Air conditioning system and communication method
By establishing sessions only within the same refrigerant system network and using centralized communication across systems, the air conditioning system reduces processing time and memory usage, ensuring secure communication while maintaining effective security measures against cyber threats.
Patent Information
- Application Number
- JP2024559737
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-11-21
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2042-11-21
AI Technical Summary
Air conditioning systems face increased processing time and memory usage due to the number of sessions required for encrypted communication, posing a challenge in maintaining security against cyber attacks.
Implementing a communication method where devices within the same refrigerant system communicate using internal/external communication and devices across refrigerant systems use centralized communication, establishing sessions only between devices within the same network to reduce the number of required sessions and shared keys.
This approach ensures secure communication while minimizing the processing time and memory usage required for communication preparation, thereby enhancing the system's security without excessive resource consumption.
Smart Images

Figure 0007796898000001 
Figure 0007796898000002 
Figure 0007796898000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an air conditioning system and a communication method. [Background technology]
[0002] Air conditioning systems are known that include one outdoor unit and multiple indoor units for each air conditioning unit. One air conditioning unit corresponds to one refrigerant system. In such air conditioning systems, all air conditioners, i.e., all outdoor units and all indoor units, are basically connected so that they can communicate with each other. Patent Document 1 describes an air conditioning system in which the outdoor units of each air conditioning unit are connected to each other by a centralized transmission line, and the outdoor unit and multiple indoor units within each air conditioning unit are connected to each other by internal and external transmission lines.
[0003] In recent years, there have been cases where air conditioning systems have become targets of cyber attacks. For this reason, security measures against cyber attacks are desired for air conditioning systems. One security measure is, for example, a method of employing encrypted communication in which communication data is encrypted using a common key. In order to carry out encrypted communication, a session must be established between two devices that perform encrypted communication. Therefore, for example, in order for all air conditioning devices to communicate with each other using encrypted communication, a session must be established for every combination of air conditioning devices. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-20092 Summary of the Invention [Problem to be solved by the invention]
[0005] However, as the number of sessions to be established increases, the processing time required to establish the sessions and the memory capacity required to store the shared keys also increase. For this reason, there is a demand for an air conditioning system that can communicate safely while suppressing the increase in processing time required for communication preparation and the increase in memory usage.
[0006] The present disclosure has been made in consideration of the above-mentioned problems, and aims to provide an air conditioning system and a communication method that communicates safely while suppressing increases in processing time and memory usage required for preparing for communication. [Means for solving the problem]
[0007] In order to achieve the above object, the air conditioning system according to the present disclosure comprises: An air conditioning system comprising a plurality of first air conditioning devices belonging to a first refrigerant system and a plurality of second air conditioning devices belonging to a second refrigerant system, the plurality of first air conditioning devices and the plurality of second air conditioning devices being communicatively connected, the plurality of first air conditioning apparatuses communicate with each other using encrypted communication in which communication data is encrypted using a common key; the plurality of second air conditioning devices communicate with each other using the encrypted communication, When a first communication device among the plurality of first air conditioning devices communicates with a second communication device among the plurality of second air conditioning devices, a first relay device among the plurality of first air conditioning devices and a second relay device among the plurality of second air conditioning devices communicate with each other using the encrypted communication. [Effects of the Invention]
[0008] In the present disclosure, when a plurality of first air conditioning units belonging to a first refrigerant system communicate with each other using encrypted communication, a plurality of second air conditioning units belonging to a second refrigerant system communicate with each other using encrypted communication, and a first communication unit belonging to the first refrigerant system communicates with a second communication unit belonging to the second refrigerant system, a first relay unit belonging to the first refrigerant system communicates with a second relay unit belonging to the second refrigerant system using encrypted communication. Therefore, according to the present disclosure, safe communication can be achieved while suppressing increases in the processing time and memory usage required for communication preparation. [Brief explanation of the drawings]
[0009] [Figure 1] Configuration diagram of an air conditioning system according to embodiment 1 [Figure 2] Network configuration diagram of an air conditioning system according to embodiment 1 [Figure 3] Session list diagram [Figure 4] Diagram showing the session establishment procedure [Figure 5] An explanatory diagram of an overview of the functions of an air conditioning system according to embodiment 1. [Figure 6] Functional configuration diagram of the outdoor unit according to the first embodiment [Figure 7] Functional configuration diagram of an indoor unit according to embodiment 1 [Figure 8] An illustration of frames sent and received in encrypted communication [Figure 9] Flowchart showing processing at the time of frame transmission according to the first embodiment [Figure 10] Flowchart showing frame reception processing according to the first embodiment [Figure 11] Functional configuration diagram of an outdoor unit and an indoor unit according to embodiment 2 [Figure 12] Functional configuration diagram of an outdoor unit and an indoor unit according to embodiment 3 [Figure 13] Configuration diagram of an air conditioning system according to embodiment 4 [Figure 14] Functional configuration diagram of an outdoor unit and an indoor unit according to embodiment 4 [Figure 15]FIG. 13 shows a device confirmation screen displayed by a system controller according to the fifth embodiment. [Figure 16] Network configuration diagram of an air conditioning system according to a sixth embodiment DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals.
[0011] (Embodiment 1) FIG. 1 is a diagram showing the configuration of an air conditioning system 1000 pertaining to Embodiment 1. The air conditioning system 1000 is a system for conditioning the air inside a building, condominium, apartment, factory, etc. The air conditioning system 1000 comprises an outdoor unit 100A, an outdoor unit 100B, an indoor unit 200AA, an indoor unit 200AB, an indoor unit 200BA, an indoor unit 200BB, and a system controller 300. Hereinafter, where appropriate, the outdoor unit 100A and the outdoor unit 100B will be collectively referred to as the outdoor unit 100, and the indoor unit 200AA, the indoor unit 200AB, the indoor unit 200BA, and the indoor unit 200BB will be collectively referred to as the indoor unit 200.
[0012] The air conditioning system 1000 includes refrigerant system 400A and refrigerant system 400B as refrigerant systems. A refrigerant system is a part of an air conditioning system through which a refrigerant whose state changes depending on temperature, pressure, etc. flows. The same refrigerant flows through the same refrigerant system. Hereinafter, refrigerant system 400A and refrigerant system 400B will be collectively referred to as refrigerant system 400 where appropriate.
[0013] The refrigerant system 400A includes an outdoor unit 100A, an indoor unit 200AA, an indoor unit 200AB, and refrigerant piping 61A. The refrigerant piping 61A is piping for circulating refrigerant between the outdoor unit 100A, the indoor unit 200AA, and the indoor unit 200AB. The refrigerant system 400B includes an outdoor unit 100B, an indoor unit 200BA, an indoor unit 200BB, and refrigerant piping 61B. The refrigerant piping 61B is piping for circulating refrigerant between the outdoor unit 100B, the indoor unit 200BA, and the indoor unit 200BB. Hereinafter, the refrigerant piping 61A and the refrigerant piping 61B will be collectively referred to as refrigerant piping 61 where appropriate.
[0014] The outdoor unit 100 is a piece of equipment that conditions indoor air and is installed outdoors. Conditioning indoor air means adjusting the temperature, humidity, air cleanliness, etc. of the indoor air. The indoor unit 200 is a piece of equipment that conditions indoor air and is installed indoors. The indoor unit 200 blows air into the room for heating, cooling, dehumidification, ventilation, etc. The system controller 300 controls the outdoor unit 100 and the indoor unit 200, and controls the operation of the entire air conditioning system 1000. The outdoor unit 100, the indoor unit 200, and the system controller 300 are connected so that they can communicate with each other.
[0015] 2 shows the network configuration of the air conditioning system 1000. The outdoor unit 100A, the indoor unit 200AA, the indoor unit 200AB, the communication lines 71A and 71B belong to a communication network 710. The outdoor unit 100B, the indoor unit 200BA, the indoor unit 200BB, the communication lines 72A and 72B belong to a communication network 720. The outdoor unit 100A, the outdoor unit 100B, the system controller 300, the communication lines 73A and 73B belong to a communication network 730. In this way, in this embodiment, one communication network is formed for each refrigerant system 400, and one communication network is formed by each outdoor unit 100 and the system controller 300.
[0016] The communication line 71A is a communication line that connects the outdoor unit 100A and the indoor unit 200AA. The communication line 71B is a communication line that connects the indoor unit 200AA and the indoor unit 200AB. The communication line 72A is a communication line that connects the outdoor unit 100B and the indoor unit 200BA. The communication line 72B is a communication line that connects the indoor unit 200BA and the indoor unit 200BB. The communication line 73A is a communication line that connects the outdoor unit 100A and the system controller 300. The communication line 73B is a communication line that connects the outdoor unit 100A and the outdoor unit 100B. Hereinafter, the communication lines 71A and 71B will be collectively referred to as the communication lines 71, the communication lines 72A and 72B will be collectively referred to as the communication lines 72, and the communication lines 73A and 73B will be collectively referred to as the communication lines 73, as appropriate. Each of the communication lines 71, 72, and 73 is, for example, an Ethernet (registered trademark) cable.
[0017] Communication network 710 and communication network 720 are communication networks that interconnect devices that belong to the same refrigerant system 400. Specifically, communication network 710 is a communication network that interconnects devices that belong to refrigerant system 400A. In communication network 710, outdoor unit 100A, indoor unit 200AA, and indoor unit 200AB communicate with each other via communication line 71. Communication network 720 is a communication network that interconnects devices that belong to refrigerant system 400B. In communication network 720, outdoor unit 100B, indoor unit 200BA, and indoor unit 200BB communicate with each other via communication line 72.
[0018] The communication network 730 is a communication network in which devices that do not belong to the same refrigerant system 400 are interconnected. Specifically, the communication network 730 is a communication network in which the outdoor units 100 and system controllers 300 that belong to each refrigerant system 400 are interconnected. In the communication network 730, the outdoor units 100A, 100B, and the system controller 300 communicate with each other via a communication line 73. Each of the communication networks 710, 720, and 730 is a LAN (Local Area Network) capable of IP (Internet Protocol) communication.
[0019] The configurations of the outdoor unit 100, indoor unit 200, and system controller 300 will be described in detail below. In the description of the configurations of the outdoor unit 100 and indoor unit 200, the configuration related to information processing, communication processing, etc. will be mainly described, and descriptions of the compressor, condenser, refrigerant piping, expansion valve, evaporator, etc. will be omitted. The outdoor unit 100 comprises a control unit 11, a memory unit 12, an internal / external communication unit 15, and a centralized communication unit 16. The indoor unit 200 comprises a control unit 21, a memory unit 22, and an internal / external communication unit 25. The system controller 300 comprises a control unit 31, a memory unit 32, a display unit 33, an operation reception unit 34, and a centralized communication unit 36.
