Communication method and networked system

Devices in a network autonomously determine IP addresses and routing tables using public key hashes, enabling independent data communication and reducing router dependency.

JP7788595B2Active Publication Date: 2025-12-19帝都久利寿 +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023100077
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-06-19
Publication Date
2025-12-19
Estimated Expiration
2039-01-31

AI Technical Summary

Technical Problem

In networks with a large number of devices, the need for numerous routers and their associated responsibilities becomes cumbersome, making it desirable for each device to independently perform data communication.

Method used

Each device determines its IP address based on a hash value of its public key, retains state information, and updates a routing table based on notification messages from other devices, enabling autonomous data communication.

Benefits of technology

This approach allows each device to independently manage data communication, reducing the need for multiple routers and enhancing network autonomy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007788595000001
    Figure 0007788595000001
  • Figure 0007788595000002
    Figure 0007788595000002
  • Figure 0007788595000003
    Figure 0007788595000003
Patent Text Reader

Abstract

To provide a configuration in which each device can achieve data communication independently in a network including many devices.SOLUTION: A data transmission method includes: a step in which each of a plurality of devices determines an IP address of each device based on a hash value calculated according to a hash function from a public key of each device; a step in which each of the devices maintains state information reflecting a connection relationship of each device and sends a notification message indicating content of the state information to other devices; a step in which each of the devices updates the state information maintained by each device based on the notification message received from the other devices; and a step of determine a routing table maintained among the devices included in the set to be used to search for devices being destinations of data transmission among a set of devices logically defined based on the state information held by each device.SELECTED DRAWING: Figure 15
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to techniques for data communication between devices with authenticated IP addresses. [Background technology]

[0002] Recent Information and Communication Technology Advances in ICT (Information and Communication Technology) have been remarkable, and devices connected to networks such as the Internet are no longer limited to traditional information processing devices such as personal computers and smartphones, but are now expanding to include a wide variety of things. This technological trend is known as the "Internet of Things" (IoT), and various technologies and services are being proposed and put into practical use. In the future, it is expected that billions of people and tens of billions or even trillions of devices on Earth will be connected simultaneously. To realize such a networked world, it is necessary to provide solutions that enable simpler, safer, and more free connections.

[0003] Typically, on a network, data communication between devices is achieved using an IP (Internet Protocol) address that is statically or dynamically assigned to each device.

[0004] In order to realize data communication between devices, data sent from the source device must be forwarded to the destination device. This data forwarding process is called "routing." To realize this routing, many routers are placed on the network.

[0005] As disclosed in Japanese Patent Laid-Open No. 05-022293 (Patent Document 1), a router has a routing information table that stores routing information, and determines a route and relays the received frame according to the internetworking address in the received frame and the contents of the routing information table (see paragraphs

[0005] and

[10] of Japanese Patent Laid-Open No. 05-022293).

[0006] etc.). [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Publication No. 05-022293 Summary of the Invention [Problem to be solved by the invention]

[0007] According to Patent Document 1, assuming a network with a large number of devices, a large number of routers are required, and the responsibilities of each router also become large. Therefore, in a network with a large number of devices, it is preferable to have a configuration in which each device can independently perform data communication. The present disclosure provides a solution for realizing such a configuration. [Means for solving the problem]

[0008] According to an embodiment of the present disclosure, there is provided a data transmission method in a network to which a plurality of devices are connected. The data transmission method includes a step of each of the plurality of devices determining an IP address of each device based on a hash value calculated from a public key held by each device according to a hash function, a step of each of the plurality of devices retaining state information reflecting the connection relationship between each of the plurality of devices and transmitting a notification message indicating the content of the state information to other devices, and a step of each of the plurality of devices receiving a notification message from the other devices. The method includes a step of updating state information held by each device based on the notification message received, and a step of determining a routing table held among devices included in a set of devices logically defined based on the state information held by each device, used to search for a device to be the destination of data transmission.

[0009] The notification message may include identification information for identifying each device, which is calculated based on the IP address determined by each device.

[0010] The data transmission method may further include a step in which each of the multiple devices transmits to another device a public key and an electronic certificate associated with the public key that each device possesses, and a step in which, in the device that receives the public key and the electronic certificate, determines an IP address of the device that transmitted the public key and the electronic certificate based on a hash value calculated from the public key according to a hash function.

[0011] The determined IP address may include a predetermined unique value for identification. The determined IP address may include a value according to the type of device that determined the IP address.

[0012] According to another aspect of the present disclosure, there is provided a communication processing method for a device connected to a network, the communication processing method including the steps of determining an IP address of the device itself based on a hash value calculated from a public key according to a hash function, retaining state information reflecting connection relationships with other devices and transmitting notification messages indicating the contents of the state information to the other devices, updating the state information based on the notification messages received from the other devices, and retaining a routing table used to search for a device that is a destination for data transmission among a set of devices logically defined based on the state information retained by each device.

[0013] The notification message may include identification information for identifying the device itself, which is calculated based on the determined IP address of the device itself.

[0014] The communication processing method may further include a step of determining a routing table when it is determined based on the state information that the own device will act as a root node in the set.

[0015] Maintaining the routing table may include receiving the routing table from another device.

[0016] The state information and the notification message may include identification information for specifying the device designated as the root node. The updating step may include a step of determining, in a case where the device designated as the root node included in the received notification message does not match the device designated as the root node included in the state information, one of the devices as the root node in accordance with a predetermined rule.

[0017] The communication processing method may further include the steps of obtaining a digital certificate associated with the public key from a certificate authority, and transmitting the public key and the digital certificate to the other device.

[0018] The communication processing method includes a step of determining the authenticity of the electronic certificate when receiving a public key and an electronic certificate associated with the public key from another device, and a step of, if the electronic certificate is determined to be authentic, transmitting the electronic certificate to the other device based on a hash value calculated from the public key according to a hash function. and determining an IP address of the device.

[0019] The determined IP address may include a predetermined unique value for identification. The determined IP address may include a value according to the type of device that determined the IP address.

[0020] According to another aspect of the present disclosure, there is provided a communication processing method for a device connected to a network, the communication processing method including the steps of receiving a public key held by another device and a digital certificate associated with the public key, determining the validity of the digital certificate, and if the digital certificate is determined to be valid, determining an IP address based on a hash value calculated from the public key according to a hash function as an authenticated IP address of the other device, and providing a service corresponding to the authenticated IP address of the other device in response to a request from the other device.

[0021] The public key may be determined so that an IP address determined based on a hash value calculated from the public key according to a hash function conforms to a predetermined format.

[0022] According to yet another aspect of the present disclosure, an apparatus includes a network interface for connecting to a network, and a control unit connected to the network interface. The control unit performs the following processes: determining an IP address of the apparatus itself based on a hash value calculated from a public key according to a hash function; storing state information reflecting connections with other devices and transmitting notification messages indicating the contents of the state information to the other devices; updating the state information based on notification messages received from the other devices; and storing a routing table used to search for a device that is a destination for data transmission among a set of devices logically defined based on the state information stored in each device.

[0023] According to yet another aspect of the present disclosure, there is provided a communication processing program for a computer having a network interface for connecting to a network, the communication processing program causing the computer to execute the communication processing method when executed by the computer. [Effects of the Invention]

[0024] According to the present disclosure, it is possible to provide a configuration in which each device can independently realize data communication in a network in which a large number of devices exist. [Brief explanation of the drawings]

[0025] [Figure 1] 1 is a schematic diagram showing an example of an overall configuration of a network system according to an embodiment of the present invention; [Figure 2] FIG. 2 is a schematic diagram illustrating an example of a hardware configuration of a device according to the present embodiment. [Figure 3] FIG. 2 is a schematic diagram showing an example of a configuration of programs and data of a device according to the present embodiment. [Figure 4] FIG. 10 is a diagram illustrating an IP address authentication procedure in the network system according to the present embodiment. [Figure 5] FIG. 10 is a diagram showing an example of type specifying information embedded in an IP address used in the network system according to the present embodiment. [Figure 6] 10 is a flowchart showing a processing procedure in which a device provides an authenticated IP address in the network system according to the present embodiment. [Figure 7] FIG. 2 is a diagram illustrating a process for notifying an IP address in the network system according to the present embodiment. [Figure 8] FIG. 2 is a diagram illustrating a process for notifying an IP address in the network system according to the present embodiment. [Figure 9] 10 is a sequence chart showing a processing procedure for notifying an IP address in the network system according to the present embodiment. [Figure 10] FIG. 1 is a diagram for explaining an example of an application for providing a service using the network system according to the present embodiment. [Figure 11] FIG. 10 is a diagram for explaining another application example of service provision using the network system according to the present embodiment. [Figure 12]It is a diagram for explaining an example of routing in the network system according to this embodiment. [Figure 13] It is a diagram for explaining a method of realizing routing in the network system according to this embodiment. [Figure 14] It is another diagram for explaining a method of realizing routing in the network system according to this embodiment. [Figure 15] It is a sequence chart showing a processing procedure related to the realization of routing in the network system according to this embodiment. [Figure 16] It is a diagram showing an example of the data structure of the state information and the state notification message used in the network system according to this embodiment. [Figure 17] It is a diagram showing an example of updating state information by a state notification message in the network system according to this embodiment. [Figure 18] It is a flowchart showing a processing procedure related to the determination of a routing table in the network system according to this embodiment. [Figure 19] It is a flowchart showing a processing procedure related to packet transmission and reception of each device in the network system according to this embodiment.

