Communication system, communication device, management device, and information terminal used therein
The communication system addresses installation complexity and security challenges by implementing pre-configured authentication and encryption mechanisms, facilitating easy and secure data exchange between information terminals.
Patent Information
- Application Number
- JP2024063028
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-06-29
- Filing Date
- 2024-04-09
- Publication Date
- 2025-08-27
- Estimated Expiration
- 2037-06-29
AI Technical Summary
Existing communication systems require significant effort for installation and configuration, especially when introducing a VPN connection, and often necessitate changes to network configurations, failing to adequately address the reduction of installation effort and ensuring high security for data exchange between information terminals via a global network.
A communication system with pre-configured user and device authentication lists, encryption keys, and secure storage areas, allowing for simplified user authentication and device-to-device authentication, reducing the need for manual configuration and ensuring high security through multi-factor authentication and secure data exchange.
The system significantly reduces user installation effort by automating authentication processes and ensuring secure, confidential data exchange between information terminals, enhancing overall convenience and security.
Smart Images

Figure 0007730200000001 
Figure 0007730200000002 
Figure 0007730200000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication system in which one information terminal and another information terminal exchange data via a global network, and to a communication device, a management device, and an information terminal used in the system. [Background technology]
[0002] It would be extremely convenient if one information terminal could exchange data with another information terminal via a global network, but in this case, how to ensure security becomes important.
[0003] One method is to connect two communication devices that function as routers to each other via a VPN (Virtual Private Network), and then connect one of the communication devices to a private network. It is known that an information terminal located in one network is connected to an information terminal located in another private network to which the other communication device is connected in a pseudo-LAN manner.
[0004] While this VPN connection can ensure high security through tunneling and encryption, it requires a lot of effort to set up the initial setup and various operational settings.
[0005] In an attempt to solve this problem, a method using a server that centralizes information or a method using a structured overlay have been developed and are now known (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2011-45050 Summary of the Invention [Problem to be solved by the invention]
[0007] Although the above document reduces the effort required to configure communication devices when introducing a system to some extent, the configuration work itself is still required. Furthermore, when replacing a normal router with a dedicated communication device capable of VPN connection in order to introduce this communication system, it is often necessary to change the network configuration of the information terminal inside the communication device, and the problem of reducing the effort required for introduction has not yet been resolved.
[0008] The present invention aims to provide a communication system that reduces the effort required for installation, has excellent expandability for terminals and groups, and can ensure high security when one information terminal exchanges data with another information terminal via a global network, as well as a communication device, management device, and information terminal used therein. [Means for solving the problem]
[0009] In order to solve the above-mentioned problems, a communication system of the present invention is a communication system in which a plurality of information terminals included in the same group exchange data with each other via a global network, and includes a communication device connected to each information terminal in the group to perform highly confidential intercommunication between the plurality of information terminals included in the group, and the communication device has a storage unit in which user authentication information for authenticating a user via the connected information terminal is stored and a device authentication list which lists device authentication information required for authenticating each communication device for all communication devices in the same group is stored in advance in a state inaccessible to the user. When exchanging data between the information terminals via the global network, a user authentication process is performed between the information terminals using the user authentication information, and an inter-device authentication process is performed between the information terminals and other communication devices by referencing the device authentication list.
[0010] According to one embodiment of the communication system, a management device is provided that is connected to the global network and performs at least a portion of the device-to-device authentication processing between the plurality of communication devices, and the device authentication list is a list of device authentication information required for authentication of the communication devices and the management device for all communication devices and all management devices in the same group, and the communication devices and the management device have a memory unit in which the device authentication list is pre-stored in a state in which at least a portion of the list is inaccessible to the user.
[0011] The device authentication list may include, for example, device authentication information including the device ID and password of each communication device already registered in the group, and device authentication information including the device ID and password of a temporary user that is reserved in advance for an unregistered communication device in the group, and the management device or the communication device may, for example, when registering a new user in the group, validate the device ID and password of the temporary user and notify all the communication devices of the validated user's device ID.
[0012] The device authentication list may include, for example, a temporary group name reserved in advance for an unregistered group, and device authentication information including the device IDs and passwords of temporary users included in this temporary group name, and the management device or the communication device may, for example, when registering a new group, rewrite the temporary group name to a true group name, validate the device IDs and passwords of at least some of the temporary users of the true group name, and notify the communication device of the validated user of the new group of the rewritten true group name and the device IDs of the validated users.
[0013] The storage unit of the communication device may store, in a state inaccessible to the user, at least a portion of the encryption keys for performing encrypted communications between the communication devices or trigger information for generating the encryption keys. The storage unit of the management device may store, in a state inaccessible to the user, at least a portion of the encryption keys for performing encrypted communications between the communication devices and between the communication devices and the management device or trigger information for generating the encryption keys.
[0014] The information terminals include, for example, personal computers, smartphones, and tablet terminals operated by users, as well as IoT (Internet of Things) devices, M2M (Machine to Machine) devices, cameras, robots, remote control devices, automobiles, and AI (Artificial Intelligence) devices. This includes devices that send and receive various data such as instruments.
[0015] The communication device may have, for example, a user authentication unit that determines whether to permit access in response to an access request from the information terminal based on user authentication information stored in the memory unit, an inter-device authentication unit that performs inter-device authentication processing with other communication devices based on a device authentication list stored in the memory unit, an input / output unit that inputs and outputs information to and from information terminals that have been permitted access by the user authentication unit, and a data transmission / reception unit that transmits and receives data to and from other communication devices that have been authenticated by the inter-device authentication unit.
[0016] The present invention provides a communication device in a communication system in which a plurality of information terminals included in the same group exchange data with each other via a global network, the communication device comprising: a communication unit for transmitting and receiving data to and from the plurality of information terminals included in the group; A communication device connected to a terminal has a memory unit that stores user authentication information for authenticating a user via the connected information terminal, and has a device authentication list that lists the device authentication information required for authenticating each communication device for all communication devices in the same group, and in which at least some of the device authentication information is stored in advance in a state in which the user cannot access it, and when exchanging data between the information terminals via the global network, user authentication processing is performed between the information terminal and the communication device, using the user authentication information, and device-to-device authentication processing is performed between the communication device and other communication devices, referring to the device authentication list.
[0017] Furthermore, the management device of the present invention is a management device that, in a communication system in which multiple information terminals included in the same group exchange data with each other via a global network, executes at least a part of the inter-device authentication processing between communication devices connected to each information terminal in the group in order to perform highly confidential inter-communication between the multiple information terminals included in the group, and has a memory unit in which an equipment authentication list that lists the equipment authentication information required for authenticating each communication device for all communication devices in the same group is pre-stored, and when data is exchanged between the information terminals via the global network, executes the inter-device authentication processing between the communication devices by referring to the equipment authentication list.
[0018] The communication device may be equipped with a history analysis unit that analyzes communication history stored in a memory unit at any time, and an abnormality determination unit that determines unauthorized access or unauthorized operation based on the daily operating status of the communication device analyzed by the history analysis unit.
[0019] The communication device may have a position sensor, and may refer to position information acquired from the position sensor to determine whether the communication device is in a position where it should be used or not.
[0020] The input / output unit may provide the information terminal with a data input screen that resembles a mailed item or a slip as a user interface.
[0021] The communication device or management device may include information acquired from an IoT device or an M2M device in the data exchanged.
[0022] The communication device or management device may have an AI function that performs machine learning based on data acquired from other communication devices or management devices and provides an optimal solution.
[0023] The communication device may be a device equipped with a detachable connection device in which information is pre-stored, or may be an IC card or SIM card attached to the information terminal, or may be a communication circuit and communication software built into a mobile terminal. [Effects of the Invention]
[0024] According to the present invention, when data is exchanged between information terminals via a global network, user authentication processing is performed between the communication device and the information terminal using user authentication information, and device-to-device authentication processing is performed between other communication devices by referencing a device authentication list. As a result, the user only needs to register their own user authentication information, and other authentication processing is performed based on a device authentication list that is pre-set (stored) between the communication devices. This reduces the user's installation effort. Furthermore, because at least a portion of the device authentication list is pre-set (stored) in the memory of each communication device in a state inaccessible to the user, communication security for data exchange between information terminals can be easily ensured. [Brief explanation of the drawings]
[0025] [Figure 1] 1 is an explanatory diagram illustrating an overview of a communication system to which the present invention is applied; [Figure 2] FIG. 2 is an explanatory diagram illustrating a configuration of a communication device. [Figure 3] FIG. 10 is a diagram illustrating a data structure of a user authentication information storage unit. [Figure 4] 10 is a diagram illustrating a data structure of a device authentication information storage unit. [Figure 5] 10 is a diagram illustrating a data structure of a device authentication information storage unit. [Figure 6] 10 is a diagram illustrating a data structure of a device authentication information storage unit. [Figure 7] 10 is a diagram illustrating a data structure of a device authentication information storage unit. [Figure 8] FIG. 2 is a diagram illustrating a data structure of an encryption key information storage unit. [Figure 9] FIG. 2 is a diagram illustrating a data structure of a target data storage unit. [Figure 10] FIG. 2 is a conceptual diagram conceptually showing the configuration of an encryption unit and a decryption unit. [Figure 11] FIG. 2 is a conceptual diagram conceptually showing the configuration of an encryption key providing unit. [Figure 12] FIG. 2 is a conceptual diagram conceptually showing the configuration of a password providing unit. [Figure 13] FIG. 2 is an explanatory diagram illustrating a configuration of a management device. [Figure 14] FIG. 10 is a flowchart showing a processing procedure when device-to-device authentication is performed by the present communication system. [Figure 15] FIG. 2 is a flow chart showing a processing procedure when data is exchanged by the present communication system. [Figure 16] FIG. 10 is an explanatory diagram illustrating the configuration of a group top screen, which is a type of GUI. [Figure 17] FIG. 10 is an explanatory diagram illustrating the configuration of a transmission screen, which is a type of GUI. [Figure 18] FIG. 10 is an explanatory diagram illustrating the configuration of a target data display screen. [Figure 19] FIG. 10 is a flowchart showing a processing procedure for exchanging target data in a communication system according to another embodiment. [Figure 20] FIG. 10 is an explanatory diagram illustrating an overview of a communication system according to another embodiment of the present invention. [Figure 21] FIG. 10 is an explanatory diagram illustrating an overview of a group configuration according to another embodiment of the present invention. [Figure 22] FIG. 10 is an explanatory diagram illustrating the configuration of a communication device according to another embodiment of the present invention. [Figure 23]FIG. 10 is an explanatory diagram illustrating an overview of a communication system according to another embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0026] 1 is an explanatory diagram illustrating an overview of a communication system to which the present invention is applied (hereinafter referred to as "this communication system"). The illustrated communication system includes two or more (two in the illustrated example) communication devices 2, 2 connected via an external network 1, which is a global network supporting a general-purpose communication protocol such as TCP / IP, and a management device 3 connected to each communication device 2 via the external network 1.
[0027] The communication device 2 communicates with the external network 1 via the router 4, and can also communicate with one or more information terminals 7 via an internal network 6, which is a private network built inside the router 4 and supports general-purpose communication protocols such as TCP / IP. Here, from the perspective of a device connected between the external network 1 and the internal network 6, "inside" refers to the internal network 6 side, and "outside" refers to the external network 1 side. The detailed configuration of the communication device 2 will be described later.
[0028] In the communication system of this embodiment, a device authentication list for mutual authentication between communication devices 2 is set in the communication device 2 in a state where at least a portion of the list cannot be directly intervened by the user, and specific group communication is performed using multi-factor authentication based on this device authentication list and user authentication information individually set by the user, thereby improving the security of communication between specific groups. Here, the device authentication list and user authentication information include IDs and passwords (including hashed passwords) for authentication. In addition, the communication device 2 and management device 3 store encryption keys (common key, public key, private key) for anonymizing and transmitting various data, or trigger information for generating these keys.
[0029] Furthermore, in the communication system of this embodiment, in order to flexibly respond to changes in communication, the communication device 2 and management device 3 are pre-configured at the time of shipment to include unregistered users and groups in anticipation of future user additions. When making changes, the group administrator simply submits an electronic request to the system administrator, who then uses a change tool to make the changes. Furthermore, device authentication information is managed separately into information requiring high confidentiality, such as passwords required for device authentication, and information requiring less confidentiality, such as user names and nicknames that can be viewed by all users, thereby ensuring information security. Any user with a communication device 2 can create a dedicated group as the group administrator for their own group. Furthermore, a user in one group can also apply for user or group registration to the system administrator in an electronic document and register as a user in another group.
[0030] The term "communication" here includes both wireless and wired communication.
[0031] Furthermore, the term "communication system" as used herein is a concept that includes a network (in this example, an external network 1 and an internal network 6) and all communication devices that communicate via the network (in this example, a communication device 2, a management device 3, and an information terminal 7).
[0032] Furthermore, a "secret area" is a storage area where confidential information such as passwords, encryption keys, or trigger information for generating them can be stored in a state where users cannot access it from the outside, and corresponds to, for example, the Trust Zone (trademark) in the memory area of a CPU. In the Trust Zone, the CPU's operating modes are divided into a normal area and a secure area. In the secure area, a secure OS runs, on which applications run, and confidential information is placed in the secure area under monitoring mode.
[0033] In other words, the "secret area" creates a physically separate memory space within the CPU, isolating it from the space where the general-purpose OS runs, and a dedicated OS runs in the secure area, managing secure information on the back end of the system. The operation of the normal general-purpose OS can be seen from the secure area, but the secure area cannot be recognized from the general-purpose OS, which makes it possible to prevent external attacks and attempts to intentionally disable the secure mechanism and install other mechanisms.
[0034] In addition, "information terminal" includes devices that send and receive various data, such as personal computers, smartphones, and tablet terminals operated by users, as well as IoT devices, M2M devices, cameras, robots, remote control devices, automobiles, and AI devices, for example, Windows (trademark), Mac OS (trademark), etc. This refers to PCs, communication terminals, and mobile phone terminals that run on operating systems such as Linux (trademark). "User" includes anyone who is using or intends to use this communication system. Multiple OSs may be used on the information terminal at the same time, or may be switched between.
[0035] Furthermore, a "communication device" is a connection device that is placed between a terminal device and a network and connects the terminal devices to each other via the network, and is purchased or rented for use by one or more users from a business that provides the services of this communication system or a person commissioned by that business, and includes, for example, AT-compatible machines with communication functions, dedicated communication equipment, EPROMs built into secret areas of PCs, smartphones, IoT devices and tablet terminals, IC cards and SIMs (Subscriber Identity Modules) that are attached to these, and multifunction machines that combine devices with the aforementioned communication functions.
