Authentication data generation program, data authentication program, authentication data generation apparatus, data authentication apparatus, data authentication system, authentication data generation method, and data authentication method

WO2026168495A1PCT designated stage Publication Date: 2026-08-13SHIKUMI LAB INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-04
Publication Date
2026-08-13

Smart Images

  • Figure JP2026004029_13082026_PF_FP_ABST
    Figure JP2026004029_13082026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention provides a technology for verifying data acquired by an apparatus that may possibly be subject to spoofing attacks or replay attacks. A method for generating verification data includes: a step (S232) for calculating a hash value of data acquired by an edge device (100); a step (S236) for transmitting the hash value to an external TSA apparatus (210); a step (S238) for receiving, from the external TSA apparatus (210), a second time stamp token (TST(2)) generated by applying an electronic signature to the hash value; steps (S242, S244) for generating a first time stamp token (TST(1)) by applying an electronic signature to the hash value; a step (S250) for transmitting, by the edge device (100), the data, a signed navigation message, the TST(1), and the TST(2) to an external authentication station (220); and a step (S254) for receiving a signed verification result from the external authentication station (220).
Need to check novelty before this filing date? Find Prior Art

Description

Authentication data generation program, data authentication program, authentication data generation device, data authentication device, data authentication system, authentication data generation method, and data authentication method

[0001] The present disclosure relates to data authentication, and more specifically, to a technique for verifying data associated with time information.

[0002] As one type of unauthorized access in a communication network, a reflection attack (also referred to as a "replay attack") is known. In a replay attack, data obtained by eavesdropping on communication is used as it is, and the data itself is treated as genuine data. Therefore, it is impossible to detect that unauthorized access is being performed based only on the data. Another type of unauthorized access is a spoofing attack in which a user attempts to access by impersonating another person's device or user. Regarding spoofing, for example, Japanese Patent Application Laid-Open No. 2022-179962 (Patent Document 1) discloses a technique for determining spoofing of a consumer signal.

[0003] Japanese Patent Application Laid-Open No. 2022-179962

[0004] Many information communication devices (hereinafter also referred to as "edge devices") have a positioning function and receive positioning signals transmitted from satellites. The edge device uses the time information included in the positioning signal as the time information of the edge device. When such an edge device is subjected to a spoofing attack or a replay attack by a device that has illegally obtained the positioning signal, the edge device may adopt the illegal time information included in the data used in the replay attack as the time information obtained from the positioning signal. When illegal time information is used by the edge device, incorrect time information is adopted as a timestamp, or inaccurate position information is derived. As a result, the edge device outputs illegal data. Therefore, there is a need for a technique to verify whether the data output from the edge device is genuine or false.

[0005] This disclosure is made in light of the above-mentioned background, and one of its objectives is to provide a technique for verifying whether data acquired by a device is genuine or false.

[0006] According to one embodiment, an authentication data generation program is provided that causes a computer to generate data for verification. The authentication data generation program causes the computer to perform the following steps: receive a digitally signed navigation message; acquire data; calculate a hash value of the data; generate a first timestamp token by digitally signing the time information and hash value based on the digitally signed navigation message; transmit the hash value to a time authentication device; receive a second timestamp token generated by the time authentication device digitally signing the hash value and the time information of the time authentication device; and transmit the data, the digitally signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

[0007] In other aspects, a data authentication program is provided for causing a computer to perform a method of authenticating information received from a terminal. This method includes the steps of receiving an electronically signed navigation message and receiving information from a terminal. The information includes data acquired by the terminal, a hash value calculated from the data, a first timestamp token generated by electronically signing time information based on the electronically signed navigation message received by the terminal, and a second timestamp token generated by the time authentication device electronically signing time information of the time authentication device and the hash value sent from the terminal to the time authentication device, and sent from the time authentication device to the terminal. The method further includes the step of determining whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0008] In another embodiment, an authentication data generation device is provided that generates data for authentication. This authentication data generation device comprises a receiver for receiving an electronically signed navigation message, a sensor, a transmitter for transmitting a signal to another device, and a processor. The processor calculates a hash value of the data acquired by the sensor, electronically signs the time information and hash value based on the electronically signed navigation message to generate a first timestamp token, transmits the hash value to a time authentication device, receives a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device, and transmits the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

[0009] In another embodiment, a data authentication device is provided for authenticating received data. The data authentication device comprises a receiver for receiving information from a terminal and a processor. The information includes data acquired by the terminal, a hash value calculated from the data, a first timestamp token generated by digitally signing time information based on a digitally signed navigation message received by the terminal, and a second timestamp token generated by the time authentication device digitally signing time information of the time authentication device and a hash value transmitted from the terminal to the time authentication device, and transmitted from the time authentication device to the terminal. The processor determines whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0010] In another embodiment, a data authentication system for authenticating data is provided. The data authentication system comprises an authentication data generation device and a data authentication device. The authentication data generation device comprises a receiver for receiving an electronically signed navigation message, a sensor, a transmitter for transmitting a signal to another device, and a processor. The processor calculates a hash value of the data acquired by the sensor, electronically signs the time information and hash value based on the electronically signed navigation message to generate a first timestamp token, transmits the hash value to the time authentication device, receives a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device, and transmits the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to the data authentication device. The data authentication device determines whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0011] In another embodiment, a method for generating authentication data is provided in which a computer generates data for authentication. This method includes the steps of: receiving an electronically signed navigation message; acquiring data; calculating a hash value of the data; generating a first timestamp token by electronically signing the time information and hash value based on the electronically signed navigation message; transmitting the hash value to a time authentication device; receiving a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device; and transmitting the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

[0012] In another embodiment, a data authentication method is provided for a computer to authenticate information received from a terminal. The data authentication method includes the steps of receiving an electronically signed navigation message and receiving information from a terminal. The information includes data acquired by the terminal, a hash value calculated from the data, a first timestamp token generated by electronically signing time information based on the electronically signed navigation message received by the terminal, and a second timestamp token generated by the time authentication device electronically signing a hash value transmitted from the terminal to the time authentication device and time information of the time authentication device, and transmitted from the time authentication device to the terminal. The data authentication method further includes the step of determining whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0013] The above and other objects, features, aspects and advantages of this invention will become apparent from the following detailed description relating to this invention, which will be understood in conjunction with the accompanying drawings.

