Authentication device, authentication system, and authentication method
The authentication system securely authenticates devices remotely by generating challenge data from electromagnetic characteristics, ensuring secure and reliable authentication without exposing the device's unique characteristics.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2024-12-17
- Publication Date
- 2026-04-24
AI Technical Summary
Conventional authentication methods require physical proximity and transmission of electromagnetic characteristics over a communication network, risking data leakage and impersonation.
An authentication system that generates challenge data based on electromagnetic characteristics, allowing remote authentication without transmitting these characteristics, using a two-dimensional graph representation to determine authenticity through response data comparison.
Prevents electromagnetic characteristic leakage and ensures secure remote authentication by keeping the device's unique characteristics secret, preventing fraudulent impersonation.
Smart Images

Figure 0007851387000001 
Figure 0007851387000002 
Figure 0007851387000003
Abstract
Description
Technical Field
[0001] This disclosure relates to authentication technology for electronic devices.
Background Art
[0002] In conventional authentication of electronic devices, the electromagnetic characteristics of an electronic device are measured, the measured electromagnetic characteristics are stored in advance, and later, the electromagnetic characteristics of the device to be authenticated are measured. The authenticity of the device to be authenticated is determined by comparing the electromagnetic characteristics of the device to be authenticated with the electromagnetic characteristics stored in advance (for example, Patent Document 1). Also, a method of performing authentication focusing on the spectrum of electromagnetic waves radiated from an electronic device as the electromagnetic characteristics of the electronic device has been proposed (for example, Non-Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] According to conventional technology, the authentication device (authentication device) had to be placed near the device to be authenticated (authenticated device), and the electromagnetic characteristics of the authenticated device measured on-site had to be compared with the electromagnetic characteristics stored in the authentication device beforehand. Furthermore, if the authentication device and the authenticated device were in different locations and authentication was to be performed via a communication network, the electromagnetic characteristic data of the authenticated device had to be transmitted to the authentication device over the communication network. When communication is performed via a communication network, there was a problem in that if the communication data on the communication network was intercepted and the electromagnetic characteristic data of the authenticated device was leaked, a counterfeit device could be authenticated by impersonating a genuine authenticated device.
[0006] This disclosure was made to solve such problems and aims to provide an authentication technology that can prevent the leakage of the electromagnetic characteristics of a device to be authenticated when the authentication of the device is performed via a communication network. [Means for solving the problem]
[0007] One aspect of the authentication device according to the embodiments of this disclosure is An expected response data value corresponding to challenge data generated from the electromagnetic characteristics of the first certified device, depending on at least one electromagnetic characteristic of the first certified device. The system includes a response data determination unit that compares the electromagnetic characteristics of the second device to be authenticated with the response data corresponding to the challenge data to determine the authenticity of the second device to be authenticated, wherein the electromagnetic characteristics of the first device to be authenticated and the electromagnetic characteristics of the second device to be authenticated are characteristics that can be represented as a two-dimensional graph consisting of an X axis and a Y axis, and the challenge data is generated as a pair [Xn, Yn] (where n is an integer) of a plurality of X axis values Xn and a Y axis threshold Yn at each X axis value. , characterized by . [Effects of the Invention]
[0008] According to the authentication device of the embodiment of this disclosure, the electromagnetic characteristics of the device to be authenticated are not transmitted or received, thus preventing leakage of the electromagnetic characteristics of the device to be authenticated. [Brief explanation of the drawing]
[0009] [Figure 1]This figure shows an example configuration of an authentication system that includes an authentication device and a response device. [Figure 2A] This figure shows an example of the hardware configuration for the authentication device and the response device. [Figure 2B] This figure shows an example of the hardware configuration for the authentication device and the response device. [Figure 3] This is a flowchart of the authentication method. [Figure 4] This figure shows examples of electromagnetic properties (EMCi, EMCr), challenge data, response data, and expected response data values. [Modes for carrying out the invention]
[0010] Hereinafter, various embodiments of this disclosure will be described in detail with reference to the attached drawings. Components that are denoted by the same or similar reference numerals in the drawings have the same or similar configuration or function, and redundant descriptions of such components will be omitted.
