Communication device, communication method, and communication program

JP7912282B2Active Publication Date: 2026-08-28帝都久利寿 +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2025170852
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-09-05
Filing Date
2025-10-09
Publication Date
2026-08-28
Estimated Expiration
2039-02-15

AI Technical Summary

Benefits of technology

【0039】 本開示によれば、通信ネットワークへの接続に対するユーザ体験又はユーザの利便性を向上させることが可能な情報処理方法、情報処理プログラム、情報処理装置及び情報処理システムを提供することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007912282000002
    Figure 0007912282000002
  • Figure 0007912282000003
    Figure 0007912282000003
  • Figure 0007912282000004
    Figure 0007912282000004
Patent Text Reader

Abstract

To provide an information processing method, an information processing program, an information processing device, and an information processing system capable of improving user experience or user convenience for connection to a communication network.SOLUTION: A method for processing information is executed by a processor of a device and includes a step (S2) of generating a public key of the device based on a private key of the device, a step (S3) of generating a hash value based on the public key and a predetermined hash function, and a step (S6) of determining an IP address of the device based on the hash value.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing method, an information processing program, an information processing apparatus, and an information processing system. Background Art

[0002] Recent years have witnessed remarkable development in information and communication technology, and not only personal computers, smartphones and tablets, but also all kinds of things such as automobiles, home appliances and sensor devices are being connected to communication networks such as the Internet. In this way, it is expected that an IoT (Internet of Things) society, in which trillions of devices around the world are connected to communication networks, will arrive in the near future (see Patent Document 1). Prior Art Documents Patent Documents

[0003] Patent Document 1 Japanese National Publication of International Patent Application No. 2016-515328 Summary of the Invention Problems to be Solved by the Invention

[0004] Incidentally, as disclosed in Patent Document 1, in current IoT technology, an Internet service provider (ISP) manages the IP addresses of each device connected to the Internet. For example, when a predetermined device is connected to the Internet, the ISP assigns an IP address to the predetermined device. Thereafter, the predetermined device can access a web server on the Internet using the IP address assigned by the ISP. As described above, when connecting a device to a communication network such as the Internet, intervention from an operator that manages IP addresses, such as an ISP, is required, and there is room for improvement in terms of enhancing user experience or user convenience with respect to connection to the communication network.

[0005] This disclosure aims to provide information processing methods, information processing programs, information processing devices, and information processing systems that can improve the user experience or user convenience for connecting to communication networks. [Means for solving the problem]

[0006] An information processing method relating to one aspect of this disclosure is executed by the processor of the device, The steps include generating a public key for the device based on the private key of the device, The steps include generating a hash value based on the public key and a predetermined hash function, The steps include determining the network address of the device based on the hash value, Includes.

[0007] Furthermore, the information processing method may further include the step of generating the secret key.

[0008] Furthermore, the information processing method may further include the step of transmitting the public key to an external device located outside the device.

[0009] Furthermore, the information processing method may further include a step of determining whether the hash value satisfies predetermined conditions. If the hash value satisfies the predetermined conditions, the network address may be determined based on the hash value.

[0010] Furthermore, the information processing method may further include the step of generating the secret key.

[0011] If the hash value does not satisfy the predetermined conditions, the steps of generating the private key, generating the public key, and generating the hash value may be repeated until the hash value satisfies the predetermined conditions.

[0012] Furthermore, the predetermined conditions may include conditions associated with the first two digits of the hash value.

[0013] Further, the predetermined condition may include a condition associated with the type of the device.

[0014] Further, the step of generating the hash value may include a step of generating the hash value based on the public key, a value associated with a predetermined organization, and the predetermined hash function.

[0015] Further, the value associated with the predetermined organization may be a value associated with a trademark of the predetermined organization.

[0016] Further, the information processing method may further include a step of acquiring an electronic certificate associated with the public key from a certificate authority.

[0017] Further, the information processing method may further include a step of transmitting the public key and the electronic certificate to an external device existing outside the device.

[0018] Further, the electronic certificate may include information related to an attribute of the device.

[0019] Further, the electronic certificate may include attribute information of a user associated with the device.

[0020] Further, the electronic certificate may include attribute information of the device and / or a user associated with the device, and a hash value of the entire attribute information, .

[0021] Further, a part of the attribute information may be hashed.

[0022] Further, a part of the attribute information may be hashed based on the part of the attribute information and a predetermined coefficient.

[0023] Further, the information processing method: a step of receiving a public key of an external device from the external device existing outside the apparatus, a step of generating a hash value of the external device based on the public key of the external device and the predetermined hash function, and a step of determining a network address of the external device based on the hash value of the external device.

[0024] Further, the step of receiving the public key of the external device may include a step of receiving the public key of the external device and an electronic certificate associated with the public key. The information processing method may further include a step of determining whether or not the electronic certificate is valid. When it is determined that the electronic certificate is valid, based on the public key of the external device, the external the hash value of the device may be generated.

[0025] An information processing method according to an aspect of the present disclosure is executed by a processor of an apparatus, and includes a step of determining a network address of the apparatus based on a public key of the apparatus.