[0014] This is a diagram showing the configuration of the digital trust system 10. This is a sequence diagram showing the flow of processing between the edge device 100, the external TSA device 210, and the external certification authority 220. This is a diagram conceptually showing the configuration of a timestamp token. This is a flowchart showing part of the processing performed between the edge device 100, the external TSA device 210, and the external certification authority 220. This is a flowchart showing part of the processing performed by the edge device 100 after receiving verification results from the external certification authority 220. This is a flowchart illustrating part of the processing when a drive recorder functions as the edge device 100. This is a diagram conceptually showing one mode in which a verification service is provided. This is a block diagram showing the hardware configuration of the computer system 800.

[0015] Embodiments of the present invention will be described below with reference to the drawings. In the following description, identical parts are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions of them will not be repeated.

[0016] <Overall Configuration> Referring to Figure 1, a digital trust system 10 according to this embodiment will be described. Figure 1 is a diagram showing the configuration of the digital trust system 10. The digital trust system 10 is realized by a plurality of satellites 11, an edge device 100, a signal authentication system 110, and a control station 120. The plurality of satellites 11 include a plurality of quasi-zenith satellites (QZSS) 130 as an example of a satellite-based augmentation system (SBAS), and a plurality of GPS (Global Positioning System) satellites 140 as an example of an existing global navigation satellite system (GNSS). The signal authentication system 110 and the edge device 100 function as an external authentication system 12.

[0017] The edge device 100 is an information and communication terminal with positioning capabilities. The edge device 100 includes a processor 101, a GNSS receiving circuit 102, and a memory 103. The memory 103 stores the public key 114. Examples of edge devices 100 include mobile phones, tablet terminals, dashcams, smartphones, smartwatches, and wearable devices. The processor 101 executes instructions to control the operation of the edge device 100. The processor 101 can be a CPU (Central Processing Unit), MPU (Micro Processor Unit), FPGA (Field Programmable Gate Array), or any other device that executes instructions.

[0018] The GNSS receiving circuit 102 receives four or more positioning signals and uses the time information contained in each positioning signal to derive the position of the edge device 100. Each positioning signal may be a positioning signal transmitted from multiple quasi-zenith satellites 130 or other SBAS satellites, or a positioning signal transmitted from a GPS satellite 140. The memory 103 holds data received by the edge device 100 and data generated by the edge device 100. The memory 103 is implemented by flash memory or other non-volatile memory. In other aspects, the memory 103 may be removable. When the processor 101 receives the public key 114 from the signal authentication system 110, it stores the public key 114 in the memory 103.

[0019] The signal authentication system 110 manages a private key 111 and a public key 114 that forms a pair with the private key 111. The signal authentication system 110 is configured to communicate with control stations 120 of multiple quasi-zenith satellites 130. The signal authentication system 110 receives positioning signals uploaded to each quasi-zenith satellite 130, performs electronic authentication of the positioning signals using the private key 111, and attaches an electronic signature to the positioning signals. The control station 120 uploads the electronically signed positioning signals to each quasi-zenith satellite 130. On the other hand, the control station 120 transmits the public key 114 to the edge device 100. For example, an edge device 100 that wishes to receive the authentication service realized in the digital trust system 10 according to this embodiment can obtain the public key 114 from the control station 120.

[0020] Each quasi-zenith satellite 130 transmits a positioning signal with an electronic signature. On the other hand, the GPS satellite 140 transmits a conventional, well-known positioning signal.

[0021] The edge device 100 can receive electronically signed positioning signals transmitted from each quasi-zenith satellite 130 or conventional, well-known positioning signals transmitted from GPS satellites 140. The GNSS receiving circuit 102 calculates the distance to each satellite by performing predetermined calculations using the time information contained in the positioning signals received from each of the four satellites, and further determines the position of the edge device 100.

[0022] Since the configuration of positioning signals is well known, it is possible that a pseudo-signal (spoofing signal) with a similar configuration to the positioning signal may be generated. Such a pseudo-signal may provide incorrect information to the edge device 100. For example, a spoofing device 150 may transmit a spoofing signal with the same configuration as the positioning signal transmitted from the GPS satellite 140. If the signal output of the spoofing device 150 is greater than the signal output of other transmitters near the edge device 100, the edge device 100 may receive the spoofing signal transmitted from the spoofing device 150 as a positioning signal, and the GNSS receiving circuit 102 may calculate the position of the edge device 100 using the time information contained in the positioning signal. In that case, the calculated position may be an incorrect position.

[0023] Furthermore, the edge device 100 may synchronize its time information with time information obtained from the spoofing signal. If this happens, the timestamp attached to the signal output from the edge device 100 will indicate incorrect time information, and other communication devices receiving such signals may malfunction. Therefore, a technology is needed to detect that the signal transmitted from the edge device 100 that has been subjected to a spoofing attack is not a genuine signal.

[0024] <Overview of External Authentication Sequence> Referring to Figure 2, the authentication sequence according to one embodiment will be described. Figure 2 is a sequence diagram showing the flow of processing between the edge device 100, the external TSA device 210, and the external certification authority 220.

[0025] The edge device 100 includes, in addition to the configuration shown in Figure 1, a sensor 201, a spatiotemporal gateway (GW) circuit 202, and an internal time stamp authority (TSA) circuit 203. The edge device 100 can be implemented as, for example, a smartphone or other mobile phone, a drive recorder, or an earthquake measurement system. The spatiotemporal gateway circuit 202 and the internal TSA circuit 203 are implemented by the processor 101.

