Apparatus management method, apparatus management system, and program
Patent Information
- Application Number
- JP2025503650
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-08-06
- Publication Date
- 2025-10-21
AI Technical Summary
Existing device management systems face security risks due to the potential unauthorized access and misuse of encryption keys when wireless communication is performed between devices and terminals, as third parties can intercept and misuse encryption keys.
A device management method and system that generates a connection ID each time wireless communication occurs between a device and a terminal, using shared key information to encrypt operation commands, ensuring that even if an unauthorized party obtains the encrypted command, they cannot decode it without the correct connection ID, thus preventing unauthorized access.
This approach enhances communication safety by ensuring that even if an unauthorized party acquires the encrypted operation command, they cannot use it to access the device due to the dynamic nature of the connection ID, thereby reducing the risk of unauthorized use of the device.
Abstract
Description
Device management method, device management system, and program
[0001] The present disclosure relates to a device management method, a device management system, and a program. More particularly, the present disclosure relates to a device management method, a device management system, and a program for managing devices operated using wireless terminals.
[0002] Patent Literature 1 discloses a delivery locker. The delivery locker includes a storage unit for storing packages, a control unit for generating an encryption key for encrypting information indicating the storage status of the packages in the storage unit, and a wireless communication unit. The wireless communication unit wirelessly communicates with a mobile terminal to transmit the generated encryption key to a server device via the mobile terminal.
[0003] When the wireless communication unit of the delivery box transmits the encryption key to the server device via a mobile terminal (terminal device), there is a possibility that a third party may illegally obtain the encryption key and misuse it.
[0004] International Publication No. 2020 / 170686
[0005] An object of the present disclosure is to provide a device management method, a device management system, and a program that improve the security of communications.
[0006] A device management method according to one aspect of the present disclosure includes, when a wireless terminal accepts an operation related to the use of a service and wirelessly communicates with a device, a step in which the wireless terminal transmits connection ID information generated each time the wireless terminal and the device communicate wirelessly to the wireless terminal. The wireless terminal is used to use the service provided by the device to which the device ID information is assigned. The device management method includes a step in which a device management server managing the device receives, from a service management server managing the wireless terminal, operation information related to the operation content accepted by the wireless terminal, operation request information based on the device ID information, and the connection ID information. The device management method includes a step in which the device management server generates a first operation command based on the operation request information, causing the device to perform the service corresponding to the operation content. The device management method includes a step in which the device management server generates a second operation command by encrypting the first operation command using shared key information shared between the device management server and the device and the connection ID information. The device management method includes a step in which the device management server transmits the second operation command to the service management server. The device management method includes a step of receiving, by the device, the second operation command from the wireless terminal that has received the second operation command from the service management server, a step of decrypting, by the device, the second operation command using the shared key information and the connection ID information to obtain the first operation command, and a step of executing, by the device, the service in accordance with the first operation command.
[0007] A device management system according to one aspect of the present disclosure includes a device assigned device ID information and a device management server that manages the device. The device includes a first communication unit that communicates wirelessly with a wireless terminal used to use a service provided by the device, a functional unit that provides the service, and a first processing unit. The device management server includes a second communication unit that communicates with a service management server that manages the wireless terminal, and a second processing unit. When the wireless terminal accepts an operation related to the use of the service and communicates wirelessly with the device, the first communication unit transmits connection ID information to the wireless terminal, which is generated each time the wireless terminal and the device communicate wirelessly. From the service management server, the second communication unit receives operation information related to the operation content accepted by the wireless terminal, operation request information based on the device ID information, and the connection ID information. Based on the operation request information, the second processing unit generates a first operation command that causes the device to perform the service corresponding to the operation content. The second processing unit generates a second operation command by encrypting the first operation command using shared key information shared between the device management server and the device and the connection ID information. The second communication unit transmits the second operation command to the service management server. The first communication unit receives the second operation command from the wireless terminal that has received the second operation command from the service management server. The first processing unit decrypts the second operation command using the shared key information and the connection ID information to obtain the first operation command. The first processing unit causes the function unit to execute the service in accordance with the first operation command.
[0008] A program according to one aspect of the present disclosure is a program for causing a computer system to function as the device included in the device management system. The program causes the computer system to execute a first step, a second step, a third step, and a fourth step. In the first step, when the wireless terminal accepts an operation related to use of the service and wirelessly communicates with the device, the wireless terminal transmits to the wireless terminal the connection ID information generated each time the wireless terminal and the device wirelessly communicate with each other. In the second step, the second operation command is received from the wireless terminal that has received the second operation command from the service management server. In the third step, the second operation command is decrypted using the shared key information and the connection ID information to obtain the first operation command. In the fourth step, the service is executed in accordance with the first operation command.
[0009] A program according to one aspect of the present disclosure is a program for causing a computer system to function as the device management server included in the device management system. The program causes the computer system to execute a first step, a second step, a third step, and a fourth step. In the first step, the program receives, from the service management server, operation information relating to the operation content accepted by the wireless terminal, operation request information based on the device ID information, and connection ID information. In the second step, the program generates, based on the operation request information, a first operation command for causing the device to perform the service corresponding to the operation content. In the third step, the program generates a second operation command by encrypting the first operation command using the shared key information shared between the device management server and the device and the connection ID information. In the fourth step, the program transmits the second operation command to the service management server.
[0010] Fig. 1 is a schematic system configuration diagram of a device management system according to an embodiment of the present disclosure. Fig. 2 is a sequence diagram illustrating the operation of the device management system. Fig. 3 is a sequence diagram illustrating the operation of the device management system.
[0011] Hereinafter, a device management method and a device management system according to embodiments will be described in detail with reference to the drawings. The configurations described in the following embodiments are merely examples of the present disclosure. The present disclosure is not limited to the following embodiments, and various modifications are possible depending on the design, etc., as long as the effects of the present disclosure can be achieved.
