communication systems
The communication system encrypts data at the edge device using the information management server's public key, ensuring secure transmission via a relay device, thereby addressing data leakage risks and simplifying key management.
Patent Information
- Application Number
- JP2021150237
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-15
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2041-09-15
AI Technical Summary
Edge devices, such as wearable devices, cannot directly obtain the public key of a data server to encrypt management information, leading to potential leakage or tampering of data during transmission via a relay device infected with a virus.
A communication system where the edge device encrypts management information using the public key of an information management server, transmitted via a second network, and the relay device transmits this encrypted data to the information management server via a first network, ensuring the data remains encrypted throughout the process.
Enhances security by preventing data leakage or tampering during transmission, while reducing the complexity of key management and accommodating larger data volumes through data division and recombination.
Smart Images

Figure 0007806425000001 
Figure 0007806425000002 
Figure 0007806425000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication system that collects management information acquired by edge devices via a relay device, and more particularly to a technique for ensuring the security of the management information. [Background technology]
[0002] In recent years, wearable devices that are worn on parts of the human body, such as the head, arm, or wrist, to acquire physical information have come into use. These wearable devices can acquire physical information by measuring body temperature, heart rate, and other parameters using built-in sensors. Furthermore, the acquired physical information can be collected by a data server on a network, allowing the physical information of a specific person or multiple people to be analyzed. In this case, since the physical information is transmitted to the data server, it is preferable to prevent the physical information from being leaked during transmission.
[0003] Here, in a system in which a gateway device controls equipment connected to an internal network means in accordance with control information transmitted from a terminal device via an external network means, the terminal device encrypts the control information using a public key transmitted from the gateway device and transmits it to the gateway device, the gateway device decrypts the control information using a private key corresponding to the public key, and the equipment is controlled using the decrypted control information, as disclosed in Patent Document 1.
[0004] Therefore, it is conceivable that the physical information acquired by the above-mentioned wearable device may also be encrypted and transmitted to a data server. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-64181 Summary of the Invention [Problem to be solved by the invention]
[0006] However, edge devices such as wearable devices are connected to a gateway acting as a relay device via short-range wireless communication such as Bluetooth Low Energy (BLE) or Near Field Communication (NFC), which is different from the network to which the data server is connected, and therefore, although the gateway can directly obtain the public key of the data server to encrypt management information such as physical information, the edge device cannot directly obtain the public key of the data server to encrypt management information such as physical information. Therefore, even in the technology disclosed in Patent Document 1, control information is not encrypted between the gateway device and the device.
[0007] It is also possible to encrypt the management information at the edge device using a public key or common key shared only between the edge device and the relay device and then transmit it to the relay device. However, in this case, the management information encrypted and transmitted by the edge device will first be decrypted at the relay device, which may result in the management information being leaked from the relay device, particularly if the relay device is infected with a virus.
[0008] The present invention has been made in consideration of the problems associated with the conventional technology as described above, and aims to provide a communication system in which an information management server collects management information acquired by an edge device connected to a relay device via a network different from the network to which the information management server is connected to the relay device, and which can improve security against leakage or tampering of management information transmitted from the edge device to the information management server via the relay device. [Means for solving the problem]
[0009] In order to achieve the above object, the present invention provides: A communication system in which an information management server connectable to a relay device via a first network collects management information acquired by an edge device connected to the relay device via a second network, The relay device a first communication unit that transmits a public key of the information management server to the edge device via the second network and receives, via the second network, the management information encrypted by the edge device using the public key of the information management server and transmitted; a second communication unit that transmits the management information received by the first communication unit in the encrypted state to the information management server via the first network, The edge device a first encryption unit that encrypts the acquired management information using a public key of the information management server; a third communication unit that receives the public key of the information management server transmitted from the relay device via the second network, and transmits the management information encrypted by the encryption unit to the relay device via the second network; The information management server a fourth communication unit that receives the management information transmitted from the relay device via the first network; and a first decryption unit that decrypts the management information received by the fourth communication unit using a private key that corresponds to the public key of the information management server.
