Password protection program employing any communication standard
The password protection program enhances factory control system security by dynamically converting setting passwords into communication passwords with additional digits and arguments, and increasing waiting times for incorrect attempts, thus preventing unauthorized access.
Patent Information
- Application Number
- PCT/JP2024/038788
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-02
- Filing Date
- 2024-10-31
- Publication Date
- 2025-05-08
AI Technical Summary
In factories that prohibit outsiders from entering, control devices are vulnerable to password theft due to simple password changes, analysis of file structures, and communication protocol analysis, which can lead to unauthorized access.
A password protection program that uses a control device to monitor or control another device, defining password protection operations based on an arbitrary communication standard. The program converts setting passwords into communication passwords, incorporating additional digits and arguments from a sequence table, and increases waiting time for repeated failed authentication attempts.
The solution significantly enhances password security by dynamically changing passwords with each use, making it difficult to steal the password and structure, even if data is repeatedly output and input. The increased waiting time for incorrect passwords discourages unauthorized access, effectively protecting factory control systems.
Smart Images

Figure JP2024038788_08052025_PF_FP_ABST
Abstract
Description
Password protection program using any communication standard
[0001] The present invention relates to a password protection program that specifies password protection operations for a system that has a control device for controlling a controlled device and a control device that monitors the control device or controls it by writing data or programs, and in which the control device and the control device communicate with each other using any communication standard.
[0002] Traditionally, factories have used control devices to automate production processes and control controlled devices. For example, a programmable logic controller (PLC) that unifies control of distributed control devices, a touch panel (TP) that allows for diverse input and output from users, converters and amplifiers that control servo motors and inverter motors, and a control device that inputs and outputs analog values are combined to automate production processes. Most of the control devices that control the controlled devices are accompanied by control devices and parameter settings that are either independently designed or use personal computers (PCs). These devices are called engineering tools, support tools, console boxes, parameter units, operation boxes, keyers, numeric keypads, etc., and are used to control the control devices and set parameters for the controlled devices via methods such as serial communication and LAN (Local Area Network). Programs in programmable logic controllers (PLCs), screen data in touch panels (TPs), and settings such as speed, time, and tilt in converters, amplifiers, and other control devices are all determined through trial and error, and to prevent this know-how from being copied, many programs, screen data, and settings are made unreadable using passwords or other security measures, and various other security measures are in place. Also, passwords have long been used in systems such as cash cards used with automatic teller machines (ATMs), and in today's world with the spread of the Internet, authentication is also performed using user IDs (identification) and passwords, and these old, simple systems are still in use.
[0003] Among various security processes, for example, Patent Document 1 (Patent Application No. 2019-224393) has been proposed, which aims to provide an information processing device, authentication system, information processing method, and authentication method that can enhance security without compromising user convenience. Also, Patent Document 2 (Patent Application No. 5874796) has been proposed, which aims to maximize the ability of users to access and operate a programmable logic controller (PLC) that is connected to a programming device via a common bus and controls controlled equipment via the programming device's input device and display. Patent Document 3 (Patent Application No. 4238964) has been proposed, which aims to accurately protect only the necessary parts of a user program with security without significantly increasing the number of keys (e.g., passwords), even when the number of user program divisions reaches a huge number, for example, hundreds or thousands. Patent Document 4 (Patent Application No. 6910748) has been proposed, which aims to provide a password authentication system that can maintain a high level of security using passwords with a small number of digits. Furthermore, Patent Document 5 (Patent 3455196) has been devised to address the issue of improving the security of data and programs in a control device that enables large-scale general-purpose networking by performing protocol conversion.
[0004] The idea in Patent Document 1 (Patent Application No. 2019-224393) is an authentication system in which many users have individual user IDs and passwords, and all authentication is permitted on the server side; the question is what and how to disallow it, but it does not make the user terminal unusable. Irreversible hash functions are a widely known technology.
[0005] The idea in Patent Document 2 (Patent 5874796) is to change the user's operation authority level, which is set by the system software, without stopping the operation of the controlled device, but there is almost no need to frequently change the user's operation authority level, and other methods can be used to deal with this.
[0006] In the invention of Patent Document 3 (Patent 4238964), each program is designated as a program block, and a password can be set for the whole, a group, or each block, thereby reducing the number of keys.
[0007] In the invention of Patent Document 4 (Patent 6910748), a logical operation is performed using a user password stored in the user's mind and a unique code secretly stored in a terminal device and set for each Web (World Wide Web) site, outputting a multi-digit operation result, which is then used as an authentication password for authentication processing. Therefore, the user only needs to memorize a password with a small number of digits in their mind, and authentication processing is performed using a complex multi-digit password. Furthermore, a single authentication password is used to output a different authentication password for each Web site. In other words, it cannot be used without a Web environment. Furthermore, security processing for the Web environment itself is required.
[0008] In the invention of Patent Document 5 (Patent 3455196), input operations are accepted only if the password entered from another computer matches, and passwords are structured in a hierarchical structure, allowing operations up to the level of the operator.
[0009] Patent Application No. 2019-224393, Patent No. 5874796, Patent No. 4238964, Patent No. 6910748, Patent No. 3455196
[0010] The problem to be solved is that in factories where outsiders are prohibited from entering, a device that monitors the communication status is installed between a control device for controlling controlled equipment and a connection cable that connects the control device to a control device that monitors the control device or writes data or programs to control the controlled equipment, or between the control device and a wireless device, and an attempt is made to obtain the password that is first sent from the control device.
