Providing apparatus, providing method, communication apparatus, communication method, and program
Abstract
Problem to be solved.To lessen a processing for ensuring the security.
Solution.A security management server 103 receives IPsec request messages 406, 407 from a digital camera 102 and a printer 101, makes up IPsec setting contents, and returns the IP setting contents 409, 410 to the digital camera 102 and the printer 101. The IPsec request messages 406, 407 include session IDs, IPsec levels (any of use, require and unique), an authenticating algorithm and an encrypting algorithm. The IPsec setting contents 409, 410 include an authenticating algorithm, an encrypting algorithm, authenticating keys and encrypting keys.
Copyright (C)2006,JPO&NCIPI
Term
Term ended
Projected expiry passed 31 March 2024, 2.5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
15 claims: 8 independent, 7 dependent
- 1It is a providing device that provides information necessary for performing security communication to the first device and the second device, and receives parameter candidates for performing security communication from the first device and the second device. The receiving means to be generated, the generating means for generating the information necessary for performing the security communication based on the parameter candidates received from the first device and the second device, and the security communication generated by the generating means. A providing device comprising a transmitting means for transmitting information necessary for performing the information to the first device and the second device. セキュリティ通信を行うために必要な情報を第1の装置と第2の装置に提供する提供装置であって、 セキュリティ通信を行うためのパラメータの候補を、第1の装置及び第2の装置から受信する受信手段と、 第1の装置及び第2の装置から受信したパラメータの候補に基づいて、セキュリティ通信を行うために必要な情報を生成する生成手段と、 前記生成手段により生成されたセキュリティ通信を行うために必要な情報を、前記第1の装置及び第2の装置に送信する送信手段とを有することを特徴とする提供装置。
- 2The first device and the second device are the providing devices that provide the first device and the second device with the information necessary for the secure communication, and the first device and the second device. Receiving means for receiving identification information for identifying communication between devices and parameter candidates for ensuring security from the first device and the second device, and receiving from the first device and the second device. A generation means for generating information necessary for ensuring the security of communication based on the candidate parameters, and the communication generated by the generation means for ensuring the security of the communication identified by the identification information. A providing device including a transmitting means for transmitting information necessary for ensuring security to the first device and the second device. 第1の装置と第2の装置がセキュリティの確保された通信を行うために必要な情報を第1の装置と第2の装置に提供する提供装置であって、 第1の装置と第2の装置間の通信を識別する識別情報、及び、セキュリティを確保するためのパラメータの候補を、第1の装置及び第2の装置から受信する受信手段と、 第1の装置及び第2の装置から受信したパラメータの候補に基づいて、通信のセキュリティを確保するために必要な情報を生成する生成手段と、 識別情報により識別される通信のセキュリティを確保するために前記生成手段により生成された前記通信のセキュリティを確保するために必要な情報を、前記第1の装置及び第2の装置に送信する送信手段とを有することを特徴とする提供装置。
- 3This is a method of providing information necessary for performing security communication to the first device and the second device, and receives parameter candidates for performing security communication from the first device and the second device. Then, based on the parameter candidates received from the first device and the second device, the information necessary for performing the security communication is generated, and the information necessary for performing the generated security communication is described above. A provision method comprising transmitting to a first device and a second device. セキュリティ通信を行うために必要な情報を第1の装置と第2の装置に提供する提供方法であって、 セキュリティ通信を行うためのパラメータの候補を、第1の装置及び第2の装置から受信し、 第1の装置及び第2の装置から受信したパラメータの候補に基づいて、セキュリティ通信を行うために必要な情報を生成し、 前記生成されたセキュリティ通信を行うために必要な情報を、前記第1の装置及び第2の装置に送信することを特徴とする提供方法。
- 4It is a method of providing the information necessary for the first device and the second device to perform secure communication to the first device and the second device, and is a method of providing the first device and the second device. Identification information that identifies communication between devices and parameter candidates for ensuring security are received from the first device and the second device, and the parameters received from the first device and the second device. Based on the candidates, the information necessary for ensuring the security of the communication is generated, and the information necessary for ensuring the security of the generated communication for ensuring the security of the communication identified by the identification information. Is transmitted to the first device and the second device. 第1の装置と第2の装置がセキュリティの確保された通信を行うために必要な情報を第1の装置と第2の装置に提供する提供方法であって、 第1の装置と第2の装置間の通信を識別する識別情報、及び、セキュリティを確保するためのパラメータの候補を、第1の装置及び第2の装置から受信し、 第1の装置及び第2の装置から受信したパラメータの候補に基づいて、通信のセキュリティを確保するために必要な情報を生成し、 識別情報により識別される通信のセキュリティを確保するために前記生成された前記通信のセキュリティを確保するために必要な情報を、前記第1の装置及び第2の装置に送信することを特徴とする提供方法。
- 7A communication device that receives information necessary for ensuring the security of communication with a communication partner from a providing device, and a transmission means for transmitting parameter candidates for ensuring security to the providing device, and security. It has a receiving means for receiving the information necessary for ensuring the above from the providing device, and a security ensuring means for ensuring security in communication with the communication partner based on the information received from the providing device by the receiving means. A communication device characterized by. 通信相手との間で行う通信のセキュリティを確保するために必要な情報を提供装置から受け取る通信装置であって、 セキュリティを確保するためのパラメータの候補を、提供装置に送信する送信手段と、 セキュリティを確保するために必要な情報を、提供装置から受信する受信手段と、 前記受信手段により提供装置から受信した情報を元に、通信相手との通信にセキュリティを確保するセキュリティ確保手段とを有することを特徴とする通信装置。
- 8A communication device that receives information necessary for ensuring the security of communication with the communication partner from the providing device, and secures an identifier that identifies the communication established with the communication partner and security. Based on the transmitting means for transmitting the candidate parameters for the function to the providing device, the receiving means for receiving the information necessary for ensuring security from the providing device, and the information received from the providing device by the receiving means. A communication device characterized by having a security ensuring means for ensuring security in communication established with a communication partner. 通信相手との間で行う通信のセキュリティを確保するために必要な情報を提供装置から受け取る通信装置であって、 通信相手との間で確立された通信を識別する識別子、及び、セキュリティを確保するためのパラメータの候補を、提供装置に送信する送信手段と、 セキュリティを確保するために必要な情報を、提供装置から受信する受信手段と、 前記受信手段により提供装置から受信した情報を元に、通信相手との間で確立された通信にセキュリティを確保するセキュリティ確保手段とを有することを特徴とする通信装置。
- 9It is a communication method that receives information necessary for ensuring the security of communication with the communication partner from the providing device, and sends parameter candidates for ensuring security to the providing device to ensure security. A communication method characterized in that information necessary for the purpose is received from a providing device, and security is ensured for communication with a communication partner based on the information received from the providing device. 通信相手との間で行う通信のセキュリティを確保するために必要な情報を提供装置から受け取る通信方法であって、 セキュリティを確保するためのパラメータの候補を、提供装置に送信し、 セキュリティを確保するために必要な情報を、提供装置から受信し、 前記提供装置から受信した情報を元に、通信相手との通信にセキュリティを確保することを特徴とする通信方法。
- 10It is a communication method that receives information necessary for ensuring the security of communication with the communication partner from the providing device, and secures the identification information that identifies the communication established with the communication partner and the security. Parameter candidates for this are sent to the providing device, information necessary for ensuring security is received from the providing device, and is established with the communication partner based on the information received from the providing device. A communication method characterized by ensuring security in communication. 通信相手との間で行う通信のセキュリティを確保するために必要な情報を提供装置から受け取る通信方法であって、 通信相手との間で確立された通信を識別する識別情報、及び、セキュリティを確保するためのパラメータの候補を、提供装置に送信し、 セキュリティを確保するために必要な情報を、提供装置から受信し、 前記提供装置から受信した情報を元に、通信相手との間で確立された通信にセキュリティを確保することを特徴とする通信方法。
Independent claims8
103 paragraphs, as filed
The present invention relates to a providing device, a providing method, and a communication partner that provide information necessary for the first device and the second device to perform secure communication to the first device and the second device. The present invention relates to a communication device, a communication method, and a program for realizing the provision method or the communication method, which receives information necessary for ensuring the security of communication between the two.