[0011] Embodiment 1. <Structure> (Authentication system) Referring to Figures 1 and 2, the configuration of an authentication system comprising an authentication device and a response device according to Embodiment 1 of this disclosure will be described. The authentication system according to this disclosure is a system for authenticating the authenticity of a device to be authenticated (a second device to be authenticated) 100. That is, the device to be authenticated 100 is a device seeking authentication. The device to be authenticated 100 has inherent electromagnetic characteristics (EMC). Hereinafter, the inherent electromagnetic characteristics EMC will be denoted as electromagnetic characteristics EMCi, using the initial letter of "inherent".
[0012] Even if the certified device 100 is manufactured with the same design as other certified devices not shown, each device has different electromagnetic characteristics (EMCi) due to individual component manufacturing tolerances, printed circuit board manufacturing tolerances, assembly tolerances, etc. Examples of such electromagnetic characteristics (EMCi) include radiated electromagnetic noise emitted into space by the operation of the certified device 100, and conducted electromagnetic noise transmitted through cables when the certified device 100 is operating. Another example of electromagnetic characteristics (EMCi) is the reflection characteristics (S-parameters) observed from a specific external I / F such as the power connector or signal connector of the certified device 100, regardless of the operation of the certified device 100 (power on / off). 11 Characteristics), pass characteristics between multiple external I / Fs (S parameter of S) nm Characteristics (where n and m are numbers assigned to multiple external interfaces), F-parameters, Z-parameters, and Y-parameters converted from S-parameters are examples. These are generally characteristics expressed on the frequency axis, but the electromagnetic characteristics (EMCi) of the certified device 100 may also be characteristics expressed on the time axis, such as the reflected waveform when a step wave or impulse wave is applied to a specific external interface of the certified device 100 or the transmitted waveform at another external interface. Furthermore, a combination of multiple electromagnetic characteristics may be used as the electromagnetic characteristics (EMCi). Examples of the certified device 100 include, for example, electrical equipment or electronic equipment, or electrical or electronic components, but are not limited to these examples as long as electromagnetic characteristics can be obtained. For example, it may be a mechanical component that does not include an electrical circuit.
[0013] To authenticate the authenticity of the device to be authenticated 100, the authentication system according to this disclosure comprises an authentication device 200, a storage device 500, and a response device 300, as shown in Figure 1. Communication between the authentication device 200 and the response device 300 is performed via a wired or wireless communication network 400. The storage device 500 is a device that pre-records the electromagnetic characteristics EMCi of one or more devices to be authenticated. Hereinafter, the electromagnetic characteristics EMCi of the device to be authenticated (the first device to be authenticated) recorded in the storage device 500 will be denoted as electromagnetic characteristics EMCr, using the initial letter of "registered" to mean "recorded".
[0014] (Authentication Device) The authentication device 200 is a device that authenticates the authenticity of the authenticated device 100. To achieve such an objective, the authentication device 200 includes, as functional units, an electromagnetic characteristic acquisition unit (first electromagnetic characteristic acquisition unit) 210, a challenge data generation unit 220, an expected value generation unit 230, a challenge data transmission unit 240, a response data reception unit 250, and a response data determination unit 260.
[0015] (Electromagnetic Characteristic Acquisition Unit) The electromagnetic characteristic acquisition unit 210 is a functional unit that acquires at least one electromagnetic characteristic EMCr from the storage device 500. The electromagnetic characteristic acquisition unit 210 supplies the acquired electromagnetic characteristic EMCr to the challenge data generation unit 220 and the expected value generation unit 230. Note that the supply of data may be performed via a control unit (not shown) provided in the authentication device 200. The same applies hereinafter.
[0016] (Challenge Data Generation Unit) The challenge data generation unit 220 is a functional unit that generates challenge data corresponding to the electromagnetic characteristic EMCr acquired by the electromagnetic characteristic acquisition unit 210. The challenge data generation unit 220 supplies the generated challenge data to the challenge data transmission unit 240 and the expected value generation unit 230.
