Wireless communication device, program and method
Abstract
[Subject] The wireless-radios machine which updates an encryption key to more suitable timing is offered. [Solution means] The access point equipment in this case of the operation has a function which sends out the picture image data from an analog television signal to a notebook PC. When the channel of the analog television signal concerned is changed, with this access point equipment (Step 310), TCP communication is stopped (Step 314), and after performing renewal of attestation (Step 302) and an encryption key, TCP connection is established based on (Step 303) and this new encryption key. (Step 305). [Selection figure] Fig. 3
Term
Term ended
Projected expiry passed 27 December 2024, 1.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
8 claims: 4 independent, 4 dependent
- 1In a wireless communication device that wirelessly transmits data from a plurality of data sources to another device, an authentication means for authenticating with the other device and the data from the data source are encrypted using an encryption key. The encryption means, the communication means for transmitting the data encrypted by the encryption means to the other device authenticated by the authentication means, and the data for supplying the data to be transmitted to the other device. A wireless communication device including a switching means for switching sources and an encryption key updating means for updating the encryption key used by the encryption means when the data source is switched by the switching means. 複数のデータソースからのデータを他の機器に無線で送信する無線通信機器において、 前記他の機器との認証を行う認証手段と、 前記データソースからの前記データを暗号鍵を用いて暗号化する暗号化手段と、 前記暗号化手段により暗号化された前記データを、前記認証手段により認証された前記他の機器に送信する通信手段と、 前記他の機器に送信する前記データを供給する前記データソースを切り換える切替手段と、 前記切替手段により前記データソースが切り換えられた際に、前記暗号化手段が使用する前記暗号鍵を更新する暗号鍵更新手段とを備えることを特徴とする無線通信機器。
- 4Any of claims 1 to 3, wherein the encryption key updating means newly generates the encryption key used by the encryption means when the data source is switched by the switching means. The wireless communication device described in item 1. 前記暗号鍵更新手段は、前記切替手段により前記データソースが切り替えられた際に、前記暗号化手段が使用する前記暗号鍵を新たに生成することを特徴とする請求項1乃至請求項3のいずれか1項記載の無線通信機器。
- 5In a program that controls a wireless communication device that wirelessly transmits data from a plurality of data sources to another device, an authentication function that authenticates with the other device and the data from the data source are encrypted using an encryption key. The encryption function for encrypting the data, the communication function for transmitting the data encrypted by the encryption means to the other device authenticated by the authentication function, and the data to be transmitted to the other device. It is characterized by having a switching function for switching the data source to be supplied and an encryption key update function for updating the encryption key used in the encryption function when the data source is switched by the switching function. program. 複数のデータソースからのデータを他の機器に無線で送信する無線通信機器を制御するプログラムにおいて、 前記他の機器との認証を行う認証機能と、 前記データソースからの前記データを暗号鍵を用いて暗号化する暗号化機能と、 前記暗号化手段により暗号化された前記データを、前記認証機能により認証された前記他の機器に送信する通信機能と、 前記他の機器に送信する前記データを供給する前記データソースを切り換える切替機能と、 前記切替機能により前記データソースが切り換えられた際に、前記暗号化機能で使用する前記暗号鍵を更新する暗号鍵更新機能とを備えることを特徴とするプログラム。
- 7In a wireless communication method in which data from a plurality of data sources is wirelessly transmitted to another device, an authentication step for authenticating with the other device and the data from the data source are encrypted using an encryption key. The data source was switched by the communication step of transmitting to the other device authenticated in the authentication step, the switching step of switching the data source for supplying the data to be transmitted to the other device, and the switching step. A wireless communication method comprising:an encryption key update step for updating the encryption key used for encryption in the communication step. 複数のデータソースからのデータを他の機器に無線で送信する無線通信方法において、 前記他の機器との認証を行う認証ステップと、 前記データソースからの前記データを暗号鍵を用いて暗号化し、前記認証ステップで認証された前記他の機器に送信する通信ステップと、 前記他の機器に送信する前記データを供給する前記データソースを切り換える切替ステップと、 前記切替ステップにより前記データソースが切り換えられた際に、前記通信ステップで暗号化に使用する前記暗号鍵を更新する暗号鍵更新ステップとを備えることを特徴とする無線通信方法。
Independent claims4
39 paragraphs, as filed
The present invention relates to a wireless communication device such as an access point device used in a wireless LAN system, a program for controlling the wireless communication device, and a wireless communication method.