IPsec is a standardized technology with sufficient functionality and security to achieve security at the general IP layer. The core of IPsec is the automatic generation of SA (Security Association) by the IKE protocol specified in RFC2409 The Internet Key Exchange (IKE), and SA establishment is Phase 1 (or ISAKMP SA), Phase 2 (or IPsec SA). It is divided into two stages. Patent Document 1 is a patent document relating to IPsec.
In the aggressive mode, in Phase 1, the encryption algorithm of the IKE communication path is selected in the first round trip, and the key exchange (key for IKE communication) is performed by the DH (Diffee-Hellman) key exchange algorithm in the second round trip, and in the third round trip. Authenticate the communication partner. In Phase 2, the secret communication path established in Phase 1 is used in the first round trip to exchange the encryption algorithm and secret key used in the security protocol ESP or AH, and the subsequent connection approval is sent only as transmission. The setting information exchanged in this way is registered as an SA entry of the SAD (Security Association Database) of both terminal devices, and is used for mutual secure communication.
IPsec communication is standardized so that it can be automatically set between terminal devices in this way, but some preset settings are essential for this purpose.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2001-298449</text></patcit>
<p> As for the authentication performed in the third round trip of Phase 1, the authentication by the Pre-Shared Key method is generally supported. The Pre-Shared Key method is valid only between two terminal devices that perform security communication, that is, a common key that must be kept secret so that it is not known to others is given to the target device by an administrator with technology. On the other hand, it is assumed that it will be set directly. Therefore, although it can be operated between a specific small number of devices, it has been pointed out that it is difficult to operate when setting a Pre-Shared Key between an unspecified number of devices.</p><p> In addition, the DH key exchange algorithm, public key cryptography algorithm, etc. used in IPsec are heavy in processing, and when IPsec is processed in a mobile terminal with relatively low CPU power, it takes several seconds or more, so it is practical. Has been pointed out as having problems in terms of mounting, such as the need for a dedicated arithmetic chip.</p><p> An object of the present invention is to reduce processing for ensuring security.</p>
<p> The provided device, method, and program of the present invention receives parameter candidates for performing security communication from the first device and the second device, and receives parameter candidates from the first device and the second device. Based on the above, information necessary for performing security communication is generated, and information necessary for performing previously generated security communication is transmitted to the first device and the second device. ..</p><p> Further, the communication device, method, and program of the present invention transmits parameter candidates for ensuring security to the providing device, receives information necessary for ensuring security from the providing device, and receives the information necessary for ensuring security from the providing device. It is characterized by ensuring security in communication with the communication partner based on the information received from.</p>
<p> As described above, it is possible to reduce the processing for ensuring security.</p>
Hereinafter, embodiments according to the present invention will be described in detail with reference to the drawings.
FIG. 1 is a network configuration diagram of an embodiment of the present invention. In Fig. 1, 100 is the Internet, and communication using the IPv6 protocol is possible. The 101 is a printer directly or indirectly connected to the Internet 100, and can communicate using the IPv6 protocol via the Internet 100. The 102 is a digital still camera (hereinafter referred to as a digital camera) directly or indirectly connected to the Internet 100, and can communicate using the IPv6 protocol via the Internet 100.
103 is a security management server connected to the Internet 100, and is a server that manages the security of the printer 101 and the digital camera 102 in peer-to-peer communication via the Internet 100. The security management server 103 holds detailed information on both devices, and the security of communication with both devices via the Internet 100 has already been ensured. That is, the security management server 104 and the printer 101 are equipped with a common authentication key / encryption key so that information is not leaked to the outside. Based on the information of the authentication key / encryption key, the security management server 103 And the printer 101 can authenticate each other about communication and encrypt the communication contents.
The printer 101 and the digital camera 102 are capable of peer-to-peer communication using the IPv6 protocol. Address registration (SIP Register) for the security management server 103 by both devices is performed. In this state, the digital camera 102 sends a session request (SIP Invite) to the printer 101, so that both devices establish a session for peer-to-peer communication. After the session is established, both devices will be able to perform peer-to-peer communication with the required application. That is, in this embodiment, the security management server 103 also serves as a SIP server. SIP (Session Initiation Protocol) is specified in RFC2543.
The network information of each device and server in the network configuration shown in Fig. 1 is as follows.
That is, for example, the device IDs of the printer 101 and the digital camera 102 are BJ001 and DC101, and these device IDs are used as device identifiers in the security management server 103. This device ID is also used as a SIP URI for SIP communication exchanged when performing peer-to-peer communication between devices. The IPv6 addresses of the printer 101, the digital camera 102, and the security management server 103 are 3ffe: 514 :: 1, 2002: 200 :: 1, 2001: 340 :: 1. The device ID and IPv6 address of the printer 101 and the digital camera 102 are registered in the security management server 103.
The security management server 103 is a device that mediates between the digital camera 102 and the printer 101 for establishing a session (communication), and the device ID (identifier) of the printer 101 included in the session request from the digital camera 102 is used as the IP of the printer 101. Convert to an address. The session between the digital camera 102 and the printer 101 is established based on this IP address.
