Wireless transmission system and wireless transmission method
The wireless transmission system improves security in multi-hop networks by using a verification formula with random numbers and shared secret information to authenticate relay devices, preventing unauthorized access and protecting sensitive data during maintenance or updates.
Patent Information
- Application Number
- JP2021206178
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-20
- Publication Date
- 2025-09-08
- Estimated Expiration
- 2041-12-20
AI Technical Summary
Conventional wireless communication systems face security vulnerabilities, particularly in multi-hop transmission, where relay devices can be spoofed, leading to potential ID and password leakage, and encrypted location information misuse during maintenance or updates.
A wireless transmission system employs a relay device and an update device that utilize a verification formula involving randomly generated numbers and shared secret information to authenticate each other, ensuring secure access for maintenance or updates, with additional security measures like biometric authentication and additional secret information.
Enhances security by preventing unauthorized access and protecting shared secret information, thereby safeguarding communication integrity and maintaining secure operations of relay devices.
Smart Images

Figure 0007735176000001 
Figure 0007735176000002 
Figure 0007735176000003
Abstract
Description
[Technical Field]
[0001] FIELD OF THE INVENTION Embodiments of the present invention relate to wireless transmission technology. [Background technology]
[0002] In recent years, multi-hop transmission technology has become widespread in wireless communications, leading to the expansion of communication areas and network networks. By using multi-hop transmission technology, wireless communication networks can be expanded to remote areas such as mountainous regions, remote islands, and rural areas. This allows wireless sensors, mobile phones, and mobile terminals to be used in remote locations. In wireless communications that enable such wide-area communications, security measures against information leakage, tampering, and fraud during communications are important. In particular, in multi-hop transmission, security measures for relay devices that multi-hop the communication radio waves are important.
[0003] Conventionally, there are known techniques for enhancing the security of authentication using IDs and passwords for accessing relay devices for maintenance or repair work. For example, a method using location information is known. In this method, an authentication server authenticates an input device based on the location information and connection request of the input device and the radio wave strength of the location information and connection request received by a wireless communication device. Here, the encrypted location information of the input device is decrypted by the authentication server and compared with the distance calculated from the radio wave strength. Authentication is granted if the location information and the distance match, and is denied if they do not match. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-276603 [Patent Document 2] Japanese Patent Application Laid-Open No. 2010-193118 [Patent Document 3] Japanese Patent Application Laid-Open No. 2009-17516 Summary of the Invention [Problem to be solved by the invention]
[0005] In conventional technology, if a relay device is spoofed, an input device may access the relay device, which could result in the leakage of IDs and passwords. Also, encrypted location information may be leaked and misused. Also, encrypted location information may be decrypted and used. Therefore, it is important to improve the security of authentication between the input device and the relay device.
[0006] The embodiments of the present invention have been made in consideration of the above circumstances, and have an object to provide a wireless transmission technology that can improve security when performing maintenance or updating of a relay device. [Means for solving the problem]
[0007] A wireless transmission system according to an embodiment of the present invention includes a relay device that relays communication data transmitted from a wireless device, and an update device that remotely accesses the relay device and performs maintenance or updating of the relay device, wherein the update device transmits a generated first random number to the relay device in an encrypted state, the relay device transmits a generated second random number to the update device, and the update device, upon receiving the second random number, compares the first random number with the 、 The second random number and 、 Secret information that has been shared with the relay device in advance and made secret additional secret information that is shared with the relay device in advance together with the secret information and is additionally set in the verification formula; and transmits the encrypted first random number and the authentication information to the relay device, and the relay device receives the encrypted first random number and the authentication information and transmits the encrypted first random number and the authentication information to the relay device. The aforementioned The relay device is configured to perform a calculation by applying the result to a verification formula, and permit access from the update device if the verification formula is satisfied. Crate , The authentication information u' is expressed by the following formula: u'=(r+sd+s'd) mod q where r is the first random number, d is the second random number, s is the secret information, and s' is the additional secret information. . [Effects of the Invention]
[0008] According to an embodiment of the present invention, a wireless transmission technique is provided that can improve security when performing maintenance or updating of a relay device. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 2 is a configuration diagram showing a communication path of the wireless transmission system according to the first embodiment. [Figure 2] FIG. 2 is a configuration diagram showing a relay device and an update device according to the first embodiment. [Figure 3] FIG. 2 is a block diagram showing a relay device according to the first embodiment. [Figure 4] FIG. 2 is a block diagram showing an update device according to the first embodiment. [Figure 5] FIG. 3 is an exchange diagram showing a parameter update method according to the first embodiment. [Figure 6] FIG. 10 is a configuration diagram showing a relay device and an update device according to a second embodiment. [Figure 7] FIG. 11 is a configuration diagram showing a relay device and an update device according to a third embodiment. [Figure 8] FIG. 11 is an exchange diagram showing a parameter update method according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] (First embodiment) DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS A wireless transmission system and a wireless transmission method according to embodiments will be described in detail below with reference to the accompanying drawings. First, a first embodiment will be described with reference to FIGS.
