Information processing system
The hash chain network with slave and master chips in the information processing system addresses sensor data management challenges by ensuring data integrity and efficiency through layered verification and storage, enabling prompt detection of abnormalities and reducing CPU load.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SEEDS
- Filing Date
- 2025-12-24
- Publication Date
- 2026-07-23
AI Technical Summary
Conventional information processing systems face challenges in managing increasing sensor data loads and ensuring prompt detection and normalization of data abnormalities, such as corruption or loss, while reducing CPU load and maintaining data integrity.
An information processing system that employs a hash chain network with slave and master chips, utilizing wireless communication to transmit and verify data units with added hash values, ensuring data integrity through multiple layers of verification and storage, and using acknowledgment signals for efficient and reliable data transmission.
The system achieves safer and more efficient data transmission by detecting data tampering and unauthorized insertion, ensuring data reliability and reducing CPU load through layered verification and storage mechanisms.
Smart Images

Figure JP2025045408_23072026_PF_FP_ABST
Abstract
Description
Information processing system
[0001] The present invention relates to an information processing system.
[0002] Conventionally, when transmitting and receiving information, it is important to take measures against the risk of data destruction. In this regard, technologies for reducing the data destruction risk during information transmission have been proposed (see, for example, Patent Document 1).
[0003] Japanese Patent Application Laid-Open No. 2017-026755
[0004] Here, when constructing a system for transmitting data from a sensor via a communication line using only the conventional technologies including the above-mentioned Patent Document 1, it was normal for one or a small number of CPUs (Central Processing Units) to centrally manage all the output information from the sensor. However, in recent years, the number and types of sensors have been increasing, and the load on the CPU for managing the output information has been increasing more and more. In contrast, when a situation such as data corruption of transmitted data due to lightning, electrostatic discharge phenomena, electromagnetic wave noise from other electronic devices, or even data loss occurs, if it takes time for the CPU to perform data validity check processing, the CPU side cannot take prompt action. Therefore, in a situation where the importance of being able to immediately detect an abnormality in transmitted data that causes the system to malfunction while reducing the load on the CPU and further being able to instantly normalize the abnormality in transmitted data has been increasing.
[0005] The present invention has been made in view of such a situation, and an object thereof is to realize safer and more efficient information processing in an information processing system that transmits data.
[0006] To achieve the above objective, an information processing system according to one aspect of the present invention includes: a first type electronic device having at least a transmission function for transmitting transmission data in accordance with a predetermined wireless communication method and including a first storage medium for storing the transmission data; and a second type electronic device having at least a reception function for receiving the transmission data in accordance with the predetermined wireless communication method and including a second storage medium for storing the transmission data, wherein the first type electronic device includes: target data acquisition and processing means for acquiring target data to be transmitted, or acquiring the source data of the target data and processing the source data to generate the target data; transmission data generation means for generating the transmission data in predetermined units based on the target data; and transmission data transmission control means for executing control to transmit the transmission data to the second type electronic device in accordance with the predetermined wireless communication method; and the second type electronic device includes: transmission data reception control means for executing control to receive the transmission data in accordance with the predetermined wireless communication method; confirmation means for confirming the received transmission data; and storage control means for executing control to store the confirmed transmission data in the second storage medium; and the transmission data generation means of the first type electronic device is The system further includes: generation means that repeatedly generates data for each predetermined unit based on the target data; first electronic device storage control means that generates the data of the predetermined unit to be processed generated by the generation means as first unit data and records the hash value associated with the transmission data received as a notification from the second electronic device in the first storage medium; first processing means that generates a hash value based on the latest hash value among the hash values recorded in the first storage medium, generates information including the hash value as first association information, and adds the first association information to the first unit data to be processed; and second processing means that generates information including at least the hash value obtained from the first unit data as second association information and adds the second association information to the first unit data to be processed.The p-th transmission data is output as the p-th transmission data, to which the first association information and the second association information have been added to the first unit data generated by the generation means at the p-th time (where p is an integer value of 2 or more). The transmission data transmission control means of the first type electronic device executes control to transmit the p-th transmission data to the second type electronic device. The verification means of the second type electronic device, upon receiving the transmission data from the first type electronic device, confirms that the hash value obtained from the first association information of the received transmission data matches one of the hash values stored in the second storage medium, and recalculates the hash value based on the hash value obtained from the first association information in the transmission data and the first unit data of the transmission data, and confirms that the recalculated hash value matches the hash value obtained from the second association information in the transmission data. The second type electronic device further has a reception notification means that notifies the first type electronic device of the reception when the verification means has confirmed the transmission data. The storage control means of the second type electronic device executes control to store the p-th transmission data, which has been confirmed, in the second storage medium together with the p-th hash value obtained from the second association information of the p-th transmission data and the reception notification.
[0007] According to the present invention, it is possible to achieve safer and more efficient information processing in an information processing system that transmits data.
[0008] This is a schematic diagram showing the overall outline of an information processing system according to one embodiment of the present invention. This is a block diagram showing the functional configuration of the slave chip HCCS and master chip HCCM that constitute the information processing system according to one embodiment of the present invention. This is a schematic diagram showing the structure of the transmitted data and how that data is transmitted and verified in the hash chain network. This is a diagram showing the challenges in conventional hash chain technology. This is a block diagram showing how data is transmitted normally in an information processing system according to one embodiment of the present invention. This is a block diagram showing how the transmission data reception control unit 61 of the master chip HCCM receives the transmitted data and then transmits a reception notification to the slave chip HCCS in an information processing system according to one embodiment of the present invention. This is a block diagram showing how the slave chip HCCS and master chip HCCM send and receive the next data, data X+1, in an information processing system according to one embodiment of the present invention. This is a block diagram showing how the slave chip HCCS and master chip HCCM send and receive the next data, data X+2, in an information processing system according to one embodiment of the present invention. This block diagram shows the processing flow in an information processing system according to one embodiment of the present invention when the slave chip HCCS transmits data X+1, which is the next data, but the master chip HCCM does not receive it. This block diagram shows the processing flow in an information processing system according to one embodiment of the present invention when the slave chip HCCS transmits new data X+1α after the transmission error shown in Figure 10 occurs. This block diagram shows the processing flow in an information processing system according to one embodiment of the present invention when the slave chip HCCS transmits data X+1, which is the next data, and the master chip HCCM receives it, but the reception notification sent from the master chip HCCM is not delivered to the slave chip HCCS. This block diagram shows the processing flow in an information processing system according to one embodiment of the present invention when the slave chip HCCS transmits new data X+1α after the transmission error shown in Figure 12 occurs.This figure shows the process by which a slave chip HCCS and a master chip HCCM set base values corresponding to time information in an information processing system according to one embodiment of the present invention. This is a schematic diagram showing how a smart key and an automobile control unit are controlled in an information processing system according to one embodiment of the present invention. This is a block diagram showing the system configuration in which a smart key and an automobile control unit are controlled in an information processing system according to one embodiment of the present invention.