The security management server 103 is a providing device that provides information necessary for performing security communication to the digital camera (first device) 102 and the printer (second device) 101, and is a parameter for performing security communication. To receive candidates from the digital camera 102 and the printer 101, generate information necessary for performing security communication based on the parameter candidates received from the digital camera 102 and the printer 101, and perform the generated security communication. The necessary information is transmitted to the digital camera 102 and the printer 101.
The security management server 103 receives the identification information for identifying the communication between the digital camera 102 and the printer 101 from the digital camera 102 and the printer 101, and the generated information necessary for performing the security communication is identified by the identification information. In order to ensure the security of communication, it is transmitted to the digital camera 102 and the printer 101.
The printer 101 and the digital camera 102 are communication devices that receive information necessary for ensuring the security of communication with the communication partner from the security management server 103 (providing device), and are parameters for ensuring security. Candidates are sent to the security management server 103, information necessary for ensuring security is received from the security management server 103, and security is provided for communication with the communication partner based on the information received from the security management server 103. Secure.
The printer 101 and the digital camera 102 transmit the identification information that identifies the communication established with the communication partner to the security management server 103, and based on the information received from the security management server 103, the printer 101 and the digital camera 102 communicate with the communication partner. Ensure security for established communications.
The parameter candidates for performing security communication are, for example, candidates for at least one or both of an authentication algorithm and an encryption algorithm for ensuring security.
Further, the information necessary for ensuring security is at least one or both of the authentication algorithm and the encryption algorithm for ensuring security, or the key for ensuring security.
FIG. 2 shows an example of a hardware configuration for operating a software program that realizes the functions of the present embodiment. Here, an example in which the security management server 104 is configured by the computer 1500 is shown, but the printer 101 and the digital camera 102 can be similarly configured by adding the printing unit and the imaging unit.
The computer 1500 includes a CPU 1501, a ROM 1502, a RAM 1503, a disk controller (DC) 1505 of a hard disk (HD) 1507 and a floppy (registered trademark) disk (FD) 1508, and a network interface card (NIC) 1506. It is configured so that it can communicate with each other via 1504. Then, the system bus 1504 is connected to the Internet 100 shown in FIG. 1 above via the network interface card 1506.
The CPU 1501 comprehensively controls each component connected to the stem bus 1504 by executing the software stored in the ROM 1502 or HD1507 or the software supplied from the FD1508. That is, the CPU1501 performs control for realizing the operation in the present embodiment by reading and executing a processing program according to the processing sequence described below from the ROM1502, the HD1507, or the FD1508. RAM1503 functions as the main memory or work area of CPU1501. The DC1505 controls access to the HD1507 and FD1508, which store boot programs, various applications, editing files, user files, network management programs, and the processing programs according to this embodiment. NIC1506 communicates with each other using the IPv6 communication protocol through the Internet 100.
The security management server 103, which is a providing device that provides the information necessary for performing security communication to the digital camera (first device) 102 and the printer (second device) 101, selects parameter candidates for performing security communication. It has a NIC 1506 received from the digital camera 102 and the printer 101, and a CPU 1501 that generates information necessary for performing security communication based on parameter candidates received from the digital camera 102 and the printer 101. The NIC1506 is a transmission means for transmitting the generated information necessary for performing security communication to the digital camera 102 and the printer 101. NIC1506 receives a session request message (Invite request message) requesting that the digital camera 102 establish a session with printer 101, and CPU1501 sets the device ID (identifier) of printer 101 included in the session request message to the IP of printer 101. It translates into an address and mediates the establishment of a session (communication) between the digital camera 102 and the printer 102.
Further, NIC1506 of the security management server 103 receives the identification information for identifying the communication between the digital camera 102 and the printer 101 from the digital camera 102 and the printer 101, and the generated information necessary for performing the security communication is the identification information. To ensure the security of the communication identified by, it is transmitted to the digital camera 102 and the printer 101.
The printer 101 and the digital camera 102 are communication devices that receive information necessary for ensuring the security of communication with the communication partner from the security management server (providing device) 103, and are parameters for ensuring security. Candidates are sent to the security management server 103, and information necessary for ensuring security is received from the providing device, NIC1506, and based on the information received from the security management server 103 by NIC1506, communication with the communication partner is performed. It has a CPU 1501 to ensure security.
The NIC1506 of the printer 101 and the digital camera 102 transmits the identification information that identifies the communication established with the communication partner to the security management server 103, and the CPU 1501 communicates based on the information received from the security management server 103. Ensure security for established communication with the other party. NIC1506 of the digital camera 102 sends a request message (Invite request message) requesting the establishment of a session (communication) with the printer 101 to the security management server 103.
The parameter candidates for performing security communication are, for example, candidates for at least one or both of an authentication algorithm and an encryption algorithm for ensuring security.
Further, the information necessary for ensuring security is at least one or both of the authentication algorithm and the encryption algorithm for ensuring security, or the key for ensuring security.
FIG. 3 is a module configuration diagram of the printer 101 and the security management server 103. 301 to 305 are modules installed in the security management server 103, and 311 to 316 are modules installed in the printer 101. The digital camera 101 also has the same module configuration as the printer 101.
Reference numeral 301 denotes a communication module, which is used for receiving an IPsec request message and transmitting IPsec setting contents to the printer 101 via the network interface card 1506. 302 is a request receiving module that receives an IPsec request message from the printer 101. 303 is an IPsec creation table, and the request reception module 302 manages and stores the session information between each device obtained from the IPsec request message and the IPsec-related information of the device. The details of the IPsec creation table will be described with reference to FIG. Reference numeral 304 denotes a cryptographic communication module, which exchanges messages with the printer 101 using a secure communication path secured in advance. Reference numeral 305 is an IPsec setting module, and processing of creating IPsec setting contents to be used by the printer 101 is performed from the information in the IPsec creation table 303.
The 311 is a communication module, which is used for receiving the IPsec request message and transmitting the IPsec setting contents to the security management server 103 via the network interface card 1506. This module is equivalent to the communication module 301. 312 is a request issuing module that creates IPsec request messages. An IPsec request is issued by this module, and the IPsec setting contents are acquired from the security management server 103.
Reference numeral 313 is an encrypted communication module, and messages are exchanged with the security management server 103 using a secure communication path secured in advance. This module is equivalent to the cryptographic communication module 304. The cryptographic communication module 304 of the security management server 103 and the cryptographic communication module 313 of the digital camera 102 communicate using the cryptographic communication path formed by using the first secret symmetric key owned by each. Further, the cryptographic communication module 304 of the security management server 103 and the cryptographic communication module 313 of the printer 101 communicate with each other using the cryptographic communication path formed by using the second secret symmetric key owned by each.
Reference numeral 314 is an IPsec setting module, which is a module for setting the IPsec setting contents created by the IPsec setting module 305 to the printer 101.
