Secure communication method and system in the internet of things environment
Patent Information
- Application Number
- KR1020230195761
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-12-28
Smart Images

Figure 112023147319374-PAT00001_ABST
Abstract
Description
Technology Field
[0001] The present disclosure relates to a secure communication method and system in an Internet of Things environment. Background Technology
[0002] The Internet of Things (IoT) system is a technology in which everyday physical objects are connected to each other via the Internet to exchange data. Objects collect data through sensors and can provide useful information to one another through network connections. For example, with the advancement of IoT technology, it can be applied in various fields such as object metering, object tracking, and object monitoring.
[0003] In the Internet of Things environment, although relatively simple and small-capacity data is collected and transmitted, multiple objects are interconnected to exchange data, so there is a need to protect the network and ensure secure communication between devices.
[0004] In addition, to operate the Internet of Things system sustainably and efficiently, it is necessary to operate the entire system at low power.
[0005] The aforementioned background technology is technical information that the inventor possessed for the derivation of the present invention or acquired during the process of deriving the present invention, and it cannot be considered as prior art disclosed to the general public prior to the filing of the present invention. The problem to be solved
[0006] Some embodiments according to the present disclosure aim to provide a secure communication method and system in an Internet of Things environment. The problems to be solved by the present invention are not limited to those mentioned above, and other problems and advantages of the present invention not mentioned can be understood from the following description and will be more clearly understood by the embodiments of the present invention. Furthermore, it will be understood that the problems and advantages to be solved by the present invention can be realized by the means and combinations thereof set forth in the claims. means of solving the problem
[0007] As a technical means for achieving the technical problem described above, the first aspect of the present disclosure may provide a method for secure communication in an Internet of Things environment, comprising: a step in which an issuing authority obtains a first issuance key and a second issuance key generated by a user and receives a default key from a device; a step in which the issuing authority performs first authentication with the device using the default key and issues a first device master key generated using the first issuance key to the device; a step in which the issuing authority performs second authentication with the device using the first device master key and issues a second device master key generated using the second issuance key to the device; a step in which the issuing authority performs third authentication with the device using the second device master key and transmits the authentication result to an authentication server; a step in which the authentication server stores the authentication result and searches for the device based on the stored authentication result; and a step in which a data server performs an exchange of encrypted data with the searched device.
[0008] A second aspect of the present disclosure provides a secure communication system in an Internet of Things environment, comprising: a device for acquiring measurement data in the Internet of Things environment; an issuing authority for performing first, second, and third authentications with the device and transmitting the authentication results to an authentication server; an authentication server for storing the authentication results and searching for the device based on the stored authentication results; and a data server for exchanging encrypted data with the searched device.
[0009] In addition to this, other methods for implementing the present invention, other systems, and computer-readable recording media storing a computer program for executing said methods may be further provided.
[0010] Other aspects, features, and advantages other than those described above will become clear from the following drawings, claims, and detailed description of the invention. Brief explanation of the drawing
[0011] FIG. 1 is a diagram illustrating an example of a secure communication system in an Internet of Things environment according to one embodiment. FIG. 2 is a configuration diagram illustrating an example of the internal configuration of an issuing institution according to one embodiment. FIG. 3a is a configuration diagram illustrating an example of the internal configuration of a device according to one embodiment. FIG. 3b is a diagram illustrating an example of a method for controlling the operating state and power consumption of a device according to one embodiment. FIG. 4 is a flowchart illustrating an example of a secure communication method in an Internet of Things environment according to one embodiment. FIGS. 5a and 5b are flowcharts illustrating an example of a primary authentication method between an issuing authority and a device according to one embodiment. FIGS. 6a and 6b are flowcharts illustrating an example of a secondary authentication method between an issuing authority and a device according to one embodiment. FIG. 7 is a flowchart illustrating an example of a third authentication method between an issuing authority and a device according to one embodiment. FIG. 8 is a flowchart illustrating another example of a secure communication method in an Internet of Things environment according to one embodiment. FIG. 9a is a configuration diagram illustrating an example of the internal configuration of an authentication server according to one embodiment. FIG. 9b is a configuration diagram illustrating an example of the internal configuration of a data server according to one embodiment. FIGS. 10 and 11 are flowcharts illustrating an example of a data exchange method between an authentication server, a data server, and a device according to one embodiment. Specific details for implementing the invention
[0012] The advantages and features of the present invention, and the methods for achieving them, will become clear by referring to the embodiments described in detail together with the accompanying drawings. However, the present invention is not limited to the embodiments presented below, but can be implemented in various different forms and should be understood to include all modifications, equivalents, and substitutions that fall within the spirit and scope of the present invention. The embodiments presented below are provided to ensure that the disclosure of the present invention is complete and to fully inform those skilled in the art of the scope of the invention. In describing the present invention, detailed descriptions of related known technologies are omitted if it is determined that such detailed descriptions may obscure the essence of the present invention.
[0013] The terms used in this application are used merely to describe specific embodiments and are not intended to limit the invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, terms such as “comprising” or “having” are intended to specify the presence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0014] Some embodiments of the present disclosure may be represented by functional block configurations and various processing steps. Some or all of these functional blocks may be implemented by various numbers of hardware and / or software configurations that execute specific functions. For example, the functional blocks of the present disclosure may be implemented by one or more microprocessors or by circuit configurations for a specific function. Additionally, for example, the functional blocks of the present disclosure may be implemented in various programming or scripting languages. The functional blocks may be implemented as algorithms executed on one or more processors. Furthermore, the present disclosure may employ prior art for electronic configuration, signal processing, and / or data processing, etc. Terms such as “mechanism,” “element,” “means,” and “configuration” may be used broadly and are not limited to mechanical and physical configurations.
[0015] Furthermore, the connecting lines or connecting members between the components depicted in the drawings are merely illustrative of functional connections and / or physical or circuit connections. In the actual device, connections between components may be represented by various alternative or added functional connections, physical connections, or circuit connections.
[0016] Embodiments are described in detail below with reference to the attached drawings. However, embodiments may be implemented in various different forms and are not limited to the examples described herein.
[0017] FIG. 1 is a diagram illustrating an example of a secure communication system in an Internet of Things environment according to one embodiment.
[0018] Referring to FIG. 1, a secure communication system (1) (hereinafter referred to as the 'system') in an Internet of Things environment may include an issuing authority (10), a device (20), an authentication server (30), and a data server (40). For example, the issuing authority (10), the device (20), the authentication server (30), and the data server (40) may be connected via a network (50) in a wired or wireless communication manner to transmit and receive data to and from each other.
[0019] First, in the present disclosure, the device (20) refers to an Internet of Things device. For example, the device (20) may include household devices such as home appliances, kitchen appliances, heating and cooling devices, lighting devices, and healthcare devices, industrial devices such as network cameras, equipment monitoring devices, energy metering devices, and object location tracking devices, and operating devices such as automobiles and drones.
[0020] The device (20) can generate data by measuring temperature, humidity, weight, location, etc. For example, the data generated by the device (20) may include metering data such as energy usage measurement data, tracking data such as object location tracking data, and monitoring data such as facility monitoring data. Additionally, the device (20) can store data or transmit data to an external device (e.g., an external server or another device). At this time, the device (20) may be equipped with a Secure Element (SE) to maintain the security of the data being stored and the data to be transmitted. For example, the Secure Element (SE) can securely manage important information such as encryption keys, authentication information, and personal information, and can encrypt various data (e.g., measurement data) or generate digital signatures. Hereinafter, with reference to FIG. 3a, examples of the internal configuration of the device (20) and examples of the operation of the device (20) (or the Secure Element installed in the device (20)) will be described in detail.