[0020] The control unit 11 includes a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), RTC (Real Time Clock), etc. The CPU is also called a central processing unit, central arithmetic unit, processor, microprocessor, microcomputer, DSP (Digital Signal Processor), etc., and functions as a central arithmetic processing unit that executes processes and calculations related to the control of the outdoor unit 100. In the control unit 11, the CPU reads out programs and data stored in the ROM and uses the RAM as a work area to perform overall control of the outdoor unit 100. The RTC is, for example, an integrated circuit with a timekeeping function. The CPU can determine the current date and time from the time information read out from the RTC.
[0021] The control unit 11 executes, for example, device control of the outdoor unit 100. The control unit 11 also communicates with the indoor unit 200 through internal / external communication using the internal / external communication unit 15. The control unit 11 also communicates with other outdoor units 100 or the system controller 300 through centralized communication using the centralized communication unit 16. The control unit 11 executes creation and analysis of commands in the internal / external communication and centralized communication.
[0022] The storage unit 12 includes a nonvolatile semiconductor memory such as a flash memory, an EPROM (Erasable Programmable ROM), or an EEPROM (Electrically Erasable Programmable ROM), and serves as a so-called auxiliary storage device. The storage unit 12 stores programs and data used by the control unit 11 to execute various processes. The storage unit 12 also stores data generated or acquired by the control unit 11 executing various processes. For example, the storage unit 12 stores its own server certificate, root certificate, its own private key, its own public key, a common key, etc.
[0023] The internal / external system communication unit 15 executes transmission and reception processing of internal / external system communication in accordance with control by the control unit 11. That is, the internal / external system communication unit 15 communicates with the indoor unit 200 via the communication line 71 or the communication line 72 in accordance with control by the control unit 11. Internal / external system communication is communication between devices belonging to the same refrigerant system 400. That is, communication between the outdoor unit 100A, the indoor unit 200AA, and the indoor unit 200AB, which belong to the communication network 710, is internal / external system communication. Furthermore, communication between the outdoor unit 100B, the indoor unit 200BA, and the indoor unit 200BB, which belong to the communication network 720, is also internal / external system communication. The internal / external system communication unit 15 includes, for example, a communication interface equipped with a communication driver IC (Integrated Circuit).
[0024] The centralized communication unit 16 executes transmission and reception processing of centralized communication in accordance with the control of the control unit 11. That is, the centralized communication unit 16 communicates with other outdoor units 100 or the system controller 300 via the communication line 73 in accordance with the control of the control unit 11. Centralized communication is communication between devices that do not belong to the same refrigerant system 400. That is, communication between the outdoor unit 100A, the outdoor unit 100B, and the system controller 300, which belong to the communication network 730, is centralized communication. The centralized communication unit 16 includes, for example, a communication interface that includes a communication driver IC.
[0025] The control unit 21 includes a CPU, ROM, RAM, RTC, etc. The CPU is also called a central processing unit, central processing unit, processor, microprocessor, microcomputer, DSP, etc., and functions as a central processing unit that executes processing and calculations related to the control of the indoor unit 200. In the control unit 21, the CPU reads out programs and data stored in the ROM and uses the RAM as a work area to perform overall control of the indoor unit 200.
[0026] The control unit 21, for example, executes device control of the indoor unit 200. The control unit 21 also communicates with the outdoor unit 100 or other indoor units 200 through internal / external communication using the internal / external communication unit 25. The control unit 21 creates and analyzes commands in the internal / external communication.
[0027] The storage unit 22 includes a nonvolatile semiconductor memory such as a flash memory, an EPROM, or an EEPROM, and serves as a so-called auxiliary storage device. The storage unit 22 stores programs and data used by the control unit 21 to execute various processes. The storage unit 22 also stores data generated or acquired by the control unit 21 executing various processes. For example, the storage unit 22 stores its own server certificate, a root certificate, its own private key, its own public key, a common key, etc.
[0028] The internal / external communication unit 25 executes transmission / reception processing for internal / external communication in accordance with control by the control unit 21. That is, the internal / external communication unit 25 communicates with the outdoor unit 100 or another indoor unit 200 via the communication line 71 or the communication line 72 in accordance with control by the control unit 21. The internal / external communication unit 25 includes, for example, a communication interface including a communication driver IC.
[0029] The control unit 31 includes a CPU, ROM, RAM, RTC, etc. The CPU is also called a central processing unit, central arithmetic unit, processor, microprocessor, microcomputer, DSP, etc., and functions as a central arithmetic processing unit that executes processing and calculations related to the control of the system controller 300. In the control unit 31, the CPU reads out programs and data stored in the ROM and uses the RAM as a work area to perform overall control of the system controller 300.
[0030] The control unit 31, for example, executes device control of the system controller 300. The control unit 31 also communicates with the outdoor unit 100 through centralized communication using the centralized communication unit 36. The control unit 31 creates and analyzes commands in the centralized communication. The control unit 31 controls the display unit 33 to display various screens. The control unit 31 also acquires information received from the user by the operation reception unit 34.
[0031] The storage unit 32 includes a nonvolatile semiconductor memory such as a flash memory, an EPROM, or an EEPROM, and serves as a so-called auxiliary storage device. The storage unit 32 stores programs and data used by the control unit 31 to execute various processes. The storage unit 32 also stores data generated or acquired by the control unit 31 executing various processes. For example, the storage unit 32 stores its own server certificate, a root certificate, its own private key, its own public key, a common key, etc.
[0032] The display unit 33 displays various images under the control of the control unit 31. For example, the display unit 33 displays a screen for accepting various operations from the user. The display unit 33 includes a touch screen, a liquid crystal display, etc. The operation accepting unit 34 accepts various operations from the user and supplies information indicating the contents of the accepted operations to the control unit 31. The operation accepting unit 34 includes a touch screen, a button, a lever, etc.
[0033] The centralized communication unit 36 executes transmission and reception processing of centralized communication in accordance with the control of the control unit 31. That is, the centralized communication unit 36 communicates with the outdoor unit 100 via the communication line 73 in accordance with the control of the control unit 31. The centralized communication unit 36 includes, for example, a communication interface including a communication driver IC.
[0034] Next, communication between the devices included in the air conditioning system 1000 will be described. The devices included in the air conditioning system 1000 communicate with each other using internal / external communication or centralized communication. Specifically, devices belonging to communication network 710 communicate with each other using internal / external communication. Furthermore, devices belonging to communication network 720 communicate with each other using internal / external communication. Furthermore, devices belonging to communication network 730 communicate with each other using centralized communication.
[0035] It should be noted that devices that do not belong to the same communication network communicate with each other via the outdoor unit 100. For example, the indoor unit 200AA that belongs to the communication network 710 communicates with the indoor unit 200BB that belongs to the communication network 720 via the outdoor unit 100A and the outdoor unit 100B. In this case, the indoor unit 200AA communicates with the outdoor unit 100A via indoor / outdoor communication, the outdoor unit 100A communicates with the outdoor unit 100B via centralized communication, and the outdoor unit 100B communicates with the indoor unit 200BB via indoor / outdoor communication.
[0036] In this embodiment, both the internal / external communication and the centralized communication are IP communications, and a unique IP address is set for each device included in the air conditioning system 1000. Also, in this embodiment, server authentication and encrypted communication in accordance with TLS (Transport Layer Security) are performed for both the internal / external communication and the centralized communication.
[0037] Each device included in the air conditioning system 1000 has a server certificate unique to the device, a private key unique to the device, a public key unique to the device, and a root certificate common to the air conditioning system 1000. The root certificate may be prepared by the device manufacturer, may be supplied by the user at the time of installation, or may be generated from information acquired from the user at the time of installation. Furthermore, each device included in the air conditioning system 1000 may generate a common key required for encrypted communication by itself, or may receive this common key from another device.
[0038] Generally, when server authentication and encrypted communication are performed according to TLS, an end-to-end session is established at the start of communication. However, in this embodiment, a session is established between devices that belong to the same communication network, and a session is not established between devices that do not belong to the same communication network. In this embodiment, devices that do not belong to the same communication network communicate with each other via the outdoor unit 100. This configuration can suppress an increase in the startup time required to start communication and an increase in memory usage. Therefore, secure communication can be achieved while suppressing an increase in the processing time required to prepare for communication and an increase in memory usage.
[0039] Fig. 3 shows a session list representing a list of sessions established in this embodiment. As shown in Fig. 3, in this embodiment, sessions are established only between devices that belong to the same communication network. When a session is established between two devices, two sessions are established: one session in which one device is a server and the other device is a client, and another session in which the other device is a server and the one device is a client.
[0040] For example, consider a case where the system controller 300 and the outdoor unit 100A communicate with each other. In this case, a session is established with the system controller 300 as the server and the outdoor unit 100A as the client, ensuring security in the communication direction from the outdoor unit 100A to the system controller 300. A session is then established with the outdoor unit 100A as the server and the system controller 300 as the client, ensuring security in the communication direction from the system controller 300 to the outdoor unit 100A.
[0041] When establishing an end-to-end session, the number of pairs of devices to establish a bidirectional session is 7C2=21, so 21×2=42 sessions must be established. On the other hand, in this embodiment, the number of pairs of devices to establish a bidirectional session is 9, so 9×2=18 sessions must be established.
[0042] The procedure for establishing a session when a client authenticates a server will be described below with reference to Fig. 4. This procedure is a procedure for establishing a TLS session using public key cryptography.
[0043] First, in step S1, the client requests a connection to the server. In step S2, the server sends the client a server certificate containing the server's public key. In step S3, the client verifies that it holds the root certificate of the certification authority that signed the server certificate. In step S4, the client decrypts the digital signature included in the server certificate with the public key included in the root certificate and verifies that the server is legitimate.
[0044] In step S5, the client generates a common key to be used for encrypted communication. In step S6, the client encrypts the generated common key with the server's public key. In step S7, the client transmits the common key encrypted with the server's public key to the server. In step S8, the server decrypts the common key encrypted with the server's public key with the server's private key to obtain the common key.
[0045] In step S9, the client encrypts data to be sent to the server with the common key. In step S10, the client sends the data encrypted with the common key to the server. In step S11, the server decrypts the data encrypted with the common key with the common key and obtains the data.
[0046] The processing from step S1 to step S11 ensures security in the communication direction from the client to the server. Furthermore, if the client and server are interchanged and the processing from step S1 to step S11 is executed, bidirectional security is ensured. For example, if the processing from step S1 to step S11 is executed with the system controller 300 as the server and the outdoor unit 100A as the client, security is ensured in the communication direction from the outdoor unit 100A to the system controller 300. Furthermore, if the processing from step S1 to step S11 is executed with the system controller 300 as the client and the outdoor unit 100A as the server, security is ensured in the communication direction from the system controller 300 to the outdoor unit 100A.
[0047] Note that if the shared key is used continuously for a long period of time, the risk of the shared key being leaked increases. Therefore, it is preferable that sessions are established periodically and the shared key is updated periodically.