[0026] Sensor 201 is one or more sensors corresponding to the edge device 100. For example, if the edge device 100 is implemented as a smartphone, then sensor 201 may be a GPS sensor, an accelerometer, a gyroscope, a biometric authentication sensor, a light sensor, an image sensor (camera), etc.

[0027] The spacetime gateway circuit 202 performs processing for communication between the edge device 100 and the external TSA device 210 and the external certification authority 220 or other information and communication devices. The internal TSA circuit 203 performs timestamp authentication within the edge device 100. Specifically, the internal TSA circuit 203 uses the time information of the edge device 100 to digitally sign the data received from the spacetime gateway 202. In certain situations, the time information used for timestamp authentication is synchronized with the time information contained in the GPS signal.

[0028] The external TSA device 210, as a separate device from the edge device 100, performs timestamp authentication on data received from the edge device 100. For example, the external TSA device 210, like the internal TSA circuit 203, performs an electronic signature on data received from the spacetime gateway circuit 202. The external TSA device 210 may also have a GNSS receiving circuit. In this case, the time of the external TSA device 210 and the time of another device with a GNSS receiving circuit, such as the edge device 100, will be approximately synchronized.

[0029] The external certification authority 220 includes a QZNMA (Quasi-Zenith Satellite Navigation Message Authentication) authenticator 221. The external certification authority 220, as an independent entity separate from the edge device 100, verifies whether the data transmitted from the edge device 100 is authentic.

[0030] More specifically, in step S230, the sensor 201 of the edge device 100 transmits the detected data to the spatiotemporal gateway circuit 202. In step S232, the spatiotemporal gateway circuit 202 calculates the hash value of the data received from the spatiotemporal gateway circuit 202. In step S234, the spatiotemporal gateway circuit 202 transmits the calculated hash value to the external TSA device 210. Here, the form or manner of communication between the spatiotemporal gateway circuit 202 and the external TSA device 210 is not particularly limited. The communication may be via a public network such as the Internet, or a dedicated line provided by a carrier offering a specific communication service.

[0031] In step S236, the external certification authority 220 performs electronic authentication on the hash value received from the edge device 100 and generates a second timestamp token (TST(2)). The second timestamp token (TST(2)) includes the hash value and time information according to the clock of the external certification authority 220. In step S238, the external certification authority 220 transmits the second timestamp token (TST(2)) to the edge device 100.

[0032] In step S240, the spacetime gateway circuit 202 transmits the calculated hash value (step S232) to the internal TSA circuit 203. In step S242, the internal TSA circuit 203 performs electronic authentication on the hash value and generates a first timestamp token (TST(1)). The first timestamp token (TST(1)) includes the hash value and time information that follows the clock of the external certification authority 220. In step S244, the internal TSA circuit 203 transmits the first timestamp token (TST(1)) to the edge device 100.

[0033] In step S250, the spacetime gateway circuit 202 transmits an authentication request to the external certification authority 220. More specifically, the spacetime gateway circuit 202 transmits to the external certification authority 220 the data detected by the sensor 201, the digitally signed GNSS navigation message, the first timestamp token (TST(1)), the second timestamp token (TST(2)), and the authentication request for the said data. Here, the form or manner of communication between the spacetime gateway circuit 202 and the external TSA device 210 is not particularly limited. The communication may be via a public network such as the Internet, or a dedicated line provided by a carrier of a specific communication service.

[0034] In step S252, the QZNMA authenticator 221 of the external certification authority 220 verifies whether the data sent from the edge device (S230) is genuine. More specifically, the QZNMA authenticator 221 compares the time information contained in TST(1) with the time information contained in TST(2) to determine whether the difference between these times is within a predetermined time. If the difference in time is within a predetermined time, the QZNMA authenticator 221 determines that the data is genuine. That is, the data is considered to be data correctly acquired by the sensor 201, and the QZNMA authenticator 221 generates a QZNMA verification result as a result of this determination.

[0035] In other situations, verification of whether the data is genuine may be performed based on whether the order of time information included in TST(1) and time information included in TST(2) is as expected.

[0036] In other words, if the edge device 100 is subjected to a spoofing attack or a replay attack and its time is overwritten with false time information, the time information contained in TST(1) may be considerably earlier or considerably later than the genuine time information contained in TST(2). Therefore, the external certification authority 220 can compare the time information contained in TST(1) with the time information contained in TST(2) and, based on the difference between the times or the order of the time information, determine that the time information is not the actual time information, and if it is estimated that the data is not genuine, it can determine that the data is not genuine.

[0037] In step S254, the external certification authority 220 transmits the QZNMA verification result, which has been electronically authenticated, to the edge device 100. The edge device 100 stores the received QZNMA verification result in memory 103. The user of the edge device 100 can submit the QZNMA verification result to a third party that requests it.

[0038] <Timestamp Token> The timestamp token used for data verification will be explained with reference to Figure 3. Figure 3 is a conceptual diagram of the structure of a timestamp token. Below, we will explain the case in which the edge device 100 can obtain genuine data (Case A) and the case in which invalid data is obtained (Case B).

[0039] [Case (A)] Case (A) illustrates the case where the edge device 100 is not subjected to a reply attack or spoofing attack, that is, when genuine data is obtained at the edge device 100. TST(1) 310 includes a hash value 311 and time information 312. The hash value 311 is obtained by inputting the data obtained by the sensor 201 into a pre-prepared hash function. The time information 312 is a timestamp A that follows the clock of the edge device 100. TST(1) 310 is digitally signed (step S242) by encryption with a pre-prepared secret key.

[0040] TST(2) 320 includes a hash value 321 and time information 322. The hash value 321 is obtained by inputting the data received from the edge device 100 (S234) into a pre-prepared hash function. The time information 322 is a timestamp A' that follows the clock of the external TSA circuit 203. TST(2) 310 is digitally signed (step S236) by encryption with a pre-prepared secret key.