[0036] Furthermore, the "communication device" may be a communication circuit and communication software built into a mobile terminal such as a smartphone, or a communication circuit and communication software built into a SIM. In this case, for example, regardless of the presence or absence of a management device, the communication circuit and communication software in the memory area of the CPU of the mobile terminal or SIM may be used. The secret area stores secret information such as passwords and encryption keys, and executes the communication process according to the present invention. This enables highly confidential device-to-device communication to be achieved using only a mobile terminal and dedicated software.
[0037] Furthermore, a "management device" is connected to the network as needed and mediates at least part of the data sent and received between communication devices. The "management device" is provided by the service provider of this communication system, and includes, for example, AT-compatible devices with communication capabilities, dedicated communication devices, EPROMs embedded in secret areas of PCs, smartphones, and tablet devices, as well as IC cards and SIM cards inserted into these. The service provider of this communication system may install multiple "management devices" depending on the amount of line traffic, install one for a specific group, or install multiple devices in Japan and overseas.
[0038] The information terminal 7 is equipped with a network interface (not shown) that supports the general-purpose communication protocol and is assigned a private IP. This information terminal 7 is capable of communicating with the communication device 2 via the internal network 6, and is also capable of communicating with the external network 1 via the internal network 6, the communication device 2, and the router 4. In other words, when communicating with the external network 1, the information terminal 7 always communicates via or is referred to by the communication device 2.
[0039] The router 4 is equipped with an inward network interface (not shown) that supports the general-purpose communication protocol, is assigned a static private IP, and is connected to the internal network 6, and an inward / outward network interface (not shown) that supports the general-purpose communication protocol, is assigned a static or dynamic global IP, and is connected to the external network 1. The communication devices 2 and information terminals 7 that are arranged on the internal network 6 side of the router 4 are able to communicate with the external network 1 side by IP masquerading by the router 4.
[0040] Like the communication device 2, the management device 3 is also connected to the external network 1 via a router 8. The configuration of the router 8 is the same as or substantially the same as that of the router 4. The detailed configuration of this management device 3 will also be described later.
[0041] This communication system is intended to exchange data (target data) between an information terminal 7 located on one internal network 6 and an information terminal 7 located on another internal network 6 via an external network 1.
[0042] Specifically, a sending information terminal 7A (see FIG. 15), which is one information terminal 7, sends target data to a receiving information terminal 7B (see FIG. 15), which is another information terminal 7, via an external network 1. Briefly explaining the processing procedure (steps) of the communication system at this time, the sending information terminal 7A first passes the target data to a sending communication device 2A (see FIG. 15), which is a communication device 2 on the internal network 6 side, via the internal network 6 in which the sending information terminal 7A is located. The sending communication device 2A then transmits the target data via the external network 1 to a receiving communication device 2B (see FIG. 15), which is a communication device 2 on the internal network 6 side in which the receiving information terminal 7B is located. The receiving communication device 2B distributes the received target data to the receiving information terminal 7B, which is located on the internal network 6 to which the receiving communication device 2B is directly connected.
[0043] According to such a processing procedure, by ensuring security between the two communication devices 2A, 2B, it is possible to ensure the safety of the exchange of target data, and by enabling smooth exchange of data between the information terminals 7A, 7B and the communication devices 2A, 2B, overall convenience can be sufficiently ensured.
[0044] 1 can function as both a transmitting communication device 2A and a receiving communication device 2B. Therefore, each information terminal 7 shown in the figure can function as both a transmitting information terminal 7A and a receiving information terminal 7B.
[0045] When two communication devices 2, 2 communicate with each other via the external network 1, multiple communication paths may be provided between them so that even if a failure occurs on one communication path, the above communication can continue via another communication path. For example, in the example shown in Figure 1, multiple communication paths are formed by providing multiple routers 4 for one communication device 2, as shown by the virtual lines.
[0046] 1, a router 4 is provided separately from the communication device 2, but this router 4 may be omitted and the communication device 2 itself may have the router function. The same applies to the relationship between the management device 3 and the router 8, and the router 8 may be omitted.
[0047] Next, the configuration of the communication device 2 will be described in detail with reference to FIGS. 2 is an explanatory diagram illustrating the configuration of the communication device 2. The communication device 2 includes a storage unit 21 configured with a secret area in a memory area within a CPU, a RAM (Random Access Memory), a ROM (Read-Only Memory), an HDD (Hard Disk Drive), or an SSD (Solid State Drive) and the like, and temporarily or permanently storing various types of information, a control unit 22 configured with a CPU, a RAM, an SSD, and the like, and executing various programs, an inward network interface (communication means) 23 connected to the internal network 6, an outward network interface (communication means) 24 connected to the external network 1 side (specifically, the router 4), a GPS sensor (status detection sensor, position acquisition sensor) 25 serving as position acquisition means for acquiring position information of the communication device 2, an acceleration sensor (status detection sensor) 26 serving as load detection means for detecting a load on the communication device 2, and a gyro sensor (status detection sensor) 27 serving as attitude detection means for detecting the attitude of the communication device 2.
[0048] The inbound network interface 23 is assigned a private IP for the internal network 6 . When a router 4 is present, a global IP or a private IP is assigned to the outgoing network interface 24 of the communication device 2 for connecting to the router 4. On the other hand, when the router 4 is omitted as described above, a global IP is assigned to the outgoing network interface 24 of the communication device 2 for directly connecting the communication device 2 to the external network 1.
[0049] Incidentally, when a router 4 is provided, the communication devices 2 are normally isolated from the external network 1, and therefore one communication device 2 cannot access another communication device 2 via the global network 1. To make this possible, forwarding settings (port forwarding settings) are made in advance for the router 4 so that when the router 4 receives a communication packet specifying the communication port used in this communication system, the communication packet is forwarded from this router 4 to the communication device 2 arranged inside it.
[0050] In other words, when one communication device 2 accesses another communication device 2 via a router 4, if the other communication device 2 is located inside the router 4, the one communication device 2 needs to retain (store) connection information to the router 4 (specifically, the global IP of the router 4, etc.) as connection information for the other communication device 2.
[0051] On the other hand, if the router 4 is not present, the one communication device 2 will It is necessary to store the connection information for the network interface 24 as the connection information for the other communication device 2. Incidentally, the communication port number is usually common to each communication device 2, so there is no need to pay special attention to it except for the setting of the router 4.
[0052] The storage unit 21 includes a connection information storage unit 21a in which connection information for one or more other communication devices 2 and connection information for the management device 3 are stored, a user authentication information storage unit 21b in which user authentication information such as the user ID, password or hash data thereof of a user who is permitted or may be permitted to access the communication device 2 from the information terminal 7 is stored, a device authentication information storage unit 21c in which a device authentication list is stored that lists, for all communication devices in the same group, device authentication information required for authenticating other communication devices 2 and the management device 3 that may perform highly confidential intercommunication via the global network 1, and an encryption key or the encryption key information storage unit 21d in which trigger information for generating these is stored, a target data storage unit 21f in which at least a portion of the target data transmitted by the transmitting communication device 2A or the target data received by the receiving communication device 2B is stored sequentially, a communication history information storage unit 21g in which information on the communication history (communication history information) from the two network interfaces 23, 24 is stored sequentially, a sensing information storage unit 21h in which sensing information (sensing results) from each of the status detection sensors 25, 26, 27 is stored sequentially, and a history analysis information storage unit 21i in which the analysis results of this communication history information and sensing information, etc. are stored sequentially as history analysis information.
[0053] Among these, particularly highly confidential IDs, passwords (including hashed data), and encryption keys or trigger information for generating them may be prepared in multiple sets in advance, and one of them may be switched by a switching header.Furthermore, the user authentication information storage unit 21b, device authentication information storage unit 21c, encryption key information storage unit 21d, etc., which store this information, are provided in a memory area that cannot be accessed from the outside, such as a secret area in the memory area of the CPU.
[0054] 3 is a diagram showing the data structure of the user authentication information stored in the user authentication information storage unit 21b. The user authentication information includes a user ID and a password set via the information terminal 7. It should be noted that the password may be stored as hashed data. In this example, two information terminals 7 are connected to one communication device 2 via the internal network 6, and therefore two sets of user authentication information are also stored.
[0055] 4 to 7 are diagrams showing the data structure of the device authentication list stored in the device authentication information storage unit 21c. This device authentication list stores the same information in all communication devices 2 and management devices 3. In the example shown in the figures, the device authentication information storage unit 21c is a data table adapted to a highly versatile relational database such as Oracle (trademark) or MySQL (registered trademark).
[0056] The device authentication list stored in the device authentication information storage unit 21c is a list of device authentication information required for authenticating each communication device 2 and management device 3 for all communication devices 2 and management devices 3 in the same group. The device authentication list 21c1 shown in FIG. 4 has the following fields: "Device ID" which is an initial ID; "Last name" which stores the user's last name; "First name" which stores the user's first name; "Email" which stores the user's email address; "Authority" which stores the authority as to whether the user is a general user or an administrator; "Affiliation" which stores the company ID (organization ID) of the company to which the user belongs; "Status" which stores the user's status (in this example, either valid or invalid); and "Update date and time" which stores the date and time when the user's information was updated.
[0057] Incidentally, the email address may be used as an ID when the user undergoes device-to-device authentication. Furthermore, while the "last name" and "first name" stored in the device authentication information storage unit 21c are, in principle, real names, they may be abbreviations derived from the project, personal nicknames, handle names, etc., from the perspective of making it difficult to identify individuals. In this case, a corresponding field is prepared.
[0058] 5 is a diagram showing the data structure of the device authentication list 21c2. This device authentication list 21c2 has the following fields: a "device ID" which is an initial ID, a "switching header" for switching passwords, a "password," and "password hash data." Because this device authentication list 21c2 requires a particularly high level of confidentiality, tens to hundreds of pairs of passwords and their hash data are prepared for each device ID, and one pair is switched for use at a predetermined timing using the switching header. The device authentication list 21c2 has a many-to-one relationship with the device authentication list 21c1 based on the device ID.
[0059] 6 is a diagram showing the data structure of company information, which is device authentication list 21c3. In the example shown in the figure, the company information has, as fields, a "company ID (organization ID)" which is an initial ID, and a "company name" which stores the company name of the company ("organization name" which stores the organization name of the organization). Incidentally, the above-mentioned device authentication list 21c1 has, as a field, the company ID which is the initial ID of this company information, and there is a many-to-one relationship between device authentication list 21c1 and device authentication list 21c3. Note that, like the personal names ("last name" and "first name") in device authentication list 21c1, the "company name" in this device authentication list 21c3 may be an abbreviation derived from the project, or a nickname or handle name of the company, from the perspective of making it difficult to identify the actual company.
[0060] 7 is a diagram showing the data structure of group information, which is the device authentication list 21c4. The group information has fields such as "group ID" which is an initial ID, "group name" which is the name of the group, "member 1," "member 2," ... "member n" which store the device IDs of users belonging to the group, and "update date and time" which stores the date and time when the group information was updated.
[0061] The number of users that can be registered in each group (for example, n people in the example shown in Fig. 7) is determined when the data structure is decided, so it is necessary to ensure an appropriate number that is neither too many nor too few. Furthermore, in order to obtain information about each user to be registered in the group from the device authentication list 21c1, this group information has a field for "device ID," which is the initial ID of the device authentication list 21c1, and this creates a many-to-one relationship between the device authentication list 21c4 and the device authentication list 21c1.
[0062] 8 is a diagram showing the data structure of encryption key information stored in the encryption key information storage unit 21d. (a) in the figure shows common key information 21d1. Dozens to hundreds of types of common keys are prepared in advance in the common key information 21d1, and one of these common keys is selected and used by the switching header. In this example, the common key is common to all communication devices 2 and management device 3, but a different common key may be prepared for each communication partner or for each management unit such as a region or department within the same group. In this case, the number of types of common keys to be prepared increases, but the risk of a common key being stolen is reduced.
[0063] FIG. 1(b) shows private key / public key information 21d2. The private key / public key information 21d2 also has several tens to several hundreds of types of private keys / public keys prepared in advance, and one pair of these is selected and used by the switching header. FIG. 1(c) shows public key information 21d3 of each communication device 2 and management device 3. The public key information 21d3 contains a number of private keys / public keys for each device ID. Ten to several hundred types of public keys are prepared in advance, and one of these is selected and used by the switching header. Note that the common key information 21d1 and the public key information 21d3 for each communication device 2 and management device 3 are stored as information common to all communication devices 2 and management devices 3, while the private key / public key information 21d2 is stored only in that communication device 2 or management device 3. However, the public key among them is stored in a location in the public key information 21d3 for each communication device 2 and management device 3 that corresponds to its own device ID.
[0064] 9 is a table showing the data structure of the target data storage unit. The target data storage unit 21f has the following fields: a "data ID" which is an initial ID; a "subject" which stores the subject of the target data; a "confidentiality level" which indicates the confidentiality level of the target data in multiple stages; a "viewing period" which indicates the period during which the target data can be viewed with a start and end date; a "number of views" which stores the number of times the target data can be viewed; a "number of views" which stores the remaining number of times a user who received the target data can view it on their own information terminal 7 at that time; a "sender" which stores the device ID of the user who sent the target data; a "receiver" which stores the device ID of the user who receives the target data; a "comment" which stores a comment from the sender included in the target data; a "data storage destination" which stores information on the storage destination of the main data of the target data (e.g., an image file, a video file, etc.); and a "transmission date and time" which stores the transmission date and time of the target data.
[0065] In the illustrated example, the confidentiality level is set to three levels: "Confidential" (0) which is a low confidentiality level, "Important" (1) which is a medium confidentiality level, and "Confidential" (2) which is a high confidentiality level. The start date of the viewing period is always set after the date and time of transmission. Of course, this start date can also be set after a predetermined period has elapsed since the date and time of transmission. The number of times the viewing is permitted can be specified between once and unlimited (in the illustrated example, there are two levels: once or unlimited). Furthermore, the target data storage unit 21f has a field for "device ID," which is the initial ID of the device authentication information storage unit 21c, in order to acquire information on the user who will be the sender and information on the user who will be the recipient from the device authentication information storage unit 21c. Therefore, the target data storage unit 21f and the device authentication information storage unit 21c have a many-to-one relationship. Incidentally, when a user (sender) belonging to a certain group designates one or more users from among multiple users belonging to this group as recipients (destinations), data having each field of the target data storage unit 21f is prepared for each recipient and stored in the target data storage unit 21f.