[0010] In the present invention configured as described above, the management information acquired by the edge device is encrypted by the edge device using the public key of the information management server transmitted from the relay device via the second network, and transmitted to the relay device via the second network. Thereafter, the relay device transmits the encrypted management information transmitted from the edge device to the information management server via the first network, and the encrypted management information is decrypted by the information management server using a private key corresponding to the public key of the information management server.
[0011] In this way, although the edge device connects to the relay device via a second network different from the first network to which the information management server is connected, the public key of the information management server is transmitted from the relay device via the second network, so that the management information acquired by the edge device and collected by the information management server can be encrypted using the public key of the information management server.Furthermore, since the management information encrypted by the edge device is transmitted to the information management server without being decrypted by the relay device, security against leakage or tampering of the management information acquired by the edge device while it is being transmitted to the information management server is improved.
[0012] Furthermore, if the relay device has a second encryption unit that encrypts the public key of the information management server, the first communication unit transmits the public key of the information management server encrypted by the second encryption unit to the edge device via the second network, and the edge device has a second decryption unit that decrypts the encrypted public key of the information management server received by the third communication unit, security is improved when the public key of the information management server is transmitted from the relay device to the edge device.
[0013] In addition, if the second encryption unit encrypts the public key of the information management server using the public key of the edge device, and the second decryption unit decrypts the encrypted public key of the information management server received by the third communication unit using a private key corresponding to the public key of the edge device, the security of the exchange of the public key of the information management server between the relay device and the edge device can be improved and the effort required to manage the keys for encrypting and decrypting the public key of the information management server can be reduced.
[0014] Furthermore, if the edge device has a data division unit that divides the management information encrypted by the first encryption unit into multiple pieces, the third communication unit transmits the management information divided by the data division unit to the relay device via the second network, the relay device has a data combination unit that combines the divided management information transmitted from the edge device and received by the first communication unit, and the second communication unit transmits the management information combined by the data combination unit to the information management server via the first network, then even if the amount of data that the second network can transmit is small and the amount of management information to be transmitted from the edge device to the information management server via the relay device is large, the management information can be transmitted from the edge device to the information management server while maintaining security. [Effects of the Invention]
[0015] According to the present invention, although the edge device connects to the relay device via a second network different from the first network to which the information management server is connected, the public key of the information management server is transmitted from the relay device via the second network, so that the management information acquired by the edge device and collected by the information management server can be encrypted using the public key of the information management server.Furthermore, since the management information encrypted by the edge device is transmitted to the information management server without being decrypted by the relay device, security against leakage or tampering of the management information acquired by the edge device while it is being transmitted to the information management server can be improved.
[0016] In addition, in a configuration in which the relay device has a second encryption unit that encrypts the public key of the information management server, the first communication unit transmits the public key of the information management server encrypted by the second encryption unit to the edge device via a second network, and the edge device has a second decryption unit that decrypts the encrypted public key of the information management server received by the third communication unit, security can be improved when the public key of the information management server is transmitted from the relay device to the edge device.
[0017] In addition, in this case, if the second encryption unit encrypts the public key of the information management server using the public key of the edge device, and the second decryption unit decrypts the encrypted public key of the information management server received by the third communication unit using a private key corresponding to the public key of the edge device, the security of the exchange of the public key of the information management server between the relay device and the edge device can be improved, and the effort required to manage the keys for encrypting and decrypting the public key of the information management server can be reduced.
[0018] In addition, in a configuration in which the edge device has a data division unit that divides the management information encrypted by the first encryption unit into multiple pieces, the third communication unit transmits the management information divided by the data division unit to the relay device via the second network, the relay device has a data combination unit that combines the divided management information transmitted from the edge device and received by the first communication unit, and the second communication unit transmits the management information combined by the data combination unit to the information management server via the first network, even if the amount of data that the second network can transmit is small and the amount of management information to be transmitted from the edge device to the information management server via the relay device is large, the management information can be transmitted from the edge device to the information management server while maintaining security. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a diagram illustrating an embodiment of a communication system according to the present invention. [Figure 2] FIG. 2 is a functional block diagram showing the configuration of the edge device shown in FIG. [Figure 3] 2 is a functional block diagram showing the configuration of the gateway shown in FIG. 1. [Figure 4] 2 is a functional block diagram showing a configuration of an information management server shown in FIG. 1. [Figure 5]FIG. 5 is a sequence diagram for explaining the process up to registering the public key of the information management server in the gateway in order to collect data acquired by the edge device in the communication system shown in FIGS. 1 to 4 while ensuring security in the information management server. [Figure 6] 5 is a sequence diagram for explaining the processing up to the point where data acquired by an edge device is collected by an information management server in the communication system shown in FIGS. 1 to 4. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0020] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0021] FIG. 1 is a diagram showing an embodiment of a communication system according to the present invention.
