Communication system, configuration terminal and program
The communication system addresses security vulnerabilities by generating device-specific common keys through encrypted protocols, ensuring secure communication and preventing unauthorized access to home appliances.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2022-03-08
- Publication Date
- 2026-05-15
AI Technical Summary
Existing communication systems between home appliances and terminals face security vulnerabilities due to the risk of unauthorized access when common keys or passwords are disclosed, allowing third parties to easily access the appliances.
A communication system that includes a setting terminal, a communication device, and a server, utilizing identification information acquisition, password acquisition, and common key generation mechanisms to establish secure communication by generating a common key based on unique device-specific information and encrypted communication protocols.
This system enables secure communication with devices and prevents unauthorized access by third parties, reducing the impact of common key leaks through device-specific key generation.
Smart Images

Figure 0007859841000001 
Figure 0007859841000002 
Figure 0007859841000003
Abstract
Description
Technical Field
[0004] ,
[0006] , , ,
[0005] , , , ,
[0001] The present disclosure relates to a communication system, a setting terminal, and a program.
Background Art
[0002] In recent years, technologies that connect home appliances inside a house to a home network and enable various settings and controls of the home appliances through operations by a user via terminals such as a smartphone and a tablet terminal have been well known (for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the above case, it is preferable that the exchange of data between the terminal and the home appliance is performed by encrypted communication using a common key for security. However, there is a problem that if the common key or the password for generating the common key is directly disclosed, a third party can easily access the home appliance.
[0005] The present disclosure has been made to solve the above problems, and an object thereof is to provide a communication system, a setting terminal, and a program capable of establishing secure communication with a device and preventing unauthorized access to the device by a third party.
Means for Solving the Problems
[0006] To achieve the above object, the communication system according to the present disclosure includes a setting terminal, a communication device, and a server, wherein the setting terminal An identification information acquisition means for acquiring identification information of the aforementioned communication device, A password acquisition means that notifies the server of the identification information and obtains a password from the server for generating a common key to be used for communication with the communication device, A means for acquiring generation factor information that acquires generation factor information that is the generation factor of the aforementioned common key, A means for notifying the communication device of the generation factor information, The system comprises a common key generation means that generates the common key based on the password and the generation factor information, The aforementioned communication equipment is A password storage means for storing a password corresponding to the aforementioned communication device, The system comprises a common key generation means that generates a common key used for communication with the setting terminal based on the password stored in the password storage means and the generation factor information notified from the setting terminal, The aforementioned server, A device management information storage means that stores device management information linking the identification information of the communication device with the password of the communication device, The system includes a password notification means that, upon receiving notification of the identification information from the setting terminal, notifies the setting terminal of the password corresponding to the identification information. [Effects of the Invention]
[0007] According to this disclosure, it becomes possible to establish secure communication with the device and prevent unauthorized access to the device by third parties. [Brief explanation of the drawing]
[0008] [Figure 1] Diagram showing the overall configuration of the communication system in Embodiment 1. [Figure 2] Block diagram showing the server hardware configuration in Embodiment 1 [Figure 3] Block diagram showing the hardware configuration of the setting terminal in Embodiment 1 [Figure 4]Block diagram showing the hardware configuration of the device in Embodiment 1 [Figure 5] Diagram showing the functional configuration of the setting terminal in Embodiment 1 [Figure 6] Diagram for explaining the information storage medium in Embodiment 1 [Figure 7] Diagram showing the functional configuration of the server in Embodiment 1 [Figure 8] Diagram showing the functional configuration of the device in Embodiment 1 [Figure 9] Flowchart showing the procedure of the communication setting process executed by the setting terminal in Embodiment 1 [Figure 10] Flowchart showing the operation of the server during the communication setting process in Embodiment 1 [Figure 11] Flowchart showing the operation of the device during the communication setting process in Embodiment 1 [Figure 12] Diagram showing the overall configuration of the communication system in Embodiment 2 [Figure 13] Diagram showing the functional configuration of the setting terminal in Embodiment 2 [Figure 14] Diagram showing the functional configuration of the server in Embodiment 2 [Figure 15] Diagram showing the functional configuration of the device in Embodiment 2
Embodiments for Carrying Out the Invention
[0009] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings.
[0010] (Embodiment 1) FIG. 1 is a diagram showing the overall configuration of a communication system 1 in Embodiment 1. The communication system 1 is an example of a communication system according to the present disclosure. The communication system 1 is a system that enables remote monitoring of the state of a device 4 installed in a house H and also enables various settings and operation controls for the device 4 by a setting terminal 3. As shown in FIG. 1, the communication system 1 includes a server 2, a setting terminal 3, and a device 4.
[0011] <Server 2> Server 2 is an example of a server related to this disclosure. Server 2 is a so-called cloud server installed by the manufacturer, sales company, etc., of device 4. Server 2 provides a service to remotely monitor the status of device 4 and to remotely control device 4.