[0012] (Embodiment) (1) Overview FIG. 1 is a schematic system configuration diagram of a device management system 1 according to this embodiment.
[0013] The device management system 1 includes devices 10 that provide predetermined services, a device management server 20 that manages the devices 10, and a service management server 30 that manages wireless terminals 40 that are used to use the services provided by the devices 10. Note that it is not essential for the device management system 1 to include the service management server 30, and the service management server 30 can be omitted as appropriate.
[0014] The device management system 1 includes at least a device 10 to which device ID information is assigned, and a device management server 20 that manages the device 10 .
[0015] The device 10 has a first communication unit 12 that performs wireless communication with a wireless terminal 40 used to use the service provided by the device 10, a functional unit 13 that provides the service, and a first processing unit 11.
[0016] The device management server 20 includes a second communication unit 22 that communicates with the service management server 30 that manages the wireless terminal 40 , and a second processing unit 21 .
[0017] When the wireless terminal 40 accepts an operation related to the use of the service and performs wireless communication with the device 10, the first communication unit 12 transmits to the wireless terminal 40 connection ID information that is generated each time the wireless terminal 40 and the device 10 perform wireless communication.
[0018] The second communication unit 22 receives, from the service management server 30, operation request information based on operation information and device ID information relating to the operation content accepted by the wireless terminal 40, and connection ID information.
[0019] The second processing unit 21 generates a first operation command for causing the device 10 to perform a service according to the operation content, based on the operation request information.
[0020] The second processing unit 21 generates a second operation command by encrypting the first operation command using the shared key information and connection ID information shared between the device management server 20 and the device 10 .
[0021] The second communication unit 22 transmits the second operation command to the service management server 30 .
[0022] The first communication unit 12 receives the second operation command from the wireless terminal 40 that has received the second operation command from the service management server 30 .
[0023] The first processing unit 11 decrypts the second operation command using the shared key information and the connection ID information to obtain the first operation command.
[0024] The first processing unit 11 causes the function unit 13 to execute a service in accordance with the first operation command.
[0025] Here, the device 10 is an IoT (Internet of Things) device having a communication function capable of providing a predetermined service. The device 10 is, for example, a security-related device that provides a service related to security in a target space, a lighting fixture that provides a service to control the environment of the target space, an environmental control device such as an air conditioner, a cleaning robot that provides a service to clean the target space, or various cooking appliances that provide a service to cook ingredients. In the following embodiment, the device 10 is a security-related device that provides a service related to security in a target space, and will be described as an example in which the device 10 is an electric lock device that locks or unlocks the front door of a residence.
[0026] The wireless terminal 40 is a communication terminal equipped with a communication function and used by a user who uses the service provided by the device 10, and is, for example, a smartphone, a tablet terminal, a computer terminal, or the like.
[0027] In the device management system 1 of this embodiment, the second processing unit 21 of the device management server 20 encrypts the first operation command using connection ID information and shared key information generated each time wireless communication is performed between the wireless terminal 40 and the device 10. Therefore, the encrypted second operation command is different data each time. Therefore, even if a third party illegally obtains the second operation command when the service management server 30 transmits the second operation command to the wireless terminal 40 or when the wireless terminal 40 transmits the second operation command to the device 10 and transmits the second operation command from another wireless terminal to the device 10, new connection ID information is generated when the other wireless terminal wirelessly communicates with the device 10. Therefore, the illegally obtained second operation command cannot be decrypted using the newly generated connection ID information, thereby reducing the possibility of a third party illegally using the service provided by the device 10. Therefore, this embodiment can provide a device management system 1 with improved communication security.
[0028] (2) Details The device management system 1 according to this embodiment will be described in detail below with reference to FIGS. 1 to 3. FIG.
[0029] (2.1) Configuration As described above, the device management system 1 of this embodiment includes the device 10 and the device management server 20. The device management system 1 of this embodiment further includes a service management server 30.
[0030] The configuration of each part of the device management system 1 and the configuration of the wireless terminal 40 will be described below.
[0031] (2.1.1) Device As described above, the device 10 includes the first processing unit 11, the first communication unit 12, and the function unit 13. The device 10 further includes a first storage unit 14.
[0032] The first processing unit 11 is mainly composed of a computer system having one or more processors and a memory. The functions of the first processing unit 11 are realized by the processor of the computer system executing a program recorded in the memory of the computer system. The program may be recorded in the memory, provided via a telecommunications line such as the Internet, or provided by being recorded on a non-transitory recording medium such as a memory card.
[0033] The first communication unit 12 performs wireless communication with the wireless terminal 40. The communication method for wireless communication between the first communication unit 12 and the wireless terminal 40 is, for example, Bluetooth (registered trademark) Low Energy (BLE). Note that the communication method for wireless communication between the first communication unit 12 and the wireless terminal 40 may be a communication method such as Bluetooth, Wi-Fi (registered trademark), ZigBee (registered trademark), or a low-power radio that does not require a license (specified low-power radio).
[0034] The functional unit 13 has a function of providing predetermined services. In this embodiment, the device 10 is an electric lock device, and the functional unit 13 provides, for example, a service of locking and unlocking the front door of the dwelling unit.
[0035] The first storage unit 14 includes a memory such as a rewritable nonvolatile memory, such as a random access memory (RAM), a read-only memory (ROM), or an electrically erasable programmable read-only memory (EEPROM). The first storage unit 14 stores individual device ID information (e.g., a MAC address, an IP address, etc.) assigned to the device 10. The first storage unit 14 also stores shared key information set by the device management server 20 in which the device 10 is registered. In this embodiment, the device 10 is an electric lock device, and the shared key information is set in the device 10 during the manufacturing stage of the device 10.