[0011] Reference numeral 1 in Fig. 1 denotes a wireless transmission system of this embodiment. This wireless transmission system 1 includes a wireless device 2, a relay device 3, a transmitting / receiving device 4, and a matching / decoding device 5. Here, the wireless device 2, the relay device 3, and the transmitting / receiving device 4 are connected wirelessly. Furthermore, the transmitting / receiving device 4 and the matching / decoding device 5 are connected by wire.
[0012] The wireless transmission system 1 is used to transmit communication data wirelessly from remote locations such as rural areas, mountainous regions, and remote islands, and to receive this information at a base location such as an urban area. The wireless transmission system 1 is provided with relay points that relay communication in order to perform long-distance wireless communication (wireless communication). It is then possible to verify whether communication has been performed via a legitimate relay point.
[0013] The wireless device 2 is a wireless IoT or mobile terminal that monitors a specific device in a remote location. For example, it is attached to a specific device, such as equipment installed in a plant, and detects various data. For example, it detects vibration, temperature, air pressure, pressure, distance, speed, water level, or thickness. Then, it transmits communication data including the detected information to a base station. Alternatively, multiple wireless devices 2 are installed in remote locations, and each transmits communication data via wireless communication. The wireless device 2 may encrypt the communication data to be transmitted.
[0014] The wireless device 2 is configured with a device that incorporates an electronic circuit or IC chip that performs arithmetic processing and wireless communication functions, such as a tablet terminal, a PDA (Personal Digital Assistant), a personal computer, a notebook computer, a small personal computer, a smartphone, a mobile phone, or a portable or wearable electronic device.
[0015] The communication data of these communication devices undergoes security processing and is transmitted wirelessly from an antenna installed in the communication device. Various communication standards can be applied to such wireless communication methods. For example, unlicensed communications such as IEEE 802.11, IEEE 802.15.1, and IEEE 802.15.4, as well as communications provided by mobile communication carriers such as LTE, 4G, and 5G, can be applied. Local 5G, in which a license is obtained and a privately operated communication network is constructed, can also be applied.
[0016] The relay device 3 is a so-called access point that relays communication data transmitted from a wireless device 2 installed in a remote location and forwards the communication data to a pre-set next relay device 3. For example, the communication data is forwarded via multiple relay devices 3A, 3B, and 3C. The forwarded communication data is finally received by a transmitting / receiving device 4 installed in the home location.
[0017] In this embodiment, a predetermined route that passes through a plurality of relay devices 3A, 3B, and 3C and another route that passes through a plurality of other relay devices 3D are provided as routes for transmitting communication data. Any one of these routes is appropriately selected to transmit the communication data. In transmitting communication data, it is possible to specify the route order of the relay devices 3 or to make it necessary to pass through a specific relay device 3 as a security condition. Since the route can be changed depending on the situation, security can be improved. The route selection is performed automatically by the matching / decoding device 5 or arbitrarily by an administrator.
[0018] The relay device 3 is composed of a device that incorporates an electronic circuit or IC chip with a communication relay function. For example, the relay device 3 receives radio waves from the wireless device 2 with an antenna, performs necessary security processing on the communication data, and then wirelessly transmits the communication data to the next destination. The communication data is then finally transmitted to the transmitting / receiving device 4.
[0019] Here, the antenna for transmitting and receiving communication data is selected according to the purpose. For example, if omnidirectionality is required, a dipole antenna or monopole antenna is used. If directionality is required, a parabolic antenna or horn antenna is used. Note that maintenance or updates are performed on the relay device 3 as needed. Maintenance includes various types of maintenance, operation checks, repairs, etc. Updates include updating parameters for security processing, etc. Security processing includes at least one of encryption processing and authentication processing performed on communication data.