[0048] Next, functions of the air conditioning system 1000 will be described with reference to Figures 5, 6, and 7. Figure 5 is an explanatory diagram outlining the functions of the air conditioning system 1000. Figure 6 is a functional configuration diagram of the outdoor unit 100A. Figure 7 is a functional configuration diagram of the indoor unit 200AA.
[0049] The air conditioning system 1000 is a system comprising a plurality of first air conditioning apparatuses belonging to a first refrigerant system and a plurality of second air conditioning apparatuses belonging to a second refrigerant system, with the plurality of first air conditioning apparatuses and the plurality of second air conditioning apparatuses connected so as to be able to communicate with each other. The refrigerant system 400A is an example of a first refrigerant system, and the refrigerant system 400B is an example of a second refrigerant system. The outdoor unit 100A, the indoor unit 200AA, and the indoor unit 200AB are an example of a first air conditioning apparatus, and the outdoor unit 100B, the indoor unit 200BA, and the indoor unit 200BB are an example of a second air conditioning apparatus.
[0050] The multiple first air conditioning apparatuses communicate with each other using encrypted communication, in which communication data is encrypted using a common key. That is, the outdoor unit 100A, the indoor unit 200AA, and the indoor unit 200AB communicate with each other using encrypted communication. The multiple second air conditioning apparatuses communicate with each other using encrypted communication. That is, the outdoor unit 100B, the indoor unit 200BA, and the indoor unit 200BB communicate with each other using encrypted communication.
[0051] When the first communication device and the second communication device communicate with each other, the first relay device and the second relay device communicate with each other using encrypted communication. The first relay device is any one of the first air conditioning devices among the multiple first air conditioning devices. The second relay device is any one of the second air conditioning devices among the multiple second air conditioning devices. The first communication device is any one of the first air conditioning devices among the multiple first air conditioning devices. The second communication device is any one of the second air conditioning devices among the multiple second air conditioning devices. The first relay device may be the first communication device, and the second relay device may be the second communication device.
[0052] The outdoor unit 100A is an example of a first relay device, and the outdoor unit 100B is an example of a second relay device. The outdoor unit 100A, the indoor unit 200AA, and the indoor unit 200AB are examples of a first communication device, and the outdoor unit 100B, the indoor unit 200BA, and the indoor unit 200BB are examples of a second communication device. Note that Fig. 5 shows an example in which the indoor unit 200AA is the first communication device, and the indoor unit 200BA is the second communication device.
[0053] The first relay device relays communication between the first communication device and the second communication device when the first relay device is not the first communication device. Specifically, the first relay device communicates with the second relay device using encrypted communication that uses a first common key shared by the first relay device and the second relay device. The first relay device also communicates with the first communication device using encrypted communication that uses a second common key shared by the first relay device and the first communication device.
[0054] The second relay device relays communication between the first communication device and the second communication device when the second relay device is not the second communication device. Specifically, the second relay device communicates with the first relay device using encrypted communication with a first common key. The second relay device also communicates with the second communication device using encrypted communication with a third common key shared by the second relay device and the second communication device.
[0055] When the first relay device is the first communication device, the first relay device communicates with the second communication device using encrypted communication with the first common key. When the second relay device is the second communication device, the second relay device communicates with the first relay device using encrypted communication with the first communication device.
[0056] When a first communication device communicates with the system controller 300, the first relay device and the system controller 300 communicate with each other using encrypted communication. When a second communication device communicates with the system controller 300, the second relay device and the system controller 300 communicate with each other using encrypted communication.
[0057] If the first relay device is not the first communication device, the first relay device relays communication between the first communication device and system controller 300. Specifically, the first relay device communicates with the first communication device through encrypted communication using the second common key, and communicates with system controller 300 through encrypted communication using the fourth common key. The fourth common key is a common key shared by the first relay device and system controller 300.
[0058] If the second relay device is not the second communication device, the second relay device relays communication between the second communication device and system controller 300. Specifically, the second relay device communicates with the second communication device through encrypted communication using a third common key, and communicates with system controller 300 through encrypted communication using a fifth common key. The fifth common key is a common key shared by the second relay device and system controller 300.
[0059] In this embodiment, a common key is prepared for each communication direction. For example, the first relay and the second relay share a first common key, which is a common key used when transmitting data from the first relay to the second relay, and a common key used when transmitting data from the second relay to the first relay. The second common key, the third common key, the fourth common key, and the fifth common key are also prepared for each communication direction.
[0060] Here, the multiple first air conditioning apparatuses belong to a first communication network. Furthermore, the multiple second air conditioning apparatuses belong to a second communication network. Furthermore, the first relay apparatus and the second relay apparatus belong to a third communication network. Communication network 710 is an example of a first communication network. Communication network 720 is an example of a second communication network. Communication network 730 is an example of a third communication network.
[0061] The third communication device includes authentication means, common key generation means, and common key transmission means. The third communication device is any one of the plurality of first air conditioning devices or the plurality of second air conditioning devices. The outdoor unit 100A, the outdoor unit 100B, the indoor unit 200AA, the indoor unit 200AB, the indoor unit 200BA, and the indoor unit 200BB are examples of the third communication device.
[0062] The authentication means authenticates the fourth communication device. The fourth communication device is a device that communicates with the third communication device out of the plurality of first air conditioning devices and the plurality of second air conditioning devices. The outdoor unit 100A, the outdoor unit 100B, the indoor unit 200AA, the indoor unit 200AB, the indoor unit 200BA, and the indoor unit 200BB are examples of the fourth communication device. The shared key generation means generates a shared key to be used for encrypted communication. After the authentication means authenticates the fourth communication device, the shared key transmission means transmits the shared key generated by the shared key generation means to the fourth communication device.
[0063] Below, with reference to Figures 6 and 7, the functions of the outdoor unit 100A and the indoor unit 200AA will be described using an example in which the outdoor unit 100A and the indoor unit 200AA communicate with each other. When the outdoor unit 100A is the third communication device, the indoor unit 200AA is the fourth communication device. When the outdoor unit 100A is the fourth communication device, the indoor unit 200AA is the third communication device. In other words, the communication partner of the outdoor unit 100A is the indoor unit 200AA, and the communication partner of the indoor unit 200AA is the outdoor unit 100A.
[0064] The outdoor unit 100A functionally comprises an authentication unit 101, a common key generation unit 102, a first encryption unit 103, a common key transmission unit 104, a second encryption unit 105, a data transmission unit 106, a first decryption unit 107, and a second decryption unit 108. The indoor unit 200AA functionally comprises an authentication unit 201, a common key generation unit 202, a first encryption unit 203, a common key transmission unit 204, a second encryption unit 205, a data transmission unit 206, a first decryption unit 207, and a second decryption unit 208. The functions of the indoor unit 200AA are basically the same as those of the outdoor unit 100A, except that it does not have a relay function.
[0065] Each of these functions is realized by software, firmware, or a combination of software and firmware. The software and firmware are written as programs and stored in the ROM or storage unit 12, 22. The CPU then executes the programs stored in the ROM or storage unit 12, 22 to realize each of these functions.
[0066] The authentication unit 101 authenticates the device with which it communicates. For example, the authentication unit 101 obtains a server certificate from the indoor unit 200AA and authenticates the indoor unit 200AA by decrypting the digital signature included in the server certificate with the public key included in the root certificate stored in the storage unit 12. "Server certificate B" shown in Fig. 6 is the server certificate of the indoor unit 200AA. The authentication unit 101 is an example of authentication means.
[0067] The shared key generation unit 102 generates a shared key to be used for encrypted communication. "Shared key A" in FIG. 6 is a shared key generated by the outdoor unit 100A, and is a shared key used when transmitting data from the outdoor unit 100A to the indoor unit 200AA. The shared key generated by the shared key generation unit 102 is stored in the storage unit 12. The shared key generation unit 102 is an example of a shared key generation means. The first encryption unit 103 encrypts the shared key generated by the shared key generation unit 102 with the public key of the communication partner device. The public key of the communication partner device is included in a server certificate obtained from the communication partner device. "Public key B" in FIG. 6 is the public key of the indoor unit 200AA. The first encryption unit 103 is an example of an encryption means.
[0068] After the authentication unit 101 has authenticated the communication partner device, the shared key transmission unit 104 transmits the shared key encrypted by the first encryption unit 103 to the communication partner device. The shared key transmission unit 104 is an example of a shared key transmission means. The second encryption unit 105 encrypts data to be transmitted to the communication partner device with the shared key generated by the shared key generation unit 102. "Data A" in FIG. 6 is data transmitted from the outdoor unit 100A to the indoor unit 200AA. The data transmission unit 106 transmits the data encrypted by the second encryption unit 105 to the communication partner device.
[0069] The first decryption unit 107 decrypts the encrypted common key received from the communication partner device using the private key of the outdoor unit 100A. This common key was encrypted by the communication partner device using the public key of the outdoor unit 100A. The public key of the outdoor unit 100A is included in the server certificate that the outdoor unit 100A sends to the communication partner device. "Common key B" in FIG. 6 is the common key generated by the indoor unit 200AA, and is the common key used when transmitting data from the indoor unit 200AA to the outdoor unit 100A. "Private key A" in FIG. 6 is the private key of the outdoor unit 100A. The common key decrypted by the first decryption unit 107 is stored in the storage unit 12.
[0070] The second decryption unit 108 decrypts the encrypted data received from the other device using the common key stored in the storage unit 12. This data is data that the other device encrypted using the common key that the other device generated. "Data B" in FIG. 6 is data that the indoor unit 200AA transmits to the outdoor unit 100A. The data decrypted by the second decryption unit 108 is stored in the storage unit 12.
[0071] Here, the outdoor unit 100A may transfer data received from another communication device to the indoor unit 200AA, which is the other communication device. In this case, the second decryption unit 108 decrypts the data received from the other communication device using the common key C. The second encryption unit 105 encrypts this decrypted data using the common key A. The data transmission unit 106 transmits this encrypted data to the indoor unit 200AA. The other communication device is the outdoor unit 100B or the system controller 300. The common key C is a common key generated by the other communication device, and is used when transmitting data from the other communication device to the outdoor unit 100A.
[0072] The authentication unit 201 authenticates the device with which it communicates. For example, the authentication unit 201 obtains a server certificate from the outdoor unit 100A and authenticates the outdoor unit 100A by decrypting the digital signature included in the server certificate with the public key included in the root certificate stored in the storage unit 22. "Server certificate A" shown in Fig. 7 is the server certificate of the outdoor unit 100A. The authentication unit 201 is an example of authentication means.
[0073] The shared key generation unit 202 generates a shared key to be used for encrypted communication. The shared key generated by the shared key generation unit 202 is stored in the storage unit 22. The shared key generation unit 202 is an example of a shared key generation means. The first encryption unit 203 encrypts the shared key generated by the shared key generation unit 202 with the public key of the device with which the communication is to be performed. "Public key A" in FIG. 7 is the public key of the outdoor unit 100A. The first encryption unit 203 is an example of an encryption means.
