Communication system and communication method
Abstract
[Task] High security communication is possible with a simple configuration.
Solution.Share the ID of the client terminal 11 and PWD offline (S11, S12). Generate a random number value R on the client terminal 11, calculate Kreg: = h (PWD), encrypt R with Kreg to obtain eKreg (R), and give the access point 21 an ID, h (ID | PWD). , Send eKreg (R) (S13, S14). The access point 21 finds the PWD corresponding to the received ID (S15), finds h (ID | PWD) (S16), calculates Kreg if it matches the received value (S17), and eKreg with Kreg. (R) is decoded to extract R (S18), and the hash value of R is transmitted to the client terminal 11 (S19). When the hash value of R matches the received value, the client terminal 11 notifies the access point 21 that the authentication is OK. After that, KCL: = h (PWD | R) is used as the encryption key.

Term
Term ended
Projected expiry passed 5 November 2021, 4.9 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
11 claims: 4 independent, 7 dependent
- 1[Claims] 1. Between a first device (11) and a second device (21) that communicate with each other. The identifier ID of the first device and the confidential information PWD are shared by the first and second devices, and the secret information PWD is shared. In the first device, a predetermined value R is generated, the one-way function value Kreg:= h (PWD) of the secret information PWD is obtained, and the obtained one-way function value Kreg of the secret information is used as an encryption key for authentication. Then, the predetermined value R is encrypted to calculate the encrypted data eKreg (R), and the identifier ID and the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD are connected to the second device. And the encrypted predetermined value eKreg (R), The second device searches for the secret information PWD corresponding to the received identifier ID, calculates the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD, and receives this. It is compared with the direction function value h (ID | PWD), and if it matches, the authentication encryption key Kreg: = h (PWD) is calculated, and a predetermined value encrypted using this authentication encryption key Kreg. eKreg (R) is decoded, a predetermined value R is extracted, and the value h (R) converted by a one-way function is transmitted to the first device. The first device obtains the one-way function value h (R) of the predetermined value R, compares this with the received one-way function value H (R) of the predetermined value R, and if they match, Notify the second device that the authentication has been established, and The first device obtains the one-way function value KCL: = h (PWD | R) of the concatenation of the secret information PWD and the predetermined value R as the common key KCL for encryption. The second device calculates the common key KCL: = h (PWD | R) and The first device and the second device communicate with each other using the common key KCL as an encryption key. A communication method characterized by that. 【特許請求の範囲】 【請求項1】相互に通信を行う第1の装置(11)と第2の装置(21)との間で、 前記第1の装置の識別子IDと秘密情報PWDとを前記第1と第2の装置で共有し、 前記第1の装置において、所定値Rを生成し、秘密情報PWDの一方向関数値Kreg:=h(PWD)を求め、求めた秘密情報の一方向関数値Kregを認証用の暗号鍵として用いて、所定値Rを暗号化して暗号データeKreg(R)を計算し、前記第2の装置に、識別子IDと、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)と、暗号化された所定値eKreg(R)とを送信し、 前記第2の装置は、受信した識別子IDに対応する秘密情報PWDを検索し、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)を計算し、これと受信した一方向関数値h(ID|PWD)と比較し、一致した場合に、認証用の暗号鍵Kreg:=h(PWD)を計算し、この認証用の暗号鍵Kregを用いて暗号化された所定値eKreg(R)を復号して、所定値Rを抽出し、これを一方向性関数で変換した値h(R)を前記第1の装置に送信し、 前記第1の装置は、所定値Rの一方向性関数値h(R)を求め、これと受信した所定値Rの一方向性関数値h(R)とを比較し、一致する場合に、認証が成立したことを前記第2の装置に通知し、 前記第1の装置は、秘密情報PWDと所定値Rの連結の一方向関数値KCL:=h(PWD|R)を暗号用の共通鍵KCLとして求め、 前記第2の装置は、共通鍵KCL:=h(PWD|R)を計算し、 前記第1の装置と前記第2の装置とは、共通鍵KCLを暗号鍵として用いて相互に通信を行う、 ことを特徴とする通信方法。
- 6A communication system for communicating between a first device (11) and a second device (21). The identifier ID of the first device and the confidential information PWD are shared by the first and second devices, and the secret information PWD is shared. The first device generates a predetermined value R, calculates the one-way function value Kreg:= h (PWD) of the secret information PWD, and uses the calculated one-way function value Kreg of the secret information as an authentication encryption key. Using, the predetermined value R is encrypted to calculate the encrypted data eKreg (R), and the identifier ID and the one-way function value h (ID | PWD) of concatenating the identifier ID and the secret information PWD are connected to the second device. ) And the encrypted predetermined value eKreg (R), The second device searches for the secret information PWD corresponding to the received identifier ID, calculates the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD, and receives this. The directional function value h (ID | PWD) is compared, and if they match, the authentication encryption key Kreg: = h (PWD) is calculated, and the predetermined value encrypted using this authentication encryption key Kreg. The value eKreg (R) is decoded, the predetermined value R is extracted, and the value h (R) converted by the one-way function is transmitted to the first device. The first device obtains the one-way function value h (R) of the predetermined value R, compares this with the received one-way function value H (R) of the predetermined value R, and if they match, Notify the second device that the authentication has been established, and The first device obtains and stores the one-way function value KCL: = h (PWD | R) of the concatenation of the secret information PWD and the predetermined value R as the common key KCL for encryption, and stores it. The second device calculates and stores the common key KCL: = h (PWD | R) and stores it. The first device and the second device communicate with each other using the common key KCL as an encryption key. A communication system characterized by that. 