[0021] The data server (40) can transmit and receive data to and from the device (20) via the network (50) and collect and store data generated by the device (20). Here, for security purposes, the exchanged data may be encrypted or decrypted by the data server (40) or the device (20). More specifically, the data server (40) may receive encrypted data from the device (20), perform decryption on the encrypted data, and store the decrypted data. Alternatively, the data server (40) may encrypt the data to be transmitted and transmit the encrypted data to the device (20). Hereinafter, with reference to FIG. 9b, examples of the internal configuration of the data server (40) and examples of the operation of the data server (40) will be described in detail.
[0022] Meanwhile, in order to maintain data security and ensure data integrity, the data server (40) performs data exchange with the device (20) that has completed authentication, and likewise, the device (20) also performs data exchange with the data server (40) that has completed authentication. At this time, in order to omit the process of performing mutual authentication whenever data exchange occurs, the issuing authority (10) in the present disclosure may perform a mutual authentication process with the device (20) in advance, and the authentication server (30) may store the authentication result after mutual authentication is completed.
[0023] More specifically, the issuing organization (10) can securely generate, store, and manage cryptographic keys using a Hardware Security Module (HSM), issue cryptographic keys to the device (20), and perform a mutual authentication process with the device (20). For example, the issuing organization (10) can perform a mutual authentication process with the device (20) through a first issuance process and a second issuance process, and can generate an authentication result based on the mutual authentication. Hereinafter, with reference to FIG. 2, examples of the internal configuration of the issuing organization (10) and examples of the operation of the issuing organization (10) will be described in detail.
[0024] The authentication server (30) can store the authentication result. Additionally, the authentication server (30) can perform encryption and decryption of data transmitted to and received from the device (20) using a hardware security module (HSM), and can perform a mutual authentication process with the device (20) as needed. Hereinafter, with reference to FIG. 9a, examples of the internal configuration of the authentication server (30) and examples of the operation of the authentication server (30) will be described in detail.
[0025] The network (50) is a network in which an issuing authority (10), a device (20), an authentication server (30), and a data server (40) can be connected to each other via wired or wireless communication. For example, the network (50) may include network technologies used in IoT systems. For example, the network (50) may include Low Power Wide Area (LPWA) networks for IoT systems such as LTE-M, NB-IoT, Sigfox, and LoRa. In addition, the network (50) may include wireless communication networks such as WiFi, 3G / 4G / 5G.
[0026] FIG. 2 is a configuration diagram illustrating an example of the internal configuration of an issuing institution according to one embodiment.
[0027] The issuing authority (100) may be a server that communicates with a device, an authentication server, and a data server. For example, the issuing authority (100) may be a server that stores various data, including an issuance key generated by a user and a default key received from a device. Alternatively, the issuing authority (100) may be a computing device that includes memory and a processor and has its own computational capabilities. Examples of how the issuing authority (100) operates are described below.
[0028] Referring to FIG. 2, the issuing institution (100) may include a processor (110), memory (120), and a communication module (130). For convenience of explanation, FIG. 2 only shows components related to the present invention. Accordingly, other general-purpose components may be included in the issuing institution (100) in addition to the components shown in FIG. 2. Furthermore, it is obvious to those skilled in the art that the processor (110), memory (120), and communication module (130) shown in FIG. 2 may be implemented as independent devices.
[0029] The processor (110) can process instructions of a computer program by performing basic arithmetic, logic, and input / output operations. Here, the instructions may be provided from memory (120) or an external device. Additionally, the processor (110) can control the overall operation of other components included in the issuing institution (100).
[0030] According to one embodiment, the processor (110) may include a hardware security module (HSM) (not shown). The hardware security module (HSM) is a dedicated hardware device for providing security that generates, stores, and manages cryptographic keys (security keys), generates digital signatures, and performs encryption and decryption operations. In the present disclosure, at least some of the operations described below as being performed by the processor (110) of the issuing authority (100) may be performed by the hardware security module (HSM) included in the issuing authority (100).
[0031] The processor (110) may be implemented as an array of multiple logic gates, or as a combination of a general-purpose microprocessor and memory storing a program that can be executed on the microprocessor. For example, the processor (110) may include a general-purpose processor, a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a controller, a microcontroller, a state machine, etc. In some environments, the processor (110) may include an application-specific integrated circuit (ASIC), a programmable logic device (PLD), a field programmable gate array (FPGA), etc. For example, the processor (110) may refer to a combination of processing devices such as a combination of a digital signal processor (DSP) and a microprocessor, a combination of multiple microprocessors, a combination of one or more microprocessors combined with a digital signal processor (DSP) core, or any other combination of such configurations.
[0032] The memory (120) may include any non-transient computer-readable recording medium. As an example, the memory (120) may include a permanent mass storage device such as a random access memory (RAM), read-only memory (ROM), disk drive, solid state drive (SSD), or flash memory. As another example, a permanent mass storage device such as a ROM, SSD, flash memory, or disk drive may be a separate permanent storage device distinct from the memory. Additionally, the memory (120) may store an operating system (OS) and at least one program code (e.g., code for the processor (110) to perform the operation described below).
[0033] These software components may be loaded from a computer-readable recording medium separate from the memory (120). This separate computer-readable recording medium may be a recording medium that can be directly connected to the issuing organization (100), and may include, for example, computer-readable recording media such as a floppy drive, disk, tape, DVD / CD-ROM drive, or memory card. Alternatively, the software components may be loaded into the memory (120) via a communication module (130) that is not a computer-readable recording medium. For example, at least one program may be loaded into the memory (120) based on a computer program (e.g., a computer program for the processor (110) to perform the operation described below) that is installed by files provided through the communication module (130) by developers or a file distribution system that distributes installation files for the application.
[0034] The communication module (130) may provide a configuration or function for the issuing authority (100) to communicate with an external device through a network. Additionally, the communication module (130) may provide a configuration or function for the issuing authority (100) to communicate with another external device (e.g., a device, an authentication server, etc.). For example, control signals, commands, data, etc. provided under the control of the processor (110) may be transmitted to an external device via the communication module (130) and the network.
[0035] According to one embodiment, the communication module (130) can obtain (receive) a primary issued key and a secondary issued key generated by the user, and receive a default key from the device.
[0036] Here, the user refers to an entity operating an Internet of Things system or an entity operating a device. The user can generate a primary issuance key and a secondary issuance key in a secure manner through a hardware security module (HSM), etc., and can transmit them to the issuing organization (100).
[0037] The default key may refer to a key that is injected into the security chip (SE) by default during the process of the security chip (SE) being installed in the device. The device (or the security chip (SE) installed in the device) can transmit the default key to the issuing organization (100) and share it.
[0038] The processor (110) can perform first, second, and third authentications with the device using a predetermined issuance program and generate an authentication result. In the mutual authentication process with the device, the processor (110) (or HSM) can generate, store, and use one or more encryption keys and generate one or more random numbers. For example, the encryption key used in the mutual authentication process may be a symmetric key. To generate a symmetric key, encryption algorithms such as AES (Advanced Encryption Standard), AES-GCM (AES Galois / Counter Mode), and ARIA (Academy, Research Institute, and Agency) may be used. Additionally, the issuing agency (100) may further include a random number generator (e.g., True Random Number Generator) for generating random numbers. In addition, the processor (110) (or HSM) may use encryption technologies such as Hash (hash function), Message-Digest (message digest), and HMAC (Hash-Based Message Authentication Code) during the mutual authentication process with the device.
[0040] (1st verification for 1st issuance)
[0041] The processor (110) can perform primary authentication with the device using a default key. Here, primary authentication between the issuing authority (100) and the device refers to mutual authentication for primary issuance. Below, the operation performed by the processor (110) of the issuing authority (100) for primary authentication with the device is described.
[0042] First, the processor (110) can generate a first server random for primary authentication. For example, the processor (110) (or the HSM of the issuing authority (100)) can generate a server random, which is a random number for security, using an issuance program.