[0009] Embodiments of the present invention will be described below with reference to the drawings.
[0010] This invention relates to an information processing system. The invention relates to a technology that enables efficient transmission while ensuring data reliability. First, the receiving side transmits an acknowledgment signal, and the transmitting side always refers to the most recent of these acknowledgment signals when transmitting. The receiving side verifies whether the transmission is based on a valid acknowledgment signal and receives only the data that has been verified. Based on this acknowledgment mechanism, the transmitting side acquires the raw data to be transmitted and processes it by adding a base value. This processed data is divided into predetermined units and processed sequentially. In processing each unit of data, the relationship between the currently processed data and the data processed immediately before it is established using a hash value. Furthermore, a hash value of the data being processed itself is also generated and added as association information. This double association makes it possible to detect data tampering and unauthorized insertion. The transmission data generated through these processes is transmitted via wireless communication. On the receiving side, in addition to verifying the validity of the aforementioned acknowledgment signals, the validity of the received data itself is also verified, and only the verified data is stored in the storage medium. Thus, the present invention ensures data reliability in multiple layers and achieves efficient data transmission by combining strict management of reception confirmation signals with multiple safety assurance mechanisms. Figure 1 is a schematic diagram showing the overall outline of an information processing system according to one embodiment of the present invention. This system is, for example, a system located in a factory, and is composed of a slave hash chain chip (hereinafter referred to as "slave chip") and a master hash chain chip (hereinafter referred to as "master chip") that are interconnected via a predetermined wireless communication network (hereinafter referred to as "hash chain network"). Here, wireless communication includes wireless communication using radio waves, voice communication using sound waves, or communication using light, but the present invention is not limited to wireless communication and is also effective for wired communication.
[0011] Hereafter, when it is not necessary to distinguish between slave chips, they will be referred to as "Slave Chip HCCS," and when it is necessary to distinguish between them, they will be described as "Slave Chip HCCS-1," "Slave Chip HCCS-2," and so on.
[0012] The slave chip HCCS, for example, has a sensor and a transmission function that transmits data according to a predetermined wireless communication method. The master chip HCCM, for example, controls an actuator and has a receiving function that receives the transmitted data. Both hash chain chips each include a recording medium for storing the transmitted data.
[0013] Specifically, the slave chip HCCS acquires, for example, a detection signal from a connected sensor as target data to be transmitted. The slave chip HCCS generates block-level transmission data, as described later, from this target data. The generated transmission data is broadcast to the hash chain network.
[0014] Meanwhile, the master chip HCCM receives the transmitted data in block units, which will be described later. The master chip HCCM verifies the validity of the received transmission data and, based on the transmission data, executes control, for example, on an actuator.
[0015] In this system, the slave chip HCCS and the master chip HCCM are connected via a network, enabling safe and efficient transmission of control data, for example, from sensors to actuators.
[0016] The slave chip HCCS, the master chip HCCM, and the control devices described later are information processing devices equipped with a CPU (Central Processing Unit), memory-related units such as ROM (Read Only Memory) and RAM (Random Access Memory), input / output interfaces, and communication units. Through the cooperation of these various hardware components and software, various processes can be executed. As a result, the aforementioned information processing system can be provided.
[0017] Figure 2 is a block diagram showing the functional configuration of a slave chip HCCS and a master chip HCCM that constitute an information processing system according to one embodiment of the present invention. In the CPU of the slave chip HCCS, the target data acquisition and processing unit 51, the transmission data generation unit 52, the generation unit 53, the first processing unit 54, the second processing unit 55, the transmission data transmission control unit 56, and the base value and other information acquisition unit 57 are functional. In the CPU of the master chip HCCM, the transmission data reception control unit 61, the confirmation unit 62, the storage control unit 63, the base value generation unit 64, the time synchronization unit 65, and the information transmission control unit 66 are functional.
[0018] The target data acquisition and processing unit 51 has the function of acquiring the raw data of the target data to be transmitted and generating the target data by processing it at a predetermined timing, for example, by adding a predetermined base value, time information, electronic key, etc., as described later. The transmission data generation unit 52 has the function of generating transmission data for predetermined units based on the target data. The generation unit 53 has the function of repeating the process of generating data for predetermined units based on the target data. The first processing unit 54 has the function of using the data of the predetermined unit to be processed this time, generated by the generation unit as first unit data, and the data of the predetermined unit generated last time as second unit data, generating information that includes at least the hash value obtained from the second unit data as first association information, and adding this information to the first unit data to be processed. The second processing unit 55 has the function of generating information that includes at least the hash value obtained from the first unit data as second association information, and adding this second association information to the first unit data to be processed. The transmission data transmission control unit 56 has the function of executing control to transmit the transmission data to the master chip HCCM according to a predetermined wireless communication method. The base value information acquisition unit 57 has the function of acquiring base values and information such as reception notifications, which will be described later, that are necessary when generating transmission data, and the function of storing the acquired information in the storage medium 18.