[0017] (Expected Value Generation Unit) The expected value generation unit 230 is a functional unit that compares the electromagnetic characteristic EMCr acquired by the electromagnetic characteristic acquisition unit 210 with the challenge data generated by the challenge data generation unit 220, and generates a response data expected value that is the result of the comparison. The expected value generation unit 230 supplies the generated response data to the response data determination unit 260.
[0018] (Challenge Data Transmission Unit) The challenge data transmission unit 240 is a functional unit that transmits the challenge data generated by the challenge data generation unit 220 to the response device 300 via the communication network 400.
[0019] (Response data receiving unit) The response data receiving unit 250 is a functional unit that receives response data related to the authenticated device 100, which is generated by the response device 300, from the response device 300 via the communication network 400.
[0020] (Response data determination unit) The response data determination unit 260 is a functional unit that compares the expected response data value generated by the expected value generation unit 230 with the response data received by the response data receiving unit 250 to determine the authenticity of the device to be authenticated 100.
[0021] (Response device) The response device 300 is a device that responds to the authentication device 200 by generating response data based on the electromagnetic characteristics (EMCi) of the device to be authenticated 100 and challenge data received from the authentication device 200, and transmitting the generated response data to the authentication device 200. To achieve this objective, the response device 300 includes, as functional units, an electromagnetic characteristic acquisition unit (second electromagnetic characteristic acquisition unit) 310, a challenge data receiving unit 320, a response data generation unit 330, and a response data transmission unit 340.
[0022] (Electromagnetic characteristics acquisition department) The electromagnetic characteristics acquisition unit 310 is a functional unit that acquires the electromagnetic characteristics (EMCi) of the device to be certified 100. The electromagnetic characteristics acquisition unit 310 supplies the acquired electromagnetic characteristics (EMCi) to the response data generation unit 330. The data may also be supplied via a control unit (not shown) provided in the response device 300. The same applies hereafter.
[0023] (Challenge data receiving unit) The challenge data receiving unit 320 is a functional unit that receives challenge data from the authentication device 200 via the communication network 400. The challenge data receiving unit 320 supplies the received challenge data to the response data generation unit 330.
[0024] (Response data generation unit) The response data generation unit 330 is a functional unit that generates response data by comparing the electromagnetic characteristics EMCi supplied from the electromagnetic characteristics acquisition unit 310 with the challenge data supplied from the challenge data receiving unit 320. The response data generation unit 330 supplies the generated response data to the response data transmission unit 340.
[0025] (Response data transmission unit) The response data transmission unit 340 is a functional unit that transmits the response data generated by the response data generation unit 330 to the authentication device 200 via the communication network 400.
[0026] The response device 300 may be a separate device from the device to be authenticated 100, as shown in Figure 1, or it may be integrated with the device to be authenticated 100. If the response device 300 is integrated with the device to be authenticated 100, for example, the device to be authenticated 100 includes the functional part of the response device 300.
[0027] Next, with reference to Figures 2A and 2B, an example of the hardware configuration of the authentication device 200 and the response device 300 will be described. The functional units of the authentication device 200 and the response device 300 are realized by processing circuitry. The processing circuitry may be a dedicated processing circuit 600 as shown in Figure 2A, or a processor 700 that executes a program stored in memory 800 as shown in Figure 2B.
[0028] If the processing circuitry is a dedicated processing circuit 600, the dedicated processing circuit 600 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (application-specific integrated circuit), an FPGA (field-programmable gate array), or a combination thereof. Each functional part of the authentication device 200 and the response device 300 may be implemented by multiple separate processing circuits, or each functional part may be implemented together by a single processing circuit.
[0029] When the processing circuitry is a processor 700, the functional units of the authentication device 200 and the response device 300 are realized by software, firmware, or a combination of software and firmware. The software and firmware are written as programs and stored in memory 800. The processor 700 realizes the functions of each functional unit by reading and executing the programs stored in memory. Here, examples of memory 800 include non-volatile or volatile semiconductor memories such as RAM (random access memory), ROM (read-only memory), flash memory, EPROM (erasable programmable read-only memory), and EEPROM (electrically erasable programmable read-only memory), as well as magnetic disks, flexible disks, optical disks, compact disks, minidiscs, and DVDs.