[0012] As shown in Figure 2, Server 2 comprises a control circuit 20, a communication interface 21, and an auxiliary storage device 22 as its hardware configuration. The control circuit 20 comprehensively controls Server 2. Although not shown in the figures, the control circuit 20 includes a CPU (Central Processing Unit), ROM (Read Only Memory), and RAM (Random Access Memory). Details of the functions of Server 2 realized by the control circuit 20 will be described later.
[0013] The communication interface 21 is an interface for communicating with other devices, including the configuration terminal 3 and the device 4, and is, for example, an interface based on Ethernet®.
[0014] The auxiliary storage device 22 is an example of a device management information storage means related to this disclosure. The auxiliary storage device 22 is composed of a read / write non-volatile semiconductor memory, an HDD (Hard Disk Drive), etc. Examples of read / write non-volatile semiconductor memory include EEPROM (Electrically Erasable Programmable Read-Only Memory) and flash memory. The auxiliary storage device 22 stores a communication management program, which is a program that manages communication between the setting terminal 3 and the device 4, a remote monitoring and control program, which is a program that realizes remote monitoring and remote control of the device 4, and data used when these programs are executed.
[0015] Server 2 can obtain communication management programs and remote monitoring and control programs from other servers via communication. These programs can also be distributed on computer-readable storage media such as CD-ROMs (Compact Disc Read Only Memory), DVDs (Digital Versatile Discs), magneto-optical disks, USB (Universal Serial Bus) memory, HDDs, SSDs (Solid State Drives), and memory cards. When such storage media are directly or indirectly attached to Server 2, it can read and acquire the communication management programs and remote monitoring and control programs from those media.
[0016] <Settings Terminal 3> The configuration terminal 3 is an example of a configuration terminal related to this disclosure. The configuration terminal 3 is an electronic device such as a smartphone or tablet owned by a user living in a residence H. As shown in Figure 3, the configuration terminal 3 has a hardware configuration comprising a control circuit 30, a first communication interface 31, a second communication interface 32, a display 33, an operation reception unit 34, an image sensor 35, and an auxiliary storage device 36.
[0017] The control circuit 30 comprehensively controls the setting terminal 3. Although not shown in the diagram, the control circuit 30 includes a CPU, ROM, and RAM. Details of the functions of the setting terminal 3 realized by the control circuit 30 will be described later.
[0018] The first communication interface 31 is an interface for communicating with the server 2, and is, for example, an interface for wireless LAN (Local Area Network) communication, LTE (Long Term Evolution) communication, 5G (Fifth Generation Mobile Communication System) communication, etc.
[0019] The second communication interface 32 is an interface for communicating with the device 4, and is an interface for performing, for example, wireless LAN communication, BLE (Bluetooth® Low Energy) communication, sound wave communication, NFC (Near Field Communication), etc.
[0020] The display 33 is comprised of display devices such as liquid crystal displays and organic EL (Electro-Luminescence) displays. The display 33 displays various screens and the like under the control of the control circuit 30. The operation reception unit 34 is comprised of one or more input devices such as push buttons, touch panels, and touchpads, and receives operation input from the user and outputs signals related to the received operation to the control circuit 30.
[0021] The image sensor 35 is an image sensor such as a CCD (Charge-Coupled Device) or CMOS (Complementary Metal Oxide Semiconductor).
[0022] The auxiliary storage device 36 is a storage device composed of read-write non-volatile semiconductor memory. Examples of read-write non-volatile semiconductor memory include EEPROM and flash memory. The auxiliary storage device 36 stores various programs, including application programs (hereinafter referred to as "device operation apps") that establish secure communication with the device 4 and enable various setting operations, operation control operations, etc., on the device 4, as well as data used when these programs are executed.
[0023] The configuration terminal 3 can obtain the above-mentioned device operation application or update programs for updating the device operation application via communication from server 2 or other servers. These programs can also be distributed on computer-readable storage media such as CD-ROMs, DVDs, magneto-optical disks, USB memory sticks, HDDs, SSDs, and memory cards. If such a storage media is directly or indirectly attached to the configuration terminal 3, it can read and obtain the device operation application or update programs from that storage media.
[0024] <Device 4> Device 4 is an example of a communication device related to this disclosure. Device 4 is a home appliance that is, for example, a so-called IoT (Internet of Things) device, information appliance, network appliance, smart appliance, etc. As shown in Figure 4, device 4 has a hardware configuration that includes a control circuit 40, a first communication interface 41, a second communication interface 42, and an auxiliary storage device 43. In addition, device 4 also includes hardware to realize its original functions (for example, in the case of an air conditioner, the function of adjusting the air temperature; in the case of a television, the function of receiving television broadcasts, the function of outputting video and audio, etc.).