[0036] (2.1.2) Device Management Server The device management server 20 manages or controls the managed devices 10. As described above, the device management server 20 includes the second processing unit 21 and the second communication unit 22. The device management server 20 also includes a second storage unit 23.
[0037] The second processing unit 21 mainly comprises a computer system having one or more processors and a memory. The functions of the second processing unit 21 are realized by the processor of the computer system executing a program recorded in the memory of the computer system. The program may be recorded in the memory, or may be provided via a telecommunications line such as the Internet, or may be recorded on a non-transitory recording medium such as a memory card and provided.
[0038] The second communication unit 22 communicates with the service management server 30 via a network 50 such as the Internet. It is preferable that an encrypted communication method such as TLS (Transport Layer Security) / SSL (Secure Sockets Layer) communication be used for communication between the second communication unit 22 and the service management server 30. Note that the network 50 is not limited to the Internet and may be, for example, a local communication network established in the area where the device 10 is installed.
[0039] The second storage unit 23 includes, for example, a RAM, a ROM, or a rewritable nonvolatile memory such as an EEPROM. The second storage unit 23 stores device ID information of the device 10 registered as a management target in the device management server 20 in association with shared key information set in the device 10. The shared key information may be set in the device management server 20 that manages the device 10 during the manufacturing stage of the device 10, or the shared key information set in the device 10 when registering the device 10 with the device management server 20 after shipping from the factory may be registered in the device management server 20. In other words, when registering the device 10 to be managed, the device management server 20 sets the shared key information to be shared with the device 10 in both the device management server 20 and the device 10. The second storage unit 23 also stores an API (Application Programming Interface) that generates a first operation command for causing the device 10 to execute a desired service in response to a request from the service management server 30 and generates a second operation command by encrypting the first operation command.
[0040] The equipment management server 20 makes the above API public to the service management server 30, and when the second communication unit 22 receives a request from the service management server 30, the second processing unit 21 generates a second operation command and causes the second communication unit 22 to transmit the generated second operation command to the service management server 30.
[0041] (2.1.3) Service Management Server The service management server 30 has a function of managing the services provided by the device 10. The service management server 30 has, for example, a function of managing users who use the services provided by the device 10, and a function of charging users according to the use of the service if the use of the service is fee-based. For example, the service management server 30 assigns a user ID and password for using the service to a user who can use the service provided by the device 10, and the user inputs the user ID and password into the wireless terminal 40 to have the wireless terminal 40 authenticated by the service management server 30.
[0042] It is also assumed that the service management server 30 is pre-registered in a device management server 20 that manages one or more devices 10 used to provide services that are under the management of the service management server 30. In other words, the service management server 30 that manages the services provided by the managed devices 10 is pre-registered in the device management server 20. The device management server 20 issues, for example, an ID and a password to the service management server 30, and when the service management server 30 accesses the device management server 20, the user inputs the ID and password to have the device management server 20 authenticate the user.
[0043] The service management server 30 includes a third communication unit 32 that communicates with the wireless terminal 40 and the device management server 20. The service management server 30 further includes a third processing unit 31 and a third storage unit 33.
[0044] The third processing unit 31 mainly comprises a computer system having one or more processors and a memory. The functions of the third processing unit 31 are realized by the processor of the computer system executing a program recorded in the memory of the computer system. The program may be recorded in the memory, or may be provided via a telecommunications line such as the Internet, or may be recorded on a non-transitory recording medium such as a memory card and provided.
[0045] The third communication unit 32 communicates with the device management server 20 via a network 50 such as the Internet. The third communication unit 32 also communicates with the wireless terminal 40 via the network 50 (including a mobile communication network) and a wireless access point (denoted as "AP" in FIG. 1 ) 51.
[0046] The third storage unit 33 includes, for example, a RAM, a ROM, or a rewritable nonvolatile memory such as an EEPROM. The third storage unit 33 stores the network address of the service management server 30, the network address of the device management server 20, and the like. The third storage unit 33 also stores terminal ID information of wireless terminals 40 registered as managed by the service management server 30 and device ID information of devices 10 available to the wireless terminals 40. The third storage unit 33 also stores operation request information indicating which device 10 is to execute which service. The service management server 30 manages multiple services, and the third storage unit 33 stores multiple pieces of operation request information corresponding to each of the multiple services. For example, if the service management server 30 manages a service for unlocking and a service for locking a front door using the device 10, which is an electric lock device, the third storage unit 33 stores operation request information corresponding to the service for unlocking the front door and the service for locking the front door.
[0047] (2.1.4) Wireless Terminal The wireless terminal 40 includes a fourth processing unit 41 , a fourth communication unit 42 , a fifth communication unit 43 , a display unit 44 , an operation reception unit 45 , and a fourth storage unit 46 .
[0048] The fourth processing unit 41 mainly comprises a computer system having one or more processors and a memory. The processor of the computer system executes a program stored in the memory of the computer system, thereby realizing the functions of the fourth processing unit 41. The program may be stored in the memory, may be provided via a telecommunications line such as the Internet, or may be provided by being recorded on a non-transitory recording medium such as a memory card.
[0049] The fourth communication unit 42 performs wireless communication with the device 10. The communication method for wireless communication between the fourth communication unit 42 and the device 10 is, for example, BLE. Note that the communication method for wireless communication between the fourth communication unit 42 and the device 10 is not limited to BLE, and may be a communication method such as Bluetooth, Wi-Fi, ZigBee, or low-power radio that does not require a license.
[0050] The fifth communication unit 43 is connected to a network 50 such as the Internet via a wireless access point 51 , and communicates with the service management server 30 via the network 50 .
[0051] The display unit 44 includes, for example, a thin display device such as a liquid crystal display, etc. The display unit 44 displays on the screen of the display device display content indicating the operating state of the device 10, operation buttons for causing the device 10 to perform desired operations, etc.