[0019] The transmission data reception control unit 61 has the function of executing control to receive transmission data according to a predetermined wireless communication method. The verification unit 62 has the function of verifying the validity of the received transmission data. The storage control unit 63 has the function of executing control to store the verified transmission data in a storage medium. The base value generation unit 64 has the function of generating base values. The time synchronization unit 65 has the function of synchronizing the time with the recording device group. The information transmission control unit 66 has the function of transmitting information such as reception notification and time information based on the synchronized time to the slave chip HCCS.
[0020] Figure 3 is a schematic diagram showing the structure of transmitted data and how that data is transmitted and verified within the hash chain network.
[0021] The transmitted data consists of block X, block X+1, block X+2, and the hash value added to each data block. For example, block X+1 has data X+1, a previous hash value X which includes the hash value of the previous block X, and a current hash value X+1 which includes the hash value based on data X+1.
[0022] The validity of the transmitted data is verified using the following procedure. First, it is checked whether the previous (N-1) hash value obtained from the previous hash value X of block X+1 matches the previous hash value recorded on the storage medium. Next, the current hash value is recalculated based on the previous hash value obtained from the previous hash value X in block X+1 and data X+1, and it is checked whether the recalculated current hash value matches the current hash value obtained from the current hash value X+1 of block X+1.
[0023] These verifications ensure the continuity and legitimacy of the transmitted data, preventing data tampering and unauthorized insertion. The verified transmitted data is recorded on the storage medium along with its hash value.
[0024] The setting of baseline values from the master chip HCCM to the slave chip HCCS is performed at the following timings.
[0025] First, the base value information acquisition unit 57 of the slave chip HCCS requests a base value from the master chip HCCM when the slave chip HCCS is started up. Similarly, the base value request is also performed when the slave chip HCCS is reset or reconfigured.
[0026] Meanwhile, the base value generation unit 64 of the master chip HCCM sends a base value reset request to the slave chip HCCS when it is time for periodic base value updates or when emergency resets are necessary. At these times, the aforementioned base value request and authentication processing flow is executed.
[0027] Figure 4 illustrates the challenges of conventional hash chain technology. In conventional hash chains, if a block of transmitted data is missing, the hash values held by the transmitting slave and receiving master will differ, making it impossible to perform the intended, proper verification. Furthermore, it is based on the assumption of continuous data transmission, and intermittent transmission has not been considered. As shown in Figure 4, if a block is missing, the continuity of the data cannot be determined. This is because the current hash value X and the previous hash value X+1 will not match.
[0028] Therefore, an information processing system that can determine the continuity of data intermittently will be described as an embodiment of the present invention with reference to Figures 5 to 13.
[0029] Figure 5 is a block diagram showing the normal transmission of data. In step S101, the target data acquisition and processing unit 51 of the slave chip HCCS generates transmission data consisting of the previous hash value, data X, and current hash value X, and the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM. In step S102, the transmission data reception control unit 61 of the master chip HCCM receives the transmission data.
[0030] Figure 6 is a block diagram showing how the transmission data reception control unit 61 of the master chip HCCM receives the transmission data and then transmits a reception notification to the slave chip HCCS. In step S201, the transmission data transmission control unit 56 transmits a reception notification X to the slave chip. In step S202, the storage control unit 63 stores the current hash value X and the reception notification X in association in the storage medium 18.
[0031] Figure 7 is a block diagram showing how the slave chip HCCS receives a reception notification sent from the master chip HCCM. In step S301, the transmission data reception control unit 61 receives the reception notification X from the master chip HCCM. In step S302, the base value information acquisition unit 57 of the slave chip HCCS stores the current hash value X and the reception notification X in association in the storage medium 18.
[0032] Figure 8 is a block diagram showing how the slave chip HCCS and the master chip HCCM send and receive data X+1, which is the next data. In step S401, the target data acquisition and processing unit 51 uses a hash value for which a reception notification exists when transmitting data X+1. In this case, the reception notification X is used. In step S402, the target data acquisition and processing unit 51 generates transmission data consisting of the previous hash value X, data X+1, and the current hash value X+1. In step S403, the base value and other information acquisition unit 57 stores the current hash value X+1 in the storage medium 18. In step S404, the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM.
[0033] In step S405, the transmission data reception control unit 61 of the master chip HCCM receives the transmission data. In step S406, the verification unit 62 confirms that the previous hash value X of the received transmission data matches the current hash value X stored in the storage medium 18, and confirms its continuity and legitimacy. In step S407, the storage control unit 63 stores the current hash value X+1 of the data whose legitimacy has been confirmed in the storage medium 18. In step S408, the information transmission control unit 66 of the master chip HCCM transmits a reception notification X+1 corresponding to the data X+1 to the slave chip HCCS. In step S409, the storage control unit 63 stores the reception notification X+1 corresponding to the data X+1 in the storage medium 18, associating it with the current hash value X+1. In step S410, the base value information acquisition unit 57 of the slave chip HCCS receives the reception notification X+1. In step S411, the base value information acquisition unit 57 stores the received notification X+1 in the storage medium 18, associating it with the current hash value X+1.
[0034] Figure 9 is a block diagram showing how the slave chip HCCS and the master chip HCCM send and receive data X+2. In step S501, the target data acquisition and processing unit 51 uses a hash value for which a reception notification exists when transmitting data X+2. In this case, the reception notification X+1 is used. In step S502, the target data acquisition and processing unit 51 generates transmission data consisting of the previous hash value X+1, data X+2, and the current hash value X+2. In step S503, the base value and other information acquisition unit 57 stores the current hash value X+2 in the storage medium 18. In step S504, the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM.