[0025] The control circuit 40 consists of a CPU, ROM, and RAM (none of which are shown), and comprehensively controls the device 4. Details of the functions of the device 4 realized by the control circuit 40 will be described later.
[0026] The first communication interface 41 is an interface for communicating with the device 4, and is, for example, an interface for wireless LAN communication, BLE communication, sound wave communication, NFC, etc. The second communication interface 42 is an interface for communicating with the server 2, and is, for example, an interface for wireless LAN communication.
[0027] The auxiliary storage device 43 is composed of, for example, a read / write non-volatile semiconductor memory, an HDD, etc. Examples of read / write non-volatile semiconductor memory include EEPROM and flash memory. The auxiliary storage device 43 stores various programs, including a communication control program which is a program for controlling communication with the server 2 and the configuration terminal 3, and data used when these programs are executed.
[0028] Device 4 can obtain the above-mentioned communication control program or update programs for updating the communication control program via communication from Server 2 or other servers. These programs can also be distributed on computer-readable recording media such as CD-ROMs, DVDs, magneto-optical disks, USB memory sticks, HDDs, SSDs, and memory cards. When such recording media are directly or indirectly attached to Device 4, it can read and obtain the communication control program or update program from the recording media.
[0029] <Functional configuration of setting terminal 3> Figure 5 shows the functional configuration of the configuration terminal 3. As shown in Figure 5, the configuration terminal 3 comprises a device information acquisition unit 300, an authentication request unit 301, an electronic signature notification unit 302, a password acquisition unit 303, a generation factor information acquisition unit 304, a generation factor information notification unit 305, a first common key generation unit 306, a second common key acquisition unit 307, and a second common key notification unit 308. These functional units are realized when the control circuit 30 of the configuration terminal 3 executes the device operation application stored in the auxiliary storage device 36.
[0030] The device information acquisition unit 300 is an example of an identification information acquisition means according to this disclosure. The device information acquisition unit 300 acquires the device ID (identifier), which is the identification information of the device 4, and connection information for connecting to the device 4. In this embodiment, as shown in Figure 6, an information holder 44 is affixed to the surface of the housing of the device 4, on which a matrix-type two-dimensional code 440 containing the device ID and connection information of the device 4 is printed. The device information acquisition unit 300 acquires the device ID and connection information by decoding the two-dimensional code 440 captured by the image sensor 35.
[0031] The authentication request unit 301 is an example of a means for obtaining an electronic signature related to this disclosure. The authentication request unit 301 communicates with the server 2 via the first communication interface 31 using encrypted communication such as SSL (Secure Sockets Layer) or TLS (Transport Layer Security), transmits user identification information to identify the user of the configuration terminal 3, and requests user authentication from the server 2. Subsequently, when the server 2 issues an electronic signature indicating that the legitimacy of the user has been confirmed, the authentication request unit 301 obtains the electronic signature.
[0032] The electronic signature notification unit 302 is an example of an electronic signature notification means related to this disclosure. The electronic signature notification unit 302 notifies the device 4 of the electronic signature obtained by the authentication request unit 301 via the second communication interface 32.
[0033] The password acquisition unit 303 is an example of a password acquisition means related to this disclosure. The password acquisition unit 303 communicates with the server 2 using the encrypted communication described above, notifies the server 2 of the device ID of device 4 acquired by the device information acquisition unit 300, and queries the server 2 for a password, thereby obtaining a password from the server 2 for generating a first common key, which is a common key used for communication with the device 4.
[0034] The generation factor information acquisition unit 304 is an example of a means for acquiring generation factor information related to this disclosure. The generation factor information acquisition unit 304 acquires generation factor information that will be the generation factor of the first common key. For example, the generation factor information acquisition unit 304 acquires time information indicating the current time from a clock function (not shown) provided by the control circuit 30 as generation factor information. Alternatively, the generation factor information acquisition unit 304 generates a random number and acquires the generated random number as generation factor information.
[0035] The generation factor information notification unit 305 is an example of a generation factor information notification means related to this disclosure. The generation factor information notification unit 305 notifies the device 4 of the generation factor information acquired by the generation factor information acquisition unit 304 via the second communication interface 32.
[0036] The first common key generation unit 306 is an example of a common key generation means related to this disclosure. The first common key generation unit 306 generates a first common key based on the password obtained by the password acquisition unit 303 and the generation factor information described above. Thereafter, the setting terminal 3 exchanges data with the device 4 using secure encrypted communication with the first common key.
[0037] The second symmetric key acquisition unit 307 communicates with server 2 using encrypted communication such as SSL or TLS, notifies server 2 of the device ID of device 4 acquired by device information acquisition unit 300, and queries server 2 for the second symmetric key. As a result, it obtains the second symmetric key from server 2, which is the symmetric key used for communication between device 4 and server 2.