[0052] The operation reception unit 45 includes a position input device such as a touchpad combined with a display device. The operation reception unit 45 receives an operation (such as a tap, double tap, flick, or swipe) in which the user touches an operation button displayed on the screen of the display device with a finger, and outputs a signal corresponding to the operation to the fourth processing unit 41.
[0053] The fourth storage unit 46 includes a memory such as a RAM, a ROM, or a rewritable nonvolatile memory such as an EEPROM, etc. The fourth storage unit 46 stores terminal ID information of the wireless terminal 40, device ID information of the device 10 used with the wireless terminal 40, an application program for operating the device 10, etc.
[0054] (2.2) Description of Operation (2.2.1) Description of Service Provision Operation The operation of the device management system 1 when a user uses a wireless terminal 40 to access a service provided by the device 10 will be described with reference to the sequence diagram in Figure 2. Note that the sequence diagram shown in Figure 2 is merely an example of a device management method according to this embodiment, and the order of processing may be changed as appropriate, and processing may be added or omitted as appropriate. In Figure 2, the device 10 and the device management server 20 are connected by a single virtual communication path.
[0055] When the fourth processing unit 41 of the wireless terminal 40 executes an application program for operating the device 10, operation buttons and the like for operating the device 10 are displayed on the screen of the display unit 44. In this embodiment, the device 10 is an electric lock device, and the display unit 44 displays an unlock operation button for unlocking the front door using the electric lock device, which is the device 10, or a lock operation button for locking the front door.
[0056] For example, when the user taps an unlock operation button displayed on the screen of the display unit 44, the operation acceptance unit 45 accepts the user's unlock operation and outputs a signal indicating that the unlock operation has been performed to the fourth processing unit 41 (step ST1). When the signal indicating that the unlock operation has been performed is input from the operation acceptance unit 45, the fourth processing unit 41 starts communication between the fourth communication unit 42 and the device 10 (step ST2), and causes the fourth communication unit 42 to transmit a request signal requesting connection ID information to the device 10 (step ST3).
[0057] When the first communication unit 12 of the device 10 receives a request signal from the wireless terminal 40, the first processing unit 11 generates individual connection ID information each time communication is performed with the wireless terminal 40 (step ST4), and causes the first communication unit 12 to transmit the connection ID information to the wireless terminal 40 (step ST5). In other words, this embodiment further includes a step in which the device 10 generates connection ID information each time wireless communication is performed with the wireless terminal 40.
[0058] When the fourth communication unit 42 of the wireless terminal 40 receives the connection ID information from the device 10, the fourth processing unit 41 causes the fifth communication unit 43 to transmit the connection ID information, the device ID information of the device 10, operation information indicating the operation content of the device 10 accepted by the operation acceptance unit 45, and the terminal ID information to the service management server 30 via the network 50 (step ST6).
[0059] When the third communication unit 32 of the service management server 30 receives the connection ID information, device ID information, operation information, and terminal ID information from the wireless terminal 40, the third processing unit 31 checks whether the user is eligible to use the service provided by the device 10 based on the device ID information, operation information, terminal ID information, etc. (step ST7). When the third processing unit 31 checks that the user of the wireless terminal 40 is eligible to use the service provided by the device 10, the third processing unit 31 generates operation request information indicating which device 10 should execute which service based on the device ID information and operation information. The third processing unit 31 then transmits the operation request information and connection ID information from the third communication unit 32 to the device management server 20 via the network 50 (step ST8).
[0060] When the second communication unit 22 of the device management server 20 receives the operation request information and connection ID information from the service management server 30, the second processing unit 21 determines whether the service management server 30 is registered with the device management server 20 based on the operation request information received from the service management server 30 and the ID information of the service management server 30. That is, the second processing unit 21 determines whether the operation request information is from a service management server 30 that is authorized to provide a service using the device 10. Here, if the service management server 30 is registered with the device management server 20, the second processing unit 21 identifies the device 10 to be operated based on the operation request information and generates a first operation command for causing the identified device 10 to execute a service corresponding to the operation content (step ST9). Note that if the service management server 30 is not registered with the device management server 20, the second processing unit 21 discards the operation request information and does not perform the process of generating the first operation command. As described above, in the device management system 1 of this embodiment, the device management server 20 executes a step of determining whether the service management server 30 is registered with the device management server 20 based on operation request information received from the service management server 30. Also, in the device management system 1, if the service management server 30 is registered with the device management server 20, the device management server 20 executes a step of identifying the device 10 to be operated based on the operation request information. Then, in the device management system 1, the device management server 20 executes a step of generating a first operation command that causes the identified device 10 to perform a service according to the operation content. The device management server 20 generates the first operation command based on the operation request information only if the service management server 30 is registered with the device management server 20, thereby reducing the possibility that an unauthorized service management server 30 will execute a service using the device 10.
[0061] Next, the second processing unit 21 generates a second operation command by encrypting the first operation command using shared key information shared with the device 10 to be operated and connection ID information received from the service management server 30 (step ST10). The second processing unit 21 generates the second operation command by encrypting the first operation command using key information obtained by, for example, performing an operation (e.g., an XOR operation) on the shared key information and the connection ID information. Note that the encryption method is, for example, the AES method, but the encryption method can be changed as appropriate as long as plain text can be encrypted using two pieces of information, the shared key information and the connection ID information.
[0062] When the second processing unit 21 generates the second operation command, it causes the second communication unit 22 to transmit the generated second operation command to the service management server 30 (step ST11). When the third communication unit 32 of the service management server 30 receives the second operation command from the device management server 20, the third processing unit 31 causes the third communication unit 32 to transmit the second operation command to the wireless terminal 40 (step ST12).
[0063] When the fifth communication unit 43 of the wireless terminal 40 receives the second operation command from the service management server 30, the fourth processing unit 41 causes the fourth communication unit 42 to transmit the second operation command to the device 10 (step ST13).