【請求項6】第1の装置(11)と第2の装置(21)との間で通信を行う通信システムであって、 前記第1の装置の識別子IDと秘密情報PWDとを前記第1と第2の装置で共有し、 前記第1の装置は、所定値Rを生成し、秘密情報PWDの一方向関数値Kreg:=h(PWD)を計算し、計算した秘密情報の一方向関数値Kregを認証用の暗号鍵として用いて、所定値Rを暗号化して暗号データeKreg(R)を計算し、前記第2の装置に、識別子IDと、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)と、暗号化された所定値eKreg(R)とを送信し、 前記第2の装置は、受信した識別子IDに対応する秘密情報PWDを検索し、識別子IDと秘密情報PWDとの連結の一方向関数値h(ID|PWD)を計算し、これと受信した一方向関数値h(ID|PWD)とを比較し、一致した場合に、認証用の暗号鍵Kreg:=h(PWD)を計算し、この認証用の暗号鍵Kregを用いて暗号化された所定値eKreg(R)を復号して、所定値Rを抽出し、これを一方向性関数で変換した値h(R)を前記第1の装置に送信し、 前記第1の装置は、所定値Rの一方向性関数値h(R)を求め、これと受信した所定値Rの一方向性関数値h(R)とを比較し、一致する場合に、認証が成立したことを前記第2の装置に通知し、 前記第1の装置は、秘密情報PWDと所定値Rの連結の一方向関数値KCL:=h(PWD|R)を暗号用の共通鍵KCLとして求めて保存し、 前記第2の装置は、共通鍵KCL:=h(PWD|R)を計算して保存し、 前記第1の装置と前記第2の装置とは、共通鍵KCLを暗号鍵として用いて相互に通信を行う、 ことを特徴とする通信システム。
- 7Between a first device (11) and a second device (21) that communicate with each other. The private key KCL of the first device is generated, and the address of the first device and the pair of this private key KCL are notified offline to the second device and registered. The second device generates its own private key KAP when idle and The second device receives the connection request from the first device, searches the private key KCL of the first device from the address of the first device of the request source, and generates the session key K. , The concatenation of the predetermined value R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device to generate encrypted data eKCL (R | K | KAP), and the first Send to the device and The first device decrypts the encrypted data eKCL (R | K | KAP) addressed to itself with its own private key KCL, and uses the predetermined value R, the session key K, and the secret key KAP of the second device. Is extracted, and the extracted predetermined value R is encrypted with the private key KAP of the second device to generate encrypted data eKAP (R), and the generated encrypted data eKAP (R) is used in the second device. Send and The second device receives the encrypted data eKAP (R), decrypts it with the private key KAP of the second device, extracts a predetermined value R, and extracts the extracted predetermined value R and the first first device. It is compared with the predetermined value R transmitted to the device, and if they match, it is determined that the authentication has been established, and it is determined. The first device and the second device store the secret key KCL of the first device and the secret key KAP of the second device, respectively. Hereinafter, the first device and the second device execute encrypted communication using the secret key KCL of the first device and the secret key KAP of the second device. A communication method characterized by that. 【請求項7】相互に通信を行う第1の装置(11)と第2の装置(21)との間で、 前記第1の装置の秘密鍵KCLを生成し、前記第1の装置のアドレスとこの秘密鍵KCLのペアを、前記第2の装置にオフラインで通知して登録し、 前記第2の装置は、アイドル時に、自己の秘密鍵KAPを生成し、 前記第2の装置は、前記第1の装置からの接続要求を受信し、要求元の前記第1の装置のアドレスから前記第1の装置の秘密鍵KCLを検索し、セッション鍵Kを生成し、所定値Rとセッション鍵Kと自己の秘密鍵KAPとの連結を前記第1の装置の秘密鍵KCLにて暗号化して暗号データeKCL(R|K|KAP)を生成して、前記第1の装置に送信し、 前記第1の装置は、自己宛の暗号データeKCL(R|K|KAP)を自己の秘密鍵KCLにて復号して、所定値Rとセッション鍵Kと前記第2の装置の秘密鍵KAPとを抽出し、さらに、抽出した所定値Rを前記第2の装置の秘密鍵KAPで暗号化して暗号データeKAP(R)を生成し、生成した暗号データeKAP(R)を前記第2の装置に送信し、 前記第2の装置は、暗号データeKAP(R)を受信し、これを前記第2の装置の秘密鍵KAPにて復号して所定値Rを抽出し、抽出した所定値Rと前記第1の装置に送信した所定値Rとを比較し、一致していれば、認証成立と判別し、 前記第1の装置と前記第2の装置は、それぞれ、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを保存し、 以後、前記第1の装置と前記第2の装置は、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを用いて、暗号通信を実行する、 ことを特徴とする通信方法。
- 10A communication system that communicates between a first device (11) and a second device (21). The private key KCL of the first device is generated, the address of the first device and the pair of this private key KCL are notified offline to the second device, and this is registered in the storage unit. The second device generates and stores its own private key KAP when idle. The second device receives the connection request from the first device, searches the private key KCL of the first device from the address of the first device of the request source, and generates the session key K. , The concatenation of the predetermined value R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device to generate encrypted data eKCL (R | K | KAP), and the first Send to the device and The first device decrypts the encrypted data eKCL (R | K | KAP) addressed to itself with its own private key KCL, and uses the predetermined value R, the session key K, and the secret key KAP of the second device. Is extracted, and the extracted predetermined value R is encrypted with the private key KAP of the second device to generate encrypted data eKAP (R), and the generated encrypted data eKAP (R) is used in the second device. Send and The second device receives the encrypted data eKAP (R), decrypts it with the private key KAP, extracts a predetermined value R, and transmits the extracted predetermined value R to the first device. Compare with the predetermined value R, and if they match, it is determined that the authentication has been established, and The first device and the second device store the secret key KCL of the first device and the secret key KAP of the second device, respectively. Hereinafter, the first device and the second device are characterized in that encrypted communication is executed by using the secret key KCL of the first device and the secret key KAP of the second device. Communications system. 【請求項10】第1の装置(11)と第2の装置(21)との間で通信を行う通信システムであって、 前記第1の装置の秘密鍵KCLを生成し、前記第1の装置のアドレスとこの秘密鍵KCLのペアを、前記第2の装置にオフラインで通知し、これを記憶部に登録し、 前記第2の装置は、アイドル時に、自己の秘密鍵KAPを生成し格納し、 前記第2の装置は、前記第1の装置からの接続要求を受信し、要求元の前記第1の装置のアドレスから前記第1の装置の秘密鍵KCLを検索し、セッション鍵Kを生成し、所定値Rとセッション鍵Kと自己の秘密鍵KAPとの連結を前記第1の装置の秘密鍵KCLにて暗号化して暗号データeKCL(R|K|KAP)を生成して、前記第1の装置に送信し、 前記第1の装置は、自己宛の暗号データeKCL(R|K|KAP)を自己の秘密鍵KCLにて復号して、所定値Rとセッション鍵Kと前記第2の装置の秘密鍵KAPとを抽出し、さらに、抽出した所定値Rを前記第2の装置の秘密鍵KAPで暗号化して暗号データeKAP(R)を生成し、生成した暗号データeKAP(R)を前記第2の装置に送信し、 前記第2の装置は、暗号データeKAP(R)を受信し、これを秘密鍵KAPにて復号して所定値Rを抽出し、抽出した所定値Rと前記第1の装置に送信した送った所定値Rと比較し、一致していれば、認証成立と判別し、 前記第1の装置と前記第2の装置は、それぞれ、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを保存し、 以後、前記第1の装置と前記第2の装置は、前記第1の装置の秘密鍵KCLと前記第2の装置の秘密鍵KAPとを用いて、暗号通信を実行する、ことを特徴とする通信システム。