[0038] The second symmetric key notification unit 308 performs encrypted communication with device 4 using the first symmetric key and notifies device 4 of the second symmetric key acquired by the second symmetric key acquisition unit 307.
[0039] <Server 2 Functional Configuration> Figure 7 shows the functional configuration of Server 2. As shown in Figure 7, Server 2 includes a user authentication unit 200, a password notification unit 201, and a second common key notification unit 202 as characteristic functional configurations related to this disclosure. These functional units are realized when the control circuit 20 of Server 2 executes the communication management program described above, which is stored in the auxiliary storage device 22. In addition, Server 2 also has functions for remote monitoring and remote control of the device 4, but such functions will not be explained here.
[0040] The user authentication unit 200 is an example of an electronic signature issuance means related to this disclosure. When the user authentication unit 200 receives a user authentication request from the configuration terminal 3, it authenticates the user. Specifically, the user authentication unit 200 determines whether the user is a legitimate user by comparing the user identification information transmitted from the configuration terminal 3 with the user identification information of each user that has been registered in advance by each user and stored in the auxiliary storage device 22. If the user authentication unit 200 determines that the user is a legitimate user, it generates an electronic signature using a private key and issues it to the configuration terminal 3. On the other hand, if it determines that the user is not a legitimate user, the user authentication unit 200 does not issue an electronic signature to the configuration terminal 3.
[0041] The password notification unit 201 is an example of a password notification means related to this disclosure. When the password notification unit 201 receives a device ID notification from the setting terminal 3 and receives a password inquiry, it retrieves the password corresponding to the device ID from the device management information stored in the auxiliary storage device 22 and notifies the setting terminal 3 of the retrieved password. The device management information is information that links the device ID, password, and second common key for each device 4.
[0042] When the second common key notification unit 202 receives notification of the device ID from the configuration terminal 3 and receives an inquiry for the second common key, it obtains the second common key corresponding to the device ID from the device management information stored in the auxiliary storage device 22 and notifies the configuration terminal 3 of the obtained second common key.
[0043] <Functional Configuration of Device 4> Figure 8 shows the functional configuration of device 4. As shown in Figure 8, device 4 comprises an electronic signature verification unit 400, a first common key generation unit 401, and a server communication establishment unit 402 as characteristic functional configurations related to this disclosure. These functional units are realized when the control circuit 40 of device 4 executes the above-mentioned communication control program stored in the auxiliary storage device 43.
[0044] The electronic signature verification unit 400 is an example of an electronic signature verification means related to this disclosure. The electronic signature verification unit 400 verifies the validity of the electronic signature notified from the setting terminal 3 using a public key that is stored in advance in the auxiliary storage device 43.
[0045] The first common key generation unit 401 is an example of a common key generation means related to this disclosure. When the first common key generation unit 401 receives notification of generation factor information from the setting terminal 3, it generates a first common key based on its own password, i.e., the password corresponding to the device 4, and the notified generation factor information. The password is stored in advance in the auxiliary storage device 43. The auxiliary storage device 43 of the device 4 is an example of a password storage means related to this disclosure. The first common key generated here is the same as the first common key generated by the setting terminal 3. The first common key generation unit 401 generates the first common key only if the electronic signature verification unit 400 verifies that the electronic signature notified from the setting terminal 3 is legitimate. Thereafter, the device 4 exchanges data with the setting terminal 3 using secure encrypted communication with the first common key.
[0046] The server communication establishment unit 402 establishes secure encrypted communication with server 2 using the second symmetric key notified from the configuration terminal 3 via encrypted communication using the first symmetric key.
[0047] <Communication settings processing> Figure 9 is a flowchart showing the steps of the communication setup process performed by the configuration terminal 3. The communication setup process is executed when the user initiates the communication setup operation in the device operation application.
[0048] (Step S100) The configuration terminal 3 obtains the device ID and connection information of device 4 by decoding the two-dimensional code 440 captured by the image sensor 35. After that, the configuration terminal 3 proceeds to step S101.
[0049] (Step S101) The configuration terminal 3 requests user authentication from the server 2. Subsequently, the processing of the configuration terminal 3 proceeds to step S102.
[0050] (Step S102) Configuration terminal 3 obtains the digital signature issued by server 2. Subsequently, the processing of configuration terminal 3 proceeds to step S103.
[0051] (Step S103) The configuration terminal 3 notifies the device 4 of the acquired electronic signature. Subsequently, the processing of the configuration terminal 3 proceeds to step S104.
[0052] (Step S104) The configuration terminal 3 obtains a password to generate the first common key, which is a common key used for communication between the server 2 and the device 4. After that, the configuration terminal 3 proceeds to step S105.