[0064] When the first communication unit 12 of the device 10 receives the second operation command from the wireless terminal 40, the first processing unit 11 acquires the first operation command by decrypting the second operation command using the shared key information and the connection ID information generated in step ST4 (step ST14). If the first processing unit 11 successfully decrypts the first operation command, it controls the function unit 13 in accordance with the first operation command and provides the desired service (here, the service of unlocking the front door) via the function unit 13 (step ST15).
[0065] As described above, in the device management system 1 of this embodiment, the device management server 20 generates the second operation command by encrypting the first operation command using the connection ID information and shared key information generated each time the wireless terminal 40 and the device 10 communicate. Therefore, the second operation command obtained by encrypting the first operation command is different each time. Therefore, even if someone illicitly obtains the second operation command and transmits the illegally obtained second operation command to the device 10 from another wireless terminal, the second operation command cannot be correctly decrypted using the connection ID information and shared key information generated when the other wireless terminal communicates with the device 10, thereby preventing unauthorized use of the device 10. Therefore, this embodiment realizes a device management system 1 with improved communication security. Furthermore, because the connection ID information used by the device 10 to decrypt the second operation command is generated each time the device 10 communicates with the wireless terminal 40, communication security can be further improved compared to using connection ID information input from an external source.
[0066] The first processing unit 11 of the device 10 preferably sets the expiration date to the elapsed time T1 from the first time point when the connection ID information is transmitted to the wireless terminal 40 to the second time point when the second operation command is received. In other words, the device 10 preferably invalidates the second operation command if the elapsed time T1 from the first time point when the connection ID information is transmitted to the wireless terminal 40 to the second time point when the second operation command is received exceeds the expiration date. Therefore, the first processing unit 11 counts the elapsed time T1 from the first time point when the connection ID information is transmitted to the wireless terminal 40 to the second time point when the second operation command is received. If the elapsed time T1 is equal to or less than the expiration date, the first processing unit 11 executes a process to decrypt the received second operation command. However, if the elapsed time T1 exceeds the expiration date, the first processing unit 11 invalidates the received second operation command. This further reduces the possibility of using an illegally obtained second operation command, thereby realizing a device management system 1 with further improved communication security.
[0067] (2.2.2) Device Registration Operation Next, the operation of the device management system 1 when, for example, a user who is the owner of the device 10 registers the device 10 in the device management server 20 using the wireless terminal 40 will be described with reference to the sequence diagram of Fig. 3. Note that the sequence diagram shown in Fig. 3 is merely one example of a method for registering the device 10 in the device management server 20, and the order of the processes may be changed as appropriate, and processes may be added or omitted as appropriate.
[0068] First, a registration process (step ST21) is performed to register the service management server 30 that manages the service provided by the device 10 in the device management server 20, and when using the service, an authentication process (step ST22) is performed in which the device management server 20 authenticates the registered service management server 30. The registration process to register the service management server 30 in the device management server 20 and the authentication process to authenticate the service management server 30 by the device management server 20 may be performed by any conventionally known method, and the method is not critical.
[0069] Furthermore, a registration process (step ST23) is performed to register the wireless terminal 40 used to use the service with the service management server 30, and when the service is used, an authentication process (step ST24) is performed by the service management server 30 to authenticate the registered wireless terminal 40. The registration process to register the wireless terminal 40 with the service management server 30 and the authentication process to authenticate the wireless terminal 40 by the service management server 30 may be performed by any conventionally known method, and the method is not critical.
[0070] When the user who is the owner of the device 10 registers a new device 10 in the device management server 20, the user operates the wireless terminal 40 to acquire device ID information from the device 10 (step ST25).
[0071] When the wireless terminal 40 acquires the device ID information from the device 10, it transmits the device ID information and the terminal ID information to the service management server 30 (step ST26).
[0072] When the service management server 30 receives the device ID information and terminal ID information from the wireless terminal 40, it determines the content of the service to be provided to the user based on the terminal ID information, and sends the service ID information indicating the content of the service and the device ID information to the device management server 20 (step ST27).
[0073] Based on the service ID information and device ID information received from the service management server 30, the device management server 20 generates operation request information for causing the device 10 to execute the service corresponding to the service ID information (step ST28), and transmits this operation request information to the service management server 30 (step ST29).
[0074] When the service management server 30 receives the operation request information from the device management server 20, the service management server 30 stores the operation request information in the third storage unit 33 in association with the terminal ID information of the wireless terminal 40, operation information indicating the operation content accepted by the wireless terminal 40, and device ID information of the device 10 (step ST30). Thereafter, when the service management server 30 receives from the wireless terminal 40 a request signal requesting the provision of a service by the device 10, it transmits operation request information corresponding to the requested service to the device management server 20. In this way, when the device 10 that executes a service managed by the service management server 30 is registered in the device management server 20, the device management server 20 registers the service managed by the service management server 30 in association with the device 10.
[0075] (3) Modifications The above embodiment is merely one of various embodiments of the present disclosure. The above embodiment can be modified in various ways depending on the design, etc., as long as the object of the present disclosure can be achieved. Furthermore, functions similar to those of the device management system 1 may be embodied in a device management method, a computer program, a non-transitory recording medium on which a program is recorded, or the like.