The 315 is a SIP module, which is used when the printer 101 and the digital camera 102 perform peer-to-peer communication and establish a session for peer-to-peer communication using SIP. That is, the printer 101 registers the IPv6 address (3ffe: 514 :: 1) automatically set when connecting to the Internet 100 in the security management server 103 together with its own device ID (BJ101). As a result, the SIP URI of the printer 101 (for example, BJ101@device.ccc.com) and its IPv6 address are managed by the security management server 103. Similarly, the digital camera 102 also registers the SIP URI and its IPv6 address in the security management server 103. Using the registered SIP URI of printer 101, digital camera 102 sends a session request message (SIP). By sending Invite) to the printer 101 via the security management server 103, negotiations for establishing a session and mutual device information are exchanged, and a session is established. The above SIP processing is performed by the SIP module 315. The session establishment process will be described in detail with reference to FIG.
316 is an application, which is an application used by the printer 101 to perform peer-to-peer communication with another device (for example, a digital camera 102).
FIG. 4 is a sequence diagram of this embodiment. In this sequence diagram, the registration process (SIP Register) for performing SIP communication has already been completed, and the procedure for performing peer-to-peer communication from the digital camera 102 to the printer 101 is shown.
401 is an Invite request message requesting the establishment of a session, which is sent to the printer 101 via the security management server 103. The Invite request message 401 requesting the establishment of the session includes the session ID (identification information for identifying the communication) of the session (communication) requesting the establishment. In the Invite request message of this 401, the address information and application information (port number) of the digital camera 102 when performing peer-to-peer communication between the digital camera 102 and the printer 101, and the security information for securely performing the peer-to-peer communication are included in the SDP (Session). Described in Description Protocol) and attached. The SDP is read from, for example, the HD1507.
The printer 101 sends the response message of 402 to the digital camera 102 via the security management server 103 as a reply to the received Invite request message 401. The response message of this 402 includes, for example, an SDP in which "200OK" permitting session acceptance is returned (hereinafter referred to as a 200OK message) and various information necessary for peer-to-peer communication with the digital camera 102 is described. This SDP is read from, for example, the HD1507. If the response message 402 also contains an error message and the session cannot be accepted (for example, if a session is being established with another device and a new session cannot be established with the digital camera 102, or if the digital camera 102 cannot be established. If there is a request for a function that is not supported by the printer 102 in the SDP information sent from the printer 102), an error message is sent at 402.
In 403, the digital camera 102 that has received the 200OK message 402 for the Invite request sends an Ack message to the printer 101 notifying that the 200OK message 402 has been accepted. By exchanging the Ack message of 403, the digital camera 102 and the printer 101 have established a session for peer-to-peer communication. If the SIP message sent at 402 is an error message that refuses to accept the session, the Ack message is also sent at 403.
The session (communication) between the digital camera 102 and the printer 101 is established by mediation by the security management server 103. That is, the device ID (identifier) of the printer 101 included in the Invite request message (session request) 401 from the digital camera 102 is converted into the IP address of the printer 101. The session between the digital camera 102 and the printer 101 is established based on this IP address.
In the 404, the digital camera 102 starts the IPsec request processing for peer-to-peer communication with the printer 101, triggered by the transmission of the Ack message 403. Specifically, the above-mentioned SIP module 315 makes an IPsec request request to the request issuing module 312. Similarly, in the 405 as well, the printer 101 starts the IPsec request processing for peer-to-peer communication with the digital camera 102, triggered by the reception of the Ack message 403.
In the IPsec request processing (404) on the digital camera 102 side, it is determined whether or not to perform security communication using IPsec in peer-to-peer communication between the digital camera 102 and the printer 101, and when IPsec is used, the security management server 103 is used. In response, 406 IPsec request messages are sent. Similarly, in the IPsec request processing (405) on the printer 101 side, it is determined whether or not to perform security communication using IPsec in the peer-to-peer communication between the digital camera 102 and the printer 101, and when IPsec is used, security is determined. Sends an IPsec request message of 407 to the management server 103. The details of the above IPsec request processing (404, 405) will be described with reference to FIGS. 6 and 7. As will be described later, the printer 101 and the digital camera 102 are communication devices that receive information necessary for ensuring the security of communication with the communication partner from the security management server 103 (providing device), and ensure security. The candidate parameters (including IPsec request messages 406 and 407) are sent to the security management server 103.
Upon receiving the IPsec request message (406, 407), the security management server 103 analyzes the IPsec request message at 408 after the IPsec request message contents from the two devices attempting peer-to-peer communication are prepared, and then analyzes the IPsec request message and sets the IPsec settings. Create and reply the IPsec settings to each device. The details of the above processing will be described with reference to FIGS. 8 and 9. As will be described later, the security management server 103 is a providing device that provides information necessary for performing security communication to the first device and the second device, and is a candidate for parameters for performing security communication. The including IPsec request messages 406 and 407) are received from the digital camera (first device) 102 and the printer (second device) 101, and the IPsec setting contents (IPsec setting contents) are received based on the parameter candidates received from the digital camera 102 and the printer 101. (Information necessary for security communication) is generated, and the IPsec setting contents are transmitted to the digital camera 102 and the printer 101.
The IPsec setting contents of each device created by 408 are transmitted to the digital camera 102 and the printer 101 as replies to the IPsec request message by 409 and 410, respectively. The digital camera 102 that has received the IPsec setting contents of 409 sets IPsec. Similarly, the printer 101 that has received the IPsec setting contents of 410 also sets IPsec. When the IPsec setting is completed for both devices, secure peer-to-peer communication between the digital camera 102 and the printer 101 is started at 411. The printer 101 and the digital camera 102 are communication devices that receive information necessary for ensuring the security of communication with the communication partner from the security management server 103 (providing device), and are IPsec setting contents (ensuring security). Information necessary for this) is received from the security management server 103, and security is ensured for communication with the communication partner based on the IPsec setting contents received from the security management server 103.
That is, FIG. 4 shows a procedure for setting the session key and security setting information necessary for realizing security communication by IPSEC between the digital camera (first terminal) 102 and the printer (second terminal) 101. There is.
The security management server (SIP server) 103 includes an Invite request message (connection call message) 401 from the digital camera (first terminal) 102 to the printer (second terminal) 101, and a response message to the digital camera 102 from the printer 101. (Connection response message) Relay 402.
The security management server 103 acquires the security setting candidate information of the digital camera 102 included in the IPsec request message (encryption communication setting request message) 406 from the digital camera 102, and the IPsec request message (encryption communication setting request message) 407 from the printer 101. Acquires the security setting candidate information of the printer 101 included in.