[0053] (Step S105) The configuration terminal 3 obtains generation factor information (e.g., time information, random numbers, etc.) that will be used to generate the first common key. After that, the processing of the configuration terminal 3 proceeds to step S106.
[0054] (Step S106) The configuration terminal 3 notifies the device 4 of the acquired generation factor information. Subsequently, the processing of the configuration terminal 3 proceeds to step S107.
[0055] (Step S107) The configuration terminal 3 generates a first common key based on the password obtained from server 2 and the obtained generation factor information. Subsequently, the configuration terminal 3 proceeds to step S108.
[0056] (Step S108) The configuration terminal 3 obtains the second common key from the server 2, which is the common key used for communication between the device 4 and the server 2. After that, the configuration terminal 3 proceeds to step S109.
[0057] (Step S109) The configuration terminal 3 notifies device 4 of the second common key obtained from server 2. After that, the configuration terminal 3 terminates the communication configuration process.
[0058] <Operational flow of Server 2> Figure 10 is a flowchart showing the operation of Server 2 during the above communication configuration process of Configuration Terminal 3.
[0059] (Step S200) When Server 2 receives a user authentication request from Configuration Terminal 3, it authenticates the user. After that, Server 2's processing proceeds to step S201.
[0060] (Step S201) If Server 2 determines that the user is a legitimate user, it generates an electronic signature using the private key and issues the generated electronic signature to the configuration terminal 3. After that, Server 2's processing proceeds to step S202.
[0061] (Step S202) When Server 2 receives notification of the device ID from the configuration terminal 3 and is inquired about the password, it retrieves the password corresponding to the device ID from the device management information stored in the auxiliary storage device 22 and notifies the configuration terminal 3 of the retrieved password. After that, Server 2's processing proceeds to step S203.
[0062] (Step S203) When Server 2 receives notification of the device ID from Configuration Terminal 3 and is inquired about the second common key, it retrieves the second common key corresponding to the device ID from the device management information stored in the auxiliary storage device 22 and notifies Configuration Terminal 3 of the retrieved second common key. After that, Server 2's operation during Configuration Terminal 3's communication configuration process ends.
[0063] <Operation Flow of Device 4> Figure 11 is a flowchart showing the operation of device 4 during the above communication setting process of setting terminal 3.
[0064] (Step S300) Device 4 receives and acquires the electronic signature notified from the configuration terminal 3. Subsequently, the processing of device 4 proceeds to step S301.
[0065] (Step S301) Device 4 verifies the validity of the electronic signature using the public key previously stored in the auxiliary storage device 43. After that, the processing of device 4 proceeds to step S302.
[0066] (Step S302) Device 4 receives and acquires the generation cause information notified from the configuration terminal 3. Subsequently, the processing of device 4 proceeds to step S303.
[0067] (Step S303) Device 4 generates a first symmetric key based on the password corresponding to Device 4 and the generation factor information obtained from the configuration terminal 3. Device 4 generates the first symmetric key only if the electronic signature obtained from the configuration terminal 3 is verified to be legitimate. After that, the processing of Device 4 proceeds to step S304.
[0068] (Step S304) Device 4 receives and acquires the second common key notified from the configuration terminal 3. Subsequently, the processing of device 4 proceeds to step S305.
[0069] (Step S305) Device 4 uses the second common key obtained from configuration terminal 3 to establish secure encrypted communication with server 2. After that, device 4's operation during the communication configuration process on configuration terminal 3 is terminated.
[0070] As described above, in the communication system 1 of this embodiment, the configuration terminal 3 obtains a password corresponding to the device 4 from the server 2 and generates a first common key used for communication with the device 4 based on the obtained password. This makes it possible to establish secure communication with the device 4 and prevent unauthorized access to the device 4 by third parties.
[0071] Furthermore, since a first common key is generated for each device (4), the impact of the first common key being leaked can be reduced.
[0072] (Variation 1) Device 4 may also be a communication adapter that is electrically connected to a consumer electronics appliance via an interface conforming to a standardized serial communication protocol.
[0073] (Modification 2) The two-dimensional code 440 may be directly drawn on the surface of the housing of the device 4 by paint, engraving, etc., or, if the device 4 is equipped with a display device, it may be displayed on the display device.
[0074] (Variation 3) The two-dimensional code 440 is not limited to a matrix-type two-dimensional code, but may also be a stack-type two-dimensional code. Alternatively, the device ID and connection information of device 4 may be indicated by a one-dimensional code.
[0075] (Modification 4) The information holder 44 may be configured to include an IC tag, and the IC tag may transmit a wireless signal containing the device ID and connection information of the device 4. In this case, the setting terminal 3 obtains the device ID and connection information of the device 4 by receiving the wireless signal transmitted from the IC tag.