[0043] The processor (110) can generate a first session key using a generated first server random, a default key received from a device, and a first device random (described later). For example, the processor (110) can generate a first session key by applying an encryption algorithm using a default key to data combining the first server random and the first device random. For example, the encryption algorithm may be an HMAC-SHA256 function.
[0044] Additionally, the processor (110) can generate a first server password code by encrypting the first device random and the first server random using the first session key, and can generate a command to transmit the generated first server password code together with the first server random to the device. More specifically, the processor (110) can generate a first server password code by applying an encryption algorithm to the first device random and the first server random using the first session key. Here, the encryption algorithm may be a symmetric encryption algorithm such as AES (Advanced Encryption Standard), AES-GCM (AES Galois / Counter Mode), ARIA (Academy, Research Institute, and Agency) as described above.
[0045] Similarly, the processor (110) can generate a first device password code by applying an encryption algorithm to the first device random and the first server random using the first session key. In other words, the processor (110) of the issuing authority can generate a device password code using the same encryption algorithm as the device.
[0046] Subsequently, in response to receiving a first device password code from a device through a communication module (130), the processor (110) can perform verification of the first device password code using a first session key. More specifically, the processor (110) can compare a first device password code directly generated using the first session key with a first device password code received from the device to determine whether the directly generated session key (first session key) and the session key generated by the device (first session key) are the same value.
[0047] (1st issuance)
[0048] After the first authentication is completed, the processor (110) can issue a first device master key to the device. Here, the first device master key may refer to an encryption key used in the second authentication process for second issuance between the issuing authority (100) and the device.
[0049] More specifically, the processor (110) can first generate a first device master key by encrypting information regarding a security chip (SE Information, SI) included in a device that has completed first authentication and first device master key information using a first issued key. Here, the information regarding the security chip (SI) may include unique information regarding the security chip, such as the serial number of the security chip and an initial random number included in the security chip. Additionally, the first device master key information refers to a predetermined value that enables the distinction of the generated device master key, and may include a value for distinguishing it from the second device master key described later.
[0050] Afterwards, the processor (110) can generate a command to encrypt the generated primary device master key using the first session key and transmit the encrypted primary device master key to the device.
[0051] According to one embodiment, the processor (110) can generate a key check value (kcv) using the primary device master key. Here, the key check value (kcv) may refer to a small digital value capable of verifying the validity of the (primary) device master key. For example, the processor (110) can generate the key check value (kcv) by encrypting specific data (e.g., data known to the issuing authority and the device, public data, agreed-upon data, etc.) with the primary device master key. The key check value (kcv) can subsequently be used by the device to verify the validity of the primary device master key. To this end, the processor (110) can generate a command to transmit the encrypted primary device master key and the key check value (kcv) to the device.
[0053] (Secondary authentication for secondary issuance)
[0054] The processor (110) can perform secondary authentication with the device using the primary device master key generated through primary authentication and issued to the device. Here, secondary authentication between the issuing organization (100) and the device refers to mutual authentication for secondary issuance. Below, the operation performed by the processor (110) of the issuing organization (100) for secondary authentication with the device is described.
[0055] First, the processor (110) can generate a second server random for secondary authentication. For example, the processor (110) (or the HSM of the issuing authority (100)) can generate a server random, which is a random number for security, using an issuing program.
[0056] The processor (110) can generate a second session key using the generated second server random, the second device random received from the device (described later), and the first device master key. For example, the processor (110) can generate a second session key by applying an encryption algorithm using the first device master key to data combining the second server random and the second device random. For example, the encryption algorithm may be the HMAC-SHA256 function. Additionally, the processor (110) can generate a second server password code by encrypting the second device random and the second server random using the second session key, and can generate a command to transmit the generated second server password code together with the second server random to the device. More specifically, the processor (110) can generate a second server password code by applying an encryption algorithm to the second device random and the second server random using the second session key. Here, the encryption algorithm may be a symmetric encryption algorithm such as the aforementioned AES (Advanced Encryption Standard), AES-GCM (AES Galois / Counter Mode), and ARIA (Academy, Research Institute, and Agency).
[0057] Similarly, the processor (110) can generate a second device password code by applying an encryption algorithm to the second device random and the second server random using the second session key. In other words, the processor (110) of the issuing authority can generate a device password code using the same encryption algorithm as the device.
[0058] Subsequently, in response to receiving a second device password code from a device through a communication module (130), the processor (110) can perform verification of the second device password code using a second session key. More specifically, the processor (110) can compare a second device password code generated directly using the second session key with a second device password code received from the device to determine whether the session key generated directly (second session key) and the session key generated by the device (second session key) are the same value.
[0059] (2nd issuance)
[0060] The processor (110) can issue a second device master key to the device after the second authentication is completed. Here, the second device master key may refer to an encryption key used in the third authentication process for generating an authentication result between the issuing authority (100) and the device.
[0061] More specifically, the processor (110) can first generate a second device master key by encrypting information (SI) regarding a security chip included in a device that has completed second authentication and second device master key information using a second issued key. Here, the second device master key information refers to a predetermined value that enables the distinction of the generated device master key, and may include a value for distinguishing it from the first device master key.
[0062] Afterwards, the processor (110) can generate a command to encrypt the generated secondary device master key using the second session key and transmit the encrypted secondary device master key to the device.
[0063] According to one embodiment, the processor (110) can generate a key check value (kcv) using a secondary device master key. Here, the key check value (kcv) may refer to a small digital value capable of verifying the validity of the (secondary) device master key. For example, the processor (110) can generate the key check value (kcv) by encrypting specific data (e.g., data known to both the issuing authority and the device, public data, agreed-upon data, etc.) with the secondary device master key. The key check value (kcv) can subsequently be used by the device to verify the validity of the secondary device master key. To this end, the processor (110) can generate a command to transmit the encrypted secondary device master key and the key check value (kcv) together to the device.
[0065] (3rd Certification)
[0066] The processor (110) can perform third authentication with the device using a second device master key generated through second authentication and issued to the device. Here, third authentication between the issuing authority (100) and the device refers to mutual authentication for generating an authentication result. Additionally, the third session key generated during the third authentication process between the issuing authority (100) and the device can be used in the encryption and decryption processes of data during the data exchange process with the device. Below, the operations performed by the processor (110) of the issuing authority (100) for third authentication with the device are described.
[0067] First, the processor (110) can generate a third server random for third authentication. For example, the processor (110) (or the HSM of the issuing authority (100)) can generate a server random, which is a random number for security, using an issuing program.
[0068] The processor (110) can generate a third session key using a generated third server random, a third device random (described later) received from a device, and a second device master key. For example, the processor (110) can generate a third session key by applying an encryption algorithm using the second device master key to data combining the third server random and the third device random. For example, the encryption algorithm may be the HMAC-SHA256 function.
[0069] Additionally, the processor (110) can generate a third server password code by encrypting the third device random and the third server random using the third session key, and can generate a command to transmit the generated third server password code together with the third server random to the device. More specifically, the processor (110) can generate a third server password code by applying an encryption algorithm to the third device random and the third server random using the third session key. Here, the encryption algorithm may be a symmetric encryption algorithm such as AES (Advanced Encryption Standard), AES-GCM (AES Galois / Counter Mode), ARIA (Academy, Research Institute, and Agency) as described above.
[0070] Similarly, the processor (110) can generate a third device password code by applying an encryption algorithm to the third device random and the third server random using the third session key. In other words, the processor (110) of the issuing authority can generate a device password code using the same encryption algorithm as the device.
[0071] Subsequently, in response to receiving a third device password code from a device through a communication module (130), the processor (110) can perform verification of the third device password code using a third session key. More specifically, the processor (110) can compare a third device password code generated directly using the third session key with a third device password code received from the device to determine whether the session key generated directly (third session key) and the session key generated by the device (third session key) are the same value.
