200 Device device, 210 Initial key management unit, 220 Activation key request unit, 230 Activation processing unit, 240 Device key storage unit, 300 Key activation device, 310 Activation key management unit, 320 Flag management unit, 321 Activation permission flag, 322 Status flag, 400 Application device, 410 Device key management unit, 420 User management unit, 500 User terminal device, 510 Activation permission request unit, 800 Device key operation system, 80 Signal line, 909 Electronic circuit, 910 Processor, 921 Memory, 922 Auxiliary storage device, 930 Input / output interface, 950 Communication interface.

Claims

1. In a device key operation system that operates a device key used for authenticating an information transmission device manufactured in a factory, a factory device that is used in the factory and generates the device key, an initial key for calculating the device key, and an activation key; a device device mounted on the information transmission device; a key activation device that manages the activation key; and a user terminal device used by a user of the information transmission device are provided, The factory device transmits the device identifier for identifying the information transmission device and the initial key to the device device, and transmits the device identifier and the activation key to the key activation device, The key activation device includes an activation permission flag indicating whether or not to permit activation of the activation key. When receiving an activation permission request for requesting activation of the activation key from the user terminal device, it authenticates the user. When the user authentication is successful, it sets the activation permission flag to permitted. When receiving an activation key acquisition request for requesting acquisition of the activation key from the device device, it refers to the activation permission flag, and if the activation permission flag is permitted, it transmits the activation key to the device device. The device device is a device key operation system that calculates the device key based on the initial key and the activation key received from the key activation device.

2. The user terminal device transmits the user information used for authenticating the user and the device identifier to the key activation device in the activation permission request, The key activation device authenticates the user using the user information. When the user authentication is successful, it sets the activation permission flag to permitted. The device device transmits the device identifier to the key activation device in the activation key acquisition request, The key activation device The device key operation system according to claim 1, wherein when receiving the activation key acquisition request, it refers to the activation permission flag, and if the activation permission flag is permission, it transmits the activation key to the device apparatus.

3. The factory apparatus transmits the device identifier and the device key to an application apparatus that communicates with the information transmission device, The application apparatus stores the device identifier and the device key transmitted from the factory apparatus in a storage device, The device apparatus is a device key authentication request for requesting authentication as to whether the calculated device key is legitimate, and transmits a device key authentication request including the calculated device key and the device identifier to the application apparatus, The application apparatus authenticates whether the calculated device key included in the device key authentication request is legitimate based on the device identifier and the device key stored in the storage device according to claim 1 or claim 2.

4. The application apparatus stores the expiration date of the device key in a storage device together with the device identifier and the device key transmitted from the factory apparatus, and authenticates whether the calculated device key included in the device key authentication request is legitimate based on the device identifier, the device key, and the expiration date stored in the storage device according to claim 3.

5. The factory apparatus generates a random number for the initial key, generates a random number for the activation key, and generates a device key obtained by encrypting the initial key with the activation key according to claim 1 or claim 2.

6. The factory apparatus The device key operation system according to claim 1 or claim 2, which generates a random number for the device key, generates a random number for the activation key, and generates the initial key by encrypting the device key with the activation key.

7. The device device The device key operation system according to claim 5, which includes a device key management unit that calculates the device key by encrypting the initial key with the activation key.

8. The device device The device key operation system according to claim 6, which includes a device key management unit that calculates the device key by decrypting the initial key with the activation key.

9. The key activation device The device key operation system according to claim 1 or claim 2, which determines whether the activation key acquisition request is received within a certain time from the time when the activation permission request is received, and sets the activation key acquisition request received within the certain time as a valid activation key acquisition request.

10. The key activation device The device key operation system according to claim 3, which includes a status flag indicating whether the activation of the activation key has been performed or not for the information transmission device. When the device identifier and the activation key are received from the factory device, the device identifier and the activation key are stored in a storage device, the activation permission flag corresponding to the device identifier is set to invalid, and the status flag corresponding to the device identifier is set to not implemented.

11. The application device A device key authentication confirmation notice that authenticates that the calculated device key is regular and includes the device identifier, and transmits the device key authentication confirmation notice to the device device and the key activation device. The key activation device When receiving the machine key authentication confirmation notice, the device key operation system according to claim 10 sets the activation permission flag corresponding to the device identifier to invalid and sets the status flag corresponding to the device identifier to "completed".

12. The factory device When receiving a device key reissue request for reissuing the device key of the information transmission device corresponding to the device identifier, sends a device key invalidation notice corresponding to the device identifier to the device device, and regenerates the device key and the activation key corresponding to the device identifier. The application device Stores the device identifier and the regenerated device key transmitted from the factory device in a storage device. The key activation device Stores the device identifier and the regenerated activation key transmitted from the factory device in a storage device, and sets the status flag of the regenerated activation key corresponding to the device identifier from "completed" to "not implemented". The device key operation system according to claim 11.

13. The key activation device When receiving a device key invalidation request for invalidating the device key of the information transmission device corresponding to the device identifier, sets the status flag corresponding to the device identifier to "invalidated", and sends a device key invalidation notice corresponding to the device identifier to the device device and the application device. The device key operation system according to claim 11.

14. The information transmission device is an IoT (Internet of Things) device. The device key operation system according to claim 1 or claim 2.

15. In a device key operation method used in a device key operation system for operating a device key used for authentication of an information transmission device manufactured in a factory, The factory device used in the factory generates the device key, the initial key for calculating the device key, and the activation key, and transmits the device identifier for identifying the information transmission device and the initial key to the device device mounted on the information transmission device, and transmits the device identifier and the activation key to the key activation device that manages the activation key. The key activation device includes an activation permission flag indicating whether to permit the activation of the activation key. When receiving an activation permission request for requesting the activation of the activation key from the user terminal device used by the user of the information transmission device, it authenticates the user. When the authentication of the user is successful, it sets the activation permission flag to permitted. When receiving an activation key acquisition request for requesting the acquisition of the activation key from the device device, it refers to the activation permission flag, and if the activation permission flag is permitted, it transmits the activation key to the device device. A device key operation method in which the device device calculates the device key based on the initial key and the activation key received from the key activation device.

16. In a device key operation program used in a device key operation system for operating a device key used for authenticating an information transmission device manufactured in a factory. Causing a computer, which is a factory device used in the factory, to execute a process of generating the device key, the initial key for calculating the device key, and the activation key, and transmitting the device identifier for identifying the information transmission device and the initial key to the device device mounted on the information transmission device, and transmitting the device identifier and the activation key to the key activation device that manages the activation key. The key activation device includes an activation permission flag indicating whether to permit the activation of the activation key. When receiving an activation permission request for requesting activation of the activation key from a user terminal device used by a user of the information transmission device, authenticate the user, set the activation permission flag to permitted when the authentication of the user is successful, and when receiving an activation key acquisition request for requesting acquisition of the activation key from the device device, refer to the activation permission flag and, if the activation permission flag is permitted, cause a computer, which is the key activation device, to execute a process of transmitting the activation key to the device device. A device key operation program that causes a computer, which is the device device, to execute a process of calculating the device key based on the initial key and the activation key received from the key activation device.

Citation Information

Patent Citations

  • Information processing apparatus, server apparatus, information processing method, and program

    JP2011258034A

  • IC card system, communication terminal therefor and portable terminal therefor

    JP2012065123A

  • Equipment authentication system, manufacturer key generation device, equipment key generation device, production equipment, cooperative authentication device, equipment playback key generation device, equipment authentication method, and equipment authentication program

    WO2015001600A1