[0026] Further, the information processing method may further include a step of executing communication using the network address of the apparatus without intervention of a server that manages network addresses.

[0027] Further, the information processing method may be executed in a network layer of the OSI reference model.

[0028] Further, there is provided an information processing program for causing a computer to execute the information processing method. Furthermore, there is provided a computer-readable storage medium storing the information processing program.

[0029] An information processing apparatus according to an aspect of the present disclosure includes at least one processor and a memory storing computer-readable instructions. When the computer-readable instructions are executed by the processor, the information processing apparatus is configured to execute the information processing method.

[0030] An information processing system according to one aspect of the present disclosure includes a first device and a second device that is communicatively connected to the first device.

[0031] The first apparatus, Based on the first private key of the first device, the first public key of the first device is generated. A first hash value is generated based on the first public key and a predetermined hash function. Based on the first hash value, the first network address of the first device is determined. The first public key is transmitted to the second device.

[0032] The second device is Based on the second private key of the second device, the second public key of the two devices is generated. A second hash value is generated based on the second public key and the predetermined hash function. Based on the second hash value, the second network address of the second device is determined. The second public key is transmitted to the first device.

[0033] The first apparatus, The second public key is received from the second device. The second hash value is generated based on the second public key and the predetermined hash function, The second network address is determined based on the second hash value.

[0034] The second device is Having received the first public key from the first device, A first hash value is generated based on the first public key and the predetermined hash function. The first network address is determined based on the first hash value.

[0035] Furthermore, the first device is Send the first public key to the Certificate Authority, Obtain the first digital certificate associated with the first public key from the aforementioned certification authority, The first digital certificate and the first public key may be transmitted to the second device.

[0036] The second device is The second public key is sent to the aforementioned Certificate Authority or another Certificate Authority, Obtain a second digital certificate associated with the second public key from the aforementioned certification authority or another certification authority, The second digital certificate and the second public key may be transmitted to the first device.

[0037] The first apparatus, The second public key and the second digital certificate are received from the second device. You may determine whether the second digital certificate is legitimate.

[0038] The second device is The first public key and the first digital certificate are received from the first device. You may determine whether the first digital certificate is legitimate. [Effects of the Invention]

[0039] According to this disclosure, it is possible to provide an information processing method, information processing program, information processing device, and information processing system that can improve the user experience or user convenience for connecting to a communication network. [Brief explanation of the drawing]

[0040] [Figure 1] This figure shows an example of the hardware configuration of an information processing device according to an embodiment of the present invention (hereinafter referred to as "this embodiment"). [Figure 2] This is a flowchart illustrating an example of the process for determining the IP address of an information processing device. [Figure 3] This diagram shows an information processing device and a server on the internet. [Figure 4]This diagram shows an information processing system that includes two information processing devices. [Figure 5] This flowchart illustrates an example of the process for determining the IP address of an external device. [Figure 6] This flowchart shows an example of a process for determining the legitimacy of an electronic certificate sent from an external device. [Figure 7] This diagram shows an information processing system that includes four information processing devices. [Figure 8] This figure shows an example of an electronic certificate before and after some of the user attribute information is hashed. [Modes for carrying out the invention]

[0041] The following description of this embodiment will be made with reference to the drawings. First, the hardware configuration of the information processing device 2 according to an embodiment of the present invention (hereinafter simply referred to as "this embodiment") will be described below with reference to Figure 1.

[0042] Figure 1 shows an example of the hardware configuration of the information processing device 2 according to this embodiment. As shown in Figure 1, the information processing device 2 (hereinafter simply referred to as "device 2") comprises a control unit 20, a storage device 23, a network interface 25, a display unit 26, and an input operation unit 27. These are connected to each other via a bus 29 so as to be able to communicate with each other.

[0043] Device 2 may be, for example, a personal computer, a smartphone, a tablet, or a wearable device attached to the user's body (e.g., arm or head) (e.g., a smartwatch or AR glasses). Alternatively, Device 2 may be a smart home appliance, a connected car, or a control device installed in a factory. Thus, the types of Device 2 include all devices that are connected to a communication network such as the Internet using an IP address (an example of a network address) and that are equipped with a processor and memory. This embodiment Device 2 includes a display unit 26 and an input operation unit 27, but these are not essential components of device 2.

[0044] The control unit 20 is configured to control the operation of the device 2 and includes memory and a processor. The memory is configured to store computer-readable instructions (e.g., information processing programs). For example, the memory may consist of a ROM (Read Only Memory) in which various programs are stored and a RAM (Random Access Memory) having multiple work areas in which various programs executed by the processor are stored. Alternatively, the memory may consist of flash memory or the like. The processor may be, for example, a CPU or an MPU (Microprocessor). The system includes at least one of a CPU (CPU Unit) and a GPU (Graphics Processing Unit). The CPU may be composed of multiple CPU cores. The GPU may be composed of multiple GPU cores. The processor may be configured to load a specified program from various programs embedded in the storage device 23 or ROM onto RAM and to execute various processes in cooperation with RAM. In particular, the device 2 is configured to execute the information processing method according to this embodiment by having the processor execute an information processing program stored in memory.

