Air conditioning system and authentication method
A networked authentication system in air conditioning systems authenticates devices within their respective networks in parallel, addressing the inefficiency of single-point verification, thereby reducing authentication time and enhancing security.
Patent Information
- Application Number
- JP2025525431
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-05
- Publication Date
- 2025-12-01
- Estimated Expiration
- 2043-06-05
AI Technical Summary
Existing air conditioning systems lack efficient device authentication methods that can quickly verify the legitimacy of all devices within the system, leading to prolonged authentication times.
Implementing a networked authentication system where each network within the air conditioning system includes an authentication device that authenticates other devices within its network, allowing for parallel authentication processes across multiple networks.
This approach significantly reduces the time required for device authentication in air conditioning systems by enabling simultaneous verification across networks, improving security and efficiency.
Smart Images

Figure 0007778274000001 
Figure 0007778274000002 
Figure 0007778274000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an air conditioning system and an authentication method. [Background technology]
[0002] In recent years, there have been cases where air conditioning systems equipped with outdoor and indoor units have been targeted by cyberattacks. For this reason, security measures against cyberattacks are desired for air conditioning systems. One example of such security measures is device authentication, which verifies that each device in an air conditioning system is legitimate.
[0003] Such technology relating to device authentication is described, for example, in Patent Document 1. Patent Document 1 describes an air conditioning system in which an outdoor unit provided in an air conditioner authenticates a system controller that operates the air conditioner. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] International Publication No. 2021 / 166105 Summary of the Invention [Problem to be solved by the invention]
[0005] However, the technology described in Patent Document 1 is insufficient as a security measure because it does not authenticate any devices other than the system controller among the devices included in the air conditioning system. Here, for example, if one device included in the air conditioning system authenticates all other devices, the time required for device authentication would be enormous. For this reason, there is a demand for technology that shortens the time required for authenticating devices included in the air conditioning system.
[0006] The present disclosure has been made in consideration of the above-mentioned problems, and aims to provide an air conditioning system and an authentication method that reduce the time required to authenticate devices included in the air conditioning system. [Means for solving the problem]
[0007] In order to achieve the above object, the air conditioning system according to the present disclosure comprises: An air conditioning system having a plurality of devices including an outdoor unit and an indoor unit, each of the plurality of devices belongs to at least one network among a plurality of networks; Each of the plurality of networks includes an authentication device that authenticates other devices that belong to the network to which the device belongs. picture, the plurality of networks includes a first network and a second network; The plurality of devices includes a first authentication device that belongs to the first network and authenticates other devices that belong to the first network, and a second authentication device that belongs to the first network and the second network, is authenticated by the first authentication device, and authenticates other devices that belong to the second network. . [Effects of the Invention]
[0008] In the present disclosure, each of the multiple networks includes an authentication device that authenticates other devices that belong to the network to which the device belongs. Therefore, according to the present disclosure, it is possible to reduce the time required to authenticate devices included in the air conditioning system. [Brief explanation of the drawings]
[0009] [Figure 1] Configuration diagram of an air conditioning system according to embodiment 1 [Figure 2] Configuration diagram of device according to embodiment 1 [Figure 3] An explanation of the authentication procedure for each device [Figure 4] An explanatory diagram of an authentication method in an air conditioning system according to embodiment 1. [Figure 5] Illustration of authentication-related information [Figure 6] FIG. 1 is a sequence diagram showing the flow of processing executed by each device according to the first embodiment. [Figure 7] Configuration diagram of an air conditioning system according to embodiment 2 [Figure 8] An explanatory diagram of an authentication method in an air conditioning system according to a second embodiment. [Figure 9] FIG. 10 is a sequence diagram showing the flow of processing executed by each device according to the second embodiment. [Figure 10] An explanatory diagram of an authentication method in an air conditioning system according to a third embodiment. [Figure 11] An explanatory diagram of an authentication method in an air conditioning system according to a fourth embodiment [Figure 12] An explanatory diagram of an authentication method in an air conditioning system according to a fifth embodiment [Figure 13] An explanatory diagram of an authentication method in an air conditioning system according to a sixth embodiment [Figure 14] A sequence diagram showing the flow of processing executed by each device according to the sixth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals.
[0011] (Embodiment 1) Fig. 1 is a diagram showing the configuration of an air conditioning system 1000 according to this embodiment. The air conditioning system 1000 is a system for conditioning the air inside a building, condominium, apartment, factory, etc. The air conditioning system 1000 has a function for authenticating each device included in the air conditioning system 1000. Device authentication is to confirm whether a device is a legitimate device or an illegitimate device.
[0012] An authentic device is, for example, a device that has not been disguised by spoofing and is a reliable device. An unauthorized device is, for example, a device that has been disguised by spoofing and is an unreliable device. The air conditioning system 1000 includes a cloud server 110, a system controller 120, an outdoor unit 131, an outdoor unit 132, an indoor unit 141, an indoor unit 142, an individual controller 143, an indoor unit 144, an indoor unit 145, an individual controller 146, an individual controller 151, and a communication adapter 152.
[0013] The cloud server 110 is a server that provides resources in cloud computing and services related to air conditioning processing. In this embodiment, the cloud server 110 remotely controls or monitors each device included in the air conditioning system 1000 via the system controller 120.
[0014] The system controller 120 is a device that controls the overall operation of the air conditioning system 1000. The cloud server 110 and the system controller 120 are connected to each other via at least one of a communication line 311 and a communication line 312. In other words, the cloud server 110 and the system controller 120 may be connected to each other via the communication line 311, or may be connected to each other via the communication lines 311 and 312 that are connected to each other by a broadband router 500.
[0015] The communication line 311 is the Internet, a telephone network, or the like. This telephone network is compatible with LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), or the like. The communication line 312 is, for example, a line for a LAN (Local Area Network) provided in a building, condominium, apartment, factory, or the like. The cloud server 110, the system controller 120, the communication line 311, and the communication line 312 constitute a network 210. The network 210 is a network to which devices used for remote control, among those provided in the air conditioning system 1000, are connected. Hereinafter, the network 210 will be referred to as a remote control system, and communication using the network 210 will be referred to as remote control system communication, as appropriate.