Independent claims4
190 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to cryptographic communication systems and methods.
【0002】
[Conventional technology]
As an inexpensive and easy wireless LAN construction device, a wireless LAN compliant with IEEE802.11b has become widespread.
【0003】
[Problems to be Solved by the Invention]
However, IEEE802.11b points out "security" issues. That is, the security protocol WEP (Wired Equivalent Privacy) of IEEE802.11b is vulnerable, and there is a risk that the security of communication will not be maintained. Similar problems also apply to wired communication, and simpler and more reliable cryptographic communication systems, cryptographic communication protocols, and the like are desired.
【0004】
The present invention has been made in view of the above circumstances, and an object of the present invention is to provide a system and a method capable of performing highly reliable communication. Another object of the present invention is to enable highly secure communication with a simple configuration.
【0005】
[Means for solving problems]
In order to achieve the above object, the communication method according to the first aspect of the present invention is the above-mentioned first device between the first device (11) and the second device (21) that communicate with each other. The device identifier ID and the secret information PWD are shared by the first and second devices, the predetermined value R is generated in the first device, and the one-way function value of the secret information PWD is Kreg: = h (PWD). ) Is obtained, the one-way function value Kreg of the obtained secret information is used as the encryption key for authentication, the predetermined value R is encrypted, the encrypted data eKreg (R) is calculated, and the identifier ID is sent to the second device. , A one-way function value h (ID | PWD) for concatenating the identifier ID and the secret information PWD, and an encrypted predetermined value eKreg (R) are transmitted, and the second device receives the received identifier ID. Search for the secret information PWD corresponding to, calculate the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD, and compare this with the received one-way function value h (ID | PWD). If they match, the authentication encryption key Kreg: = h (PWD) is calculated, and the predetermined value eKreg (R) encrypted using this authentication encryption key Kreg is decrypted to obtain the predetermined value. R is extracted, and the value h (R) obtained by converting this with a one-way function is transmitted to the first device, and the first device transmits the one-way function value h (R) of a predetermined value R. The calculated value is compared with the received one-way function value h (R) of the predetermined value R, and if they match, the second device is notified that the authentication has been established. , The one-way function value KCL: = h (PWD | R) that concatenates the secret information PWD and the predetermined value R is obtained as the common key KCL for encryption, and the second device is the common key KCL: = h (PWD | R). R) is calculated, and the first device and the second device communicate with each other using the common key KCL as an encryption key.
【0006】
For example, the second device stores the address of the first device and the common key KCL in association with each other, and determines the address of the first device when communicating with the first device. The common key KCL corresponding to the determined address is read, and the read common key KCL is used to decrypt the received data from the first device, encrypt the data transmitted to the first device, and perform the first device. The device reads its own common key KCL at the time of communication with the second device, decodes the received data from the second device using the read common key KCL, and transfers the data to the second device. Encrypt the transmitted data of.
【0007】
The first device calculates the one-way function value Ksave: = h (PIN) of the user's identification information PIN to obtain the storage encryption key Ksave, and encrypts the common key KCL with this storage encryption key Ksave. , The encrypted common key eKsave (KCL) is stored, the second device stores the address of the first device in association with the common key, and discards the identifier ID and the secret information PWD. You may do so.
【0008】
The second device generates the identifier ID and the secret information PWD of the first device, stores them in the storage unit together with the generation date and time T, and transfers the identifier ID and the secret from the second device to the first device. The information PWD may be passed offline and registered in the first device.