[0035] In step S505, the transmission data reception control unit 61 of the master chip HCCM receives the transmission data. In step S506, the verification unit 62 confirms that the previous hash value X+1 of the received transmission data matches the current hash value X+1 stored in the storage medium 18, and confirms continuity and legitimacy. Here, since the previous hash value X+1 has been sent, the reception notification X corresponding to the current hash value X stored based on the previous previous hash value X will not be referenced thereafter. For this reason, the reception notification X corresponding to this current hash value X may be deleted. In other words, if the current hash value that is the same as the current hash value stored as corresponding to a certain previous hash value is sent from the slave chip HCCS, the current hash value corresponding to the previous hash value received before that current hash value may be deleted. To put it another way, if a current hash value identical to a previous hash value stored as corresponding to a certain previous hash value is sent from the slave chip HCCS, the current hash value corresponding to the previous hash value received before the current hash value may be overwritten with the current hash value stored as corresponding to the previous hash value sent from the slave chip. In step S507, the storage control unit 63 stores the current hash value X+2 of the data whose validity has been confirmed in the storage medium 18. In step S508, the information transmission control unit 66 of the master chip HCCM sends a reception notification X+2 corresponding to the data X+2 to the slave chip HCCS. In step S509, the storage control unit 63 stores the reception notification X+2 corresponding to the data X+2 in the storage medium 18, associating it with the current hash value X+2. In step S510, the base value information acquisition unit 57 of the slave chip HCCS receives the reception notification X+2. In step S511, the base value information acquisition unit 57 stores the received notification X+2 in the storage medium 18, associating it with the current hash value X+2.
[0036] Figure 10 is a block diagram showing the processing flow when the slave chip HCCS sends the next data, data X+1, but the master chip HCCM is unable to receive it.
[0037] In step S601, the target data acquisition and processing unit 51 uses a hash value for which a reception notification exists when transmitting data X+1. In this case, the reception notification X is used. In step S602, the target data acquisition and processing unit 51 creates transmission data consisting of the previous hash value X, data X+1, and the current hash value X+1. In step S603, the base value and other information acquisition unit 57 stores the current hash value X+1 in the storage medium 18. In step S604, the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM.
[0038] In step S605, the transmission data reception control unit 61 of the master chip HCCM should normally receive the transmission data, but the master chip HCCM is unable to receive the transmission data due to a communication failure in the communication line, a reception error in the master chip HCCM, or other reasons. Compared with Figure 8, steps S605 to S611, which correspond to steps S405 to S411 that should be executed by the master chip HCCM in the process shown in Figure 8, are not executed in the process shown in Figure 10. Furthermore, because the reception notification X+1 is not received, the base value information acquisition unit 57 of the slave chip HCCS is unable to execute step S611, which should be executed, namely the step of associating the current hash value X+1 with the reception notification X+1 and storing it in the storage medium 18.
[0039] Figure 11 is a block diagram showing the processing flow when the slave chip HCCS transmits new data X+1α after the transmission error shown in Figure 10 occurs. However, the same applies when retransmitting data X+1.
[0040] In step S701, the target data acquisition and processing unit 51 uses the hash value associated with the corresponding received notification. Ideally, the target data acquisition and processing unit 51 would like to use the current hash value X+1 as the previous hash value, but there is no current hash value X+1 associated with the received notification. Therefore, the target data acquisition and processing unit 51 uses the current hash value X associated with the received notification X.
[0041] In step S702, the target data acquisition and processing unit 51 creates transmission data consisting of the previous hash value X, data X+1α, and the current hash value X+1α. In step S703, the base value and other information acquisition unit 57 stores the current hash value X+1α in the storage medium 18. In step S704, the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM.
[0042] In step S705, the transmission data reception control unit 61 of the master chip HCCM receives the transmission data. In step S706, the verification unit 62 confirms that the previous hash value X of the received transmission data matches the current hash value X stored in the storage medium 18, and verifies its validity. That is, even if one block is missing, the verification of validity can be performed without any problems. In step S707, the storage control unit 63 stores the current hash value X+1α of the data whose validity has been proven in the storage medium 18. In step S708, the information transmission control unit 66 of the master chip HCCM sends a reception notification X+1α corresponding to the data X+1α to the slave chip HCCS. In step S709, the storage control unit 63 stores the reception notification X+1α corresponding to the data X+1α in the storage medium 18, associating it with the current hash value X+1α. In step S710, the base value information acquisition unit 57 of the slave chip HCCS receives the reception notification X+1α. In step S711, the base value information acquisition unit 57 records the received notification X+1α in the storage medium 18, associating it with the current hash value X+1α. Here, the base value information acquisition unit 57 overwrites the current hash value X+1, which does not have a corresponding received notification, with the current hash value X+1α associated with the received notification X+1α.
[0043] Figure 12 is a block diagram showing the processing flow when the slave chip HCCS transmits data X+1, which is the next data, and the master chip HCCM receives it, but the reception notification sent from the master chip HCCM is not delivered to the slave chip HCCS.
[0044] In step S801, when transmitting data X+1, the target data acquisition and processing unit 51 uses the hash value for which a reception notification exists. In this case, reception notification X is used. In step S802, the target data acquisition and processing unit 51 creates transmission data consisting of the previous hash value X, data X+1, and the current hash value X+1. In step S803, the base value and other information acquisition unit 57 stores the current hash value X+1 in the storage medium 18. In step S804, the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM.
[0045] In step S805, the transmission data reception control unit 61 of the master chip HCCM receives the transmission data. In step S806, the confirmation unit 62 confirms that the previous hash value X of the transmitted transmission data matches the current hash value X stored in the storage medium 18, and confirms the continuity and legitimacy. In step S807, the storage control unit 63 stores the current hash value X+1 of the data whose legitimacy has been proven in the storage medium 18. In step S808, the information transmission control unit 66 of the master chip HCCM transmits the reception notification X+1 corresponding to data X+1 to the slave chip HCCS. In step S809, the storage control unit 63 stores the reception notification X+1 corresponding to data X+1 in the storage medium 18 in association with the current hash value X+1.
[0046] However, due to a communication failure or reception error, in step S810, the base value and other information acquisition unit 57 of the slave chip HCCS cannot receive the reception notification X+1. Therefore, the base value and other information acquisition unit 57 cannot execute the original reception notification acquisition step and the step of storing the reception notification in the storage medium 18 in association with the current hash value.
[0047] FIG. 13 is a block diagram showing the processing flow when the slave chip HCCS newly transmits data X+1α after the transmission error shown in FIG. 12. However, the same applies when retransmitting data X+1.