[0016] Outdoor unit 131 and outdoor unit 132 are equipment that condition indoor air and are installed outdoors. Conditioning indoor air means adjusting the temperature, humidity, air cleanliness, etc. of the indoor air. Indoor unit 141, indoor unit 142, indoor unit 144, and indoor unit 145 are equipment that condition indoor air and are installed indoors. Indoor unit 141, indoor unit 142, indoor unit 144, and indoor unit 145 blow air into the room for heating, cooling, dehumidification, ventilation, etc. Outdoor unit 131 circulates a refrigerant between indoor unit 141 and indoor unit 142 via refrigerant piping (not shown). Outdoor unit 132 circulates a refrigerant between indoor unit 144 and indoor unit 145 via refrigerant piping (not shown).
[0017] The individual controller 143 is a controller for controlling devices that belong to the network 231 to which the own device belongs. In other words, the individual controller 143 is a controller for controlling the outdoor unit 131, the indoor unit 141, and the indoor unit 142. The individual controller 146 is a controller for controlling devices that belong to the network 232 to which the own device belongs. In other words, the individual controller 146 is a controller for controlling the outdoor unit 132, the indoor unit 144, and the indoor unit 145.
[0018] The system controller 120 and the outdoor units 131 and 132 are connected to each other via a communication line 320. The communication line 320 is a line for connecting the system controller 120 and the air conditioning apparatuses. In this embodiment, the air conditioning apparatuses connected to the system controller 120 are two air conditioning apparatuses, the outdoor units 131 and 132. The system controller 120, the outdoor units 131 and 132, and the communication line 320 constitute a network 220. The network 220 is a network in which the system controller 120 and the air conditioning apparatuses are connected. Hereinafter, the network 220 will be referred to as a system controller system, and communication using the network 220 will be referred to as system controller system communication, as appropriate.
[0019] The outdoor unit 131, the indoor unit 141, the indoor unit 142, and the individual controller 143 are connected to one another via a communication line 331. The outdoor unit 132, the indoor unit 144, the indoor unit 145, and the individual controller 146 are connected to one another via a communication line 332. Each of the communication lines 331 and 332 is a line for connecting devices in the same refrigerant system.
[0020] The outdoor unit 131, the indoor unit 141, the indoor unit 142, the individual controller 143, and the communication line 331 constitute a network 231. The outdoor unit 132, the indoor unit 144, the indoor unit 145, the individual controller 146, and the communication line 332 constitute a network 232. Each of the networks 231 and 232 is a network to which devices in the same refrigerant system are connected. Hereinafter, the networks 231 and 232 will be referred to as the refrigerant system, and communication using the network 231 or the network 232 will be referred to as refrigerant system communication, as appropriate.
[0021] The individual controller 151 is a controller for controlling devices connected to itself. In other words, the individual controller 151 is a controller for controlling the indoor unit 141. The indoor unit 141 and the individual controller 151 are connected to each other via a communication line 341. The communication line 341 is a line for connecting the indoor unit 141 and the individual controller 151. The indoor unit 141, the individual controller 151, and the communication line 341 constitute a network 241. The network 241 is a network in which the indoor unit 141 and the individual controller 151 are connected. Hereinafter, the network 241 will be referred to as an individual controller system, and communication using the network 241 will be referred to as individual controller system communication, as appropriate.
[0022] The communication adapter 152 is a communication adapter for expanding the system to which the devices connected to the communication adapter 152 belong. In other words, the communication adapter 152 is a communication adapter for expanding the air conditioning system 1000 to which the indoor unit 145 belongs. The indoor unit 145 and the communication adapter 152 are connected to each other via a communication line 342. The communication line 342 is a line for connecting the indoor unit 145 and the communication adapter 152. The indoor unit 145, the communication adapter 152, and the communication line 342 configure a network 242.
[0023] The network 242 is a network to which the indoor unit 145 and the communication adapter 152 are connected. Hereinafter, the network 242 will be referred to as a system expansion system, and communication using the network 242 will be referred to as system expansion system communication, as appropriate. The communication adapter 152 has a function of connecting the network 232 with a network not shown. Therefore, the communication adapter 152 is also connected to devices not shown that belong to a network not shown.
[0024] As described above, the air conditioning system 1000 includes a plurality of devices 100 that belong to at least one of a plurality of networks included in the air conditioning system 1000. The device 100 is a collective term for the outdoor unit 131, the outdoor unit 132, the indoor unit 141, the indoor unit 142, the individual controller 143, the indoor unit 144, the indoor unit 145, the individual controller 146, the individual controller 151, and the communication adapter 152. As shown in FIG. 2 , the device 100 includes, for example, a control unit 11, a memory unit 12, a display unit 13, an operation reception unit 14, a first communication unit 15, and a second communication unit 16.
[0025] The control unit 11 includes a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), RTC (Real Time Clock), etc. The CPU is also called a central processing unit, central arithmetic unit, processor, microprocessor, microcomputer, DSP (Digital Signal Processor), etc., and functions as a central processing unit that executes processes and calculations related to the control of the device 100. In the control unit 11, the CPU reads programs and data stored in the ROM and uses the RAM as a work area to perform overall control of the device 100. The RTC is, for example, an integrated circuit with a timekeeping function. The CPU can determine the current date and time from the time information read from the RTC.
[0026] The storage unit 12 includes a nonvolatile semiconductor memory such as a flash memory, an EPROM (Erasable Programmable ROM), or an EEPROM (Electrically Erasable Programmable ROM), and serves as a so-called auxiliary storage device. The storage unit 12 stores programs and data used by the control unit 11 to execute various processes. The storage unit 12 also stores data generated or acquired by the control unit 11 as a result of executing various processes.
[0027] The display unit 13 displays various images under the control of the control unit 11. For example, the display unit 13 displays a screen for accepting various operations from the user. The display unit 13 includes a touch screen, a liquid crystal display, etc. The operation accepting unit 14 accepts various operations from the user and supplies information indicating the contents of the accepted operations to the control unit 11. The operation accepting unit 14 includes a touch screen, a button, a lever, etc.
[0028] The first communication unit 15 communicates with the device 100 connected to a certain network under the control of the control unit 11. The second communication unit 16 communicates with the device 100 connected to another network under the control of the control unit 11. The first communication unit 15 and the second communication unit 16 communicate with the device 100 in accordance with various wired communication standards or various wireless communication standards. Wireless communication standards include Wi-Fi (registered trademark), Bluetooth (registered trademark), Zigbee (registered trademark), LTE (Long Term Evolution), 4G (4th Generation), 5G (5th Generation), etc. Wired communication standards include Ethernet (registered trademark), USB (Universal Serial Bus, registered trademark), Thunderbolt (registered trademark), etc. The first communication unit 15 and the second communication unit 16 are provided with communication interfaces that comply with various communication standards.