Embodiments for Carrying Out the Invention

[0026] Embodiments according to the present disclosure will be described in detail with reference to the drawings. For the same or corresponding parts in the drawings, the same reference numerals are given and the description thereof will not be repeated.

[0027] <A. Overall Configuration of Network System 1> First, the overall configuration of the network system 1 according to this embodiment will be described.

[0028] 1 is a schematic diagram showing an example of the overall configuration of a network system 1 according to the present embodiment. Referring to FIG. 1, it is assumed that a plurality of devices 100-1, 100-2, 100-3, 100-4, 100-5, etc. (hereinafter, sometimes collectively referred to as "devices 100") are connected to an arbitrary network 2 such as the Internet or an intranet. Some of the devices 100 may be connected to the network 2 via wireless communication established with an access point 4. Alternatively, another portion of the devices 100 may be connected to the network 2 via wireless communication established with a mobile base station 6.

[0029] Thus, network 2 may include any of a local area network (LAN), a wide area network (WAN), a radio access network (RAN), and the Internet.

[0030] Each of the devices 100 connected to the network can be considered a "node" of the network, and in the following description, the devices 100 may also be referred to as a "node."

[0031] In network system 1 according to the present embodiment, the following communication is performed between devices 100: The data communication is realized according to the procedure as described above. Note that any physical connection method between the devices 100 may be used.

[0032] Device 100 includes any device that has the function of communicating data with other devices using its own IP address. Device 100 may be configured as a standalone communication device, or may be configured as part of or incorporated into some other object.

[0033] More specifically, device 100 may be, for example, a personal computer, a smartphone, a tablet, or a wearable device (for example, a smart watch or AR glasses) attached to a user's body (for example, an arm or a head). Device 100 may also be a control device or a part thereof installed in a smart home appliance, a connected automobile, a factory, or the like.

[0034] The network system 1 according to this embodiment further includes one or more certificate authorities 200. Each of the certificate authorities 200 is a computer configured with one or more servers. Using one or more certificate authorities 200, the IP address of each device 100 is authenticated according to a procedure described below. As a result, each device 100 has an authenticated IP address.

[0035] In this specification, "authenticated IP address" means a state in which the legitimacy of the IP address held by each device 100 is guaranteed to the communication destination or a third party. More specifically, an "authenticated IP address" means an IP address that is generated by an irreversible cryptographic hash function and is authenticated directly or indirectly by a certification authority (details will be described later). By using such an "authenticated IP address," it is possible to ensure that the IP address used by each device 100 for data communication is not forged.

[0036] As a result, any device 100 included in the network system 1 is uniquely identified based on the IP address of each device 100. That is, each device can determine the destination or destination device for data transmission based on the IP address of each device.

[0037] The IP address is assumed to be a global IP address that can be used for data communication between devices 100 connected to the Internet, but may also be a private IP address that is used only within a specific network.

[0038] IP addresses differ in the number of bits that make up the address depending on the version. In the currently established IPv4 (Internet Protocol Version 4), a 32-bit address range is defined, and in the currently established IPv6 (Internet Protocol Version 6), a 128-bit address range is defined. In the present embodiment, the IP address conforming to IPv6 will be mainly described. However, the present disclosure is also applicable to network addresses defined with a larger number of bits or network addresses defined with a smaller number of bits.

[0039] <B. Configuration Example of Device 100> Next, a configuration example of the hardware and software of the device 100 used in the network system 1 according to the present embodiment will be described.

[0040] FIG. 2 is a schematic diagram showing a hardware configuration example of the device 100 according to the present embodiment. Referring to FIG. 2, the device 100 includes, as main components, a control unit 110 which is a processing circuitry.

[0041] The control unit 110 is an operation entity for realizing the provision of functions and the execution of processing according to the present embodiment. The control unit 110 may be configured such that a processor executes computer readable instructions (an OS (Operating System) and a communication processing program as shown in FIG. 3) stored in a memory using a processor and a memory as shown in FIG. 2. Alternatively, an ASIC (Application The control unit 110 may be realized using a hardwired circuit such as an ASIC (Application Specific Integrated Circuit). Alternatively, the control unit 110 may be realized by implementing a circuit corresponding to computer-readable instructions on an FPGA (Field-Programmable Gate Array). The control unit 110 may also be realized by appropriately combining a processor, memory, ASIC, FPGA, etc.

[0042] In the configuration using a processor and memory as shown in FIG. 2, the control unit 110 includes a processor 102, a main memory 104, a storage 106, and a ROM (Read Only Memory) 108.

[0043] The processor 102 is an arithmetic circuit that sequentially reads and executes computer-readable instructions. The processor 102 is configured, for example, with a central processing unit (CPU), a micro processing unit (MPU), a graphics processing unit (GPU), etc. The control unit 110 may be realized using a plurality of processors 102 (multiprocessor configuration), or may be realized using a processor having a plurality of cores (multicore configuration).

[0044] The main memory 104 is a volatile storage device such as a dynamic random access memory (DRAM) or a static random access memory (SRAM). The processor 102 loads a specified program from among various programs stored in the storage 106 or the ROM 108 onto the main memory 104, and works in cooperation with the main memory 104 to realize various processes according to this embodiment.

[0045] The storage 106 is a non-volatile storage device such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, etc. The storage 106 stores various programs executed by the processor 102 and various data to be described later.

[0046] The ROM 108 permanently stores various programs executed by the processor 102 and various data to be described later.

[0047] In a configuration in which the processor 102 executes computer-readable instructions stored in memory as shown in FIG. 2, the memory corresponds to the storage 106 and the ROM 108 .

[0048] An example of the programs and data stored in the memory of the device 100 will now be described.

[0049] 3 is a schematic diagram showing an example of the configuration of programs and data of device 100 according to the present embodiment. Referring to FIG. 3, the memory (storage 106 and / or ROM 108) of device 100 stores, for example, an OS as a program including computer-readable instructions. 160, a communication processing program 170, and various applications 300 are stored.

[0050] The OS 160 is a program that provides basic functions for realizing the processing executed by the device 100. The communication processing program 170 is a program that mainly provides the functions and executes the processing according to the present embodiment. Note that the communication processing program 170 may also provide the functions and execute the processing according to the present embodiment by using a library provided by the OS 160, etc.

[0051] The various applications 300 are programs for realizing various functions provided by the device 100, and can be installed at the user's discretion. Typically, the various applications 300 provide various processes that utilize the data communication function provided by the communication processing program 170.

[0052] The memory (storage 106 and / or ROM 108) of the device 100 also stores, for example, a private key 172, a public key 174, and a digital certificate 176 as data necessary for providing functions and executing processes according to the present embodiment. The private key 172 and the public key 174 are a key pair generated according to an arbitrary encryption / decryption algorithm. The private key 172 is used for encrypted communication with other devices. The public key 174 is used to determine the IP address of each device 100 according to a procedure described below. The digital certificate 176 is issued by the certificate authority 200 for the public key 174 and is used to ensure the validity of the IP address of the device 100. Typically, the digital certificate 176 includes a hash value (digital signature) calculated from the public key 174 of each device 100 using the private key of the certificate authority 200. Upon receiving the digital certificate 176 , the device 100 uses the public key of the certificate authority 200 to verify the authenticity of the digital certificate 176 and the public key 174 associated with the digital certificate 176 .

[0053] The procedures for generating a key pair (private key 172 and public key 174), obtaining a digital certificate 176, and using this data will be described later.

[0054] It is not necessary to provide both the storage 106 and the ROM 108, and only one of them may be provided depending on the implementation. Furthermore, when both the storage 106 and the ROM 108 are provided, for example, the key pair (private key 172 and public key 174) may be stored in the ROM 108 to enhance confidentiality.

[0055] 2, the device 100 further includes a network interface 120 for connecting the device 100 to a network. The network interface 120 performs data communication with other devices over the network.

[0056] Network interface 120 includes a wired connection terminal such as an Ethernet (registered trademark) port, a Universal Serial Bus (USB) port, a serial port such as IEEE 1394, or a legacy parallel port. Alternatively, network interface 120 may include a processing circuit and an antenna for wireless communication with a device, a router, a mobile base station, or the like. Wireless communication supported by network interface 120 may be, for example, Wi-Fi (registered trademark), Bluetooth (registered trademark), ZigBee (registered trademark), Low Power Wide Area (LPWA), GSM (registered trademark), W-CDMA, CDMA200, Long Term Evolution (LTE), or a fifth-generation mobile communication system (5G).