[0076] A device management method according to one aspect includes a step in which, when a wireless terminal 40 accepts an operation related to the use of a service and wirelessly communicates with a device 10, the device 10 transmits connection ID information to the wireless terminal 40, the connection ID information being generated each time the wireless terminal 40 and the device 10 communicate wirelessly. The wireless terminal 40 is used to use a service provided by the device 10 to which the device ID information is assigned. The device management method includes a step in which a device management server 20 managing the device 10 receives, from a service management server 30 managing the wireless terminal 40, operation information related to the operation content accepted by the wireless terminal 40, operation request information based on the device ID information, and connection ID information. The device management method includes a step in which the device management server 20 generates a first operation command, based on the operation request information, for causing the device 10 to perform a service corresponding to the operation content. The device management method includes a step in which the device management server 20 generates a second operation command by encrypting the first operation command using shared key information shared between the device management server 20 and the device 10 and the connection ID information. The device management method includes a step in which the device management server 20 transmits the second operation command to the service management server 30. The device management method includes a step in which the device 10 receives a second operation command from the wireless terminal 40 that has received the second operation command from the service management server 30 (i.e., a step in which the device 10 receives the second operation command from the service management server 30 via the wireless terminal 40). The device management method includes a step in which the device 10 decrypts the second operation command using shared key information and connection ID information to obtain a first operation command. The device management method includes a step in which the device 10 executes a service in accordance with the first operation command.
[0077] A (computer) program according to one aspect is a program for causing a computer system to function as the device 10 included in the device management system 1. The program causes the computer system to execute a first step, a second step, a third step, and a fourth step. In the first step, when the wireless terminal 40 accepts an operation related to use of a service and wirelessly communicates with the device 10, connection ID information generated each time the wireless terminal 40 and the device 10 communicate wirelessly is transmitted to the wireless terminal 40. In the second step, a second operation command is received from the wireless terminal 40 that has received the second operation command from the service management server 30. In the third step, the second operation command is decrypted using the shared key information and the connection ID information to obtain a first operation command. In the fourth step, the service is executed in accordance with the first operation command.
[0078] A (computer) program according to one aspect is a program for causing a computer system to function as the device management server 20 included in the device management system 1. The program causes the computer system to execute a first step, a second step, a third step, and a fourth step. In the first step, operation request information based on device ID information and operation information related to operation content accepted by the wireless terminal 40, and connection ID information, are received from the service management server 30. In the second step, a first operation command is generated based on the operation request information to cause the device 10 to perform a service corresponding to the operation content. In the third step, a second operation command is generated by encrypting the first operation command using shared key information and connection ID information shared between the device management server 20 and the device 10. In the fourth step, the second operation command is transmitted to the service management server 30.
[0079] Modifications of the above embodiment are listed below. The modifications described below can be applied in appropriate combinations.
[0080] The executing entities of the device management system 1 or device management method of the present disclosure (device 10, device management server 20, service management server 30, and wireless terminal 40) include a computer system. The computer system is primarily composed of a processor and memory as hardware. The processor executes a program stored in the memory of the computer system to realize the functions of the executing entities of the device management system 1 or device management method of the present disclosure. The program may be pre-stored in the memory of the computer system, provided via a telecommunications line, or provided by being stored on a non-transitory recording medium readable by the computer system, such as a memory card, optical disk, or hard disk drive. The processor of the computer system is composed of one or more electronic circuits including a semiconductor integrated circuit (IC) or a large-scale integrated circuit (LSI). The integrated circuits, such as ICs and LSIs, are referred to by different names depending on the degree of integration, and include integrated circuits called system LSIs, very large-scale integration (VLSI), or ultra-large-scale integration (ULSI). Furthermore, a field-programmable gate array (FPGA), which is programmed after the LSI is manufactured, or a logic device capable of reconfiguring the connections within the LSI or the circuit partitions within the LSI, can also be employed as a processor. Multiple electronic circuits may be integrated into a single chip or distributed across multiple chips. Multiple chips may be integrated into a single device or distributed across multiple devices. The computer system referred to here includes a microcontroller having one or more processors and one or more memories. Therefore, the microcontroller is also composed of one or more electronic circuits, including a semiconductor integrated circuit or a large-scale integrated circuit.
[0081] Furthermore, it is not essential for the device management system 1 that multiple functions are concentrated in one housing, and the components of the device management system 1 may be distributed across multiple housings. Furthermore, at least some of the functions of the device management system 1, for example, some of the functions of the device management server 20 or the service management server 30, may be realized by the cloud (cloud computing) or the like.
[0082] Conversely, in the above embodiment, at least some of the functions of the device management system 1 that are distributed across multiple devices may be consolidated into a single housing. For example, functions that are distributed across the device management server 20 and the service management server 30 may be consolidated into a single housing. For example, the device management server 20 and the service management server 30 do not need to be physically separated, but may be logically (virtually) separated. The device management server 20 that manages the devices 10 and the service management server 30 that manages services using the devices 10 may be virtually provided on the same physical server.
[0083] The business operator that manages the devices 10 using the device management server 20 and the business operator that manages the users who use the service using the service management server 30 may be the same or different.
[0084] Furthermore, in the above embodiment, the device 10 generates connection ID information each time it communicates with the wireless terminal 40, but the wireless terminal 40 may transmit the connection ID information generated to the device 10 each time it communicates with the device 10, and the device 10 may use the connection ID information generated by the wireless terminal 40.
[0085] Although the wireless terminal 40 mediates communication between the device 10 and the service management server 30, if the device 10 can communicate with the service management server 30, the device 10 may send the device ID information and connection ID information directly to the service management server 30.
[0086] (Summary) The above-described embodiments and the like disclose the following aspects.
[0087] A first aspect of the device management method includes a step in which, when a wireless terminal (40) accepts an operation related to the use of a service and wirelessly communicates with a device (10), the device (10) transmits connection ID information generated each time the wireless terminal (40) and the device (10) communicate wirelessly to the wireless terminal (40). The wireless terminal (40) is used to use a service provided by the device (10) to which the device ID information is assigned. The device management method includes a step in which a device management server (20) managing the device (10) receives, from a service management server (30) managing the wireless terminal (40), operation request information based on the device ID information and operation information related to the operation content accepted by the wireless terminal (40). The device management method includes a step in which the device management server (20) generates a first operation command based on the operation request information to cause the device (10) to perform a service corresponding to the operation content. The device management method includes a step in which a device management server (20) generates a second operation command by encrypting a first operation command using shared key information and connection ID information shared between the device management server (20) and the device (10). The device management method includes a step in which the device management server (20) transmits the second operation command to a service management server (30). The device management method includes a step in which the device (10) receives the second operation command from a wireless terminal (40) that has received the second operation command from the service management server (30). The device management method includes a step in which the device (10) decrypts the second operation command using the shared key information and connection ID information to obtain a first operation command. The device management method includes a step in which the device (10) executes a service in accordance with the first operation command.