When the security management server 103 receives the IPsec request message 406 from the digital camera 102 and the IPsec request message 407 from the printer 101, the security management server 103 sets the IPsec settings for each of the digital camera 102 and the printer 101 (encryption key (session key) used for encrypted communication). ) And security setting information).
The security management server 103 and the digital camera 102 transmit the IPsec setting contents 409 for the digital camera 102 to the digital camera 102 from the security management server 103 using the encrypted communication path formed by using the first secret symmetric key owned by each. , The security management server 103 and the printer 101 each transmit the IPsec setting contents 410 for the printer 101 from the security management server 103 to the printer 101 using the encrypted communication path formed by using the second secret symmetric key owned by the security management server 103 and the printer 101. To do.
The digital camera 102 and the printer 101 start an IPsec encrypted communication path between the digital camera 102 and the printer 101 from the received IPsec setting contents.
FIG. 5 shows an example of the IPsec creation table 303. This IPsec creation table 303 is provided on the RAM 1503. 501 is a session ID, which indicates a session ID established by two devices using SIP. The 502 and 503 store the information of two devices that perform peer-to-peer communication using IPsec by establishing the previous session. The device information of the source (digital camera 102) of the previously received IPsec request message (406) is stored in hostA, and the other device information is stored in hostB. Reference numeral 504 stores the reception time of the last received IPsec request message. This is when the IPsec request messages from the two devices that use IPsec are not aligned (that is, the IPsec request message is received from the digital camera 102, but the IPsec request message is received from the printer 101 that is the communication partner. It is used for timeout processing (if not). 505 indicates the status of the IPsec creation table. This status has values for waiting (waiting for IPsec request (407) from the other device), generating (creating IPsec settings), and sent (replying IPsec settings (409, 410) completed). To do.
The details of the device information stored in 502 and 503 will be described below. The device ID is stored in 506, and the IPv6 address used by the device is stored in 507. The 508 stores the port number of the application used in peer-to-peer communication, and the 509 stores the IPsec level used in peer-to-peer communication. At this IPsec level, there are values of use (use of IPsec is not mandatory), require (use of IPsec is mandatory), and unique (SA to be used in IPsec is uniquely specified). The value of SPI (Security Parameter Index) used in the IPsec setting is stored in 510. The ah (authentication) algorithm name possessed by the device is stored in 511, and the esp (encryption) algorithm name possessed by the device is stored in 512. In addition, a plurality of algorithm names may be stored in 511 and 512, and in that case, the ones having the highest usage priority are stored in order.
521 shows specific IPsec creation table entries, and 522 and 523 show hostA device information and hostB device information stored in 502 and 503 of entry 521, respectively.
6 and 7 show the processing flow on the device side in this embodiment. 6 and 7 show a part of the program stored in the ROM 1502, HD1507, or FD1508 so that the computer CPU1501 can read it.
FIG. 6 describes a process of requesting an IPsec request from the SIP Invite process to the request issuing module 312 in the SIP module 315.
In 601, the message type in SIP Invite processing is determined. In SIP Invite processing, if Ack message 403 (Fig. 4) is sent or if Ack message 403 is received, the process proceeds to 602, otherwise the process proceeds to 605 and normal SIP module processing is performed. Here, the case of transmitting the Ack message 403 corresponds to the digital camera 102 that sent the Invite request message 401, and the case of receiving the Ack message 403 corresponds to the printer 101 that sent the 200OK message 402.
In 602, each call-ID, From, To information and own SDP information are acquired from the session information established by SIP Invite processing. Each of the above information includes the session ID established in the previous SIP Invite process, the two device IDs that use the session, and various information about itself. In 603, the IPsec request request is made to the request issuing module 312 together with the above information. In 604, in response to the result of the IPsec request request in 603, the IPv6 address and port number of the communication partner are notified to the higher-level application, and peer-to-peer communication is performed by the two devices. If the result of the IPsec request request is an error (that is, if the IPsec setting is not completed normally, or if the use of IPsec is not instructed, etc.), the error is notified to the higher-level application. , You may ask the user whether to perform peer-to-peer communication even when IPsec is not used.
FIG. 7 mainly describes the processing of the request issuing module 312 that received the IPsec request request in 603.
In 701, the value of sec_level is acquired from the own SDP information received together with the IPsec request request in 603. The details of SDP information will be described later. When the sec_level value acquired in 701 is judged by 702 and the sec_level information does not exist in the SDP information or when the sec_level value is "none" (that is, when IPsec is not used in peer-to-peer communication) , If the sec_level information is an appropriate value (use, require, or unique), the process proceeds to 703. In 703, each information of Call-ID, From, and To received together with the IPsec request request is acquired in 603, and in 704, the IPv6 address and port number are acquired from the self-SDP information. The 705 includes the IPsec algorithm installed in the device and the currently available SPI (Security Parameter). Get Index). This IPsec algorithm is at least one or both of an authentication algorithm and an encryption algorithm, and the IPsec algorithm (identifier) mounted on the device is obtained from, for example, HD1507. The 706 creates an IPsec request message to be sent to the security management server 103 from the various information acquired in the above 701, 703, 704, and 705. The details of the IPsec request message will be described later.
At 707, the IPsec request message created by 706 is sent to the security management server 103 by the procedure of encrypting the message content by the encrypted communication module 313 and transmitting to the security management server 103 by the communication module 311. That is, the printer 101 and the digital camera 102 are communication devices that receive information necessary for ensuring the security of communication with the communication partner from the security management server 103 (providing device), and the security is provided in this 707. A candidate IPsec algorithm (parameter) for securing (including an IPsec request message) is sent to the security management server 103. In this 707, the printer 101 and the digital camera 102 transmit the Call-ID, which is the identification information for identifying the communication established with the communication partner, to the security management server 103.
The 708 receives the response message (409, 410) for the IPsec request message (406, 407) sent in the 707, and acquires the IPsec setting contents from the response message. The received response message will be described in detail with reference to FIG. In 709, the validity of the acquired IPsec setting contents is checked, and if it is not valid (that is, when the security management server 103 returns an error), an error is made, and if it is valid, the process proceeds to 710. In the 710, the IPsec setting contents whose validity has been confirmed are passed to the IPsec setting module 314, and the setting is made in the kernel of the device by using the "set key" command.
The printer 101 and the digital camera 102 are communication devices that receive information necessary for ensuring the security of communication with the communication partner from the security management server 103 (providing device), and the security is ensured in this 708. The IPsec setting contents, which are necessary information for the purpose, are received from the security management server 103, and the 710 secures the communication with the communication partner based on the information received from the security management server 103.
The printer 101 and the digital camera 102 are established by sending and receiving the communication (Invite request message 401, response message 402, Ack message 403) established with the communication partner based on IPsec which is the information received from the security management server 103. Secure communication).