[0041] If the time information of the edge device 100 has not been overwritten by an unauthorized signal from an external source (for example, a spoofing signal or a signal that leads to a reply attack), the difference between timestamp A when the internal TSA circuit 203 digitally signs and timestamp A' when the external TSA device digitally signs will be only a time difference due to the delay in communication between the edge device 100 and the external TSA device 210, and will not be a time difference of several hours or several days. Therefore, if the difference between timestamp A and timestamp A' is only a few minutes, the data acquired by the edge device 100 can be determined to be authentic.

[0042] [Case (B)] Case (B) illustrates a case where the edge device 100 is subjected to a reply attack or spoofing attack, that is, when malicious data is obtained on the edge device 100, for example, when the time information of the edge device 100 is rewritten.

[0043] TST(1) 330 includes a hash value 331 and time information 332. The hash value 331 is obtained by inputting data acquired by the sensor 201 into a pre-prepared hash function. The time information 332 is a timestamp B that follows the clock of the edge device 100.

[0044] The TST (2) 320 is the same as in the case of the case (A), and the time information 322 includes the time stamp A'. If the clock time information is rewritten due to the edge device 100 being subjected to a replay attack or a spoofing attack, the time stamp B will follow the incorrect time included in the signal causing the replay attack or spoofing attack. Therefore, the difference between the time stamp A' and the time stamp B can be large on the order of several hours, several days, or several months.

[0045] <Control Structure> Referring to FIG. 4, the control structure of the digital trust system 10 will be described. FIG. 4 is a flowchart showing a part of the processing performed between the edge device 100, the external TSA device 210, and the external certification authority 220.

[0046] In step S410, the edge device 100 detects a trigger (e.g., sudden shake, sudden acceleration) to start an external authentication sequence based on the output from the sensor 201. When the edge device 100 is realized as a seismic measurement system, the edge device 100 records the output signal from the sensor 201 as an accelerometer included in the seismic measurement system in the memory.

[0047] In step S415, the edge device 100 acquires data (e.g., seismic measurement values, images of the in-vehicle camera of the drive recorder, etc.) from the memory. In step S420, the edge device 100 inputs the data into a hash function to calculate a hash value, and transmits the hash value to the external TSA device 210.

[0048] In step S425, the edge device 100 acquires time information from the internal clock. The edge device 100 has a GNSS reception circuit 102. Therefore, when the edge device 100 is operating normally, the time information is synchronized with the time of the navigation message received by the GNSS reception circuit 102. On the other hand, when the edge device 100 is subjected to a replay attack or a spoofing attack, the time information may be rewritten incorrectly according to the signal causing these attacks.

[0049] In step S430, the edge device 100 digitally signs the hash value and time information to generate a first timestamp token (TST(1)). In step S435, the edge device 100 transmits the hash value to the external TSA device 210. In step S440, the external TSA device 210 digitally signs the received hash value and time information to generate a second timestamp token (TST(2)). In step S445, the external TSA transmits TST(2) to the edge device 100.

[0050] In step S450, the edge device 100 transmits the acquired data (step S415), the digitally signed navigation message, TST(1), and TST(2) to the external certification authority 220. The digitally signed navigation message is digitally signed by the signal authentication system 110 and uploaded from the control station 120 to each quasi-zenith satellite 130. In step S455, the external certification authority 220 uses the information received from the edge device 100 to verify the data acquired by the edge device 100 (QZNMA verification). For example, the external certification authority 220 compares the timestamp contained in TST(1) with the timestamp contained in TST(2), calculates the difference between the timestamps, or identifies the order of events.

[0051] In step S460, the QZNMA authenticator 221 of the external certification authority 220 determines whether the data transmitted by the edge device is genuine. If the QZNMA authenticator 221 determines that the data is genuine (YES in step S460), it switches control to step S470. Otherwise (NO in step S460), the QZNMA authenticator 221 switches control to step S480.

[0052] In step S470, the QZNMA authenticator 221 generates a result indicating that the data is genuine. In step S480, the QZNMA authenticator 221 generates a result indicating that the data is false. In step S490, the QZNMA authenticator 221 transmits this result to the edge device 100.

[0053] As described above, according to this embodiment, the edge device 100 calculates the hash value of the acquired data to generate TST(1), and receives TST(2) generated from the hash value from the external TSA device 210. The edge device 100 transmits the data, the signed navigation message, TST(1), and TST(2) to the external certification authority 220, which calculates the time difference between TST(1) and TST(2). Whether the data acquired by the edge device 100 is genuine can be determined by the time difference or order of TST(1) and TST(2). This allows for accurate determination of whether the data received by the edge device 100 is genuine, even if the edge device 100 is subject to spoofing or replay attacks. Furthermore, the data transmitted from the edge device 100 to the external TSA device 210 is a hash value, and its data volume is far less than that of the actual data. This can suppress the delay in communication between the edge device 100 and the external TSA device 210.

[0054] <Operation of the Edge Device> The operation of the edge device 100 will be explained with reference to Figure 5. Figure 5 is a flowchart showing part of the processing performed by the edge device 100 when it receives verification results from the external certification authority 220.

[0055] In step S510, the processor 101 of the edge device 100 detects that it has received the verification result from the external certification authority 220. In step S520, the processor 101 determines whether the result indicates that the time information of the edge device 100 is authentic. That is, the processor 101 determines whether the data acquired by the edge device 100 is authentic. If the processor 101 determines that the result indicates that the time information of the edge device 100 is authentic (the data is authentic) (YES in step S520), it switches control to step S530. Otherwise (NO in step S520), the processor 101 switches control to step S550.

[0056] In step S530, the processor 101 executes a predetermined process. For example, the processor 101 performs a position calculation using the time information of the edge device 100. Alternatively, the processor 101 performs a process using the position information of the edge device 100. In step S540, the processor 101 outputs a notification indicating that the process has been completed successfully. In step S550, the processor 101 outputs a notification indicating that the time information of the edge device 100 is false.