[0030] Furthermore, some of the functional parts of the authentication device 200 and the response device 300 may be implemented using dedicated hardware, while other parts may be implemented using software or firmware. In this way, the processing circuit can implement each of the above-mentioned functions using hardware, software, firmware, or a combination thereof.
[0031] <Operation> Next, the operation of the authentication system of this disclosure will be explained with reference to Figures 3 and 4. First, the electromagnetic characteristics (EMCi) of the device to be authenticated 100 are recorded in the storage device 500 in advance, along with the identification information of the device to be authenticated 100. As described above, the electromagnetic characteristics (EMCi) of the device to be authenticated 100 recorded in the storage device 500 are referred to as electromagnetic characteristics (EMCr). The recording of electromagnetic characteristics (EMCi) is performed for each device to be authenticated that is expected to be authenticated later.
[0032] The authentication system operates in response to an authentication request being made to the device to be authenticated 100 from the device to be authenticated 100 or another external system (not shown) to the authentication device 200. In response to the occurrence of an authentication request, in step ST101, the electromagnetic characteristic acquisition unit 210 of the authentication device 200 acquires the electromagnetic characteristic EMCr of the device to be authenticated 100 from one or more electromagnetic characteristics recorded in the storage device 500.
[0033] In step ST102, the challenge data generation unit 220 generates challenge data, which is a dataset corresponding to the electromagnetic characteristic EMCr. "Dataset corresponding to the electromagnetic characteristic EMCr" means a dataset that, in a two-dimensional graph representing the electromagnetic characteristic EMCr, includes at least one pair (X,Y) of X-axis value X and Y-axis value Y, where the Y-axis value Y is smaller than the maximum value and larger than the minimum value of the electromagnetic characteristic EMCr.
[0034] As an example, the challenge data generation unit 220 generates challenge data in the form of a pair [Xn,Yn] (where n is an integer) consisting of multiple X-axis values (Xn; e.g., frequency or time) of electromagnetic characteristics EMCr and a threshold value for the Y-axis value (Yn; e.g., gain, phase, or signal waveform) at each X-axis value. When generating challenge data by combining multiple electromagnetic characteristics, the challenge data may be in the form of a pair of threshold values Y1n and Y2n for different characteristics corresponding to a common X-axis value (Xn), such as [Xn,Y1n,Y2n,...] (where n is an integer). The challenge data generation unit 220 randomly generates such challenge data each time an authentication request occurs. That is, the number of n on the X-axis, the X-axis values (Xn), and all or part of the Y-axis threshold Yn corresponding to Xn are randomly generated each time an authentication request occurs, even for the same device 100 being authenticated.
[0035] As another example, the challenge data generation unit 220 may generate a set of challenge data [Xn,Y] (where n is an integer) consisting of multiple X-axis values Xn and a single Y-axis threshold Y that is common to all X-axis values.
[0036] As another example, the challenge data generation unit 220 may generate multiple shared X-axis values Xn as challenge data for the X-axis, which are fixed values shared in advance between the authentication device 200 and the response device 300, or variable values generated and shared using a common tool each time an authentication request is made. For the Y-axis, it may generate multiple Y-axis thresholds Yn that are different from each other for the multiple shared X-axis values.
[0037] As another example, the challenge data generation unit 220 may generate multiple shared X-axis values Xn as challenge data for the X-axis, which are fixed values shared in advance between the authentication device 200 and the response device 300, or variable values generated and shared using a common tool each time an authentication request is made. For the Y-axis, it may generate a common and single Y-axis threshold Y for the multiple shared X-axis values.
[0038] As an example, the challenge data generation unit 220 may generate a number of X-axis values Xn and some or all of the Y-axis thresholds Y or Yn for each X-axis value as random values each time an authentication request occurs.
[0039] In step ST103, the expectation value generation unit 230 compares the electromagnetic characteristic EMCr with the generated challenge data and generates an expected response data value as a result of the comparison. That is, the expectation value generation unit 230 generates an expected response data value that is expected for the generated challenge data. For example, the expectation value generation unit 230 compares the electromagnetic characteristic EMCr of the device under authentication 100 with the generated challenge data and generates an n-bit bit sequence (first data) as the expected response data value, setting it to "1" if the level of the electromagnetic characteristic EMCr corresponding to the specified Xn is greater than or equal to Yn, and to "0" if it is less than Yn. It is assumed that this method of generating response data from electromagnetic characteristics and challenge data is also set in advance in the response data generation unit 330 of the response device 300.