[0011] Furthermore, the problem to be solved is that the attacker is willing to prepare new control devices and control equipment, and sets new passwords one after another by subtly changing a simple password, and then analyzes the file structure or analyzes the communication protocol using equipment that monitors the communication status in an attempt to obtain the password.
[0012] Furthermore, the problem to be solved is that in factories where outsiders are prohibited from entering, attempts are made to obtain passwords by automatically repeating all possible password combinations using a personal computer or the like.
[0013] The first aspect of the present invention is a password protection program that prescribes password protection operation for a system that has a control device for controlling a controlled device, and a control device that monitors the control device or controls it by writing data or a program, and the control device and the control device communicate with each other using an arbitrary communication standard, wherein, for a set password that is set in the control device to restrict access to the control device, the control device sets a new set password in the control device or requests the control device for the set password that has already been set, and each time the control device performs either of these operations to communicate with the control device, sets an arbitrary first argument, performs a function operation using data corresponding to the first argument from a common sequence table provided in both the control device and the control device and the set password, and creates a communication password that is the result of the function operation and the number of digits of the set password plus the number of digits of the first argument, and performs the communication; When the control device or the control equipment has a function for outputting data whose access is restricted to the control device externally, the password protection program causes the system to execute the following steps: when the control device or the control equipment has a function for outputting data whose access is restricted by the set password, an arbitrary second argument is set, and each time the set password is newly set and outputted externally, or each time the set password is changed and outputted externally, the program performs the function processing using the set password and data corresponding to the second argument in the sequence table used in creating the communication password or a new sequence table, and replaces the result of the function processing used in creating the communication password or the result of the new function processing with an output password having the number of digits of the set password plus the number of digits of the second argument, and outputs the output password externally; and decomposes the communication password communicated to the control device or the output password that has been input into the argument used in creating the communication password or the result of the function processing, and performs function processing in the reverse direction to that used when creating the communication password or the result of the function processing using the data corresponding to the argument obtained by decomposing the data in the sequence table and the result of the function processing, thereby extracting the set password.
[0014] The second aspect of the present invention is a password protection program according to the first aspect of the present invention, which further causes the system to execute the following: when the control device is restricted by a set password set in the control device to restrict access to the control device and the control device authenticates the set password, if the set password does not match, a waiting time is passed before re-entry is possible, and if the set password again does not match, a waiting time is extended further than the previous waiting time.
[0015] A third aspect of the present invention is a password protection program according to the second aspect of the present invention, which further causes the system to execute the following: when the control device is restricted by a set password that is set in the control device to restrict access to the control device and the control device authenticates the set password, if the set password does not match, the control device communicates to the control device the next waiting time or the number of times that it does not match, and if the set password matches, the control device communicates to the control device that the next waiting time or the number of times that it does not match has been reset to its initial value.
[0016] A fourth aspect of the present invention is a password protection program according to the third aspect of the present invention, which further causes the system to execute the following: if the control device is restricted by the set password and the waiting time or number of mismatches is not an initial value, the control device communicates to the control device the waiting time or number of mismatches in the first communication to the control device.
[0017] The fifth aspect of the present invention is a password protection program that specifies password protection operations for a system that has a control device for controlling a controlled device and a control device that monitors the control device or controls it by writing data or programs to it, and that communicates with the control device using an arbitrary communication standard, and that further causes the system to execute the following: when a set password is set in the control device to restrict access to the control device, the control device is restricted by the set password, and the control device authenticates the set password, if the set password does not match, a waiting time has elapsed before the password can be re-entered, and if the set password still does not match, a waiting time is extended beyond the previous waiting time.
[0018] A sixth aspect of the present invention is a password protection program according to the fifth aspect of the present invention, which further causes the system to execute the following: when the control device is restricted by a set password that is set in the control device to restrict access to the control device and the control device authenticates the set password, if the set password does not match, the control device communicates to the control device the next waiting time or the number of times that it does not match, and if the set password matches, the control device communicates to the control device that the next waiting time or the number of times that it does not match has been reset to its initial value.
[0019] The seventh aspect of the present invention is a password protection program according to the sixth aspect of the present invention, which further causes the system to execute the following: if the control device is restricted by the set password and the waiting time or number of mismatches is not an initial value, the control device communicates to the control device the waiting time or number of mismatches in the first communication to the control device.
[0020] The effect of the present invention is that by installing a device for monitoring the communication status between the connection cable connecting the control device and the control device or the radio, a simple password is subtly changed, and even if the same password is set repeatedly, the entire password changes significantly. Also, even if the same simple password is set alternately and repeatedly, it is difficult to create the same password, although it depends on the size of the sequence table, so that the password and structure cannot be easily stolen.
[0021] Furthermore, if the set password is simply replaced without using arguments using a table or sequence table that is common to the control device and the control equipment, the password and structure can be easily stolen by repeating the same simple password alternately, with little variation, so adding arguments makes it impossible to steal the password and structure.
[0022] Furthermore, by using the function for outputting data from the control device that is restricted by a set password and storing or duplicating the data via an external storage medium, a simple password can be subtly changed or the same password can be set alternately and repeatedly, and output and input can be repeated. Even if the data is analyzed using a bitmap or the like, the entire password will change significantly. Also, even if the same simple password is output alternately and repeatedly, it is difficult to obtain the same password, although this depends on the size of the sequence table, so the password and structure cannot be stolen.