[0073] (Generate and deliver authentication results)
[0074] The processor (110) can generate an authentication result after performing up to third authentication with the device. For example, the processor (110) can generate a CSV (Comma-Separated Values) file containing results regarding mutual authentication with the device. For example, the authentication result may include information about the device (Device Information, DI), information about the security chip included in the device (SI), information about the server random (e.g., third server random) and device random (e.g., third device random) used in the authentication between the issuing authority and the device, and information about the number of authentications (Sequence Counter).
[0075] Afterward, the processor (110) can generate a command to send the generated authentication result to the authentication server.
[0077] FIG. 3a is a configuration diagram illustrating an example of the internal configuration of a device according to one embodiment, and FIG. 3b is a diagram illustrating an example of a method for controlling the operating state and power consumption of a device according to one embodiment.
[0078] Referring to FIG. 3a, the device (300) may include a processor (310), memory (320), an input / output interface (330), and a communication module (340). For convenience of explanation, FIG. 3a only shows components related to the present invention. Accordingly, other general-purpose components may be included in the device (300) in addition to the components shown in FIG. 3a. Furthermore, it is obvious to those skilled in the art that the processor (310), memory (320), input / output interface (330), and communication module (340) shown in FIG. 3a may be implemented as independent devices.
[0079] Meanwhile, as described above, the device (300) may be equipped with a security chip (SE). That is, the processor (310) of the device (300) may include a security chip (not shown), and at least some of the operations described below as being performed by the processor (310) of the device (300) may be performed by the security chip (SE) included in the device (300).
[0080] According to one embodiment, the processor (310) may perform first authentication, second authentication, and third authentication with the issuing authority (or, in some embodiments, an authentication server). In the mutual authentication process with the issuing authority (or, an authentication server), the processor (310) (or SE) may generate, store, and use one or more encryption keys and generate one or more random numbers. For example, the encryption key used in the mutual authentication process may be a symmetric key. To generate the symmetric key, encryption algorithms such as AES (Advanced Encryption Standard), AES-GCM (AES Galois / Counter Mode), and ARIA (Academy, Research Institute, and Agency) may be used. Additionally, the processor (310) may further include a random number generator (e.g., True Random Number Generator) for generating random numbers. Additionally, the processor (310) (or SE) may use encryption technologies such as Hash (hash function), Message-Digest (message digest), and HMAC (Hash-Based Message Authentication Code) during the mutual authentication process with the issuing authority (or authentication server). Meanwhile, specific examples of how the processor (310) operates for mutual authentication with the issuing authority (or authentication server) will be explained in detail below.
[0081] According to another embodiment, the processor (310) may perform encryption of data and decryption of encrypted data to perform data exchange with a data server (or authentication server). Examples of specific operations of the processor (310) for data exchange will be described in detail below through FIGS. 9a and 9b.
[0082] In addition, the processor (310) can control the operation of the device (300) so that a measurement target object (e.g., temperature, humidity, weight, location, etc.) can be measured and collected depending on the type of device (300). In this disclosure, a description of the operation of the processor (310) for measurement is omitted.
[0083] Meanwhile, since the implementation example of the processor (310) may be the same as the implementation example of the processor (110) of the issuing institution described above with reference to FIG. 2, a detailed description is omitted.
[0084] Various data, such as data required for the operation of the processor (310) and data generated according to the operation of the processor (310), can be stored in the memory (320). Additionally, an operating system (OS) and at least one program (e.g., a program required for the operation of the processor (310)) can be stored in the memory (320).
[0085] Additionally, in the present disclosure, the memory (320) may store encryption keys (e.g., default key, device random, server random, session key, device master key, etc.) used in the mutual authentication process with the issuing authority (or, authentication server).
[0086] Meanwhile, since the implementation example of the memory (320) is the same as the implementation example of the memory (120) described above with reference to FIG. 2, a detailed description is omitted.
[0087] The input / output interface (330) may be a means for interfacing with a device for input or output (e.g., a touch screen, keyboard, mouse, etc.) that may be connected to or included in the device (300). In FIG. 3a, the input / output interface (330) is shown as an element configured separately from the processor (310), but is not limited thereto, and the input / output interface (330) may be configured to be included in the processor (310).
[0088] The communication module (340) may provide configuration or functions for communicating with the device (300) and other external devices (e.g., an issuing authority, an authentication server, and a data server) through a network. For example, control signals, commands, data, etc. provided under the control of the processor (310) may be transmitted to an external device via the communication module (340) and the network. For example, the communication module (340) may transmit a default key to the issuing authority.
[0090] (1st verification for 1st issuance)
[0091] The processor (310) can perform a first authentication with the issuing authority. Here, the first authentication with the issuing authority means mutual authentication to obtain a first device master key from the issuing authority.
[0092] The processor (310) can generate a first device random for primary authentication with the issuing authority. For example, the processor (310) (or the SE of the device (300)) can generate a device random that is a random number for security. Additionally, the processor (310) can generate a command to transmit the first device random to the issuing authority.
[0093] The processor (310) can generate a first session key using the generated first device random, the first server random received from the issuing agency, and a default key. For example, the processor (310) can generate a first session key by applying an encryption algorithm using a default key to data combining the first server random and the first device random. For example, the encryption algorithm may be the HMAC-SHA256 function.
[0094] The processor (310) can generate a first server password code by applying an encryption algorithm to the first device random and the first server random using the first session key. In other words, the processor (310) of the device can generate a server password code using the same encryption algorithm as the issuing authority.
[0095] The processor (310) can perform verification of the first server password code using the first session key in response to receiving the first server password code from the issuing authority through the communication module (340). More specifically, the processor (310) can compare the first server password code directly generated using the first session key with the first server password code received from the issuing authority to determine whether the directly generated session key (first session key) and the session key generated by the issuing authority (first session key) are the same value. Additionally, the processor (310) can generate the first device password code by encrypting the first device random and the first server random using the first session key, and can generate a command to transmit the generated first device password code to the issuing authority.
[0096] (1st Device Master Key Verification)
[0097] The processor (310) can verify the primary device master key using a key check value (kcv) in response to receiving the primary device master key from the issuing authority.
[0098] More specifically, the processor (310) can perform decryption of the primary device master key using the first session key and can generate a key check value using the key (primary device master key) obtained through decryption. For example, the processor (310) can generate a key check value (kcv) by encrypting specific data (e.g., data known to each other by the issuing institution and the device, public data, agreed data, etc.) with the primary device master key.
[0099] Additionally, the processor (310) can verify the primary device master key by checking whether the key check value generated using the primary device master key and the key check value received from the issuing authority (i.e., the key check value generated by the issuing authority) are the same value. Through this, the device can verify the security and integrity of the primary device master key issued by the issuing authority.
[0101] (Secondary authentication for secondary issuance)
[0102] The processor (310) can perform secondary authentication with an issuing authority (or, authentication server). Here, secondary authentication with an issuing authority means mutual authentication to obtain a secondary device master key from the issuing authority (or, authentication server).
[0103] The processor (310) may generate a second device random for secondary authentication with an issuing authority (or, in some embodiments, an authentication server). For example, the processor (310) (or the SE of the device (300)) may generate a device random that is a random number for security. Additionally, the processor (310) may generate a command to transmit the second device random to the issuing authority.
[0104] The processor (310) can generate a second session key using the generated second device random, the second server random received from the issuing authority, and the first device master key. For example, the processor (310) can generate a second session key by applying an encryption algorithm using the first device master key to data combining the second server random and the second device random. For example, the encryption algorithm may be the HMAC-SHA256 function.