[0076] (Variation 5) The configuration terminal 3 further includes a password update unit (an example of a password update means related to this disclosure) (not shown) that updates the password corresponding to the device 4, and a password update notification unit (an example of a password update notification means related to this disclosure) (not shown) that notifies the device 4 and server 2 of the updated password. The generation factor information acquisition unit 304 may acquire the generation factor information again after the password has been updated, the generation factor information notification unit 305 may notify the device 4 of the generation factor information acquired again, and the first common key generation unit 306 may update the first common key based on the updated password and the generation factor information acquired again. The timing of when the password update unit updates the password is an arbitrary design matter.
[0077] In this case, device 4 stores the password notified from the configuration terminal 3 as the password corresponding to device 4 in the auxiliary storage device 43, and the first common key generation unit 401 updates the first common key based on the notified password and the notified generation factor information. Furthermore, server 2 is equipped with a device management information update unit (an example of a device management information update means related to this disclosure) (not shown) that updates the device management information when it receives a password notification from the configuration terminal 3.
[0078] This configuration reduces the risk of unauthorized access to device 4 due to password leaks.
[0079] (Experimental variation 6) Server 2 may further include a password update unit (an example of password update means related to this disclosure) (not shown) that updates the password corresponding to device 4, and a password update notification unit (an example of password update notification means related to this disclosure) (not shown) that notifies device 4 of the updated password via setting terminal 3, or directly notifies device 4. The timing of when the password update unit updates the password is an arbitrary design matter.
[0080] In this case, device 4 stores the password notified by server 2 as the password corresponding to device 4 in the auxiliary storage device 43.
[0081] This configuration reduces the risk of unauthorized access to device 4 due to password leaks.
[0082] (Example 7) Device 4 may further include a password update unit (not shown) that updates the password corresponding to itself, and a password update notification unit (not shown) that notifies the server 2 of the updated password via the setting terminal 3, or directly via the second communication interface 42. The timing of when the password update unit updates the password is an arbitrary design matter.
[0083] In this case, server 2 further includes a device management information update unit (not shown) that updates the device management information when it receives a password notification from device 4.
[0084] This configuration reduces the risk of unauthorized access to device 4 due to password leaks.
[0085] (Variation 8) All or part of the functional components of the configuration terminal 3 (see Figure 5) may be implemented using dedicated hardware. Similarly, all or part of the functional components of the server 2 (see Figure 7) may be implemented using dedicated hardware. Furthermore, all or part of the functional components of the device 4 (see Figure 8) may be implemented using dedicated hardware. Dedicated hardware includes, for example, single circuits, complex circuits, programmed processors, ASICs (Application Specific Integrated Circuits), FPGAs (Field-Programmable Gate Arrays), or combinations thereof.
[0086] The technical concepts related to each of the above modifications may be implemented individually or in combination as appropriate.
[0087] (Embodiment 2) Next, Embodiment 2 of this disclosure will be described. In the following description, components and the like that are common to Embodiment 1 will be denoted by the same reference numerals, and their descriptions will be omitted.
[0088] Figure 12 shows the overall configuration of the communication system 1A in Embodiment 2. The communication system 1A is an example of a communication system according to the present disclosure. The communication system 1A is a system that enables remote monitoring of the status of equipment 4A installed in a house H, and also enables various settings and operation control of equipment 4A via a setting terminal 3A. As shown in Figure 12, the communication system 1A comprises a server 2A, a setting terminal 3A, and equipment 4A.
[0089] <Server 2A> Server 2A is an example of a server related to this disclosure. Server 2A is a so-called cloud server installed by the manufacturer, sales company, etc., of equipment 4A. Server 2A remotely monitors the status of equipment 4A and provides a service for remotely controlling equipment 4A. The hardware configuration of Server 2A is the same as that of Server 2 in Embodiment 1 (see Figure 2). Details of the functions of Server 2A will be described later.
[0090] <Setting terminal 3A> The configuration terminal 3A is an example of a configuration terminal related to this disclosure. The configuration terminal 3A is an electronic device such as a smartphone or tablet owned by a user living in residence H. The hardware configuration of the configuration terminal 3A is the same as that of the configuration terminal 3 in Embodiment 1 (see Figure 3). Details of the functions of the configuration terminal 3A will be described later.
[0091] <Device 4A> Device 4A is an example of a communication device related to this disclosure. Device 4A is, for example, a home appliance that is also known as an IoT device, information appliance, network appliance, smart appliance, etc. The hardware configuration of device 4A is the same as that of device 4 in Embodiment 1 (see Figure 4). Details of the functions of device 4A will be described later.