[0023] Furthermore, since this invention is also made public, even if it is understood that a password is formed using a structure that utilizes key arguments extracted by random number calculations or a random number table, a sequence table, and reversible function processing, a user of this invention can arbitrarily create a sequence table and select any function processing, and it is also arbitrary how to combine the key arguments extracted by random number calculations or a random number table with the created value, so even when using this invention, the function of confidentiality can be fully achieved.
[0024] Furthermore, this invention can be used simply by generating arguments using random number operations or a random number table, incorporating a sequence table, and performing reversible function processing. Therefore, if it is incorporated into a conventional password program during communication and output, it is possible to improve the confidentiality function without making any major changes and without degrading the functionality, configuration, or features of the conventional password program.
[0025] Furthermore, if the password does not match, the waiting time until it can be entered increases one after another. Therefore, automatically repeating all possible password combinations takes an enormous amount of time, making it difficult to obtain the password. Naturally, since the passwords are tried sequentially, there is a probability of a match, but depending on the number of digits, it is not easy to obtain the password after just a few hundred tries. Furthermore, even in factories where outsiders are prohibited from entering, sacrificing actual production is not an option, and simply increasing the waiting time exponentially is sufficient. Since control devices are not used by an unspecified number of people like automated teller machines (ATMs), this function, while simple, is very important. However, simply making the user wait makes it difficult to distinguish between a malfunction and a previous password mismatch. Therefore, it is preferable to display the waiting time and the remaining waiting time to inform the user that the previous password did not match. Furthermore, by displaying the information, it is possible to roughly estimate how many times the password has failed to match.
[0026] Furthermore, if the password does not match, the waiting time until entry can be made increases, so resetting or turning off the power and trying again can be done to reduce the increased waiting time and number of times, or to make them the same as last time.The waiting time and number of times are stored, and these waiting times and numbers are shared by the control device and the control equipment through communication, so that even if resetting or turning off the power and trying again is done, the structure that causes the waiting time to increase continues, so the password and structure cannot be easily stolen.
[0027]
[0023] FIG. 1 is a diagram illustrating the relationship between a cable or wireless device communicating using a given communication standard, a control device controlling a controlled device, and a control device monitoring the control device or writing and controlling data or programs in a device and equipment according to an embodiment of the present invention. FIG. 2 is a flowchart illustrating password authentication, including communication between a control device for controlling a controlled device and a control device controlling the control device according to an embodiment of the present invention. FIG. 3 is a flowchart illustrating output from a control device controlling a control device according to an embodiment of the present invention when a password is set. FIG. 4 is a flowchart illustrating input from a control device controlling a control device according to an embodiment of the present invention when a password is set. FIG. 5 is a flowchart illustrating password conversion for communication or output performed between a control device for controlling a controlled device and a control device controlling the control device according to an embodiment of the present invention. FIG. 6 is a flowchart illustrating password conversion for setting performed between a control device for controlling a controlled device and a control device controlling the control device according to an embodiment of the present invention.
[0028] The following describes an embodiment of the present invention with reference to the accompanying drawings. Figure 1 shows a diagram of the relationship between a cable or wireless device communicating using a given communication standard, a control device controlling a controlled device, and a control device monitoring the control device or writing and controlling data or programs. A "user" (1) uses a "control device" (2) that controls a "controller" (4) connected via a "communication cable or wireless device" (3) to monitor the "controller" (4) that controls the controlled device, set parameters, write programs, output set data to a "storage medium" (5), input data from the "storage medium" (5), and even test run the active control device. The "controller" (2) that controls the control device performs all processing, including password processing, using a "conventional control device program" (8). The "controller" (4) that controls the controlled device also performs all processing, including password processing, using a "conventional control device program" (B). Furthermore, the "communication cable or wireless device" (3) is implemented in various standards, such as a multi-core parallel cable, a LAN (Local Area Network) cable, or a USB (Universal Serial Bus) cable. In conventional password processing, the "communication passwords" (J and K), the output password for "output data with output password" (G), and the output password for "read data with output password" (H) are all set passwords, so the "communication / output password conversion program" (6), the "setting password conversion program" (7 and 9), and the "communication password conversion program" (A) are unnecessary. Programs are added solely for converting setting passwords to communication / output passwords or converting communication / output passwords to setting passwords. The "communication / output password conversion program" (6) and the "communication password conversion program" (A) are the same program, and similarly, the "setting password conversion program" (7) and the "setting password conversion program" (9) are the same program.The "communication / output password conversion program" and "communication password conversion program" of 6 and A convert a set password into a communication password or an output password under the instructions of the "conventional control device program" of 8 or the "conventional control device program" of B when sending the set password to the "control device" of 4, when sending it to the "control device" of 2, or when outputting it to the "storage medium" of 5. Similarly, the "set password conversion program" of 7 and 9 converts a received communication password or an input output password into a set password under the instructions of the "conventional control device program" of 8 or the "conventional control device program" of B. To convert the "setting password" of N or K into the "communication / output password" of U or the "communication password" of s, an arbitrary "argument" of P or m is used, and the "extracted value" of R or p specified by the argument from the "sequence table" of Q or n and the "setting password" of N or k are used to "functionize" S or q, and the "functionized value" of T or r is combined with an arbitrary "argument" of P or d to form the "communication / output password" of U or the "communication password" of s. Furthermore, to convert V's "communication / output password" or c's "communication password" into b's or j's "setting password," the communication / output password is decomposed into W's or d's "arguments" and X's or e's "function values." Using the W's or d's "arguments," Z's or g's "extracted values" specified as random numbers from Y's or f's "sequence table," and X's or e's "function values," a's or h's "function values" are "functionized" to produce b's or j's "setting password." When creating U's "communication / output password" or s's "communication password," P's or m's "arguments" are generated by calculating random numbers and matching them to Q's, Y's, f's, or m's "sequence table." However, if a random number function is unavailable, a random number table may be used. A simple sequence is also acceptable. While output is handled by 2's "control device," it may also be handled by 4's "control device."Using the above method, the setting password, communication password, and output password are all different. The communication password or output password changes each time the setting password is set and communication is performed, or if the control device is already restricted by the setting password, each time the control device requests the setting password and communication is performed, each time the control device first connects, each time a new setting password is set and output, or each time a changed setting password is output. Furthermore, even if the password is a single character, all characters change, creating confusion for those attempting to search through communication or output data. Adding version information to the above communication / output passwords also makes it possible to support control devices that operate for decades. Furthermore, passwords can be further strengthened by intentionally changing the number sequence, function, or combination method. Note that the functions used in the "communication / output password conversion program" (6 and A) and the "setting password conversion program" (7 and 9) must have a reversible relationship. In other words, if the function used in the "communication / output password conversion program" is additive, the function used in the "setting password conversion program" is subtractive. Furthermore, if a password is used to prevent tampering or if the program on the control device side needs to be simplified, the communication password itself can be used as the password within the control device, but this would result in an extremely weak password.Incidentally, simplifying the program on the control device side is not possible because it would deviate from the purpose of this invention.