[0057] <Example of a Drive Recorder> Referring to Figure 6, another example of this embodiment will be described. Figure 6 is a flowchart illustrating part of the processing when a drive recorder functions as an edge device 100.

[0058] In step S610, the processor of the drive recorder installed in the vehicle detects a collision with another vehicle based on the output of the acceleration sensor. The processor saves the time information of the collision, the vehicle's position information at the time of the collision obtained from the GPS signal, and image data of the collision. In step S615, the processor calculates the hash value of the image data and transmits the obtained hash value to the internal TSA circuit 203.

[0059] In step S620, the internal TSA circuit 203 performs electronic authentication of the hash value and generates a first timestamp token (TST(1)) with an electronic signature attached to the hash value. In step S625, the drive recorder establishes communication with the external certification authority 220 and transmits the calculated hash value to the external TSA device 210. The communication is, for example, via an internet connection using a mobile communication network.

[0060] In step S630, the external TSA device 210 digitally signs the hash value received from the drive recorder to generate a second timestamp token (TST(2)), and transmits the generated TST(2) to the drive recorder. In step S635, the drive recorder transmits the image data, the digitally signed GNSS navigation message, TST(1), and TST(2) to the external certification authority 220.

[0061] In step S640, the QZNMA authenticator 221 of the external certification authority 220 verifies the data acquired by the edge device 100 using the navigation message received from the edge device 100 and TST(1) and TST(2). In step S645, the QZNMA authenticator 221 determines whether the difference between the time of TST(1) and the time of TST(2) is within a preset range. If the QZNMA authenticator 221 determines that the difference is within a preset range (YES in step S645), it switches control to step S650. Otherwise (NO in step S645), the QZNMA authenticator 221 switches control to step S660.

[0062] In step S650, the QZNMA authenticator 221 generates a result indicating that the image data transmitted by the drive recorder is genuine data. In step S660, the QZNMA authenticator 221 generates a result indicating that the image data transmitted by the drive recorder is not genuine data (it is false data).

[0063] In step S670, the external certification authority 220 sends the generated result to the drive recorder. In step S680, the drive recorder sends the result received from the external certification authority 220 to the insurance company's server for the vehicle. In step S690, the insurance company's server takes the result into consideration and performs insurance processing. For example, the server estimates the severity of the accident by considering information from the image data and the acceleration at the time of the collision, or calculates the insurance payout resulting from the accident.

[0064] As described above, according to this embodiment, a drive recorder, as an example of an edge device 100, requests authentication from an external certification authority 220 to verify that the acquired data is genuine. If the acquired data is genuine, the external certification authority 220 transmits an authentication result to the drive recorder indicating this. The drive recorder or its user can prove that the data acquired by the drive recorder is not false by presenting the authentication result to a third party (for example, an insurance company).

[0065] <Authentication Service> According to this embodiment, the digitally signed verification data transmitted from the external certification authority 220 to the edge device 100 is further provided to the service provider and can be used for verification based on a request from a third party. Therefore, an overview of an example of a verification service according to this embodiment will be described with reference to Figure 7. Figure 7 is a diagram that conceptually represents one aspect of how the verification service is provided. Note that the same components as those described above are given the same numbers. Therefore, the same explanation will not be repeated.

[0066] The verification service is implemented by the service provider's server 700. The server 700 has a database 710. The database 710 stores electronically signed verification data received from edge devices 100 and other devices, associated with the identification information of those devices. The server 700 can communicate with a third-party terminal 720. The terminal 720 is implemented by a tablet device, a desktop PC, or other computer device.

[0067] <Accumulation of Electronically Signed Verification Data> First, the process by which electronically signed verification data is accumulated on server 700 is as follows:

[0068] In step S750, the external certification authority 220 transmits digitally signed verification data to the edge device 100. In step S760, the edge device 100 establishes communication with the server 700 and transmits digitally signed verification data to the server 700. The timing of establishing communication with the server 700 may be, for example, when the user of the edge device 100 performs a predetermined operation, when the digitally signed verification data contains predetermined data items necessary to establish the communication, or when a predetermined time has arrived.

[0069] When the edge device 100 establishes communication with the server 700, it transmits the digitally signed verification data received from the external certification authority 220 to the server 700. The server 700 associates the digitally signed verification data with the identification information of the edge device 100 and stores it in the database 710. The processing in steps S750 and S760 is performed for each edge device. The server 700 can be configured on the cloud, and multiple servers 700 may each have a database 710.

[0070] <Request for Verification Service by a Third Party> In certain situations, a third party, different from the user of the edge device 100, can use a verification service that utilizes data acquired by the edge device 100. For example, as illustrated in Figure 6, there are cases where it is necessary to verify whether image data acquired by a drive recorder is genuine. In such cases, when the third party operates terminal 720 and sends a verification request to server 700 (step S770), server 700 searches for digitally signed verification data associated with the identification information contained in the verification request, using the identification information as a search key. If server 700 is able to extract digitally signed verification data that matches the search key, it sends that digitally signed verification data to the third party's terminal 720 as a verification result. On the other hand, if server 700 is unable to extract digitally signed verification data that matches the search key, it sends a message to that effect as a search result to terminal 720.

[0071] A third party can refer to the search results received from server 700 and determine whether the image data that triggered the verification request is a genuine image (i.e., whether it is an image that depicts the facts).

[0072] Referring to Figure 8, the configuration of the computer system 800 that implements the external TSA device 210, the signal authentication system 110, and the terminal 720 will be described. Figure 8 is a block diagram showing the hardware configuration of the computer system 800. The computer system 800 mainly consists of a CPU 1 that executes each instruction included in the computer program, a mouse 2 and a keyboard 3 that receive input instructions from the user of the computer system 800, a RAM 4 that temporarily stores data generated by the execution of the program by the CPU 1 or data input via the mouse 2 or keyboard 3, a hard disk 5 that permanently stores data, an optical disc drive 6, a communication interface (I / F) 7, and a monitor 8. Each component is connected to the others by a data bus. A CD-ROM 9 or other optical disc is mounted in the optical disc drive 6.