[0045] The storage device 23 is, for example, a storage device such as an HDD (Hard Disk Drive), SSD (Solid State Drive), or flash memory, and is configured to store programs and various data. The storage device 23 may store the information processing program according to this embodiment that has been transmitted from a server on the Internet.

[0046] The network interface 25 is configured to connect device 2 to a communication network. Specifically, the network interface 25 may include various wired connection terminals for communicating with external devices such as servers via the communication network. The network interface 25 may also include various processing circuits and antennas for communicating with wireless routers or wireless base stations. The wireless communication standard is, for example, Wi-Fi®, Bluetooth®, ZigBee®, LPWA, or fifth-generation mobile communication system (5G). The communication network includes at least one of a local area network (LAN), wide area network (WAN), wireless access network (RAN), and the internet.

[0047] The display unit 26 may be a display device such as a liquid crystal display or an organic EL display, or it may be a transparent or non-transparent head-mounted display worn on the operator's head. Furthermore, the display unit 26 may be a projector device that projects images onto a screen.

[0048] The input operation unit 27 is configured to receive input operations from a user operating the device 2 and to generate instruction signals corresponding to those input operations. The input operation unit 27 is, for example, a touch panel superimposed on the display unit 26, operation buttons mounted on the housing, a mouse and / or keyboard, etc. After the instruction signals generated by the input operation unit 27 are transmitted to the control unit 20 via the bus 29, the control unit 20 performs predetermined operations according to the instruction signals. The display unit 26 and the input operation unit 27 may be connected to the device 2 via an input / output interface such as USB.

[0049] Next, the information processing method according to this embodiment will be described below with reference to Figure 2. Figure 2 is a flowchart illustrating an example of the process for determining the IP address (for example, a global IP address) of device 2. As shown in Figure 2, in step S1, device 2 The control unit 20 generates a secret key for device 2 using a random number generator. Here, the random number generator may be implemented by the OS program of device 2, or it may be implemented as a hardware component (logic circuit, etc.) of device 2. The size of the generated secret key is, for example, 512 bits.

[0050] Next, in step S2, the control unit 20 generates a public key for the device 2 based on the generated secret key and a predetermined cryptographic algorithm. Here, the predetermined cryptographic algorithm is, for example, an elliptic curve cryptography algorithm. The size of the generated public key is, for example, 256 bits.

[0051] Next, in step S3, the control unit 20 generates a hash value based on the generated public key and a predetermined hash function. Here, the predetermined hash function is a cryptographic hash function, for example, BLAKE is used. The size of the generated hash value is, for example, 256 bits.

[0052] Furthermore, in step S3, the control unit 20 may generate a hash value based on the generated public key, a value associated with a predetermined organization, and a predetermined hash function. Here, an example of a value associated with a predetermined organization is a value associated with the predetermined organization's trademark. For example, if the predetermined organization uses trademark X (e.g., "connectFree"), the value of trademark X may be used when generating the hash value. In this case, it is possible to prevent a third party other than the predetermined organization from creating an information processing program to execute the information processing method according to this embodiment without the permission of the predetermined organization.

[0053] Next, the control unit 20 determines whether the generated hash value satisfies the condition associated with the first two digits (the first and second digits) of the hash value displayed in hexadecimal (step S4). In this regard, if the size of the hash value is 256 bits, the hash value will be displayed in 64 hexadecimal digits. For example, if the first two digits of the 64-digit hash value are "FC" (i.e., hash value = FC...), the control unit 20 may determine that the hash value satisfies the determination condition in step S4. If the determination condition in step S4 is YES, the process proceeds to step S5. On the other hand, if the determination condition in step S4 is NO, the process proceeds to step S1. In other words, the processes in steps S1 to S3 are repeatedly executed until the determination condition in step S4 is satisfied.

[0054] Next, in step S5, the control unit 20 determines whether the hash value satisfies the conditions associated with the type of device 2 (step S5). In this regard, the type of device 2 associated with the IP address can be identified according to the values ​​of the third and fourth digits from the beginning of the IP address displayed in hexadecimal. For example, the following relationship is assumed between the values ​​of the third and fourth digits from the beginning of the IP address and the type of device.

[0055] [Table 1]

[0056] Here, the condition for step S5 is met if the third and fourth digits of the hash value displayed in hexadecimal match the third and fourth digits from the beginning of the IP address corresponding to the type of device 2. For example, let's assume that the type of device 2 is a personal computer. In this case, the third and fourth digits from the beginning of the IP address of device 2 are "00", so if the third and fourth digits from the beginning of the hash value displayed in hexadecimal are "00" (i.e., hash value = FC00...), the condition for step S5 is met. On the other hand, if the third and fourth digits from the beginning of the hash value are "11" (i.e., hash value = FC11...), the condition for step S5 is not met. If the condition for step S5 is YES, the process proceeds to step S6. On the other hand, if the condition for step S5 is NO, the process proceeds to step S1. In other words, the processes of steps S1 to S3 are repeatedly executed until the condition for step S5 is met. Note that step S5 may be omitted.