[0029] It should be noted that device 100 does not necessarily have to include all of control unit 11, storage unit 12, display unit 13, operation reception unit 14, first communication unit 15, and second communication unit 16. For example, device 100 may not have display unit 13, may not have operation reception unit 14, may not have first communication unit 15, or may not have second communication unit 16.
[0030] Next, the authentication procedure for each device 100 employed in the air conditioning system 1000 will be described with reference to FIG.
[0031] First, in the present embodiment, each of the multiple devices 100 included in the air conditioning system 1000 belongs to at least one of the multiple networks 200 included in the air conditioning system 1000. Network 200 is a collective term for network 210, network 220, network 231, network 232, network 241, and network 242. Each of the multiple networks 200 includes an authentication device that authenticates other devices that belong to the network 200 to which the device itself belongs, and an authenticatee device that is authenticated by the authentication device. In the present embodiment, authentication of the device 100 is not performed across networks 200, and authentication of the device 100 is completed within the network 200. In other words, in the present embodiment, authentication of the device 100 is performed for each network 200.
[0032] In this embodiment, the multiple networks 200 included in the air conditioning system 1000 include a first network, a second network, and a third network, and the multiple devices 100 included in the air conditioning system 1000 include a first authenticated device, a second authenticated device, and a third authenticated device. The first authenticated device belongs to the first network and authenticates other devices that belong to the first network. The second authenticated device belongs to both the first network and the second network, is authenticated by the first authenticated device, and authenticates other devices that belong to the second network. The third authenticated device belongs to both the second network and the third network, is authenticated by the second authenticated device, and authenticates other devices that belong to the third network.
[0033] For example, as shown in Fig. 3, assume that in network 200A, devices 100A, 100B, and 100C are connected by communication line 300A; in network 200B, devices 100B, 100D, and 100E are connected by communication line 300B; and in network 200C, devices 100D, 100F, and 100G are connected by communication line 300C. Hereinafter, communication lines 300A, 300B, and 300C will be collectively referred to as communication line 300 as appropriate. In this case, in network 200A, device 100A authenticates devices 100B and 100C. Therefore, device 100A is the authenticating device, and devices 100B and 100C are authenticated devices.
[0034] In network 200B, device 100B authenticates devices 100D and 100E. Therefore, device 100B is an authenticating device, and devices 100D and 100E are devices to be authenticated. In network 200C, device 100D authenticates devices 100F and 100G. Therefore, device 100D is an authenticating device, and devices 100F and 100G are devices to be authenticated.
[0035] Network 200A is an example of a first network, network 200B is an example of a second network, and network 200C is an example of a third network. Device 100A is an example of a first authenticated device, device 100B is an example of a second authenticated device, and device 100D is an example of a third authenticated device. In this embodiment, in each network 200, one authenticated device authenticates all other devices 100 as devices to be authenticated, and authenticated devices other than the first authenticated device are authenticated by authenticated devices belonging to the other networks 200.
[0036] In this embodiment, network 210 corresponds to network 200A, network 220 corresponds to network 200B, and networks 231 and 232 correspond to network 200C. In this embodiment, cloud server 110 corresponds to device 100A, system controller 120 corresponds to device 100B, and outdoor units 131 and 132 correspond to device 100C.
[0037] Hereinafter, an authentication method in the air conditioning system 1000 will be specifically described with reference to Fig. 4. As shown in Fig. 4, in this embodiment, a plurality of devices 100 included in the air conditioning system 1000 are connected in a tree structure.
[0038] The cloud server 110 is the root node. The system controller 120 is a child node having the cloud server 110 as its parent node. The outdoor units 131 and 132 are child nodes having the system controller 120 as its parent node. The indoor units 141, 142, and the individual controller 143 are child nodes having the outdoor unit 131 as its parent node. The indoor units 144, 145, and the individual controller 146 are child nodes having the outdoor unit 132 as its parent node. The individual controller 151 is a child node having the indoor unit 141 as its parent node. The communication adapter 152 is a child node having the indoor unit 145 as its parent node.
[0039] In this embodiment, a parent node authenticates a child node. That is, an authentication device provided in each of multiple networks 200 authenticates a device 100 that corresponds to a child node from the perspective of the authentication device itself. Specifically, cloud server 110, which is a first authentication device, authenticates system controller 120 within network 210, which is a first network. System controller 120, which is a second authentication device, authenticates outdoor units 131 and 132 within network 220, which is a second network.
[0040] The outdoor unit 131, which is the third authenticated device, authenticates the indoor units 141, 142, and individual controller 143 within network 231, which is the third network. The outdoor unit 132, which is the third authenticated device, authenticates the indoor units 144, 145, and individual controller 146 within network 232, which is the third network. The indoor unit 141, which is the fourth authenticated device, authenticates the individual controller 151 within network 241, which is the fourth network. The indoor unit 145, which is the fourth authenticated device, authenticates the communication adapter 152 within network 242, which is the fourth network.
[0041] In this way, the devices 100 that belong to the upper network 200 and the lower network 200 are devices to be authenticated in the upper network 200, and are devices to be authenticated in the lower network 200. For example, the outdoor unit 131 is a device to be authenticated in the network 220, and is a device to be authenticated in the network 231. Also, for example, the indoor unit 141 is a device to be authenticated in the network 231, and is an authenticating device in the network 241.
[0042] In this embodiment, the authenticating device authenticates the device to be authenticated based on authentication-related information written in the storage unit 12 of the device 100 when the device 100 is shipped. Fig. 5 shows the authentication-related information. The authentication-related information includes a CA (Certificate Authority) certificate, a device certificate, a device private key, and a device public key. The CA certificate is a certificate common to all manufacturers and is used to verify the device certificate. The CA certificate is created by the manufacturer and written in the storage unit 12 of each device 100 when the device 100 is shipped from the factory. The CA certificate includes a CA public key. Information encrypted with the CA private key can be decrypted with the CA public key.