[0073] Processing in the computer system 800 is realized by each piece of hardware and software executed by the CPU 1. Such software may be pre-stored on the hard disk 5. Alternatively, the software may be stored on a CD-ROM 9 or other recording medium and distributed as a computer program. Or, the software may be provided as a downloadable application program by an information provider connected to the so-called Internet. Such software is read from the recording medium by an optical disc drive 6 or other reading device, or downloaded via a communication interface 7, and then temporarily stored on the hard disk 5. The CPU 1 reads the software from the hard disk 5 and stores it in RAM 4 in the form of an executable program. The CPU 1 then executes the program.

[0074] The components of the computer system 800 shown in Figure 8 are common. Therefore, one of the essential parts of the technical concept relating to this disclosure can be said to be the software stored on the RAM 4, hard disk 5, CD-ROM 9, and other recording media, or software that can be downloaded via a network. The recording media may include non-temporary, computer-readable data recording media. Since the operation of each hardware component of the computer system 800 is well known, a detailed explanation will not be repeated.

[0075] Furthermore, the recording medium is not limited to CD-ROMs, FDs (Flexible Disks), and hard disks, but may also be magnetic tape, cassette tapes, optical discs (MO (Magnetic Optical Disc) / MD (Mini Disc) / DVD (Digital Versatile Disc)), IC (Integrated Circuit) cards (including memory cards), optical cards, mask ROMs, EPROMs (Electronically Programmable Read-Only Memory), EEPROMs (Electronically Erasable Programmable Read-Only Memory), flash ROMs, and other semiconductor memory media that permanently hold programs. The term "program" here includes not only programs that can be directly executed by the CPU, but also programs in source code format, compressed programs, encrypted programs, etc. Also, in certain situations, the computer system 800 can function as an edge device 100.

[0076] Some of the technical features understood from the above can be summarized as follows: (1) According to one embodiment, an authentication data generation program is provided that causes a computer to generate data for verification. The authentication data generation program causes a computer (e.g., edge device 100, computer system 800) to perform the following steps: receive an electronically signed navigation message; acquire data; calculate a hash value of the data; electronically sign the time information and hash value based on the electronically signed navigation message to generate a first timestamp token; transmit the hash value to a time authentication device (e.g., external TSA device 210); receive a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device; and transmit the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device (e.g., external certification authority 220).

[0077] (2) In a certain situation, the authentication data generation program causes the computer to further execute the steps of receiving the verification result from the data authentication device and outputting the verification result.

[0078] (3) In a given situation, the verification result by the data authentication device includes a determination result indicating whether or not the computer's time information is genuine. The authentication data generation program causes the computer to perform a step of processing using the computer's time information, based on the indication that the computer's time information is genuine.

[0079] (4) In a given situation, processing using time information includes processing to calculate the computer's position.

[0080] (5) In a given situation, the time authentication device and the data authentication device are synchronized. (6) In a given situation, an electronically signed navigation message is received from a satellite that constitutes the Global Navigation Satellite System.

[0081] (7) In other aspects, a data authentication program is provided for causing a computer (e.g., an external authentication authority 220, a computer system 800) to perform a method for authenticating information received from a terminal. This method includes the steps of receiving an electronically signed navigation message and receiving information from a terminal. The information includes data acquired by the terminal, a hash value calculated from the data, a first timestamp token generated by electronically signing time information based on the electronically signed navigation message received by the terminal, and a second timestamp token generated by the time authentication device electronically signing a hash value transmitted from the terminal to the time authentication device and time information of the time authentication device, and transmitted from the time authentication device to the terminal. The method further includes the step of determining whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0082] (8) In a given situation, the method further includes the step of determining whether the information received from the terminal is authentic, based on the time information contained in the electronically signed navigation message received by the computer and the time information contained in the electronically signed navigation message contained in the information received from the terminal.

[0083] (9) In a given situation, the decision-making step includes determining that the information received from the terminal is genuine based on the fact that the difference between the time information contained in the first timestamp token and the time information contained in the second timestamp token is less than or equal to a predetermined threshold.

[0084] (10) In a given situation, the decision-making step includes determining that the data acquired by the terminal is false based on the fact that the time information contained in the first timestamp token is older than the time information contained in the second timestamp token by a predetermined amount of time.

[0085] (11) According to another embodiment, an authentication data generation device (e.g., edge device 100, computer system 800) is provided that generates data for authentication. This authentication data generation device comprises a receiver (e.g., GNSS receiving circuit 102) for receiving electronically signed navigation messages, sensors (e.g., sensor 201, camera), a transmitter for transmitting signals to other devices, and a processor (processor 101). The processor calculates a hash value of the data acquired by the sensors, electronically signs the time information and hash value based on the electronically signed navigation message to generate a first timestamp token, transmits the hash value to a time authentication device, receives a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device, and transmits the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

[0086] (12) In a certain phase, the processor further receives the data authentication result from the data authentication device and outputs the authentication result.

[0087] (13) In a given situation, the verification result by the data authentication device includes a determination result indicating whether or not the time information of the authentication data generation device is genuine. The processor further performs processing using the time information of the authentication data generation device based on the fact that the time information of the authentication data generation device is indicated to be genuine.

[0088] (14) In a given situation, the processing using time information includes the processing of calculating the position of the authentication data generation device.

[0089] (15) In a given situation, the time authentication device and the data authentication device are synchronized. (16) In a given situation, an electronically signed navigation message is received from a satellite that constitutes the Global Navigation Satellite System.