[0057] The device 100 may include optional components such as a display unit 130 and an input unit 140. 40 and a media interface 150.

[0058] Display unit 130 is a component for externally presenting processing results, etc., from processor 102. Display unit 130 may be, for example, an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display. Display unit 130 may also be a head-mounted display worn on the user's head, or a projector that projects an image onto a screen.

[0059] Input unit 140 is a component for receiving input operations from a user who operates device 100. Input unit 140 may be, for example, a keyboard, a mouse, a touch panel arranged on display unit 130, or operation buttons arranged on the housing of device 100.

[0060] The media interface 150 reads various programs (computer-readable instructions) and / or various data from a non-transitory medium 152 on which the various programs and / or various data are stored.

[0061] The medium 152 may be, for example, an optical medium such as a DVD (Digital Versatile Disc), or a semiconductor medium such as a USB memory. The media interface 150 employs a configuration according to the type of the medium 152. The various programs and / or data read by the media interface 150 may be stored in the storage 106 or the like.

[0062] Instead of installing various programs and / or various data in device 100 via medium 152, necessary programs and data may be installed in device 100 from a distribution server on a network. In this case, the necessary programs and data are obtained via network interface 120.

[0063] As described above, the display unit 130, the input unit 140, and the media interface 150 are optional components, and may be connected from outside the device 100 via any interface such as a USB.

[0064] It is the control unit 110 that realizes the provision of functions and the execution of processes according to this embodiment, and the technical scope of the present application includes at least the hardware and / or software for realizing the control unit 110. As described above, the hardware may include not only a configuration composed of a processor and a memory, but also a hard-wired circuit using an ASIC or the like, and a configuration using an FPGA. That is, the control unit 110 can be realized by installing a program in a general-purpose computer, or can also be realized as a dedicated chip.

[0065] In addition, the software executed by the processor may include not only those distributed via the medium 152, but also those appropriately downloaded via a distribution server.

[0066] Note that the configuration for realizing the provision of functions and the execution of processes according to this embodiment is not limited to the control unit 110 shown in FIG. 2, and can be implemented using any technology according to the era in which it is realized.

[0067] <C. Authenticated IP Address> Next, the process for providing an authenticated IP address to each device 100 and the like will be described.

[0068] (c1: IP Address Determination Process) In the network system 1 according to this embodiment, typically, the IP addresses of each device 100 are authenticated using an authenticated IP address. As an example, the IP addresses of each device 100 may be authenticated using a public key infrastructure (PKI).

[0069] FIG. 4 is a diagram for explaining the IP address authentication procedure in the network system 1 according to this embodiment. Note that the symbols such as "S1" to "S4" in FIG. 4 correspond to the step numbers shown in FIG. 6.

[0070] 4, device 100 has a key pair consisting of private key 172 and public key 174. A hash value 178 is calculated by inputting public key 174 into a predetermined hash function 180, and all or a part of the calculated hash value 178 is used as IP address 190 of device 100.

[0071] In accordance with this process of determining the IP address 190, the device 100 transmits the public key 174 to the certificate authority 200 and associates the public key 174 with the digital certificate 176 issued by the certificate authority 200. The device 100 transmits its own public key 174 and digital certificate 176 to the other device. The other device confirms the legitimacy of the IP address 190 of the device 100 based on the public key 174 and digital certificate 176 published by the device 100. Once the legitimacy of the IP address 190 is confirmed, data communication is initiated using the IP address 190 whose legitimacy has been confirmed. The device 100 and the other device can communicate directly with each other, but in addition to the direct communication process, an inquiry process at the certificate authority 200 may also be included.

[0072] In this way, in the network system 1 according to this embodiment, the IP address 190 itself can be authenticated, and by the device itself holding such an authenticated IP address 190, an autonomous network can be constructed without using an IP address statically or dynamically assigned to each device.

[0073] The process for providing an authenticated IP address in network system 1 according to the present embodiment will now be described in detail.

[0074] The key pair, private key 172 and public key 174, may be generated by device 100 itself, or may be provided from an external source and pre-stored in device 100. If provided from an external source, device 100 may acquire only private key 172 and generate public key 174 by itself.

[0075] As an example of a method for generating public key 174, which is a key pair, a bit string of a predetermined length (e.g., 512 bits) generated by a random number generator may be used as private key 172, and public key 174 consisting of a bit string of a predetermined length (e.g., 256 bits) may be generated from private key 172 according to a known encryption algorithm (e.g., elliptic curve encryption algorithm). Note that when device 100 itself generates the key pair, the random number generator may be realized using a function provided by OS 160, or may be realized using a hardwired circuit such as an ASIC.

[0076] The hash function 180 may be a known irreversible cryptographic hash function (e.g., BLAKE). The hash function 180 may be a bit string of a predetermined length (e.g., 256 bits). A hash value 178 consisting of the byte (bit) is calculated.

[0077] In addition to public key 174, an arbitrary keyword may be input to hash function 180. A message associated with a predetermined organization may be used as the arbitrary keyword. A message including the name of a trademark owned by the predetermined organization may be used as the message associated with the predetermined organization. For example, the name of a registered trademark owned by the predetermined organization (e.g., "connectFree") may be used as the keyword to be input to hash function 180. By adopting such an implementation method, it is possible to prevent a third party other than the predetermined organization from implementing network system 1 according to this embodiment and related methods and programs without the permission of the predetermined organization.

[0078] All or part of hash value 178 calculated by hash function 180 is used as IP address 190. For example, when a 256-bit (64 hexadecimal digits) hash value 178 is calculated, any 32 digits (e.g., the first 32 digits) of the 64-digit hash value 178 may be determined as IP address 190 (128 bits) corresponding to IPv6. Alternatively, the first 8 digits of the 64-digit hash value 178 may be determined as IP address 190 (32 bits) corresponding to IPv4.

[0079] Alternatively, the 128-bit hash value 178 may be calculated from the hash function 180, taking into account the IP address 190 (128 bits) corresponding to IPv6. In this case, the entire calculated hash value 178 can be determined as the IP address 190 (128 bits) corresponding to IPv6.

[0080] According to this embodiment, an IP address 190 unique to the device 100 can be determined based on the public key 174 of the device 100. In this way, the device 100 can be connected to a network such as the Internet using the IP address 190 determined by the device 100. Furthermore, the device 100 can perform data communication using the IP address 190 determined by itself, even if there is no service provider (server) that manages global IP addresses, such as an Internet service provider (ISP). Furthermore, the device 100 can connect to a global network such as the Internet and perform data communication using the IP address 190 determined by itself, even if there is no server that manages private IP addresses, such as a DHCP (Dynamic Host Configuration Protocol) server implemented in an access point or the like. Therefore, the user experience and convenience of connecting to a network such as the Internet can be improved.

[0081] (c2: Unique string) The IP address 190 determined by the device 100 may be identified as having been determined in accordance with the processing procedure according to this embodiment. To achieve this identification, for example, a predetermined unique value (unique character string) for identification may be included in the IP address 190. In other words, the determined IP address may include the predetermined unique value (unique character string) for identification.

[0082] As an example, the first two digits (the first and second digits from the beginning) of the IP address 190 expressed in hexadecimal may be fixed to a predetermined unique string (for example, "FC"). Since the hash function 180 is usually a one-way function, it is not possible to reverse-calculate the public key 174 from the IP address 190. Therefore, a random number generator may be used to repeatedly generate the private key 172 and the public key 174 until the determined IP address 190 satisfies a predetermined condition (in this case, the first two digits become a predetermined unique value). In other words, the public key 174 is determined based on a hash value calculated from the public key 174 according to the hash function. The P address 190 may be determined to conform to a predetermined format.

[0083] In this way, by including a predetermined unique value for identification (for example, the first two digits are "FC") in IP address 190, a third party can determine whether IP address 190 of device 100 was determined by device 100 itself.

[0084] (c3: Type-specific information) The IP address 190 determined by the device 100 may include information that can identify the type of the device 100. To achieve this identification, for example, the IP address 190 may include a value that corresponds to the type of the device 100. In other words, the determined IP address 190 may include a value that corresponds to the type of the device 100 that determined the IP address 190.

[0085] As an example, a value (type-specific information) according to the type of device 100 may be embedded in the third and fourth digits from the beginning of the IP address 190 expressed in hexadecimal numbers.

[0086] Fig. 5 is a diagram showing an example of type specifying information embedded in an IP address used in network system 1 according to the present embodiment. The type specifying information shown in Fig. 5 may be stored in advance in ROM 108 (see Fig. 2) of control unit 110 of each device 100. As an example, a value according to the type of device as shown in Fig. 5 can be used.