[0048] In step S901, the target data acquisition and processing unit 51 uses the hash value having the corresponding reception notification. Originally, the target data acquisition and processing unit 51 wants to use the current hash value X + 1 as the previous hash value, but there is no current hash value X + 1 having a reception notification. Therefore, the target data acquisition and processing unit 51 uses the current hash value X having the reception notification X.
[0049] In step S902, the target data acquisition and processing unit 51 creates transmission data composed of the previous hash value X, the data X + 1α, and the current hash value X + 1α. In step S903, the base value and other information acquisition unit 57 stores the current hash value X + 1α in the storage medium 18. In step S904, the transmission data transmission control unit 56 transmits the transmission data to the master chip HCCM.
[0050] In step S905, the transmission data reception control unit 61 of the master chip HCCM receives the transmission data. In step S906, the confirmation unit 62 confirms that the previous hash value X of the transmitted transmission data matches the current hash value X stored in the storage medium 18, and confirms the validity. Thereby, even if one block is missing in the transmission data, the verification and confirmation can be performed without problems. In step S907, the storage control unit 63 stores the current hash value X + 1α of the data whose validity has been proven in the storage medium 18. In step S908, the information transmission control unit 66 of the HCCM transmits the reception notification X + 1α corresponding to the data X + 1α to the slave chip HCCS. In step S909, the storage control unit 63 stores the reception notification X + 1α corresponding to the data X + 1α in the storage medium 18 in association with the current hash value X + 1α.
[0051] In step S910, the base value and other information acquisition unit 57 of the slave chip HCCS receives the reception notification X + 1α. In step S911, the base value and other information acquisition unit 57 records the reception notification X + 1α in the storage medium 18 in association with the current hash value X + 1α. Here, the base value and other information acquisition unit 57 overwrites the current hash value X + 1 having no corresponding reception notification with the current hash value X + 1α associated with the reception notification X + 1α.
[0052] Incidentally, the transmission error shown in Figure 12 may occur multiple times in a row. For this reason, the memory control unit 63 of the master chip HCCM needs to store the associated pairs of the current hash value and the received notification as a history in multiple storage media 18.
[0053] Then, in order to verify the legitimacy of the transmission data accompanied by the current hash value backed by the reception notification shown in Figure 13, the verification unit 62 confirms the legitimacy of the received transmission data based on whether one of the current hash values stored in the storage medium 18 as history and paired with the reception notification matches the previous hash value associated with the received transmission data.
[0054] Then, the memory control unit 63 overwrites the previously stored current hash value X+1 and the corresponding received notification X+1 with the confirmed valid current hash value X+1α and the corresponding received notification X+1α.
[0055] Figure 14 shows the process by which the slave chip HCCS and the master chip HCCM set a base value corresponding to the time information. By deriving the current hash value based on the base value corresponding to the time information and the data, the above information processing system becomes an information processing system with improved security.
[0056] In step S1000, at a predetermined timing, the public key of the base value generation unit 64 of the slave chip HCCS is recorded, for example, in the recording device group BNC shown in Figure 1. Then, in step S1001, the information transmission control unit 66 of the master chip HCCM transmits time information to the slave chip HCCS.
[0057] In step S1002, the target data acquisition and processing unit 51 of the slave chip HCCS transmits the unique information of the slave chip HCCS to the master chip HCCM. In step S1003, the base value generation unit 64 of the master chip HCCM obtains the public key of the slave chip HCCS from the blockchain based on the unique information of the slave chip HCCS.
[0058] In step S1004, the base value generation unit 64 of the master chip HCCM encrypts the initial base value with the public key of the slave chip HCCS, and the information transmission control unit 66 transmits the encrypted public key to the slave chip HCCS. In step S1005, the base value information acquisition unit 57 of the slave chip HCCS decrypts the public key encrypted with the secret key and shares the time information with the master chip HCCM. In this case, the base value is accompanied by time information and functions as a one-time base value.
[0059] (Second Embodiment) In the first embodiment described above, an embodiment was described in which data transmission from the slave chip HCCS to the master chip HCCM within the local hash chain network becomes intermittent due to a communication failure or a communication error between the slave chip and the master chip.
[0060] In the second embodiment, an embodiment for securely and reliably transmitting data in one-to-one communication will be described. For example, a control unit of an automobile and a smart key will be used as an example.
[0061] Automotive smart key systems are widely used because they allow for features such as unlocking doors and starting the engine. However, in recent years, vulnerabilities to malicious attack methods such as relay attacks and replay attacks have been pointed out, and damage is particularly frequent in luxury cars.
[0062] Here, a relay attack is an attack method that allows the vehicle to be unlocked illegally even when the smart key is not nearby, by relaying the signals communicated between the vehicle's control unit and the smart key. A replay attack, on the other hand, is an attack method that allows the vehicle to be unlocked illegally by intercepting previously transmitted signals and retransmitting them.
[0063] Therefore, in this embodiment, the above problem is solved by applying the data transmission method using the reception confirmation signal described in the first embodiment to an automotive smart key system. The following will be a detailed explanation with reference to the drawings. The smart key has the functional unit of the slave chip HCCS shown in Figure 2, and the control unit of the automobile has the functional unit of the master chip HCCM shown in Figure 2. In addition, the setting device shown in Figure 5 has the functional unit shown in Figure 2 and appropriately combines the functions of both the slave chip HCCS and the master chip HCCM.
[0064] Referring to Figures 15 and 16, a control method using a hash chain that securely and reliably controls a master chip HCCM, such as one represented by an automobile, and a slave chip HCCS, such as one represented by a smart key, by establishing a one-to-one correspondence. Figure 15 is a schematic diagram showing an information processing system comprising a smart key HCCS-K, an automobile control unit HCCM-C, a setting device 1B, and a memory device group BCN. Figure 16 is a block diagram showing the system configuration in which the smart key and the automobile control unit are controlled. The smart key, which is one of the slave chips HCCS, and the automobile control unit HCCM-C, which is one of the master chips HCCM, are connected by wireless communication and are also connected to the setting device. Furthermore, the setting device is connected to the memory device group BCN.