[0022] 1, the communication system of this embodiment is configured to include edge devices 10-1 to 10-6, gateways 20-1 and 20-2, an information management server 30, and a certificate authority 40. Data acquired by edge devices 10-1 to 10-6 is transmitted to information management server 30 via gateways 20-1 and 20-2, and collected and managed by information management server 30. In this embodiment, gateway 20-1 is installed in a position where it can communicate with edge devices 10-1 to 10-3 via short-range wireless communication, and gateway 20-2 is installed in a position where it can communicate with edge devices 10-4 to 10-6 via short-range wireless communication. As a result, gateway 20-1 and edge devices 10-1 to 10-3, and gateway 20-2 and edge devices 10-4 to 10-6 are set as pairs that perform short-range wireless communication, respectively. In FIG. 1, an example is given in which there are six edge devices 10-1 to 10-6 and two gateways 20-1 and 20-2, with edge devices 10-1 to 10-3 communicating with gateway 20-1 and edge devices 10-4 to 10-6 communicating with gateway 20-2, but the numbers of each and the number of connections between them are not limited to these.
[0023] FIG. 2 is a functional block diagram showing the configuration of edge devices 10-1 to 10-6 shown in FIG.
[0024] The edge devices 10-1 to 10-6 shown in Figure 1 are, for example, devices that can be worn on the human body to detect body temperature and pulse rate, and are configured to be connectable to gateways 20-1 and 20-2 via short-range wireless communication that serves as a second network, such as BLE (Bluetooth Low Energy) or NFC (Near Field Communication).
[0025] As shown in FIG. 2, each of the edge devices 10-1 to 10-6 includes a data acquisition unit 11, a communication unit 12, a decryption unit 13, an encryption unit 14, and a data division unit 15.
[0026] The data acquiring unit 11 has a sensor and acquires data to be used as management information using the sensor. For example, if the edge devices 10-1 to 10-6 are devices that detect the body temperature and pulse rate of a human body, the edge devices 10-1 to 10-6 detect and acquire the body temperature and pulse rate using the sensor while attached to the human body.
[0027] The communication unit 12 serves as a third communication unit in the present invention. The communication unit 12 is composed of a communication antenna and a low-capacity microcomputer that performs communication processing, and performs wireless communication with the gateways 20-1 and 20-2 via short-range wireless communication such as BLE or NFC.
[0028] The decryption unit 13 serves as a second decryption unit in the present invention. The decryption unit 13 manages the private keys of the edge devices 10-1 to 10-6 themselves, and decrypts the public keys of the information management server 30 that have been encrypted and transmitted by the gateways 20-1 and 20-2 and received by the communication unit 12, using the private keys of the edge devices 10-1 to 10-6 themselves.
[0029] The encryption unit 14 serves as a first encryption unit in the present invention. The encryption unit 14 encrypts the data acquired by the data acquisition unit 11 using the public key of the information management server 30 decrypted by the decryption unit 13.
[0030] The data division unit 15 divides the data encrypted by the encryption unit 14 into pieces of a size that can be transmitted from the communication unit 12 to the gateways 20-1 and 20-2 via short-range wireless communication.
[0031] The decryption unit 13, encryption unit 14 and data division unit 15 are configured by a low-capacity microcomputer.
[0032] FIG. 3 is a functional block diagram showing the configuration of the gateways 20-1 and 20-2 shown in FIG.