[0105] The processor (310) can generate a second server password code by applying an encryption algorithm to the second device random and the second server random using the second session key. In other words, the processor (310) of the device can generate a server password code using the same encryption algorithm as the issuing authority.
[0106] The processor (310) can perform verification of the second server password code using the second session key in response to receiving the second server password code from the issuing authority through the communication module (340). More specifically, the processor (310) can compare the second server password code generated directly using the second session key with the second server password code received from the issuing authority to determine whether the session key generated directly (second session key) and the session key generated by the issuing authority (second session key) are the same value. Additionally, the processor (310) can generate the second device password code by encrypting the second device random and the second server random using the second session key, and can generate a command to transmit the generated second device password code to the issuing authority (or authentication server).
[0107] (Secondary Device Master Key Verification)
[0108] The processor (310) can verify the secondary device master key using a key check value (kcv) in response to receiving the secondary device master key from the issuing authority.
[0109] More specifically, the processor (310) can perform decryption of the secondary device master key using the second session key and can generate a key check value using the key (second device master key) obtained through decryption. For example, the processor (310) can generate a key check value (kcv) by encrypting specific data (e.g., data known to each other by the issuing institution and the device, public data, agreed data, etc.) with the secondary device master key.
[0110] Additionally, the processor (310) can verify the secondary device master key by checking whether the key check value generated using the secondary device master key and the key check value received from the issuing authority (i.e., the key check value generated by the issuing authority) are the same value. Through this, the device can verify the security and integrity of the secondary device master key issued by the issuing authority.
[0112] (3rd Certification)
[0113] The processor (310) can perform third authentication with the issuing authority (or, authentication server). Here, third authentication with the issuing authority refers to mutual authentication to generate an authentication result. Additionally, the third session key generated during the third authentication process between the issuing authority (100) and the device can be used in the encryption and decryption process of the data during the data exchange process with the data server.
[0114] The processor (310) may generate a third device random for third authentication with an issuing authority (or, in some embodiments, an authentication server). For example, the processor (310) (or the SE of the device (300)) may generate a device random that is a random number for security. Additionally, the processor (310) may generate a command to transmit the third device random to the issuing authority.
[0115] The processor (310) can generate a third session key using the generated third device random, the third server random received from the issuing authority, and the second device master key. For example, the processor (310) can generate a third session key by applying an encryption algorithm using the second device master key to data combining the third server random and the third device random. For example, the encryption algorithm may be the HMAC-SHA256 function.
[0116] The processor (310) can generate a third server password code by applying an encryption algorithm to the third device random and the third server random using the third session key. In other words, the processor (310) of the device can generate a server password code using the same encryption algorithm as the issuing authority.
[0117] The processor (310) can perform verification of the third server password code using the third session key in response to receiving the third server password code from the issuing authority through the communication module (340). More specifically, the processor (310) can compare the third server password code generated directly using the third session key with the third server password code received from the issuing authority to determine whether the session key generated directly (third session key) and the session key generated by the issuing authority (third session key) are the same value. Additionally, the processor (310) can generate the third device password code by encrypting the third device random and the third server random using the third session key, and can generate a command to transmit the generated third device password code to the issuing authority (or authentication server).
[0118] Meanwhile, referring to FIG. 3b, the processor (310) can control the power consumed based on the operating state (350) of the device (300). For example, the operating state (350) of the device (300) may include an active state (360), a ready or idle state (370), and a power-off state (380). More specifically, the operating state (360) of the device (300) may include a state of performing one of first authentication, second authentication, and third authentication with an issuing authority (or authentication server), and a state of performing an exchange of encrypted data with a data server. Additionally, the standby state (370) of the device (300) may include a state of waiting to receive a signal from any one of the issuing authority, authentication server, and data server, that is, a state of detecting a request for use of the security chip (SE) of the device (300). For example, the processor (310) can control the operation of the device (300) to use a predetermined standby power when the operating state of the device (300) is in a standby state (370). The predetermined standby power may be an amount of power less than the power consumed when the device (300) is in a state (360) of performing operation. According to the embodiment, by minimizing the amount of power consumed by the device (300) (or security chip (SE)), it is possible to build an Internet of Things system even with a low-performance device and improve the durability of the device used.
[0120] FIG. 4 is a flowchart illustrating an example of a secure communication method in an Internet of Things environment according to one embodiment. Additionally, FIG. 5a and 5b are flowcharts illustrating an example of a first authentication method between an issuing authority and a device according to one embodiment, FIG. 6a and 6b are flowcharts illustrating an example of a second authentication method between an issuing authority and a device according to one embodiment, and FIG. 7 is a flowchart illustrating an example of a third authentication method between an issuing authority and a device according to one embodiment. FIG. 8 is a flowchart illustrating another example of a secure communication method in an Internet of Things environment according to one embodiment.
[0121] Referring to FIGS. 4 through 7, examples of a secure communication method in an Internet of Things environment may include a series of operations of a user device (410), a device (420), an issuing authority (430), and an authentication server (440). However, this is not limited thereto, and at least some of the operations of each component described above through FIGS. 1 through 3b may also be applied to the secure communication method of FIGS. 4 through 7. Redundant descriptions will be omitted.
[0122] First, referring to FIG. 4, the issuing authority (430) can obtain a primary issuance key and a secondary issuance key generated by the user through the user device (410) (step 401), and can receive a default key from the device (420) (step 402).
[0123] Subsequently, in step 403, the issuing authority (430) and the device (420) can perform a first authentication with each other using a default key, and in step 404, the issuing authority (430) can issue a first device master key generated using the first issuance key to the device (420). This will be explained with reference to FIGS. 5a and 5b.
[0124] In step 501, the issuing agency (430) and the device (420) can each generate a first server random and a first device random, and the issuing agency (430) can receive the first device random from the device (420) (step 502).
[0125] Subsequently, at step 503, the issuing authority (430) can generate a first session key using a default key, a first device random, and a first server random, and at step 504, the issuing authority (430) can generate a first server password code using the first session key, a first device random, and a first server random, and transmit it to the device (420) together with the first server random.
[0126] Subsequently, in step 505, the device (420) can generate a first session key using a default key, a first device random, and a first server random.
[0127] In step 506, the device (420) can verify the first server password code using the first session key.
[0128] In step 507, the device (420) can generate a first device password code using a first session key, a first device random, and a first server random, and transmit the generated first device password code to an issuing authority.
[0129] In step 508, the issuing authority (430) can complete the first authentication with the device (420) by verifying the first device password code using the first session key.
[0130] Subsequently, in step 509, the issuing authority (430) can generate a primary device master key by encrypting information (SI) regarding a security chip included in the device (420) and primary device master key information using a primary issuing key.
[0131] In step 510, the issuing authority (430) can encrypt the primary device master key using the first session key and transmit the encrypted primary device master key to the device (420) along with the key check value.
[0132] In step 511, the device (420) can decrypt the encrypted primary device master key using the first session key. In step 512, the device (420) can generate a key check value using the decrypted primary device master key. Additionally, in step 513, the device (420) can verify the primary device master key using the key check value.
[0134] Referring again to FIG. 4, in step 405, the issuing authority (430) and the device (420) can perform secondary authentication with each other using the primary device master key, and in step 406, the issuing authority (430) can issue the secondary device master key generated using the secondary issuance key to the device (420). In this regard, this will be explained with reference to FIG. 6a and FIG. 6b.
[0135] In step 601, the issuing agency (430) and the device (420) can each generate a second server random and a second device random, and the issuing agency (430) can receive the second device random from the device (420) (step 602).
[0136] Subsequently, at step 603, the issuing authority (430) can generate a second session key using the first device master key, the second device random, and the second server random, and at step 604, the issuing authority (430) can generate a second server password code using the second session key, the second device random, and the second server random, and transmit the generated second server password code together with the second server random to the device (420).