[0065] In this embodiment, the setting device 1B is used to perform the initial setup between the smart key HCCS-K and the vehicle's control unit HCCM-C.
[0066] First, during the manufacturing stage of the smart key HCCS-K, the target data acquisition and processing unit 51 of the setting device 1B acquires unique information contained within the smart key HCCS-K. This unique information may be a public key for signing or a public key provided by a secure element. The first type unique information recording control unit executes control to register the acquired unique information in an information recording device such as a blockchain.
[0067] Similarly, during the automobile manufacturing process, the target data acquisition and processing unit 51 of the setting device 1B acquires unique information (such as the vehicle ID and the public key for encryption) of the automobile's control unit HCCM-C. The storage control unit 63 of the setting device 1B executes control to record the acquired unique information in the storage device group BCN. The automobile's control unit may also function as the setting device.
[0068] Next, the base value information acquisition unit 57 of the setting device 1B connects to the smart key HCCS-K to acquire unique information (key ID, etc.), and from that unique information, it acquires information registered in the storage device group BCN (signature public key, etc.). In addition, the base value information acquisition unit 57 of the setting device 1B also connects to the vehicle's control unit HCCM-C to acquire time information and unique information (vehicle ID, etc.), and from that unique information, it acquires information registered in the storage device group BCN (encryption public key, etc.).
[0069] The base value generation unit 64 of the setting device 1B generates a base value (Seed) and executes control to record it in the respective storage media 18 of the smart key HCCS-K and the vehicle control unit HCCM-C. The storage control unit 63 of the vehicle control unit HCCM-C records the unique information of the smart key HCCS-K (such as key ID and signature public key) in the storage media 18 of the vehicle control unit HCCM-C. The base value information acquisition unit 57 of the smart key HCCS-K executes control to record time information and unique information (such as encryption public key) in the storage media 18 of the smart key HCCS-K. Instead of recording in the information recording device, the information may be recorded directly in the vehicle control unit. When recording in the vehicle control unit, upon receiving the unique ID from the smart key, it compares it with the information recorded in itself, authenticates that it is a legitimate smart key if there is a match for the unique ID, obtains the public key recorded in association with that unique ID, and encrypts the Seed.
[0070] In the actual authentication process, the target data acquisition and processing unit 51 of the smart key HCCS-K calculates the current hash value from a value calculated based on a base value and time information, the desired operation information (such as unlocking or locking), and the previously transmitted hash value (unique information in the case of the first transmission), triggered by a button press or approach to the vehicle, as shown below in Figure 16. The transmission data generation unit 52 generates transmission data that includes the previously transmitted hash value, the value calculated based on time information, the desired operation information, and the current hash value. The transmission data transmission control unit 56 then executes control to either encrypt the generated transmission data with the vehicle's public key and transmit it, or to add a digital signature with the smart key HCCS-K's private key and transmit it.
[0071] On the vehicle side, the verification unit 62 of the control unit HCCM-C calculates the current hash value using a value calculated based on the previously received hash value and time information, the desired operation information, and the base value it holds, and verifies whether it is equal to the received current hash value. If the verification is successful, the control unit HCCM-C executes control to perform the operation requested by the smart key HCCS-K. If the received data is encrypted, it is decrypted, and if a digital signature is attached, the signature is also verified.
[0072] In this case, if the vehicle's control unit HCCM-C and the smart key HCCS-K are far apart or have obstacles between them, communication failures may occur. For this reason, in the authentication operation described above, it is effective to apply the hash chain technology that utilizes the received notification described in the first embodiment.
[0073] Although one embodiment of the present invention has been described above, the present invention is not limited to the embodiments described above, and any modifications, improvements, etc. that can achieve the objectives of the present invention are considered to be included in the present invention.
[0074] For example, the system configuration shown in Figure 1 and the hardware configuration described above are merely illustrative examples for achieving the objectives of the present invention and are not particularly limited.
[0075] Furthermore, the functional block diagram shown in Figure 2 is merely illustrative and not particularly limiting. In other words, it is sufficient that the information processing system in Figure 1 has the functionality to execute the series of processes described above as a whole, and the functional blocks and databases used to realize this functionality are not particularly limited to the example in Figure 2.
[0076] Furthermore, the location of the functional blocks is not limited to Figure 2, but can be arbitrary. For example, at least a portion of the functional blocks may be provided by another information processing device.
[0077] Furthermore, the series of processes described above can be executed by hardware or by software. Also, a single functional block may consist of hardware alone, software alone, or a combination of both.
[0078] When a series of processes are executed by software, the programs that make up that software are installed on a computer or other device from a network or storage medium. The computer may be a computer built into dedicated hardware. Alternatively, the computer may be a computer capable of performing various functions by installing various programs, such as a server, a general-purpose smartphone, or a personal computer.
[0079] Such recording media containing programs may consist not only of removable media (not shown) distributed separately from the main unit of the device to provide the program to the user, but also of recording media provided to the user in a state where they are pre-installed in the main unit of the device.
[0080] In this specification, the step of describing a program to be recorded on a recording medium includes not only processes that are performed chronologically in that order, but also processes that are not necessarily performed chronologically, but are executed in parallel or individually.
[0081] In summary, the information processing system to which the present invention applies only needs to have the following configuration, and can take various forms.