[0033] The gateways 20-1 and 20-2 shown in FIG. 1 are configured to be connectable to the edge devices 10-1 to 10-6 via short-range wireless communication such as BLE or NFC, and are also configured to be connectable to the information management server 30 and the certification authority 40 via a communication line 50 which serves as a first network such as the Internet.
[0034] As shown in FIG. 3, the gateways 20-1 and 20-2 include communication units 21 and 22, a verification unit 23, an encryption unit 24, and a data combining unit 25.
[0035] The communication unit 21 serves as a first communication unit in the present invention. The communication unit 21 performs wireless communication with the edge devices 10-1 to 10-6 via short-range wireless communication such as BLE or NFC.
[0036] The communication unit 22 serves as a second communication unit in the present invention. The communication unit 22 transmits and receives information to and from the information management server 30 and the certification authority 40 via a communication line 50 such as the Internet.
[0037] The verification unit 23 verifies the authenticity of the public key of the information management server 30 by comparing the public key of the information management server 30 transmitted from the information management server 30 via the communication line 50 with the public key of the information management server 30 obtained from the certification authority 40 via the communication line 50.
[0038] The encryption unit 24 serves as a second encryption unit in the present invention. The encryption unit 24 manages the public keys of the edge devices 10-1 to 10-6 by incorporating them into a program, and encrypts the public key of the information management server 30, the authenticity of which has been confirmed by the verification unit 23, using the public key of the edge device 10-1 to 10-6 that is the data sender.
[0039] The data combining unit 25 combines the data transmitted from the edge devices 10-1 to 10-6 and received by the communication unit 21.
[0040] FIG. 4 is a functional block diagram showing the configuration of the information management server 30 shown in FIG.
[0041] The information management server 30 shown in FIG. 1 uses the private key / public key of the information management server 30 to collect and manage data acquired by the edge devices 10-1 to 10-6.
[0042] As shown in FIG. 4, the information management server 30 includes a communication unit 31, a decryption unit 32, a data management unit 33, and a database .
[0043] The communication unit 31 serves as a fourth communication unit in the present invention. The communication unit 31 transmits the public key of the information management server 30 to the certification authority 40 via the communication line 50 in order to register it, and receives, via the communication line 50, a digital certificate including the public key authenticated by the certification authority 40. The communication unit 31 also transmits the digital certificate received from the certification authority 40 to the gateways 20-1 and 20-2 via the communication line 50. The communication unit 31 also receives, via the communication line 50, data that has been acquired by the edge devices 10-1 to 10-6 and transmitted via the gateways 20-1 and 20-2.
[0044] The decryption unit 32 serves as a first decryption unit in the present invention. The decryption unit 32 manages the private key of the information management server 30, and decrypts data transmitted via the gateways 20-1 and 20-2 and received by the communication unit 31 using the private key of the information management server 30.
[0045] The data management unit 33 stores the data decoded by the decoding unit 32 in a database 34 .
[0046] The following describes a process for collecting data acquired by the edge device 10-1 in the communication system configured as above in the information management server 30 while ensuring security.
[0047] First, the process up to registering the public key of the information management server 30 in the gateway 20-1 will be described.
[0048] Figure 5 is a sequence diagram for explaining the process of registering the public key of the information management server 30 in the gateway 20-1 in order to collect data acquired by the edge device 10-1 in the information management server 30 while ensuring security in the communication system shown in Figures 1 to 4.
[0049] First, in the information management server 30, a private key and a corresponding public key are created in order to collect data acquired by the edge devices 10-1 to 10-6 in the information management server 30 while ensuring security (step S1).
[0050] Next, in the information management server 30, in order to register the public key created in step S1, the public key is transmitted from the communication unit 31 to the certificate authority 40 via the communication line 50 (step S2).
[0051] When the public key of the information management server 30 is transmitted from the information management server 30 via the communication line 50, the certificate authority 40 authenticates the transmitted public key of the information management server 30 (step S3), and issues an electronic certificate including the authenticated public key to the information management server 30 (step S4). The above-mentioned process up to the issuance of the electronic certificate is a general process.