[0057] Next, the control unit 20 determines the IP address of device 2 based on the hash value that satisfies the determination conditions of steps S4 and S5 (step S6). For example, if the hash value size is 256 bits and an IP address corresponding to IPv6 (128 bits) is used as the IP address of device 2, the control unit 20 may determine the first 32 digits of the 64-digit hash value as the IP address of device 2. Also, if the hash value size is 128 bits and an IP address corresponding to IPv6 (128 bits) is used as the IP address of device 2, the control unit 20 may determine all 32 digits of the hash value as the IP address of device 2. Furthermore, if the hash value size is 256 bits and an IP address corresponding to IPv4 (32 bits) is used as the IP address of device 2, the control unit 20 may determine the first 8 digits of the 64-digit hash value as the IP address of device 2.

[0058] Furthermore, after the processing in step S6, a step may be provided to determine whether the determined IP address of device 2 overlaps with the IP address of another device. Specifically, after the processing in step S6, device 2 transmits information about its IP address to a management server that manages IP addresses via a communication network. The management server determines whether the IP address transmitted from device 2 overlaps with one of the IP addresses included in the IP address management table stored in its storage device. If the IP address of device 2 overlaps with one of the IP addresses included in the IP address management table, the management server may send a message to device 2 indicating that the registration of the IP address is rejected. In this case, device 2 performs the processing from steps S1 to S6 again and then sends information about the determined IP address to the management server again. On the other hand, if the IP address of device 2 does not overlap with any of the IP addresses included in the IP address management table, the management server may send a message to device 2 indicating that the registration of the IP address is permitted.

[0059] Next, in step S7, the control unit 20 obtains the digital certificate associated with the generated public key from a certification authority of a predetermined organization. That is, the user of device 2 registers the public key with the certification authority and obtains the digital certificate associated with the registered public key from the certification authority. More specifically, the control unit 20 sends a request for issuance of the public key and digital certificate (certificate signing request) to the certification authority's server via the communication network. Next, the certification authority's server registers the public key and issues the digital certificate associated with the public key in response to the received digital certificate issuance request. After that, the certification authority's server sends the digital certificate to device 2 via the communication network.

[0060] Furthermore, the designated organization's Certificate Authority may also be the designated organization's Intermediate Certificate Authority. In addition, a prescribed fee may be required when obtaining a digital certificate associated with a public key from the Certificate Authority.

[0061] According to this embodiment, a unique IP address for device 2 is determined based on the public key of device 2. In this way, device 2 can be connected to a communication network such as the Internet using the IP address determined by device 2 itself. In particular, device 2 can connect to the Internet using the IP address determined by device 2 itself, without going through a service provider (server) that manages global IP addresses such as an ISP. In this regard, as shown in Figure 3, user U operating device 2 can access a web server 6 on the Internet 4 via a wireless LAN router 3 through predetermined routing by using the IP address determined by device 2 itself. Furthermore, device 2 can communicate directly with external devices using the IP address determined by device 2 itself, without going through a server that manages private IP addresses (e.g., a DHCP server) (details will be described later).

[0062] Therefore, it is possible to provide an information processing method and apparatus 2 that can improve the user experience or user convenience when connecting to a communication network such as the Internet.

[0063] Furthermore, according to this embodiment, it is possible to generate hash values ​​that satisfy the conditions of steps S4 and S5. In other words, it is possible to generate an IP address associated with a hash value that satisfies the conditions of steps S4 and S5.

[0064] Specifically, the first two digits of the hash value, expressed in hexadecimal, can be fixed (for example, hash value = FC...). In other words, the first two digits of the IP address can be fixed (for example, IP address = FC...). Therefore, a third party can determine whether the IP address of device 2 is the IP address determined by device 2 itself.

[0065] Furthermore, in this embodiment, a hash value can be generated according to the type of device 2. In other words, an IP address can be generated according to the type of device 2. Therefore, a third party can identify the type of device 2 based on its IP address.

[0066] Furthermore, in this embodiment, hash values ​​are repeatedly generated until the conditions in steps S4 and S5 are met, so it is possible to reliably generate an IP address associated with a hash value that satisfies the conditions in steps S4 and S5.

[0067] Furthermore, according to this embodiment, the public key is directly authenticated by the Certificate Authority through the acquisition of an electronic certificate, and the IP address determined based on the public key is also indirectly authenticated by the Certificate Authority. The device is then authenticated. In this way, device 2 can connect to a communication network such as the Internet using an IP address that has been indirectly authenticated by the certification authority.

[0068] In this embodiment, the secret key for device 2 is generated using the random number generator of device 2, but the secret key for device 2 may be provided by an external device that is communicatively connected to device 2. Also, the order of the steps shown in Figure 2 is not particularly limited. For example, the process of step S6 may be executed after the process of step S7.

[0069] Furthermore, the digital certificate associated with the public key may include information related to the attributes of device 2 (attribute information). The attribute information of device 2 may include, for example, at least one of the following: the version information of the OS program of device 2 and information regarding the serial numbers of the hardware constituting device 2 (e.g., processor, storage device, etc.). In addition, the attribute information of device 2 included in the digital certificate may be encrypted using a hash function or the like. In this case, when device 2 sends a request for issuance of the public key and digital certificate (certificate signing request), it may send the attribute information of device 2 to the certification authority's server. In this way, because the attribute information of device 2 is included in the digital certificate, it is authenticated that the digital certificate was issued in accordance with the request of device 2. For this reason, it is preferable to prevent other devices other than device 2 from using device 2's public key and digital certificate.