[0029] 2 is a flowchart of password authentication, including communication between a control device that controls a controlled device and a control device that controls the control device, according to one embodiment. Reference numeral 20 denotes a control device that controls the control device, and 21 denotes a control device that controls the controlled device. Since the "control device" 20 and the "control device" 21 mostly communicate for processes other than password authentication, the flowchart shows password authentication from "Start password authentication" 22 to "End password authentication" 2B. First, the "control device" 21 performs "communication password conversion" 23, and transmits either the waiting time or the number of mismatches, the version of the sequence table, and the communication password to the "control device" 20. A "version check" 24 is selected based on the version of the sequence table that was transmitted. If the selection result is "match," the process proceeds to "convert set password" at 26. If the selection result is "mismatch," the latest version of the sequence table and the latest data of the sequence table are transmitted to the "control device" at 21, and the process proceeds to selecting "receive version" at 25. The "receive version" at 25 is selected to notify that the latest version of the sequence table and the latest data of the sequence table have been transmitted. If the selection result is "no," the process proceeds to selecting "status of waiting time or number of mismatches" at 2D. If the selection result is "yes," the process proceeds to "convert communication password" at 23 because of repeated merging. If "receive version" at 25 is selected and the selection result becomes "no," the process proceeds to selecting "status of waiting time or number of mismatches" at 2D. If the selection result is "initial value," the control device proceeds to "end password authentication" at 2E, and ends password authentication. If the selection result is "not the initial value," the process moves to "Convert communication password" at 23 in order to rejoin, and repeats the process. On the control device side, "Version check" at 24 is selected, and if the selection result is "Match," "Convert set password" at 26 is performed, and "Waiting time or number of mismatches status" at 27 is selected. If the selection result is "not the initial value," the process moves to "Consume time equivalent to waiting time or number of mismatches" at 28, and if the selection result is "initial value," the process moves to "Enter password" at 29 in order to rejoin.When the "Wait time or number of mismatches" state of 25 is selected and the selection result is "initial value," the process proceeds to "Enter password" of 29 in order to merge. When the "Wait time or number of mismatches" state of 27 is selected and the selection result is "Not initial value," the process proceeds to "Consume time equivalent to the wait time or number of mismatches" of 28, the process proceeds to "Enter password" of 29, and the process proceeds to "Authenticate with set password" of 2A. If the selection result is "Match," the process proceeds to "Initialize wait time or number of mismatches" of 2C, and if the selection result is "Mismatch," the process proceeds to "Increase wait time or number of mismatches" of 2B. When the "Authenticate with set password" of 2A is selected and the selection result is "Mismatch," the process proceeds to communication processing in which either the wait time or the number of mismatches is transmitted to the "Control device" of 21 in order to merge. When "Authenticate with set password" 2A is selected and the selection result is "Match," "Initialize waiting time or number of mismatches" 2C is performed, and either the waiting time or the number of mismatches is sent to the "control device" 21, and the control device side proceeds to "End password authentication" 2E, and ends password authentication.
[0030] Further explanation will be provided based on the above flowchart. This communication process increases the waiting time until the next password entry if the password does not match. Even if someone who does not know the password randomly attempts authentication, increasing the logarithmic time will encourage them to give up on the authentication attempt. Furthermore, by checking the version of the sequence table, the sequence table can be intentionally updated, further improving confidentiality. Details of each symbol are provided below. The "control device" 20 controls the control device and sets parameters. Given that the control device is the primary device, this is not necessarily required and therefore plays a secondary role. The "control device" 21 is controlled by the control device. The "communication password conversion" 23 is a process for converting the set password into a communication password, and is described in detail in Figure 5. The "version check" selection 24 determines whether the sequence table matches. The "receive version" selection 25 determines whether the sequence table is rewritten and resent upon reception. "Convert set password" 26 is a process for converting a communication password to a set password, and is described in detail in FIG. 6. The selection of "Wait time or number of mismatches status" 27 determines whether or not to "Consume time for wait time or number of mismatches" 28. "Consume time for wait time or number of mismatches" 28 actually consumes wait time. "Password input" 29 causes the set password to be input. The selection of "Authenticate with set password" 2A is the final choice of whether to end this set password authentication or repeat it. "Add wait time or number of mismatches" 2B adds time as a penalty for a mismatch. "Initialize wait time or number of mismatches" 2C initializes the time as a penalty for a match. The selection of "Wait time or number of mismatches status" 2D determines whether to "End password authentication" 2E or repeat it.