[0066] Furthermore, with regard to this target data storage unit 21f, in relation to the transmission and reception of target data, the same data is stored separately in the memory unit 21 of the sending communication device 2A and the memory unit 21 of the receiving communication device 2B. Furthermore, target data whose viewing period has expired may be deleted from the target data storage unit 21f of the memory unit 21, 21 of the sending communication device 2A or the receiving communication device 2B.
[0067] As shown in Fig. 2, the control unit 22 realizes various functions by programs executed on an OS. This OS may be a general-purpose OS such as Windows (registered trademark) or Linux (registered trademark), or may be a proprietary dedicated OS, or multiple OSs (for example, one general-purpose OS and one dedicated OS) may be used in combination. When multiple OSs are used in combination, a dual boot method may be used, or a method of virtually running one OS on another may be used. In this example, a single open-source general-purpose OS such as Linux is used.
[0068] The control unit 22 includes an encryption unit 22a that encrypts data to generate ciphertext, and a decryption unit 22b that decrypts the ciphertext encrypted by the encryption unit 22a of the other communication device 2 to generate plaintext. a password providing unit 22d that provides passwords used for encryption, decryption, user authentication, etc.; an encryption communication unit 22e that performs encrypted communication between the communication devices 2, 2 or between the communication device 2 and the management device 3; a user authentication unit 22f that performs user authentication of a user who accesses the communication device 2 by an information terminal 7; an inter-device authentication unit 22v that performs inter-device authentication between the communication device 2 and another communication device 2 or the management device 3; and a GUI (Graphical User Interface) that provides a GUI to the information terminal 7 connected via the internal network 6 on the side where the communication device 2 is located. an input / output unit 22g such as a web server that provides a user interface such as a user interface (UI), a data receiving unit 22h that receives target data from the information terminal 7; a data transmitting unit 22i that transmits the target data received by the data receiving unit 22h and encrypted by the encryption unit 22a to the target receiving communication device 2B; a canceling unit 22j that cancels the exchange of target data between the sending information terminal 7A and the receiving information terminal 7B; a data receiving unit 22k on the receiving information terminal 7B side that receives the target data from the sending communication device 2A; a data distribution unit 22l that distributes the target data decrypted by the decoding unit 22b to the target receiving side information terminal 7B; a viewing restriction unit 22m that restricts the distribution of the target data by the data distribution unit 22l based on information such as a viewing period and the number of viewings included in the target data (transmission data); a packet control unit 22n that controls communication (packets) via at least one of the two network interfaces 23 and 24; and a communication history information storage unit 21g that sequentially stores and accumulates communication history information from the two communication interfaces 23 and 24 in the above-mentioned communication history information storage unit 21g and also stores and accumulates the communication history information from each of the state detection sensors 25, 26,27 in the above-mentioned sensing information storage unit 21h, a history analysis unit 22p that analyzes history information such as communication history information and sensing information stored in the storage unit 21 and stores the results of the analysis in the history analysis information storage unit 21i of the storage unit 21 as the above-mentioned history analysis information, an abnormality determination unit 22q that determines various abnormalities in the communication device 2 based on the history information and the history analysis information, and a communication restriction unit 22r that restricts (specifically, prohibits or limits the areas in which communication is possible) communication via the communication device 2 when an abnormality is determined by the abnormality determination unit 22q.
[0069] Furthermore, the control unit 22 may be provided with a communication path selection unit 22s that selects one communication path from among multiple communication paths between the communication devices 2, 2 or between the communication device 2 and the management device 3 when multiple communication paths exist. Furthermore, when communicating with a communication partner other than a user in the group, the communication path selection unit 22s may be configured to use a GUI corresponding to the communication partner. If communication with users other than the communication group is also possible depending on the confidentiality level of the data to be transmitted and received, the communication path selection unit 22s may also function to select data transmission and reception via a normal communication path that does not go through the communication device 2 and the management device 3 depending on the IP address of the destination.
[0070] The encryption unit 22a encrypts the target data or various other information exchanged between the communication devices 2, 2 using a predetermined algorithm. When encrypting the target data, the encryption strength is changed depending on the confidentiality level set for the target data (the "confidentiality level" in the target data storage unit 21f). Encryption may be performed multiple times using different algorithms or encryption keys. It is also possible to divide the data into multiple data segments, change the order of the segments, and use a scrambling process to encrypt each data segment as appropriate. In this case, encryption for each data segment may be performed once or multiple times, and the algorithm, encryption key, and number of times may be different for each data segment. The decryption unit 22b decrypts the ciphertext encrypted by the encryption unit 22a of the other communication device 2 using a predetermined algorithm corresponding to the encryption algorithm used by the encryption unit 22a.
[0071] 10 is a conceptual diagram showing the configuration of the encryption unit and the decryption unit. The encryption unit 22a includes an input unit 22a1 that receives input of plain text (for example, target data, etc.), and an input unit 22a 1, and output means 22a3 that outputs ciphertext (e.g., target data, etc.) encrypted by the encryption means 22a2. When encryption is performed by the encryption means 22a2, an encryption key including encryption information is provided to the encryption means 22a2 from the encryption key information storage unit 21d of the communication device 2 or by the encryption key providing unit 22c. On the other hand, the decryption unit 22b has an input means 22b1 that accepts input of ciphertext (e.g., target data, etc.), a decryption means 22b2 that decrypts the ciphertext input by the input means 22b1, and an output means 22b3 that outputs the plaintext (e.g., target data, etc.) decrypted by the decryption means 22b2.
[0072] The encryption key provided to the encryption means 22a2 and the encryption key provided to the decryption means 22b2 must be the same or corresponding encryption keys, specifically, a combination of the same common key or a combination of a corresponding private key and public key. For example, a ciphertext encrypted by the encryption unit 22a of the sending communication device 2A is transmitted to the receiving communication device 2B via the outgoing network interface 24 of the sending communication device 2A. The receiving communication device 2B receives the ciphertext via the outgoing network interface 24 of the receiving communication device 2B and decrypts it using the decryption unit 22b of the receiving communication device 2B to generate decipherable plaintext.
[0073] In this case, the encryption key used by one of the two communication devices 2A, 2B must be the same or correspond to the encryption key used by the other. For example, this may be a combination of common keys or a combination of a private key and a public key corresponding to the private key. In this communication system, multiple pairs of identical or corresponding encryption keys are pre-stored in the memories 21, 21 of the two communication devices 2A, 2B, respectively, enabling communication in an encrypted environment immediately after installation of the communication devices 2A, 2B. Note that when a common key is used as the encryption key, the memories 21, 21 of each communication device 2A, 2B may pre-store a password or other trigger information used to generate the common key, rather than the common key itself. In this case, the common key is generated by the communication devices 2A, 2B and the management device 3 using the same algorithm and at the same time.
[0074] Furthermore, encryption by encryption unit 22a may be performed multiple times on the same data, changing the encryption key each time. In this case, the ciphertext output from output means 22a3 is returned to input means 22a1. Meanwhile, decryption unit 22b can also return data output from output means 22b3 to input means 22b1 in response to this. Decryption unit 22b can then decrypt the same data encrypted multiple times using an encryption key that is the same as or corresponds to the encryption key used for the encryption, in the reverse order to that used for the encryption, thereby obtaining the original plaintext. Furthermore, decryption unit 22b may have a "temporary decryption mode" and function to automatically re-encrypt data once viewing or working with it has finished after decryption. The common key, public key, and private key used for encryption and decryption are stored in the encryption key information storage unit 21d as described above, and are read out and used as needed. However, they may be generated separately by the encryption key providing unit 22c and used. The encryption key providing unit 22c may provide the generated encryption key to the encryption unit 22a or the decryption unit 22b, or may store it in the storage unit 21.
[0075] 11 is a conceptual diagram showing the configuration of encryption key providing unit 22c. Encryption key providing unit 22c has encryption key generating means 22c1 that generates an encryption key, random number generating means 22c2 that generates true random numbers or pseudo-random numbers used to generate the encryption key, information input / output means 22c3 that inputs and outputs information to and from storage unit 21, and encryption key output means 22c4 that outputs an encryption key used in encryption unit 22a and decryption unit 22b.
[0076] The random number generating means 22c2 receives uncertain information (for example, True random numbers are generated by using trigger information (for example, the timing of pressing a keyboard), or pseudo-random numbers are generated by using a password or other definite trigger information. When generating true random numbers, a Radon pulse generator or the like may be used. The password is provided to the random number generation means 22c2 from the password providing unit 22d. Other definite trigger information is output from the secret area of the storage unit 21 to the random number generation means 22c2 via the information input / output means 22c3. When generating pseudo-random numbers, a conventionally known means such as an LFSR (linear feedback shift register) is used. The encryption key generating means 22c1 generates an encryption key based on the random number from the random number generating means 22c2 and the trigger information acquired from the secret area of the storage unit 21 via the information input / output means 22c3.
[0077] Encryption key output means 22c4 outputs the encryption key generated by encryption key generation means 22c1 or the encryption key acquired from storage unit 21 via information input / output means 22c3. On the other hand, the encryption key generated by encryption key generation means 22c1 can be stored in a secret area of storage unit 21 via information input / output means 22c3.
[0078] The password providing unit 22d provides passwords (information) used for user authentication, authentication between communication devices 2, 2 for encrypted communication, authentication between the communication device 2 and the management device 3, and generation of the encryption key mentioned above.
[0079] 12 is a conceptual diagram showing the configuration of the password providing unit 22d. The password providing unit 22d has a password generating means 22d1 that generates a password, a random number generating means 22d2 that generates a true random number or a pseudo-random number used to generate the password, an information input / output means 22d3 that inputs and outputs information to and from the storage unit 21, and a password output means 22d4 that outputs password information. The random number generation means 22d2 generates true random numbers by utilizing uncertain information (such as the timing of pressing a keyboard) input via the input / output unit 22g or the like, or generates pseudo-random numbers by utilizing determined trigger information. As in the above case, a Radon pulse generator or the like may also be used for generating true random numbers. The trigger information is acquired from a secret area of the storage unit 21 via the information input / output means 22d3.
[0080] Since pseudo-random numbers are generated with a certain degree of periodicity, it is also possible to introduce the concept of a one-time password when generating pseudo-random numbers between two communication devices 2, 2. This one-time password can be used for user authentication, communication encryption, authentication between the communication devices 2, 2, and authentication between the communication device 2 and the management device 3. As an example, when a one-time password is used for user authentication, a token may be provided to the user, and the password may be generated using the token. In this case, however, it is desirable to also incorporate check data (correction signal) so that synchronization can be corrected midway. For example, a check digit or the like used for the purpose of detecting code errors may be used to correct any deviations in the synchronization process.
[0081] Password generation means 22d1 generates a password based on the random number generated by random number generation means 22d2, trigger information acquired from the secret area of storage unit 21 via information input / output means 22d3, etc. The generated password is passed to password output means 22d4, or is stored in the secret area of storage unit 21 via information input / output means 22d3. The password output means 22d4 receives and outputs a password from the password generation means 22d1, and may also receive and output a password directly from the input / output unit 22g that the user input via the information terminal 7, or may output a password acquired from a secret area of the storage unit 21 via the information input / output means 22d3. The output password is output to each unit such as the input / output unit 22g and the encryption key provision unit 22c as necessary.
[0082] 2, the encryption communication unit 22e performs encrypted communication between the communication device 2 and another communication device 2 and between the communication device 2 and the management device 3. In other words, communication between the communication devices 2, 2 (inter-device communication) or communication between the communication device 2 and the management device 3 (inter-device communication) is encrypted by the encryption communication unit 22e. In this example, during this inter-device communication, the devices are connected to each other via VPN (inter-device connection) using protocols such as IPSec (IP Security Architecture) or PPTP (Point-to-Point Tunneling Protocol), and tunneling and A secure communication path is established using encryption. The encryption unit 22a and decryption unit 22b are used for encryption and decryption, but encryption and decryption may also be performed independently by the encryption communication unit 22e. Incidentally, the settings for this VPN connection are made in advance and do not need to be made at the time of installation.
[0083] A device authentication list, which is information for authentication (device-to-device authentication) used in this encrypted communication, is stored in the device authentication information storage units 21c, 31c of each communication device 2 and the management device 3. This device authentication list is set when the communication device 2 is shipped and is stored in the storage unit 21 so that it cannot be accessed from outside, providing a secure system in operation that prevents leakage via the user. When trigger information is used, it is also possible to set a trigger timing such as a set time or a transmission operation, and generate device authentication data based on the trigger information. Incidentally, between devices that perform encrypted communication, it is necessary for each device to hold the same or corresponding device authentication list and encryption key information, but between devices that do not perform encrypted communication, it is not necessary for each device to hold such common information. In addition, connection information for other communication devices 2 and management device 3 with which data may be exchanged is pre-stored in connection information storage unit 21a of memory unit 21, and does not need to be reconfigured when introducing communication device 2.
[0084] The user authentication unit 22f performs user authentication on a user who requests access (login) to the communication device 2 using the information terminal 7, based on the information stored in the user authentication information storage unit 21b of the storage unit 21, and determines whether to permit access. Incidentally, to prevent "spoofing" due to leakage of the ID or password, user authentication may be performed using a one-time password, as described above. Furthermore, since "spoofing" becomes possible if the ID or password is leaked, it is desirable to perform personal authentication of the user and device-to-device authentication of the communication device using multi-stage authentication that combines multiple authentication methods or multi-factor authentication method that combines multiple elements. Furthermore, user authority and information disclosed to the user may be added or changed each time this multi-stage authentication progresses.
[0085] The device authentication information storage unit 21c stores a sufficient number or the maximum number of pieces of user information as temporary users in advance, and when a new user is to be registered, the information of one temporary user registered in the device authentication information storage unit 21c is changed and updated from the management device 3 side (more specifically, from the information update unit 32h described later). Incidentally, users permitted to access (log in) by the inter-device authentication unit 22v are limited to users whose "status" in the device authentication information 21c1 is set to valid (1). Furthermore, this "status" information is also set to invalid (0) for temporary users, and by switching this to valid (1) from the management device 3 side, the user can use the communication system. However, this switching between valid and invalid is not limited to these methods.