【0009】
In this case, if the second device cannot detect the identifier received from the first device in the storage unit, the authentication is not established and the difference between the current date and time and the generation date and time T is greater than or equal to the set value. If there is, the authentication is not established, and in the second device, the one-way function value h (ID | PWD) of the concatenation of the identifier ID and the secret information PWD is calculated, and if it does not match the received one, the authentication is not established. The second device searches for the secret information PWD corresponding to the received identifier ID, calculates the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD, and receives this. Compared with the directional function value h (ID | PWD), if they do not match, authentication may be rejected. Further, the first device obtains the unidirectional function value h (R) of the predetermined value R, compares this with the received unidirectional function value h (R) of the predetermined value R, and does not match. May transmit the unsuccessful authentication to the second device.
【0010】
In order to achieve the above object, the communication system according to the second aspect of the present invention is a communication system that communicates between the first device (11) and the second device (21). The identifier ID of the first device and the secret information PWD are shared by the first and second devices, and the first device generates a predetermined value R, and the one-way function value Kreg: = of the secret information PWD. The h (PWD) is calculated, the calculated one-way function value Kreg of the secret information is used as the encryption key for authentication, the predetermined value R is encrypted, the encrypted data eKreg (R) is calculated, and the second device is described above. The one-way function value h (ID | PWD) of concatenation of the identifier ID, the identifier ID and the secret information PWD, and the encrypted predetermined value eKreg (R) are transmitted to the second device. The secret information PWD corresponding to the received identifier ID is searched, the one-way function value h (ID | PWD) of the connection between the identifier ID and the secret information PWD is calculated, and this and the received one-way function value h (ID | Compare with PWD), and if they match, calculate the encryption key Kreg: = h (PWD) for authentication, and decrypt the predetermined value eKreg (R) encrypted using this encryption key Kreg for authentication. Then, a predetermined value R is extracted, and the value h (R) obtained by converting this with a one-way function is transmitted to the first device, and the first device sends the value h (R) obtained by converting the predetermined value R to the one-way function value of the predetermined value R. h (R) is obtained, this is compared with the received one-way function value h (R) of the predetermined value R, and if they match, the second device is notified that the authentication has been established, and the above The first device obtains the one-way function value KCL: = h (PWD | R) of the concatenation of the secret information PWD and the predetermined value R as the common key KCL for encryption, and the second device is the common key KCL :. = H (PWD | R) is calculated, and the first device and the second device communicate with each other using the common key KCL as an encryption key.
【0011】
In order to achieve the above object, the communication method according to the third aspect of the present invention is the above-mentioned first device between the first device (11) and the second device (21) that communicate with each other. The private key KCL of the device is generated, the address of the first device and the pair of the private key KCL are notified offline to the second device and registered, and the second device is self-registered when idle. The private key KAP is generated, the second device receives the connection request from the first device, and searches the private key KCL of the first device from the address of the first device that is the request source. Then, a session key K is generated, and the connection between the predetermined value R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device, and the encrypted data eKCL (R | K | KAP). Is generated and transmitted to the first device, and the first device decrypts the encryption data eKCL (R | K | KAP) addressed to itself with its own private key KCL, and sets it to a predetermined value R. The session key K and the private key KAP of the second device are extracted, and the extracted predetermined value R is encrypted with the private key KAP of the second device to generate encrypted data eKAP (R). The encrypted data eKAP (R) is transmitted to the second device, and the second device receives the encrypted data eKAP (R) and decrypts it with the private key KAP of the second device. The predetermined value R is extracted, the extracted predetermined value R is compared with the predetermined value R transmitted to the first device, and if they match, it is determined that the authentication is established, and the first device and the second device are used. Each of the devices stores the private key KCL of the first device and the private key KAP of the second device, and thereafter, the first device and the second device are the first device. It is characterized in that encrypted communication is executed by using the private key KCL of the above and the private key KAP of the second device.
【0012】
For example, when the second device stores the address of the first device and the common key KCL in association with each other and communicates between the second device and each of the first devices. The second device determines the address of the first device, reads the common key KCL corresponding to the determined address, and uses the read common key KCL to receive data from the first device. Is decrypted, the data transmitted to the first device is encrypted, and the first device reads its own common key KCL when communicating with the second device, and uses the read common key KCL. , When the data received from the second device is decrypted, the data transmitted to the second device is encrypted, and the data common to the plurality of first devices is transmitted from the second device. The second device reads its own private key KAP, and the read private key KAP is used to encrypt data transmitted to a plurality of the first devices, and the first device is the second device. The private key KAP of the device is read, and the read data received from the second device is decrypted using the read private key KAP.
【0013】
For example, when the destination address of the data to be transmitted is a broadcast address, the second device encrypts the data with the private key KAP of the second device and sends the data, and each of the first devices receives the data. The data is decrypted with the private key KAP of the second device, and when the destination address is stored in the storage unit, the data to be transmitted is encrypted with the private key KCL corresponding to the destination address and transmitted. The first device decodes the data addressed to itself with its own private key KCL, and discards the data to be transmitted when the destination address is not stored in the storage unit.
【0014】
In order to achieve the above object, the communication system according to the fourth aspect of the present invention is a communication system that communicates between the first device (11) and the second device (21). The private key KCL of the first device is generated, the address of the first device and the pair of this private key KCL are notified offline to the second device, registered in the storage unit, and the second device is registered. Device generates and stores its own private key KAP when idle, and the second device receives a connection request from the first device and receives the connection request from the first device and receives the connection request from the request source address of the first device. The private key KCL of the first device is searched, a session key K is generated, and the connection between the predetermined value R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device. The encrypted data eKCL (R | K | KAP) is generated and transmitted to the first device, and the first device sends the encrypted data eKCL (R | K | KAP) addressed to itself to its own private key KCL. Decrypts with, extracts the predetermined value R, the session key K, and the private key KAP of the second device, and further encrypts the extracted predetermined value R with the private key KAP of the second device for encryption. The data eKAP (R) is generated, the generated encrypted data eKAP (R) is transmitted to the second device, and the second device receives the encrypted data eKAP (R) and sends it to the private key KAP. Decrypts and extracts the predetermined value R, compares the extracted predetermined value R with the predetermined value R sent to the first device, and if they match, it is determined that the authentication is successful, and the first The device and the second device store the private key KCL of the first device and the private key KAP of the second device, respectively. It is characterized in that encrypted communication is executed by using the private key KCL of the first device and the private key KAP of the second device.