[0031] FIG. 3 is a flowchart of output when a password is added by a control device controlling a control device according to an embodiment of the present invention. 30 is the control device controlling the control device. Since the "control device" 30 is performing processes other than outputting data with an output password, the flowchart covers output of data with an output password from "Start Output with Output Password" 31 to "End Output with Output Password" 35. Once started, "Output Password Conversion" 32 is performed, followed by "Execute Output" 33, which ends the process. This output process simply converts the set password to an output password and outputs the output password and all data. Details of each symbol are provided below. "Output Password Conversion" 32 is the process of converting the set password to an output password, and is described in detail in FIG. 5. "Execute Output" 33 is the process of outputting all data. While this process is performed on the control device side, it may also be performed on the control device side via communication. Alternatively, the entire process may be performed on the control device side.
[0032] 4 is a flowchart of input when a password is assigned to a control device that controls a control device according to an embodiment of the present invention. First, "Execute Read" 42 is performed, then "Configured Password Conversion" 43 is performed, and "Wait Time or Number of Mismatches Status" 44 is selected. If the selection result is "Not Initial Value," the process proceeds to "Consume Time Equal to the Number of Mismatches" 45. If the selection result is "Initial Value," the process proceeds to "Enter Password" 46 to merge, and "Enter Password" 46 is performed. If "Wait Time or Number of Mismatches Status" 44 is selected and the selection result is "Not Initial Value," the process proceeds to "Consume Time Equal to the Number of Mismatches" 45, then "Enter Password" 46, and then "Authenticate with Configured Password" 47 is selected. If the selection result is "match," the process proceeds to "initialize wait time or number of mismatches" in 4B, and if the selection result is "mismatch," the process proceeds to "increment wait time or number of mismatches" in 48. If "authenticate with set password" in 47 is selected and the selection result is "mismatch," the process proceeds to "increment wait time or number of mismatches" in 48, and then selects "forced termination" in 49. If the selection result is "yes," the process proceeds to "discard read data" in 4A, and if the selection result is "no," the process proceeds to "select wait time or number of mismatches status" in 44 in order to merge. If "forced termination" in 49 is selected and the selection result is "yes," the process proceeds to "discard read data" in 4A, and then proceeds to "initialize wait time or number of mismatches" in 4B in order to merge. Select "Authenticate with set password" in 47, and if the selection result is "Match," perform "Initialize waiting time or number of mismatches" in 4B, proceed to "End reading with output password" in 4C, and end reading with output password.
[0033] Further explanation will be provided based on the above flowchart. The process associated with reading this data involves increasing the waiting time before the next input if the password does not match. Even if someone who does not know the password randomly attempts authentication, increasing the time logarithmically encourages them to give up on the authentication attempt. Furthermore, if the read is canceled, the read data is discarded. Details of each symbol are provided below. The "control device" 40 controls the control device and sets parameters. Given that the control device is the primary device, this is not necessarily required, and therefore plays a secondary role. The "input execution" 42 inputs all data. The "set password conversion" 43 is a process for converting the communication password to the set password, and details are provided in Figure 6. The "waiting time or number of mismatches" selection 44 determines whether or not to "consume time equivalent to the waiting time or number of mismatches" 26. The "consume time equivalent to the waiting time or number of mismatches" 45 actually consumes waiting time. "Password input" 46 prompts the user to input the set password. "Authentication with set password" 47 is the final choice of whether to end or repeat the input with the output password. "Add waiting time or number of mismatches" 48 adds time as a penalty for mismatch. "Forced termination" 49 is the choice of whether to end or continue the input with the output password without input. "Discard input data" 4A discards the input data because it is forced to terminate in order to perform "Authentication with set password" 47. "Initialize waiting time or number of mismatches" 4B initializes the time as a penalty for a match. Note that this process is performed on the control device side, but it may also be performed on the control device side via communication. Alternatively, the entire process may be performed on the control device side.