[0043] The device certificate is a certificate unique to the device 100, and includes a device public key signed with a CA private key. The device certificate is created by the manufacturer and written to the storage unit 12 of the device 100 when the device 100 is shipped from the factory. The device private key is a private key unique to the device 100. The device public key is a public key unique to the device 100. Information encrypted with the device public key can be decrypted with the device private key. The device private key and device public key are created by the device 100 itself and written to the storage unit 12 of the device 100 when the device 100 is shipped from the factory.
[0044] In this embodiment, the authenticating device authenticates the device to be authenticated by verifying the device certificate of the device to be authenticated, acquired from the device to be authenticated, with a CA certificate held by the authenticating device. The authentication process executed by the air conditioning system 1000 will be described below with reference to Fig. 6. Note that Fig. 6 shows sequences relating to the cloud server 110, system controller 120, outdoor unit 131, indoor unit 141, and individual controller 151, and omits sequences relating to other devices.
[0045] The cloud server 110, the system controller 120, the outdoor unit 131, the indoor unit 141, and the individual controller 151 each start device authentication in response to the occurrence of a device authentication trigger. The device authentication trigger may be set for each device 100, for example, and the devices 100 in each network may proceed with device authentication completely in parallel. Therefore, the order in which device authentication is started is not limited to the example shown in FIG. 6. For example, in FIG. 6, device authentication of the outdoor unit 131 by the system controller 120 may be performed after device authentication of the individual controller 151 by the indoor unit 141. Possible triggers for device authentication include a user operation on a user interface, a trigger based on plug-and-play, etc. Possible user operations include a user operation on the operation reception unit 14, which includes a touch screen, a DIP switch, etc.
[0046] When the above-mentioned trigger occurs, in step ST111, the cloud server 110 requests the system controller 120 for the device certificate of the system controller 120. Meanwhile, in step ST122, the system controller 120 transmits the device certificate of the system controller 120 to the cloud server 110. In step ST113, the cloud server 110 verifies the device certificate received from the system controller 120 with a CA certificate held by the cloud server 110.
[0047] Specifically, the cloud server 110 decrypts the device public key, which is included in the device certificate and signed with the CA private key, using the CA public key included in the CA certificate. If the cloud server 110 successfully decrypts the device public key using the CA public key, it determines that the device certificate is a valid certificate and that the system controller 120 is a valid device 100. If the cloud server 110 fails to decrypt the device public key using the CA public key, it determines that the device certificate is an invalid certificate and that the system controller 120 is an invalid device 100.
[0048] Furthermore, when the above-mentioned trigger occurs, in step ST121, the system controller 120 requests the outdoor unit 131 for its device certificate. Meanwhile, in step ST132, the outdoor unit 131 transmits the device certificate of the outdoor unit 131 to the system controller 120. In step ST123, the system controller 120 verifies the device certificate received from the outdoor unit 131 with a CA certificate held by the system controller 120.
[0049] The system controller 120, the outdoor unit 131, the indoor unit 141, etc. verify the device certificate with the CA certificate using the same method as the cloud server 110. Although not shown, the system controller 120 also requests a device certificate from the outdoor unit 132, and verifies the device certificate obtained from the outdoor unit 132 with the CA certificate.
[0050] When the above-mentioned trigger occurs, in step ST131, the outdoor unit 131 requests the indoor unit 141 for the device certificate of the indoor unit 141. Meanwhile, in step ST142, the indoor unit 141 transmits the device certificate of the indoor unit 141 to the outdoor unit 131. In step ST133, the outdoor unit 131 verifies the device certificate received from the indoor unit 141 with the CA certificate held by the outdoor unit 131.
[0051] Although not shown in the figure, the outdoor unit 131 also requests device certificates from the indoor unit 142 and the individual controller 143, and verifies the device certificates acquired from the indoor unit 142 and the individual controller 143 using a CA certificate. Also, although not shown in the figure, the outdoor unit 132 also requests device certificates from the indoor unit 144, the indoor unit 145, and the individual controller 146, and verifies the device certificates acquired from the indoor unit 144, the indoor unit 145, and the individual controller 146 using a CA certificate.
[0052] When the above-mentioned trigger occurs, in step ST141, the indoor unit 141 requests the individual controller 151 for its device certificate. Meanwhile, in step ST152, the individual controller 151 transmits the device certificate of the individual controller 151 to the indoor unit 141. In step ST143, the indoor unit 141 verifies the device certificate received from the individual controller 151 with a CA certificate held by the indoor unit 141. Although not shown in the figure, the indoor unit 145 requests the communication adapter 152 for a device certificate and verifies the device certificate acquired from the communication adapter 152 with the CA certificate.
[0053] The authentication device transmits the authentication result of its own device and the authentication result acquired from the child node to the parent node. Specifically, in step ST144, the indoor unit 141 transmits the authentication result for the individual controller 151 to the outdoor unit 131. Also, although not shown, the indoor unit 145 transmits the authentication result for the communication adapter 152 to the outdoor unit 132. Also, in step ST134, the outdoor unit 131 transmits the authentication results for the indoor unit 141, the indoor unit 142, the individual controller 143, and the individual controller 151 to the system controller 120.
[0054] Furthermore, although not shown in the figures, the outdoor unit 132 transmits the authentication results for the indoor units 144, 145, individual controllers 146, and communication adapter 152 to the system controller 120. Furthermore, in step ST124, the system controller 120 transmits the authentication results for the outdoor units 131, 132, indoor units 141, 142, individual controllers 143, indoor units 144, 145, individual controllers 146, individual controller 151, and communication adapter 152 to the cloud server 110. As a result, all authentication results are supplied to the cloud server 110, which is the root node.
[0055] Thereafter, encrypted communication is performed between the authenticated devices 100. Specifically, first, the authenticating device generates a pair of a network public key and a network private key. The authenticating device encrypts a network certificate signed with the authenticating device's device private key and the network private key with the device public key of the device to be authenticated, and transmits them to the device to be authenticated. The device to be authenticated decrypts the encrypted network certificate and network private key with the device private key of the device to be authenticated. The network certificate includes the network public key. Thereafter, the authenticating device and the device to be authenticated perform encrypted communication based on the network certificate, for example, in accordance with the DTLS (Datagram Transport Layer Security) protocol.
[0056] In this embodiment, each of the multiple networks 200 included in the air conditioning system 1000 includes an authentication device that authenticates other devices that belong to the network 200 to which the air conditioning system 1000 belongs. That is, in this embodiment, an authentication device is provided for each network 200, and device authentication is performed for each network 200. Therefore, in this embodiment, authentication sequences in the multiple networks 200 can be performed in parallel.