[0092] <Functional Configuration of Configuration Terminal 3A> Figure 13 shows the functional configuration of the setting terminal 3A. As shown in Figure 13, the setting terminal 3A comprises a device information acquisition unit 300, an authentication request unit 301, an electronic signature notification unit 302, a first common key acquisition unit 309, a second common key acquisition unit 307, and a second common key notification unit 308. These functional units are realized when the control circuit 30 of the setting terminal 3A executes a device operation application, which is an application program stored in the auxiliary storage device 36, enabling secure communication with the device 4A and allowing various setting operations, operation control operations, etc., to be performed on the device 4A.
[0093] The first common key acquisition unit 309 is an example of a common key acquisition means related to this disclosure. The first common key acquisition unit 309 communicates with server 2A using encrypted communication such as SSL or TLS, notifies server 2A of the device ID of device 4A acquired by device information acquisition unit 300, and queries server 2A for the first common key, thereby obtaining the first common key, which is the common key used for communication with device 4A, from server 2A.
[0094] <Functional Configuration of Server 2A> Figure 14 shows the functional configuration of server 2A. As shown in Figure 14, server 2A includes a user authentication unit 200, a first common key notification unit 203, and a second common key notification unit 202 as characteristic functional configurations related to this disclosure. These functional units are realized when the control circuit 20 of server 2A executes a communication management program, which is a program stored in the auxiliary storage device 22 that manages communication with the setting terminal 3A and the device 4A.
[0095] The first common key notification unit 203 is an example of a common key notification means according to this disclosure. When the first common key notification unit 203 receives notification of a device ID from the setting terminal 3A and receives an inquiry for the first common key, it obtains the first common key corresponding to the device ID from the device management information stored in the auxiliary storage device 22 and notifies the setting terminal 3A of the obtained first common key. In this embodiment, the device management information is information that links the device ID, the first common key, and the second common key for each device 4A.
[0096] <Functional Configuration of Device 4A> Figure 15 is a diagram showing the functional configuration of device 4A. As shown in Figure 15, device 4A comprises an electronic signature verification unit 400, a configuration terminal communication establishment unit 403, and a server communication establishment unit 402 as characteristic functional configurations related to this disclosure. These functional units are realized when the control circuit 40 of device 4A executes a communication control program, which is a program for controlling communication with server 2A and configuration terminal 3A, stored in the auxiliary storage device 43.
[0097] If the electronic signature notified by the configuration terminal 3A is verified by the electronic signature verification unit 400 to be legitimate, the configuration terminal communication establishment unit 403 establishes secure encrypted communication with the configuration terminal 3A using the first common key previously stored in the auxiliary storage device 43. The auxiliary storage device 43 of the device 4A is an example of a common key storage means related to this disclosure.
[0098] As described above, in the communication system 1A of this embodiment, the configuration terminal 3A obtains a first common key used for communication with device 4A from the server 2A. This enables the establishment of secure communication with device 4A and prevents unauthorized access to device 4A by third parties.
[0099] (Variation 1) Server 2A may further include a generation factor information acquisition unit (an example of generation factor information acquisition means) (not shown) that acquires generation factor information that is the cause of generating a first common key used between configuration terminal 3A and device 4A; a generation factor information notification unit (an example of generation factor information notification means related to this disclosure) (not shown) that notifies device 4A of the generated generation factor information via configuration terminal 3A or directly to device 4A; and a common key update unit (an example of common key update means related to this disclosure) (not shown) that updates the first common key based on the generated generation factor information. The timing at which the common key update unit updates the first common key is an arbitrary design matter.
[0100] In this case, device 4A further includes a shared key update unit (an example of a shared key update means according to this disclosure) (not shown) that updates the first shared key based on the generation factor information notified by server 2A. Alternatively, server 2A may notify device 4A of the updated first shared key via setting terminal 3A, or notify device 4A directly.
[0101] This configuration reduces the risk of unauthorized access to device 4A due to the leakage of the first common key.
[0102] (Modification 2) The device 4A may further include a generation factor information acquisition unit (not shown) that acquires generation factor information that is the cause of generating a first common key used with the configuration terminal 3A, a generation factor information notification unit (not shown) that notifies the server 2A of the generated generation factor information via the configuration terminal 3A, or notifies the server 2A directly, and a common key update unit (not shown) that updates the first common key based on the generated generation factor information. The timing at which the common key update unit updates the first common key is an arbitrary design matter.
[0103] In this case, server 2A further includes a shared key update unit (not shown) that updates the first shared key based on the generation factor information notified by device 4A. Alternatively, device 4A may notify server 2A of the updated first shared key via setting terminal 3A, or notify server 2A directly.
[0104] This configuration reduces the risk of unauthorized access to device 4A due to the leakage of the first common key.
[0105] (Variation 3) All or part of the functional unit of the configuration terminal 3A (see Figure 13) may be implemented using dedicated hardware. Similarly, all or part of the functional unit of the server 2A (see Figure 14) may be implemented using dedicated hardware. Furthermore, all or part of the functional unit of the device 4A (see Figure 15) may be implemented using dedicated hardware. Dedicated hardware may include, for example, a single circuit, a complex circuit, a programmed processor, an ASIC, an FPGA, or a combination thereof.