【0015】
The computer may be operated as the first device or the second device, or a program for causing the computer to execute the operation of the first device or the second device may be created and distributed.
【0016】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, the communication system and the communication method according to the embodiment of the present invention will be described with reference to the drawings.
【0017】
As shown in FIG. 1, the communication system according to this embodiment is an access point (server) that constitutes a wireless LAN 41 between a plurality of client terminals (user terminals) 11 (111 to 11n) and the client terminals 11. It is composed of 21 and a gateway server 31 connected to an access point 21 via a wired LAN 42 or the like and connected to an external network.
【0018】
Each client terminal 11 is composed of a personal computer, a workstation, or the like, and as shown in FIG. 2, includes a storage unit 111, an input unit 112, a display unit 113, and a processing unit 114, and is equipped with a wireless LAN card 12. Has been done.
【0019】
The storage unit 111 is composed of RAM, ROM, a hard disk, and the like, and stores various data and programs. In this embodiment, data such as the identifier ID of the own terminal, password PWD, random value R, private key KCL, registration key Kreg, storage key Ksave, authentication program, encryption program, application program, communication program, etc. Memorize the operation program of.
【0020】
The input unit 112 includes a keyboard, a mouse, a recording medium input / output device, and the like, and supplies various data and instructions to the processing unit 114. The display unit 113 displays various information.
【0021】
The processing unit 114 includes a processor and the like, and operates according to an operation program stored in the storage unit 111. In this embodiment, the authentication process and the encrypted communication process are executed. Further, the processing unit 114 includes a timer.
【0022】
The wireless LAN card 12 is configured as a so-called PC card, is attached to the client terminal 11, converts the transmission data supplied from the processing unit 114 into a wireless signal and transmits it to the access point 21, and the wireless LAN card 12 transmits. The signal is received, decoded, and provided to the processing unit 114. A unique MAC (Machine Access Control) address for identifying the card is stored in the wireless LAN card 12.
【0023】
The access point 21 is for configuring a wireless LAN 41 with a plurality of client terminals 11 and transmitting data between the wireless LAN 41 and the wired LAN 42, and as shown in FIG. 3, a wireless IF ( It includes an interface) 211, a wired IF (interface) 212, a storage unit 213, a database 214, an input unit 215, a display unit 216, and a processing unit 217.
【0024】
The wireless IF211 receives the wireless signal from the client terminal 11, demodulates it, provides it to the processing unit 217, and converts the transmission data provided from the processing unit 217 into a wireless signal for wireless transmission.
【0025】
The wired IF 212 provides the signal on the wired LAN 42 to the processing unit 217, and sends the signal provided from the processing unit 217 onto the wired LAN 42.
【0026】
The storage unit 213 is composed of RAM, ROM, a hard disk, and the like, and stores various data and programs. In this embodiment, data such as a random number value R, a private key KCL, a registration key Kreg, and a storage key Ksave, and an operation program such as an authentication program, an encryption program, an application program, and a communication program are stored.
【0027】
Database (DB) 214 includes a registration information DB and a client key DB, as shown in FIG. The registration information DB stores the identifier ID of each client terminal 11, the password (preset secret information) PWD, and the generation date and time T of the identifier ID and the password PWD in association with each other. The client key DB stores the MAC address of the wireless LAN card 12 mounted on the client terminal 11 and the client key (secret encryption key; common key) KCL in association with each other.
【0028】
The input unit 215 of FIG. 3 includes a keyboard, a mouse, a recording medium input / output device, and the like, and supplies various data and instructions to the processing unit 217. The display unit 216 displays various information.
【0029】
The processing unit 217 includes a processor and the like, and operates according to an operation program stored in the storage unit. In particular, in this embodiment, wireless encrypted communication processing including authentication processing of the client terminal 11 and data bridging processing between the wireless LAN 41 and the wired LAN 42 are executed. The details of the processing will be described later.
【0030】
The gateway server 31 in FIG. 1 is connected to a wired LAN 42 and is connected to an external network such as an Internet-in IN.
【0031】
Next, the operation of the communication system having the above configuration will be described. In this communication system, in order to receive data via the wireless LAN 41 constructed between the client terminal 11 and the access point 21, it is necessary to take the procedures of pre-registration and mutual authentication as shown in FIG. is there.
【0032】
(1) Pre-registration of client terminal 11 to access point 21 When a new client terminal 11 is connected to the wireless LAN 41, the system administrator generates an ID and password PWD in advance at the access point 21 (step S11), and displays the generation date and time T in the registration information DB as shown in Fig. 4 (step S11). Register as shown in a).
【0033】
The generated identifier ID and password PWD are notified offline to the client terminal 11, input from, for example, the input unit 213, and registered in the storage unit 111 (step S12). As a result, the identifier ID and password PWD of the new client terminal 11 are shared between the client terminal 11 and the access point 21.
【0034】
(2) Mutual authentication and exchange of encryption key between client terminal 11 and access point 21 a) The client terminal 11 requests the access point 21 to connect when it wants to communicate via the wireless LAN 41. In response to this request, the access point 21 temporarily establishes a wireless communication connection with the client terminal 11 by open authentication.