[0052] In the information management server 30, when the communication unit 31 receives the electronic certificate issued by the certificate authority 40 via the communication line 50, the received electronic certificate is transmitted to the gateways 20-1 and 20-2 via the communication line 50 (step S5). Since the information management server 30 manages in advance the gateways 20-1 and 20-2 registered in the system, it can identify the gateways 20-1 and 20-2 to which the electronic certificate is to be transmitted.
[0053] After the digital certificate transmitted from the information management server 30 is received by the communication unit 22 of the gateway 20-1 via the communication line 50, the gateway 20-1 acquires the digital certificate of the information management server 30 from the certification authority 40 (step S6). At this time, the gateway 20-1 uses information such as an identifier included in the digital certificate transmitted from the information management server 30 to identify the digital certificate to be acquired to the certification authority 40.
[0054] In gateway 20-1, which has acquired the electronic certificate of information management server 30 from certification authority 40, verification unit 23 compares and verifies the electronic certificate sent from information management server 30 in step S5 with the electronic certificate acquired from certification authority 40 in step S6, and if the two match, the public key included in the electronic certificate of information management server 30 is registered in gateway 20-1 (step S7).
[0055] In this way, in order to collect data acquired by edge device 10-1 in the information management server 30 while ensuring security in the communication system shown in Figures 1 to 4, the public key of the information management server 30 is registered in gateway 20-1, and the public key of the information management server 30 is shared between the information management server 30 and gateway 20-1.
[0056] Next, a process of collecting data acquired by the edge device 10-1 at the information management server 30 will be described.
[0057] FIG. 6 is a sequence diagram for explaining the processing up to collection of data acquired by edge device 10-1 by information management server 30 in the communication system shown in FIGS.
[0058] The edge device 10-1 is set to transmit the data acquired by the data acquisition unit 11 to the information management server 30 at regular intervals. Therefore, when it is time to transmit the data acquired by the data acquisition unit 11 to the information management server 30, the edge device 10-1 transmits an advertising signal from the communication unit 12 to notify that the data acquired by the data acquisition unit 11 will be transmitted (step S11).
[0059] When the advertisement signal transmitted from the edge device 10-1 is received by the communication unit 21 of the gateway 20-1, which can communicate with the edge device 10-1 via short-range wireless communication, the communication unit 21 performs pairing between the gateway 20-1 and the edge device 10-1 to establish a communication path (step S12).
[0060] When a communication path is established between the edge device 10-1 and the gateway 20-1, the edge device 10-1 stops transmitting the advertising signal.
[0061] Next, in the gateway 20-1, the encryption unit 24 encrypts the public key of the information management server 30 registered in step S7 using the public key of the edge device 10-1 that is managed by being incorporated into a program (step S13).
[0062] Then, in the gateway 20-1, the public key of the information management server 30 encrypted by the encryption unit 24 is transmitted from the communication unit 21 to the edge device 10-1 via short-range wireless communication (step S14).
[0063] When the public key of the information management server 30 transmitted from the gateway 20-1 is received by the communication unit 12 of the edge device 10-1, the decryption unit 13 of the edge device 10-1 decrypts the public key of the information management server 30 received by the communication unit 12 using the private key of the edge device 10-1 that corresponds to the public key of the edge device 10-1 with which the public key was encrypted (step S15).
[0064] In this way, the gateway 20-1 encrypts the public key of the information management server 30 and transmits it to the edge device 10-1, and the edge device 10-1 decrypts the public key of the information management server 30 transmitted from the edge device 10-1, thereby improving security when the public key of the information management server 30 is transmitted from the gateway 20-1 to the edge device 10-1. At this time, a common key common to the edge device 10-1 and the gateway 20-1 may be used to encrypt and decrypt the public key of the information management server 30, but by using the public key of the edge device 10-1 to encrypt the public key of the information management server 30 and the private key of the edge device 10-1 to decrypt it, security in the exchange of the public key of the information management server 30 between the gateway 20-1 and the edge device 10-1 can be improved and the effort required to manage the keys for encrypting and decrypting the public key of the information management server 30 can be reduced.
[0065] When the edge device 10-1 decrypts the public key of the information management server 30 transmitted from the gateway 20-1, it notifies the gateway 20-1 that the decryption of the public key of the information management server 30 has been successful (step S16).