An example of the above-mentioned SDP is as follows. v = 0o = BJ001 2451851 112144870 IN IP6 3ff: 514 :: 1s = -c = IN IP6 3ffe: 514 :: 1t = 0 0m = application 80 HTTPk = ipsec_level: require This example is the SDP content of printer 101. Explain important information. The "3ffe: 514 :: 1" in the second line "o =" is the IPv6 address of the printer 101. Similarly, the IPv6 address is described in the fourth line "c =". The "80" in the sixth line "m =" is the port number of the application, indicating that the "HTTP" protocol is used. Then, sec_level is described in "k =" on the seventh line, and the value of "require" is specified in this example. The request issuing module 312 acquires this sec_level in 701 in FIG. The request issuing module 312 acquires the IPv6 address on the second or fourth line and the port number on the sixth line at 704. This SDP is stored in the hard disk 1508 and so on.
An example of the IPsec request message created in 706 of FIG. 7 is as follows. <ipsec-request> <session-id> 2451851 </ session-id> <local-host> DC101 </ local-host> <remote-host> BJ101 </ remote-host> <ipv6-address> 2002: 200: 1 </ ipv6-address> <port> 46127 </ port> <level> require </ level> <spi> 0x834 </ spi> <ah-algo> hmac-sha1 </ ah-algo> <ah-algo > hmac-md5 </ ah-algo> <esp-algo> blowfish-cbc </ esp-algo> <esp-algo> 3des-cbc </ esp-algo> </ ipsec-request> This example shows an IPsec request message sent from the digital camera 102. The data is described in XML format and is enclosed in <ipsec-request> tags. In this embodiment, it is not important to convert this data format to XML format, and there is no problem in the data transmission method using other formats. Hereinafter, each item will be described. <session-id> indicates the session ID established between the digital camera 102 and the printer 101, and <local-host> indicates the device ID of the digital camera 102. <remote-host> indicates the device ID of the printer 101, which is the partner of peer-to-peer communication, and <ipv6-address> indicates the IPv6 address of the digital camera 102. <port> indicates the port number used by the application of the digital camera 102, and <level> indicates the IPsec level (sec_level) of the digital camera 102. In the form of negotiating the IPsec level, the value is the same as that of the printer 101, which is the partner of peer-to-peer communication. sec_level is one of use, require, and unique values. <spi> indicates the SPI (Security Parameter Index) value of the digital camera 102. <ah-algo> indicates the ah (authentication) algorithm possessed by the digital camera 102, and <esp-algo> indicates the esp (encryption) algorithm possessed by the digital camera 102. There is a possibility that multiple authentication algorithms and encryption algorithms are possessed. In that case, multiple <ah-algo> tags and multiple <esp-algo> tags are described in order from the algorithm with the highest usage priority. The ah (authentication) algorithm in <ah-algo> and <esp-algo>
As described above, the digital camera 102 transmits the IPsec request message (encrypted communication setting request message) 406 including the security setting candidate information to the security management server 103. In addition, the printer 101 transmits an IPsec request message (encryption communication setting request message) 407 including security setting candidate information to the security management server 103.
As described above, the digital camera 102 and the printer 101 start the encrypted communication path by IPsec between the digital camera 102 and the printer 101 from the received IPsec setting contents.
8 and 9 show the processing flow on the security management server side in this embodiment. 6 and 7 show a part of the program stored in the ROM 1502, HD1507, or FD1508 so that the computer CPU1501 can read it.
FIG. 8 mainly describes the process of receiving the IPsec request message and returning the IPsec setting contents in the request receiving module 302. In particular, a process of establishing a session for peer-to-peer communication between the digital camera 102 and the printer 101, receiving the first IPsec request message from the digital camera 102, and immediately after receiving the IPsec request message from the printer 102 will be described.
1001 is a process for determining the timeout of IPsec request processing. In this IPsec request processing, the IPsec setting contents can be created by receiving the IPsec request messages 406 and 407 from both devices, triggered by establishing a session between the two devices by SIP. Therefore, when the IPsec request message cannot be received from one of the devices for some reason (for example, the IPsec request message 406 from the digital camera 102 is received, but the IPsec request message 407 from the printer 101 cannot be received). In the meantime, the IPsec setting contents cannot be created, and the device 102 that normally sends the IPsec request message keeps waiting for the IPsec setting contents. In order to avoid this situation, the security management server 103 checks the request time value of 504 and the status value of 505 on 1001, and the status is waiting and request. An entry whose time is 5 seconds or more past the current time is judged to be a timeout entry. If it is determined that a timeout has occurred, an error is returned to the digital camera 102 at 1014 and the error ends. If there is no timeout entry, the process proceeds to 1002.
In 1002, the IPsec request message is received, the data of the <level> tag is acquired from the received IPsec request message, and the value is determined. If this value does not match use, require, or unique (that is, the received IPsec request message is not a valid IPsec request), send an error to the source of the IPsec request message at 1016. If any of the above is matched, the process proceeds to 1003.
The security management server 103 is a providing device that provides information necessary for performing security communication to the digital camera (first device) 102 and the printer (second device) 101, and the security management server 103 performs security communication in the 1002. Receive an IPsec request message including candidate parameters for the digital camera 102 and the printer 101. The security management server 103 receives the session ID, which is the identification information for identifying the communication between the digital camera 102 and the printer 101, from the digital camera 102 and the printer 101 in the 1002.
In 1003, the IPsec creation table that already exists in the IPsec creation table 303 is referred to. At this time, the session ID (501) of the IPsec creation table is compared with the <session-id> tag information of the received IPsec request message, and the same IPsec creation table is determined and extracted by 1004. If there is no IPsec creation table that has the same session ID as the received IPsec request message, that is, if the IPsec request message 406 (Fig. 4) from the digital camera 102 is received, processing proceeds to 1005 and the session ID is the same. If the IPsec creation table exists (that is, when the IPsec request message 407 from the printer 101 is received), the process proceeds to 1008.
When the first IPsec request message (IPsec request message 406 from the digital camera 102) is received, a new IPsec creation table is created at 1005. In 1006, the session ID information is acquired from the received IPsec request message, and the time when the IPsec request message is received is also acquired. Furthermore, the above information is stored in 501 and 504, respectively, in the IPsec creation table, and the waiting status value is set in 505. Also, add the device (digital camera 102) information that sent the IPsec request message to the IPsec creation table. Specifically, hostA (502) contains the information from 506 to 512 (Fig. 5) (device ID, address, port, IPsec level, SPI (Security Parameter) of digital camera 102). Index), authentication algorithm, and encryption algorithm) are stored from the received IPsec request message 406. In 1007, the information of the device (printer 101) that is the communication partner of the device that sent the IPsec request message is added to the IPsec creation table created in 1005. Specifically, only the device ID of the communication partner (device ID of the printer 101) is stored in hostB (503). The processing up to this point completes the processing of the IPsec request message from the digital camera 102.