[0020] The transmitting / receiving device 4 is configured with a device incorporating an electronic circuit or IC chip with communication transmission and reception functions. For example, it receives communication data from the wireless device 2 transmitted via the relay device 3. The antenna is selected according to the purpose, just like the relay device 3. The transmitting / receiving device 4 then transmits the received communication data to the matching / decoding device 5.
[0021] The matching / decoding device 5 is configured with a device incorporating an electronic circuit or IC chip having arithmetic processing functions and wireless communication functions. This matching / decoding device 5 is configured, for example, with a general-purpose PC. The matching / decoding device 5 verifies the integrity of communication data by, for example, decrypting the encryption, detecting tampering, and performing security processing such as authenticating the wireless device 2 or the relay device 3. Then, the matching / decoding device 5 acquires the integrity of communication data and stores it.
[0022] In this embodiment, for ease of understanding, the wireless device 2, the relay device 3, and the transmission / reception device 4 are described as being different types of devices, but these devices may have the same configuration. For example, the wireless device 2, the relay device 3, and the transmission / reception device 4 may all be configured as tablet terminals or smartphones. A network capable of multi-hop transmission may be constructed using these devices.
[0023] Furthermore, in this embodiment, the transmitting / receiving device 4 and the matching / decoding device 5 are described as separate devices, but the transmitting / receiving device 4 and the matching / decoding device 5 may be integrated into one device.
[0024] 2, the wireless transmission system 1 includes an update device 6 that remotely accesses the relay device 3 to perform maintenance or updates on the relay device 3. The update device 6 is handled by an operator who performs maintenance or updates on the relay device 3. The operator uses the update device 6 to update parameters used for encryption processing or authentication processing in the relay device 3, for example.
[0025] The update device 6 is a device for inputting and outputting information, and is composed of a device with built-in electronic circuits or IC chips for processing functions and wireless communication functions. For example, it may be composed of various communication devices such as tablet terminals, PDAs, personal computers, laptops, small personal computers, smartphones, mobile phones, portable or wearable electronic devices, etc.
[0026] The update device 6 is connected to the relay device 3 wirelessly or via a wire. For example, in the case of a wireless connection, communication that does not require a license, such as IEEE.802.11, IEEE.802.15.1, or IEEE.802.15.4, or communication provided by a mobile communication carrier, such as LTE, 4G, or 5G, can be applied. Furthermore, local 5G, in which a license is obtained and a self-operated communication network is constructed, can also be applied. In addition, in the case of a wired connection, a metal cable or optical fiber can be applied. Note that the update device 6 may be connected to a predetermined relay device 3 using a route that passes through multiple relay devices 3A, 3B, and 3C.
[0027] The relay device 3 and the update device 6 of this embodiment are configured as computers having hardware resources such as a processor and memory, and in which software-based information processing is realized using the hardware resources by the CPU executing various programs. Furthermore, the wireless transmission method of this embodiment is realized by having the computer execute various programs.
[0028] In this embodiment, a worker uses the update device 6 to perform a predetermined task related to the maintenance or update of the relay device 3. Here, the relay device 3 authenticates whether the accessing update device 6 is legitimate. If authenticated, the access is permitted, and if not, the access is denied. For this authentication, as will be explained below, a first random number, a second random number, secret information, authentication information, and a verification formula are used. In this way, the security of the relay device 3 can be improved. Furthermore, the security of the authentication between the relay device 3 and the update device 6 can be improved.
[0029] As shown in FIG. 3, the relay device 3 includes a communication unit 10, a storage unit 11, and a control unit 12. The communication unit 10 communicates with other devices wirelessly or via a wired connection. The storage unit 11 stores various information required for processing. The storage unit 11 includes a portable storage medium that is detachable from the relay device 3. The control unit 12 controls the relay device 3 in an integrated manner.
[0030] The control unit 12 includes a second random number generation unit 13 and a verification unit 14. These are realized by the CPU executing a program stored in a memory or a HDD. Here, the second random number generation unit 13 generates a second random number. The verification unit 14 verifies whether the accessing update device 6 is legitimate or not.