[0137] Subsequently, in step 605, the device (420) can generate a second session key using the first device master key, the second device random, and the second server random.
[0138] In step 606, the device (420) can verify the second server password code using the second session key.
[0139] In step 607, the device (420) can generate a second device password code using a second session key, a second device random, and a second server random, and transmit the generated second device password code to an issuing authority.
[0140] In step 608, the issuing authority (430) can complete secondary authentication with the device (420) by verifying the second device password code using the second session key.
[0141] Subsequently, in step 609, the issuing authority (430) can generate a secondary device master key by encrypting information (SI) regarding the security chip included in the device (420) and secondary device master key information using a secondary issuing key.
[0142] In step 610, the issuing authority (430) can encrypt the secondary device master key using the second session key and transmit the encrypted secondary device master key to the device (420) along with the key check value.
[0143] In step 611, the device (420) can decrypt the encrypted secondary device master key using the second session key. In step 612, the device (420) can generate a key check value using the decrypted secondary device master key. Additionally, in step 612, the device (420) can verify the secondary device master key using the key check value.
[0145] Referring again to FIG. 4, in step 407, the issuing authority (430) and the device (420) can perform tertiary authentication with each other using a secondary device master key, and in step 408, the issuing authority (430) can transmit the generated authentication result to the authentication server (440). Additionally, in step 409, the authentication server (440) can store the received authentication result. This is explained with reference to FIG. 7.
[0146] In step 701, the issuing agency (430) and the device (420) can each generate a third server random and a third device random, and the issuing agency (430) can receive the third device random from the device (420) (step 702).
[0147] Subsequently, at step 703, the issuing authority (430) can generate a third session key using a secondary device master key, a third device random, and a third server random, and at step 704, the issuing authority (430) can generate a third server password code using the third session key, the third device random, and the third server random, and transmit the generated third server password code together with the third server random to the device (420).
[0148] Subsequently, in step 705, the device (420) can generate a third session key using a secondary device master key, a third device random, and a third server random.
[0149] In step 706, the device (420) can verify the third server password code using the third session key.
[0150] In step 707, the device (420) can generate a third device password code using a third session key, a third device random, and a third server random, and transmit the generated third device password code to an issuing authority.
[0151] In step 708, the issuing authority (430) can complete third authentication with the device (420) by verifying the third device password code using the third session key.
[0153] FIG. 8 is a flowchart illustrating another example of a secure communication method in an Internet of Things environment according to one embodiment.
[0154] Referring to FIG. 8, a secure communication method in an Internet of Things environment according to one embodiment may further include a data server (850).
[0155] For example, in step 804, the data server (850) can transmit device information (DI) to the authentication server (840). Here, device information (DI) refers to information about a device to be linked for data exchange.
[0156] Subsequently, in step 805, the authentication server (840) can search for the device based on the received device information and the stored authentication result. Here, since the details described above through FIGS. 2 to 7 can be applied in the same way as the authentication result generated by the issuing authority (830) (step 801), transmitted to the authentication server (840) (step 802), and stored in the authentication server (840) (step 803), a redundant description is omitted.
[0157] According to one embodiment, the authentication server (840) can search for a target device by searching for information regarding the target device linked for data exchange from the previously stored authentication results. In other words, in one embodiment, the authentication results may already be stored in the authentication server (840) before data exchange between the data server (850) and the device (820) takes place. Additionally, the target device is a device linked with the data server (850) for data exchange, and in step 804, the device information received from the data server (850) may be information of the target device.
[0158] Meanwhile, in step 806, the authentication server (840) may provide the retrieved authentication result to the data server (850), and the data server (850) may perform mutual exchange of encrypted data with the retrieved device (820) (step 807). This is explained in detail through FIGS. 9a to 11.
[0159] FIG. 9a is a configuration diagram illustrating an example of the internal configuration of an authentication server according to one embodiment.
[0160] The authentication server (910) may be a server that communicates with a device, an issuing authority, and a data server. For example, the authentication server (910) may be a server that stores various data, including authentication results received from an issuing authority. Alternatively, the authentication server (910) may be a computing device that includes memory and a processor and has its own computational capabilities. For example, the authentication server (910) may perform encryption on data or decryption on encrypted data. Examples of how the authentication server (910) operates are described below.
[0161] Referring to FIG. 9a, the authentication server (910) may include a processor (911), memory (912), and a communication module (913). For convenience of explanation, FIG. 9a only illustrates components related to the present invention. Accordingly, other general-purpose components may be included in the authentication server (910) in addition to the components illustrated in FIG. 9a. Furthermore, it is obvious to those skilled in the art that the processor (911), memory (912), and communication module (913) illustrated in FIG. 9a may be implemented as independent devices.
[0162] The processor (911) can process instructions of a computer program by performing basic arithmetic, logic, and input / output operations. Here, the instructions may be provided from memory (912) or an external device. Additionally, the processor (911) can control the overall operation of other components included in the authentication server (910).
[0163] According to one embodiment, the processor (911) may include a hardware security module (HSM) (not shown). The hardware security module (HSM) is a dedicated hardware device for providing security that generates, stores, and manages cryptographic keys (security keys), generates digital signatures, and performs encryption and decryption operations. In the present disclosure, at least some of the operations described below as being performed by the processor (911) of the authentication server (910) may be performed by the hardware security module (HSM) included in the authentication server (910).
[0164] According to one embodiment, the processor (911) may store the authentication result generated by the issuing authority in memory (912). For example, the processor (911) may interpret a CSV file containing the results regarding mutual authentication between the device and the issuing authority, and store the authentication result contained in the CSV file in memory (912). The processor (911) stores the mutual authentication information of the device(s) in memory (912) in advance before data exchange with the device(s), thereby enabling secure communication with the device(s) immediately without a separate additional authentication process.
[0165] According to another embodiment, the processor (911) can perform third authentication with the device using a second device master key. In other words, at least some of the operations performed by the processor (110) of the issuing authority (100) for third authentication with the device, as described above with reference to FIG. 2, can be performed by the processor (911) of the authentication server (910). Redundant descriptions are omitted.
[0166] Meanwhile, the data server may request the authentication server (910) to encrypt the data and decrypt the encrypted data in order to perform data exchange with the device. Prior to this, the data server may request the authentication server (910) to search for the target device in order to link with the target device to perform data exchange. In response to the request of the data server, the processor (911) of the authentication server (910) may search for the device based on the previously stored authentication results.
[0168] (Data Decryption)
[0169] When a data server receives encrypted data from a device, the authentication server (910) may receive a request from the data server to decrypt the encrypted data. For example, the authentication server (910) may receive the encrypted data and information (DI) about the device from the data server.
[0170] The processor (911) can retrieve information (DI) regarding a device received from a data server from a previously stored authentication result to obtain an authentication result regarding a device. The retrieved authentication result regarding a device may include information regarding the device, information regarding a security chip included in the device, information regarding a server random (e.g., a third server random) and a device random (e.g., a third device random) used in authentication between the issuing authority and the device, and information regarding the number of authentications, as described above.
[0171] The processor (911) can generate a secondary device master key by encrypting information (SI) regarding the security chip (SE) included in the authentication result and secondary device master key information using a secondary issuance key.
[0172] Additionally, the processor (911) can generate a third session key using the generated secondary device master key, the third server random and the third device random included in the authentication result. For example, the processor (911) can generate a third session key by combining the third server random, the third device random and the secondary device master key, and applying a hash function to the combined data.
[0173] Additionally, the processor (911) can perform decryption of the encrypted data using the third session key and generate a command to transmit the decrypted data to the data server.
[0175] (Data encryption)
[0176] When a data server transmits encrypted data to a device, prior to this, an authentication server (910) may receive a request from the data server for encryption of the data. For example, the authentication server (910) may perform encryption on the data to be transmitted in response to receiving a request from the data server for encryption of the data. For example, the authentication server (910) may receive information (DI) regarding the data to be transmitted and the device from the data server.