[0074] After authentication unit 201 authenticates the other party's device, shared key transmission unit 204 transmits the shared key encrypted by first encryption unit 203 to the other party's device. Shared key transmission unit 204 is an example of a shared key transmission means. Second encryption unit 205 encrypts data to be transmitted to the other party's device with the shared key generated by shared key generation unit 202. Data transmission unit 206 transmits the data encrypted by second encryption unit 205 to the other party's device.
[0075] The first decryption unit 207 decrypts the encrypted common key received from the other device with the private key of the indoor unit 200AA. "Private key B" in FIG. 7 is the private key of the indoor unit 200AA. The common key decrypted by the first decryption unit 207 is stored in the storage unit 22. The second decryption unit 208 decrypts the encrypted data received from the other device with the common key stored in the storage unit 22. The data decrypted by the second decryption unit 208 is stored in the storage unit 22.
[0076] In this embodiment, the outdoor unit 100A, the outdoor unit 100B, the indoor unit 200AA, the indoor unit 200AB, the indoor unit 200BA, the indoor unit 200BB, and the system controller 300 have the function of performing encrypted communication. Furthermore, the outdoor unit 100A and the outdoor unit 100B also have the function of relaying communication between other devices by encrypted communication. Therefore, with regard to encrypted communication, the function of the outdoor unit 100B is basically the same as the function of the outdoor unit 100A. Furthermore, with regard to encrypted communication, the function of the indoor unit 200AB, the indoor unit 200BA, the indoor unit 200BB, and the system controller 300 is basically the same as the function of the indoor unit 200AA.
[0077] After a session is established between the devices, the devices encrypt frames using a common key and communicate with each other. The frames transmitted and received between the devices will be described below with reference to Fig. 8. As shown in Fig. 8, a frame includes an IP header, a TCP header, and application data.
[0078] The IP header is the header portion that stores information used by IP. Information used by IP includes the IP version, source address, destination address, etc. In Figure 8, "DA1" indicates the destination address and "SA1" indicates the source address. The TCP header is the header portion that stores information used by TCP.
[0079] Application data is data used in applications related to air conditioning control. In this embodiment, the scope of encryption is application data. Application data is an example of communication data. Application data includes information such as a source address, a destination address, and data. In FIG. 8, "DA2" indicates the destination address, "SA2" indicates the source address, and "data" indicates data related to air conditioning control. The source address and destination address included in the application data remain unchanged while the frame is being sent and received. On the other hand, the source address and destination address included in the IP header are rewritten as appropriate while the frame is being sent and received. Below, an example will be described in which a frame is sent from communication device A to communication device B.
[0080] When communication device A and communication device B belong to the same communication network, the source address and destination address included in the IP header are unchanged. For example, communication device A sets the address of communication device B in DA1 and DA2, and transmits a frame to communication device B in which the address of communication device A is set in SA1 and SA2. In this case, the frame received by communication device B also has the address of communication device B set in DA1 and DA2, and the address of communication device A set in SA1 and SA2.
[0081] On the other hand, if communication device A belongs only to communication network A and communication device B belongs to communication network B and communication network C, the source address and destination address included in the IP header are changed. For example, communication device A sets the address of relay device A in DA1, the address of communication device B in DA2, and transmits a frame in which the address of communication device A is set in SA1 and SA2 to relay device A. Relay device A is a device that relays communication between communication device A and communication device B, and belongs to communication network A and communication network C. Relay device A sets the address of communication device B in DA1, the address of relay device A in SA1, the address of communication device B in DA2, and transmits a frame in which the address of communication device A is set in SA2 to communication device B.
[0082] Furthermore, when communication device A belongs only to communication network A and communication device B belongs only to communication network B, the source address and destination address included in the IP header are changed. For example, communication device A sets the address of relay device A in DA1, sets the address of communication device B in DA2, and transmits a frame in which the address of communication device A is set in SA1 and SA2 to relay device A. Relay device A sets the address of relay device B in DA1, sets the address of relay device A in SA1, sets the address of communication device B in DA2, and transmits a frame in which the address of communication device A is set in SA2 to relay device B. Relay device B is a device that relays communication between communication device A and communication device B, and belongs to communication network B and communication network C. Relay device B sets the address of communication device B in DA1, sets the address of relay device B in SA1, sets the address of communication device B in DA2, and transmits a frame in which the address of communication device A is set in SA2 to communication device B.
[0083] Next, the frame transmission process executed by the outdoor unit 100, the indoor unit 200, and the system controller 300 will be described with reference to Fig. 9. The frame transmission process is started, for example, in response to the occurrence of a trigger to transmit a frame to another device after a session has been established between the devices. The following describes an example in which the outdoor unit 100A executes the frame transmission process.
[0084] First, the control unit 11 included in the outdoor unit 100A generates application data (step S101). For example, the control unit 11 generates application data in which a control command related to air conditioning control is set as the data, the address of the destination of the control command is set in DA2, and the address of the outdoor unit 100A is set in SA2. After completing the processing of step S101, the control unit 11 determines whether or not the device indicated by DA2 included in the application data belongs to the communication network to which the control unit 11 belongs (step S102). Note that if the control unit 11 belongs to multiple communication networks, it determines whether or not the device indicated by DA2 belongs to any of the multiple communication networks to which the control unit 11 belongs.
[0085] When the control unit 11 determines that the device indicated by DA2 belongs to the communication network to which the control unit 11 itself belongs (step S102: YES), the control unit 11 encrypts the frame using a common key shared between the control unit 11 itself and the device indicated by DA2 (step S103). Note that the encryption of the frame is the encryption of application data included in the frame. Upon completing the processing of step S103, the control unit 11 transmits the encrypted frame to the device indicated by DA2 (step S104). That is, the control unit 11 sets the address indicated by DA2 in DA1, sets its own address in SA1, and transmits the frame.
[0086] If the control unit 11 determines that the device indicated by DA2 does not belong to the communication network to which it belongs (step S102: NO), it identifies a relay device that relays communication between itself and the device indicated by DA2 (step S105). This relay device is a device that belongs to both the communication network to which it belongs and another communication network. After completing the process of step S105, the control unit 11 encrypts the frame using a common key shared between itself and the relay device (step S106).
[0087] When the process of step S106 is completed, control unit 11 transmits the encrypted frame to the relay device (step S107). That is, control unit 11 sets the address of the relay device in DA1, sets its own address in SA1, and transmits the frame. When the process of step S104 or step S107 is completed, control unit 11 completes the frame transmission process.
[0088] Next, the frame reception process executed by the outdoor unit 100, the indoor unit 200, and the system controller 300 will be described with reference to Fig. 10. The frame reception process is started, for example, in response to receiving a frame from another device after a session has been established between the devices. The following description will be given taking as an example a case where the outdoor unit 100A executes the frame reception process.
[0089] First, the control unit 11 decrypts the received frame (step S201). The control unit 11 decrypts the frame using a common key shared between the control unit 11 and the device that sent the frame. After completing the process of step S201, the control unit 11 determines whether DA2 included in the decrypted frame is its own address (step S202). If the control unit 11 determines that DA2 is its own address (step S202: YES), it executes processing according to the application data included in the frame (step S203). For example, if the application data includes a control command, the control unit 11 executes processing according to the control command.
[0090] If the control unit 11 determines that DA2 is not its own address (step S202: NO), it determines whether or not the device indicated by DA2 included in the decoded frame belongs to the communication network to which it belongs (step S204).
[0091] When the control unit 11 determines that the device indicated by DA2 belongs to the communication network to which the control unit 11 itself belongs (step S204: YES), the control unit 11 encrypts the frame using a common key shared between the control unit 11 itself and the device indicated by DA2 (step S205). After completing the process of step S205, the control unit 11 transmits the encrypted frame to the device indicated by DA2 (step S206). That is, the control unit 11 sets the address of the device indicated by DA2 in DA1, sets its own address in SA1, and transmits the frame.
[0092] If the control unit 11 determines that the device indicated by DA2 does not belong to the communication network to which it belongs (step S204: NO), it identifies a relay device that relays communication between itself and the device indicated by DA2 (step S207). This relay device belongs to both the communication network to which it belongs and the communication network to which the device indicated by DA2 belongs. After completing the process of step S207, the control unit 11 encrypts the frame using a common key shared between itself and the relay device (step S208).
[0093] When the process of step S208 is completed, control unit 11 transmits the encrypted frame to the relay device (step S209). That is, control unit 11 sets the address of the relay device in DA1, sets its own address in SA1, and transmits the frame. When the process of step S203, step S206, or step S209 is completed, control unit 11 completes the frame reception process.
[0094] Note that the outdoor unit 100B, indoor unit 200AA, indoor unit 200AB, indoor unit 200BA, indoor unit 200BB, and system controller 300 execute frame transmission processing and frame reception processing in the same way as the outdoor unit 100A. However, the indoor unit 200AA, indoor unit 200AB, indoor unit 200BA, indoor unit 200BB, and system controller 300 do not execute relay processing using encrypted communication. Therefore, in the frame reception processing executed by these devices, step S202 always returns YES, and the processing from step S204 to step S209 is not executed.
[0095] The following will specifically explain the processing executed by each device when the indoor unit 200AA transmits a frame to the indoor unit 200BA.
[0096] First, in step S101, the indoor unit 200AA generates application data to be sent to the indoor unit 200BA. In this application data, the address of the indoor unit 200BA is set in DA2, and the address of the indoor unit 200AA is set in SA2. In step S102, the indoor unit 200AA determines that the indoor unit 200BA indicated by DA2 does not belong to the communication network 710 to which the indoor unit 200AA belongs. In step S105, the indoor unit 200AA identifies the outdoor unit 100A that will relay communication between the indoor unit 200AA and the indoor unit 200BA.
[0097] In step S106, the indoor unit 200AA encrypts the frame using a common key shared between the indoor unit 200AA and the outdoor unit 100A. In step S107, the indoor unit 200AA transmits the encrypted frame to the outdoor unit 100A. In this frame, the address of the outdoor unit 100A is set in DA1, and the address of the indoor unit 200AA is set in SA1.
[0098] In step S201, the outdoor unit 100A decrypts the frame received from the indoor unit 200AA using a common key shared between the indoor unit 200AA and the outdoor unit 100A. In step S202, the outdoor unit 100A determines that DA2 included in the decrypted frame is not its own address. In step S204, the outdoor unit 100A determines that the indoor unit 200BA indicated by DA2 does not belong to either the communication network 710 or the communication network 730 to which the outdoor unit 100A belongs.
[0099] In step S207, the outdoor unit 100A identifies the outdoor unit 100B that will relay communication between the outdoor unit 100A and the indoor unit 200BA. In step S208, the outdoor unit 100A encrypts the frame using a common key shared between the outdoor unit 100A and the outdoor unit 100B. In step S209, the outdoor unit 100A transmits the encrypted frame to the outdoor unit 100B. In this frame, the address of the outdoor unit 100B is set in DA1, and the address of the outdoor unit 100A is set in SA1.