[0031] As shown in FIG. 4, the update device 6 includes a communication unit 20, a storage unit 21, an input unit 22, an output unit 23, a biometric authentication unit 24, and a control unit 25. The communication unit 20 communicates with other devices wirelessly or via a wired connection. The storage unit 21 stores various information required for processing. The storage unit 21 includes a portable storage medium that is detachable from the update device 6. The input unit 22 receives predetermined information in response to an operation by an operator. The output unit 23 outputs predetermined information to the operator. The biometric authentication unit 24 performs biometric authentication of the operator. The control unit 25 provides overall control of the update device 6.
[0032] The input unit 22 includes input devices such as a mouse and a keyboard. That is, predetermined information is input to the input unit 22 in response to the operation of these input devices.
[0033] The output unit 23 outputs predetermined information. The update device 6 includes a device for displaying images, such as a display that outputs information. In other words, the output unit 23 controls the images displayed on the display. The display may be separate from the computer main body, or may be integrated with it.
[0034] The biometric authentication unit 24 performs biometric authentication using biometric information (vital information) of the worker. Examples of biometric authentication include fingerprint authentication, iris authentication, vein authentication, face authentication, voiceprint authentication, and handwriting authentication. Authentication using a password and biometric authentication may be used together.
[0035] The control unit 25 includes a first random number generation unit 26 and an authentication information generation unit 27. These are realized by the CPU executing a program stored in the memory or the HDD. Here, the first random number generation unit 26 generates a first random number. The authentication information generation unit 27 generates authentication information.
[0036] Next, the authentication mode of the update device 6 will be described with reference to the exchange diagram shown in Fig. 5. Here, updating of parameters of the relay device 3 is exemplified as a predetermined task performed by an operator. Note that this can also be applied to other maintenance or update-related tasks.
[0037] Here, it is assumed that the concealed secret information is shared in advance between the relay device 3 and the update device 6. The secret information is secret information that is not disclosed to the outside, and is stored in advance in the storage units 11 and 21 of the relay device 3 and the update device 6, respectively.
[0038] First, the update device 6 generates a first random number. Then, the update device 6 encrypts the generated first random number. Furthermore, the update device 6 transmits the encrypted first random number to the relay device 3.
[0039] Next, the relay device 3 receives the encrypted first random number and generates a second random number. Then, the relay device 3 transmits the generated second random number to the update device 6.
[0040] Next, the update device 6 receives the second random number from the relay device 3 and generates authentication information from the first random number, the second random number, and the secret information. Then, the update device 6 transmits the generated authentication information to the relay device 3.
[0041] Next, the relay device 3 that has received the authentication information performs calculations by applying the encrypted first random number and the authentication information to a preset verification formula (1). If the verification formula (1) is satisfied, the relay device 3 permits access from the update device 6. On the other hand, if the verification formula (1) is not satisfied, the relay device 3 denies the access, assuming that it is from an unauthorized device.
[0042] Next, if the relay device 3 permits access, it transmits a notification to that effect to the update device 6. Here, the worker can perform the update using the update device 6. For example, update parameters are transmitted from the update device 6 to the relay device 3. Then, the relay device 3 updates the parameters. These parameters are confidential information including, for example, secret information used in encryption processing or authentication processing of communication data. In this way, it is possible to update the parameters used by the relay device 3 for processing while increasing security when communication data is relayed. Note that updating the parameters of the relay device 3 includes updating the secret information.
[0043] After access is permitted, data encryption, authentication, and tamper detection are performed on a packet-by-packet basis during communication between the relay device 3 and the update device 6. A number is assigned to the packet data, allowing addition or loss of packets to be determined.
[0044] The verification formula (1) of the first embodiment is as follows: g u (g -s ) d =g r+sd (g -s ) d =g r …(1)
[0045] Here, g is a primitive root modulo a prime number q, and g and q are shared in advance between the relay device 3 and the update device 6. r is a first random number, and r is less than q-1 and is relatively prime to q. g ris the first random number encrypted with the primitive root g. d is the second random number, which is less than q-1 and relatively prime to q. s is secret information. u is authentication information.