[0040] In step ST104, the challenge data transmission unit 240 transmits the challenge data to the response device 300 via the communication network 400, either in parallel with or before / after the generation of the expected response data value.
[0041] The challenge data transmitted from the authentication device 200 in this manner is received by the challenge data receiving unit 320 of the response device 300 via the communication network 400 (step ST201).
[0042] In step ST202, the electromagnetic characteristic acquisition unit 310 acquires the electromagnetic characteristics (EMCi) of the certified device 100 based on the reception of the challenge data. For example, it may extract the electromagnetic characteristics (EMCi) recorded as data within the certified device 100, or, if the characteristics are such as S-parameters, it may perform measurements using a function equivalent to a network analyzer (and perform conversions if the characteristics are such as F, Z, or Y parameters), or, if the response characteristics to step waves or impulse waves, it may perform measurements using a function equivalent to a signal generator and a function equivalent to an oscilloscope.
[0043] Next, in step ST203, the response data generation unit 330 compares the acquired electromagnetic characteristics EMCi of the certified device 100 with the received challenge data and generates the result of the comparison as response data. Following the example above, similar to the operation of the expected value generation unit 230, if the level of the electromagnetic characteristics EMCi corresponding to Xn specified in the challenge data is Yn or greater, it is set to "1", and if it is less than Yn, it is set to "0", generating an n-bit bit sequence (second data) as response data. The response data generation unit 330 passes the generated response data to the response data transmission unit 340.
[0044] Next, in step ST204, the response data transmission unit 340 transmits the generated response data to the authentication device 200 via the communication network 400.
[0045] The response data transmitted from the response device 300 in this manner is received by the response data receiving unit 250 of the authentication device 200 via the communication network 400 (step ST105).
[0046] Finally, in step ST106, the response data determination unit 260 compares the expected response data value generated by the expected value generation unit 203 with the response data received by the response data receiving unit 250 to determine the authenticity of the device to be authenticated 100. For example, it compares the n-bit expected response data value generated by the expected value generation unit 230 with the n-bit response data received by the response data receiving unit 250. If there is a perfect match, or if a certain number of bits (for example, 85% or more of the total bits) match, the device to be authenticated is authenticated as authentic. The authentication result is transmitted to the device to be authenticated 100 that originated the authentication request, or to another external system (not shown), etc.
[0047] Figure 4 shows examples of electromagnetic characteristics (EMCi, EMCr), challenge data, response data, and expected response data values as illustrated in the above operation description.
[0048] Reference number 211 is an example of recorded electromagnetic characteristics (EMCr) of a certified device acquired by the electromagnetic characteristics acquisition unit 210 of the authentication device 200. As shown in Figure 4, electromagnetic characteristics (EMCr) are represented as a two-dimensional graph consisting of the X and Y axes.
[0049] Reference number 221 is an example of challenge data generated by the challenge data generation unit 220 of the authentication device 200, and is shown as challenge data consisting of a set of multiple X-axis values of electromagnetic characteristics (the X-axis being, for example, frequency or time) and a threshold value for the Y-axis value in that X-axis [Xn, Yn] (where n is an integer).
[0050] Reference number 311 is an example of the electromagnetic characteristics (EMCi) of the certified device 100 acquired by the electromagnetic characteristics acquisition unit 310 of the response device 300. As shown in Figure 4, the electromagnetic characteristics (EMCi) are represented as a two-dimensional graph consisting of the X and Y axes.