[0082] The information processing system includes: a first type electronic device (e.g., a "slave chip HCCS" shown in Figure 2) that has at least a transmission function to transmit transmission data according to a predetermined wireless communication method and includes a first storage medium (e.g., a "storage medium 18" shown in Figure 2) for storing the transmission data; and a second type electronic device (e.g., a "master chip HCCM" shown in Figure 2) that has at least a reception function to receive the transmission data according to the predetermined wireless communication method and includes a second storage medium (e.g., a "storage medium 18" shown in Figure 2) for storing the transmission data; and the first type electronic device includes: a target data acquisition and processing means (e.g., a "target data acquisition and processing unit 51" shown in Figure 2) for acquiring target data to be transmitted, or for acquiring the source data of the target data and processing the source data to generate the target data; and a transmission data generation means (e.g., a "transmission data generation unit 52" shown in Figure 2) for generating the transmission data in predetermined units based on the target data. The first electronic device comprises: transmission data transmission control means (for example, "transmission data transmission control unit 56" shown in Figure 2) that executes control to transmit the transmission data to the second electronic device in accordance with the predetermined wireless communication method; the second electronic device comprises: transmission data reception control means (for example, "transmission data reception control unit 61" shown in Figure 2) that executes control to receive the transmission data in accordance with the predetermined wireless communication method; confirmation means (for example, "confirmation unit 62" shown in Figure 2) that confirms the received transmission data; and storage control means (for example, "storage control unit 63" shown in Figure 2) that executes control to store the confirmed transmission data in the second storage medium; the first electronic device comprises: transmission data generation means (for example, "generation unit 53" shown in Figure 2) that repeats the process of generating data for each predetermined unit based on the target data; and generates the data of the predetermined unit that is the target of processing generated by the generation means as first unit data. The system further includes a first type electronic device storage control means (for example, the "base value information acquisition unit 57" in Figure 2) that records the hash value associated with the transmission data received as notification from the second type electronic device onto the first storage medium,The first processing means (for example, the "first processing unit 54" shown in Figure 2) generates a hash value based on the latest hash value among the hash values recorded in the first storage medium, generates information including the hash value as first association information, and adds the first association information to the first unit data to be processed; the second processing means (for example, the "second processing unit 55" shown in Figure 2) generates information including at least the hash value obtained from the first unit data as second association information, and adds the second association information to the first unit data to be processed; the p-th transmission data is output as the p-th transmission data to be processed, and the transmission data transmission control means of the first electronic device executes control to transmit the p-th transmission data to the second electronic device. The verification means of the second type electronic device, upon receiving transmission data from the first type electronic device, confirms that the hash value obtained from the first association information of the received transmission data matches one of the hash values stored in the second storage medium, and recalculates the hash value based on the hash value obtained from the first association information of the transmission data and the first unit data of the transmission data, and confirms that the recalculated hash value matches the hash value obtained from the second association information of the transmission data, thereby confirming the transmission data. The second type electronic device further has a reception notification means that notifies the first type electronic device of the reception once the verification of the transmission data has been performed by the verification means, and the storage control means of the second type electronic device is characterized by executing a control to store the p-th transmission data that has been confirmed in the second storage medium together with the p-th hash value obtained from the second association information of the p-th transmission data and the reception notification.
[0083] This enables reliable detection of data tampering and unauthorized insertion during data transmission from Type 1 electronic equipment to Type 2 electronic equipment through reception notifications and verification using dual hash values. Furthermore, even if data continuity is interrupted due to communication failures, secure and efficient data transmission can be achieved by using reception notifications and hash value history.
[0084] The information processing system disclosed as a second embodiment includes: a first type electronic device (e.g., a "smart key" as described in the second embodiment) having at least a transmission function to transmit transmission data according to a predetermined wireless communication method and including a first storage medium (e.g., a "storage medium 18" as described in Figure 2) for storing the transmission data; a second type electronic device (e.g., a "control unit for an automobile" as described in the second embodiment) having at least a reception function to receive the transmission data according to the predetermined wireless communication method and including a second storage medium (e.g., a "storage medium 18" as described in Figure 2) for storing the transmission data; a group of recording devices (e.g., a "blockchain" as described in the second embodiment) consisting of one or more recording devices; and another information processing device (e.g., a "setting device 1B" as described in the second embodiment) that communicates with the first type electronic device and the second type electronic device, respectively, wherein the first type electronic device includes: a target data acquisition and processing means (e.g., a "target data acquisition and processing unit 51" as described in Figure 2) for acquiring target data to be transmitted, or for acquiring the original data of the target data and processing the original data to generate the target data; The first electronic device comprises: a transmission data generation means (for example, a "transmission data generation unit 52" shown in Figure 2) that generates the transmission data for each predetermined unit based on the target data; a transmission data transmission control means (for example, a "transmission data transmission control unit 56" shown in Figure 2) that executes control to transmit the transmission data to the second electronic device according to the predetermined wireless communication method; and a first unique information recording control means that executes control to record the first unique information, which is unique information associated with the first electronic device, in the group of recording devices. The second electronic device comprises: a transmission data reception control means (for example, a "transmission data reception control unit 61" shown in Figure 2) that executes control to receive the transmission data according to the predetermined wireless communication method; a confirmation means (for example, a "confirmation unit 62" shown in Figure 2) that confirms the received transmission data; and a storage control means (for example, a "storage control unit 63" shown in Figure 2) that executes control to store the confirmed transmission data in the second storage medium.The other information processing device comprises: a Type 2 unique information recording control means that executes control to record Type 2 unique information, which is unique information associated with the Type 2 electronic device, on the recording device; a unique time information acquisition means (for example, the "unique time information acquisition unit" described in the second embodiment) that acquires the Type 1 unique information from the Type 1 electronic device and acquires the Type 2 unique information and time information from the Type 2 electronic device; a base value provision means (for example, the "base value provision unit" described in the second embodiment) that generates a base value and provides it to the Type 1 electronic device and the Type 2 electronic device, respectively; a unique time information provision means that provides the Type 1 unique information acquired from the Type 1 electronic device to the Type 2 electronic device and provides the Type 2 unique information acquired from the Type 2 electronic device and the time information to the Type 1 electronic device; and the transmission data generation means of the Type 1 electronic device comprises a generation means (for example, the "generation unit 53" described in Figure 2) that repeats the process of generating data for each predetermined unit based on the target data. The generation means generates the base value, the time information, the second type unique information, and the data of the predetermined unit of the processing target generated this time as first unit data at a predetermined timing, and further includes a first type electronic device storage control means that records the hash value associated with the transmission data received as a notification from the second type electronic device among the hash values recorded in the first storage medium in the first storage medium, and a first processing means (for example, the "first processing unit 54" shown in Figure 2) that generates a hash value based on the latest hash value among the hash values recorded in the first storage medium, generates information including the hash value as first association information, and adds the first association information to the first unit data of the processing target, and a second processing means (for example, the "second processing unit 55" shown in Figure 2) that generates information including at least the hash value obtained from the first unit data as second association information, and adds the second association information to the first unit data of the processing target, At the p-th time (where p is an integer value of 2 or more), the data to which the first association information and the second association information have been added to the first unit data generated by the generation means is output as the p-th transmission data.The transmission data transmission control means of the first type electronic device executes control to transmit the p-th transmission data to the second type electronic device. The verification means of the second type electronic device, upon receiving transmission data from the first type electronic device, confirms that the hash value obtained from the first association information of the received transmission data matches either the hash value obtained from the first association information of the received transmission data or the hash value stored in the second storage medium. It also recalculates the hash value based on the hash value obtained from the first association information of the transmission data and the first unit data of the transmission data, and confirms that the recalculated hash value matches the hash value obtained from the second association information of the transmission data, thereby confirming the transmission data. The second type electronic device further has a reception notification means that notifies the first type electronic device of receipt when the verification means has confirmed the transmission data. The storage control means of the second type electronic device executes control to store the p-th transmission data, which has been confirmed, in the second storage medium together with the p-th hash value obtained from the second association information of the p-th transmission data and the reception notification. This allows for secure sharing of unique information between the smart key and the vehicle's control unit via a configuration device during data transmission. Furthermore, by combining base values and time information, it is possible to prevent malicious attacks such as relay attacks and replay attacks. In addition, even if data continuity is interrupted due to communication failures, secure and efficient data transmission can be achieved by using reception notifications and hash value history.