[0090] (17) In another embodiment, a data authentication device (e.g., an external certification authority 220, a computer system 800) is provided for authenticating received data. The data authentication device comprises a receiver (e.g., a communication interface 7) for receiving information from a terminal (e.g., an edge device 100) and a processor (e.g., a CPU 1). The information includes data acquired by the terminal, a hash value calculated from the data, a first timestamp token generated by digitally signing time information based on a digitally signed navigation message received by the terminal, and a second timestamp token generated by the time authentication device digitally signing a hash value transmitted from the terminal to the time authentication device and time information of the time authentication device, and transmitted from the time authentication device to the terminal. The processor determines whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0091] (18) In a given situation, the processor further determines whether the information received from the terminal is authentic based on the time information contained in the digitally signed navigation message received by the data authentication device and the time information contained in the digitally signed navigation message contained in the information received from the terminal.

[0092] (19) In a given situation, the judgment includes determining that the information received from the terminal is genuine based on the fact that the difference between the time information contained in the first timestamp token and the time information contained in the second timestamp token is less than or equal to a predetermined threshold.

[0093] (20) In a given situation, the judgment includes determining that the data acquired by the terminal is false based on the fact that the time information contained in the first timestamp token is older than the time information contained in the second timestamp token by a predetermined amount of time.

[0094] (21) In another embodiment, a data authentication system is provided for authenticating data. The data authentication system comprises an authentication data generation device (e.g., an edge device 100) and a data authentication device (e.g., an external authentication authority 220). The authentication data generation device comprises a receiver for receiving a digitally signed navigation message, a sensor, a transmitter for transmitting a signal to another device, and a processor. The processor calculates a hash value of the data acquired by the sensor, digitally signs the time information and hash value based on the digitally signed navigation message to generate a first timestamp token, transmits the hash value to the time authentication device, receives a second timestamp token generated by the time authentication device digitally signing the hash value and the time information of the time authentication device, and transmits the data, the digitally signed navigation message, the first timestamp token, and the second timestamp token to the data authentication device. The data authentication device determines whether the information received from the authentication data generation device is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0095] (22) According to another embodiment, a method for generating authentication data is provided in which a computer generates data for authentication. This method includes the steps of: receiving an electronically signed navigation message; acquiring data; calculating a hash value of the data; generating a first timestamp token by electronically signing the time information and hash value based on the electronically signed navigation message; transmitting the hash value to a time authentication device; receiving a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device; and transmitting the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

[0096] (23) In another embodiment, a data authentication method is provided for a computer to authenticate information received from a terminal. The data authentication method includes the steps of receiving an electronically signed navigation message and receiving information from a terminal. The information includes data acquired by the terminal, a hash value calculated from the data, a first timestamp token generated by electronically signing time information based on the electronically signed navigation message received by the terminal, and a second timestamp token generated by the time authentication device electronically signing a hash value transmitted from the terminal to the time authentication device and time information of the time authentication device, and transmitted from the time authentication device to the terminal. The data authentication method further includes the step of determining whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

[0097] As described above, according to this embodiment, the edge device 100 calculates the hash value of the acquired data and transmits the hash value to an external TSA device 210, which is separate from the edge device 100. The external TSA device 210 digitally signs the hash value, generates a second timestamp token (TST(2)), and transmits TST(2) to the edge device 100. The time information contained in TST(2) is time information that follows the clock of the external TSA device 210. The edge device 100 also digitally signs internally and generates a first timestamp token (TST(1)). The time information contained in TST(1) is time information that follows the clock of the edge device 100. The edge device 100 transmits the acquired data, the digitally signed navigation message contained in the received positioning signal, TST(1), and TST(2) to the external certification authority 220. The external certification authority 220 compares the time information contained in TST(1) with the time information contained in TST(2), and if the difference between these time information is within a predetermined range, it determines that the data acquired by the edge device 100 is authentic. The external certification authority 220 digitally signs the result of the determination to generate a verification result and transmits the verification result to the edge device 100. This proves to a third party that the data acquired by the edge device 100 is authentic.

[0098] On the other hand, if the edge device 100 is subjected to a malicious attack and its clock is rewritten, the difference between the time information contained in TST(1) and the time information contained in TST(2) will diverge significantly, for example, by several days or several weeks. When the external certification authority 220 detects such a difference, it determines that the data acquired by the edge device 100 is not genuine. The external certification authority 220 digitally signs this determination to generate a verification result and sends the verification result to the edge device 100. This indicates that the data acquired by the edge device 100 is at least not genuine.

[0099] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the invention is indicated by the claims rather than by the foregoing description, and all modifications within the meaning and scope of equivalents of the claims are intended to be included.

[0100] The disclosed technical concept is applicable to earthquake measurement systems, drive recorders, and other devices capable of acquiring information.

[0101] 2 Mouse, 3 Keyboard, 4 RAM, 5 Hard disk, 6 Optical disc drive, 7 Communication interface, 8 Monitor, 9 CD-ROM, 10 Digital trust system, 11 Satellite, 12 External authentication system, 100 Edge device, 101 Processor, 102 GNSS receiving circuit, 103 Memory, 110 Signal authentication system, 111 Private key, 114 Public key, 120 Control station, 130 Quasi-zenith satellite, 140 GPS satellite, 150 Spoofing device, 201 Sensor, 202 Spacetime GW circuit, 203 Internal TSA circuit, 210 External TSA device, 220 External certification authority, 221 QZNMA authenticator, 700 Server, 710 Database, 720 Terminal, 800 Computer system.

Claims

1. Authentication data generation program for causing a computer to generate data for verification, wherein the authentication data generation program causes the computer to perform the following steps: receiving a digitally signed navigation message; acquiring data; calculating a hash value of the data; generating a first timestamp token by digitally signing the time information based on the digitally signed navigation message and the hash value; transmitting the hash value to a time authentication device; receiving a second timestamp token generated by the time authentication device digitally signing the hash value and the time information of the time authentication device; and transmitting the data, the digitally signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

2. The authentication data generation program according to claim 1, further comprising the steps of: causing the computer to receive the verification result from the data authentication device; and outputting the verification result.