[0034] FIG. 5 is a flowchart illustrating a password conversion process for communication or output performed between a control device for controlling a controlled device and a control device that controls the control device according to an embodiment. This conversion process consists of four steps, which are performed sequentially. However, the security of the process and the password itself is significantly affected by the password specifications. Therefore, we will first explain the basic password specifications. A password has 10 possible combinations for single-digit numbers and 100 possible combinations for double-digit numbers, with the security increasing with the number of digits. Furthermore, including alphabets, hiragana, katakana, and kanji characters, uppercase and lowercase letters, and half-width and full-width characters further enhances security, but requires an input device other than a numeric keypad and increases complexity. Among control devices that control general control devices, those without programmable control often only use four-digit numbers. Those with programmable control, such as the Q Series programmable logic controller (PLC) manufactured by Mitsubishi Electric Corporation, use a minimum of six digits and a maximum of 32 digits, with half-width alphanumeric characters. For the purposes of this example, the password specification is a five-digit string of half-width alphanumeric characters, including symbols (from 20(H) "blank" to 7E(H) "tilde (~)" in the ASCII (American Standard Code for Information Interchange) table). Simply put, there are 735091890625 possible combinations. The number sequence table is assumed to have 1,000 entries. Furthermore, the function processing replaces each digit with an ASCII (American Standard Code for Information Interchange) number, and adds or subtracts each digit (addition for communication or output password conversion, subtraction for setting password conversion). The combination of the argument and the function result, in that order, becomes the communication or output password. Note that the password does not have to be processed using ASCII (American Standard Code for Information Interchange). Furthermore, any reversible function is acceptable. Although this would limit global applicability, ASCII (American Standard Code for Information Interchange) could also be expanded to include katakana. For example, if the password is "Y5f7$", then in "Generate a random number" in 51, since the sequence table contains 1,000 meaningless five-digit numbers, a random number between 0 and 999 is generated. For example, the argument is "85".In "52, extract a value from a sequence table using a generated random number as an argument," the sequence table contains 1,000 meaningless five-digit numbers. For example, if the 84th number is "15724(H)," the 85th number is "E38A0(H)," and the 86th number is "41227(H)," the argument is "85," so "E38A0(H)" is extracted. Since there are five digits, the sequence table is 32 bits. In "53, perform a function process using the set password and the extracted sequence value," addition is performed digit by digit. Therefore, the first digit of the set password is "$," which is "24(H)" in ASCII (American Standard Code for Information Interchange). Adding "0" to the password does not change it to "24(H)," or "$." The second digit of the password is "7," which is "37(H)" in ASCII (American Standard Code for Information Interchange) numbers, and when an "A" is added, it becomes "41(H)" and "A." The third digit of the password is "f," which is "66(H)" in ASCII (American Standard Code for Information Interchange) numbers, and when an "4" is added, it becomes "6A(H)" and "j." The fourth digit of the password is "5," which is "35(H)" in ASCII (American Standard Code for Information Interchange) numbers, and when an "8" is added, it becomes "3D(H)" and "=". The fifth digit of the password is "Y," which is "46(H)" in ASCII (American Standard Code for Information Interchange) numbers, and when an "E" is added, it becomes "67(H)" and "g." In other words, "Y5f7$" becomes "g=nA$." "Concatenate function result and argument" in 54 means that if the sequence table is shared, the combination is performed to identify the set password. Here, the argument is combined first, followed by the function result. Therefore, the password for communication or output is "85g = nA$." Note that the numbers in the sequence table are in hexadecimal because they vary within a range of 16, but this is meaningless and decimal numbers are also acceptable, although the range of variation is smaller. Conversely, if we expand on this, if we consider the ASCII (American Standard Code for Information Interchange) table's values from 20(H) "blank" to 7E(H) "tilde (~)" as numbers, we get a 95-base number system, which can cover the entire ASCII (American Standard Code for Information Interchange) table.In other words, if you consider 20(H) "blank" to be 0 and 7E(H) "tilde (~)" to be 94, then the data can be any five ASCII (American Standard Code for Information Interchange) characters.
[0035] Also, because the set password is calculated digit by digit, the sequence table lists 32-bit numbers corresponding to the set password, but this is only one way of doing it. Another way is to think of the sequence table as a container for arranging digits, and one piece of data can be used to arrange four hexadecimal digits, or 25 pieces of data for 100 digits. Each piece of data can be any numeric value, and the first digit can be selected using an argument, and the remaining digits can be determined based on that digit. In this case, not much memory is required. Furthermore, if a digit is spilled, it can simply be returned to the beginning. For example, if the E after ...ED387EA09... is the 85th digit, and the remaining digits are the values obtained by adding a prime number digit (2, 3, 5, 7) from that digit, then if the argument is 85, the result will be E38E0(H).
[0036] FIG. 6 is a flowchart of the set password conversion performed by a control device for controlling a controlled device and a control device that controls the control device according to one embodiment. This conversion process consists of three steps, which are performed in order. Here, the password specifications shown in FIG. 5 are used. Specifically, the password specifications are five alphanumeric characters, including half-width symbols (from "space" at 20(H) to "tilde (~)" at 7E(H) in the ASCII (American Standard Code for Information Interchange) table). The last column of the sequence table is set to 1000. Furthermore, the function processing replaces each digit with an ASCII (American Standard Code for Information Interchange) number, and adds or subtracts each digit (addition for communication or output password conversion, subtraction for setting password conversion). The combination of the argument and the function result, in that order, forms the communication or output password. Let's assume the communication or output password is "85g = nA$." This is the password created in FIG. 5. "Decomposing the password for communication / output" 61 involves decomposing it into an argument and a function result. Since the argument and function result are combined in that order, the number of digits in the password is taken into consideration. In this example, "85g = nA$" is the password for communication or output, so "85" is the argument and "g = nA$" is the function result. In "Extracting a value from a sequence table using the decomposed value as an argument" 62, the sequence table contains a string of 1,000 meaningless five-digit numbers. If the 84th number is "15724(H)," the 85th number is "E34A0(H)," and the 86th number is "41227(H)," the random number is "85," so "E38A0(H)" is extracted. "Performing inverse function processing on the decomposed function result and the extracted sequence value" in 63 means performing subtraction, the inverse of addition, for each digit. Therefore, the first digit of the function result is "$," which is "24(H)" in ASCII (American Standard Code for Information Interchange) numbers, and even if "0" is subtracted, it remains "24(H)" and "$." The second digit of the function result is "A," which is "41(H)" in ASCII (American Standard Code for Information Interchange) numbers, and subtracting "A" results in "37(H)" and "7." The third digit of the function result is "j," which is "6A(H)" in ASCII (American Standard Code for Information Interchange) numbers, and subtracting "4" results in "6A(H)" and "f."The fourth digit of the function result is "=", which is "3D(H)" in ASCII (American Standard Code for Information Interchange) numbering, and when "8" is subtracted, it becomes "35(H)" and "5". The fifth digit of the function result is "g", which is "67(H)" in ASCII (American Standard Code for Information Interchange) numbering, and when "E" is subtracted, it becomes "37(H)" and "Y". In other words, the function result "g = nA$" becomes the set password "Y5f7$".