[0046] Moreover, the authentication information u in the first embodiment is expressed by the following formula. u=(r+sd) mod q
[0047] The update device 6 performs a calculation by substituting the first random number r, the second random number d, and the secret information s into this formula to generate the authentication information u. This calculation can be performed correctly only when the first random number r and the secret information s are known. Furthermore, since the authentication information u is composed of the first random number r and the second random number d, it is also a random number.
[0048] Then, the update device 6 transmits this authentication information u to the relay device 3. If the verification formula (1) is satisfied, the update device 6 is found to be legitimate because it has the secret information s shared with the relay device 3. On the other hand, if the verification formula (1) is not satisfied, the update device 6 is determined to be a fraudulent one.
[0049] The primitive root g and the prime number q are shared in advance between the relay device 3 and the update device 6. For example, the primitive root g and the prime number q are stored in advance in the storage units 11 and 21 of the relay device 3 and the update device 6, respectively. The primitive root g and the prime number q may be publicly available information.
[0050] The secret information s may be any information that is kept secret. For example, a password used by a worker, a predetermined random number, or the like may be used as the secret information s.
[0051] At least a part of the secret information s may be composed of biometric information of the worker. For example, the worker's fingerprint, iris, veins, face, voiceprint, handwriting, etc. are stored as the secret information s in the storage unit 11 of the relay device 3. When performing work, the worker has the biometric authentication unit 24 of the update device 6 read his / her biometric information. The update device 6 generates authentication information u using this biometric information as the secret information s. In this way, only specific workers whose biometric information has been registered in advance in the relay device 3 can perform maintenance or updates, thereby improving security when maintaining or updating the relay device 3. Furthermore, using biometric information for the secret information s makes it difficult to forge the secret information s.
[0052] In addition, the encrypted first random number g r The second random number d and the authentication information u are exchanged, but even if the communication is intercepted and the interceptor is able to obtain this information, the interceptor cannot impersonate the update device 6.
[0053] In the first embodiment, the encrypted first random number g is verified by the verification formula (1). r and the authentication information u, the secret information s will not be leaked during the series of authentication operations. For example, neither the relay device 3 nor the update device 6 transmits the secret information s to the other party, and the secret information s does not flow on the communication line in either the wireless or wired communication, so there is no risk of the secret information s being leaked.
[0054] The functions of the relay device 3 and the update device 6 may be interchanged. For example, when the relay device 3 accesses the update device 6, the update device 6 may authenticate whether the relay device 3 is legitimate. Even in this case, what is verified in the verification formula (1) is the encrypted first random number g r Since the authentication information is u, the secret information s will not be leaked during the series of authentication procedures.
[0055] In the first embodiment, the relay device 3 and the update device 6 communicate one-to-one. Here, by connecting the relay device 3 and the update device 6 using a cable and establishing wired communication, the encrypted first random number g r The second random number d and the authentication information u may be prevented from being spatially leaked. When wireless communication is used, the communication range may be limited by adjusting the radio wave intensity.
[0056] (Second embodiment) Next, a second embodiment will be described with reference to Fig. 6. The above-mentioned drawings will be referred to as appropriate. Components that are the same as those shown in the above-mentioned embodiment will be assigned the same reference numerals, and duplicated descriptions will be omitted.
[0057] As shown in FIG. 6, in the second embodiment, one update device 6 accesses multiple relay devices 3A, 3B, and 3C to perform maintenance or updates on these relay devices 3A, 3B, and 3C. This facilitates maintenance or updates on multiple relay devices 3A, 3B, and 3C. It is also possible to perform maintenance or updates on multiple relay devices 3A, 3B, and 3C at the same time. For example, the update device 6 can transmit the same update parameters to multiple relay devices 3A, 3B, and 3C to perform updates. An effective wireless transmission method is LPWA (Low Power Wide Area), which enables wireless communication over a wide area.
[0058] Furthermore, in the second embodiment, additional secret information s' is used in addition to the first random number r, the second random number d, and the secret information s. Using this information, the update device 6 generates authentication information u'. Here, the relay device 3 and the update device 6 share in advance the secret information s and the secret information s, and the secret additional secret information s' that is additionally set in the verification formula (2). Then, the update device 6 generates the authentication information u' from the first random number r, the second random number d, the secret information s, and the additional secret information s'. In this way, adding the additional secret information s' can further improve security.