[0088] According to this aspect, the device management server (20) encrypts the first operation command using connection ID information and shared key information generated each time wireless communication is performed between the wireless terminal (40) and the device (10). Therefore, the encrypted second operation command is different data each time. Therefore, even if a third party illegally obtains the second operation command when the service management server (30) transmits the second operation command to the wireless terminal (40) or when the wireless terminal (40) transmits the second operation command to the device (10) and transmits the second operation command from another wireless terminal to the device (10), new connection ID information is generated when the other wireless terminal wirelessly communicates with the device (10). Therefore, the illegally obtained second operation command cannot be decrypted using the newly generated connection ID information. This reduces the possibility of a third party illegally using a service provided by the device (10). Therefore, a device management method with improved communication security can be provided.
[0089] In the device management method of the second aspect, in the first aspect, the device (10) invalidates the second operation command if the elapsed time from the first point in time when the connection ID information is transmitted to the wireless terminal (40) to the second point in time when the second operation command is received exceeds the expiration date.
[0090] According to this aspect, by setting an expiration date for the time that has elapsed from the first point in time to the second point in time, the security of communication can be further improved.
[0091] The device management method of the third aspect, in the first or second aspect, further includes a step in which, when the device management server (20) registers the device (10) to be managed, the device management server (20) sets shared key information to be shared with the device (10) in each of the device management server (20) and the device (10).
[0092] According to this aspect, even when a new device (10) is added to the device management server (20), the security of communication with the added device (10) can be improved.
[0093] A fourth aspect of the device management method is the same as any of the first to third aspects, and further includes a step in which the device management server (20) determines whether the service management server (30) is registered with the device management server (20) based on operation request information received from the service management server (30). The device management method further includes a step in which, if the service management server (30) is registered with the device management server (20), the device management server (20) identifies the device (10) to be operated based on the operation request information. The device management method further includes a step in which the device management server (20) generates a first operation command to cause the identified device (10) to perform a service corresponding to the operation content.
[0094] According to this aspect, it is possible to reduce the possibility that a service using the device (10) is provided by a service management server (30) that is not registered in the device management server (20).
[0095] The device management method of the fifth aspect is any one of the first to fourth aspects, further including a step of generating connection ID information each time the device (10) performs wireless communication with the wireless terminal (40).
[0096] According to this aspect, the device (10) decrypts the second operation command using the connection ID information generated by the device (10), thereby further improving the security of communication compared to when the second operation command is decrypted using connection ID information input from outside.
[0097] A device management system (1) of a sixth aspect includes a device (10) assigned with device ID information and a device management server (20) that manages the device (10). The device (10) has a first communication unit (12) that wirelessly communicates with a wireless terminal (40) used to use a service provided by the device (10), a function unit (13) that provides the service, and a first processing unit (11). The device management server (20) has a second communication unit (22) that communicates with a service management server (30) that manages the wireless terminal (40), and a second processing unit (21). When the wireless terminal (40) accepts an operation related to the use of the service and wirelessly communicates with the device (10), the first communication unit (12) transmits connection ID information, which is generated each time the wireless terminal (40) and the device (10) wirelessly communicate with each other, to the wireless terminal (40). A second communication unit (22) receives, from the service management server (30), operation request information based on operation information and device ID information regarding operation content accepted by the wireless terminal (40), and connection ID information. A second processing unit (21) generates a first operation command for causing the device (10) to perform a service according to the operation content, based on the operation request information. The second processing unit (21) generates a second operation command by encrypting the first operation command using shared key information and connection ID information shared between the device management server (20) and the device (10). The second communication unit (22) transmits the second operation command to the service management server (30). A first communication unit (12) receives the second operation command from the wireless terminal (40) that has received the second operation command from the service management server (30). The first processing unit (11) decrypts the second operation command using the shared key information and connection ID information to acquire the first operation command. A first processing unit (11) causes a function unit (13) to execute a service in accordance with a first operation command.
[0098] According to this aspect, the first operation command is encrypted using connection ID information and shared key information generated each time wireless communication is performed between the wireless terminal (40) and the device (10). Therefore, the encrypted second operation command is different data each time. Therefore, even if a third party illegally obtains the second operation command when the service management server (30) transmits the second operation command to the wireless terminal (40) or when the wireless terminal (40) transmits the second operation command to the device (10) and transmits the second operation command from another wireless terminal to the device (10), new connection ID information is generated when the other wireless terminal wirelessly communicates with the device (10). Therefore, the illegally obtained second operation command cannot be decrypted using the newly generated connection ID information. This reduces the possibility of a third party illegally using the service provided by the device (10). Therefore, a device management system (1) with improved communication security can be provided.
[0099] The device management system (1) of the seventh aspect is the sixth aspect, further comprising a service management server (30). The service management server (30) has a third communication unit (32) that communicates with the wireless terminal (40) and the device management server (20).
[0100] According to this aspect, it is possible to provide a device management system (1) with improved communication security.
[0101] A program according to an eighth aspect is a program for causing a computer system to function as the device (10) included in the device management system (1) according to the sixth aspect. This program causes the computer system to execute a first step, a second step, a third step, and a fourth step. In the first step, when a wireless terminal (40) accepts an operation related to the use of a service and wirelessly communicates with the device (10), connection ID information generated each time the wireless terminal (40) and the device (10) communicate wirelessly is transmitted to the wireless terminal (40). In the second step, a second operation command is received from the wireless terminal (40) that has received the second operation command from the service management server (30). In the third step, the second operation command is decrypted using the shared key information and the connection ID information to obtain a first operation command. In the fourth step, the service is executed in accordance with the first operation command.