[0100] In step S201, outdoor unit 100B decrypts the frame received from outdoor unit 100A using the common key shared between outdoor unit 100A and outdoor unit 100B. In step S202, outdoor unit 100B determines that DA2 included in the decrypted frame is not its own address. In step S204, outdoor unit 100B determines that indoor unit 200BA indicated by DA2 belongs to the communication network 720 to which outdoor unit 100B belongs.
[0101] In step S205, the outdoor unit 100B encrypts the frame using a common key shared between the outdoor unit 100B and the indoor unit 200BA. In step S206, the outdoor unit 100B transmits the encrypted frame to the indoor unit 200BA. In this frame, the address of the indoor unit 200BA is set in DA1, and the address of the outdoor unit 100B is set in SA1.
[0102] In step S201, the indoor unit 200BA decrypts the frame received from the outdoor unit 100B using a common key shared between the outdoor unit 100B and the indoor unit 200BA. In step S202, the indoor unit 200BA determines that DA2 included in the decrypted frame is its own address. In step S203, the indoor unit 200BA executes processing according to the application data included in the decrypted frame.
[0103] In this embodiment, when a first communication device belonging to a first refrigerant system communicates with a second communication device belonging to a second refrigerant system, a first relay device belonging to the first refrigerant system and a second relay device belonging to the second refrigerant system communicate with each other using encrypted communication. That is, in this embodiment, encrypted communication is realized between the first air conditioning devices, between the second air conditioning devices, and between the first relay device and the second relay device. For this reason, in this embodiment, the number of sessions established within the air conditioning system 1000 is small. Therefore, according to this embodiment, safe communication can be achieved while suppressing an increase in the processing time required for communication preparation and an increase in memory usage.
[0104] Furthermore, in this embodiment, the first relay device relays communication between the first communication device and the second communication device when the first relay device is not the first communication device. Furthermore, the second relay device relays communication between the first communication device and the second communication device when the second relay device is not the second communication device. Furthermore, the first relay device relays communication between the first communication device and system controller 300 when the first relay device is not the first communication device. Furthermore, the second relay device relays communication between the second communication device and system controller 300 when the second relay device is not the second communication device. Therefore, according to the embodiment, appropriate relaying using encrypted communication by the first relay device and the second relay device can be realized.
[0105] Furthermore, in this embodiment, multiple first air conditioning apparatuses belong to a first communication network, multiple second air conditioning apparatuses belong to a second communication network, and the first relay apparatus and second relay apparatus belong to a third communication network. In other words, in this embodiment, it is easy to separate communications between apparatuses belonging to the same refrigerant system from communications between apparatuses belonging to different refrigerant systems. Therefore, according to this embodiment, it is easy to identify apparatuses belonging to the same refrigerant system.
[0106] Furthermore, in this embodiment, a common key is shared after authenticating the device with which the communication is being made. Therefore, according to this embodiment, it is possible to prevent inappropriate devices from being connected to the air conditioning system 1000.
[0107] (Embodiment 2) In the first embodiment, an example in which a common key is prepared for each communication direction was described. In the present embodiment, an example in which a common key is shared between both communication directions will be described. Hereinafter, the description of the same configurations and functions as those in the first embodiment will be omitted or simplified as appropriate.
[0108] The configuration of the air conditioning system according to this embodiment is basically the same as the configuration of air conditioning system 1000 according to embodiment 1. That is, the air conditioning system according to this embodiment includes two outdoor units, four indoor units, and a system controller, and two refrigerant systems each including one outdoor unit and two indoor units. In this embodiment, one refrigerant system includes outdoor unit 120A and indoor unit 220AA.
[0109] The functions of the outdoor unit 120A and the indoor unit 220AA will be described below with reference to Fig. 11, taking as an example a case where the outdoor unit 120A and the indoor unit 220AA communicate with each other. In this embodiment, the outdoor unit 120A is the third communication device, and the indoor unit 220AA is the fourth communication device. The communication partner of the outdoor unit 120A is the indoor unit 220AA, and the communication partner of the indoor unit 220AA is the outdoor unit 120A.
[0110] The outdoor unit 120A functionally comprises an authentication unit 101, a common key generation unit 102, a first encryption unit 103, a common key transmission unit 104, a second encryption unit 105, a data transmission unit 106, and a second decryption unit 108. The indoor unit 220AA functionally comprises an authentication unit 201, a second encryption unit 205, a data transmission unit 206, a first decryption unit 207, and a second decryption unit 208. The functions of the outdoor unit 120A are similar to those of the outdoor unit 100A, except that the outdoor unit 120A does not comprise the first decryption unit 107. The functions of the indoor unit 220AA are similar to those of the indoor unit 120AA, except that the indoor unit 220AA does not comprise the common key generation unit 202, the first encryption unit 203, and the common key transmission unit 204.
[0111] The authentication unit 101 authenticates the other device. The shared key generation unit 102 generates a shared key to be used for encrypted communication. The shared key generated by the shared key generation unit 102 is stored in the storage unit 12. The first encryption unit 103 encrypts the shared key generated by the shared key generation unit 102 with the public key of the other device. After the authentication unit 101 authenticates the other device, the shared key transmission unit 104 transmits the shared key encrypted by the first encryption unit 103 to the other device.
[0112] The second encryption unit 105 encrypts data to be transmitted to the communication partner device using the common key generated by the common key generation unit 102. The data transmission unit 106 transmits the data encrypted by the second encryption unit 105 to the communication partner device. The second decryption unit 108 decrypts the encrypted data received from the communication partner device using the common key stored in the storage unit 12. Note that the outdoor unit 120A may transfer data received from another communication device to the communication partner indoor unit 220AA.
[0113] The authentication unit 201 authenticates the other party's device. The second encryption unit 205 encrypts data to be transmitted to the other party's device using the common key decrypted by the first decryption unit 207. The data transmission unit 206 transmits the data encrypted by the second encryption unit 205 to the other party's device. The first decryption unit 207 decrypts the encrypted common key received from the other party's device using the private key of the indoor unit 220AA. The common key decrypted by the first decryption unit 207 is stored in the storage unit 22. The second decryption unit 208 decrypts the encrypted data received from the other party's device using the common key stored in the storage unit 22. The data decrypted by the second decryption unit 208 is stored in the storage unit 22.
[0114] As described above, in the present embodiment, the outdoor unit 120A generates a common key to be shared in two-way encrypted communication, and the indoor unit 220AA does not generate a common key. That is, in the present embodiment, one of the two devices that establish a session generates a common key to be shared in two-way encrypted communication. The number of common keys generated in the present embodiment is half the number of common keys generated in the first embodiment. Therefore, in the present embodiment, the processing time for generating common keys is short, and the memory usage for storing the common keys is small. In other words, according to the present embodiment, it is possible to further suppress the increase in processing time and memory usage required for preparing for communication.
[0115] (Embodiment 3) In the first embodiment, an example was described in which a communication partner is authenticated using a public key cryptosystem when a TLS session is established. In the present embodiment, an example is described in which a communication partner is authenticated using a pre-shared key system when a TLS session is established. Hereinafter, descriptions of configurations and functions similar to those in the first and second embodiments will be omitted or simplified as appropriate.
[0116] The configuration of the air conditioning system according to this embodiment is basically the same as the configuration of the air conditioning system 1000 according to embodiment 1. That is, the air conditioning system according to this embodiment includes two outdoor units, four indoor units, and a system controller, and two refrigerant systems each including one outdoor unit and two indoor units. In this embodiment, one refrigerant system includes an outdoor unit 130A and an indoor unit 230AA.
[0117] The functions of the outdoor unit 130A and the indoor unit 230AA will be described below with reference to Fig. 12, taking as an example a case where the outdoor unit 130A and the indoor unit 230AA communicate with each other. In this embodiment, the outdoor unit 130A is the third communication device, and the indoor unit 230AA is the fourth communication device. The communication partner of the outdoor unit 130A is the indoor unit 230AA, and the communication partner of the indoor unit 230AA is the outdoor unit 130A.
[0118] The outdoor unit 130A functionally comprises a common key generation unit 102, a first encryption unit 103, a common key transmission unit 104, a second encryption unit 105, a data transmission unit 106, a second decryption unit 108, and an encryption key generation unit 109. The indoor unit 230AA functionally comprises a second encryption unit 205, a data transmission unit 206, a first decryption unit 207, a second decryption unit 208, and an encryption key generation unit 209. The functions of the outdoor unit 130A are similar to those of the outdoor unit 100A, except that the outdoor unit 130A does not comprise the authentication unit 101 and the first decryption unit 107, but instead comprises the encryption key generation unit 109. The functions of the indoor unit 230AA are the same as those of the indoor unit 230AA, except that it does not have the authentication unit 201, the common key generation unit 202, the first encryption unit 203, and the common key transmission unit 204, but has an encryption key generation unit 209.
[0119] The shared key generation unit 102 generates a shared key to be used for encrypted communication. The shared key generated by the shared key generation unit 102 is stored in the storage unit 12. In this embodiment, authentication of the communication partner using the public key cryptosystem is not performed, and therefore the storage unit 12 does not store the server certificate of the outdoor unit 130A, the root certificate, the public key of the outdoor unit 130A, the private key of the outdoor unit 130A, etc. On the other hand, in this embodiment, authentication of the communication partner using the pre-shared key system is performed, and therefore the storage unit 12 stores an encryption key for the pre-shared key system. The storage unit 12 is an example of a storage means.
[0120] The first encryption unit 103 encrypts the common key generated by the common key generation unit 102 with the encryption key stored in the storage unit 12. The common key transmission unit 104 transmits the common key encrypted by the first encryption unit 103 to the communication partner device. The second encryption unit 105 encrypts data to be transmitted to the communication partner device with the common key generated by the common key generation unit 102.
[0121] The data transmission unit 106 transmits the data encrypted by the second encryption unit 105 to the communication partner device. The second decryption unit 108 decrypts the encrypted data received from the communication partner device using the common key stored in the storage unit 12. Note that the outdoor unit 130A may transfer data received from another communication device to the communication partner indoor unit 230AA.
[0122] The encryption key generation unit 109 generates an encryption key in the pre-shared key system from shared information that is set when the outdoor unit 130A is manufactured or shipped. This shared information is information that is shared between the outdoor unit 130A and the indoor unit 230AA. This shared information is stored in the storage unit 12 when the outdoor unit 130A is manufactured or shipped. This shared information is also stored in the storage unit 22 when the indoor unit 230AA is manufactured. The shared information is, for example, manufacturer identification information that indicates the manufacturer that manufactured the outdoor unit 130A and the indoor unit 230AA.