[0059] The additional secret information s' is shared by a portable storage medium. For example, a non-volatile storage medium such as a flash memory or various magnetic or optical storage devices can be used. The storage medium includes, for example, an HDD, an SSD, a CD, a DVD, a flexible disk, an SD card, and a micro SD card. Using a volatile storage medium is also effective as a theft prevention measure. In the second embodiment, a USB memory 7 is exemplified as the storage medium.
[0060] For example, the relay device 3 and the update device 6 have a detachable USB memory 7. An operator shares the additional secret information s' by attaching the USB memory 7 storing the additional secret information s' to each of the relay device 3 and the update device 6. In this way, by using a physical storage medium when updating the additional secret information s', the additional secret information s' can be protected from eavesdropping. Note that the secret information s may also be shared using a physical storage medium.
[0061] The device to which the USB memory 7 storing the additional secret information s' is attached may be either the relay device 3 or the update device 6. For example, if the additional secret information s' is pre-stored in either the relay device 3 or the update device 6, the USB memory 7 may be attached to the other device.
[0062] By connecting the USB memory 7 storing the same additional secret information s' to the multiple relay devices 3A, 3B, and 3C, the worker can share the additional secret information among all of the relay devices 3A, 3B, and 3C and the update device 6. Furthermore, by storing the additional secret information s' in the USB memory 7, the component (such as a HDD) storing the secret information s and the component storing the additional secret information s' can be stored in a distributed manner.
[0063] The verification equation (2) of the second embodiment is as follows: g u’ (g -s-s’ ) d =g r+sd+s’d (g -s-s’ ) d=g r …(2)
[0064] Here, g is a primitive root modulo a prime number q, and g and q are shared in advance between the relay device 3 and the update device 6. r is a first random number, and r is less than q-1 and is relatively prime to q. g r is the first random number encrypted with the primitive root g. d is the second random number, which is less than q-1 and relatively prime to q. s is secret information. s' is additional secret information. u' is authentication information.
[0065] Moreover, the authentication information u' in the second embodiment is expressed by the following formula. u'=(r+sd+s'd) mod q
[0066] The update device 6 performs calculations by substituting the first random number r, the second random number d, the secret information s, and the additional secret information s' into this formula to generate authentication information u'. This calculation can be performed correctly only when the first random number r, the secret information s, and the additional secret information s' are known. Furthermore, since the authentication information u' is composed of the first random number r and the second random number d, it is also a random number.
[0067] Then, the update device 6 transmits this authentication information u' to the relay device 3. If the verification formula (2) is satisfied, the update device 6 is found to be legitimate because it has the secret information s and the additional secret information s' shared with the relay device 3. On the other hand, if the verification formula (2) is not satisfied, the update device 6 is determined to be a fraudulent one.
[0068] The same second random number d is generated for each of the multiple relay devices 3A, 3B, and 3C. When the update device 6 receives the second random number d, it can identify each of the relay devices 3A, 3B, and 3C based on the wireless communication line used for reception.
[0069] In the second embodiment, the encrypted first random number g r and authentication information u' are simultaneously transmitted from the update device 6 to the relay device 3 only once, and the encrypted first random number g rThis can reduce the risk of leakage compared to sending the authentication information u' multiple times.
[0070] Furthermore, security can be improved by generating authentication information u' using additional secret information s' in addition to the first random number r, the second random number d, and the secret information s. Note that updating the parameters of the relay device 3 in the second embodiment includes updating the additional secret information.
[0071] At least a part of the additional secret information s' may be composed of biometric information of the worker. For example, the worker's fingerprint, iris, veins, face, voiceprint, handwriting, etc. are stored in the USB memory 7 as the additional secret information s'. When performing work, the worker has the biometric authentication unit 24 of the update device 6 read his / her biometric information. The update device 6 generates authentication information u' using this biometric information as the additional secret information s'. In this way, only specific workers whose biometric information has been registered in advance in the relay device 3 can perform maintenance or updating, thereby improving security when maintaining or updating the relay device 3. Furthermore, using biometric information for the additional secret information s' makes it difficult to forge the additional secret information s'.
[0072] (Third embodiment) Next, a third embodiment will be described with reference to Figures 7 and 8. The aforementioned drawings will be referred to as appropriate. Components identical to those shown in the aforementioned embodiments will be assigned the same reference numerals, and redundant description will be omitted.