[0106] (Modification 4) Modifications 1 to 4 of Embodiment 1 can also be applied to this embodiment.
[0107] The technical concepts related to each of the above modifications may be implemented individually or in combination as appropriate.
[0108] This disclosure is not limited to the embodiments and modifications described above, and various modifications are certainly possible without departing from the spirit of this disclosure. [Explanation of Symbols]
[0109] 1,1A Communication system, 2,2A Server, 3,3A Configuration terminal, 4,4A Equipment, 20,30,40 Control circuits, 21 Communication interface, 22,36,43 Auxiliary storage device, 31,41 First communication interface, 32,42 Second communication interface, 33 Display, 34 Operation reception unit, 35 Image sensor, 44 Information holder, 200 User authentication unit, 201 Password notification unit, 202 Second common key notification unit, 203 First common key notification unit, 300 Equipment information acquisition unit, 301 Authentication request unit, 302 Electronic signature notification unit, 303 Password acquisition unit, 304 Generation factor information acquisition unit, 305 Generation factor information notification unit, 306,401 First common key generation unit, 307 Second common key acquisition unit, 308 Second common key notification unit, 309 First common key acquisition unit, 400 Electronic signature verification unit, 402 Server communication establishment unit, 403 Configuration terminal communication establishment unit, 440 Two-dimensional code
Claims
1. The system includes a configuration terminal, communication equipment, and a server. The aforementioned configuration terminal is An identification information acquisition means for acquiring identification information of the aforementioned communication device, A password acquisition means that notifies the server of the identification information and obtains a password from the server for generating a common key to be used for communication with the communication device, A means for acquiring generation factor information that acquires generation factor information that is the generation factor of the aforementioned common key, A means for notifying the communication device of the generation factor information, The system comprises a common key generation means that generates the common key based on the password and the generation factor information, The aforementioned communication equipment is A password storage means for storing a password corresponding to the aforementioned communication device, The system comprises a common key generation means that generates a common key used for communication with the setting terminal based on the password stored in the password storage means and the generation factor information notified from the setting terminal, The aforementioned server, A device management information storage means that stores device management information linking the identification information of the communication device with the password of the communication device, A communication system comprising: a password notification means that, upon receiving notification of the identification information from the setting terminal, notifies the setting terminal of a password corresponding to the identification information.
2. The server further comprises an electronic signature issuing means for issuing an electronic signature to the configuration terminal, The aforementioned configuration terminal is An electronic signature acquisition means for acquiring the electronic signature from the server, The system further comprises an electronic signature notification means for notifying the communication device of the electronic signature, The communication device further comprises an electronic signature verification means for verifying the electronic signature notified from the setting terminal, The communication system according to claim 1, wherein the common key generation means of the communication device generates the common key only when the electronic signature is verified to be valid by the electronic signature verification means.
3. The aforementioned configuration terminal is A password update means for updating the password corresponding to the aforementioned communication device, The system further comprises a password update notification means for notifying the communication device and the server of the updated password, The means for acquiring the generation factor information acquires the generation factor information again after the password has been updated. The generation factor information notification means notifies the communication device of the generation factor information that has been acquired again. The shared key generation means updates the shared key based on the updated password and the generation factor information. The communication device stores the password notified from the setting terminal as the password corresponding to the communication device in the password storage means. The common key generation means of the communication device updates the common key based on the notified password and the notified generation factor information. The communication system according to claim 1 or 2, wherein the server further comprises a device management information update means for updating the device management information based on a password notified from the configuration terminal.
4. The aforementioned server, A password update means for updating the password corresponding to the aforementioned communication device, The system further comprises a password update notification means for notifying the communication device of the updated password, The communication system according to claim 1 or 2, wherein the communication device stores the password notified by the server as the password corresponding to the communication device in the password storage means.
5. An identification information acquisition means for acquiring identification information of communication equipment, A password acquisition means that notifies the server of the identification information and obtains from the server a password corresponding to the identification information, which is a password for generating a common key used for communication with the communication device, A means for acquiring generation factor information that acquires generation factor information that is the generation factor of the aforementioned common key, A means for notifying the communication device of the generation factor information, A configuration terminal comprising a common key generation means for generating the common key based on the password and the generation factor information.
6. Computers, means for acquiring identification information of communication equipment, A password acquisition means that notifies the server of the identification information and obtains from the server a password corresponding to the identification information, which is a password for generating a common key used for communication with the communication device. A means for acquiring generation factor information that is the generation factor of the aforementioned common key, A means for notifying the communication device of the generation factor information, A program that functions as a common key generation means for generating the common key based on the password and the generation factor information.