[0123] Generally, the outdoor unit and indoor unit of an air conditioning system are manufactured by the same manufacturer. Therefore, when the shared information is manufacturer identification information, the shared information stored in storage unit 12 is the same as the shared information stored in storage unit 22. The encryption key generation unit 109 generates an encryption key from the shared information in accordance with a key generation algorithm, which is an algorithm for generating an encryption key in the pre-shared key system. This key generation algorithm generates the same encryption key from the same shared information, and generates different encryption keys from different shared information.
[0124] Furthermore, the encryption key generation unit 209, which will be described later, also generates an encryption key from the shared information in accordance with this key generation algorithm. Therefore, when the shared information stored in the storage unit 12 is the same as the shared information stored in the storage unit 22, the encryption key generated by the encryption key generation unit 109 is the same as the encryption key generated by the encryption key generation unit 209. On the other hand, when the shared information stored in the storage unit 12 is different from the shared information stored in the storage unit 22, the encryption key generated by the encryption key generation unit 109 is different from the encryption key generated by the encryption key generation unit 209. The encryption key generated by the encryption key generation unit 109 is stored in the storage unit 12. The encryption key generation unit 109 is an example of an encryption key generation means.
[0125] In second encryption unit 205, first decryption unit 207 decrypts data to be transmitted to the communication partner device, and encrypts the data with the common key stored in storage unit 22. Data transmission unit 206 transmits the data encrypted by second encryption unit 205 to the communication partner device.
[0126] In this embodiment, authentication of the communication partner using the public key cryptosystem is not performed, and therefore the server certificate of the indoor unit 230AA, the root certificate, the public key of the indoor unit 230AA, the private key of the indoor unit 230AA, etc. are not stored in the storage unit 22. On the other hand, in this embodiment, authentication of the communication partner using the pre-shared key system is performed, and therefore an encryption key in the pre-shared key system is stored in the storage unit 22. The storage unit 22 is an example of storage means.
[0127] The first decryption unit 207 decrypts the encrypted common key received from the other party's device using the encryption key in the pre-shared key system stored in the storage unit 22. The common key decrypted by the first decryption unit 207 is stored in the storage unit 22. The second decryption unit 208 decrypts the encrypted data received from the other party's device using the common key stored in the storage unit 22. The data decrypted by the second decryption unit 208 is stored in the storage unit 22.
[0128] The encryption key generation unit 209 generates an encryption key in the pre-shared key system from shared information that is set when the indoor unit 230AA is manufactured. This shared information is stored in the storage unit 22 when the indoor unit 230AA is manufactured or shipped. The encryption key generation unit 209 generates an encryption key from the shared information in accordance with the key generation algorithm described above. The encryption key generated by the encryption key generation unit 209 is stored in the storage unit 22. The encryption key generation unit 209 is an example of encryption key generation means.
[0129] The other outdoor units, other indoor units, and system controller according to this embodiment have the function of generating an encryption key from shared information in accordance with the above-mentioned key generation algorithm, similar to outdoor unit 130A and indoor unit 230AA. In other words, the devices according to this embodiment share an encryption key in the pre-shared key system by generating the same encryption key from the same shared information.
[0130] In this embodiment, when a TLS session is established, the communication partner is authenticated using a pre-shared key method. That is, in this embodiment, mutual authentication is achieved by sharing an encryption key in the pre-shared key method. Therefore, in this embodiment, authentication of the communication partner using a public key encryption method is not required, and an increase in the processing time required to prepare for communication can be further suppressed.
[0131] In this embodiment, two devices establishing a session generate an encryption key in the pre-shared key system from shared information set at the time of manufacture or shipment. In this embodiment, the shared information set at the time of manufacture or shipment is manufacturer identification information, and the same encryption key is shared by devices manufactured by the same manufacturer. Therefore, this embodiment makes it easy to share an encryption key when building an air conditioning system using devices manufactured by the same manufacturer.
[0132] (Fourth embodiment) In the third embodiment, an example was described in which an encryption key in the pre-shared key system is generated based on shared information set at the time of manufacture or shipment. In the present embodiment, an example is described in which an encryption key in the pre-shared key system is generated based on shared information set at the time of system construction. Hereinafter, descriptions of configurations and functions similar to those in the first to third embodiments will be omitted or simplified as appropriate.
[0133] Figure 13 is a diagram showing the configuration of an air conditioning system 1400 pertaining to Embodiment 4. The air conditioning system 1400 includes an outdoor unit 140A, an outdoor unit 140B, an indoor unit 240AA, an indoor unit 240AB, an indoor unit 240BA, an indoor unit 240BB, and a system controller 340. Hereinafter, where appropriate, the outdoor unit 140A and the outdoor unit 140B will be collectively referred to as the outdoor unit 140, and the indoor unit 240AA, the indoor unit 240AB, the indoor unit 240BA, and the indoor unit 240BB will be collectively referred to as the indoor unit 240.
[0134] Air conditioning system 1400 includes refrigerant systems 440A and 440B as refrigerant systems. Hereinafter, refrigerant systems 440A and 440B will be collectively referred to as refrigerant system 440 as appropriate. Refrigerant system 440A includes an outdoor unit 140A, an indoor unit 240AA, an indoor unit 240AB, and refrigerant piping 61A. Refrigerant system 440B includes an outdoor unit 140B, an indoor unit 240BA, an indoor unit 240BB, and refrigerant piping 61B.
[0135] The outdoor unit 140 includes a control unit 11, a memory unit 12, an operation reception unit 14, an internal / external communication unit 15, a centralized communication unit 16, a position detection sensor 17, and a time detection sensor 18. The indoor unit 240 includes a control unit 21, a memory unit 22, an operation reception unit 24, an internal / external communication unit 25, a position detection sensor 27, and a time detection sensor 28. The system controller 340 includes a control unit 31, a memory unit 32, a display unit 33, an operation reception unit 34, a centralized communication unit 36, a position detection sensor 37, and a time detection sensor 38.
[0136] The outdoor unit 140 has the same configuration as the outdoor unit 100, except that it is equipped with an operation reception unit 14, a position detection sensor 17, and a time detection sensor 18. The indoor unit 240 has the same configuration as the indoor unit 200, except that it is equipped with an operation reception unit 24, a position detection sensor 27, and a time detection sensor 28. The system controller 340 has the same configuration as the system controller 300, except that it is equipped with a position detection sensor 37 and a time detection sensor 38.
[0137] The operation reception unit 14 receives various operations from the user and supplies information indicating the content of the received operations to the control unit 11. For example, the operation reception unit 14 receives from the user setting information that is set to generate an encryption key in a pre-shared key system when the air conditioning system 1400 is constructed. The operation reception unit 14 includes a touch screen, buttons, levers, etc. The position detection sensor 17 detects the position where the outdoor unit 140 is installed. The position detection sensor 17 includes, for example, a GPS (Global Positioning System) receiver. The time detection sensor 18 detects the current time. The time detection sensor 18 includes, for example, a radio clock, a GPS receiver, etc.
[0138] The operation reception unit 24 receives various operations from the user and supplies information indicating the content of the received operations to the control unit 21. For example, the operation reception unit 24 receives the above-mentioned setting information from the user when the air conditioning system 1400 is constructed. The operation reception unit 24 includes a touch screen, buttons, levers, etc. The position detection sensor 27 detects the position where the indoor unit 240 is installed. The position detection sensor 27 includes, for example, a GPS receiver. The time detection sensor 28 detects the current time. The time detection sensor 28 includes, for example, a radio clock, a GPS receiver, etc.
[0139] The operation reception unit 34 receives the above setting information from the user when constructing the air conditioning system 1400. The position detection sensor 37 detects the position where the system controller 340 is installed. The position detection sensor 37 includes, for example, a GPS receiver. The time detection sensor 38 detects the current time. The time detection sensor 38 includes, for example, a radio clock, a GPS receiver, etc.
[0140] The functions of the outdoor unit 140A and the indoor unit 240AA will be described below with reference to Fig. 14, taking as an example a case where the outdoor unit 140A and the indoor unit 240AA communicate with each other. In this embodiment, the outdoor unit 140A is the third communication device, and the indoor unit 240AA is the fourth communication device. The communication partner of the outdoor unit 140A is the indoor unit 240AA, and the communication partner of the indoor unit 240AA is the outdoor unit 140A.
[0141] The outdoor unit 140A functionally comprises a common key generation unit 102, a first encryption unit 103, a common key transmission unit 104, a second encryption unit 105, a data transmission unit 106, a second decryption unit 108, an encryption key generation unit 109, a setting information acquisition unit 110, a position information acquisition unit 111, and a time information acquisition unit 112. The indoor unit 240AA functionally comprises a second encryption unit 205, a data transmission unit 206, a first decryption unit 207, a second decryption unit 208, an encryption key generation unit 209, a setting information acquisition unit 210, a position information acquisition unit 211, and a time information acquisition unit 212. The functions of the outdoor unit 140A are similar to those of the outdoor unit 130A, except that the outdoor unit 140A comprises the setting information acquisition unit 110, the position information acquisition unit 111, and the time information acquisition unit 112. The indoor unit 240AA has the same functions as the indoor unit 230AA, except that it is provided with a setting information acquisition section 210, a position information acquisition section 211, and a time information acquisition section 212.
[0142] The setting information acquisition unit 110 acquires setting information from the user via the operation acceptance unit 14. The setting information acquisition unit 210 acquires this setting information from the user via the operation acceptance unit 24. This setting information is information set by the user in order to generate an encryption key in the pre-shared key system when the air conditioning system 1400 is constructed. Here, the user sets the same setting information in each device included in the air conditioning system 1400 when the air conditioning system 1400 is constructed. Therefore, the setting information acquired by the setting information acquisition unit 110 and the setting information acquired by the setting information acquisition unit 210 are basically the same information. The setting information acquisition unit 110 and the setting information acquisition unit 210 are examples of setting information acquisition means.
[0143] The position information acquisition unit 111 acquires information indicating the position where the outdoor unit 140A is installed from the position detection sensor 17 as position information indicating the position where the air conditioning system 1400 is constructed. The position information acquisition unit 211 acquires information indicating the position where the indoor unit 240AA is installed from the position detection sensor 27 as position information indicating the position where the air conditioning system 1400 is constructed.
[0144] The location information is information that roughly indicates the location where the air conditioning system 1400 is constructed, for example, by city, town, village, address, etc. Here, the location where the outdoor unit 140A is installed and the location where the indoor unit 240AA is installed are generally not that far apart. For this reason, the location information acquired by the location information acquisition unit 111 and the location information acquired by the location information acquisition unit 211 are basically the same. The location information acquisition unit 111 and the location information acquisition unit 211 are examples of location information acquisition means.
[0145] The time information acquisition unit 112 acquires information indicating the time when power was applied to the outdoor unit 140A from the time detection sensor 18, as time information indicating the time when the air conditioning system 1400 was constructed. The time information acquisition unit 212 acquires information indicating the time when power was applied to the indoor unit 240AA from the time detection sensor 28, as time information indicating the time when the air conditioning system 1400 was constructed.