[0073] 7, in the third embodiment, one update device 6 accesses one relay device 3 to perform maintenance or update of this relay device 3. In this way, it is possible to individually maintain or update only a specific relay device 3.
[0074] Next, an authentication mode of the update device 6 of the third embodiment will be described with reference to the exchange diagram shown in Fig. 8. Here, it is assumed that the concealed secret information s is shared in advance between the relay device 3 and the update device 6.
[0075] First, the update device 6 generates a first random number r. Then, the update device 6 encrypts the generated first random number r. Furthermore, the update device 6 transmits the encrypted first random number r to the relay device 3.
[0076] Next, the encrypted first random number g r The relay device 3 receives the second random number d and generates a second random number d. Then, the relay device 3 transmits the generated second random number d to the update device 6.
[0077] Next, the update device 6 receives the second random number d from the relay device 3 and generates authentication information u from the first random number r, the second random number d, and the secret information s.
[0078] Next, the update device 6 performs hash function calculation using the second random number d and the secret information s to calculate the hash value h. Then, the update device 6 transmits the generated authentication information u and hash value h to the relay device 3. Note that the hash value h can be calculated correctly only when the secret information s and the second random number d are known. Also, it is difficult to derive the secret information s or the second random number d from the hash value h using this function.
[0079] Next, the relay device 3 receives the authentication information u and the hash value h and encrypts the first random number g r and the authentication information u are applied to a preset verification formula (1) for calculation. Furthermore, the relay device 3 performs hash function calculations by itself using the second random number d and the secret information s to calculate the hash value h'. The relay device 3 then compares the calculated hash value h' with the hash value h received from the update device 6. If the verification formula (1) holds and both hash values h and h' match, the relay device 3 permits access from the update device 6. On the other hand, if the verification formula (1) does not hold or if both hash values h and h' do not match, the relay device 3 determines that the access is from an unauthorized device and denies the access.
[0080] Next, if the relay device 3 permits access, it transmits a notification to that effect to the update device 6. At this point, the worker can perform the update using the update device 6. For example, update parameters are transmitted from the update device 6 to the relay device 3. Then, the relay device 3 updates the parameters.
[0081] In the third embodiment, in addition to verifying the authentication information u, the hash values h and h' are collated, so that it is possible to confirm that the update device 6 is legitimate. Therefore, it is possible to improve the security in the process for authenticating the update device 6.
[0082] In the third embodiment, the relay device 3 and the update device 6 may be connected one-to-one via a wire. In this way, information exchanged between the relay device 3 and the update device 6 is not susceptible to eavesdropping, and maintenance or updating can be performed safely.
[0083] The wireless transmission system and wireless transmission method have been described based on the first to third embodiments, but the configuration applied in any one of the embodiments may be applied to another embodiment, or the configurations applied in each embodiment may be combined.
[0084] The system of the above-described embodiment includes a control device with a highly integrated processor such as a dedicated chip, FPGA (Field Programmable Gate Array), GPU (Graphics Processing Unit), or CPU (Central Processing Unit), a storage device such as ROM (Read Only Memory) or RAM (Random Access Memory), an external storage device such as HDD (Hard Disk Drive) or SSD (Solid State Drive), a display device such as a monitor, an input device such as a mouse or keyboard, and a communication interface. This system can be realized with a hardware configuration using a normal computer.
[0085] The programs executed by the systems of the above-described embodiments are provided in advance in a ROM, etc. Alternatively, the programs may be provided in the form of installable or executable files stored on a computer-readable, non-transitory storage medium such as a CD-ROM, CD-R, memory card, DVD, or flexible disk (FD).
[0086] The programs executed by this system may be stored on a computer connected to a network such as the Internet and provided by downloading them via the network. This system may also be configured by combining separate modules that independently perform the functions of the components and interconnect them via a network or dedicated lines.
[0087] In the above embodiment, the update device 6 first transmits the encrypted first random number to the relay device 3, then the relay device 3 transmits the second random number to the update device 6, and then the update device 6 transmits the authentication information to the relay device 3, but other modes are also possible. For example, the relay device 3 may first transmit the second random number to the update device 6, and then the update device 6 may simultaneously transmit the encrypted first random number and the authentication information to the relay device 3.