[0070] Furthermore, the digital certificate may include attribute information of the user associated with device 2 (for example, the user who owns device 2). For example, user attribute information may include the user's name, identification number, contact information, age, gender, address, or credit card information. In this way, because the user's attribute information is included in the digital certificate, it is effectively prevented from third parties other than the user using the public key and digital certificate of device 2. Moreover, when device 2 sends a digital certificate containing user attribute information to a web server, the web server can verify the user attribute information contained in the digital certificate. Therefore, users of device 2 can use online services (such as e-commerce sites) provided by the web server without registering user information, etc. In other words, users of device 2 can be freed from the hassle of managing login information (login ID and login password) for each online service, making it possible to provide users with a richer online experience.

[0071] Furthermore, the hash value of the attribute information of device 2 and / or the user's attribute information (hereinafter sometimes simply referred to as "attribute information") described in the digital certificate may be included in the digital certificate. The hash value is generated based on the attribute information and a cryptographic hash function. In this case, if the attribute information described in the digital certificate is tampered with by a third party, the hash value will change, and the tampering of the attribute information can be detected based on the hash value. For example, when device 2 transmits a digital certificate to an external device, the external device calculates the hash value of the attribute information of the digital certificate and determines whether the calculated hash value matches the hash value shown in the digital certificate. If the calculated hash value matches the hash value shown in the digital certificate, the external device determines that the attribute information of the digital certificate has not been tampered with. On the other hand, if the two do not match, the external device determines that the attribute information of the digital certificate has been tampered with.

[0072] Furthermore, the hash value of all the information contained in the digital certificate may also be included in the digital certificate. In this case as well, if some of the information contained in the digital certificate is tampered with by a third party, the hash value will change, and it will be possible to detect that the information contained in the digital certificate has been tampered with by a third party based on the hash value.

[0073] As described above, the electronic certificate contains attribute information of device 2 and / or user attribute information. In this case, all attribute information described in the electronic certificate may be transmitted to the external device. Furthermore, some attribute information contained in the electronic certificate may not be transmitted to the external device. In other words, some attribute information contained in the electronic certificate may be hashed by a hash function. For example, as shown in Figure 8, a user can hash the address and credit card information among the user attribute information 40 contained in the electronic certificate 8 through an input operation to device 2. In this way, an external device that receives the electronic certificate 8 from device 2 cannot identify the address and credit card information among the user attribute information 40 contained in the electronic certificate 8, but can identify the user attribute information 40 other than the address and credit card information.

[0074] Furthermore, as shown in Figure 8, the hash value of all attribute information when all attribute information is displayed matches the hash value of all attribute information when some attribute information is hidden (hashed). Similarly, the hash value of all contents written in the digital certificate when all attribute information is displayed matches the hash value of all contents written in the digital certificate when some attribute information is hidden (hashed). In other words, even if some attribute information is hashed, the hash value of all attribute information or the hash value of all contents written in the digital certificate does not change, so tampering with the digital certificate by a third party can be easily detected based on the hash value.

[0075] Furthermore, the hiding (hashing) of some attribute information may be pre-configured by the user, or it may be changed in response to a request from an external device. It should be noted that by referring to a database showing the relationship between the hash value and the original information, a situation may arise where the original attribute information can be determined based on the hash value of the attribute information. To prevent such a situation, the original attribute information may be hashed based on a predetermined coefficient and the original attribute information. In this case, the predetermined coefficient may be a constant, or it may be a variable that changes based on predetermined information (e.g., date information of an electronic certificate).

[0076] Next, the information processing system 30 according to this embodiment will be described below, mainly with reference to Figures 4 and 5. Figure 4 is a diagram showing the information processing system 30 including an information processing device 2A (hereinafter simply referred to as "device 2A") and an information processing device 2B (hereinafter simply referred to as "device 2B"). Figure 5 is a flowchart illustrating an example of the process for determining the IP address of an external device.

[0077] In this embodiment of the information processing system 30, for the sake of simplicity, the number of information processing devices connected to each other in a communicative manner is set to two, but the number of information processing devices connected to each other in a communicative manner may be three or more. Also, each of devices 2A and 2B shall have the hardware configuration of device 2 shown in Figure 1.

[0078] Furthermore, it is assumed that each of devices 2A and 2B has already performed the process to determine its IP address as shown in Figure 2. That is, device 2A has already performed the process to determine its own IP address. Therefore, as shown in Figure 4, device 2A has already generated a public key 7A associated with its IP address and has already obtained a digital certificate 8A associated with the public key 7A from the certification authority. Similarly, it is assumed that device 2B has already performed the process to determine its own IP address. Therefore, as shown in Figure 4, device 2B has already generated a public key 7B associated with its IP address and has already obtained a digital certificate 8B associated with the public key 7B from the certification authority.