[0087] As shown in FIG. 5, for example, if the type of device 100 is a personal computer, the value "00" indicating a personal computer is set in the third and fourth digits from the beginning of the IP address 190.

[0088] As described above, hash function 180 is usually a one-way function, and therefore public key 174 cannot be calculated backward from IP address 190. Therefore, private key 172 and public key 174 may be repeatedly generated using a random number generator until the determined IP address 190 satisfies a predetermined condition (in this case, the third and fourth digits from the beginning are values ​​indicating the type of device 100). In other words, public key 174 may be determined so that IP address 190 determined based on a hash value calculated from public key 174 according to the hash function matches a predetermined format.

[0089] In this way, by including a value indicating the type of device 100 in the IP address 190, a third party can identify the type of device 100 from the IP address 190 determined by the device 100.

[0090] (c4: Registering a public key 174 and obtaining a digital certificate 176) Next, the registration of the public key 174 and the acquisition of the digital certificate 176 will be described.

[0091] The device 100 obtains the digital certificate 176 for certifying the validity of the public key 174 from the certification authority 200. The procedure for obtaining the digital certificate 176 is to send the public key 174 from the device 100 to the certification authority 200 to register it, and to obtain the digital certificate 176 associated with the registered public key 174 from the certification authority 200.

[0092] More specifically, the device 100 (control unit 110) transmits the public key 174 and a request for issuing a digital certificate (hereinafter also referred to as a "certificate signing request") to the certification authority 200 via the network. In response to the certificate signing request received from the device 100, the certification authority 200 registers the public key 174 and issues a digital certificate 176 associated with the registered public key 174. The certification authority 200 then issues the digital certificate 176 via the network. 6 to device 100.

[0093] Typically, the digital certificate 176 includes information about the owner of the digital certificate 176 (in this example, the device 100), information about the issuer of the digital certificate 176 (in this example, the certificate authority 200), the issuer's digital signature, and the expiration date of the digital certificate 176.

[0094] Certificate authority 200 may be operated by a specific organization, or may be an intermediate certificate authority associated with a root certificate authority operated by a specific organization. Registration of public key 174 and issuance of digital certificate 176 associated with public key 174 may require a specific fee and / or maintenance fee from the specific organization.

[0095] According to the present embodiment, public key 174 is directly authenticated by certificate authority 200 through registration and acquisition of public key 174, and thus IP address 190 determined based on public key 174 is also indirectly authenticated by certificate authority 200. Such authentication by certificate authority 200 enables device 100 to realize data communication over the network using authenticated IP address 190.

[0096] Note that the digital certificate 176 associated with the public key 174 may include information related to the attributes of the device 100 (hereinafter also referred to as "attribute information") in order to improve confidentiality. The attribute information of the device 100 may include, for example, version information of the OS 160 and communication processing program 170 of the device 100, or the serial number of the hardware (e.g., processor, storage, etc.) that constitutes the device 100. In this case, the device 100 may transmit the attribute information of the device 100 to the certificate authority 200 when transmitting the public key 174 and the certificate signing request. Note that the attribute information of the device 100 included in the digital certificate 176 may be encrypted using a known irreversible cryptographic hash function or the like.

[0097] In this way, by including the attribute information of device 100 in digital certificate 176, it is possible to authenticate that digital certificate 176 has been issued in response to a certificate signing request from device 100 itself. In other words, it is possible to more reliably prevent a device other than device 100 from masquerading as device 100 and using public key 174 and digital certificate 176 of device 100.

[0098] (c5: Processing procedure) Next, a process for providing an authenticated IP address in each device 100 will be described.

[0099] 6 is a flowchart showing a processing procedure in which device 100 provides an authenticated IP address in network system 1 according to the present embodiment. The processing procedure shown in FIG. 6 is executed in each device 100, and each step shown in FIG. 6 is executed by control unit 110 of each device 100.

[0100] 6, device 100 acquires a key pair (private key 172 and public key 174) generated according to an arbitrary algorithm (step S1). This key pair may be generated by device 100 itself, or may be acquired by device 100 from an external source. Alternatively, device 100 may acquire only private key 172 from an external source and generate public key 174 internally.

[0101] Next, the device 100 inputs the public key 174 into a predetermined hash function 180 to calculate a hash value 178, and then converts all or part of the calculated hash value 178 into a hash value. The device 100 determines the IP address 190 of the device 100 from the public key 174 (step S2). That is, the device 100 determines the IP address of its own device based on the hash value 178 calculated from the public key 174 according to the hash function 180.

[0102] In addition, an appropriate key pair (private key 172 and public key 174) may be generated so that IP address 190 includes a unique string (e.g., the first and second digits of IP address 190) and / or type-specific information (e.g., the first and fourth digits of IP address 190).

[0103] Furthermore, the device 100 transmits the public key 174 and a request for issuing a digital certificate (certificate signing request) to the certificate authority 200 (step S3). In response to the certificate signing request received from the device 100, the certificate authority 200 registers the public key 174 and issues a digital certificate 176 associated with the registered public key 174. The certificate authority 200 then transmits the digital certificate 176 to the device 100 via the network. The device 100 then receives and stores the digital certificate 176 from the certificate authority 200 (step S4).

[0104] Thus, the device 100 obtains a digital certificate 176 associated with the public key 174 from a certificate authority.

[0105] Note that the execution order of the process in step S2 and the processes in steps S3 and S4 is not limited.

[0106] <D. Data communication processing> Next, data communication processing between devices 100 using the authenticated IP addresses will be described.

[0107] (d1: Notification of IP address) First, the process related to the notification of IP addresses between devices 100 in the network system 1 according to the present embodiment will be described.

[0108] FIGS. 7 and 8 are diagrams for explaining the process related to the notification of IP addresses in the network system 1 according to the present embodiment. FIGS. 7 and 8 show an example of exchanging IP addresses among three devices 100-1, 100-2, and 100-3. Note that the same process is possible between two devices 100, and the same process is also possible among more devices 100.

[0109] In the states shown in FIGS. 7 and 8, each of the devices 100-1, 100-2, and 100-3 has determined IP addresses 190-1, 190-2, and 190-3 according to the procedure described above, and has also completed the registration of public keys 174-1, 174-2, and 174-3 with the certification authority 200 and the acquisition of electronic certificates 176-1, 176-2, and 176-3 from the certification authority 200, respectively.

[0110] As shown in FIGS. 7 and 8, each device 100 transmits (broadcasts) the public key 174 and the electronic certificate 176 associated with the public key 174 at regular intervals or for each event. That is, each device 100 transmits the public key 174 and the electronic certificate 176 to other devices. Note that when the public key 174 is included in the electronic certificate 176, only the electronic certificate 176 may be transmitted.

[0111] FIG. 7 shows an example in which device 100-1 has public key 174-1 and public key 174- 7 shows an example in which devices 100-2 and 100-3 transmit (broadcast) public key 174-1 and digital certificate 176-1 associated with device 100-1. In the example shown in Fig. 7, it is assumed that devices 100-2 and 100-3 receive public key 174-1 and digital certificate 176-1 transmitted by device 100-1. Then, devices 100-2 and 100-3 determine whether digital certificate 176-1 is valid, and if it is determined to be valid, determine IP address 190-1 of device 100-1 based on associated public key 174-1 and register it in connection tables 194-2 and 194-3, respectively.

[0112] Here, the connection table contains information about each device 100 for data communication, and each device 100 refers to the connection table to identify the IP address of the destination device 100, and establish the necessary session.

[0113] More specifically, device 100-2 first determines whether digital certificate 176-1 broadcast from device 100-1 is valid. In this process of determining validity, the integrity of digital certificate 176-1 is verified.

[0114] As an example of the integrity verification process, the device 100-2 first checks the owner information of the digital certificate 176-1, the issuer information of the digital certificate 176-1, and the existence of the issuer's digital signature. The device 100-2 then determines whether the digital certificate 176-1 is within its expiration date. Furthermore, the device 100-2 determines whether the issuer of the digital certificate 176-1 is trustworthy. In particular, if the digital certificate 176-1 was issued by an intermediate certification authority, the device 100-2 identifies a root certification authority associated with the intermediate certification authority that issued the digital certificate 176-1 and determines whether the identified root certification authority is trustworthy. For example, if the identified root certification authority matches one or more root certification authorities stored in the device 100-1, the device 100-2 determines that the issuer of the digital certificate 176-1 is trustworthy.

[0115] If the above-described determination process is passed, device 100-2 determines that digital certificate 176-1 broadcast from device 100-1 is valid. Device 100-2 then calculates hash value 178-1 by inputting public key 174-1 broadcast from device 100-1 into a predetermined hash function 180, and determines IP address 190-1 of device 100-1 using all or part of the calculated hash value 178-1. Here, it is assumed that devices 100-1 and 100-2 share a common hash function 180. It is also assumed that the process of determining IP address 190-1 from hash value 178-1 is common between devices 100-1 and 100-2.