【0035】
b) Next, the processing unit 114 of the client terminal 11 executes a random number program to generate a random number value R (a random number is desirable, but an arbitrary constant may be used). Further, the processing unit 114 calculates the hash value of the connection between the password PWD and the random number value R defined by the equation 1 and the hash value of the password PWD by the predetermined hash function h (), and the client terminal 11 The client key KCL and the registration key Kreg are stored in the storage unit 111 (step S13). The client key KCL is a private key common to the client 11 and the access point 21, and the registration key Kreg is a common key used only for the authentication process.
[Number 1]
KCL: = h (PWD | R) Kreg: = h (PWD) A communication system that communicates between the first device (11) and the second device (21) by generating the private key KCL of the first device, and using the address of the first device and this. The private key KCL pair is notified offline to the second device and registered in the storage unit, and the second device generates and stores its own private key KAP when idle, and the second device generates and stores the private key KAP. The device receives the connection request from the first device, searches the private key KCL of the first device from the address of the first device that is the request source, generates the session key K, and generates a predetermined value. The concatenation of R, the session key K, and its own private key KAP is encrypted with the private key KCL of the first device to generate encrypted data eKCL (R | K | KAP), and the first device is used. The first device transmits and decrypts the encrypted data eKCL (R | K | KAP) addressed to itself with its own private key KCL, and the predetermined value R, the session key K, and the secret of the second device are transmitted. The key KAP is extracted, and the extracted predetermined value R is encrypted with the private key KAP of the second device to generate the encrypted data eKAP (R), and the generated encrypted data eKAP (R) is used as the second device. The second device receives the encrypted data eKAP (R), decrypts it with the private key KAP, extracts a predetermined value R, and extracts the extracted predetermined value R and the first first device. It is compared with the random number value R sent to the device, and if they match, it is determined that the authentication has been established, and the first device and the second device have the private key KCL of the first device, respectively. The secret key KAP of the second device is stored, and thereafter, the first device and the second device store the secret key KCL of the first device and the secret key KAP of the second device. Use to perform encrypted communication, [0036]
c) Next, the hash value h (ID | PWD) of the concatenation of the identifier ID and the password PWD and the encrypted data eKreg (R) by the registration key Kreg of the random number value R are generated and stored in the storage unit 111. Temporarily store. The hash value h (ID | PWD) of the concatenation of the identifier ID and the password PWD may be calculated by either the access point 21 or the client terminal 11 by the transmission stage.
【0037】
d) Subsequently, the client terminal 11 transmits its own identifier ID, the hash value h (ID | PWD), and the encrypted data eKreg (R) to the access point 21 (step S14).
【0038】
e) The processing unit 217 of the access point 21 receives these data via the wireless IF211 and temporarily stores them in the storage unit 213. Then, the registration information DB is searched using the received identifier ID as a key.
【0039】
f) In this search process, if the received identifier ID is not registered in the registration information DB, it is determined that it is an unauthorized access, an unauthorized access error is returned, and then the connection with the client terminal 11 is established. Disconnect (step S15). On the other hand, when the identifier ID is registered in the registration information DB, the corresponding password PWD and the generation date / time T are read out.
【0040】
g) Next, find the difference between the read generation date and time T and the current date and time, and determine whether or not it is greater than or equal to the reference value. g-1) If the difference between the generation date and time T and the current date and time exceeds the reference value, that is, if a long period of time has passed since registration, the registration timeout is returned to the client terminal 11 via wireless IF211. To do. The processing unit 114 of the client terminal 11 receives this via the wireless LAN card 12, and causes the display unit 113 to display a message to the effect that it should be re-registered.
【0041】
g-2) On the other hand, if the difference between the generation date and time T and the current date and time is less than the reference value, that is, if it does not correspond to the registration timeout, the processing unit 217 verifies the hash value h (ID | PWD) ( Step S16). That is, the processing unit 217 calculates the hash value h (ID | PWD) of the connection between the received identifier ID and the password PWD read from the registration information DB, and the hash value h (ID | PWD) received from the client terminal 11. Determine if it matches. If it is determined that they do not match, the processing unit 217 returns a challenge failure to the client terminal 11 and disconnects the connection.
【0042】
h) On the other hand, when it is determined that the calculated hash value h (ID | PWD) and the received hash value h (ID | PWD) match, the processing unit 217 determines that the registration key Kreg (: = h (PWD)). )) Is calculated (step S17).
【0043】
Next, the processing unit 217 decrypts the encrypted data eKreg (R) of the received random number value R using the generated registration key Kreg, and extracts the random number value R previously generated by the client terminal 11. (Step S18).
【0044】
i) The processing unit 217 calculates the hash value h (R) of the extracted random number value R, and transmits this to the client terminal 11 (step S19).
【0045】
j) Next, the processing unit 114 of the client terminal 11 verifies the hash value h (R) of the random number value R (step S20). That is, the processing unit 114 calculates the hash value h (R) of the random number value R stored in the storage unit 111, and compares this with the hash value h (R) received from the access point 21. If the two hash values do not match, the processing unit 114 returns "authentication failure (NG)" to the access point 21 and disconnects the connection. On the other hand, if it is determined that they match, "authentication success (OK)" is returned to the access point 21.
【0046】
k) In response to the notification of successful authentication, the processing unit 217 of the access point 21 calculates the client key KCL: = h (PWD | R) (step S21), and the MAC included in the header information of the wireless communication. Register {MAC address, KCL} in the client key DB of database 214 using the address. Then, the identifier ID and password PWD on the storage unit 213 are destroyed.
【0047】
l) After transmitting the authentication success, the processing unit 114 of the client terminal 11 inputs the user's PIN (personal identification information) recorded on, for example, an authentication IC card or the like from the input unit 112. The processing unit 114 calculates the hash value of the input PIN: = h (PIN) and uses it as the storage key Ksave. The processing unit 114 encrypts the client key KCL using this storage key Ksave, and stores the encrypted client key eKsave (KCL) in the storage unit 111.