[0057] In this embodiment, the time required for device authentication of the entire air conditioning system 1000 is shorter than in a configuration in which a single device 100, such as the cloud server 110 or the system controller 120, authenticates all of the other devices 100. In other words, according to this embodiment, it is possible to reduce the time required for authenticating the devices 100 included in the air conditioning system 1000. Note that each authenticated device does not need to have very high processing power, because it does not need to authenticate devices 100 that belong to a network 200 to which the authenticated device does not belong.
[0058] In addition, in this embodiment, a second authenticated device that belongs to both the first network and the second network and authenticates other devices that belong to the second network is authenticated by the first authenticated device that belongs to the first network. In addition, in this embodiment, a third authenticated device that belongs to both the second network and the third network and authenticates other devices that belong to the third network is authenticated by the second authenticated device that belongs to the second network. In other words, in this embodiment, authenticated devices other than the first authenticated device are authenticated by the other authenticated devices. Therefore, according to this embodiment, it is possible to authenticate all devices 100 other than the first authenticated device, which is the base point of authentication.
[0059] Furthermore, in this embodiment, the first authenticated device is cloud server 110, and the second authenticated device is system controller 120. Cloud server 110 is a device 100 that is less susceptible to spoofing and is more reliable than system controller 120. For this reason, it is believed that no particular problem will arise if cloud server 110 is not authenticated by other devices. Furthermore, system controller 120 is authenticated by cloud server 110. Therefore, according to this embodiment, improved security can be expected.
[0060] Furthermore, in this embodiment, the multiple devices 100 included in the air conditioning system 1000 are connected in a tree structure, and the authentication devices included in each of the multiple networks 200 authenticate the devices 100 that correspond to child nodes from the perspective of the device itself. In this embodiment, a chain of device authentication is established in which parent nodes authenticate child nodes with the root node as the base point. Therefore, according to this embodiment, all devices 100 other than the root node are properly authenticated.
[0061] Furthermore, in this embodiment, the authentication sequence in each network 200 is independent, and it is possible to employ an authentication sequence that is not dependent on the device configuration, network configuration, etc. For example, in this embodiment, a first authenticated device, which is the base point of device authentication, authenticates other devices that belong to the first network to which the first authenticated device belongs. If the first authenticated device belongs to multiple first networks, the first authenticated device authenticates other devices that belong to each of the first networks. If the device to be authenticated, which has been authenticated by the first authenticated device, also belongs to a second network to which the first authenticated device does not belong, it authenticates other devices that belong to the second network as a second authenticated device.
[0062] If the device to be authenticated that has been authenticated by the second authentication device also belongs to a third network to which the second authentication device does not belong, it authenticates other devices that belong to the third network as the third authentication device. Subsequently, using a similar procedure, if there are other devices that the device to be authenticated that has been authenticated by the authentication device itself should authenticate, it authenticates the other devices as the authenticating device. With this configuration, all devices 100 other than the first authentication device, which is the base point of device authentication, are authenticated.
[0063] (Embodiment 2) In the first embodiment, an example has been described in which device authentication is performed based on a highly reliable cloud server 110 that is difficult to spoof. In the present embodiment, an example will be described in which device authentication is performed based on a highly reliable refrigerant system device 100 that is difficult to spoof when such a cloud server 110 does not exist. Note that the description of the same configurations and functions as those in the first embodiment will be omitted or simplified as appropriate.
[0064] 7 is a diagram showing the configuration of an air conditioning system 1200 according to this embodiment. The air conditioning system 1200 includes a system controller 120, an outdoor unit 131, an outdoor unit 132, an indoor unit 141, an indoor unit 142, an individual controller 143, an indoor unit 144, an indoor unit 145, an individual controller 146, an individual controller 151, and a communication adapter 152. The air conditioning system 1200 does not include a cloud server 110 that is difficult to spoof and highly reliable. Therefore, in this embodiment, device authentication is performed based on refrigerant system devices 100 that are considered difficult to spoof and highly reliable, among the devices 100 included in the air conditioning system 1200.
[0065] The refrigerant system devices 100 include outdoor unit 131, outdoor unit 132, indoor unit 141, indoor unit 142, indoor unit 144, indoor unit 145, and the like. Generally, when considering the size of an outdoor unit and an indoor unit, it is considered that outdoor units are more difficult to replace with counterfeits and are less likely to be disguised. In other words, outdoor units are considered to be more reliable than indoor units. Furthermore, outdoor units generally often have higher processing capabilities than indoor units. Therefore, in this embodiment, the outdoor units are used as the base point for device authentication. Specifically, in this embodiment, outdoor units 131 and 132 are used as the base points for device authentication.
[0066] As shown in FIG. 8, in this embodiment, a plurality of devices 100 included in an air conditioning system 1200 are connected in a tree structure, with the system controller 120 being the root node.
[0067] In this embodiment, outdoor unit 131, which is a first authenticated device, authenticates system controller 120 within network 220, which is a first network. Outdoor unit 131 authenticates indoor units 141, 142, and individual controller 143 within network 231, which is the first network. Outdoor unit 132, which is a first authenticated device, authenticates system controller 120 within network 220, which is the first network. Outdoor unit 132 authenticates indoor units 144, 145, and individual controller 146 within network 232, which is the first network. Indoor unit 141, which is a second authenticated device, authenticates individual controller 151 within network 241, which is the second network. Indoor unit 145, which is a second authenticated device, authenticates communication adapter 152 within network 242, which is the second network.
[0068] In this embodiment as well, the authenticating device authenticates the device to be authenticated by verifying the device certificate of the device to be authenticated, acquired from the device to be authenticated, with the CA certificate held by the authenticating device. The authentication process executed by the air conditioning system 1200 will be described below with reference to Fig. 9. Note that Fig. 9 shows a sequence relating to the system controller 120, outdoor unit 131, indoor unit 141, and individual controller 151, and omits sequences relating to other devices.
[0069] First, outdoor unit 131, which is the first authenticated device and the starting point of device authentication, starts device authentication in response to the occurrence of a device authentication trigger. When the trigger occurs, outdoor unit 131 requests the system controller 120 for its device certificate in step ST231A. Meanwhile, system controller 120 transmits the system controller 120's device certificate to outdoor unit 131 in step ST222. In step ST233A, outdoor unit 131 verifies the device certificate received from system controller 120 with a CA certificate held by outdoor unit 131.