[0088] The first random number and the second random number in the above-described embodiment may be generated by software or hardware. Here, the first random number and the second random number may be different values or may be the same value.
[0089] Furthermore, in the above-described embodiment, the first random number and the second random number are newly generated each time the update device 6 accesses the relay device 3, thereby improving resistance to brute-force attacks compared to a system in which IDs and passwords are reused.
[0090] According to at least one of the embodiments described above, the relay device can improve security when performing maintenance or updates on the relay device by allowing access from the update device if the verification formula is satisfied.
[0091] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be implemented in various other forms, and various omissions, substitutions, modifications, and combinations can be made without departing from the spirit of the invention. These embodiments and modifications thereof are intended to be included within the scope and spirit of the invention, as well as within the scope of the invention described in the claims and their equivalents. [Explanation of symbols]
[0092] 1...wireless transmission system, 2...wireless device, 3 (3A, 3B, 3C, 3D)...relay device, 4...transmitter / receiver device, 5...matching / decoding device, 6...update device, 7...USB memory, 10...communication unit, 11...memory unit, 12...control unit, 13...second random number generation unit, 14...verification unit, 20...communication unit, 21...memory unit, 22...input unit, 23...output unit, 24...biometric authentication unit, 25...control unit, 26...first random number generation unit, 27...authentication information generation unit.
Claims
1. a relay device that relays communication data transmitted from the wireless device; an update device that remotely accesses the relay device and performs maintenance or updates on the relay device; Equipped with the update device transmits the generated first random number to the relay device in an encrypted state; the relay device transmits the generated second random number to the update device; the update device that has received the second random number generates authentication information from the first random number, the second random number, concealed secret information that has been shared with the relay device in advance, and concealed additional secret information that has been shared with the relay device in advance together with the secret information and is additionally set in a verification formula, and transmits the generated authentication information to the relay device; the relay device that has received the encrypted first random number and the authentication information performs calculations by applying the encrypted first random number and the authentication information to the preset verification formula; the relay device permits access from the update device if the verification formula is satisfied. It is structured as follows: The authentication information u' is expressed by the following formula: u'=(r+sd+s'd) mod q where r is the first random number, d is the second random number, s is the secret information, and s′ is the additional secret information. Wireless transmission system.
2. a portable storage medium is detachably attached to the relay device and the update device, and the additional secret information is shared by attaching the storage medium storing the additional secret information to at least one of the relay device and the update device; 10. The wireless transmission system of claim 1.
3. the relay device performs encryption processing or authentication processing on the communication data and relays the communication data; the update device updates parameters used in the encryption process or the authentication process in the relay device.
3. The wireless transmission system according to claim 1 or 2.
4. At least a part of the secret information or the additional secret information is composed of biometric information of a worker who performs maintenance or updating. The wireless transmission system according to any one of claims 1 to 3.
5. One of the update devices accesses a plurality of the relay devices to perform maintenance or update of the relay devices. The wireless transmission system according to any one of claims 1 to 4.
6. One of the update devices accesses one of the relay devices to perform maintenance or update of the relay device.
6. The wireless transmission system according to claim 1.
7. 1. A wireless transmission method using a relay device that relays communication data transmitted from a wireless device, comprising: an update device is provided that accesses the relay device from a remote location and performs maintenance or updates on the relay device; the update device transmits the generated first random number to the relay device in an encrypted state; the relay device transmits the generated second random number to the update device; the update device that has received the second random number generates authentication information from the first random number, the second random number, concealed secret information that has been shared with the relay device in advance, and concealed additional secret information that has been shared with the relay device in advance together with the secret information and is additionally set in a verification formula, and transmits the generated authentication information to the relay device; the relay device that has received the encrypted first random number and the authentication information performs calculations by applying the encrypted first random number and the authentication information to the preset verification formula; the relay device permits access from the update device if the verification formula is satisfied. Execute the process, The authentication information u' is expressed by the following formula: u'=(r+sd+s'd) mod q where r is the first random number, d is the second random number, s is the secret information, and s′ is the additional secret information. Wireless transmission method.
Citation Information
Patent Citations
Remote operation system, its controlling method and program for realizing that controlling method
JP2003230186A
IC card system and computer program
JP2006243860A
Authentication system and determination method
JP2008276603A
Authentication system, and authentication method
JP2009017516A
Data collection system
JP2010193118A