[0086] Similarly to the device authentication list 21c1, the device authentication list 21c2, which lists company information, also stores a sufficient number or maximum number of pieces of temporary company information in advance. Similarly, the device authentication list 21c3, which is group information, also stores a sufficient number or maximum number of pieces of group information, including information on temporary groups, in advance. This information is stored by the management device 3 (more specifically, the information update unit 32h described later). The maximum number of temporary users is registered in advance in the temporary group. The maximum number of temporary users can be requested by the group administrator at the time of installation, or the number of temporary users that has been set in advance can be confirmed.
[0087] The input / output unit 22g provides a GUI to the information terminal 7 of a user who is permitted to access, and receives input from the information terminal 7. The input / output unit 22g is configured by a Web server or the like.
[0088] The data receiving unit 22h receives the target data from the user's sending information terminal 7A via the input / output unit 22g. The user who will be the sender first uses the sending information terminal 7 to select one of the groups to which the user belongs. At this time, the user may select one group based on the purpose of communication. Next, the user selects one or more users (recipients) from this group to whom the target data is to be sent, determines the number of times and period for which the recipients are allowed to view the data, and passes the target data, including this series of information, to the sending communication device 2A.
[0089] In this way, the necessary information for the target data received by the data receiving unit 22h is stored in the target data storage unit 21f of the memory unit 21 of the sending communication device 2A, and is encrypted by the encryption unit 22a using an encryption key. Incidentally, this target data is generated individually for each user to whom it is to be sent, or linked to the target data. For example, when sending to three users, three pieces of target data are generated or linked to the target data. Furthermore, when encrypting the target data, the security strength, which is determined by the presence or absence of encryption and the number of times encryption is performed, is changed depending on the confidentiality level. Since the communication itself is encrypted, it is also possible to omit encryption of the target data itself when the confidentiality level is at its lowest.
[0090] The data transmitting unit 22i transmits the target data encrypted by the encryption unit 22a to the receiving communication device 2B of the receiving information terminal 7B of the user designated as the destination. Incidentally, the data transmitting unit 22i may transmit the target data immediately, or may wait until the start of the browsing period has elapsed before performing the transmission process.
[0091] The data receiving section 22k receives the target data from the transmitting side communication device 2A.
[0092] As described above, the target data received by the data receiving unit 22k is encrypted ciphertext, and is therefore decrypted into plaintext by the decryption unit 22b. This decryption is performed using the same or corresponding encryption key as that used for encryption. If the data receiving unit 22k of the receiving communication device 2B receives the confidentiality level of the target data from the data transmitting unit 22i of the transmitting communication device 2A, the decryption can be performed quickly and accurately. However, if rules according to the confidentiality level are determined in advance, it is not necessary to exchange this confidentiality level information between the two communication devices 2A and 2B.
[0093] Of the target data that has become plain text, the necessary information is stored in the target data storage unit 21f of the storage unit 21 of the receiving-end communication device 2B.
[0094] The data delivery unit 22l delivers the target data to the receiving information terminal 7B in response to a request from the receiving information terminal 7B of the user who is the recipient of the target data. Note that the data delivery unit 22l may also deliver the target data to the receiving information terminal 7B autonomously at a predetermined timing. However, delivery by the data delivery unit 22l is permitted only when viewing is not restricted (prohibited) by the viewing restriction unit 22m.
[0095] When the number of times (remaining) the target data has been viewed is 0, the viewing restriction unit 22m restricts the viewing of the target data. If the period is not yet reached, if the number of times (remaining) that the sender has prohibited viewing is marked with a prohibition symbol such as "x," if the system administrator of the management device 3 receives a request for prohibiting viewing from the group administrator, or if viewing is prohibited for management reasons from the system administrator, the distribution of the target data to the receiver's information terminal 7B is restricted (prohibited). The viewing period has a start and end, and the period between the start and end is the period during which viewing is possible. This start can be set to the time when the sender's information terminal 7A passes the data to the sender's communication device 2A, or a predetermined time after that time. In the latter case, the receiver can view the target data after the predetermined time has elapsed since the sender sent the data.
[0096] The cancellation unit 22j performs the cancellation process on the transmitting communication device 2A side when there is a request to cancel the transmission (delivery) of the target data from the transmitting information terminal 7A. Specifically, if the target data has not yet been transmitted by the data transmission unit 22i before the start of the browsing period, the cancellation unit 22j cancels the delivery by deleting the target data stored in the memory unit 21 of the transmitting communication device 2A or canceling the transmission process. On the other hand, if the target data has already been transmitted by the data transmission unit 22i, the cancellation unit 22j cancels the delivery by remotely deleting the target data stored in the memory unit 21 of the receiving communication device 2B or canceling the delivery process of the target data itself on the receiving communication device 2B side. If the target data has been copied, the duplicated target data is also erased.
[0097] During this cancellation process, hash data or the like may be used to determine whether the cancellation instruction is valid. Specifically, for example, the sending information terminal 7A and the receiving information terminal 7B store a common hash program and common key in secret. The sending information terminal 7A concatenates a cancellation instruction code and the common key together with the cancellation instruction, hashes the result, and sends the hashed result to the receiving information terminal 7B. Upon receiving the cancellation instruction, the receiving information terminal 7B compares the hashed result of concatenating the cancellation instruction code and the common key with the received hash value. If the hashed values match, the receiving information terminal 7B determines that the cancellation instruction code has not been tampered with and that the cancellation instruction was issued by a legitimate sending information terminal 7A. At this time, user authentication may be performed again to confirm whether the cancellation instruction was issued by a user with proper authorization. An example of a user with proper authorization (hereinafter simply referred to as "user") may be the user who actually sent the target data, the group administrator, or the group registration manager. When registering a group administrator or group registration manager, the system administrator must provide a personal identification certificate (copy) to verify that the manager is the registered person. You will need to verify this with a genuine driver's license, etc.
[0098] This cancellation process from the transmitting communication device 2A makes it possible to deal with cases where incorrect target data has been delivered, improving convenience. Incidentally, even if the target data viewing period has not yet begun, if the delivery to each recipient's receiving information terminal 7B has not actually been made, the delivery can be canceled by the same process. Incidentally, to enable this data deletion, something like a deletion flag may be included in the data at the time of transmission, and this deletion flag may be normally set to OFF, and data deletion may be performed when the flag is switched ON.
[0099] The packet control unit 22n controls communications via the two network interfaces 23 and 24.
[0100] For example, when an information terminal 7 located in the internal network 6 to which the communication device 2 belongs communicates via the external network 1, the communication (packet) from the information terminal 7 passes through the communication device 2 because of the network configuration described above. The communication packet arriving at the inbound network interface 23 from the information terminal 7 is transferred to the router 4 via the outbound network interface 24, and then the router 4 Therefore, it is sent to external network 1.
[0101] In other words, the communication device 2 can acquire not only the communication history of the communication device 2 but also the communication history of the information terminal 7 on the internal network 6 side, and the packet control unit 22n controls communication packets so that this can be done.
[0102] In addition, this packet control unit 22n can control communication packets so that the communication device 2 functions as a router, and can also control communication packets so that a firewall is constructed on the inbound network interface 23 side and a firewall is constructed on the outbound network interface 24 side.
[0103] Furthermore, by using this packet control unit 22n, it becomes possible to respond to DoS attacks against IKE used in VPN connections in real time to some extent, and such information can also be analyzed by the history analysis unit 22p.
[0104] The history information accumulation unit 22o sequentially stores, as communication history, the communication history of the communication device 2 and the history of communications of the information terminal 7 belonging to the internal network 6 to which the communication device 2 belongs via the external network 1 or access communications to the communication device 2 in the communication history information storage unit 21g of the memory unit 21. In addition, the history information accumulation unit 22o sequentially stores sensing results of various sensors such as the GPS sensor 25, the acceleration sensor 26, and the gyro sensor 27 in the sensing information storage unit 21h of the memory unit 21 as sensing information (sensing history information).
[0105] The history analysis unit 22p analyzes the communication history. Specifically, the history analysis unit 22p analyzes the daily operating status, which includes the working days of each organization (for example, the company itself or a specific department of the company) constituting the internal network 6 and the working status of each user, from the communication history at that time and the communication history stored in the history information accumulation unit 22o, and stores the analysis results sequentially in the history analysis information storage unit 21i. Note that DoS attacks and other external attacks such as those described above can also be recognized by this analysis.
[0106] Furthermore, the history analysis unit 22p may automatically determine the information terminal 7 of the user accessing the communication device 2 based on the above-mentioned operating status, and the results may also be stored sequentially as analysis results in the history analysis information storage unit 21i.
[0107] Furthermore, the normal state of the communication device 2 may be analyzed based on the state detection results acquired from the GPS sensor 25, the acceleration sensor 26, and the gyro sensor 27, and the sensing history information stored in the sensing information storage unit 21h, and the analysis results may be stored in the history analysis information storage unit 21i of the memory unit 21. Furthermore, the communication device 2 may be configured to be able to communicate only during certain time periods, or may be connected to specific sensors used in IoT (various sensors such as temperature sensors, human presence sensors, and ID cards, as well as surveillance cameras, etc.).
[0108] The abnormality determination unit 22q determines whether the communication device 2 is in an abnormal state based on the sensing result, the analysis result of the communication history, and the like.
[0109] For example, when the GPS sensor 25 detects that the position of the communication device 2 connected to the PC has changed, the abnormality determination unit 22q determines that there is an abnormality, since there is a possibility of theft or the like. Specifically, first, when the communication device 2 is introduced, the location information when the power is first turned on is recognized as the installation location of the communication device 2. Next, if the location information acquired by the GPS sensor 25 or the latest location information stored in the sensing information storage unit 21h differs from the installation location, an abnormality is determined, but if they match, a normality is determined. In addition, by obtaining the sensing history or its analysis information of the GPS sensor 25 from the sensing information storage unit 21h or the history analysis information storage unit 21i and comparing this information, the sensing error of the GPS sensor 25 can be corrected to a considerable extent.
[0110] Furthermore, if the gyro sensor 27 or the acceleration sensor 26 detects a change in the attitude of the communication device 2 connected to the PC or the application of a load, the abnormality determination unit 22q also determines that an abnormality has occurred, as this may indicate theft or other theft. Specifically, if the attitude information or load information acquired by the gyro sensor 27 or the acceleration sensor 26, or the most recent attitude information or load information stored in the sensing information storage unit 21h, is an abnormal value different from normal, the abnormality determination unit 22q determines that the communication device 2 is normal. Incidentally, by using the attitude information or load information stored in the sensing information storage unit 21h and the analysis information of the attitude information or load information stored in the history analysis information storage unit 21i, the accuracy of determining whether the communication device 2 is normal or abnormal can be improved. Furthermore, if the communication device 2 is moved due to an earthquake, fire, or other reason, the sensor information is notified to the management device 3, and an abnormality response is performed. The abnormality response may include informing all users belonging to the group or interrupting communication via the corresponding communication device 2.
[0111] In the case of a mobile terminal communication device 2, it operates when the time code for time authentication or the authentication check instructed to the terminal device is passed, and stops operating if an abnormality is detected. The authentication check is performed by image authentication using a camera, fingerprint authentication, or voice authentication, either alone or in combination.
[0112] Furthermore, the abnormality determination unit 22q uses the analysis information of the communication history stored in the history analysis information storage unit 21i to determine whether the communication is normal or abnormal based on past and present communication histories acquired from the two network interfaces 23 and 24 and the communication history information storage unit 21g. Specifically, the abnormality determination unit 22q determines whether the communication is normal or abnormal, such as unauthorized access or unauthorized work, or overload, based on access from the user's information terminal 7 and the work status associated with that access, access from the information terminals 7 of companies, departments, users, etc. that are expected to be on holidays and the work status associated with that access, and whether there is an abnormal increase in the normal load, etc. Furthermore, the communication histories of all communication devices 2 are periodically sent to the management device.
[0113] When the abnormality determination unit 22q determines an abnormality, the communication restriction unit 22r restricts (prohibits) data exchange and communication via the communication device 2 determined to be abnormal. When communication is restricted in this manner, the exchange of the target data described above is also prohibited. Incidentally, at this time, communication devices 2 other than the communication device 2 determined to be abnormal maintain their communication functions in an unrestricted state, and it is possible to continue sending and receiving target data within the same group. When such an abnormality as unauthorized access or unauthorized operation is determined, a change of password, encryption key, etc. may be performed instead of or in addition to the communication restriction described above.
[0114] The communication device 2 configured as described above can function as a transmitting communication device 2A and can also function as a receiving communication device 2B. Of the components included in the control unit 22, the data receiving unit 22h, the data transmitting unit 22i, and the canceling unit 22j are functions dedicated to the transmitting side, while the data receiving unit 22k and the data delivering unit 22l are functions dedicated to the receiving side. Therefore, when the communication device 2 is dedicated to the transmitting communication device 2A, the functions dedicated to the receiving side can be omitted, while when the communication device 2 is dedicated to the receiving communication device 2B, the functions dedicated to the transmitting side can be omitted.
[0115] Next, the configuration of the management device 3 will be described in detail with reference to FIG.
[0116] 13 is an explanatory diagram illustrating the configuration of the management device 3. The management device 3 shown in the figure is composed of a memory area including a secret area of a CPU, a RAM, a ROM, an HDD or an SSD, etc. The device is equipped with a memory unit 31 that temporarily or permanently stores various information, a control unit 32 that is composed of a CPU, RAM, SSD, etc. and executes various programs, and a network interface (communication means) 33 that is connected to the external network 1 side (specifically, the router 4).
[0117] The storage unit 31 may store all information about each communication device 2 that is a target of management by the management device 3, in the same data structure. That is, the storage unit 31 has a connection information storage unit 31a having the same or substantially the same configuration as the connection information storage unit 21a, a user authentication information storage unit 31b having the same or substantially the same configuration as the user authentication information storage unit 21b, a device authentication information storage unit 31c having the same or substantially the same configuration as the device authentication information storage unit 21c, an encryption key information storage unit 31d having the same or substantially the same configuration as the encryption key information storage unit 21d, and a target data storage unit 31f having the same or substantially the same configuration as the target data storage unit 21f. However, unnecessary information may be omitted as necessary. For example, a communication history information storage unit (not shown), a sensing information storage unit (not shown), and a history analysis information storage unit (not shown) correspond to omissible data tables.