[0070] Furthermore, in step ST231B, the outdoor unit 131 requests the indoor unit 141 for its device certificate. Meanwhile, in step ST242, the indoor unit 141 transmits its device certificate to the outdoor unit 131. In step ST233B, the outdoor unit 131 verifies the device certificate received from the indoor unit 141 with a CA certificate held by the outdoor unit 131. Although not shown in the figure, the outdoor unit 131 also requests device certificates from the indoor unit 142 and the individual controller 143, and verifies the device certificates acquired from the indoor unit 142 and the individual controller 143 with the CA certificate. Furthermore, the outdoor unit 131 may authenticate the outdoor unit 132.
[0071] Furthermore, when the above-mentioned trigger occurs, in step ST241, the indoor unit 141 requests the individual controller 151 for the device certificate of the individual controller 151. Meanwhile, in step ST252, the individual controller 151 transmits the device certificate of the individual controller 151 to the indoor unit 141. In step ST243, the indoor unit 141 verifies the device certificate received from the individual controller 151 with the CA certificate held by the indoor unit 141.
[0072] The authentication result is supplied to, for example, the outdoor unit 131, which is the device 100 that is the base point of device authentication. That is, in step ST244, the indoor unit 141 transmits the authentication result for the individual controller 151 to the outdoor unit 131. This allows the outdoor unit 131 to obtain all authentication results of device authentication based on the outdoor unit 131. Although not shown in the figure, the method of device authentication based on the outdoor unit 132 is the same as the method of device authentication based on the outdoor unit 131. After device authentication based on the outdoor unit 131 and device authentication based on the outdoor unit 132 are completed, encrypted communication is performed between the authenticated devices 100.
[0073] In the present embodiment, refrigerant-system devices 100 that are difficult to spoof and highly reliable are the base point of device authentication. Therefore, according to the present embodiment, refrigerant-system devices 100 that are difficult to spoof and highly reliable are prevented from being subjected to improper operations by devices 100 that are easy to spoof and less reliable. Note that, in the present embodiment, of the refrigerant-system devices 100 that are difficult to spoof and highly reliable, outdoor units 131 and 132 are first authenticated devices that are the base point of device authentication. According to the present embodiment, spoofing of indoor unit 141, indoor unit 142, indoor unit 144, and indoor unit 145 can be detected.
[0074] Furthermore, in this embodiment, the first authenticated device, which is the refrigerant system device 100 that is difficult to spoof and highly reliable, or the second authenticated device authenticated by the first authenticated device, authenticates the system controller 120 that is easy to spoof and less reliable. Therefore, according to this embodiment, the refrigerant system device 100 is prevented from being subjected to improper operations by the system controller 120.
[0075] (Embodiment 3) In the second embodiment, an example was described in which device authentication is performed based on a plurality of refrigerant system devices 100. In the present embodiment, an example will be described in which device authentication is performed based on a single refrigerant system device 100. Note that descriptions of configurations and functions similar to those in the first and second embodiments will be omitted or simplified as appropriate.
[0076] As shown in Fig. 10, in the air conditioning system 1300 according to the present embodiment, device authentication is performed with the outdoor unit 131 as the base point of device authentication. Specifically, the outdoor unit 131, which is the first authenticated device, authenticates the system controller 120 and the outdoor unit 132 within network 220, which is the first network. The outdoor unit 131 authenticates the indoor units 141, 142, and the individual controller 143 within network 231, which is the first network. The outdoor unit 132, which is the second authenticated device, authenticates the indoor units 144, 145, and the individual controller 146 within network 232, which is the second network. The indoor unit 141, which is the second authenticated device, authenticates the individual controller 151 within network 241, which is the second network. The indoor unit 145, which is the third authenticated device, authenticates the communication adapter 152 within network 242, which is the third network.
[0077] In this embodiment, of the refrigerant system devices 100 that are difficult to counterfeit and highly reliable, the outdoor unit 131 is the first authenticated device that is the starting point for device authentication. According to this embodiment, counterfeiting of the outdoor unit 132, the indoor unit 141, the indoor unit 142, the indoor unit 144, and the indoor unit 145 can be detected.
[0078] (Fourth embodiment) In the second embodiment, an example has been described in which device authentication is performed based on outdoor units 131 and 132. In the present embodiment, an example will be described in which device authentication is performed based on indoor units 141 and 144. Note that descriptions of configurations and functions similar to those in the first to third embodiments will be omitted or simplified as appropriate.
[0079] As shown in Fig. 11, in air conditioning system 1400 according to this embodiment, device authentication is performed with indoor unit 141 and indoor unit 144 as the base points of device authentication. Specifically, indoor unit 141, which is the first authenticated device, authenticates outdoor unit 131, indoor unit 142, and individual controller 143 within network 231, which is the first network. Indoor unit 141, which is the first authenticated device, authenticates individual controller 151 within network 241, which is the first network. Outdoor unit 131, which is the second authenticated device, authenticates system controller 120 within network 220, which is the second network.
[0080] The indoor unit 144, which is the first authenticated device, authenticates the outdoor unit 132, the indoor unit 145, and the individual controller 146 within network 232, which is the first network. The outdoor unit 132, which is the second authenticated device, authenticates the system controller 120 within network 220, which is the second network. The indoor unit 145, which is the second authenticated device, authenticates the communication adapter 152 within network 242, which is the second network.
[0081] In this embodiment, of the refrigerant system devices 100 that are difficult to counterfeit and highly reliable, the indoor unit 141 and the indoor unit 144 are first authenticated devices that are the base point of device authentication. According to this embodiment, counterfeiting of the outdoor unit 131, the outdoor unit 132, the indoor unit 142, and the indoor unit 145 can be detected.
[0082] (Embodiment 5) In the fourth embodiment, an example in which device authentication is performed based on the indoor units 141 and 144 has been described. In the present embodiment, an example in which device authentication is performed based on the indoor unit 141 will be described. Note that the description of the same configurations and functions as those in the first to fourth embodiments will be omitted or simplified as appropriate.