[0079] As shown in Figure 5, in step S10, device 2A (specifically, the control unit 20 of device 2A) transmits (broadcasts) the public key 7A and the digital certificate 8A associated with the public key 7A to the outside of device 2A. Subsequently, device 2B located near device 2A In step S11, device 2B (specifically, the control unit 20 of device 2B) transmits (broadcasts) the public key 7B and the digital certificate 8B associated with the public key 7B to an external source. Subsequently, device 2A receives the public key 7B and digital certificate 8B broadcast from device 2B. Note that the processing in step S11 may be performed simultaneously with the processing in step S10, or before the processing in step S10.

[0080] Next, in step S12, device 2B determines whether the digital certificate 8A broadcast from device 2A is legitimate. Here, referring to Figure 6, the process of determining the legitimacy of the digital certificate 8A (i.e., the process in step S12) will be explained below.

[0081] As shown in Figure 6, in step S20, device 2B determines the integrity of the digital certificate 8A. Specifically, device 2B verifies the owner information, issuer information, and digital signature of the issuer of the digital certificate 8A. Next, in step S21, device 2B determines the expiration date of the digital certificate 8A. Then, in step S22, device 2B determines the trustworthiness of the issuer of the digital certificate 8A. In particular, if the certification authority that issued the digital certificate 8A is an intermediate certification authority, device 2B identifies the root certification authority of the intermediate certification authority that issued the digital certificate 8A and determines whether the identified root certification authority is trustworthy. For example, if the identified root certification authority is included in the information of multiple root certification authorities stored in the memory of device 2B, it is determined that the issuer of the digital certificate 8A is trustworthy.

[0082] Returning to Figure 5, when device 2B determines that the digital certificate 8A is valid, it generates a hash value based on the public key 7A and a predetermined hash function (step S13). Here, the predetermined hash function is a cryptographic hash function such as BLAKE, as previously explained. In this embodiment, the hash function used by device 2B and the hash function used by device 2A are assumed to be the same.

[0083] Next, in step S14, device 2B determines the IP address of device 2A based on the generated hash value. For example, as already explained, if the hash value size is 256 bits and an IPv6-compatible IP address (128 bits) is used as the IP address of device 2A, device 2B may determine the first 32 digits of the 64-digit hash value as the IP address of device 2A.

[0084] Meanwhile, in step S15, device 2A determines whether the digital certificate 8B broadcast from device 2B is legitimate. The specific processing details of step S15 are shown in Figure 6. Next, if device 2A determines that the digital certificate 8B is legitimate, it generates a hash value based on the public key 7B and a predetermined hash function (step S16). As already explained, the hash function used by device 2A is the same as the hash function used by device 2B.

[0085] Subsequently, in step S17, device 2A determines the IP address of device 2B based on the generated hash value. Similar to the process in step S14, if the size of the hash value is 256 bits and an IP address corresponding to IPv6 (128 bits) is used as the IP address of device 2B, device 2A may determine the IP address of device 2B to be the first 32 digits of the 64-digit hash value.

[0086] Thus, device 2A can know the IP addresses of devices 2A and 2B, and device 2B can know the IP addresses of devices 2A and 2B. Therefore, devices 2A and 2B can connect directly to each other without going through a server that manages IP addresses (i.e., (P2P communication between devices 2A and 2B without the need for a VPN server can be realized). In particular, since there is no need to connect devices 2A and 2B via a virtual private network (VPN) server, the power consumption required for direct connection between devices 2A and 2B can be significantly reduced. Also, when directly connecting three or more devices, there is no need to relay a VPN server, so the power consumption required for direct connection between three or more devices can be significantly reduced.

[0087] For example, device 2A can send messages to device 2B without going through a mail server, thus avoiding situations where messages from device 2A are accessed by a third party (e.g., a server administrator). Furthermore, device 2A can send image data showing its screen to device 2B without going through a VPN server. Conversely, device 2B can send operation signals to device 2A to control its screen without going through a VPN server. In this way, the user of device 2B can remotely operate device 2A. In addition, devices 2A and 2B can share electronic files with each other without going through a file exchange server. Therefore, it is possible to avoid situations where shared electronic files are accessed by a third party.

[0088] Furthermore, when device 2A sends a message to device 2B (or when device 2B sends a message to device 2A), the transmitted message (transmitted packet) may be encrypted. For example, the transmitted message may be encrypted using a shared key generated based on the public key 7A of device 2A and the public key 7B of device 2B. Also, this shared key may be changed each time a session is established between device 2A and device 2B. In this way, secure communication between device 2A and device 2B can be achieved.

[0089] Furthermore, according to this embodiment, if the digital certificate transmitted from the external device is determined to be valid, a hash value of the external device is generated based on the public key of the external device. Subsequently, the IP address of the external device is determined based on the hash value of the external device (here, from the perspective of device 2A, device 2B is the external device, while from the perspective of device 2B, device 2A is the external device). In this way, device 2A can confirm that the received public key 7B is the public key of device 2B. Furthermore, device 2A can confirm that the IP address generated based on the public key 7B is the IP address of device 2B. Therefore, device 2A can reliably obtain the IP address of device 2B and reliably communicate with device 2B using the IP address of device 2B.