[0066] Then, the gateway 20-1 requests the edge device 10-1 to prepare for data transmission to the gateway 20-1 (step S17).
[0067] In the edge device 10-1, when the gateway 20-1 requests preparation for data transmission, the encryption unit 14 encrypts the data acquired by the data acquisition unit 11 using the public key of the information management server 30 decrypted in step S15 (step S18).
[0068] Here, in the short-range wireless communication between edge devices 10-1 to 10-6 and gateways 20-1 and 20-2, the amount of data that can be transmitted is small. On the other hand, when transmission data is encrypted, the amount of encrypted data becomes large in units of 128 bytes, for example, when 80 bytes or 100 bytes of data are encrypted with a public key / private key (1024-bit key), the encrypted data becomes 128 bytes, and when 150 bytes or 200 bytes of data are encrypted, the encrypted data becomes 256 bytes.
[0069] Therefore, in the edge device 10-1, the data dividing unit 15 divides the data encrypted by the encryption unit 14 into sizes that can be transmitted from the communication unit 12 to the gateway 20-1 via short-range wireless communication (step S19). The data division size is set in advance in the data dividing unit 15 of the edge device 10-1 according to the short-range wireless communication used for communication with the gateway 20-1.
[0070] In the edge device 10-1, when the data dividing unit 15 divides the data, the edge device 10-1 notifies the gateway 20-1 that preparation for data transmission to the gateway 20-1 has been completed as a response to step S17 (step S20).
[0071] When the gateway 20-1 is notified by the edge device 10-1 that preparations for data transmission to the gateway 20-1 have been completed, the gateway 20-1 requests the edge device 10-1 to transmit data (step S21).
[0072] When the edge device 10-1 receives a request to transmit data from the gateway 20-1, the communication unit 12 sequentially transmits the divided data from step S19 to the gateway 20-1 via short-range wireless communication (step S22). At this time, the data transmitted from the edge device 10-1 is provided with information indicating the number of the divided data. The data transmitted from the edge device 10-1 is received by the communication unit 21 of the gateway 20-1 via short-range wireless communication.
[0073] Thereafter, when the edge device 10-1 transmits all of the divided data to the gateway 20-1 in step S19, it notifies the gateway 20-1 that the data transmission has been completed (step S23).
[0074] When gateway 20-1 is notified by edge device 10-1 that the data transmission has been completed, data combining unit 25 combines the data transmitted from edge device 10-1 and received by communication unit 21 (step S24). As described above, the data transmitted from edge device 10-1 and received by communication unit 21 is provided with information indicating the order of the data among the divided data, so that data combining unit 25 can combine the data transmitted from edge device 10-1 and received by communication unit 21 in the correct order.
[0075] Then, in the gateway 20-1, the combined data is transmitted from the communication unit 22 to the information management server 30 via the communication line 50 while still being encrypted with the public key of the information management server 30 (step S25).
[0076] In this way, the edge device 10-1 divides data encrypted using the public key of the information management server 30 into multiple pieces and transmits them to the gateway 20-1, and the gateway 20-1 combines the data divided by the edge device 10-1 and transmits it to the information management server 30.Even if the amount of data to be transmitted from the edge device 10-1 to the information management server 30 via the gateway 20-1 is large, the data can be transmitted from the edge device 10-1 to the information management server 30 while maintaining security via short-range wireless communication between the edge device 10-1 and the gateway 20-1.
[0077] In the information management server 30, when the data transmitted from the gateway 20-1 is received by the communication unit 31, the decryption unit 32 decrypts the data received by the communication unit 31 using the private key of the information management server 30 corresponding to the public key of the information management server 30 with which the data was encrypted by the edge device 10-1 (step S26).
[0078] Then, in the data management unit 33 of the information management server 30, the data decrypted by the decryption unit 32 is stored in the database 34, so that the data acquired by the edge device 10-1 is collected by the information management server 30 (step S27).
[0079] On the other hand, in the gateway 20-1, after the data combined by the data combining unit 25 is transmitted to the information management server 30, the communication path between the gateway 20-1 and the edge device 10-1 is disconnected (step S28).