【0048】
With the above relatively simple procedure, mutual authentication and exchange of encryption key between the client terminal 11 and the access point 21 are safely completed, and a wireless encryption channel is established.
【0049】
For example, when transmitting a packet received from the access point 21 to the client terminal 11 from the wired LAN side via the wired IF 212 to the wireless LAN side, the following processing is performed.
【0050】
First, the MAC address of the destination of the received packet is determined, and whether or not this MAC address is registered in the client key database is determined. When it is determined that the packet is registered, if the MAC address exists in the table, the client key KCL corresponding to the MAC address is read, and the part (payload) excluding the packet header of the packet is encrypted with the client key KCL. And send from wireless IF211.
【0051】
The processing unit 114 of each client terminal 11 captures wireless information via the wireless communication device 12. The processing unit 114 obtains the hash value h (PIN) of the user's PIN, and the storage key K<sub>save save</sub>Ask for this storage key K<sub>save save</sub>Is used to decrypt the encrypted client key eKsave (KCL) stored in the storage unit 111. The processing unit 114 decodes the payload portion of the packet addressed to itself by using the decrypted client key KCL, and stores it in the storage unit 111.
【0052】
On the other hand, if the MAC address included in the header is different from its own MAC address, the wireless communication device 12 discards it. As a result, the packet is addressed to itself, and only the packet encrypted with its own client key KCL is received.
【0053】
On the other hand, when the access point 21 determines that the MAC address of the transmission target packet does not exist in the client key DB, the access point 21 discards the packet.
【0054】
When sending a packet from the client terminal 11 to the access point 21, the processing unit 114 generates a storage key Ksave from the user's PIN, decrypts the client key KCL with this storage key Ksave, and then decrypts the packet. The information storage part (payload) of is encrypted with the decrypted client key KCL and sent from the wireless LAN card 12.
【0055】
The processing unit 217 of the access point 21 once captures the wireless signal via the wireless IF211, determines the source Mac address from the header information, reads the corresponding client key KCL from the client key DB, and reads the payload part. Decrypt. If necessary, the access point 21 encrypts this with an encryption algorithm for a wired LAN, and then sends a packet to the wired LAN.
【0056】
(3) Disconnection of communication When the client terminal 11 no longer exists under the control of the access point 21, the access point 21 disconnects and waits for a connection request from the client.
【0057】
As described above, this communication system can securely perform mutual authentication and exchange of encryption keys between the client terminal 11 and the access point 21 with a relatively simple procedure. It is designed based on common key cryptography. Therefore, it is possible to increase the processing speed as compared with the case of using the public key method.
【0058】
Moreover, since the private key KCL of each client terminal 11 is registered in the access point 21 and used in the authentication process, spoofing can be prevented.
【0059】
(Second Embodiment) Hereinafter, a second embodiment of the communication system according to the embodiment of the present invention will be described.
【0060】
The basic configuration of the system of this embodiment is substantially the same as the configuration of the system of the first embodiment, and the communication protocol, which is a feature point, will be mainly described below.
【0061】
(1) Client registration First, on the client terminal 11 on which the wireless LAN card 12 is installed, the processing unit 114 generates the client's private key KCL.
【0062】
Next, the MAC address of the wireless LAN card 12 and this common key KCL pair are transmitted offline to the access point 21. The access point 21 registers this pair in database 214.
【0063】
(2) Access point key generation The processing unit 217 of the access point 21 dynamically generates the private key KAP of the access point 21 and stores it in the storage unit 213 when it is idle (when the client terminal 11 communicating with the user terminal 11 does not exist).
【0064】
(3) Authentication of client terminal 11 When the access point 21 receives the connection request from the client terminal 11, the access point 21 exchanges keys and authenticates according to the following procedure.
【0065】
a). The client terminal 11 sends a connection request to the access point 21.
【0066】
b). The processing unit 217 of the access point 21 receives the connection request, accesses the database 214, and searches for the client key KCL from the MAC address of the client terminal 11.
【0067】
c). The processing unit 217 of the access point 21 randomly generates the session key K. d). The processing unit 217 of the access point 21 encrypts the concatenation of the random number value R, the session key K, and the access point key KAP with the client key KCL to generate encrypted data eKCL (R | K | KAP).
【0068】
e). The processing unit 217 of the access point 21 transmits the encrypted data eKCL (R | K | KAP) to the client terminal 11 via the wireless IF211.
【0069】
f). The processing unit 114 of the client terminal 11 decrypts the encrypted data eKCL (R | K | KAP) addressed to itself with its own client key KCL via the wireless LAN card 12, and has a random number value R and a session key. K, extract the access point key KAP.
【0070】
g). The processing unit 114 of the client terminal 11 encrypts the random number value R with the access point key KAP to generate encrypted data eKAP (R).
【0071】
h). The processing unit 114 of the client terminal 11 transmits the generated encrypted data eKAP (R) to the access point 21.
【0072】
i). The processing unit 217 of the access point 21 receives the encrypted data eKAP (R) via the wireless IF211 and decrypts it with the access point key KAP to extract the random number value R.
【0073】
j). The access point 21 compares the extracted random number value R with the previously generated random number value R, and if they match, it is judged as authentication successful (OK).
【0074】
In this way, after the client terminal 11 is successfully authenticated, wireless encrypted communication is executed between the client terminal 11 and the access point 21.
【0075】
For example, when the access point 21 transmits a packet received from the wired LAN 42 side to the wireless LAN 41 side, the processing unit 217 performs the following processing according to the value of the MAC address.
【0076】
a). First, when the destination address of the packet received via the wired IF212 is a broadcast address, the control unit 217 encrypts the payload of the packet with the access point key KAP and sends it to the wireless IF211. Each client terminal 11 receives the packet, determines that the destination address is a broadcast address, and decodes the payload with the access point key KAP stored in the storage unit 111.