[0090] On the other hand, device 2B can verify that the received public key 7A is the public key of device 2A. Furthermore, device 2B can verify that the IP address generated based on the public key 7A is the IP address of device 2A. Therefore, device 2B can reliably obtain the IP address of device 2A and reliably communicate with device 2A using the IP address of device 2A.

[0091] Furthermore, as described above, the information processing system according to this embodiment may have three or more information processing devices. For example, consider the case where the information processing system 30A has four information processing devices 2A to 2D (hereinafter simply referred to as "devices 2A to 2D"), as shown in Figure 7. Here, each of devices 2A to 2D has the hardware configuration of device 2 shown in Figure 1. In this case, each of devices 2A to 2D performs the respective processes executed by device 2A or device 2B shown in Figure 5.

[0092] In this regard, device 2A broadcasts its public key and digital certificate to the outside world, and receives public keys and digital certificates from each of the devices 2B to 2D located near device 2A. Device 2B broadcasts its public key and digital certificate to the outside world, and receives public keys and digital certificates from each of the devices 2A, 2C, and 2D. Device 2C broadcasts its public key and digital certificate to the outside world and receives the public key and digital certificate from each of the devices 2A, 2B, and 2D. Device 2D broadcasts its public key and digital certificate to the outside world and receives the public key and digital certificate from each of the devices 2A through 2C.

[0093] Subsequently, device 2A determines the IP addresses of devices 2B through 2D. Device 2B determines the IP addresses of devices 2A, 2C, and 2D. Device 2C determines the IP addresses of devices 2A, 2B, and 2D. Device 2D determines the IP addresses of devices 2A through 2C. In this way, each of devices 2A through 2D can be directly connected to three external devices using the IP addresses of devices 2A through 2D. In other words, a mesh network can be formed by devices 2A through 2D. Alternatively, the connection between devices 2A and 2D may be via predetermined routing in the communication network. Devices 2A through 2D can be connected to each other by forming an optimal path.

[0094] Furthermore, in the information processing system 30A shown in Figure 7, each of the devices 2A to 2D uses the same hash function, thus forming a mesh network; however, this embodiment is not limited to this.

[0095] For example, devices 2A and 2B may use a first hash function, while devices 2C and 2D may use a second hash function different from the first hash function. In this case, devices 2A and 2B are connected to each other in a way that allows them to communicate with one another, and devices 2C and 2D are also connected to each other in a way that allows them to communicate with one another. On the other hand, devices 2A and 2B are not connected to devices 2C and 2D in a way that allows them to communicate with one another. In this way, by using two different hash functions, two communication network groups can be constructed within the information processing system 30A.

[0096] Furthermore, in order to implement the device 2 according to this embodiment using software, an information processing program may be pre-installed in the storage device 23 or ROM. Alternatively, the information processing program may be stored in a computer-readable storage medium such as a magnetic disk (e.g., HDD, floppy disk), optical disk (e.g., CD-ROM, DVD-ROM, Blu-ray® disk), magneto-optical disk (e.g., MO), or flash memory (e.g., SD card, USB memory, SSD). In this case, the information processing program stored in the computer-readable storage medium may be installed in the storage device 23. Moreover, the information processing program installed in the storage device 23 may be loaded onto RAM, and then the processor may execute the information processing program loaded onto RAM. In this way, the information processing method according to this embodiment is executed by the device 2.

[0097] Furthermore, the information processing program may be stored on a storage medium (e.g., an HDD) on a server on a communication network such as the Internet. In this case, the information processing program may be downloaded from the server via the network interface 25. Similarly, in this case as well, the downloaded information processing program may be incorporated into the storage device 23.

[0098] Furthermore, the information processing program (information processing method) according to this embodiment is executed by the network layer in the OSI (Open Systems Interconnection) reference model. Therefore, secure communication can be achieved in the transport layer, session layer, presentation layer, and application layer of the OSI reference model, and existing application programs and physical infrastructure can be applied as is.

[0099] Although embodiments of the present invention have been described above, the technical scope of the present invention should not be interpreted as being limited by the description of these embodiments. These embodiments are examples, and various modifications to the embodiments are possible within the scope of the invention as described in the claims, as will be understood by those skilled in the art. This is how it should be understood. The technical scope of the present invention should be determined based on the scope of the invention as described in the claims and the scope of its equivalents.

[0100] For example, in the process of step S7 shown in Figure 2, device 2 may obtain digital certificates associated with the public key of device 2 from multiple organizational certification authorities. The digital certificate may also contain information related to the organizational attributes of the certification authority. For example, if the digital certificate was issued by the certification authority of organization X, the digital certificate may contain information related to the attributes of organization X.