[0177] The processor (911) can obtain an authentication result regarding a device by searching for information (DI) regarding a device received from a data server in a previously stored authentication result.
[0178] The processor (911) can generate a secondary device master key by encrypting information (SI) regarding the security chip included in the authentication result and secondary device master key information using a secondary issuance key.
[0179] The processor (911) can generate a third session key using the generated secondary device master key, the third server random and the third device random included in the authentication result.
[0180] The processor (911) can perform encryption on the data using a third session key and generate a command to transmit the encrypted data to the data server.
[0181] Meanwhile, since the implementation example of the processor (911) may be the same as the implementation example of the processor (110) of the issuing institution described above with reference to FIG. 2, a detailed description is omitted.
[0182] Various data, such as data required for the operation of the processor (911) and data generated according to the operation of the processor (911), can be stored in the memory (912). Additionally, an operating system (OS) and at least one program (e.g., a program required for the operation of the processor (911)) can be stored in the memory (912).
[0183] For example, the authentication result may be stored in the memory (912). As another example, the encryption key used in the mutual authentication process with the device (e.g., default key, device random, server random, session key, device master key) may be stored in the memory (912).
[0184] Meanwhile, since the implementation example of the memory (912) is the same as the implementation example of the memory (120) described above with reference to FIG. 2, a detailed description is omitted.
[0185] The communication module (913) may provide configuration or functions for communicating with the authentication server (910) and other external devices (e.g., issuing authorities, devices, and data servers) via a network. For example, control signals, commands, data, etc. provided under the control of the processor (911) may be transmitted to external devices via the communication module (913) and the network. For example, the communication module (913) may receive a request from the data server for encryption and decryption of data, or receive information regarding the device, encrypted data, etc. for this purpose. Additionally, the communication module (913) may transmit encrypted data or decrypted data to the data server. Redundant descriptions are omitted.
[0187] FIG. 9b is a configuration diagram illustrating an example of the internal configuration of a data server according to one embodiment.
[0188] The data server (920) may be a server that communicates with a device, an issuing authority, and an authentication server. For example, the data server (920) may be a server that stores various data, including data collected and measured by the device. Alternatively, the data server (920) may be a computing device that includes memory and a processor and has its own computational capabilities. For example, the data server (920) may perform encryption on data or decryption on encrypted data through the authentication server. Examples of how the data server (920) operates are described below.
[0189] Referring to FIG. 9b, the data server (920) may include a processor (921), memory (922), and a communication module (923). For convenience of explanation, FIG. 9b illustrates only the components related to the present invention. Accordingly, other general-purpose components may be included in the data server (920) in addition to the components illustrated in FIG. 9b. Furthermore, it is obvious to those skilled in the art that the processor (921), memory (922), and communication module (923) illustrated in FIG. 9b may be implemented as independent devices.
[0190] The processor (921) can process instructions of a computer program by performing basic arithmetic, logic, and input / output operations. Here, the instructions may be provided from memory (922) or an external device. Additionally, the processor (921) can control the overall operation of other components included in the data server (920).
[0191] According to one embodiment, the processor (921) can perform an exchange of encrypted data with a device retrieved by an authentication server. More specifically, in response to receiving encrypted data from a device, the processor (921) can perform decryption of the encrypted data using an authentication server, and can perform encryption of the data using an authentication server to transmit the encrypted data to the device. This will be described in more detail below.
[0193] (Data Decryption)
[0194] The processor (921) may request the authentication server to decrypt the encrypted data in response to receiving the encrypted data from the device.
[0195] Here, encrypted data refers to data encrypted by the device, meaning data encrypted using a third session key.
[0196] The processor (921) can generate a command to send information (DI) about the encrypted data and the device to the authentication server in order to request the authentication server to decrypt the encrypted data.
[0197] Afterwards, when the processor (921) receives decrypted data from the authentication server, it can store the decrypted data in memory (922).
[0199] (Data encryption)
[0200] The processor (921) may request the authentication server to encrypt the data in order to transmit the encrypted data to the device. The processor (921) may generate a command to transmit information (DI) regarding the data to be encrypted and the device to the authentication server in order to request the authentication server to encrypt the data.
[0201] Afterward, when the processor (921) receives encrypted data from the authentication server, it can generate a command to store the encrypted data in memory (922) or transmit it to a device.
[0202] FIGS. 10 and FIGS. 11 are flowcharts illustrating examples of a data exchange method between an authentication server, a data server, and a device according to one embodiment. More specifically, FIG. 10 is a flowchart illustrating the case where a device (1030) transmits encrypted data, and FIG. 11 is a flowchart illustrating the case where a data server (1020) transmits encrypted data.
[0203] Referring to FIGS. 10 and 11, examples of data exchange methods between an authentication server, a data server, and a device may include a series of operations of an authentication server (1010), a data server (1020), and a device (1030). However, this is not limited thereto, and at least some of the operations of each component described above through FIGS. 1 to 9 may also be applied to the data exchange method of FIGS. 10 and 11. Redundant descriptions will be omitted.
[0204] First, we will explain the case where the device (1030) transmits encrypted data.
[0205] Referring to FIG. 10, in step 1001, the device (1030) can transmit encrypted data and information about the device (DI) to the data server (1020). Here, the device (1030) can perform encryption on the data to be transmitted using a third session key generated during the third authentication process.
[0206] In step 1002, in response to receiving encrypted data from the device (1030), the data server (1020) may transmit the encrypted data and information (DI) about the device to the authentication server (1010). That is, in response to receiving encrypted data from the device (1030), the data server (1020) may perform decryption of the encrypted data through the authentication server (1010).
[0207] In steps 1003 and 1004, the authentication server (1010) can retrieve information (DI) about the device from the authentication result and obtain an authentication result about the device (1030).
[0208] In step 1005, the authentication server (1010) can generate a secondary device master key by encrypting information (SI) regarding the security chip included in the authentication result and secondary device master key information using a secondary issuance key.
[0209] In step 1006, the authentication server (1010) can generate a third session key using a secondary device master key, a third server random and a third device random included in the authentication result.
[0210] In step 1007, the authentication server (1010) can perform decryption of the encrypted data using a third session key, and in step 1008, the authentication server (1010) can transmit the decrypted data to the data server (1020). Afterwards, the data server (1020) can store the decrypted data.
[0212] The following describes a case where the data server (1020) transmits encrypted data.
[0213] Referring to FIG. 11, in order for the data server to request encryption of the data from the authentication server, in step 1101, the data server (1120) can transmit information (DI) about the data and the device to the authentication server (1110).
[0214] In steps 1102 and 1103, the authentication server (1110) can retrieve information (DI) about the device from the authentication result and obtain an authentication result about the device (1130).
[0215] Subsequently, in step 1104, the authentication server (1110) can generate a secondary device master key by encrypting the information (SI) regarding the security chip included in the authentication result and the secondary device master key information using a secondary issuance key.
[0216] In step 1105, the authentication server (1110) can generate a third session key using a secondary device master key, a third server random and a third device random included in the authentication result.
[0217] Subsequently, at step 1106, the authentication server (1110) performs encryption of the data using a third session key, and at step 1107, the authentication server (1110) can transmit the encrypted data to the data server (1120), and at step 1108, the data server (1120) can transmit the encrypted data to the device (1130).
[0218] Subsequently, according to one embodiment, the device (1130) can perform decryption of encrypted data using a third session key generated during the third authentication process, and can store and use the decrypted data.