[0146] The time information is information that roughly indicates, for example, the time when the air conditioning system 1400 was constructed, by month, week, day, etc. Here, there is generally not much difference between the time when the outdoor unit 140A is powered on and the time when the indoor unit 240AA is powered on. For this reason, the time information acquired by the time information acquisition unit 112 and the time information acquired by the time information acquisition unit 212 are basically the same. The time information acquisition unit 112 and the time information acquisition unit 212 are examples of time information acquisition means.
[0147] The encryption key generation unit 109 and the encryption key generation unit 209 generate an encryption key in the pre-shared key system from shared information acquired when the air conditioning system 1400 is constructed. Specifically, the encryption key generation unit 109 generates an encryption key from shared information including at least one of the setting information acquired by the setting information acquisition unit 110, the location information acquired by the location information acquisition unit 111, and the time information acquired by the time information acquisition unit 112. Furthermore, the encryption key generation unit 209 generates an encryption key from shared information including at least one of the setting information acquired by the setting information acquisition unit 210, the location information acquired by the location information acquisition unit 211, and the time information acquired by the time information acquisition unit 212.
[0148] Here, the setting information, location information, and time information acquired by the outdoor unit 140A are basically the same as the setting information, location information, and time information acquired by the indoor unit 240AA, respectively. In other words, the shared information acquired by the outdoor unit 140A is the same as the shared information acquired by the indoor unit 240AA. Furthermore, the encryption key generation unit 109 and the encryption key generation unit 209 generate an encryption key from the shared information according to the same key generation algorithm. Therefore, the encryption key generated by the encryption key generation unit 109 and the encryption key generated by the encryption key generation unit 209 are the same. Therefore, the same encryption key is shared between the outdoor unit 140A and the indoor unit 240AA.
[0149] When an encryption key is generated from shared information including configuration information, the encryption key is shared between devices that have the same configuration information configured. When an encryption key is generated from shared information including location information, the encryption key is shared between devices that are installed in the same location. When an encryption key is generated from shared information including time information, the encryption key is shared between devices that were powered on at the same time. When an encryption key is generated from shared information including configuration information and location information, the encryption key is shared between devices that have the same configuration information configured and are installed in the same location.
[0150] When an encryption key is generated from shared information including setting information and time information, the encryption key is shared among devices that have the same setting information set and that have been powered on at the same time.When an encryption key is generated from shared information including location information and time information, the encryption key is shared among devices that have the same setting information set, that have been powered on at the same time.When an encryption key is generated from shared information including setting information, location information, and time information, the encryption key is shared among devices that have the same setting information set, that have been powered on at the same time, that have been powered on at the same time.
[0151] The storage unit 12 stores the encryption key generated by the encryption key generation unit 109. The storage unit 22 stores the encryption key generated by the encryption key generation unit 209. The first encryption unit 103 encrypts the common key generated by the common key generation unit 102 with the encryption key stored in the storage unit 12. The common key transmission unit 104 transmits the common key encrypted by the first encryption unit 103 to the other device. The first decryption unit 207 decrypts the encrypted common key received from the other device with the encryption key in the pre-shared key system stored in the storage unit 22. The common key decrypted by the first decryption unit 207 is stored in the storage unit 22.
[0152] The other outdoor units, other indoor units, and system controller according to this embodiment have the function of generating an encryption key from shared information in accordance with the above-mentioned key generation algorithm, just like outdoor unit 140A and indoor unit 240AA. In other words, the devices according to this embodiment share an encryption key in the pre-shared key system by generating the same encryption key from the same shared information.
[0153] In this embodiment, when a TLS session is established, the communication partner is authenticated using a pre-shared key method. Therefore, in this embodiment, authentication of the communication partner using a public key cryptosystem is not required, and an increase in the processing time required for communication preparation can be further suppressed.
[0154] In this embodiment, two devices establishing a session generate an encryption key in the pre-shared key system from shared information set during system configuration. In this embodiment, the shared information set during system configuration includes at least one of configuration information, location information, and time information. Therefore, the same encryption key is shared by devices with the same configuration information, power-on time, installation location, or a combination of these. Therefore, this embodiment makes it possible to share an encryption key even when an air conditioning system is constructed using devices manufactured by different manufacturers. Note that in this embodiment, the same encryption key is not shared between devices that do not match at least in any of the configuration information, power-on time, and installation location. Therefore, this embodiment reduces the risk of encryption key leakage.
[0155] (Embodiment 5) In the first embodiment, an example was described in which air conditioning control is executed immediately after the sharing of a common key used for encrypted communication is completed. In the present embodiment, an example is described in which air conditioning control is executed after the sharing of a common key used for encrypted communication is completed and the user checks the devices connected to the air conditioning system. Hereinafter, the description of the same configurations and functions as those in the first to fourth embodiments will be omitted or simplified as appropriate.
[0156] The configuration of the air conditioning system according to this embodiment is basically the same as the configuration of the air conditioning system 1000 according to embodiment 1. In this embodiment, when a session is established between devices, the system controller 300 acquires device information from each device indicating the device name, device serial number, device model name, device type, refrigerant system to which the device belongs, etc. When session establishment is complete for all device combinations that perform encrypted communication, the system controller 300 displays a screen that presents all of the acquired device information to the user.
[0157] For example, the display unit 33 included in the system controller 300 displays a device confirmation screen shown in Fig. 15. This device confirmation screen is a screen that presents device information, including the device name, device type, and refrigerant system, for all devices connected to the air conditioning system 1000. This device confirmation screen is a screen that queries the user as to whether the devices connected to the air conditioning system 1000 are appropriate.
[0158] In this way, when the sharing of a common key is completed for all encrypted communications between a plurality of first air conditioning apparatuses and a plurality of second air conditioning apparatuses, the display unit 33 displays device information for each of all of the apparatuses performing encrypted communications. The display unit 33 is an example of a display means.
[0159] The user checks the device information displayed on the device confirmation screen and determines whether the device connected to the air conditioning system 1000 is an appropriate device. If the user determines that the device connected to the air conditioning system 1000 is an appropriate device, the user instructs the operation reception unit 34 provided in the system controller 300 to start air conditioning control. In other words, the operation reception unit 34 receives an instruction to start air conditioning control from the user after the display unit 33 displays the device information. If the user determines that the device connected to the air conditioning system 1000 is not an appropriate device, the user notifies the operation reception unit 34 that there is an abnormality. The operation reception unit 34 is an example of a start instruction reception means.
[0160] The system controller 300 starts air conditioning control after receiving an instruction to start air conditioning control from a user. The system controller 300 may perform air conditioning control automatically in accordance with predetermined settings, or may perform air conditioning control in accordance with user operations.
[0161] In this embodiment, air conditioning control is performed after device authentication by each device and device authentication by the user. That is, in this embodiment, device authentication is performed in two stages: device authentication by each device and device authentication by the user. Therefore, in this embodiment, the risk of inappropriate devices being connected to the air conditioning system 1000 can be reduced.
[0162] (Embodiment 6) In the first embodiment, an example was described in which the devices communicate with each other through internal / external communication or centralized communication. In the present embodiment, an example is described in which the devices communicate with each other through integrated communication in which the internal / external communication and the centralized communication are integrated. Hereinafter, the description of the same configurations and functions as those in the first to fifth embodiments will be omitted or simplified as appropriate.
[0163] 16 shows the network configuration of an air conditioning system 1600 according to the present embodiment. In the present embodiment, a communication network 740 is formed by outdoor unit 160A, outdoor unit 160B, indoor unit 260AA, indoor unit 260AB, indoor unit 260BA, indoor unit 260BB, system controller 360, communication line 74A, communication line 74B, communication line 74C, communication line 74D, communication line 74E, and communication line 74F.
[0164] Hereinafter, outdoor unit 160A and outdoor unit 160B will be collectively referred to as outdoor unit 160, and indoor unit 260AA, indoor unit 260AB, indoor unit 260BA, and indoor unit 260BB will be collectively referred to as indoor unit 260. Furthermore, communication line 74A, communication line 74B, communication line 74C, communication line 74D, communication line 74E, and communication line 74F will be collectively referred to as communication line 74. Communication line 74 is, for example, an Ethernet (registered trademark) cable.
[0165] The refrigerant system to which the outdoor unit 160A, the indoor unit 260AA, and the indoor unit 260AB belong is different from the refrigerant system to which the outdoor unit 160B, the indoor unit 260BA, and the indoor unit 260BB belong. However, in this embodiment, one communication network 740 is configured by all devices, regardless of the refrigerant system 400. The communication network 740 is a communication network in which all devices are interconnected. The communication network 740 is a LAN capable of IP communication.
[0166] The communication line 74A is a communication line that connects the outdoor unit 160A and the indoor unit 260AA. The communication line 74B is a communication line that connects the indoor unit 260AA and the indoor unit 260AB. The communication line 74C is a communication line that connects the outdoor unit 160B and the indoor unit 260BA. The communication line 74D is a communication line that connects the indoor unit 260BA and the indoor unit 260BB. The communication line 74E is a communication line that connects the outdoor unit 160A and the system controller 360. The communication line 74F is a communication line that connects the outdoor unit 160B and the system controller 360.
[0167] In this embodiment, as in the first embodiment, encrypted communication is carried out within each refrigerant system, and encrypted communication across refrigerant systems is carried out by relay devices belonging to each refrigerant system. In other words, multiple first air conditioning apparatuses belonging to a first refrigerant system communicate with each other using encrypted communication. The outdoor unit 160A, the indoor unit 260AA, and the indoor unit 260AB are an example of a first air conditioning apparatus. The refrigerant system to which the outdoor unit 160A, the indoor unit 260AA, and the indoor unit 260AB belong is an example of a first refrigerant system. Furthermore, multiple second air conditioning apparatuses belonging to a second refrigerant system communicate with each other using encrypted communication. The outdoor unit 160B, the indoor unit 260BA, and the indoor unit 260BB are an example of a second air conditioning apparatus. The refrigerant system to which the outdoor unit 160B, the indoor unit 260BA, and the indoor unit 260BB belong is an example of a second refrigerant system.
[0168] When a first communication device and a second communication device communicate, the first relay device and the second relay device communicate with each other using encrypted communication. The first communication device is any one of the multiple first air conditioning devices. The second communication device is any one of the multiple second air conditioning devices. The first relay device is any one of the multiple first air conditioning devices. The second relay device is any one of the multiple second air conditioning devices. Outdoor unit 160A is an example of a first relay device. Outdoor unit 160B is an example of a second relay device.
[0169] The first relay device relays communication between the first communication device and the second communication device when the first relay device is not the first communication device. The second relay device relays communication between the first communication device and the second communication device when the second relay device is not the second communication device. The first relay device relays communication between the first communication device and the system controller 360 when the first relay device is not the first communication device. The second relay device relays communication between the second communication device and the system controller 360 when the second relay device is not the second communication device.