[0083] 12, in air conditioning system 1500 according to this embodiment, device authentication is performed with indoor unit 141 as the base point of device authentication. Specifically, indoor unit 141, which is the first authenticated device, authenticates outdoor unit 131, indoor unit 142, and individual controller 143 within network 231, which is the first network. Indoor unit 141, which is the first authenticated device, authenticates individual controller 151 within network 241, which is the first network. Outdoor unit 131, which is the second authenticated device, authenticates system controller 120 and outdoor unit 132 within network 220, which is the second network.
[0084] The outdoor unit 132, which is a third authenticated device, authenticates the indoor units 144, 145, and individual controller 146 within the network 232, which is a third network. The indoor unit 145, which is a fourth authenticated device, authenticates the communication adapter 152 within the network 242, which is a fourth network.
[0085] In this embodiment, among the refrigerant system devices 100 that are difficult to counterfeit and highly reliable, the indoor unit 141 is the starting point for device authentication. According to this embodiment, counterfeiting of the outdoor unit 131, the outdoor unit 132, the indoor unit 142, the indoor unit 144, and the indoor unit 145 can be detected.
[0086] (Sixth embodiment) In the first embodiment, an example in which one-way authentication is performed in device authentication has been described. In the present embodiment, an example in which mutual authentication, which is two-way authentication, is performed in device authentication will be described. Note that the description of the same configurations and functions as those in the first to fifth embodiments will be omitted or simplified as appropriate.
[0087] As shown in FIG. 13, in this embodiment, a plurality of devices 100 included in an air conditioning system 1600 are connected in a tree structure with the system controller 120 as the root node.
[0088] In this embodiment, a parent node authenticates a child node, and a child node authenticates a parent node. That is, the system controller 120 authenticates the outdoor units 131 and 132 within the network 220. Furthermore, the outdoor units 131 and 132 authenticate the system controller 120 within the network 220.
[0089] The outdoor unit 131 authenticates the indoor units 141, 142, and individual controllers 143 within the network 231. The indoor units 141, 142, and individual controllers 143 authenticate the outdoor unit 131 within the network 231. The outdoor unit 132 authenticates the indoor units 144, 145, and individual controllers 146 within the network 232. The indoor units 144, 145, and individual controllers 146 authenticate the outdoor unit 132 within the network 232.
[0090] The indoor unit 141 authenticates the individual controller 151 within the network 241. The individual controller 151 authenticates the indoor unit 141 within the network 241. The indoor unit 145 authenticates the communication adapter 152 within the network 242. The communication adapter 152 authenticates the indoor unit 145 within the network 242.
[0091] The authentication process executed by the air conditioning system 1600 will be described below with reference to Fig. 14. Note that Fig. 14 shows sequences relating to the system controller 120, outdoor unit 131, indoor unit 141, and individual controller 151, and omits sequences relating to other devices.
[0092] First, in step ST321, the system controller 120 requests the outdoor unit 131 for the device certificate of the outdoor unit 131. Meanwhile, in step ST332A, the outdoor unit 131 transmits the device certificate of the outdoor unit 131 to the system controller 120. In step ST323, the system controller 120 verifies the device certificate received from the outdoor unit 131 with the CA certificate held by the system controller 120.
[0093] Furthermore, in step ST331B, the outdoor unit 131 requests the system controller 120 for the device certificate of the system controller 120. Meanwhile, in step ST322B, the system controller 120 transmits the device certificate of the system controller 120 to the outdoor unit 131. In step ST333B, the outdoor unit 131 verifies the device certificate received from the system controller 120 with a CA certificate held by the outdoor unit 131. Although not shown in the figure, the system controller 120 and the outdoor unit 132 authenticate each other.
[0094] Furthermore, in step ST331A, the outdoor unit 131 requests the indoor unit 141 for the device certificate of the indoor unit 141. Meanwhile, in step ST342A, the indoor unit 141 transmits the device certificate of the indoor unit 141 to the outdoor unit 131. In step ST333A, the outdoor unit 131 verifies the device certificate received from the indoor unit 141 with the CA certificate held by the outdoor unit 131.
[0095] Furthermore, in step ST341B, the indoor unit 141 requests the outdoor unit 131 for its device certificate. Meanwhile, in step ST332B, the outdoor unit 131 transmits its device certificate to the indoor unit 141. In step ST343B, the indoor unit 141 verifies the device certificate received from the outdoor unit 131 using a CA certificate held by the indoor unit 141. Although not shown, mutual authentication is also performed between the outdoor unit 131 and the indoor unit 142, between the outdoor unit 131 and the individual controller 143, between the outdoor unit 132 and the indoor unit 144, between the outdoor unit 132 and the indoor unit 145, and between the outdoor unit 132 and the individual controller 146.
[0096] Furthermore, in step ST341A, the indoor unit 141 requests the individual controller 151 for the device certificate of the individual controller 151. Meanwhile, in step ST352, the individual controller 151 transmits the device certificate of the individual controller 151 to the indoor unit 141. In step ST343A, the indoor unit 141 verifies the device certificate received from the individual controller 151 with the CA certificate held by the indoor unit 141.
[0097] Furthermore, in step ST351, the individual controller 151 requests the indoor unit 141 for the device certificate of the indoor unit 141. Meanwhile, in step ST342B, the indoor unit 141 transmits the device certificate of the indoor unit 141 to the individual controller 151. In step ST353, the individual controller 151 verifies the device certificate received from the indoor unit 141 with a CA certificate held by the individual controller 151. Furthermore, although not shown in the figure, the indoor unit 145 and the communication adapter 152 authenticate each other.
[0098] The authentication result is supplied to, for example, the system controller 120, which is the root node. Specifically, in step ST354, the individual controller 151 transmits the authentication result for the indoor unit 141 to the indoor unit 141. Also, although not shown in the figure, the communication adapter 152 transmits the authentication result for the indoor unit 145 to the indoor unit 145. Also, in step ST344, the indoor unit 141 transmits the authentication results for the indoor unit 141 and the individual controller 151 to the outdoor unit 131. Also, although not shown in the figure, the indoor unit 145 transmits the authentication results for the indoor unit 145 and the communication adapter 152 to the outdoor unit 132.
[0099] Furthermore, in step ST334, the outdoor unit 131 transmits the authentication results for the outdoor unit 131, the indoor unit 141, the indoor unit 142, the individual controller 143, and the individual controller 151 to the system controller 120. Furthermore, although not shown, the outdoor unit 132 transmits the authentication results for the outdoor unit 132, the indoor unit 144, the indoor unit 145, the individual controller 146, and the communication adapter 152 to the system controller 120. As a result, all authentication results are supplied to the system controller 120, which is the root node. Thereafter, encrypted communication is executed between the authenticated devices 100.