[0219] Unless explicitly stated or contrary to the order of the steps constituting the method according to the present invention, said steps may be performed in a suitable order. The present invention is not necessarily limited by the order in which said steps are described. The use of all examples or exemplary terms (e.g., etc.) in the present invention is merely for the purpose of describing the present invention in detail, and the scope of the present invention is not limited by said examples or exemplary terms unless limited by the claims. Furthermore, those skilled in the art will understand that various modifications, combinations, and changes may be made according to design conditions and factors within the scope of the claims or equivalents to which they are added.
[0220] Accordingly, the scope of the present invention should not be limited to the embodiments described above, and all scopes equivalent to or equivalently modified from the claims set forth below, as well as the claims set forth below, shall be considered to fall within the scope of the concept of the present invention.
Claims
Claim 1 A secure communication method in an Internet of Things (IoT) environment comprises: a step in which an issuing authority obtains a first issuance key and a second issuance key generated by a user, and receives a default key from a device; a step in which the issuing authority performs first authentication with the device using the default key and issues a first device master key generated using the first issuance key to the device; a step in which the issuing authority performs second authentication with the device using the first device master key and issues a second device master key generated using the second issuance key to the device; a step in which the issuing authority performs third authentication with the device using the second device master key and transmits the authentication result to an authentication server; a step in which the authentication server stores the authentication result and searches for the device based on the stored authentication result; and a step in which a data server performs an exchange of encrypted data with the searched device. The method comprises the step of controlling power consumed based on the operating state of the device, wherein the operating state includes a first state in which the device performs any one of the first authentication, the second authentication, and the third authentication with the issuing authority; a second state in which the device performs the exchange of encrypted data with the data server; a third state in which the device is waiting to receive a signal from any one of the issuing authority, the authentication server, and the data server; and a fourth state in which the power of the device is turned off. Claim 2 In claim 1, the step of issuing the primary device master key to the device comprises: the issuing authority and the device each generating a first server random and a first device random; the issuing authority generating a first session key using the default key, the first device random received from the device, and the first server random; the issuing authority generating a first server encryption code using the first session key, the first device random, and the first server random, and transmitting the first server encryption code and the first server random to the device; the device generating a first session key using the default key, the first device random, and the first server random received from the issuing authority; the device verifying the first server encryption code using the first session key; the device generating a first device encryption code using the first session key, the first device random, and the first server random, and transmitting the first device encryption code to the issuing authority; A method comprising: a step of completing the first authentication with the device by the issuing authority verifying the first device password code using the first session key. Claim 3 In claim 2, the step of issuing the first device master key to the device comprises: a step in which the issuing authority generates the first device master key by encrypting information regarding a security module included in the device and the first device master key information using the first issuing key; a step in which the issuing authority encrypts the first device master key using the first session key and transmits the encrypted first device master key to the device; a step in which the device decrypts the encrypted first device master key using the first session key; and a step in which the device generates a key check value using the decrypted first device master key and verifies the first device master key using the key check value. Claim 4 In claim 1, the step of issuing the secondary device master key to the device comprises: the issuing authority and the device each generating a second server random and a second device random; the issuing authority generating a second session key using the primary device master key, the second device random received from the device, and the second server random; the issuing authority generating a second server encryption code using the second session key, the second device random, and the second server random, and transmitting the second server encryption code and the second server random to the device; the device generating a second session key using the primary device master key, the second device random, and the second server random received from the issuing authority; the device verifying the second server encryption code using the second session key; the device generating a second device encryption code using the second session key, the second device random, and the second server random, and transmitting the second device encryption code to the issuing authority; A method comprising: a step of completing the second authentication with the device by the issuing authority verifying the second device password code using the second session key. Claim 5 In claim 4, the step of issuing the secondary device master key to the device comprises: a step in which the issuing authority generates the secondary device master key by encrypting information regarding a security module included in the device and secondary device master key information using the secondary issuance key; a step in which the issuing authority encrypts the secondary device master key using the second session key and transmits the encrypted secondary device master key to the device; a step in which the device decrypts the secondary device master key using the second session key; and a step in which the device generates a key check value using the decrypted secondary device master key and verifies the secondary device master key using the key check value; a method comprising Claim 6 In claim 1, the step of transmitting the authentication result to the authentication server comprises: the issuing authority and the device each generating a third server random and a third device random; the issuing authority generating a third session key using the secondary device master key, the third device random received from the device, and the third server random; the issuing authority generating a third server encryption code using the third session key, the third device random, and the third server random, and transmitting the third server encryption code to the device; the device generating a third session key using the secondary device master key, the third device random, and the third server random received from the issuing authority; the device verifying the third server encryption code using the third session key; the device generating a third device encryption code using the third session key, the third device random, and the third server random, and transmitting the third device encryption code to the issuing authority; A method comprising: a step of completing the third authentication with the device by the issuing authority verifying the third device password code using the third session key. Claim 7 A method according to claim 1, wherein the authentication result comprises information regarding the device, information regarding a security module included in the device, information regarding a server random and a device random used in authentication between the issuing authority and the device, and information regarding the number of times the authentication is performed. Claim 8 A method according to claim 1, wherein the step of searching for the device comprises searching for information regarding a target device linked for data exchange in the authentication result, and searching for the target device. Claim 9 A method according to claim 1, wherein the step of performing the exchange of the encrypted data comprises: the step of the data server performing decryption of the encrypted data through the authentication server in response to receiving the encrypted data from the device; and the step of the data server receiving the decrypted data from the authentication server and storing it. Claim 10 In claim 9, the step of performing the decryption comprises: a step in which the data server transmits the encrypted data and information regarding the device to the authentication server in response to receiving the encrypted data from the device; a step in which the authentication server searches for information regarding the device in the authentication result and obtains an authentication result regarding the device; a step in which the authentication server generates the second device master key by encrypting information regarding the security module included in the authentication result and the second device master key information using the second issued key; a step in which the authentication server generates a third session key using the second device master key, a third server random and a third device random included in the authentication result; and a step in which the authentication server performs decryption of the encrypted data using the third session key and transmits the decrypted data to the data server. Claim 11 A method according to claim 1, wherein the step of performing the exchange of the encrypted data comprises: the step of the authentication server performing encryption of the data in response to the data server requesting encryption of the data from the authentication server; and the step of the data server receiving the encrypted data from the authentication server and transmitting it to the device. Claim 12 The method according to claim 11, wherein the step of performing the encryption comprises: the step of the authentication server receiving information regarding the data and the device from the data server; the step of the authentication server searching for information regarding the device in the authentication result to obtain an authentication result regarding the device; the step of the authentication server generating the second device master key by encrypting information regarding the security module included in the authentication result and the second device master key information using the second issued key; the step of the authentication server generating a third session key using the second device master key, a third server random and a third device random included in the authentication result; and the step of the authentication server performing encryption on the data using the third session key and transmitting the encrypted data to the data server. Claim 13 delete Claim 14 delete Claim 15 A secure communication system in an Internet of Things (IoT) environment, comprising: a device that acquires measurement data in the IoT environment and controls power consumption based on an operating state; an issuing authority that performs first, second, and third authentications with the device and transmits the authentication results to an authentication server; an authentication server that stores the authentication results and searches for the device based on the stored authentication results; and a data server that performs an exchange of encrypted data with the searched device; wherein the operating state includes a first state in which the device performs one of the first authentication, the second authentication, and the third authentication with the issuing authority; a second state in which the device performs an exchange of encrypted data with the data server; a third state in which the device is waiting to receive a signal from any one of the issuing authority, the authentication server, and the data server; and a fourth state in which the power of the device is turned off.
Citation Information
Patent Citations
Mutual authentication method between mutual authentication devices based on session key and token, mutual authentication devices
KR1020170017455A
Apparatus for issuing cryptographic key of internet of things device using 2-step authentication and method thereof
KR1020200075099A
Method and system for device authentication in the IoT environment
KR102313372B1
Smart metering system with security function
KR102411265B1