EP1515519B1

A communications apparatus, communications system, and method for setting certificates

Abstract

This record has no abstract on file.

EP1515519B1, drawing sheet 1
Sheet 1 of 20

Term

Term ended

Expired 10 September 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

3 claims: 3 independent, 0 dependent

  1. 1
    An apparatus (20) for a system which includes at least a high-level apparatus (10) and a plurality of low-level apparatuses (20), the apparatus being one of the low-level apparatuses (20), the apparatus comprising:a storage unit (22, 23, 45) storing an individual certificate set and a common certificate set, wherein the common certificate set is the same common certificate set stored in advance on the other low-level apparatuses (20), the common certificate set to be used for storing a new individual certificate set in the apparatus (20);wherein the common certificate set includes: a common root-key certificate which Is to be used by the high-level apparatus (10) to determine a type of the apparatus (20) and to authenticate the validity of the apparatus (20), the common root-key certificate being the same for the other low-level apparatuses (20) and being different from a common root-key certificate for the high-level apparatus (10);a common public-key certificate that is a digital certificate not being provided with apparatus-identifying information that is to be used by the high-level apparatus (10) to authenticate the apparatus (20) when obtaining an individual certificate set from the high-level apparatus (10), the common public-key certificate being the same for the other low-level apparatuses (20);a common private-key corresponding to the common public-key certificate that is to be used by the apparatus to perform encryption;wherein the individual certificate set includes: an individual public-key certificate that is a digital certificate being provided with apparatus-identifying information;an individual private-key corresponding to the individual public-key certificate which is to be used by the apparatus (20) to perform encryption;an individual root-key certificate that is to be used to authenticate the validity of the high-level apparatus (10), the individual root-key certificate being the same for the other low-level apparatuses (20) and the same as an individual root-key certificate of the high-level apparatus (10);a communication unit (41, 42) transmitting the individual public-key certificate to the high-level apparatus (10) to allow the high-level apparatus (10) to perform decryption to authenticate the validity of the apparatus (20).
  2. 2
    A system which includes at least a high-level apparatus (10) and a plurality of low-level apparatuses (20), at least one of the low-level apparatuses (20) comprising:a storage unit (22, 23, 45) storing an individual certificate set and a common certificate set, wherein the common certificate set Is the same common certificate set stored in advance on the other low-level apparatuses (20), the common certificate set being used for storing a new individual certificate set in the apparatus (20);wherein the common certificate set includes: a common root-key certificate which is to be used by the high-level apparatus (10) to determine a type of the apparatus (20) and to authenticate the validity of the apparatus (20), the common root-key certificate being the same for the other low-level apparatuses (20) and being different from a common root-key certificate for the high-level apparatus (10);a common public-key certificate that is a digital certificate not being provided with apparatus-identifying information and that is to be used by the high-level apparatus (10) to authenticate the low-level apparatus (20) when obtaining an individual certificate set from the high-level apparatus (10), the common public-key certificate being the same for the other low-level apparatuses (20);a common private-key corresponding to the common public-key certificate that is to be used by the apparatus to perform encryption;wherein the individual certificate set includes: an individual public-key that is a digital certificate being provided with apparatus-identifying information;an individual private-key corresponding to the individual public-key certificate which is to be used by the apparatus (20) to perform encryption;an individual root-key certificate that is to be used to authenticate the validity of the high-level apparatus (10), the individual root-key certificate being the same for the other low-level apparatuses (20) and the same as an individual root-key certificate of the high-level apparatus (10);a communication unit (41, 42) transmitting the individual public-key certificate to the high-level apparatus (10) to allow the high-level apparatus (10) to perform decryption to authenticate the validity of the apparatus (20).
  3. 3
    A method of communicating implemented on an apparatus (20) for a system which includes at least a high-level apparatus (10) and a plurality of low-level apparatuses (20), the apparatus being one of the low-level apparatuses, the method comprising:storing, at the apparatus (20), an individual certificate set and a common certificate set, wherein the common certificate set is the same common certificate set stored in advance on the other low-level apparatuses (20);wherein the common certificate set includes a common root-key certificate, a common public-key certificate, and a common private-key;wherein the individual certificate set includes an individual public-key certificate, an individual private-key, and an individual root-key certificate;determining, at the high-level apparatus (10), a type of the apparatus (20) and authenticating the validity of the apparatus by using the common root-key certificate of the apparatus (20), the common root-key certificate being the same for the other low-level apparatuses (20) and being different from a common root-key certificate for the high-level apparatus (10);authenticating, at the high-level apparatus (10), the apparatus when obtaining a new individual certificate set from the high-level apparatus (10) by using the common public-key certificate that is a digital certificate not being provided with apparatus-identifying information, the common public-key certificate being the same for the other low-level apparatuses (20);performing encryption, at the apparatus (20), by using the common private key corresponding to the common public-key certificate;transmitting, at the apparatus (20), the individual public-key certificate to the high-level apparatus (10) to perform decryption to authenticate the validity of the apparatus (20) at the high-level apparatus (10), the individual public-key certificate that is a digital certificate being provided with apparatus-identifying information;performing encryption, at the apparatus (20), by using the individual private-key corresponding to the individual public-key certificate;authenticating, at the apparatus (20), the validity of the high-level apparatus (10) by using the individual root-key certificate, the individual root-key certificate being the same for the other low-level apparatus (20) and the same as an individual root-key certificate of the high-level apparatus (10).