[0051] Reference number 331 is a response data consisting of a 7-bit bit sequence generated by the response data generation unit 330 when the challenge data 221 received by the challenge data receiving unit 320 and the electromagnetic characteristics 311 of the authenticated device 100 acquired by the electromagnetic characteristics acquisition unit 310 are compared, and the response data generation unit 330 generates "1" if the level of the unique electromagnetic characteristic 311 corresponding to Xn on the X axis specified in the challenge data 221 is Yn or greater, and "0" if it is less than Yn. In this way, the response data generation unit 330 compares the Y-axis threshold Yn with the Y-axis values of multiple X-axis values Xn of the electromagnetic characteristic 311, determines which is larger, the Y-axis threshold Yn or the Y-axis value of the electromagnetic characteristic 311, and generates 7-bit data.
[0052] Reference number 231 is the expected response data, consisting of a 7-bit bit string, generated by the expected value generation unit 230 when the electromagnetic characteristic 211 acquired by the electromagnetic characteristic acquisition unit 210 and the challenge data 221 generated by the challenge data generation unit 220 are compared, and the expected value generation unit 230 generates "1" if the level of the electromagnetic characteristic 211 corresponding to Xn on the X axis specified in the challenge data 221 is greater than or equal to Yn, and "0" if it is less than Yn. In this way, the expected value generation unit 230 compares the Y-axis threshold Yn with the Y-axis values of multiple X-axis values Xn of the electromagnetic characteristic 211, determines which is larger, the Y-axis threshold Yn or the Y-axis value of the electromagnetic characteristic 211, and generates 7-bit data.
[0053] The response data 331 is received by the response data receiving unit 250 of the authentication device 200 via the communication network 400 by the response data transmission unit 340 of the response device 300. The response data determination unit 260 compares the response data 331 with the response data expected value 231 generated by the expected value generation unit 230. The authentication device 200 authenticates the device under authentication as genuine if the response data 331 and the response data expected value 231 match perfectly, or if a certain number of bits match between the response data 331 and the response data expected value 231.
[0054] As described above, when authenticating electronic devices using their unique electromagnetic characteristics, challenge data corresponding to the unique electromagnetic characteristics of the device to be authenticated is randomly generated each time an authentication request occurs, transmitted over the communication network, and authentication is performed using response data corresponding to the challenge data. Therefore, authentication can be performed over the communication network. Furthermore, even if the challenge data or response data is intercepted over the communication network, the device's unique electromagnetic characteristics are kept secret, thus preventing fraudulent authentication through impersonation or other means.
[0055] Embodiment 2. For embodiments 2 and later, we will omit redundant explanations regarding commonalities with Embodiment 1 and focus on explaining the differences from Embodiment 1.
[0056] The overall configuration diagram of the authentication system equipped with an authentication device and a response device according to Embodiment 2 is shown in Figure 1, similar to Embodiment 1.
[0057] In Embodiment 2, the challenge data generation unit 220 may generate a pair [Xn,Y] (where n is an integer) of multiple X-axis values (Xn; the X-axis is, for example, frequency or time) of the electromagnetic characteristic EMCr and a single Y-axis threshold (Y) common to the multiple X-axis values, as challenge data each time an authentication request occurs.
[0058] The challenge data generation unit 220 may randomly generate multiple X-axis values Xn and a common, single Y-axis threshold Y each time an authentication request occurs.
[0059] The expected value generation unit 230 compares the Y-axis threshold Y with the Y-axis values of multiple X-axis values Xn of the electromagnetic characteristic 211 to determine which is larger, the Y-axis threshold Y or the Y-axis values of the electromagnetic characteristic 211.
[0060] The response data generation unit 330 compares the Y-axis threshold Y with the Y-axis values of multiple X-axis values Xn of the electromagnetic characteristic 311 to determine which is larger, the Y-axis threshold Y or the Y-axis value of the electromagnetic characteristic 311.
[0061] By generating challenge data in this way, it is possible to reduce the amount of challenge data compared to Embodiment 1.
[0062] Embodiment 3. The overall configuration diagram of the authentication system equipped with an authentication device and a response device according to Embodiment 3 is shown in Figure 1, similar to Embodiment 1.
[0063] In Embodiment 3, it is assumed that multiple X-axis values are shared in advance between the authentication device 200 and the response device 300. The challenge data generation unit 220 obtains the multiple shared X-axis values by referencing memory. The multiple shared X-axis values may always be the same, or they may be changed according to predetermined rules each time an authentication request occurs.