Subsequently, it waits for the reception of the IPsec request message from the printer 101. When the IPsec request message 407 from the printer 101 is received, the processing proceeds as 1001, 1002, 1003, 1004, and the IPsec creation table having the same session ID as the <session-id> tag information of the received IPsec request message is created as the IPsec. It is acquired from the creation table 303 and the process proceeds to 1008. In 1008, the value of the device ID of hostB in the acquired IPsec creation table is compared with the value of <local-host> in the received IPsec request message. In this process, the first IPsec request message (IPsec request message 406 from the digital camera 102) and the IPsec request message received this time (IPsec request message 407 from the printer 102) mutually specify the device ID of the other party. Is determined. That is, the device ID of the printer 101 is specified as <remote-host> in the IPsec request message from the digital camera 102, and the device ID of the digital camera 102 is specified as <remote-host> in the IPsec request message from the printer 101. Checking that it has been done. If they match in this judgment, the process proceeds to 1009, and if not, both the digital camera 102 and the printer 101 return an error at 1015 and end with an error.
In 1009, the device (printer 101) information of the source of the received IPsec request message is added to the IPsec creation table. Specifically, the above-mentioned information (address, port, IPsec level, SPI (Security Parameter Index), authentication algorithm, encryption algorithm of printer 101) of 507 to 512 is sent to hostB (503) from the received IPsec request message. Store, change the request time of 504 to the time when the IPsec request message from printer 101 was received, and change the status of 505 to generating.
In 1010, the IPsec creation module 305 is requested to create an IPsec together with the information of the completed IPsec creation table. The details of this IPsec creation process will be described with reference to FIG. The security management server 103 is a providing device that provides information necessary for performing security communication to the digital camera (first device) 102 and the printer (second device) 101. In this 1010, the digital camera 102 and the printer Based on the authentication algorithm and encryption algorithm (parameter) candidates received from 101, the information required for security communication is generated.
In 1011, it is judged whether the IPsec creation process of 1010 is completed normally, and if it ends with an error, the process proceeds to 1015, and if it ends normally, the IPsec setting contents to be returned to both devices are set. Acquire and proceed to 1012. In 1012, the IPsec setting contents created for both devices (digital camera 102 and printer 101) are encrypted by the encrypted communication module 304 and transmitted to each device by the communication module 301. .. In this 1012, the security management server 103 and the digital camera 102 use the encrypted communication path formed by using the first secret symmetric key owned by each, and the IPsec setting content 409 for the digital camera 102 is set from the security management server 103 to the digital camera. The IPsec setting contents 410 for the printer 101 are transmitted from the security management server 103 to the 102 using the encrypted communication path formed by the security management server 103 and the printer 101 using the second secret symmetric key each possessed. Send to printer 101.
The security management server 103 is a providing device that provides information necessary for performing security communication to the digital camera (first device) 102 and the printer (second device) 101, and the generated IPsec setting contents (security). Information necessary for communication) is transmitted to the digital camera 102 and the printer 101 in this 1012. In this 1012, the security management server 103 transmits the IPsec setting contents to the digital camera 102 and the printer 101 in order to ensure the security of the communication identified by the session ID which is the identification information.
When this transmission process is completed normally, the status value of the IPsec creation table is changed to sent. Finally, delete the corresponding IPsec creation table in 1013. At this time, it is deleted after confirming that the status item of the corresponding IPsec creation table is sent.
FIG. 9 shows the processing in the IPsec setting module 305. In particular, the process of creating IPsec settings for peer-to-peer communication for each of the digital camera 102 and the printer 101 in response to the 1010 IPsec creation request will be described.
The IPsec setting module 305 that has received the IPsec setting request acquires the contents of the entry specified from the IPsec creation table in 1101. From the acquired IPsec creation table information, the sec_level item of the two device information (digital camera 102 information and printer 101 information) is compared with 1102. If there is a mismatch, an error will end. In addition, these information match in the comparison of 1102 in the form of negotiation in order to notify self-information from both devices using SDP in SIP Invite processing and communicate with a common security policy. To do. If the sec_levels set on both devices match, the process proceeds from 1102 to 1103.
In 1103, the data of the ah_algo item is compared from the information of both devices, and it is determined whether or not a common authentication algorithm exists. If there is a common authentication algorithm for the two devices (digital camera 102 and printer 101), the process proceeds to 1104, and if there is no common authentication algorithm, the process proceeds to 1105. In 1104, the authentication algorithm (identifier) common to the two devices is acquired. If the IPsec creation table 303 has the content shown in FIG. 5, in 1104, "hmac-sha1" is acquired.
In 1105, the data of the esp_algo item is compared from the information of both devices, and it is determined whether or not a common encryption algorithm exists. If there is a common encryption algorithm for the two devices (digital camera 102 and printer 101), the process proceeds to 1106, and if there is no common encryption algorithm, the process proceeds to 1107. In 1106, the encryption algorithm (identifier) common to the two devices is acquired. In 1107, it is determined whether a common algorithm was acquired in 1104 or 1106. If the IPsec creation table 303 has the content shown in FIG. 5, in 1107, "3des-cbc" is acquired. Here, if a common authentication algorithm and encryption algorithm cannot be obtained, an error ends.
In 1108, a key suitable for each of the authentication algorithms and encryption algorithms acquired in 1104 and 1106 is generated. Key generation is generated using random numbers and adjusted to a key length suitable for the algorithm. The details of the relationship between the algorithm and the key length will be described later. The security management server 103 is a providing device that provides information necessary for performing security communication to the digital camera (first device) 102 and the printer (second device) 101, and receives the information from the digital camera 102 and the printer 101. Generates information (authentication algorithm, encryption algorithm, and key used for security communication between digital camera 102 and printer 101) for security communication based on authentication algorithm and encryption algorithm (parameter) candidates. ..
In 1109, appropriate data is input to the template data of the IPsec setting contents from each information of the IPsec creation table acquired in 1101, each algorithm related to IPsec acquired / generated in 1104, 1106, and 1108, and its key information. , Create the IPsec settings. The details of the IPsec setting content template will be described with reference to FIG. The created IPsec setting content is completed at 1110 as the IPsec setting content of the hostA side device (digital camera 102).
Then, in 1111, a part of the IPsec setting contents created in 1109 is modified. The specific modification is to replace the description of "in" and "out" that specify the direction of communication in the SP (Security Policy) settings. The IPsec setting contents modified in 1111 will be completed in 1112 as the IPsec setting contents of the hostB side device (printer 101).