[0170] In this embodiment, when a first communication device belonging to a first refrigerant system communicates with a second communication device belonging to a second refrigerant system, the first relay device belonging to the first refrigerant system and the second relay device belonging to the second refrigerant system communicate with each other using encrypted communication. Therefore, according to this embodiment, it is possible to communicate safely while suppressing an increase in the processing time and memory usage required for communication preparation.
[0171] (Variation) Although the embodiments of the present disclosure have been described above, various modifications and applications are possible when implementing the present disclosure. It is optional which parts of the configurations, functions, and operations described in the above embodiments are adopted in the present disclosure. Furthermore, in addition to the above-described configurations, functions, and operations, further configurations, functions, and operations may also be adopted in the present disclosure. Furthermore, the configurations, functions, and operations described in the above-described embodiments can be freely combined.
[0172] In the first embodiment, an example has been described in which the air conditioning system 1000 is equipped with two refrigerant systems 400. The air conditioning system 1000 may be equipped with three or more refrigerant systems 400. In the first embodiment, an example has been described in which the refrigerant system 400 is equipped with one outdoor unit 100 and two indoor units 200. The refrigerant system 400 may be equipped with two or more outdoor units 100 and one or three or more indoor units 200. In the first embodiment, an example has been described in which the air conditioning system 1000 is equipped with a system controller 300. The air conditioning system 1000 does not have to be equipped with a system controller 300.
[0173] In the first embodiment, an example has been described in which devices included in each communication network are connected to each other by wire. Devices included in each communication network may also be connected to each other by wire. In the first embodiment, an example has been described in which the outdoor unit 100 included in each refrigerant system 400 functions as a relay device that relays encrypted communication. The indoor unit 200 included in each refrigerant system 400 may also function as a relay device that relays encrypted communication.
[0174] In the third embodiment, an example has been described in which an encryption key is generated from shared information that is set when the device is manufactured or shipped. An encryption key may be set by a user when the device is manufactured or shipped. In this case, the device does not need to generate an encryption key. Note that the user can set an encryption key corresponding to the manufacturer of the device in the device by operating, for example, the operation reception unit 14, the operation reception unit 24, the operation reception unit 34, etc.
[0175] In the fourth embodiment, an example has been described in which an encryption key is generated from shared information set when the system is constructed. An encryption key may be set by a user when the system is constructed. In this case, the device does not need to generate an encryption key. The user can set a common encryption key for each device by operating the operation reception unit 14, operation reception unit 24, operation reception unit 34, etc.
[0176] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope of the present disclosure. Furthermore, the above-described embodiments are intended to illustrate the present disclosure and do not limit the scope of the present disclosure. That is, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and the meaning of equivalent disclosures are considered to be within the scope of the present disclosure. [Industrial Applicability]
[0177] The present disclosure is applicable to air conditioning systems equipped with outdoor units and indoor units. [Explanation of symbols]
[0178] 11, 21, 31 control unit, 12, 22, 32 memory unit, 33 display unit, 14, 24, 34 operation reception unit, 15, 25 internal / external communication unit, 16, 36 centralized communication unit, 17, 27, 37 position detection sensor, 18, 28, 38 time detection sensor, 61, 61A, 61B refrigerant piping, 71, 71A, 71B, 72, 72A, 72B, 73, 73A, 73B, 74, 74A, 74B, 74C, 74D, 74E, 74F communication line, 100, 100A, 100B, 120A, 130A, 140A, 140B, 160, 160A, 160B outdoor unit, 101, 201 authentication unit, 102, 202 Common key generation unit, 103, 203 First encryption unit, 104, 204 Common key transmission unit, 105, 205 Second encryption unit, 106, 206 Data transmission unit, 107, 207 First decryption unit, 108, 208 Second decryption unit, 109, 209 Encryption key generation unit, 110, 210 Setting information acquisition unit, 111, 211 Location information acquisition unit, 112, 212 Timing information acquisition unit, 200, 200AA, 200AB, 200BA, 200BB, 220AA, 230AA, 240AA, 240AB, 240BA, 240BB, 260, 260AA, 260AB, 260BA, 260BB Indoor unit, 300, 340, 360 System controller, 400, 400A, 400B, 440, 440A, 440B Refrigerant system, 710, 720, 730, 740 Communication network, 1000, 1400, 1600 Air conditioning system
Claims
1. An air conditioning system comprising a plurality of first air conditioning devices belonging to a first refrigerant system and a plurality of second air conditioning devices belonging to a second refrigerant system, the plurality of first air conditioning devices and the plurality of second air conditioning devices being communicatively connected, the plurality of first air conditioning apparatuses communicate with each other using encrypted communication in which communication data is encrypted using a common key; the plurality of second air conditioning devices communicate with each other using the encrypted communication, When a first communication device among the plurality of first air conditioning devices communicates with a second communication device among the plurality of second air conditioning devices, a first relay device among the plurality of first air conditioning devices and a second relay device among the plurality of second air conditioning devices communicate with each other using the encrypted communication. Air conditioning system.
2. when the first relay device is not the first communication device, the first relay device communicates with the second relay device by the encrypted communication using a first common key shared by the first relay device and the second relay device, and communicates with the first communication device by the encrypted communication using a second common key shared by the first relay device and the first communication device, thereby relaying the communication between the first communication device and the second communication device; When the second relay device is not the second communication device, the second relay device communicates with the first relay device through the encrypted communication using the first common key, and communicates with the second communication device through the encrypted communication using a third common key shared by the second relay device and the second communication device, thereby relaying the communication between the first communication device and the second communication device. The air conditioning system of claim 1 .
3. a system controller that controls the plurality of first air conditioning devices and the plurality of second air conditioning devices; When the first communication device and the system controller communicate with each other, the first relay device and the system controller communicate with each other using the encrypted communication; When the second communication device and the system controller communicate with each other, the second relay device and the system controller communicate with each other using the encrypted communication.
3. The air conditioning system according to claim 1 or 2.
4. when the first relay device is not the first communication device, the first relay device communicates with the first communication device by the encrypted communication using a second common key shared by the first relay device and the first communication device, and communicates with the system controller by the encrypted communication using a fourth common key shared by the first relay device and the system controller, thereby relaying the communication between the first communication device and the system controller; when the second relay device is not the second communication device, the second relay device communicates with the second communication device through the encrypted communication using a third common key shared by the second relay device and the second communication device, and communicates with the system controller through the encrypted communication using a fifth common key shared by the second relay device and the system controller, thereby relaying the communication between the second communication device and the system controller. The air conditioning system according to claim 3 .
5. the plurality of first air conditioning devices belong to a first communication network, the plurality of second air conditioning devices belong to a second communication network different from the first communication network, the first relay device and the second relay device belong to a third communication network different from the first communication network and the second communication network; 3. The air conditioning system according to claim 1 or 2.
6. a third communication device among the plurality of first air conditioning devices and the plurality of second air conditioning devices, an authentication means for authenticating a fourth communication device that communicates with the third communication device among the plurality of first air conditioning devices and the plurality of second air conditioning devices; a common key generating means for generating the common key used in the encrypted communication; and a common key transmission means for transmitting the common key generated by the common key generation means to the fourth communication device after the authentication means has authenticated the fourth communication device.
3. The air conditioning system according to claim 1 or 2.
7. A third communication device among the plurality of first air conditioning devices and the plurality of second air conditioning devices, and a fourth communication device that communicates with the third communication device among the plurality of first air conditioning devices and the plurality of second air conditioning devices, a storage means for storing an encryption key in a pre-shared key system; the third communication device, a common key generating means for generating the common key used in the encrypted communication; an encryption means for encrypting the common key generated by the common key generation means with the encryption key stored in the storage means included in the third communication device; a common key transmission means for transmitting the common key encrypted by the encryption means to the fourth communication device, 3. The air conditioning system according to claim 1 or 2.
8. the third communication device, an encryption key generation unit that generates the encryption key to be stored in the storage unit included in the third communication device from shared information that is set at the time of manufacturing or shipping the third communication device; the fourth communication device, an encryption key generating means for generating the encryption key to be stored in the storage means included in the fourth communication device from the shared information set at the time of manufacturing or shipping the fourth communication device; The air conditioning system according to claim 7.
9. the third communication device, an encryption key generation means for generating the encryption key to be stored in the storage means included in the third communication device from shared information acquired when the air conditioning system is constructed; the fourth communication device, an encryption key generation means for generating, from the shared information acquired when the air conditioning system is constructed, the encryption key to be stored in the storage means included in the fourth communication device; The air conditioning system according to claim 7.
10. The third communication device and the fourth communication device a setting information acquisition means for acquiring setting information set by a user when constructing the air conditioning system; the shared information includes the setting information acquired by the setting information acquisition means, The air conditioning system according to claim 9.
11. the shared information includes location information indicating a location where the air conditioning system is installed, the third communication device, a location information acquiring means for acquiring, as the location information, information indicating a location where the third communication device is installed; the fourth communication device, a location information acquiring means for acquiring, as the location information, information indicating a location where the fourth communication device is installed; The air conditioning system according to claim 9.
12. the shared information includes time information indicating when the air conditioning system was constructed, the third communication device, a time information acquisition means for acquiring, as the time information, information indicating a time when the third communication device was powered on; the fourth communication device, a time information acquiring means for acquiring, as the time information, information indicating a time when the fourth communication device was powered on; The air conditioning system according to claim 9.
13. a display means for displaying device information relating to each of the plurality of first air conditioning devices and the plurality of second air conditioning devices when sharing of the common key has been completed in the encrypted communication between the plurality of first air conditioning devices, the encrypted communication between the plurality of second air conditioning devices, and the encrypted communication between the first relay device and the second relay device; and a start instruction receiving means for receiving an instruction to start air conditioning control from a user after the display means has displayed the device information.
3. The air conditioning system according to claim 1 or 2.
14. A communication method executed by an air conditioning system comprising a plurality of first air conditioning devices belonging to a first refrigerant system and a plurality of second air conditioning devices belonging to a second refrigerant system, the plurality of first air conditioning devices and the plurality of second air conditioning devices being communicatively connected, the plurality of first air conditioning apparatuses communicate with each other using encrypted communication in which communication data is encrypted using a common key; the plurality of second air conditioning devices communicate with each other using the encrypted communication, When a first communication device among the plurality of first air conditioning devices communicates with a second communication device among the plurality of second air conditioning devices, a first relay device among the plurality of first air conditioning devices and a second relay device among the plurality of second air conditioning devices communicate with each other using the encrypted communication. Communication method.
Citation Information
Patent Citations
Transmission device for air conditioner
JP2008020092A
Facility device, air conditioner, lighting device, air conditioner controller, mobile terminal, and communication system
JP2021002798A
Air conditioner and air conditioning system
JP2022123585A