[0116] Through the above processing, the device 100-2 can determine the IP address 190-1 of the device 100-1. Then, the device 100-2 adds an entry for the determined IP address 190-1 of the device 100-1 to the connection table 194-2. Note that the public key 174-1 may be registered in association with the IP address 190-1.

[0117] The same process as that of the device 100-2 is also performed in the device 100-3, and an entry for the determined IP address 190-1 of the device 100-1 is added to the connection table 194-3 of the device 100-3. The public key 174-1 may be registered in association with the IP address 190-1.

[0118] By the process shown in FIG. 7, the device 100-2 and the device 100-3 can obtain the IP address 190-1 of the device 100-1.

[0119] 8 shows an example in which device 100-2 transmits (broadcasts) public key 174-2 and digital certificate 176-2 associated with public key 174-2. In the example shown in Fig. 8, it is assumed that devices 100-1 and 100-3 receive public key 174-2 and digital certificate 176-2 transmitted by device 100-2. Then, devices 100-1 and 100-3 determine whether digital certificate 176-2 is valid, and if it is determined to be valid, determine IP address 190-2 of device 100-2 based on the associated public key 174-2 and register it in connection tables 194-1 and 194-3, respectively.

[0120] The series of processes executed in devices 100-1 and 100-3 are similar to the processes described with reference to Fig. 7, and therefore detailed description will not be repeated. By the process shown in Fig. 8, devices 100-1 and 100-3 can obtain IP address 190-2 of device 100-2.

[0121] Furthermore, device 100-3 may transmit (broadcast) public key 174-3 and digital certificate 176-3 associated with public key 174-3. Assume that devices 100-1 and 100-2 successfully receive public key 174-3 and digital certificate 176-3 transmitted by device 100-3. Then, devices 100-1 and 100-2 determine whether digital certificate 176-3 is valid. If it is determined to be valid, devices 100-1 and 100-2 determine IP address 190-3 of device 100-3 based on the associated public key 174-3 and register it in connection tables 194-1 and 194-2, respectively. Through this process, devices 100-1 and 100-2 can obtain IP address 190-3 of device 100-3.

[0122] Fig. 9 is a sequence chart showing a processing procedure relating to notification of an IP address in network system 1 according to the present embodiment. Fig. 9 shows processing procedures in three devices 100-1, 100-2, and 100-3, corresponding to Figs.

[0123] The device 100-1 transmits (broadcasts) the public key 174-1 and the digital certificate 176-1 associated with the public key 174-1 (sequence SQ10).

[0124] Upon receiving the public key 174-1 and digital certificate 176-1 transmitted by the device 100-1, the device 100-2 determines the validity of the digital certificate 176-1 (sequence SQ11). If the digital certificate 176-1 is determined to be valid, the device 100-2 determines the IP address 190-1 of the device 100-1 based on the public key 174-1 (sequence SQ12), and registers the determined IP address 190-1 of the device 100-1 in the connection table 194-2 (sequence SQ13).

[0125] Similarly, upon receiving the public key 174-1 and digital certificate 176-1 transmitted by the device 100-1, the device 100-3 determines the validity of the digital certificate 176-1 (sequence SQ14). If the digital certificate 176-1 is determined to be valid, the device 100-3 determines the IP address 190-1 of the device 100-1 based on the public key 174-1 (sequence SQ15), and registers the determined IP address 190-1 of the device 100-1 in the connection table 194-3 (sequence SQ16).

[0126] Additionally, the device 100-2 transmits (broadcasts) the public key 174-2 and the digital certificate 176-2 associated with the public key 174-2 (sequence SQ20).

[0127] Upon receiving the public key 174-2 and the digital certificate 176-2 transmitted by the device 100-2, the device 100-1 determines the validity of the digital certificate 176-2 (sequence If it is determined that the digital certificate 176-2 is valid, the device 100-1 determines the IP address 190-2 of the device 100-2 based on the public key 174-2 (sequence SQ22), and registers the determined IP address 190-2 of the device 100-2 in the connection table 194-1 (sequence SQ23).

[0128] Similarly, upon receiving the public key 174-2 and digital certificate 176-2 transmitted by the device 100-2, the device 100-3 determines the validity of the digital certificate 176-2 (sequence SQ24). If the digital certificate 176-2 is determined to be valid, the device 100-3 determines the IP address 190-2 of the device 100-2 based on the public key 174-2 (sequence SQ25), and registers the determined IP address 190-2 of the device 100-2 in the connection table 194-3 (sequence SQ26).

[0129] Furthermore, the device 100-3 transmits (broadcasts) the public key 174-3 and the digital certificate 176-3 associated with the public key 174-3 (sequence SQ30).

[0130] Upon receiving the public key 174-3 and digital certificate 176-3 transmitted by the device 100-3, the device 100-1 determines the validity of the digital certificate 176-3 (sequence SQ31). If the digital certificate 176-3 is determined to be valid, the device 100-1 determines the IP address 190-3 of the device 100-3 based on the public key 174-3 (sequence SQ32), and registers the determined IP address 190-3 of the device 100-3 in the connection table 194-1 (sequence SQ33).

[0131] Similarly, upon receiving the public key 174-3 and digital certificate 176-3 transmitted by the device 100-3, the device 100-2 determines the validity of the digital certificate 176-3 (sequence SQ34). If the digital certificate 176-3 is determined to be valid, the device 100-2 determines the IP address 190-3 of the device 100-3 based on the public key 174-3 (sequence SQ35), and registers the determined IP address 190-3 of the device 100-3 in the connection table 194-2 (sequence SQ36).

[0132] The processing of sequences SQ10 to SQ16, the processing of sequences SQ20 to SQ26, and the processing of sequences SQ30 to SQ36 can be executed in any order or in parallel.

[0133] In this way, when each device 100 receives public key 174 and digital certificate 176 associated with public key 174 from another device, it determines the validity of digital certificate 176 (sequences SQ11, SQ14, SQ21, SQ24, SQ31, SQ34). Then, when each device 100 determines that digital certificate 176 is valid, it determines the IP address of the other device based on a hash value calculated from public key 174 according to a hash function (sequences SQ12, SQ15, SQ22, SQ25, SQ32, SQ35).

[0134] As described above, in network system 1 according to the present embodiment, on the condition that digital certificate 176 transmitted from other device 100 is determined to be valid, IP address 190 of the other device 100 is determined based on public key 174 associated with digital certificate 176. On the condition that digital certificate 176 associated with public key 174 is determined to be valid, IP address 190 is determined based on public key 174, so the validity of public key 174 and the validity of IP address 190 can be guaranteed. Therefore, reliable data communication between devices 100 can be achieved.

[0135] In network system 1 according to the present embodiment, each device 100 is Since the IP address of each device 100 can be known based on the broadcast public key 174, the devices 100 can connect directly with each other even if there is no server that manages IP addresses. In particular, even if there is no virtual private network (VPN) server or the like, confidential communication can be achieved between the devices 100, which reduces the cost and power consumption required to maintain a VPN server.

[0136] (d2: Application example) In network system 1 according to the present embodiment, IP addresses can be mutually authenticated between devices 100, so that a communication destination can be identified based only on the IP address. By using such authenticated IP addresses, various services can be provided. An example of a service provided using an authenticated IP address will be described below.

[0137] 10 is a diagram illustrating an example of an application for providing a service using network system 1 according to the present embodiment. In the example of the application shown in FIG. 10, a web-based application server and a mobile terminal accessing the application server are assumed to be devices 100. The application server provides a unique web page according to the authenticated IP address of the mobile terminal from which the application server is accessed.

[0138] 10(a) shows an example of a network management table 210 held by the application server. In the network management table 210, initial screen information 214 indicating an initial screen and preference information 216 indicating preferences are defined in association with authenticated IP addresses 212 of mobile terminals that have accessed or plan to access the network. The contents of the network management table 210 may be updated manually by the user or by the application server in response to a user operation.

[0139] When the application server receives access from a mobile terminal, it references network management table 210 using the authenticated IP address assigned to the mobile terminal as a key, and determines the corresponding initial screen information 214 and preference information 216. Then, based on the determined initial screen information 214 and preference information 216, the application server determines the content of the Web page to be provided to the accessing mobile terminal.

[0140] Figure 10(b) shows an example of a web screen when an application server provides online banking services. For example, web screen example 220A, which is displayed on the display of a mobile terminal assigned authenticated IP address 1, has basic account management buttons such as "Transfer Procedure," "Check Account Balance," and "Transfer Procedure." On the other hand, web screen example 220B, which is displayed on the display of a mobile terminal assigned authenticated IP address 2, has buttons related to foreign currencies, such as "Buy Foreign Currency" and "Sell Foreign Currency," along with a chart showing changes in exchange rates over time.