[0118] A user registered in the user authentication information storage unit 31b of the storage unit 31 becomes a system administrator who can access the management device 3 via an information terminal (not shown) on the management device 3 side or the information terminal 7 on the communication device 2 side. Therefore, if a user who successfully accesses the management device 3 is able to freely obtain personally identifiable information, all information will be leaked. Therefore, personally identifiable information and non-identifiable information are managed separately. Even if a specific user successfully accesses the management device 3, the personally identifiable information is made inaccessible. Furthermore, the history is checked, and information leakage is constantly monitored by referring to the device authentication list and the presence or absence of access to the storage unit 21 for rewriting the encryption key. The management device 3 is provided by a service provider that provides services for this communication system. Therefore, the system administrator who manages the management device 3 is either the service provider or a person directly commissioned by the service provider. Furthermore, in order to prevent information from being leaked from a system administrator who has access to the management device 3, it is even better to at least double-check access to the user authentication information storage unit with another system administrator, keep all management histories, and adopt a mechanism to make public the management history of the management device 3 from the system administrator as necessary.
[0119] The connection information storage section 31a, device authentication information storage section 31c, and encryption key information storage section 31d in this memory section 31 store connection information for performing encrypted communication with each communication device 2 that is the subject of management, ID information, identical or corresponding encryption keys or passwords, or trigger information for generating these, etc.
[0120] The control unit 32 realizes various functions by a program executed on the OS. The means for using this OS is the same as or substantially the same as the control unit 22. The control unit 32 has an encryption unit 32a having the same or substantially the same configuration as the encryption unit 22a, a decryption unit 32b having the same or substantially the same configuration as the decryption unit 22b, an encryption key providing unit 32c having the same or substantially the same configuration as the encryption key providing unit 22c, a password providing unit 32d having the same or substantially the same configuration as the password providing unit 22d, an encryption communication unit 32e having the same or substantially the same configuration as the encryption communication unit 22e, a user authentication unit 32f having the same or substantially the same configuration as the user authentication unit 22f, an inter-device authentication unit 32v having the same or substantially the same configuration as the inter-device authentication unit 22v, and an input / output unit 32g having the same or substantially the same configuration as the input / output unit 22g.
[0121] In addition to these, the control unit 32 also has an information update unit 32h that updates predetermined information in the storage unit 21 of each communication device 2 that is under management, and a recovery processing unit 32i. When information is updated, the information before the update is also stored without being erased. This information history needs to be stored for at least a certain period of time, such as five years.
[0122] The information update unit 32h updates the information of the communication device 2 that is the subject of management. In other words, when encrypted communication is performed between the communication devices 2, 2, or when target data is exchanged via the communication devices 2, 2 over the external network 1, it is necessary to make at least some of the connection information, user authentication information, device authentication information, and encryption key information that are pre-stored in the storage units 21, 21 of the communication devices 2, 2 identical or corresponding to each other so as to be shared, and the information synchronization for this purpose is performed by the information update unit 32h. Furthermore, since this information synchronization is also required between the communication device 2 and the management device 3, this synchronization process is also performed by the information update unit 32h.
[0123] The information update unit 32h can also register new user, group, and company information. Specifically, the information update unit 32h replaces the temporary user information, company information, or group information stored in the user authentication information storage unit 21b and the device authentication information storage unit 21c in the storage unit 21 of each communication device 2 that is the subject of management or the communication devices 2A and 2B that communicate with each other with the actual data requested by the group administrator after the information has been confirmed. More specifically, the information update unit 32h encrypts the actual data with a common key or a public key and transmits it simultaneously to each communication device 2 via a communication line. Furthermore, when registering user information in the device authentication information storage unit 21c of each communication device 2, the information update unit 32h also performs a process of switching the "status" of the user to valid (1), while when deleting user information, the information update unit 32h also performs a process of switching the "status" of the user to temporarily invalid (0) or permanently invalid (000). In this way, a user who has been switched to invalid becomes the above-mentioned temporary user, and a user who has been switched to permanently invalid (000) becomes an irreversible invalid user.
[0124] Note that, using this information update unit 32h, one or more communication devices 2 may be further interposed on the communication path between the sending communication device 2A and the receiving communication device 2B. In this case, a list of IP addresses of communication devices on the communication path that should receive the data may be included in the transmitted data, and when each communication device receives the data, the IP address may be rewritten to that of the next communication device, and the transmission process may be repeated. In this case, too, communications between the interconnected communication devices 2, 2 are encrypted using the same method as in the above-described embodiment.
[0125] The recovery processing unit 32i executes a process to lift the communication restriction on the communication device 2 whose communication is restricted by its own communication restriction unit 22r. Incidentally, the recovery process by the management device 3 is executed after it is confirmed that the communication restriction can be lifted.
[0126] Next, the processing procedure for exchanging data using this communication system will be described with reference to FIGS.
[0127] FIG. 14 is a flow diagram showing the processing procedures for user authentication and device-to-device authentication when exchanging data using this communication system. First, when this communication system is introduced, the provider of the communication device 2 stores information necessary for confidential communication in advance in the storage units 21 and 31 set in the confidential areas of the CPUs of the communication device 2 and the management device 3. This information includes provisional information about users and groups to be added in the future. The information stored in advance and confidential is device authentication lists 21c1 to 21c4 and encryption key information 21d1 to 21d3. Furthermore, prior to using this communication system, the users of the information terminals 7A and 7B set user IDs and passwords in the communication devices 2A and 2B. These user IDs and passwords are also stored in the user authentication information storage unit 21b of the storage unit 21. Furthermore, the communication device 2 hashes the password using SHA-224, SHA-256, SHA-384, SHA-512, or the like, and stores a pair of the user ID and the hashed password in the storage unit 21 of the communication device 2. As is clear from the above, the only operations a user must perform are to enter a user ID and set a password. The information registered in the device authentication information storage unit 31c can be viewed by all users registered in the group, except for confidential information such as passwords, encryption keys, and trigger information for generating them, which must be kept secret.
[0128] Next, an example of device-to-device authentication processing will be described. When starting communication, the user first starts up the information terminal 7 and inputs a user ID and password or their hash data. Alternatively, the user starts up the GUI and inputs a user ID and password or their hash data via the sending information terminal 7A. The sending communication device 2A compares the stored user ID and password or their hash data with the input user ID and password or their hash data, and if they match, it determines that user authentication has been successful and places the information terminal 7 or GUI in a logged-in state. Note that the GUI, which resembles an envelope, displays some of the address information of the registered user.
[0129] After user authentication is complete, the sending communication device 2A then performs device-to-device authentication with the receiving communication device 2B via the management device 3 by encrypting the device ID and password of the other user (a password hashed using SHA-224, SHA-256, SHA-384, SHA-512, or the like) with a common key or the public key of the management device 3 and transmitting the encrypted password together with an encryption key switching header to the management device 3. The management device 3 decrypts the received device ID and password with the common key or the private key of the management device 3 specified in the switching header, performs device-to-device authentication between the sender and receiver based on the registration information in the device authentication information storage unit 31c, and transmits the authentication result to the receiving communication device 2B.
[0130] The receiving communication device 2B receives the authentication result from the management device 3 and authenticates the sending communication device 2A. As described above, this authentication can be performed using the same procedure as for VPN connection. For example, a message required for authentication, a common key, and a switching header are hashed to generate a message authentication code (HMAC) between the sending communication device 2A and the receiving communication device 2B, and the message and message authentication code are then transmitted and received. The sending communication device 2A and the receiving communication device 2B share a common hash program, and the message authentication code generated from the received message is compared with the received message authentication code. If the two match, device-to-device authentication is considered successful. If the common hash program is switched and used, a hash program switching header is also transmitted.
[0131] In this communication system, encrypted communication is established in advance between two communication devices 2A and 2B using the method described above, and the communication state is maintained. Furthermore, if necessary, a connection state enabling encrypted communication is also established between each communication device 2 and the management device 3. Incidentally, the target data to be exchanged (sent and received) can be a variety of data, including document data, still image data, video data, audio, music, email data, FTP data, as well as sensing data, machine control or sequence control programs, commands, and data.
[0132] Furthermore, the user can change the password and encryption key of the device ID stored in the device authentication information storage unit 21c and the encryption key information storage unit 21d at any convenient time. In this case, the information update unit 32h can transmit a switching header between the communication devices 2, 2 or between the communication device 2A and the management device 3, thereby enabling real-time sharing. That is, changes can be made to a data table related to inter-device authentication between the communication devices 2, 2 in the same group. In addition to changes in the data table, one-time passwords and one-time encryption keys can be generated using the encryption key providing unit 22c and the password providing unit 22d, and these can be shared within the same group by transmitting them as a common key or the like. Furthermore, updated passwords and encryption keys stored in a memory card can be delivered by mail or courier.
[0133] Next, the procedure for encrypting and communicating data after authentication will be described with reference to FIG. First, the transmitting-side information terminal 7A passes target data to the transmitting-side communication device 2A via the input / output unit 22g of the transmitting-side communication device 2A (S101). The transmitting communication device 2A receives this target data by the data receiving unit 22h (S102), and encrypts the received target data by the encryption unit 22a (S103). In this case, the sending communication device 2A encrypts the header information portion, which includes information for communication control, authentication, and encryption, added to the data body of the target data, with the public key of the receiving communication device 2B, and encrypts the data body with the common key. At this time, the header information portion also includes a switching header for the common key and the public key of the receiving communication device 2B.
[0134] The strength (importance) of this encryption is selected depending on the confidentiality level. For example, if the confidentiality level is low (e.g., "Confidential"), no encryption is performed, and only the scrambling process of the re-division and rearrangement process is performed. If the confidentiality level is medium (e.g., "Important"), encryption is performed once. If the confidentiality level is high (e.g., "Confidential"), encryption is performed multiple times. When encryption is performed multiple times, a public key may be used for one of the times and a secret key may be used for the others, or different encryption algorithms may be used. Furthermore, when encryption is performed multiple times, the encrypted data may be further encrypted, or the scrambling process of the re-division and rearrangement may be used, and each divided data may be encrypted using the same or different algorithms or encryption keys as described above. Note that since the communication itself is encrypted, even if encryption is not performed in S103, plaintext is not exchanged. The target data thus encrypted is transmitted to the receiving communication device 2B by the data transmitting section 22i of the transmitting communication device 2A (S104).
[0135] The receiver communication device 2B receives this target data by the data receiving unit 22k (S105), and decrypts the received target data by the decryption unit 22b (S106). Specifically, the header information portion of the received target data is decrypted with the private key, and the main body portion of the target data is decrypted with the common key. Incidentally, the encryption key used to encrypt this target data is stored in advance as common data or corresponding data in the encryption key information storage section 21d of the memory section 21 of the sending communication device 2A and the receiving communication device 2B and shared, and since the settings using this information have already been completed, various settings related to encryption and decryption at the time of installation are not required, and there is no need to send or receive common keys or public keys.
[0136] Furthermore, if necessary, confidential information required for encrypting and decrypting target data may be shared between each communication device 2 and the management device 3. Furthermore, this information may be updated in real time by the information update unit 32h between the communication devices 2, 2, or between the communication device 2A and the management device 3, and shared.
[0137] As mentioned above, encryption and decryption are performed multiple times depending on the confidentiality level, but the decrypting side must also know the information on the type of encryption to be performed depending on the confidentiality level. Possible methods for knowing this information include encrypting the information and including it in the header information, or pre-determining the encryption and decryption method in the communication device 2.
[0138] Furthermore, when decrypting encrypted target data, information regarding the confidentiality level of the target data is also required, and this information is exchanged during direct or indirect communication between the transmitting communication device 2A and the receiving communication device 2B. Specifically, this exchange is performed during operation using the GUIs shown in Figures 12 and 14, which will be described later. The target data thus decrypted is distributed to the receiving side information terminal 7B of the user by the data distribution unit 22l of the receiving side communication device 2B (S107).
[0139] However, this distribution is limited to when the target data is within the viewing period and the remaining number of views is not 0, and in other cases, the distribution is restricted by the viewing restriction unit 22m. Furthermore, when the number of times the target data can be viewed is not "unlimited" (specifically, when a finite value is specified), the data distribution unit 22l performs processing to decrement the number of times the target data is viewed by 1 each time distribution is processed.
[0140] The receiving information terminal 7B receives the target data from the receiving communication device 2B (S108). Incidentally, if multiple destinations are specified, the transmitting communication device 2A generates the same number of target data as the number of destinations, and executes the encryption (S103) and subsequent processes for each of the target data.
[0141] According to the above-described communication structure, in each communication device 2, not only the management device 3 but also the communication device 2 with which the communication is to be performed is identified and set from the time of system installation, but this connection configuration may be updated in real time by the information update unit 32h. In this case, each communication device 2 and the management device 3 may store something like a connection list in the connection information storage unit 21a, and this list may be the target of update.
[0142] If the above-mentioned encrypted communication is to be performed using a one-time encryption key, the following procedure can be followed. After the sending communication device 2A receives the data (S102), it activates the password providing unit 22d to generate a one-time password and requests the receiving communication device 2B to activate the encryption key providing unit 22c. The one-time password is different from the user's password and is generated as a new password for each transmission. The encryption key generated by the receiving communication device 2B is a private key, from which a public key is generated. Next, the generated public key is encrypted using a common key and transmitted to the sending communication device 2A. The sending communication device 2A decrypts the public key of the receiving communication device 2B using the common key, encrypts the target data with the decrypted public key, and then restricts the encrypted target data from being opened using the one-time password. Then, data obtained by linking the restricted-to-open target data and the one-time password is encrypted using the common key.
[0143] The receiving communication device 2B decrypts the received target data using the common key, extracts the one-time password from the decrypted data, and opens the target data. It then decrypts the header information portion of the opened target data using the private key, and decrypts the body portion using the common key.
[0144] Alternatively, the encryption key providing unit 22c may generate a common key. In this case, the common key is encrypted using a public key system and transmitted to the other party. Specifically, the following process is performed: (1) First, the public keys of each communication device are transmitted or set in advance by the system administrator to all communication devices 2 simultaneously or individually. Note that the sender retrieves the public key of the other party (receiver) each time a transmission is made. It may also be possible to do so. (2) The sender generates a common key and encrypts the plaintext with the common key. Since encryption is done with a common key, the encryption time is short. (3) The sender encrypts the generated common key with the public key of the other party (receiver)’s communication device 2. The common key is about tens to hundreds of bits long, so it does not take much time even if encryption is performed using a slow public key method. (4) The sender sends the ciphertext and the common key encrypted with the public key. (5) The recipient decrypts the received "common key encrypted with the public key" using the private key. (6) The recipient decrypts the received ciphertext using the decrypted common key, thereby extracting the plaintext.