[0064] When multiple X-axis values are shared in this manner, the challenge data generation unit 220 may generate multiple shared X-axis values Xn for the X-axis, which are fixed values shared in advance by the authentication device 200 and the response device 300, or variable values generated and shared using a common tool each time an authentication request is made. For the Y-axis, it may generate multiple Y-axis thresholds Yn that are different from each other for the multiple shared X-axis values.
[0065] Alternatively, the challenge data transmission unit 240 may transmit only the Y-axis thresholds Yn generated by the challenge data generation unit 220, out of the multiple X-axis values Xn and multiple Y-axis thresholds Yn, as [Yn] (where n is an integer).
[0066] This configuration allows for a further reduction in the amount of challenge data compared to Embodiment 2.
[0067] Embodiment 4. The overall configuration diagram of the authentication system equipped with an authentication device and a response device according to Embodiment 4 is shown in Figure 1, similar to Embodiment 1.
[0068] In Embodiment 4, it is assumed that multiple X-axis values are shared in advance between the authentication device 200 and the response device 300. The challenge data generation unit 220 obtains the multiple shared X-axis values by referencing memory. The multiple shared X-axis values may always be the same, or they may be changed according to a certain rule each time an authentication request occurs.
[0069] When multiple X-axis values are shared in this manner, the challenge data generation unit 220 may generate multiple shared X-axis values Xn for the X-axis, which are fixed values shared in advance by the authentication device 200 and the response device 300, or variable values that are generated and shared using a common tool each time an authentication request is made. For the Y-axis, it may generate a common and single Y-axis threshold Y for the multiple shared X-axis values Xn.
[0070] Alternatively, the challenge data transmission unit 240 may transmit only the single Y-axis threshold Y generated from the multiple X-axis values Xn and the single Y-axis threshold Y as [Y].
[0071] This configuration allows for a significant reduction in the amount of challenge data.
[0072] Embodiment 5. The overall configuration diagram of the authentication system equipped with an authentication device and a response device according to Embodiment 5 is shown in Figure 1, similar to Embodiment 1.
[0073] In Embodiment 5, the challenge data generation unit 220 may randomly generate the Y-axis threshold value for the X-axis value of the electromagnetic characteristic EMCr outside a certain percentage range, for example, outside the range of ±10% of the Y value of the electromagnetic characteristic EMCr. The challenge data generation unit 220 in Embodiments 1 to 3 may also generate the Y-axis threshold value outside a certain percentage range.
[0074] This allows for a reduction in the impact on threshold determination even if electromagnetic characteristics (EMCi) change slightly due to environmental changes or aging.
[0075] Embodiment 6. The overall configuration diagram of the authentication system equipped with an authentication device and a response device according to Embodiment 6 is shown in Figure 1, similar to Embodiment 1.
[0076] In Embodiment 6, the expected value generation unit 230 and the response data generation unit 330 may use a predetermined rule to calculate the result of a bit string obtained by comparing the generated X-axis value with the Y-axis threshold as the response data. For example, the expected value generation unit 230 and the response data generation unit 330 may encode or encrypt the bit string obtained by the comparison. The expected value generation unit 230 and the response data generation unit 330 in Embodiments 1 to 5 may operate similarly.
[0077] This makes it difficult to estimate the electromagnetic characteristics (EMCi) or EMCr) of the authenticated device, even if the challenge data and response data are intercepted multiple times.
[0078] Furthermore, it is possible to combine embodiments, or to modify or omit each embodiment as appropriate. [Industrial applicability]
[0079] The authentication system described herein can be used as an authentication system for devices to be authenticated via a communication network. [Explanation of Symbols]
[0080] 100 Authenticated device, 200 Authentication device, 203 Expected value generation unit, 210 Electromagnetic characteristic acquisition unit (first electromagnetic characteristic acquisition unit), 211 Electromagnetic characteristic EMCr, 220 Challenge data generation unit, 221 Challenge data, 230 Expected value generation unit, 231 Response data expected value, 240 Challenge data transmission unit, 250 Response data reception unit, 260 Response data determination unit, 300 Response device, 310 Electromagnetic characteristic acquisition unit (second electromagnetic characteristic acquisition unit), 311 Electromagnetic characteristic EMCi, 320 Challenge data reception unit, 330 Response data generation unit, 331 Response data, 340 Response data transmission unit, 400 Communication network, 500 Storage device, 600 Processing circuit, 700 Processor, 800 Memory.