The key lengths corresponding to the authentication algorithm and the encryption algorithm in the above-mentioned 1108 processing are as follows. For example, when "hmac-sha1" is selected as the authentication algorithm, a key having a length of 160 bits is generated as a key corresponding to this authentication algorithm. If "3des-cbc" is selected as the encryption algorithm, a 64-bit length key is generated as the key corresponding to this encryption algorithm. If the authentication algorithm is "hmac-md5", a 128-bit key will be generated. Some algorithms, such as "blowfish-cbc", can generate keys with arbitrary bit lengths from 40 bits to 448 bits, and "rijndael-cbc", 128 bits, 192. Some use either bit or 256 bit length.
FIG. 10 shows an example of the IPsec setting template in the above-mentioned processing of 1109. The IPsec setting template is described according to the format of the "setkey" command that sets IPsec, but is not limited to this format. The first and second lines show SP (Security Policy) information, and the third to sixth lines show SA (Security Association) information. By substituting the IPsec creation table and the key information generated earlier into the <> item in the figure, the IPsec setting contents are completed. The meaning of each item will be described below.
The IPv6 address of the hostA side device is assigned to <A_addr>, and the IPv6 address of the hostB side device is assigned to <B_addr>. Substitute the port number of the hostA side device for <A_port>, and substitute the port number of the hostB side device for <B_port>.
Substitute the common algorithm type acquired in 1104 and 1106 above for <sec_type>. In other words, if the authentication algorithm and encryption algorithm common to the two devices can be obtained, "ah" and "esp" are substituted, and if only the authentication algorithm can be obtained, "ah" is substituted for encryption. If only the conversion algorithm can be obtained, substitute "esp". Substitute sec_level common to both devices for <sec_level>. The authentication algorithm and the encryption algorithm are selected from the candidates of the authentication algorithm and the encryption algorithm (parameters for performing security communication) received from the digital camera 102 and the printer 101.
If "ah" and "esp" are specified for sec_type (that is, when both authentication and encryption are used), "<sec_type> / transport // <sec_level>" is set repeatedly. That is, it is described as "~ ah / transport // require esp / transport // require ~". This example describes that authentication and encryption are mandatory.
Substitute the SPI (Security Parameter Index) of the hostA side device for <A_spi>, and substitute the SPI (Security Parameter Index) of the hostB side device for <B_spi>.
If only ah is used in sec_type, the SA registration related to esp in the 4th and 6th lines is deleted, and if only esp is used in sec_type, the SA registration related to ah in the 3rd and 5th lines is deleted. ..
Also, when both ah and esp are used in sec_type, a specific line is not deleted from the template, and a different value is assigned to multiple <A_spi> and <B_spi> by adding +1. That is, when the SPI (Security Parameter Index) of the hostA side device is 0x834, "0x834" is assigned to <A_spi> on the fifth line, and "0x835" is assigned to <A_spi> on the sixth line. Then, substitute the authentication algorithm and encryption algorithm common to both devices acquired in 1104 and 1106 for <ah_algo> and <esp_algo>, respectively, and use 1108 for authentication and encryption for <ah_key> and <esp_key>. Substitute each generated key. The authentication and encryption keys are generated based on the authentication algorithm and encryption algorithm (parameters for performing security communication) candidates received from the digital camera 102 and the printer 101.
FIG. 11 shows an example of IPsec setting contents. In particular, the data in the figure shows the IPsec setting contents transmitted to the digital camera 102. The data is described in XML format and is enclosed in the <ipsec-data> tag inside the <ipsec-response> tag. In this embodiment, it is not important to convert this data format to XML format, and there is no problem in the data transmission method using other formats.
As described above, the security management server 103 acquires the authentication algorithm and the encryption algorithm (security setting candidate information) of the digital camera 102 included in the IPsec request message (encryption communication setting request message) 406 from the digital camera 102, and the printer. IPsec request message from 101 (encryption communication setting request message) Acquires security setting candidate information possessed by printer 101 included in 407 (authentication algorithm, encryption algorithm).
When the security management server 103 receives the IPsec request message 406 from the digital camera 102 and the IPsec request message 407 from the printer 101, the security management server 103 sets the IPsec settings for each of the digital camera 102 and the printer 101 (encryption key (session key) used for encrypted communication). ) And security setting information) (1108 ~ 1112).
The security management server 103 transmits the IPsec setting content 409 for the digital camera 102 to the digital camera 102, and transmits the IPsec setting content 410 for the printer 101 to the printer 101.
<figref num="1">It is a network block diagram of the Embodiment of this invention.</figref><figref num="2">It is a hardware block diagram for operating the software program which realizes the function in this embodiment.</figref><figref num="3">It is a module block diagram of the printer 101 and the security management server 103.</figref><figref num="4">It is a sequence diagram of this embodiment.</figref><figref num="5">It is a figure of an example of the IPsec creation table 303.</figref><figref num="6">It is a processing flow diagram which performs IPsec request request from SIP Invite processing to request issuing module 312 in SIP module 315.</figref><figref num="7">It is a processing flow diagram centering on the processing of the request issuing module 312 which received an IPsec request request.</figref><figref num="8">FIG. 5 is a processing flow diagram centered on processing from receiving an IPsec request message to returning an IPsec setting content in the request receiving module 302.</figref><figref num="9">It is a processing flow diagram in IPsec setting module 305.</figref><figref num="10">It is a figure which shows an example of the IPsec setting template.</figref><figref num="11">It is a figure which shows an example of the IPsec setting contents.</figref>
Code description
100 Internet 101 Printer 102 Digital Still Camera (Digital Camera) 103 Security Management Server
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2012253817A | Cited by | Japan | Examiner |
| US8468353B2 | Cited by | United States of America | Applicant |
| JP2009524369A | Cited by | Japan | Examiner |
| JP2010217595A | Cited by | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004104635 | Japan | A | |
| JP20040104635 | – | – | – |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 | |
| Written amendmentA521 | A521 |
Numbers
- Publication
- 2005295038
- Publication, DOCDB
- 2005295038
- Publication, EPODOC
- JP2005295038
- Application
- 104635
- Application, DOCDB
- 2004104635
- Application, EPODOC
- JP20040104635
Titles3
- English
- Providing device, providing method, communication device, communication method, and program
- Japanese
- 提供装置、提供方法、通信装置、通信方法、及び、プログラム
- English
- PROVIDING APPARATUS, PROVIDING METHOD, COMMUNICATION APPARATUS, COMMUNICATION METHOD, AND PROGRAM
Classification
- CPC, 3
- H04L63/061
- G06Q20/382
- H04L63/0272
- IPC, 3
- H04L12 28
- H04L9 00
- H04L29 06