[0145] In this case, if the network is eavesdropped on, the eavesdropper will be able to obtain the recipient's public key, the plaintext encrypted with the symmetric key, and the symmetric key encrypted with the public key. Data encrypted with the public key can only be decrypted using the private key, so the eavesdropper cannot obtain the symmetric key. Without the symmetric key, the plaintext cannot be decrypted.
[0146] Next, the configuration of the GUI provided to the information terminal 7 will be described with reference to FIGS. Fig. 16 is an explanatory diagram illustrating the configuration of a group top screen, which is a type of GUI. When a user logs in to the communication device 2 using the information terminal 7 by inputting the user's user ID (or the user's e-mail address) and password, the groups to which the user belongs are displayed, and when the user selects one of these groups, the group top screen 71 shown in Fig. 16 is displayed as a GUI.
[0147] The group top screen 71 includes a shared member display section 71a in which the names (full names) of one or more users belonging to the group are retrieved from the device authentication information storage section 21c and displayed in a list; a received data display operation section 71b (displaying "INBOX") where the logged-in user can click to retrieve target data received by the group from the target data storage section 21f and display a list; a sent data display operation section 71c (displaying "SENDBOX") where the logged-in user can click to retrieve target data sent by the group from the target data storage section 21f and display a list; and a send screen display operation section 71d (displaying "NEW ENVELOPE") where the logged-in user can click to display a send screen 72 (see FIG. 17) where the logged-in user can send target data to one or more other users belonging to the group. Incidentally, the user information may be displayed as an abbreviation, nickname, or handle name to avoid identifying individuals.
[0148] FIG. 17 is an explanatory diagram illustrating the configuration of a transmission screen, which is a type of GUI. The transmission screen 72 has a subject input section 72a for inputting the "subject" (displayed as "envelope name") of the target data storage section 21f, a viewing period input section 72b for inputting the "viewing period" of the target data storage section 21f, a confidentiality level input section 72c for inputting the "confidentiality level" of the target data storage section 21f (displayed as "transmission level") (in the illustrated example, one of the "confidential", "important", and "confidential" radio boxes is selected), and a confidentiality level input section 72d for inputting the "number of times that can be viewed" of the target data storage section 21f (in the illustrated example, a check box for setting the number of times that can be viewed to one is selected). It has a number of times allowed viewing input section 72d for selecting whether to view once or unlimited times by checking or unchecking the box, a destination designation section 72e for designating the "recipient" (displayed as "destination") of the target data storage section 21f (in the example shown, a list of users belonging to the group is displayed, and the recipient to be sent to is selected by checking the check box for each user), a transmission file designation section 72f for designating one or more main data of the target data (displayed as "file"), and a comment input section 72g for inputting a "comment" of the target data storage section 21f.Incidentally, the number of times allowed viewing may be designated by inputting any number.
[0149] 18 is an explanatory diagram illustrating the configuration of the target data display screen. This target data display screen 73 displays the contents of the target data, and is displayed on the same screen as the transmission screen 72, constituting a part of the GUI. Specifically, the target data display screen 73 resembles an envelope that is mailed, and includes a subject display section 73a that displays the "subject" of the target data storage section 21f ("envelope name" in the illustrated example), a sender display section 73b that displays the name (full name) of the "sender" of the target data storage section 21f, a sending date and time display section 73c that displays the "sending date and time" of the target data storage section 21f, a confidentiality level display section 73d that displays the "confidentiality level" of the target data storage section 21f (displays "sending level"), a number of views display section 73e that displays the "number of views" of the target data storage section 21f, and a number of views display section 73f that displays the number of views of the target data storage section 21f. a destination display section 73f in which the "recipients" (destination users) of the target data are listed by name, abbreviation, handle name, etc.; a transmission file display section 73g in which the file names of one or more main data of the target data are listed as transmission files; a comment display section 73h in which "comments" of the target data storage section 21f are displayed; a transmission enable state switching section 73i in which the target data can be sent (handed over) when an image resembling a postage stamp is dragged and pasted to this position in order to send the target data; and a group code (for example, a group code) to which the user who exchanges the target data belongs. and a code display section 73j for displaying the "group ID" etc. of the information storage section 21d.
[0150] In addition, this target data display screen 73 may be a screen simulating a mailing slip in addition to a mailing item, and a screen simulating a mailing slip and a screen simulating a mailing slip may be selected. In addition, in the above example, a screen simulating a vertically long mailing item is also used, but this may be a horizontally long mailing item, and one screen may be selected from a screen simulating a vertically long mailing item, a screen simulating a horizontally long mailing item, and a screen simulating a mailing slip. For example, the sending date and time is not yet determined when the date and time are entered on the sending screen 72, so "****" or a blank is displayed.
[0151] Furthermore, when an image resembling a stamp is pasted into the transmission state switching section 73i as described above, a send button 72h is displayed on the above-mentioned transmission screen 72, and when this send button 72h is clicked, the transmission (handover process) of the target data from the transmitting information terminal 7A is actually executed.
[0152] Furthermore, when one piece of target data is selected from a list of multiple pieces of target data received on this group top screen 71, or when one piece of target data is selected from a list of multiple pieces of target data sent, this target data display screen 73 is also displayed, and in this case, the actual date and time is also displayed as the sending date and time.
[0153] When the received target data is being confirmed, a browsing history display section 73k that displays the recipient's browsing history is also displayed on the target data display screen 73. It is also possible to display this browsing history display section 73k when confirming the transmitted target data, but to do so, it is necessary to synchronize the information stored in the target data storage section 21f between the transmitting communication device 2A and the receiving communication device 2B, and this synchronization process may be performed by the information update section 32h described above. 17 and 18 may be provided as a dedicated interface for each group. In this case, the GUI changes depending on the group, which is error-free and highly convenient.
[0154] According to the communication system configured as described above, an intuitively understandable GUI allows users to exchange target data with high security without having to be aware of complex algorithms.
[0155] In particular, since authentication is performed using multiple factors, including user authentication and device-to-device authentication, high security can be maintained and data can be easily exchanged. Authentication using even more factors (multi-factor authentication) may also be performed. For example, an authentication factor based on location information acquired by the GPS sensor 25 may be added. Specifically, if the GPS sensor 25 detects that the communication device 2 is not in its original location, access based on user authentication or device-to-device connection based on device-to-device authentication may be denied. Furthermore, location information of the region or country of the destination, such as a domestic or international business trip, may be used as part of user authentication to handle cases where the user is not in an authorized region.
[0156] Furthermore, when encrypting and decrypting target data, multiple encryption processes are performed in a redundant manner, i.e., encryption performed by the user using a GUI on the information terminal 7A, and encryption of communication between devices.
[0157] Furthermore, by sharing information in advance and setting it up in advance, the time and effort required for installation is reduced, making this communication system applicable to a variety of industries. It can also be used for data exchange between companies, or between a customer, a design company, a magazine or newspaper company, and a printing company or newspaper factory.
[0158] It can also be used in the patent industry and other legal or financial fields where confidential information is often handled under confidentiality obligations, when exchanging drawing data, translation data, or other confidential information, or when exchanging data with overseas parties.
[0159] Furthermore, by incorporating the information terminal 7 as a module into a digital camera or a built-in camera of a smartphone, it becomes possible to share data captured by multiple cameras, or to share data captured via a PC, and this can be used for communication such as telephone, online conference or video conference systems, online shopping systems, etc., with the bandwidth of the network line secured.In such cases, the process of transferring data to the data receiving unit 22h must be performed automatically by an application or the like.
[0160] In the above example, the target data can also be still image data, video data, or audio data captured by a video conference camera or microphone, or still image data or video data captured by a surveillance camera. Information terminals 7A and 7B may be incorporated into these cameras and microphones. For example, in the case of a surveillance camera, authentication is performed as follows: First, the surveillance camera is connected to an external network 1 (Internet) using, for example, 5G (5th Generation) specifications via a communication device 2. The user accesses their information terminal 7 (personal computer) using a user ID and password and selects the registered surveillance camera ID from the surveillance camera slip GUI. The communication device 2 connected to their information terminal 7 then performs device authentication with the surveillance camera's communication device 2 via the management device 3. If authentication is successful, the user can view and record surveillance camera footage on their information terminal 7.
[0161] The system can also be used for secure communications between color management departments and printing factories, along with a color conversion engine for standardizing color information output by different printers. Furthermore, with the sharing of sensing information and remote control in mind, the system can also be applied to encrypted data communications between automobile control devices and information management centers of automobile manufacturers or traffic control centers (national specialized organizations at police headquarters under the jurisdiction of the Public Safety Commission). In this case, as in the above-mentioned application example, the process of transferring data to the data receiving unit 22h must be performed automatically by an application or the like. This communication system can also be used for communications between automobiles and traffic control centers that control and manage traffic lights. Furthermore, information management centers of road management corporations and the like can warn drivers, provide information for safe driving, or safely provide data to automobile driving devices based on autonomous driving management information, abnormal driving information, road and regional information, etc.
[0162] This communication system can also be used for sending and receiving data between government agencies and local governments, between corporate branches or between branches and head offices, between project members within a company, sending and receiving electronic medical records within medical facilities, sending and receiving important information such as electronic medical records, confidential information, and collaborative design proposals over a wide area, online manuscript submission, electronic post office box services, etc.
[0163] In addition, in a construction project, construction is carried out under information management by multiple groups from multiple companies, from the basic design to the procurement of building materials, purchasing cost management, on-site personnel arrangements, construction progress status, shared information on complaints, legal documents, etc. While keeping the information within this construction project confidential, even those inexperienced in information management can safely transmit information without worrying about security management.
[0164] Additionally, the communication device 2 may be coupled to a heavy object such as a safe to prevent physical theft.
[0165] In this communication system, at least one communication device 2 may be provided with an information update unit (not shown) and a recovery processing unit (not shown) having the same or substantially the same configuration as the information update unit 32h and the recovery processing unit 32i of the management device 3. This makes it possible to omit the management device 3.
[0166] In this case, however, it is necessary to distinguish whether the user accessing this communication device 2 is an administrator who has the authority to manage various settings, etc., for the communication device 2, or a general user who does not have the authority to manage the communication device 2. For this reason, "group administrator" is entered in the "authority" field set in the device authentication information storage unit 21c in the memory unit 21 of the communication device 2, and "user" is entered in the general user authority field.
[0167] In addition, a "guest sending user" who can send or receive temporarily or continuously, or who can only send, and a "guest receiving user" who can receive temporarily or continuously for a limited time, may be provided. The guest sending user and guest receiving user are users who are temporarily granted permission to access the communication device 2. The authority field for the guest sending user is entered as "time-limited sender," and the authority field for the guest receiving user is entered as "time-limited receiver." In this case, the user of the communication device 2 electronically applies to the system administrator via the "group administrator." The system administrator notifies the "group administrator" and the user of the communication device 2 of the permission, registers everyone in the same group to the GUI, and assigns a time-limited password to the "guest sending user" or "guest receiving user." The "guest sending user" or "guest receiving user" is also published in the device authentication list.
[0168] On the other hand, even if the management device 3 is not omitted, the device authentication information storage unit 21c may be provided with fields for "time-limited authority" for an administrator, a general user, a guest sending user, and a guest receiving user. The administrator may further have a function (internal management function) of granting permission to other users within the company to send, receive, update information, etc., or such special authority may be separately input in the "special authority" field, and a user with such special authority may be designated as a "special user," thereby increasing the number of user types.
[0169] A user with the authority of this group manager or special user can give permission to send or receive target data, create new groups, register new users to existing groups, delete users registered in existing groups, etc. Permission to send or receive target data can be given for each user belonging to a group, or for the entire group.
[0170] Furthermore, when setting the guest sending user or guest receiving user, permission from a general user or a group administrator may be required.
[0171] 2, a connection device 28 such as an external storage medium or token or other information terminal with a communication function, such as a camera, smartphone, or tablet, may be provided that is detachably connected to the main body of the communication device 2. This connection device 28 is provided with a connection information storage unit 28a, a user authentication information storage unit 28b, a device authentication information storage unit 28c, and an encryption key information storage unit 28d that have the same or substantially the same configurations as the connection information storage unit 21a, the user authentication information storage unit 21b, the device authentication information storage unit 21c, and the encryption key information storage unit 21d described above.
[0172] The connection information storage unit 28a, the user authentication information storage unit 28b, and the device authentication information storage unit 2 The management device 3's information update unit 32h and the encryption key information storage unit 28d contain various pieces of information that have been added, changed, or deleted from the storage unit 21. Based on this addition, change, or deletion information, the control unit 22 can set a prior notice period or a subsequent reporting period, and can recognize new users, changes or deletions to the authority and other information of existing users, new groups, changes to information in existing groups, the addition of new connection destination communication devices 2, or changes or deletions to connection information for existing communication devices 2. This allows various pieces of information to be updated by connecting the connection device 28 without relying on the information update unit 32h of the management device 3 or the information update unit of the communication device 2. The update may target all of the information described above, or only a portion of the information. This can also be addressed by changing the table described above. In this case, the information to be updated may be a portion of the total information, or all of the information.
[0173] By incorporating such a function, it becomes possible for the user to change and update the network configuration, user information, group information, etc., while reducing the effort required for the user to set up the communication device 2. For example, a general user, guest sending user, or guest receiving user in a certain group can independently create one or more new groups at any time, and this user can become a general user in this new group.
[0174] Incidentally, a user who belongs to a group and has the authority to apply for the addition of a new user to the group is defined as a "group registration manager." This group registration manager uses the public key and common key sent from the system administrator of the management device 3 to electronically apply to the system administrator. The system administrator decrypts the sent application form within the management device 3 and transmits a device authentication list that reflects the new user's device ID and name, as well as the new user's addition information, including the status of switching to "enabled," and information on the deletion of affiliated users, to all communication devices 2 in the group that received the application via the management device 3. At this time, the system administrator of the management device 3 may also transmit hash data of the device authentication list to the communication devices 2 in the group, and check the device authentication list during operation of the management device 3 to prevent data tampering.
[0175] Next, a specific registration method for adding and deleting a new user will be described. First, when adding a new user, the group registration manager electronically requests the system administrator to add the new user. The system administrator, upon receiving the electronic request, filters and checks for viruses on the additional information of the new user, and if there are no problems, encrypts and registers the information in the device authentication list of the management device 3. At the same time, all users in the group are able to view at least a portion of the updated device authentication list, excluding confidential information. The list is also displayed as part of the destination information in the envelope GUI. When the newly registered user enters their user ID and password into their information terminal 7, the communication device 2 hashes the password and stores it in the memory unit 21 along with the user ID.