[0101] Furthermore, as shown in Figure 4, device 2A obtains multiple digital certificates 8A from multiple separate certification authorities, and device 2B obtains multiple digital certificates 8B from multiple separate certification authorities. In this case, in step S10, device 2A sends the public key 7A and the multiple digital certificates 8A to device 2B. Also, in step S11, device 2B sends the public key 7B and the multiple digital certificates 8B to device 2A. Furthermore, in step S12, after determining whether each of the multiple digital certificates 8A is legitimate, device 2B may determine whether at least one of the organizations of the multiple certification authorities that issued the multiple digital certificates 8A is included in the organization list showing the organizations of the multiple certification authorities stored in the memory of device 2B. Specifically, device 2B may determine whether at least one of the organizations of the multiple certification authorities that issued the multiple digital certificates 8A is included in the organization list based on information related to the attributes of the organizations included in the digital certificates 8A and the organization list. Device 2B may perform the processes in steps S13 and S14 if at least one of the organizations of the multiple certification authorities that issued multiple digital certificates 8A is included in the organization list.

[0102] Similarly, in step S15, after determining whether each of the multiple digital certificates 8B is valid, device 2A may determine whether at least one of the multiple certification authority organizations that issued the multiple digital certificates 8B is included in the organization list showing the multiple organizations stored in device 2A's memory. Specifically, device 2A may determine whether at least one of the multiple certification authority organizations that issued the multiple digital certificates 8B is included in the organization list based on information related to the attributes of the organizations included in the digital certificates 8B and the organization list. If at least one of the multiple organizations that issued the multiple digital certificates 8B is included in the organization list, device 2A may perform the processes in steps S16 and S17.

[0103] Thus, if the organization that issued the digital certificate for public key 7A is included in the organization list stored in device 2B, and the organization that issued the digital certificate for public key 7B is included in the organization list stored in device 2A, then device 2A and device 2B can be directly connected to each other. In other words, it becomes possible to select a communication partner according to conditions related to the organization that issued the digital certificate, and to construct multiple communication network groups within the information processing system.

[0104] Furthermore, in the above example, devices 2A and 2B have obtained multiple digital certificates, but even if devices 2A and 2B obtain only one digital certificate, processing related to the determination conditions associated with the organization that issued the digital certificate may be applied. For example, if the organization of the certification authority that issued the digital certificate for device 2A and the organization of the certification authority that issued the digital certificate for device 2B are different, the processing in steps S13 and S14 (steps S16 and S17) may not be executed.

[0105] In this embodiment, an IP address, which is a network address corresponding to the Internet Protocol, is described as an example of the network address of devices 2A and 2B. However, the network address is not limited to an IP address. For example, the network address of devices 2A and 2B may be a network address corresponding to a predetermined communication protocol other than the Internet Protocol.

[0106] This application appropriately incorporates the information disclosed in Japanese Patent Application No. 2018-166429, filed on September 5, 2018.

Claims

1. A communication device capable of communicating with other communication devices, A means of generating a private key, A means for determining whether the hash value generated based on the public key that forms the pair of the generated private key satisfies the conditions for being used as a network address, A means for repeating the generation of the private key until the above conditions are met, A communication device comprising means for determining the network address of the communication device based on a public key that satisfies the above conditions.

2. The communication device according to claim 1, wherein the condition includes a condition associated with the first two digits of the hash value, or a condition that the hash value includes a value associated with the type of communication device.

3. The means for generating the secret key includes a random number generator, as described in claim 1 or 2.

4. The communication device according to any one of claims 1 to 3, further comprising means for generating a public key that is a pair of the generated private key based on the generated private key and a predetermined cryptographic algorithm.

5. The communication device according to any one of claims 1 to 4, further comprising means for determining whether the determined network address overlaps with the network address of any other communication device.

6. The communication device according to any one of claims 1 to 5, further comprising means for providing the other communication device with a public key that satisfies the above conditions.

7. The communication device according to any one of claims 1 to 6, further comprising means for determining the network address of the other communication device based on the obtained second public key and the predetermined hash function, upon obtaining a second public key from the other communication device.

8. The communication device according to any one of claims 1 to 7, further comprising means for obtaining an electronic certificate associated with a public key that satisfies the aforementioned conditions.

9. A communication method for communicating with other communication devices, The steps to generate a private key, The steps include determining whether the hash value generated based on the public key that forms the pair of the generated private key satisfies the conditions for being used as a network address, The steps include repeating the generation of the private key until the above conditions are met, A communication method comprising the step of determining the network address of the communication device based on a public key that satisfies the above conditions.

10. A communication program for communicating with other communication devices, which is installed on a computer. The steps to generate a private key, The steps include determining whether the hash value generated based on the public key that forms the pair of the generated private key satisfies the conditions for being used as a network address, The steps include repeating the generation of the private key until the above conditions are met, A communication program that performs the step of determining the network address of the communication device based on a public key that satisfies the above conditions.

Citation Information

Patent Citations

  • Information transmitting and receiving system, information transmitting and receiving method, information transmitting and receiving program, and computer readable recording medium

    JP2003216571A

  • Method and Apparatus for Securely Generating Public-Private Key Pairs

    JP2003501878A

  • Host Identity Protocol Server Address Configuration

    JP2012517165A

  • To establish Internet of Things (iot) device groups and enable communication between IoT device groups

    JP2016515328A

  • User Identification System Based on Proof of Work

    JP2018511261A