[0080] Thereafter, the edge device 10-1 discards the public key of the information management server 30 decrypted in step S15 (step S29).
[0081] The above-described exchange of signals and data between edge device 10-1 and gateway 20-1 can be performed in parallel between edge devices 10-1 to 10-6 and gateways 20-1 and 20-2 by using IDs that can identify edge devices 10-1 to 10-6.
[0082] In this way, although the edge devices 10-1 to 10-6 connect to the gateways 20-1 and 20-2 via short-range wireless communication that is different from the communication line 50 to which the information management server 30 is connected, the public key of the information management server 30 is transmitted from the gateways 20-1 and 20-2 via short-range wireless communication, so that the data acquired by the edge devices 10-1 to 10-6 and collected by the information management server 30 can be encrypted using the public key of the information management server 30. Furthermore, since the data encrypted by the edge devices 10-1 to 10-6 is transmitted to the information management server 30 without being decrypted by the gateways 20-1 and 20-2, security against data leakage and tampering while the data acquired by the edge devices 10-1 to 10-6 is being transmitted to the information management server 30 can be improved.
[0083] In this embodiment, the public key of the information management server 30 is registered with the certification authority 40, and the gateways 20-1 and 20-2 compare the public key contained in the electronic certificate sent from the information management server 30 with the public key contained in the electronic certificate obtained from the certification authority 40 to confirm the authenticity of the public key of the information management server 30, thereby allowing the public key of the information management server 30 to be shared between the information management server 30 and the gateways 20-1 and 20-2. However, the mechanism for sharing the public key of the information management server 30 between the information management server 30 and the gateways 20-1 and 20-2 is not limited to this, and other mechanisms may also be used. [Explanation of symbols]
[0084] 10-1~10-6 Edge Devices 11 Data Acquisition Section 12, 21, 22, 31 Communications Department 13,32 Decoding section 14,24 Encryption part 15 Data division section 20-1, 20-2 Gateway 23 Verification Department 25 Data connection section 30 Information Management Server 33 Data Management Department 34 Databases 40 Certificate Authority 50 communication lines
Claims
1. 1. A communication system in which an information management server connectable to a relay device via a first network collects management information acquired by an edge device connected to the relay device via a second network, The relay device a first communication unit that transmits a public key of the information management server to the edge device via the second network and receives, via the second network, the management information encrypted by the edge device using the public key of the information management server and transmitted; a second communication unit that transmits the management information received by the first communication unit in the encrypted state to the information management server via the first network, The edge device a first encryption unit that encrypts the acquired management information using a public key of the information management server; a third communication unit that receives the public key of the information management server transmitted from the relay device via the second network, and transmits the management information encrypted by the encryption unit to the relay device via the second network; The information management server a fourth communication unit that receives the management information transmitted from the relay device via the first network; a first decryption unit that decrypts the management information received by the fourth communication unit using a private key corresponding to a public key of the information management server, the relay device has a second encryption unit that encrypts a public key of the information management server, and the first communication unit transmits the public key of the information management server encrypted by the second encryption unit to the edge device via the second network; The edge device has a second decryption unit that decrypts the encrypted public key of the information management server received by the third communication unit.
2. 2. The communication system according to claim 1, the second encryption unit encrypts a public key of the information management server using a public key of the edge device; a second decryption unit that decrypts the encrypted public key of the information management server received by the third communication unit using a private key that corresponds to the public key of the edge device;
3. 3. The communication system according to claim 1, the edge device has a data dividing unit that divides the management information encrypted by the first encryption unit into multiple pieces, and the third communication unit transmits the management information divided by the data dividing unit to the relay device via the second network; A communication system in which the relay device has a data combining unit that combines the divided management information sent from the edge device and received by the first communication unit, and the second communication unit transmits the management information combined by the data combining unit to the information management server via the first network.
Citation Information
Patent Citations
Home gateway apparatus and program
JP2004064181A
Radio terminal, base station, and mobile communication system
JP2012156974A
Data collection system, data collection method, gateway device and data compaction system
JP2015023375A
Sensor device, information collection system, and information collection method
JP2017192117A
Wireless communication device, and telecommunication system
JP2018121125A