[0176] When deleting a user, the group registration manager electronically requests the system administrator to delete the user. The system administrator disables communication in the header information of the requested user's information in the device authentication list and registers the change in the device authentication list along with the date, month, and year. All users in the group can view the updated device authentication list, excluding confidential information. Some of the address information is also updated and displayed in the envelope GUI. Even when permanently retiring a number, the header information of the individual name and related information is made permanently disabled.
[0177] Next, a specific registration method for adding a new group will be described. A user in the group electronically applies to the system administrator for new group registration, and the electronic application also includes a certificate certifying that all users in the group have installed the communication device 2. The system administrator filters and checks for viruses on the information of all users in the electronically applied group, and if there are no problems, registers the information of the new group in the device authentication list of the management device 3. Registration is performed by identifying the group ID and device ID of the temporary group and temporary user, and switching from an invalid state to an active state. Meanwhile, when each user of the newly registered group inputs their user ID and password into their own information terminal 7 for setup, the communication device 2 hashes the password and stores it in the user authentication information storage unit 21b of the memory unit 21. All users in the group can view the updated device authentication list, excluding confidential information. It is also displayed as part of the address information in the envelope GUI.
[0178] The system administrator of the management device 3 notifies all users belonging to the group, including the newly registered users, of the updated information of this device authentication list, specifically the group ID and device ID that have become valid, after encrypting the information. In addition to the group registration manager, a user who belongs to the group and manages the group may be designated as a "group management manager."The device authentication list that reflects information about users being added to and deleted from the group may be double-checked by the group registration manager and the group management manager.
[0179] In addition, in the same way as creating a new group, it is also possible to apply to the system administrator of the management device 3 to add a communication device 2. This application includes information such as the company, department name, address, name, alias, and contact information of the main users who make up the group. In addition, the group administrator, group registration manager, or other users can invite users who own the same type of communication device 2 to join the new group, and in this case, they can access each other's communication devices 2 using guest IDs, one-time passwords, etc.
[0180] Adding a new group, adding a user to a group, or applying for these can be done simply by connecting or disconnecting a connection device 28 that has been provided with additional information already set by the system administrator. By repeating such changes, it becomes possible to provide extensibility to the network structure and redundancy in the user and group configuration. This connection device 28 may be provided with the control unit 22, network interfaces 23 and 24, and various information detection sensors 25, 26, and 27 of the communication device 2. In this case, it can be used as a backup in case of a breakdown of the communication device 2. The control unit of this connection device 28 acquires its own location using a GPS sensor, and if this location is not within a certain range (zone), it determines that the device is not installed in its original location, and determines that an abnormality has occurred using the abnormality determination unit 22q. Furthermore, if a timer stored in the connection device 28 detects that the device is being used outside of its original usage time, the abnormality determination unit 22q may determine that an abnormality has occurred. Furthermore, to determine whether the person using the connection device 28 is a legitimate user, the person may be required to provide biometric authentication such as a password, fingerprint, or vein pattern, face authentication, or voice authentication.
[0181] Furthermore, in the data exchanged between the communication device 2 and the management device 3, or between the communication devices 2, 2, dummy information (hereinafter referred to as "fake data") may be included as appropriate in addition to the original data (such as target data, hereinafter referred to as "true data"). It is easy to include this fake data in the exchanged data in a state where it cannot be distinguished from the true data, thereby improving security.
[0182] By using such a highly secure communication system, it is possible to include sensing information or sequence control information for controlling IoT devices in the data exchanged, as well as information collected from devices and M2M information, which is information for controlling devices. This makes it easy to share sensing information and control machines via the external network 1. Furthermore, by providing a secret area in the CPU of the IoT device or M2M device and storing secret information of this communication system in the area, further security can be ensured.
[0183] For example, remote operation such as teleoperation can be realized by exchanging information with an IoT device that incorporates an information terminal 7 and is connected to or incorporates the communication device 2. More specifically, an operation device (control device) incorporating the information terminal 7 is connected to an actuation device incorporating the information terminal 7 via the network 1, and the operation device and the actuation device also incorporate or are connected to the communication devices 2, 2, respectively, functioning as an IoT device and an M2M device, and sharing sensing information and sequence information with each other through intercommunication. Therefore, the operation device and the actuation device are configured to be able to exchange data with the data receiving unit 22h and the data delivering unit 22l of the communication device 2, respectively.
[0184] A user accesses the information terminal 2 using a data acquisition PC or mobile device that continuously acquires their own sensor and camera information, using a user ID and password. For example, by selecting the ID of one or more pre-registered IoT devices from an IoT slip GUI or IoT communication connection screen, device authentication is performed for one or more communication devices 2 connected to the IoT device via a communication device 2 connected to or integrated with their IoT PC or mobile device, or via a management device function built into a management device 3 or a SIM card integrated into the mobile device. The specific authentication procedure is as described above. Once authentication is successful, data is continuously acquired using their IoT PC or mobile device, and the data is saved as needed.
[0185] Furthermore, the sending or receiving communication device 2 or management device 3 performs a virus check on data exchanged between the communication device 2 and the management device 3, or between the communication devices 2 and 2, and if a virus is detected, the data itself is discarded or the virus is deleted from the data. Furthermore, the communication device 2 or management device 3 that performed the virus check may return the virus-deleted data to the sender or may notify the sender of the presence of a virus. Alternatively, this virus check and virus deletion may be performed by a dedicated monitoring server installed domestically or overseas, or by a dedicated virus checking service company. Alternatively, the processing may be handed over to an existing virus checking server in Japan or overseas to reduce the processing load. To reduce the burden of this virus processing and other processing, multiple management devices 3 may be installed and various processing tasks may be shared.
[0186] Furthermore, although an example has been described in which the recovery procedure when an abnormality is determined by the abnormality determination unit 22q is performed by the management device 3, this recovery work can also be performed by the entire communication system. Specifically, when the above abnormality is determined, the occurrence of the abnormality is notified to all communication devices 2 managing the same group. Thereafter, to recover from the abnormal state, the authenticated user of the communication device 2 in which the abnormality occurred obtains permission from a group manager such as the system administrator of the management device 3 or the user's superior, and this permission information is confirmed by personal authentication such as biometric authentication of the connected device 28 or the system administrator or group manager, and after this confirmation is obtained, the recovery work is performed.
[0187] Furthermore, if the abnormality is determined during communication via the management device 3 and recovery is required, the network administrator of this communication system will indicate their intention to allow recovery through personal authentication such as the connection device 28 or biometric authentication, and once this intention is confirmed, the authenticated user of the communication device 2 where the abnormality occurred will send application information requesting recovery to the system administrator with administrator authority for the management device 3. Upon receiving the application, the system administrator of the management device 3 will carry out recovery work for the communication device 2 and store the result in the communication device 2. The group information is notified to all communication devices 2 that have the same group information as the group that has been specified.
[0188] Furthermore, when a general user uses an information terminal 7 to store target data encrypted using the above-mentioned GUI in the memory unit 21 of the communication device 2, access rights to this target data are limited to the general user who performed the encryption and the general user who receives the target data, and restrictions may be imposed so that even an administrator cannot view the data. In addition, hash data may be used in this inter-device communication to prevent data tampering. For example, target data and its hash data, or destination information and its hash data, etc. may be used.
[0189] Furthermore, the communication device 2 may be a general-purpose PC device or a general-purpose communication terminal equipped with a storage device or storage card that stores a communication program.
[0190] In this example, data can be exchanged within a group and among users belonging to that group, but group authentication may be performed to use this group. Specifically, users belonging to a group may be required to enter some or all of their specific information, and communication using this group may be possible only if the correct information is entered. Incidentally, if there are a large number of users in a group, the users may be classified by attributes such as country, region, age, gender, and hobbies, and something like subgroups may be created within the group.
[0191] The above-mentioned GUI simulating a receipt can also be used when entering receipts for online shopping, etc. Specifically, it is convenient to automatically output information that appears to be the same as previously entered information (for example, purchaser information) from stored data, and only require new entry of the purchase date, service name, product name, unit price, total amount, etc.
[0192] This communication system can also be applied to secure calls using voice data. Specifically, two communication devices 2, 2 are interposed between two information terminals 7, 7 on which a phone app is installed, and streaming encryption is applied to inter-device communication between the two communication devices 2, 2, thereby encrypting voice data transmitted and received between two or more information terminals 7, 7.
[0193] This communication system can also be used for confidential email. Specifically, a GUI such as a dedicated envelope can be used for each group to encrypt target data such as email text and attachments, and reversible masking processes such as subdivision scrambling and color conversion can be performed on some or all of the target data, and this data can be sent and received via device-to-device communication.
[0194] Furthermore, this communication system can also be applied to electronic medical records. Specifically, the parts of the electronic medical records that correspond to personal information are masked and stored on a cloud server connected to an external network 1. When viewing is required, the records can be viewed, added to, changed, or deleted via the communication device 2.
[0195] This communication system can also be used as a measure to prevent items from being left behind. For example, a GPS sensor terminal can be used as the transmitting information terminal 7A, which can communicate wirelessly with the portable transmitting communication device 2A, and is carried on a user's belongings such as a bag. The user's smartphone constantly transmits the user's GPS location information to a cloud server or the like, and if the GPS location information transmitted from the transmitting information terminal 7A via the transmitting communication device 2A does not match the user's GPS location information, the user may be notified that the belongings have been lost.
[0196] The transmitting information terminal 7A or an IoT device with an information terminal function may incorporate an earthquake sensor, a surveillance camera, a vital sign check sensor, a measuring device, or other sensors, and the captured image data or sensing information may be encrypted and decrypted between two communication devices 2, 2 or between the IoT devices, and transmitted to the receiving information terminal 7B. If an abnormality occurs in the captured image data or sensing data, a notification of the abnormality is sent. This notification of the abnormality may be sent from the transmitting information terminal 7A or the receiving information terminal 7B. Furthermore, if necessary, data masking may be performed to conceal some of the information.
[0197] The user's personal computer or smartphone may be used as the communication terminal 7, and a communication device 2 such as a modularized IC memory or USB memory may be attached to this communication terminal 7 to encrypt information sent and received with an online bank, mail-order company, company providing escrow services, or an individual. Furthermore, the company providing escrow services and the mail-order company may separately manage customer information to prevent information leaks.
[0198] Next, another embodiment of a communication system to which the present invention is applied will be described, focusing on the differences from the above embodiment.
[0199] In the above-described embodiment, an example was described in which the sending communication device 2A and the receiving communication device 2B directly exchange target data via a global network, but the target data may also be exchanged indirectly by interposing one or more communication devices 2 or one or more management devices 3 between them.
[0200] Specifically, the devices are connected in the following order: transmitting communication device 2A → communication device 2 (or management device 3) → ... → communication device 2 (or management device 3) → receiving communication device 2B. In this case, so that adjacent devices can communicate with each other in encrypted form, the same or corresponding device authentication information such as ID and password, and encryption key or trigger information for generating them are set and stored in advance by a system administrator, for example, at the time of shipment, in a storage area that cannot be accessed from the outside, such as a secret area set in the CPU, in the storage unit 21 of the communication device 2 or the storage unit 31 of the management device 3. Note that it is also possible to store multiple sets of this user information and secret information in advance and switch between them at a fixed timing or in response to predetermined trigger information. In addition, the exchange of target data is carried out by the data transmitting unit 22i and data receiving unit 22k of the communication device 2, or by a data transmitting unit (not shown) and a data receiving unit (not shown) having the same or substantially the same configuration as the data transmitting unit 22i and data receiving unit 22k provided in the management device 3, and the final destination and the communication path up to that point are held by each communication device 2 or management device 3.
[0201] Next, another embodiment of a communication system to which the present invention is applied will be described, focusing on the differences from the above embodiment.
[0202] 19 is a flow diagram showing a processing procedure for exchanging target data in a communication system according to another embodiment. In the embodiment shown in the figure, management device 3 is provided with a data receiving unit (not shown), a data distribution unit (not shown), and a viewing restriction unit (not shown) that are identical or substantially identical in configuration to data receiving unit 22h, data distribution unit 22l, and viewing restriction unit 22m, and each communication device 2 is provided with relay data receiving unit 22t and relay data transmitting unit 22u that relay target data to management device 3.
[0203] In this communication system, encrypted communications are established in advance between the sending side communication device 2A and the management device 3, and between the management device 3 and the receiving side communication device 2B, by the above-mentioned method, and the communication state is maintained. This allows the information terminal 7B to access the management device 3, which is normally inaccessible. This also makes it possible to provide GUIs such as those shown in Figs. 16 to 18 from the storage unit 31 of the management device 3 via the input / output unit 32g.
[0204] The ID or password for device-to-device authentication, the encryption key for encryption and decryption, and trigger information for generating these are shared between the transmitting communication device 2A and the management device 3, and between the management device 3 and the receiving communication device 2B. In this configuration, since information is concentrated in the management device 3, sufficient measures must be taken to prevent information leaks, and personal identification information and the like are managed even more strictly. Specifically, when accessing the management device 3, authentication that can identify individuals, such as fingerprint authentication, voice authentication, or face authentication, is performed, and an access log is also stored. Furthermore, the management device 3 may send messages, such as maintenance information, group change information, and usage fees, to the information terminals 7 of users using this communication system. Furthermore, the management device 3 may also send advertising information, survey information, and the like. Considering the concentration of connection information on the management device 3, one or more file servers (not shown) may be separately provided to back up or mirror data from the management device 3.
[0205] When transmitting and receiving data, first, the transmitting information terminal 7A passes the target data to the management device 3 via the input / output unit 32g of the management device 3 (S201).
[0206] The transmitting communication device 2A forcibly receives the target data sent to the management device 3 using the relay data receiving unit 22t (S202), encrypts the received target data using the encryption unit 22a (S203), and transmits the encrypted target data to the management device 3 using the relay data transmitting unit 22u (S204).
[0207] The management device 3 receives the encrypted data using the data receiving unit (S205) and decrypts it using the decryption unit 32b of the management device 3 (S206). Between the sending communication device 2A and the management device 3, a device authentication list (device ID, password, etc.) for performing device-to-device authentication, encryption keys for encryption and decryption, or trigger information for generating these are stored in advance in the storage units 21, 31 and shared. Note that the data to be decrypted by the management device 3 does not have to be all data, and it may be limited to the minimum amount necessary for transfer (for example, only header information for device authentication). Alternatively, the target data may not be decrypted at all, and the header information necessary for transfer may be separately received from the sending communication device 2A. This makes it impossible for the management device 3 to check the target data, thereby preventing data leakage from the management device 3 and further improving security.