Claims
1. A response data determination unit that determines the authenticity of the second device by comparing an expected value of response data corresponding to challenge data generated from the electromagnetic characteristics of the first device to be authenticated, corresponding to at least one electromagnetic characteristic of the first device to be authenticated, with the electromagnetic characteristics of the second device to be authenticated and the response data corresponding to the challenge data, The electromagnetic characteristics of the first certified device and the electromagnetic characteristics of the second certified device are characteristics that can be represented as a two-dimensional graph consisting of an X axis and a Y axis. The aforementioned challenge data is generated as a set [Xn, Yn] (where n is an integer) of multiple X-axis values Xn and a Y-axis threshold Yn for each X-axis value. Authentication device.
2. The Y-axis threshold Yn of the challenge data is a single Y-axis threshold Y that is common to all of the multiple X-axis values. The authentication device described in claim 1.
3. An authentication device according to claim 1, The challenge data is transmitted to the response device. The response data is received after being generated in the response device. The X-axis value Xn of the challenge data is a set of shared X-axis values Xn, which are either fixed values shared in advance between the authentication device and the response device, or variable values generated and shared using a common tool each time an authentication request is made. The Y-axis threshold Yn of the challenge data is a plurality of Y-axis thresholds Yn that are different from each other for the plurality of shared X-axis values. The authentication device transmits only the Y-axis threshold Yn from the plurality of X-axis values Xn and the plurality of Y-axis thresholds Yn as [Yn] (where n is an integer). The authentication device described in claim 1.
4. An authentication device according to claim 1, The challenge data is transmitted to the response device. The response data is received after being generated in the response device. The X-axis value Xn of the challenge data is a set of shared X-axis values Xn, which are either fixed values shared in advance between the authentication device and the response device, or variable values generated and shared using a common tool each time an authentication request is made. The Y-axis threshold Yn of the challenge data is a single Y-axis threshold Y that is common to the multiple shared X-axis values Xn. The authentication device transmits only the single Y-axis threshold Y from the plurality of X-axis values Xn and the single Y-axis threshold Y as [Y]. The authentication device described in claim 1.
5. The plurality of X-axis values Xn and some or all of the Y-axis threshold Yn for each X-axis value are random values each time an authentication request occurs. An authentication device as described in either claim 1 or claim 3.
6. The plurality of X-axis values Xn and some or all of the Y-axis threshold Y for each X-axis value are set to random values each time an authentication request occurs. An authentication device according to either claim 2 or claim 4.
7. The authentication device described in claim 1, A response device that receives the challenge data and sends the response data to the authentication device, An authentication system equipped with [specific features / features].
8. The response device and the second device to be authenticated are integrated. The authentication system described in claim 7.
9. A step in which the response data determination unit compares an expected response data value corresponding to challenge data generated from the electromagnetic characteristics of the first device to be authenticated, which corresponds to at least one electromagnetic characteristic of the first device to be authenticated, with the electromagnetic characteristics of the second device to be authenticated and the response data corresponding to the challenge data, and determines the authenticity of the second device to be authenticated. Equipped with, The electromagnetic characteristics of the first certified device and the electromagnetic characteristics of the second certified device are characteristics that can be represented as a two-dimensional graph consisting of an X axis and a Y axis. The aforementioned challenge data is generated as a set [Xn, Yn] (where n is an integer) of multiple X-axis values Xn and a Y-axis threshold Yn for each X-axis value. Authentication method.
Citation Information
Patent Citations
Device authentication system and method of controlling power feeding
JP2011150662A
Electronic circuit, authentication device, and authentication system
JP2016171452A
Battery control IC, battery pack and authentication method for the same
JP2016192840A
Solid-state imaging device, solid-state imaging device drive method, and electronic device
JP2020145533A
JPP7154444B