[0141] Such an initial screen can be determined, for example, by referring to the initial screen information 214 in the network management table 210. Furthermore, by referring to the preference information 216 in the network management table 210, it is possible to provide not only the initial screen but also services according to the preferences of each mobile terminal (i.e., the user operating the mobile terminal).

[0142] As described above, the web-based application server responds to requests from mobile terminals and provides services according to the authenticated IP address of the mobile terminal. This allows customization of the initial screen and various service contents provided when accessing an application server based on the authenticated IP address of the mobile terminal.

[0143] Fig. 11 is a diagram illustrating another application example of service provision using network system 1 according to the present embodiment. In the application example shown in Fig. 11, a usage management server of a hotel or the like and a mobile terminal that accesses the usage management server are assumed to be devices 100. In the application example shown in Fig. 11, the mobile terminal can be used as an electronic key (usage certificate).

[0144] 11(a) shows an example of a usage management table 230 held by the server. The usage management table 230 stores the details of reservations made through a reservation site or the like (room number 234 and available time 236) in association with the network address 232 assigned to the mobile terminal used to make the reservation.

[0145] When a user operates their mobile terminal to make a reservation on a reservation site, the server adds the reservation details to the usage management table 230 along with the network address assigned to the mobile terminal used to make the reservation.

[0146] 11(b), a wireless communication unit 242 is placed in front of each room of the accommodation facility 240. When a user who plans to stay approaches the reserved room with the mobile terminal used to make the reservation, the wireless communication unit 242 establishes wireless communication with the mobile terminal. Note that wireless communication between the mobile terminal and the wireless communication unit 242 may be started automatically, or may be started after an explicit operation by the user.

[0147] If the network address assigned to the mobile terminal held by the user matches any of the entries in network address 232 in usage management table 230, the server unlocks the reserved room based on the corresponding room number 234 and available time 236. In this way, in response to a request from the mobile terminal, the server provides a service according to the authenticated IP address of the mobile terminal.

[0148] While Fig. 11 illustrates a typical example in which a mobile device is used as a key for each room at a lodging facility such as a hotel, the present invention is not limited to this and can be used as any other type of usage certificate. For example, the mobile device itself can be used as an admission ticket to various facilities such as amusement facilities or various events such as concerts. Furthermore, the mobile device itself can also be used as a train or airplane ticket.

[0149] In the network system 1 according to this embodiment, the IP address of the device 100 itself is authenticated, so that unlike existing technologies, an application for displaying a ticket is not required, and the device 100 itself can be used as a usage certificate.

[0150] As described above, in network system 1 according to the present embodiment, an authenticated IP address of a mobile terminal can be obtained, and thus a service specific to each mobile terminal can be provided without the need for an application for implementing authentication processing. Also, since performing data communication between devices such as a mobile terminal and a server means obtaining an authenticated IP address, the time required to provide a service specific to a mobile terminal is extremely short, and the waiting time required for service provision can be reduced compared to a configuration in which authentication processing is performed using an application.

[0151] (d3: Routing) Next, a description will be given of processing related to data communication between devices 100. In network system 1 according to the present embodiment, each device 100 has a routing function and a data transfer function, and these functions enable realization of a network that can independently perform data communication.

[0152] The routing adopted by network system 1 according to the present embodiment will be described below. In the following description, it is assumed that data is transmitted in the form of "packets" as a typical example.

[0153] Fig. 12 is a diagram illustrating an example of routing in network system 1 according to the present embodiment. Fig. 12 illustrates, as an example, routing in a network including seven devices 100-1 to 100-7.

[0154] 12, the above-described IP address notification process allows devices 100 that have exchanged IP addresses to establish a connection 10. Devices 100 that can establish a connection 10 exchange data in a sort of peer-to-peer manner. Note that any protocol, including TCP (Transmission Control Protocol) and UDP (User Datagram Protocol), can be used for the connection 10 between devices 100.

[0155] For example, consider an example in which a packet destined for device 100-7 is sent from device 100-1. Due to routing at device 100-1, the packet is sent from device 100-1 to device 100-5 (route RT1), then due to routing at device 100-5, the packet is sent from device 100-5 to device 100-6 (route RT2), and finally due to routing at device 100-6, the packet is sent from device 100-6 to device 100-7 (route RT3).

[0156] Each of the devices 100 included in the network system 1 according to the present embodiment has the following functions to realize the routing shown in FIG.

[0157] Fig. 13 is a diagram illustrating a method for implementing routing in network system 1 according to the present embodiment. With reference to Fig. 13, in network system 1 according to the present embodiment, a plurality of devices 100 included in network system 1 are logically divided into one or more node groups 30 (node ​​groups 30-1, 30-2, 30-3, ...), and each node group 30 shares routing table 32 (routing tables 32-1, 32-2, 32-3, ...).

[0158] A node group 30 refers to a logically defined collection of devices 100, and is determined based on the contents of state information 40 held by each device 100, as will be described later.

[0159] The routing table 32 is a table used to search for the device 100 that is the destination of data transmission (destination of the transmission packet), and can typically be realized using a distributed hash table (DHT). The routing table 32 includes identification information for identifying the device 100 (node) included in the corresponding node group 30, its location, and the like.

[0160] Each of the node groups 30 includes a device 100 that serves as a root node 34 (root nodes 34-1, 34-2, 34-3, . . . ). The root node 34 is hierarchically logically connected to one or more devices 100 that serve as nodes 36.

[0161] FIG. 14 is another diagram for illustrating a method for implementing routing in network system 1 according to the present embodiment.

[0162] 14, each device 100 included in network system 1 holds state information 40 (state information 40-1, 40-2, 40-3, ...) that reflects the connection relationships (logical and physical connection relationships) of each device 100. The state information 40 reflects the connection relationships between each device 100 and other devices.

[0163] Furthermore, each device 100 periodically (for example, every few minutes) transmits a state notification message 42 indicating the contents of the state information 40 that it holds to other devices 100 in the vicinity. Based on the state notification messages 42 from the other devices 100, each device 100 updates its own state information 40 as necessary.

[0164] 14 shows an example in which device 100-1 transmits a state notification message 42, but each device 100 included in network system 1 transmits a state notification message 42. Each device 100 updates its state information 40 based on the state notification messages 42 from other devices 100, thereby logically defining a tree structure such as that shown in FIG.

[0165] It is not necessary to determine in advance which device 100 will be the root node 34. A value indicating when the device will operate as the root node 34 is initially set in the state information 40 of each device 100. The state information 40 is updated based on state notification messages 42 received thereafter from other devices, and the device 100 that should operate as the root node 34 and the device 100 that should operate as a normal node 36 are autonomously determined.

[0166] 15 is a sequence chart showing a processing procedure for realizing routing in network system 1 according to the present embodiment. In FIG. 15, interactions focusing on devices 100-1, 100-2, 100-5, and 100-4 shown in FIG.

[0167] Referring to FIG. 15, when connected to network system 1, first, each of devices 100-1, 100-3, 100-5, and 100-4 initializes its own state information 40 (sequence SQ100).

[0168] Then, device 100-1 transmits a state notification message 42 indicating the contents of its own device's state information 40 to the surrounding devices 100 (sequence SQ102). Each device that receives state notification message 42 from device 100-1 updates its own device's state information 40 based on the received state notification message 42 (sequence SQ104).

[0169] Similarly, device 100-2 transmits a state notification message 42 indicating the contents of its own state information 40 to the surrounding devices 100 (sequence SQ106). Each device that receives the state notification message 42 from device 100-2 updates its own state information 40 based on the received state notification message 42 (sequence SQ108).

[0170] Similarly, the device 100-5 transmits a state notification message 42 indicating the contents of the state information 40 of its own device to the surrounding devices 100 (sequence SQ110). Each device that receives the state notification message 42 from the device 100-5 Based on the state notification message 42, the device updates the state information 40 of its own device (sequence SQ112).

[0171] Similarly, device 100-4 transmits a state notification message 42 indicating the contents of its own state information 40 to the surrounding devices 100 (sequence SQ114). Each device that receives the state notification message 42 from device 100-4 updates its own state information 40 based on the received state notification message 42 (sequence SQ116).

[0172] In this way, each of the multiple devices 100 holds state information 40 that reflects the connection relationships between each device 100 (sequence SQ100), and transmits state notification messages 42 indicating the contents of the state information 40 to the other devices (sequences SQ102, SQ106, SQ110, SQ114). Furthermore, each of the multiple devices 100 updates the state information 40 it holds based on the state notification messages 42 received from the other devices (sequences SQ104, SQ108, SQ112, SQ116). These processes may be performed periodically.

[0173] Sequences SQ102 and SQ104, sequences SQ106 and SQ108, sequences SQ110 and SQ112, and sequences SQ114 and SQ116 can be executed at independent times, and therefore can be executed in any order, or can be executed in parallel.