[0208] When a reception request for the decrypted target data is received from the receiving information terminal 7B of the user designated as the recipient and the data is no longer subject to restriction by the viewing restriction unit of the management device 3, the management device 3 encrypts the data using the encryption unit of the management device 3 (S207) and distributes the encrypted target data to the receiving communication device 2B located on the receiving information terminal 7B side using the data distribution unit of the management device 3 (S208). Note that, as mentioned above, if not all of the target data has been decrypted, the data is sent as is to the receiving communication device 2B.
[0209] The receiving communication device 2B receives the distributed target data by the relay data receiving unit 22t (S209), and decrypts the received target data by the decryption unit 22b of the receiving communication device 2B (S210). Between the management device 3 and the receiving communication device 2B, an ID, a password, an encryption key for performing the encryption and decryption, or trigger information for generating these, are stored in advance in the memories 21 and 31 and shared.
[0210] The receiver communication device 2B transmits the decrypted target data to the receiver information terminal 7B by the relay data transmitting unit 22u (S211). The transmitted target data is received (S212).
[0211] In the communication system configured as described above, each communication device 2 only needs to share connection information to the management device 3 and secret information for encryption or authentication, and this information can be centrally managed on the management device 3 side. The same applies to user information, group information, and company information. Incidentally, although the information terminal 7 exchanges information with the management device 3, the information exchanged is automatically relayed and encrypted by the communication device 2, causing little inconvenience to the user.
[0212] 14 and 15, it is not essential to maintain a constant inter-device connection between the communication device 2 and the management device 3, and it is also possible to limit the connection between the two to the first communication. In contrast, in the configuration shown in Fig. 19, it is desirable to maintain a constant connection between the communication device 2 and the management device 3.
[0213] In addition, it is also possible to interpose one or more other communication devices 2 or management devices 3 between the sending communication device 2A and the management device 3, or between the management device 3 and the receiving communication device 2B, using the above-mentioned method.
[0214] In addition, since this management device 3 relays all data and has functions that combine some of the functions of the sending communication device 2A and receiving communication device 2B described above, it can also function as a cloud server.
[0215] Furthermore, the communication device 2 may be configured so that when a user attempts to connect to the communication device 2 using the information terminal 7, the communication device 2 is connected to the management device 3. In this case, the user can exchange data via the management device 3 without being aware of the management device 3.
[0216] Furthermore, the processing load may be reduced by omitting the decryption process (S206) and the encryption process (S207) in the management device 3. In this case, information on the receiving communication device 2B and the receiving information terminal 7B that deliver the target data is acquired directly from the sending communication device 2A or the sending information terminal 7A.
[0217] Furthermore, when the sending information terminal 7A accesses the management device 3, the sending information terminal 7A first accesses the sending communication device 2A, and the sending communication device 2A then accesses the management device 3. Similarly, when the receiving information terminal 7B accesses the management device 3, the receiving information terminal 7B first accesses the receiving communication device 2B, and the receiving communication device 2B then accesses the management device 3.
[0218] Next, another embodiment of a communication system to which the present invention is applied will be described, focusing on the differences from the above embodiment.
[0219] 20 is an explanatory diagram illustrating an overview of a communication system according to another embodiment of the present invention. In the example shown in the figure, a relay terminal 8 is provided within an internal network 6 to relay communication between an information terminal 7 and a communication device 2, and information about the relay route is stored in this relay terminal 8 as a relay table 8a.
[0220] A relay terminal 8 in one internal network 6 is connected to a relay terminal 8 in another internal network 6 by a connection line 9, and when a communication device 2 on the side of the one internal network 6 breaks down, the information terminal 7 on the side of the one internal network can use the communication device 2 on the side of the other internal network as a substitute. Addition, change, deletion, etc. of this relay route can be performed by instructions from the management device 3 of the system administrator or the information terminal 7 of the group administrator of each group. This is done by adding, changing or deleting information to the relay table 8a of the relay terminal 8.
[0221] An information terminal 7 in one internal network 6 and an information terminal 7 in another internal network 6 may be connected by a connection line 9'.
[0222] Furthermore, the relay terminal 8 can be replaced by the information terminal 7.
[0223] Next, another embodiment of a communication system to which the present invention is applied will be described, focusing on the differences from the above embodiment.
[0224] 21 is an explanatory diagram outlining a group configuration according to another embodiment of the present invention. In this communication system, new groups and users can be added using an external connection device 28 or the update method described above, which enables operation with high redundancy. For example, in the example shown in FIG. 21, user a creates group A, and adds three users b, c, and d to group A. These three users b, c, and d then create groups B, C, and D, respectively. User g, who was added to group C, then creates group G.
[0225] By successively adding groups and users in this way, it becomes possible to perform highly redundant operations. In other words, with this type of inter-device communication within a group, anyone can freely create a dedicated group at any time, so that although it is limited to communication device 2, a highly secure dedicated communication network can be freely added and modified.
[0226] Next, another embodiment of a communication system to which the present invention is applied will be described, focusing on the differences from the above embodiment.
[0227] FIG. 22 is an explanatory diagram illustrating the configuration of a communication device according to another embodiment of the present invention. The control unit 22 further includes a hacking prevention unit 22w. This hacking prevention unit 22w prevents hacking by periodically changing the port used during communication, periodically prompting the user to change their password, and automatically updating the OS and software to keep them up to date. Note that this hacking prevention unit 22w may be provided in the control unit 32 of the management device 3 to prevent hacking of the management device 3.
[0228] Next, another embodiment of a communication system to which the present invention is applied will be described, focusing on the differences from the above embodiment.
[0229] 23 is an explanatory diagram outlining a communication system according to another embodiment of the present invention. In the example shown in the figure, the information terminal 7 includes a personal computer, smartphone, or tablet terminal operated by a user, as well as devices that transmit and receive various data, such as IoT devices, M2M devices, cameras, robots, remote-controlled devices, automobiles, and AI devices. For example, the information terminal 7 is configured to be an IoT terminal capable of wireless communication with the communication device 2, or a device that is capable of wireless communication with the communication device 2 and performs sensing using a sensor and is mechanically controlled. The communication device 2 may transmit commands for controlling the IoT devices, M2M devices, cameras, robots, remote-controlled devices, AI devices, etc., to control these devices.
[0230] A plurality of communication devices 2 are provided and are communicably connected to each other via a network 9. The network 9 may be a global network, a private network, or a network that is a combination of these.
[0231] One information terminal 7 can communicate with other information terminals 7 in encrypted form via a pair of communication devices 2, 2. This allows the sensing information of all the information terminals 7 to be shared and used as big data. It becomes possible to utilize the information terminals 7 as a single unit, or to have one information terminal 2 monitor sensing information from another information terminal 7, or to mechanically control the information terminal 7.
[0232] This configuration enables robot control using M2M. Furthermore, IoT can be used to enable cooperative control between automobiles that can acquire pedestrian location information and wheelchair users, as well as communication between pedestrians, automobiles, wheelchairs, bus stops, trains, stations, airports, public facilities, private facilities, traffic lights, etc. These can be used to check the vital signs of disabled people and notify them of any abnormalities, issue warnings when a wheelchair enters a dangerous area, and check the vital signs of the wheelchair occupant to ensure their safety. [Explanation of symbols]
[0233] 1. Global Network 2. Communications equipment 2A Transmitting communication device (communication device) 2B Receiving communication device (communication device) 21 Memory section 22 Control Unit 23 Incoming Network Interface 24 outgoing network interfaces 25 GPS sensor (status detection sensor, location information acquisition sensor) 26 Acceleration sensor (status detection sensor) 27 Gyro sensor (status detection sensor) 28 Connected Devices 3 Management device 7 Information terminals 7A Sender information terminal 7B Receiving information terminal
Claims
1. A communication system in which a plurality of information terminals included in the same group exchange data with each other via a network, a plurality of communication devices respectively connected between each information terminal in the group and the network for performing highly confidential intercommunication among the plurality of information terminals included in the group; Each of the communication devices a storage unit that stores user authentication information for authenticating a user via the information terminal connected thereto, and that stores in advance a device authentication list that lists device authentication information including secret information necessary for authenticating each communication device for all communication devices in the same group, in a state in which the secret information cannot be accessed by the user; when exchanging data between the information terminals via the network, the communication devices connected to the information terminals exchanging the data execute an inter-device authentication process by referring to the device authentication list; the device authentication list includes a group ID of a temporary group reserved in advance for an unregistered group, and device IDs of temporary users included in the temporary group; When registering a new group, each of the communication devices specifies a group ID of the temporary group to be registered and a device ID of a temporary user to be registered in the temporary group, and updates the device authentication list by switching the specified group ID and device ID from an invalid state to a valid state. Communication system.
2. a plurality of communication devices included in the new group; When the device authentication list is updated in any one of the communication devices included in the new group, the user can view the updated device authentication list excluding the confidential information. The communication system according to claim 1 .
3. a management device connected to the network and executing at least a part of an inter-device authentication process between the plurality of communication devices; the device authentication list is a list of device authentication information including secret information necessary for authenticating the communication devices and the management device for all communication devices and all management devices in the same group, The management device has a storage unit in which the device authentication list is stored in advance in a state in which the user cannot access the confidential information.
3. A communication system according to claim 1 or 2.
4. the device authentication list stored in the storage unit of the management device includes a group ID of a temporary group reserved in advance for an unregistered group, and device IDs of temporary users included in the temporary group; When registering a new group, the management device specifies a group ID of the temporary group to be registered and a device ID of a temporary user to be registered in the temporary group, and updates the device authentication list by switching the specified group ID and device ID from an invalid state to a valid state, so that the newly registered user can view the updated device authentication list excluding the confidential information.
4. The communication system according to claim 3.
5. When registering the new group, the management device or the communication device rewrites the temporary group name to a true group name, and notifies the communication device of the user who has become valid in the new group of the rewritten true group name and the device ID of the user who has become valid.
5. The communication system according to claim 4.
6. In the storage unit of the communication device, at least a part of an encryption key for performing encrypted communication between the communication devices or trigger information for generating the encryption key is stored in a state inaccessible to the user. A communication system according to any one of claims 1 to 5.
7. The storage unit of the management device stores at least a part of encryption keys for performing encrypted communications between the communication devices and between the communication devices and the management device, or trigger information for generating the encryption keys, in a state inaccessible to the user. The communication system according to any one of claims 3 to 5.
8. The information terminals include personal computers, smartphones, and tablet terminals operated by users, as well as devices that send and receive various data, such as IoT devices, M2M devices, cameras, robots, remote-controlled devices, automobiles, and AI devices. A communication system according to any one of claims 1 to 7.
9. The communication device a user authentication unit that determines whether or not to permit access in response to an access request from the information terminal based on user authentication information stored in the storage unit; an inter-device authentication unit that executes inter-device authentication processing with another of the communication devices based on a device authentication list stored in the storage unit; an input / output unit that inputs and outputs information to and from the information terminal that is permitted to access by the user authentication unit; a data transmission / reception unit that transmits and receives data to and from the other communication device authenticated by the device-to-device authentication unit; The communication system according to any one of claims 1 to 8, comprising:
10. The communication device includes information acquired from an IoT device or an M2M device in the data exchanged.
10. The communication system according to claim 1, wherein:
11. The communication device has an AI function that performs machine learning based on data acquired from other communication devices and provides optimal solutions. A communication system according to any one of claims 1 to 10.
12. The communication device includes a detachable connection device in which information is stored in advance. A communication system according to any one of claims 1 to 11.
13. In a communication system in which multiple information terminals belonging to the same group exchange data with each other via a network, a communication device connected between each information terminal in the group and the network to perform highly confidential intercommunication among the plurality of information terminals included in the group, a storage unit that stores user authentication information for authenticating a user via the information terminal connected thereto, and that stores in advance a device authentication list that lists device authentication information including secret information necessary for authenticating each communication device for all communication devices in the same group, in a state in which the secret information cannot be accessed by the user; when exchanging data between the information terminals via the network, the communication devices connected to the information terminals exchanging the data execute an inter-device authentication process by referring to the device authentication list; the device authentication list includes a group ID of a temporary group reserved in advance for an unregistered group, and device IDs of temporary users included in the temporary group; When registering a new group, the device authentication list is updated by specifying the group ID of the temporary group to be registered and the device ID of the temporary user to be registered in the temporary group, and switching the specified group ID and device ID from an invalid state to a valid state. Communication equipment.
14. In a communication system in which multiple information terminals belonging to the same group exchange data with each other via a network, a management device that executes at least a part of an inter-device authentication process between a plurality of communication devices that are respectively connected between each information terminal in the group and the network in order to perform highly confidential intercommunication between the plurality of information terminals included in the group, a storage unit that stores in advance a device authentication list that lists device authentication information including secret information necessary for authenticating each communication device for all communication devices in the same group; When data is exchanged between the information terminals via the network, an inter-device authentication process is performed between the communication devices by referring to the device authentication list; the device authentication list includes a group ID of a temporary group reserved in advance for an unregistered group, and device IDs of temporary users included in the temporary group; When registering a new group, the device authentication list is updated by specifying the group ID of the temporary group to be registered and the device ID of the temporary user to be registered in the temporary group, and switching the specified group ID and device ID from an invalid state to a valid state. Management device.
15. In a communication system in which multiple information terminals belonging to the same group exchange data with each other via a network, An information terminal having a built-in communication device for performing highly confidential mutual communication among a plurality of information terminals included in the group, connected to the network via the communication device, Each of the communication devices a storage unit in which a device authentication list, which lists device authentication information including secret information necessary for authenticating each communication device for all communication devices in the same group, is stored in advance in a state in which the secret information cannot be accessed by a user; performing inter-device authentication processing between the plurality of communication devices via the network by referring to the device authentication list; the device authentication list includes a group ID of a temporary group reserved in advance for an unregistered group, and device IDs of temporary users included in the temporary group; When registering a new group, the communication device specifies a group ID of the temporary group to be registered and a device ID of a temporary user to be registered in the temporary group, and updates the device authentication list by switching the specified group ID and device ID from an invalid state to a valid state. Information terminal.
16. The communication device is an IC card or a SIM.
16. An information terminal according to claim 15.
Citation Information
Patent Citations
Content transmission history analysis system and data communication control device
JP2004080743A
VPN connection construction system
JP2006166028A
Single sign-on system, information terminal device, single sign-on server, program
JP2008181427A
Relay device
JP2011045050A
Conference system and its conference system
JP2011199847A