[0100] In this embodiment, mutual authentication is performed between an authenticating device and an authenticated device in each of a plurality of networks 200. According to this embodiment, even if there is no cloud server 110 that is difficult to spoof and highly reliable, it is possible to authenticate all devices 100 including the system controller 120 and the refrigerant system devices 100.
[0101] (Variation) Although the embodiments of the present disclosure have been described above, various modifications and applications are possible when implementing the present disclosure. It is optional which parts of the configurations, functions, and operations described in the above embodiments are adopted in the present disclosure. Furthermore, in addition to the above-described configurations, functions, and operations, further configurations, functions, and operations may also be adopted in the present disclosure. Furthermore, the configurations, functions, and operations described in the above-described embodiments can be freely combined.
[0102] The trigger by which the authenticating device of each network 200 starts authenticating the device to be authenticated can be adjusted as appropriate. For example, the authenticating device of each network 200 may start authenticating the device to be authenticated in response to a request from a specific device 100 among the multiple devices 100 included in the air conditioning system 1000. Alternatively, the authenticating device of each network 200 may start authenticating the device to be authenticated on its own initiative. In this way, the direction of device authentication and the order in which device authentication is performed do not have to match.
[0103] The configuration of the air conditioning system is not limited to those shown in embodiments 1 to 6. For example, in embodiment 1, the indoor unit 141 may be connected to the system controller 120 instead of the outdoor unit 131 in the network 220, and the indoor unit 141 and the outdoor unit 131 may be connected in the network 231. In this case, it is preferable that the indoor unit 141 is authenticated by the system controller 120 in the network 220, and the outdoor unit 131 is authenticated by the indoor unit 141 in the network 231.
[0104] The first authenticated device that serves as the base point for device authentication is not limited to the device 100 shown in Embodiments 1 to 6. For example, the outdoor unit 132 or the indoor unit 144 may be set alone as the first authenticated device, or at least one device 100 among the system controller 120, the indoor unit 142, the individual controller 143, the indoor unit 145, the individual controller 146, the individual controller 151, and the communication adapter 152 may be set as the first authenticated device.
[0105] Although multiple authentication devices may be provided in each network 200, it is preferable that one authentication device is provided in each network 200. The method of determining one authentication device in each network 200 can be adjusted as appropriate. The authentication device is preferably a device 100 that always exists and is uniquely determined in each network 200. For example, in each network 200, the device 100 with the smallest network address, the device 100 that supplies power to other devices in the network 200, etc. may be determined to be the authentication device.
[0106] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope of the present disclosure. Furthermore, the above-described embodiments are intended to illustrate the present disclosure and do not limit the scope of the present disclosure. That is, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and the meaning of equivalent disclosures are considered to be within the scope of the present disclosure. [Industrial Applicability]
[0107] The present disclosure is applicable to air conditioning systems equipped with a plurality of devices including outdoor units and indoor units. [Explanation of symbols]
[0108] 11 control unit, 12 memory unit, 13 display unit, 14 operation reception unit, 15 first communication unit, 16 second communication unit, 100, 100A, 100B, 100C, 100D, 100E, 100F, 100G equipment, 110 cloud server, 120 system controller, 131, 132 outdoor unit, 141, 142, 144, 145 indoor unit, 143, 146, 151 individual controller, 152 communication adapter, 200, 200A, 200B, 200C, 210, 220, 231, 232, 241, 242 network, 300, 300A, 300B, 300C, 311, 312, 320, 331, 332, 341, 342 communication line, 500 Broadband router, 1000, 1200, 1300, 1400, 1500, 1600 Air conditioning system
Claims
1. An air conditioning system having a plurality of devices including an outdoor unit and an indoor unit, each of the plurality of devices belongs to at least one network among a plurality of networks; each of the plurality of networks includes an authentication device that authenticates other devices that belong to the network to which the own device belongs; the plurality of networks includes a first network and a second network; the plurality of devices include a first authentication device that belongs to the first network and authenticates other devices that belong to the first network, and a second authentication device that belongs to the first network and the second network, is authenticated by the first authentication device, and authenticates other devices that belong to the second network; Air conditioning system.
2. the plurality of networks include the first network, the second network, and a third network; the plurality of devices include the first authentication device, the second authentication device, and a third authentication device that belongs to the second network and the third network, is authenticated by the second authentication device, and authenticates other devices that belong to the third network; The air conditioning system of claim 1 .
3. the plurality of devices include a system controller that controls the outdoor unit and the indoor unit, and a cloud server connected to the system controller; the first authentication device is the cloud server; the second authentication device is the system controller; 3. The air conditioning system according to claim 1 or 2.
4. The first authenticated device is one of the outdoor unit and the indoor unit.
3. The air conditioning system according to claim 1 or 2.
5. the plurality of devices includes a system controller that controls the outdoor unit and the indoor unit; the first authentication device or the second authentication device authenticates the system controller; The air conditioning system according to claim 4.
6. The plurality of devices are connected in a tree structure, The authentication device provided in each of the plurality of networks authenticates a device corresponding to a child node from the viewpoint of the authentication device itself.
3. The air conditioning system according to claim 1 or 2.
7. In each of the plurality of networks, mutual authentication is performed between the authentication device and the other device authenticated by the authentication device.
3. The air conditioning system according to claim 1 or 2.
8. An authentication method executed by an air conditioning system having a plurality of devices including an outdoor unit and an indoor unit, each of the plurality of devices belongs to at least one network among a plurality of networks; an authentication device provided in each of the plurality of networks authenticates other devices that belong to the network to which the authentication device belongs; the plurality of networks includes a first network and a second network; the plurality of devices include a first authentication device that belongs to the first network and authenticates other devices that belong to the first network, and a second authentication device that belongs to the first network and the second network, is authenticated by the first authentication device, and authenticates other devices that belong to the second network; Authentication method.
Citation Information
Patent Citations
Multi-split air conditioner floor heating centralized control system
CN112161312A
Multi-split air conditioning system
CN113865023A
Address setting device, air conditioning system and address setting method
JP2016044884A
Equipment authentication device, air conditioning system and equipment authentication method
JP2016044885A
A central controlling apparatus of a multi air-conditioning system and a method thereof
KR1020090080428A