[0174] When the device 100 that will operate as the root node 34 is determined as a result of the transmission of the state notification message 42 by each device 100, the device 100 that operates as the root node 34 (device 100-1 in the example shown in FIG. 15) determines the routing table 32 (sequence SQ120). In this way, between node groups 30 (a set of devices 100) that are logically defined based on the state information 40 held by each device 100, a process is executed to determine the routing table 32 that will be maintained between the devices 100 included in the node group 30. The routing table 32 is used to search for a device that is the destination of data transmission.

[0175] Then, the device 100 operating as the root node 34 transmits the determined routing table 32 to the other devices 100 operating as descendant nodes of the device itself (sequence SQ122).

[0176] Then, the processing of sequences SQ102 to SQ120 is repeated. 15 shows an example in which each device 100 initially sets the state information 40, but in reality, it is assumed that a new device 100 may join the network system 1 or a device 100 may leave the network system 1. In such a case, processing such as changing the device 100 operating as the root node 34 or updating the contents of the routing table 32 is performed.

[0177] Next, a detailed description will be given of the state information 40 and the state notification message 42. In the network system 1 according to the present embodiment, each device 100 sequentially updates its own state information 40 based on the state notification message 42 exchanged between adjacent devices 100, thereby logically constructing a node group 30 in which devices 100 are hierarchically connected as shown in FIG.

[0178] FIG. 16 shows an example of the data structure of state information 40 and state notification message 42 used in network system 1 according to the present embodiment. 16(a) shows an example of the data structure of the state information 40, and FIG. 16(b) shows an example of the data structure of the state notification message 42.

[0179] Referring to FIG. 16(a), state information 40 includes, as setting items, Parent ID 401, Children 402, Root ID 403, height 404, and binary representation 405.

[0180] In ParentID 401, identification information (typically, KeyID, which will be described later) for identifying a device that is a parent node of each device 100 is stored.

[0181] Children 402 stores identification information (typically, a KeyID, described later) for identifying a device that is a child node of each device 100. Note that the number of devices that are child nodes is not limited to one, so Children 402 stores one or more devices in list format.

[0182] The RootID 403 stores identification information (typically, a KeyID, which will be described later) for identifying the device 100 that operates as the root node 34 of the node group 30 to which each device belongs.

[0183] Height 404 stores the height of each device in the node group 30 to which each device belongs. Height means the maximum number of edges from the root node 34 to a leaf node in the node group 30 to which each device belongs. In other words, the depth from the root node 34 to a leaf node in the node group 30 can be determined based on the size of height.

[0184] The binary representation 405 stores identification information for identifying the device (node) to be searched for in the node group 30 to which each device belongs.

[0185] The state information 40 may also include a time stamp as an additional setting item. The time stamp may be, for example, information indicating the update time of each device 100, or information indicating the time of the state notification message 42.

[0186] Each device 100 has identification information called a KeyID for identifying the device itself. The KeyID is identification information that can uniquely identify the device 100 in the network system 1. Typically, the KeyID may be an IP address that each device 100 has, or a hash value calculated from the IP address based on a hash function.

[0187] 16(b), the state notification message 42 indicates the contents of the state information 40. More specifically, the state notification message 42 includes a ParentID 421, a RootID 422, a height 423, and a KeyID 424.

[0188] ParentID 421 stores the same value as ParentID 401 in the state information 40. RootID 422 stores the same value as RootID 403 in the state information 40. Height 423 stores the same value as height 404 in the state information 40. KeyID 424 stores KeyID, which is identification information of the device itself.

[0189] In this way, the state information 40 and the state notification message 42 include a KeyID (identification information of the device itself) as identification information for identifying each device 100. In this case, a value calculated based on the IP address determined by each device 100 may be used as the KeyID (identification information of the device itself).

[0190] The state information 40 and the state notification message 42 also include identification information (KeyID) for identifying the device 100 that is the root node 34 of each device 100.

[0191] 16 shows a state in which the state information 40 and the state notification message 42 are both initialized. That is, "null" is set in ParentID 401, the value of the KeyID of the device itself (KeyID1 in the example of FIG. 16) is set in RootID 403, and "0" is set in height 404.

[0192] The state information 40 initially set as shown in Fig. 16(a) is updated as appropriate based on state information 40 from other devices. An example of updating the state information 40 will be described below.

[0193] Fig. 17 is a diagram showing an example of updating state information 40 by state notification message 42 in network system 1 according to the present embodiment. Fig. 17 shows, as an example, an example of updating the contents of state information 40 when devices 100-1, 100-5, and 100-6 form a tree structure in this order in network system 1 shown in Fig. 12.

[0194] After being initialized, state information 40 of devices 100-1, 100-5, and 100-6 is sequentially updated based on state notification messages 42 from other devices. As a result, in all state information 40, "KeyID1" indicating device 100-1 is stored in RootID 403, and "2" is stored in height 404, which is the maximum number of edges from root node 34 to a leaf node in the node group.

[0195] In each of the state information 40, the Parent ID 401 and the Children 402 store the Key ID corresponding to the connection relationship between the nodes.

[0196] As an example, binary representation 405 stores identification information with a number of bits corresponding to the distance from the leaf node. FIG. 17 shows three examples ("0", "01", and "001") as examples. The greater the number of bits constituting the value of binary representation 405, the farther it is from the leaf node. That is, a device 100 having "0" as binary representation 405 is closer to the corresponding leaf node, and a device 100 having "001" as binary representation 405 is farther from the corresponding leaf node.

[0197] 17, the tree structure of the node group is identified based on the state information 40 of each device, and the device 100 operating as the root node 34 determines a routing table 32 based on the identified tree structure and provides it to each device belonging to the same node group. By this procedure, it is possible to determine the node group and the root node 34 of the node group, and to determine the routing table 32 in the root node 34.

[0198] It should be noted that the timing of sending the state notification message 42 from each device 100 is determined arbitrarily by each device 100, so it is not necessarily the case that the update of the state information 40 has been completed in all devices. Therefore, it is preferable that each device 100 performs version management over several generations when updating the state information 40. In other words, it is preferable to store both the contents of the state information 40 before and after the update. In this case, The device 100 operating as the remote node 34 determines the routing table 32 based on the appropriate version of the state information 40 among the state information 40 held by each device 100.

[0199] Figure 18 is a flowchart showing a processing procedure for determining a routing table in network system 1 according to the present embodiment. The processing for determining a routing table shown in Figure 18 includes processing such as determining node group 30 and updating state information 40. Each step shown in Figure 18 is executed by control unit 110 (see Figure 2) of device 100 (typically, realized by cooperation between a processor and a memory).

[0200] Referring to FIG. 18, when device 100 is connected to any network, device 100 initializes state information 40 of its own device (step S100).

[0201] Next, the device 100 determines whether or not a condition for transmitting the state notification message 42 is met (step S102). For example, it determines whether or not the time elapsed since the previous state notification message 42 has reached a predetermined time.

[0202] If the conditions for transmitting the state notification message 42 are met (YES in step S102), the device 100 generates the state notification message 42 based on the current state information 40 and transmits the state notification message 42 to other devices (step S104). If the conditions for transmitting the state notification message 42 are not met (NO in step S102), the processing of step S104 is skipped.

[0203] In this way, the device 100 holds state information 40 that reflects the connection relationships with other devices, and executes processing to transmit state notification messages 42 indicating the contents of the state information 40 to other devices (steps S100 to S104).

[0204] Next, the device 100 determines whether or not it has received a state notification message 42 from another device (step S106). If it has received a state notification message 42 from another device (YES in step S106), the device 100 determines whether or not it needs to update the state information 40 based on the received state notification message 42 (step S108). If it is determined that it needs to update the state information 40 (YES in step S108), the device 100 updates its own state information 40 (step S110). If it is determined that it does not need to update the state information 40 (NO in step S108), the processing of step S110 is skipped.

[0205] In this way, the device 100 executes the process of updating the state information 40 based on the state notification message 42 received from another device 100 (steps S106 to S110).

[0206] On the other hand, if the state notification message 42 has not been received from another device (NO in step S106), the processes of steps S108 and S110 are skipped.

[0207] Here, the processes in steps S108 and S110 will be described in detail. 13, the device included in each tree structure can be determined by determining an arbitrary device as the root node 34. The device 100 that operates as the root node 34 may be determined based on the value of the KeyID of each device 100. In other words, in the process of updating the state information 40, the device (RootID4) that is set as the root node included in the received state notification message 42 is used. If the device 100 identified by the KeyID stored in RootID 402 does not match the device 100 identified by the KeyID stored in RootID 403 that is the root node included in the state information 40, a process is executed to determine one of the devices 100 as the root node according to a predetermined rule.

[0208] In this embodiment, the size relationship of KeyIDs is used as an example of a predetermined rule. For example, the device with the smallest KeyID among devices in a certain range may be determined as the root node 34 for that range. In this case, each device 100 references the RootID 422 (see FIG. 16(b)) included in the state notification message 42 received from another device corresponding to the parent node to determine whether or not to update the state information 40.