【0077】
b). If the destination address of the packet received via the wired IF212 is a MAC address, the control unit 217 determines whether or not the destination address is registered in the database 214. If registered, the client key KCL corresponding to the MAC address is read, the payload of the packet is encrypted with the client key KCL, and the packet is sent to the wireless IF211. Each client terminal 11 determines the packet addressed to itself and decodes the payload with the client key KCL stored in the storage unit 111.
【0078】
c). If the destination address is not registered in database 214, processing unit 217 discards the packet.
【0079】
On the other hand, when data is transmitted from the client terminal 11 to the access point 21, the processing unit 114 of each client terminal 11 encrypts the payload of the packet with its own client key KCL and sends it to the wireless LAN card 12. The access point 21 determines the source from the source address, reads the corresponding client key KCL from the table on the database 214, and decodes the packet payload with the client key KCL.
【0080】
Since the communication system of the second embodiment is also designed based on the common key cryptography, the processing speed can be increased. In addition, since the client's private key is registered in advance and used in the authentication process, spoofing can be prevented. In addition, the access point key is dynamically generated and the key is exchanged with the client terminal, which can avoid the vulnerability caused by IV collision, which is a weak point of WEP.
【0081】
The present invention is not limited to the above embodiment, and various modifications and applications are possible. For example, the first and second embodiments described above exemplify a powerful solution as a basic algorithm, but can be simplified if necessary. Conversely, other verification requirements may be added during authentication. In the present invention, "successful certification" is defined as satisfying other requirements or conditions, if any.
【0082】
In the above embodiment, the hash function is illustrated as a one-way function, but other functions may be used. In the above embodiment, the present invention has been described by exemplifying communication between a client and an access point, but the present invention is not limited to this, and can be widely applied when performing encrypted communication between two devices. is there. Further, although the present invention has been described by taking a wireless LAN as an example, the present invention is not limited to the wireless LAN and can be applied to other wireless communications. Furthermore, it can also be applied to wired communication. In the case of wired communication, there is no substantive change except that the wireless LAN card 12 is changed to the LAN card and the wireless IF211 is changed to the wired IF.
【0083】
The system of the present invention can be realized by using a normal computer system without relying on a dedicated system. For example, by installing the program from a medium (flexible disk, CD-ROM, etc.) in which the program for executing the above-mentioned operation is stored in a computer, a server 111 or the like that executes the above-mentioned processing can be configured. .. In addition, when the OS realizes the above-mentioned functions by sharing or jointly by the OS and the application, only the part other than the OS may be stored in the medium.
【0084】
It is also possible to superimpose the program on the carrier wave and distribute it via the communication network. For example, the program may be posted on a bulletin board system (BBS) of a communication network and distributed via the network. Then, by starting this program and executing it in the same manner as other application programs under the control of the OS, the above-mentioned processing can be executed.
【0085】
[Effect of the invention]
According to the present invention, highly reliable communication can be performed.
[Simple explanation of drawings]
[Figure 1]
It is a figure which shows the structure of the communication system which concerns on embodiment of this invention.
[Figure 2]
It is a figure which shows the structure of the client terminal shown in FIG.
[Fig. 3]
It is a figure which shows the structure of the access point shown in FIG.
[Fig. 4]
It is a figure which shows the example of the table stored in the database shown in FIG.
[Fig. 5]
In the first embodiment, it is a figure which shows the information which is sent and received between a client terminal and an access point, and the procedure.
[Explanation of symbols]
11 Client terminal 21 access point 41 wifi 42 Wired LAN
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8990571B2 | Cited by | United States of America | Applicant |
| US8605903B2 | Cited by | United States of America | Applicant |
| US9887841B2 | Cited by | United States of America | Applicant |
| JP2020031268A | Cited by | Japan | Search report |
| WO2005071879A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2013516896A | Cited by | Japan | Search report |
| US8380168B2 | Cited by | United States of America | Applicant |
| EP1855430A3 | Cited by | European Patent Office (EPO) | Search report |
| CN113573307A | Cited by | China | Search report |
| US10361851B2 | Cited by | United States of America | Applicant |
| US9225513B2 | Cited by | United States of America | Applicant |
| JP2019154007A | Cited by | Japan | Search report |
| US8855297B2 | Cited by | United States of America | Applicant |
| US10361850B2 | Cited by | United States of America | Applicant |
| US8761389B2 | Cited by | United States of America | Applicant |
| US9166783B2 | Cited by | United States of America | Applicant |
| KR101485230B1 | Cited by | Republic of Korea | Search report |
| US7757087B2 | Cited by | United States of America | Applicant |
| US8122487B2 | Cited by | United States of America | Applicant |
| JP2007133689A | Cited by | Japan | Examiner |
| US7610488B2 | Cited by | United States of America | Applicant |
| WO2005071879A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9160531B2 | Cited by | United States of America | Applicant |
| JP2007329884A | Cited by | Japan | Examiner |
| KR101325227B1 | Cited by | Republic of Korea | Examiner |
| US9100187B2 | Cited by | United States of America | Applicant |
| JP2013138491A | Cited by | Japan | Search report |
| US8812843B2 | Cited by | United States of America | Applicant |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalA02 | A02 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2003-143128
- Publication, DOCDB
- 2003143128
- Publication, EPODOC
- JP2003143128
- Application
- 339959
- Application, DOCDB
- 2001339959
- Application, EPODOC
- JP20010339959
Titles2
- Japanese
- 【発明の名称】通信システム及び通信方法
- English
- [Title of Invention] Communication System and Communication Method
Classification
- IPC, 2
- H04L9 08
- H04L9 32