[0102] According to this aspect, the security of communication can be improved.
[0103] A program of a ninth aspect is a program for causing a computer system to function as the device management server (20) included in the device management system (1) of the sixth aspect. This program causes the computer system to execute a first step, a second step, a third step, and a fourth step. In the first step, operation request information based on device ID information and operation information related to operation content accepted by a wireless terminal (40) and connection ID information are received from a service management server (30). In the second step, a first operation command is generated based on the operation request information to cause the device (10) to perform a service corresponding to the operation content. In the third step, a second operation command is generated by encrypting the first operation command using shared key information and connection ID information shared between the device management server (20) and the device (10). In the fourth step, the second operation command is transmitted to the service management server (30).
[0104] According to this aspect, the security of communication can be improved.
[0105] Not limited to the above aspects, various configurations (including modified examples) of the device management system (1) according to the embodiment can be embodied as a device management method, a (computer) program, or a non-transitory recording medium on which a program is recorded, etc.
[0106] The configurations according to the second to fifth aspects are not essential for the device management method and may be omitted as appropriate. The configuration according to the seventh aspect is not essential for the device management system (1) and may be omitted as appropriate.
[0107] REFERENCE SIGNS LIST 1 Device management system 10 Device 11 First processing unit 12 First communication unit 13 Functional unit 20 Device management server 21 Second processing unit 22 Second communication unit 30 Service management server 32 Third communication unit 40 Wireless terminal
Claims
1. a step in which, when a wireless terminal used to use a service provided by a device to which device ID information is assigned receives an operation related to the use of the service and wirelessly communicates with the device, the device transmits connection ID information to the wireless terminal, the connection ID information being generated each time the wireless terminal and the device wirelessly communicate with each other; a step in which a device management server that manages the device receives operation information regarding the operation content accepted by the wireless terminal, operation request information based on the device ID information, and the connection ID information from a service management server that manages the wireless terminal; generating, by the device management server, a first operation command for causing the device to perform the service corresponding to the operation content, based on the operation request information; generating a second operation command by encrypting the first operation command by the device management server using shared key information shared between the device management server and the device and the connection ID information; a step of the device management server transmitting the second operation command to the service management server; receiving, by the device, the second operation command from the wireless terminal that has received the second operation command from the service management server; the device decrypting the second operation command using the shared key information and the connection ID information to obtain the first operation command; causing the device to execute the service in accordance with the first operation command; Equipment management method.
2. the device invalidates the second operation command when the elapsed time from the first point in time when the connection ID information is transmitted to the wireless terminal to the second point in time when the second operation command is received exceeds an expiration date. The device management method according to claim 1 .
3. The method further includes a step of setting, in the device management server and the device, the shared key information to be shared between the device management server and the device when the device management server registers the device to be managed. The device management method according to claim 1 or 2.
4. a step of determining, by the device management server, whether or not the service management server is registered with the device management server based on the operation request information received from the service management server; When the service management server is registered in the device management server, the device management server identifies the device to be operated based on the operation request information; and generating, by the device management server, the first operation command for causing the identified device to perform the service corresponding to the operation content. The device management method according to claim 1 or 2.
5. The device further includes a step of generating the connection ID information each time the device performs wireless communication with the wireless terminal. The device management method according to claim 1 or 2.
6. The system includes a device to which device ID information is assigned and a device management server that manages the device, the device includes a first communication unit that performs wireless communication with a wireless terminal used to use a service provided by the device, a functional unit that provides the service, and a first processing unit; the device management server includes a second communication unit that communicates with a service management server that manages the wireless terminal, and a second processing unit; When the wireless terminal accepts an operation related to use of the service and performs wireless communication with the device, the first communication unit transmits connection ID information generated each time the wireless terminal and the device perform wireless communication to the wireless terminal, the second communication unit receives, from the service management server, operation information relating to the operation content accepted by the wireless terminal, operation request information based on the device ID information, and the connection ID information; the second processing unit generates a first operation command based on the operation request information to cause the device to perform the service corresponding to the operation content; the second processing unit generates a second operation command by encrypting the first operation command using shared key information shared between the device management server and the device and the connection ID information; the second communication unit transmits the second operation command to the service management server; the first communication unit receives the second operation command from the wireless terminal that has received the second operation command from the service management server; the first processing unit decrypts the second operation command using the shared key information and the connection ID information to obtain the first operation command; the first processing unit causes the functional unit to provide the service in accordance with the first operation command; Equipment management system.
7. The service management server is further provided, the service management server has a third communication unit that communicates with the wireless terminal and the device management server; The device management system according to claim 6 .
8. A program for causing a computer system to function as the device included in the device management system according to claim 6, The computer system includes: When the wireless terminal receives an operation related to use of the service and wirelessly communicates with the device, the wireless terminal transmits the connection ID information generated each time the wireless terminal and the device communicate with each other via wireless communication to the wireless terminal; receiving the second operation command from the wireless terminal that has received the second operation command from the service management server; decrypting the second operation command using the shared key information and the connection ID information to obtain the first operation command; executing the service in accordance with the first operation command; program.
9. 7. A program for causing a computer system to function as the device management server of the device management system according to claim 6, The computer system includes: receiving, from the service management server, the operation request information based on the operation information and the device ID information relating to the operation content accepted by the wireless terminal, and the connection ID information; generating the first operation command based on the operation request information to cause the device to perform the service corresponding to the operation content; generating the second operation command by encrypting the first operation command using the shared key information and the connection ID information shared between the device management server and the device; transmitting the second operation command to the service management server; program.