[0209] Specifically, when the following conditions (1) and (2) are met, the contents of the state information 40 are updated.

[0210] (1) The value of RootID 403 in the state information 40 > the value of RootID 422 in the state notification message 42 received from the parent node and (2) Value of height 404 in state information 40 < value of height 423 in state notification message 42 received from parent node Here, condition (1) means that the KeyID of the root node 34 recognized by the parent node is smaller than the KeyID of the root node 34 recognized by the device, and condition (2) means that the parent node belongs to a tree structure deeper than the tree structure recognized by the device.

[0211] When conditions (1) and (2) are met, the contents of the state information 40 are updated so that the device is nested in the parent node. More specifically, as shown below, the ParentID 401, RootID 403, and height 404 of the state information 40 are updated to the values ​​contained in the state notification message 42 received from the parent node.

[0212] ParentID401 of state information 40 ← Value of KeyID424 of state notification message 42 received from the parent node · RootID403 in state information 40 ← Value of RootID422 in state notification message 42 received from the parent node Height 404 in state information 40 ← Value of height 423 in state notification message 42 received from parent node + 1 (increment the value of height 423) Any rule may be used to determine the root node 34. For example, the device with the largest Key ID among devices in a certain range may be determined as the root node 34 for that range, or the device with the Key ID closest to an arbitrarily set value may be determined as the root node 34. In this case, the above-mentioned condition (1) may be changed as appropriate.

[0213] Next, the device 100 determines whether or not it has received a sufficient number of state notification messages 42 from other devices (step S112). If it has received a sufficient number of state notification messages 42 from other devices (YES in step S112), the device 100 executes the following process of maintaining a routing table 32 used to search for a device that is the destination of data transmission among node groups 30 (a logically defined collection of devices 100) based on the state information 40 held by each device 100 (S116, S118, S122, S124).

[0214] More specifically, the device 100 determines whether or not the device itself operates as the root node 34 based on the state information 40 (step S114).

[0215] If the device itself operates as a root node 34 (YES in step S114), the device 100 determines a routing table 32 based on the state information 40 of the device itself and the state information 40 of the other devices (step S116), and transmits the determined routing table 32 to the other devices (step S118).

[0216] In this way, when the device 100 determines based on the state information 40 that the device 100 itself will operate as a root node in the node group 30, the device 100 executes processing to determine the routing table 32.

[0217] On the other hand, if the device 100 does not operate as the root node 34 (NO in step S114), the device 100 transmits the state information 40 of the device to the device set as the root node (step S120), and determines whether or not it has received a routing table 32 from a device operating as a root node (step S122). If it has received a routing table 32 from a device operating as a root node (YES in step S122), the device 100 stores the received routing table 32 (step S124). In this way, the device 100 holds the routing table 32 by receiving the routing table 32 from another device 100.

[0218] If the routing table 32 has not been received from the device operating as the root node (NO in step S122), the process of step S124 is skipped. Also, if a sufficient number of state notification messages 42 have not been received from other devices (NO in step S112), the process from step S102 onwards is repeated.

[0219] Then, the processes of steps S102 to S124 shown in FIG. 18 are repeatedly executed. Fig. 19 is a flowchart showing a processing procedure for transmitting and receiving packets in each device 100 in network system 1 according to this embodiment. Fig. 19(a) shows processing when a packet to be transmitted occurs in the device itself, and Fig. 19(b) shows processing when a packet is received from another device. Each step shown in Fig. 19(a) and Fig. 19(b) is executed by control unit 110 (see Fig. 2) of device 100 (typically, this is realized by cooperation between a processor and a memory).

[0220] 19(a), the device 100 determines whether or not a transmission packet addressed to another device has been given by the various applications 300 or the like (step S200). If a transmission packet addressed to another device has not been given (NO in step S200), the process of step S200 is repeated.

[0221] On the other hand, when a transmission packet addressed to another device is given (YES in step S200), the device 100 refers to the routing table 32 and transmits the transmission packet to the other device according to the route to the destination device (step S202). At this time, if the destination device is included in the descendant nodes of the device 100, the device 100 transmits the transmission packet to a child node according to the route to the descendant node. On the other hand, if the destination device is not included in the descendant nodes of the device 100, the device 100 transmits the transmission packet to a parent node of the device 100. This completes the transmission process of the transmission packet.

[0222] 19(b), it is determined whether a transmission packet has been received from another device (step S250). If a transmission packet has not been received from another device (NO in step S250), the process of step S250 is repeated.

[0223] On the other hand, if a transmission packet has been received from another device (YES in step S250), the device 100 determines whether the received transmission packet is addressed to the device itself (step S252). If the received transmission packet is addressed to the device itself (YES in step S252), the device 100 receives the packet from the sending device and outputs it to the corresponding application 300 (step S254). This ends the processing when a packet is received.

[0224] On the other hand, if the received transmission packet is not addressed to the device itself (NO in step S252), the device 100 refers to the routing table 32 and transmits the transmission packet to another device according to the route to the destination device (step S256). The process of determining the destination by referring to this routing table 32 is the same as that in step S202. Thus, the process when receiving a packet ends.

[0225] As described above, in the network system 1 according to the present embodiment, the routing table 32 is determined and shared for each node group (a logically defined set of devices 100). By adopting the routing table 32 shared for each node group in this way, when transmitting data to any device included in the network system 1, the transmission path can be determined in a shorter time.

[0226] In the network system 1 according to the present embodiment, each of the devices 100 included in the network system 1 transmits a state notification message 42 indicating the content of the state information 40 it holds to other devices 100. And each of the devices 100 appropriately updates the content of the state information 40 held by the device itself based on the content of the received state notification message 42 when receiving the state notification message 42 from other devices 100. By periodically or regularly executing such update processing of the state notification message 42 and the state information 40, even when there are changes such as the joining / leaving of devices 100 or a change in the connection topology in the network system 1, an appropriate routing table 32 can be maintained.

[0227] <E. Advantages> According to the network system 1 according to the present embodiment, in a network where a large number of devices exist, a solution can be provided in which each device can independently realize data communication.

[0228] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]

[0229] 1 Network system, 2 Network, 4 Access point, 6 Mobile base station, 10 Connection, 30 Node group, 32 Routing table, 34 Root node, 36 node, 40 state information, 42 state notification message, 100 device, 102 processor, 104 main memory, 106 storage, 108 ROM, 110 control unit, 120 network interface, 130 display unit, 140 input unit, 150 media interface, 152 media, 160 OS, 170 communication processing program, 172 private key, 174 public key, 176 digital certificate, 178 hash value, 180 hash function, 190 IP address, 194 connection table, 200 certification authority, 210 network management table, 214 initial screen information, 216 preference information, 220A, 220B screen examples, 230 usage management table, 232 network address, 234 room number, 236 available time ,240 accommodation, 242 radio communication unit, 300 application, 405 binary representation, RT1,RT2,RT3 route.

Claims

1. A method of communication in a network including a plurality of devices, comprising: Each of the plurality of devices determines an entire network address of the device using only a part or all of a hash value calculated by inputting the public key of the device into a hash function; Each device maintains a routing table used to determine where to forward data received from a given device; A communication method comprising a step in which, when each device receives a notification message from another device indicating the contents of state information reflecting the connection relationship of the other device, the device updates the routing table based on the received notification message.

2. The communication method according to claim 1 , wherein the routing table includes identification information for identifying each device and the location of the device.

3. 3. The communication method according to claim 1, wherein the notification message includes identification information calculated from a network address of a device that has generated the state information indicated by the notification message, for identifying the device that has generated the state information indicated by the notification message.

4. 4. The communication method according to claim 1, wherein a routing table is shared between devices that belong to the same node group formed by logically dividing the plurality of devices.

5. The communication method according to claim 4 , further comprising the step of a device that is designated as a root node in the node group generating the routing table.

6. The communication method according to claim 5 , wherein the state information includes identification information for identifying the device that is to be the root node.

7. 7. The communication method according to claim 5, wherein the state information includes information indicating a depth from the root node to each device.

8. 8. The communication method according to claim 5, wherein the state information includes identification information indicating a parent node of each device and identification information indicating a child node of each device.

9. 1. A networked system comprising: With multiple networked devices, each of the plurality of devices includes means for determining an entire network address of the device using all or only a part of a hash value calculated by inputting the public key of the device into a hash function; Each device is means for maintaining a routing table used to determine the destination of data received from a device; and means for, when receiving a notification message from another device indicating the contents of state information that reflects the connection relationships of the other device, updating the routing table based on the received notification message.

Citation Information

Patent Citations

  • Router with bridge function

    JP1993022293A

  • Node, routing control method, and routing control program

    JP2009171056A

  • Tree-Guided Distributed Link-State Routing Method

    JP2009529846A

  • Addressing mechanisms in mobile IP

    US20030084293A1