3. The authentication data generation program according to claim 1 or 2, wherein the verification result by the data authentication device includes a determination result indicating whether or not the computer's time information is genuine, and the authentication data generation program further causes the computer to perform a step of processing using the computer's time information based on the indication that the computer's time information is genuine.

4. The authentication data generation program according to claim 3, wherein the processing using the time information includes processing to calculate the location of the computer.

5. The authentication data generation program according to any one of claims 1 to 4, wherein the time authentication device and the data authentication device are synchronized.

6. The authentication data generation program according to any one of claims 1 to 5, wherein the electronically signed navigation message is received from a satellite constituting the Global Navigation Satellite System.

7. A data authentication program for causing a computer to perform a method for authenticating information received from a terminal, the method comprising: receiving an electronically signed navigation message; and receiving information from the terminal, the information comprising: data acquired by the terminal; a hash value calculated from the data; a first timestamp token generated by electronically signing time information based on the electronically signed navigation message received by the terminal; and a second timestamp token generated by the time authentication device electronically signing the hash value transmitted from the terminal to the time authentication device and time information of the time authentication device, and transmitted from the time authentication device to the terminal, the method further comprising: determining whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

8. The data authentication program according to claim 7, further comprising the step of determining whether the information received from the terminal is authentic based on time information contained in the electronically signed navigation message received by the computer and time information contained in the electronically signed navigation message contained in the information received from the terminal.

9. The data authentication program according to claim 7, wherein the determination step includes determining that the information received from the terminal is authentic based on the fact that the difference between the time information contained in the first timestamp token and the time information contained in the second timestamp token is less than or equal to a predetermined threshold.

10. The data authentication program according to claim 7, wherein the determination step includes determining that the data acquired by the terminal is false based on the fact that the time information contained in the first timestamp token is older than the time information contained in the second timestamp token by a predetermined amount of time.

11. Authentication data generation device for generating data for authentication, comprising: a receiver for receiving a digitally signed navigation message; a sensor; a transmitter for transmitting a signal to another device; and a processor, wherein the processor calculates a hash value of data acquired by the sensor, digitally signs the time information based on the digitally signed navigation message and the hash value to generate a first timestamp token, transmits the hash value to a time authentication device, receives a second timestamp token generated by the time authentication device digitally signing the hash value and the time information of the time authentication device, and transmits the data, the digitally signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

12. The authentication data generation device according to claim 11, wherein the processor further receives the authentication result of the data by the data authentication device and outputs the authentication result.

13. The authentication data generation device according to claim 11, wherein the verification result by the data authentication device includes a determination result indicating whether or not the time information of the authentication data generation device is genuine, and the processor further performs processing using the time information of the authentication data generation device based on the fact that the time information of the authentication data generation device is indicated to be genuine.

14. The authentication data generating device according to claim 13, wherein the processing using the time information includes a process for calculating the position of the authentication data generating device.

15. The authentication data generation device according to claim 11, wherein the time authentication device and the data authentication device are synchronized.

16. The authentication data generation device according to claim 11, wherein the electronically signed navigation message is received from a satellite constituting the Global Navigation Satellite System.

17. A data authentication device for authenticating received data, comprising: a receiver for receiving information from a terminal; and a processor, wherein the information includes: data acquired by the terminal; a hash value calculated from the data; a first timestamp token generated by digitally signing time information based on a digitally signed navigation message received by the terminal; and a second timestamp token generated by the time authentication device digitally signing the hash value transmitted from the terminal to the time authentication device and the time information of the time authentication device, and transmitted from the time authentication device to the terminal, wherein the processor determines whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

18. The data authentication device according to claim 17, wherein the processor further determines whether the information received from the terminal is authentic based on the time information contained in the electronically signed navigation message received by the data authentication device and the time information contained in the electronically signed navigation message contained in the information received from the terminal.

19. The data authentication device according to claim 17, wherein the determination includes determining that the information received from the terminal is authentic based on the fact that the difference between the time information contained in the first timestamp token and the time information contained in the second timestamp token is less than or equal to a predetermined threshold.

20. The data authentication device according to claim 17, wherein the determination includes determining that the data acquired by the terminal is false based on the fact that the time information contained in the first timestamp token is older than the time information contained in the second timestamp token by a predetermined amount of time.

21. A data authentication system for authenticating data, comprising an authentication data generation device and a data authentication device, wherein the authentication data generation device comprises a receiver for receiving an electronically signed navigation message, a sensor, a transmitter for transmitting a signal to another device, and a processor, the processor calculates a hash value of data acquired by the sensor, electronically signs the time information based on the electronically signed navigation message and the hash value to generate a first timestamp token, transmits the hash value to the time authentication device, receives a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device, transmits the data, the electronically signed navigation message, the first timestamp token and the second timestamp token to the data authentication device, and the data authentication device determines whether the information received from the authentication data generation device is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.

22. Authentication data generation method for a computer to generate data for authentication, comprising: receiving an electronically signed navigation message; acquiring data; calculating a hash value of the data; generating a first timestamp token by electronically signing the time information based on the electronically signed navigation message and the hash value; transmitting the hash value to a time authentication device; receiving a second timestamp token generated by the time authentication device electronically signing the hash value and the time information of the time authentication device; and transmitting the data, the electronically signed navigation message, the first timestamp token, and the second timestamp token to a predetermined data authentication device.

23. A data authentication method for authenticating information received by a computer from a terminal, comprising the steps of: receiving an electronically signed navigation message; and receiving information from the terminal, wherein the information comprises: data acquired by the terminal; a hash value calculated from the data; a first timestamp token generated by electronically signing time information based on the electronically signed navigation message received by the terminal; and a second timestamp token generated by the time authentication device electronically signing the hash value transmitted from the terminal to the time authentication device and time information of the time authentication device, and transmitted from the time authentication device to the terminal, the data authentication method further comprising the step of determining whether the information received from the terminal is authentic based on the time information contained in the first timestamp token and the time information contained in the second timestamp token.