[0037] As mentioned in the explanation of Figure 5, other methods are also possible. Think of the sequence table as a container for arranging digits. One piece of data can hold four hexadecimal digits, and for 100 digits, it becomes 24 pieces of data. Each piece of data can be any numeric value, and the first digit can be selected using the argument, and the remaining digits can be determined based on that digit. In this case, not much memory is required. Note that if a digit spills over, it can simply be returned to the beginning. For example, if the E after ...E328DEA09... is the 85th digit, and the remaining number is the value obtained by adding a prime number digit (2, 3, 5, 7) from that digit, then if the argument is 85, it will become E38E0(H).
[0038] Incidentally, the numbers commonly used on-site at production plants are either single digits (although in recent years restrictions such as four digits or more have been increasingly imposed) or have the same number of digits. As a reference example, let's assume the same argument "85" and list the results. The left is the setting password, and the right is the communication / output password. "0" (the remaining first four digits are 20(H)) is "85.# (*0)", "1" (the remaining first four digits are 20(H)) is "85.# (*1)", "2" (the remaining first four digits are 20(H)) is "85.# (*2)", "3" (the remaining first four digits are 20(H)) is "85.# (*3)", "4" (the remaining first four digits are 20(H)) is "85.# (*4)", "5" (the remaining first four digits are 20(H)) is "85.# (*5)", "6" (the remaining first four digits are 20(H)) is "85.# (*6)", "7" (the remaining first four digits are 20(H)) is "85.# (*7)", "8" (the remaining first four digits are 20(H)) is "85.# (*8)", "9" (the remaining first four digits are 20(H)) becomes "85.#(*9)", "00000" becomes "85E38A0", "11111" becomes "85F49B1", "22222" becomes "85G5:C2", "33333" becomes "85H6;D3", "44444" becomes "85I7<E4", "55555" becomes "85J8=F5", "66666" becomes "85K9>G6", "77777" becomes "85L:?H7", "88888" becomes "85M;@I8", "99999" becomes "85N<AJ9". Note that the arguments change each time, so this can become even more complicated.
[0039] In recent years, electrical control is becoming increasingly prevalent in all industries, and in programmable control, the data is particularly important and is generally protected with a password. It can be used not only in manufacturing machinery and plants, but also in cars and home appliances. CAN (Controller Area Network) is often used in cars, and due to its weak security, it can also be used as an anti-theft measure when adding a new device to the network. It can also be used in IoT (Internet of Things), which can sometimes identify users and is used in home appliances.
[0040] 1 User 2 Control device 3 Communication cable or radio 4 Control device 5 Storage medium 6 Communication / output password conversion program 7 Setting password conversion program 8 Conventional control device program 9 Setting password conversion program A Communication password conversion program B Conventional control device program C Other instructions D Input, etc. E Password setting / authentication instruction F Setting password input G Data output with output password H Reading data with output password J Communication password K Communication password L Read / monitor value, etc. M Other instructions / writing N Setting password P Argument Q Sequence table R Extracted value S Function T Function value U Communication / output password V Communication / output password W Argument X Function value Y Sequence table Z Extracted value a Function b Setting password c Communication password d Argument e Function value f Sequence table g Extracted value h Function j Setting password k Setting password m Argument n Sequence table p Extracted value q Function r Function value s Communication password
[0041] 20 Control device 21 Control device 22 Start password authentication 23 Convert communication password 24 Version check 25 Receive version 26 Convert set password 27 Waiting time or number of mismatches status 28 Consume time equivalent to waiting time or number of mismatches 29 Password input 2A Authenticate with set password 2B Add waiting time or number of mismatches 2C Initialize waiting time or number of mismatches 2D Waiting time or number of mismatches status 2E End password authentication
[0042] 30 Control device 31 Start output with output password 32 Convert output password 33 Execute output 34 End output with output password
[0043] 40 Control device 41 Start input with output password 42 Execute input 43 Convert set password 44 Wait time or number of mismatches status 45 Consume time equivalent to wait time or number of mismatches 46 Password input 47 Authenticate with set password 48 Add wait time or number of mismatches 49 Forced termination 4A Discard input data 4B Initialize wait time or number of mismatches 4C End input with output password
[0044] 50 Start conversion of communication / output password 51 Generate a random number 52 Use the generated random number as an argument to extract a value from the sequence table 53 Perform function processing using the set password and the extracted sequence value 54 Combine the function result with the argument 55 Complete conversion of communication / output password
[0045] 60 Start of setting password conversion 61 Decompose communication / output password 62 Extract value from sequence table using decomposed value as argument 63 Perform inverse function processing using decomposed function result and extracted sequence value 64 Setting password conversion complete
Claims
1. A password protection program that prescribes password protection operation for a system having a control device for controlling a controlled device and a control device that monitors the control device or controls it by writing data or a program thereto, wherein the control device and the control device communicate with each other according to an arbitrary communication standard, the password protection program being read by computers of both the control device and the control device to: (A) for a set password that is set in the control device or the control device to restrict access to the control device, each time one of the control device and the control device sets a new set password in the other device or requests the other device for the set password that has already been set, an arbitrary first argument is set, and a reversible function is performed in the forward direction using the numeric value of each digit of the numeric data corresponding to the first argument from a common number sequence table provided in both the control device and the control device, the numeric value of the corresponding digit if the set password is a numeric value, or the numeric value of the character code of the corresponding digit if the set password is a character string; (B) if the set password is a numeric value and a result of performing the function processing in the forward direction includes a carry-over or a carry-down, further performing a spill-over process for the string table, if the set password is a character string and