[0085] Furthermore, in the information processing system, the unique information of a Type II electronic device (for example, the "automobile control unit HCCM-C" described in the second embodiment) can include public key information. This allows transmission data sent from the smart key to be securely sent and received using a public key cryptography scheme.
[0086] Furthermore, in the information processing system, a Type II electronic device (for example, the "automobile control unit HCCM-C" described in the second embodiment) can decrypt transmitted data using a secret key. This ensures that only legitimate recipients can decrypt and process encrypted transmitted data, preventing interception or tampering by unauthorized third parties.
[0087] Furthermore, in the information processing system, the first type of electronic device can be a car key (for example, the "smart key HCCS-K" described in the second embodiment), and the second type of electronic device can be a control device that controls the locking and unlocking of the car key (for example, the "car control unit HCCM-C" described in the second embodiment). This enables secure and efficient authentication processing in the smart key system.
[0088] Furthermore, in the information processing system, the data of a predetermined unit to be processed may include data indicating an instruction to unlock a vehicle. This enables secure transmission of door unlocking instructions, ensuring legitimacy and continuity.
[0089] S... Information processing system, 51... Target data acquisition and processing unit, 52... Transmission data generation unit, 53... Generation unit, 54... First processing unit, 55... Second processing unit, 56... Transmission data transmission control unit, 57... Base value and other information acquisition unit, 61... Transmission data reception control unit, 62... Confirmation unit, 63... Storage control unit, 64... Base value generation unit, 65... Time synchronization unit, 66... Information transmission control unit, HCCS... Slave chip (slave hash chain chip), HCCS-K... Smart key, HCCM... Master chip (master hash chain chip), HCCM-A... Second type electronic device to be stored, HCCM-C... Automobile control unit, BCN... Recording device group (blockchain network), 18... Storage medium
Claims
1. An information processing system comprising: a first type electronic device having at least a transmission function for transmitting transmission data in accordance with a predetermined wireless communication method and including a first storage medium for storing the transmission data; and a second type electronic device having at least a reception function for receiving the transmission data in accordance with the predetermined wireless communication method and including a second storage medium for storing the transmission data, wherein the first type electronic device comprises: target data acquisition and processing means for acquiring target data to be transmitted, or acquiring the source data of the target data and processing the source data to generate the target data; transmission data generation means for generating the transmission data in predetermined units based on the target data; and transmission data transmission control means for executing control to transmit the transmission data to the second type electronic device in accordance with the predetermined wireless communication method; and the second type electronic device comprises: transmission data reception control means for executing control to receive the transmission data in accordance with the predetermined wireless communication method; confirmation means for confirming the received transmission data; and storage control means for executing control to store the confirmed transmission data in the second storage medium; and the transmission data generation means of the first type electronic device is The system further includes: generation means that repeatedly generates data for each predetermined unit based on the target data; first electronic device storage control means that generates the data of the predetermined unit to be processed generated by the generation means as first unit data and records the hash value associated with the transmission data received as a notification from the second electronic device in the first storage medium; first processing means that generates a hash value based on the latest hash value among the hash values recorded in the first storage medium, generates information including the hash value as first association information, and adds the first association information to the first unit data to be processed; and second processing means that generates information including at least the hash value obtained from the first unit data as second association information and adds the second association information to the first unit data to be processed.The p-th transmission data is output as the p-th transmission data, to which the first association information and the second association information have been added to the first unit data generated by the generation means at the p-th time (where p is an integer value of 2 or more). The transmission data transmission control means of the first type electronic device executes control to transmit the p-th transmission data to the second type electronic device. The verification means of the second type electronic device, upon receiving the transmission data from the first type electronic device, confirms that the hash value obtained from the first association information of the received transmission data matches one of the hash values stored in the second storage medium, and recalculates the hash value based on the hash value obtained from the first association information in the transmission data and the first unit data of the transmission data, and confirms that the recalculated hash value matches the hash value obtained from the second association information in the transmission data. The second type electronic device further has a reception notification means that notifies the first type electronic device of the reception when the verification means has confirmed the transmission data. The memory control means of the second type electronic device is an information processing system that performs control to store the p-th transmission data, which has been confirmed, in the second storage medium together with the p-th hash value obtained from the second associated information of the p-th transmission data and the reception notification.