a result of performing the function processing in the forward direction includes a carry-over or a carry-down of the string table, further performing a spill-over process for the string table, if the set password is a character string and a result of performing the function processing in the forward direction includes a carry-over or a carry-down of the string table, if the set password is a character string, arranging all of the results of the function processing for each digit, and if the spill-over process or the carry-over process has been performed, the results after the spill-over process or the carry-over process are performed, and if the set password is a numeric value, the first argument is combined with the result, or if the set password is a character string, the first argument is converted into a character string and combined with the result, as a communication password, and the communication is performed by replacing the communication password with the set password.the control device or the control device has an output function to an external storage medium, and one of the control device and the control device either sets the set password in the other or requests the other for the set password that has already been set, thereby outputting all data including the set password to the external storage medium, and each time all data is saved, an arbitrary second argument is set, and from the common number sequence table provided in both the control device and the control device, a reversible function is processed in a forward direction using the numerical value of each digit of numerical data corresponding to the second argument and having the maximum number of digits for which the set password can be set, and if the set password is a numerical value, the numerical value of the corresponding digit, or if the set password is a character string, the numerical value of the character code of the corresponding digit, and if the set password is a numerical value and a carry or borrow occurs as a result of the forward function processing, a spillover process is further performed, if the set password is a character string and the result of performing the function processing in the forward direction includes a rise or fall of the character string table, further performing out-of-range spill processing of the character string table, arranging all of the results of the function processing for each digit, and if the digit spill processing or the out-of-range spill processing has been performed, the results after the digit spill processing or the out-of-range spill processing are performed, and if the set password is a numeric value, the second argument is combined with the result, or if the set password is a character string, the second argument is converted into a character string and combined with the result, as a storage password, and outputting all data in which the storage password has been replaced with the set password to an external storage medium, and all data is stored; (C) inputting the communication password communicated from the other party or all data from the external storage medium, and decomposing the storage password from all data that has been read out into the argument used in creating the communication password or the result of the function processing, If the set password is a numeric value, the numeric value of each digit of the numeric data corresponding to the argument from the number sequence table, the numeric value having the maximum number of digits that the set password can be set to, and the numeric value of the corresponding digit of the decomposed result of the function processing, ora password protection program that causes computers of both the control device and the control device to execute the following: if the set password is a character string, converting the decomposed argument into a numerical value, and performing a function process of the reversible function in the reverse direction using the numerical value of each digit of numerical data from the sequence table that corresponds to the argument and has the maximum number of digits that the set password can be set to, and the numerical value of the character code of the corresponding digit of the decomposed result of the function process; if the set password is a numerical value and there is a carry over or a borrowing, further performing a spillover process; if the set password is a character string and there is a rise or fall in the character string table, further performing a spillover process outside the range of the character string table; if the set password is a numerical value, arranging the numerical values of all the digits; and if the set password is a character string, arranging all the character strings of the digits, and extracting the set password.
2. A password protection program as described in claim 1, characterized in that when the set password is set and the one or the other is authenticating the set password, if the input password, which is the password input to the one or the other for authentication, does not match the set password set previously or the set password extracted in (C) from the communication password communicated from the one or the other, the program allows the user to re-enter the password after a waiting time, and if there is still a mismatch between the new input password and the set password set previously by the user or the set password extracted from the communication password communicated from the one or the other, the program makes the waiting time longer than the previous waiting time.
3. A password protection program as described in claim 2, characterized in that when the set password is set and the one or the other is authenticating the set password, if an input password, which is a password input to the one or the other for authentication, does not match the set password set previously or the set password extracted in (C) from the communication password communicated from the one or the other, the next waiting time or the number of mismatches is communicated to the one or the other, and if an input password, which is a password input to the one or the other for authentication, matches the set password set previously by the oneself or the set password extracted in (C) from the communication password communicated from the one or the other, the next waiting time or the number of mismatches is set to an initial value and communicated to the one or the other.
4. A password protection program as described in claim 3, characterized in that when the set password is set and the waiting time or number of mismatches is not an initial value, the waiting time or number of mismatches is communicated to the one or the other in the first communication to the one or the other.
Citation Information
Patent Citations
Programmable controller and controlling method therefor
JP2002229608A
Password authentication circuit and method
JP2013142917A
Programmable controller
JP2013171513A
Portable electronic device, program, processing system, terminal and IC card
JP2018101218A
System and Method for Secure Remote Control of a Medical Device
US20210136048A1