In recent years, a wireless LAN system in which a terminal wirelessly communicates via an access point device has rapidly become widespread. Compared to wired systems, such wireless systems do not require wiring and are highly expandable, but on the other hand, data can be received anywhere within the range of radio waves, and it is difficult to limit communication destinations, so security. Is an important issue. In the IEEE802.11 standard, a WEP (Wired Equivalent Privacy) encryption key method is adopted to prevent communication data from being stolen by a third party. Recently, encryption methods such as TKIP (Temporal Key Integrity Protocol), WRAP (Wireless Robust Authenticated Protocol), and CCMP (Counter mode with CBC-MAC) have also been adopted by WPA (Wi-Fi Protected Access) and IEEE 802.11i. There is.
Further, in order to further improve the security, a system that updates the encryption key for each communication has been considered (see, for example, Patent Document 1). Patent Document 1 proposes a method of using a different encryption key each time by generating an encryption key on the access point device side for each communication and transmitting this to the station terminal side. The mechanism for arbitrarily updating the encryption key in this way is also defined in WPA, IEEE 802.11i, etc. mentioned above.
On the other hand, wireless LAN has a relatively high throughput of 11 Mbps for IEEE802.11b and 54 Mbps for IEEE802.11a and IEEE802.11g, so it is not only for general data communication but also for real-time performance such as video data such as TV and video. It is also used as a means of transmitting high data.
<patcit num="1"><text>Japanese Unexamined Patent Publication No. 11-234260</text></patcit>
<p> However, in the method described in Patent Document 1, the encryption key cannot be updated unless the user disconnects. Therefore, for example, when the user continues to use the connection at all times, the encryption key is not updated during that time.</p><p> In order to improve the security of data, it is conceivable to forcibly update the encryption key every time a certain period of time elapses or every time more than a certain number of packets are communicated. However, in such a method, a new encryption is used. In order to generate a key and make a connection based on this encryption key, it is necessary to disconnect once. That is, the user cannot send or receive data during that time. This problem becomes particularly remarkable when data with high real-time performance is transmitted as described above, for example, when a user is viewing video data of a television or the like via a wireless LAN.</p><p> Therefore, an object of the present invention is to provide a wireless communication device that updates an encryption key at a more suitable timing.</p>
<p> In order to achieve the above object, the wireless communication device of the present invention includes an authentication means for authenticating with the other device in a wireless communication device that wirelessly transmits data from a plurality of data sources to the other device. An encryption means that encrypts the data from the data source using an encryption key, and a communication means that transmits the data encrypted by the encryption means to the other device authenticated by the authentication means. And the switching means for switching the data source for supplying the data to be transmitted to the other device, and updating the encryption key used by the encryption means when the data source is switched by the switching means. It is characterized by being provided with an encryption key update means.</p><p> The program of the present invention is a program for controlling a wireless communication device that wirelessly transmits data from a plurality of data sources to another device, and has an authentication function for authenticating with the other device and the said from the data source. An encryption function that encrypts data using an encryption key, a communication function that transmits the data encrypted by the encryption means to the other device authenticated by the authentication function, and the other device. A switching function for switching the data source for supplying the data to be transmitted to the data source and an encryption key update function for updating the encryption key used in the encryption function when the data source is switched by the switching function. It is characterized by being prepared.</p><p> The wireless communication method of the present invention is a wireless communication method for wirelessly transmitting data from a plurality of data sources to another device, in which an authentication step for authenticating with the other device and the data from the data source are transmitted. A communication step of encrypting using an encryption key and transmitting the data to the other device authenticated in the authentication step, a switching step of switching the data source for supplying the data to be transmitted to the other device, and the switching step. It is characterized by including an encryption key update step for updating the encryption key used for encryption in the communication step when the data source is switched.</p>
<p> According to the present invention, it is possible to provide a wireless communication device that updates an encryption key at a more suitable timing.</p>
Hereinafter, the wireless communication device of the present invention, a program for controlling the wireless communication device, and a wireless communication method will be described with reference to the drawings.
FIG. 1 is a diagram showing a configuration of a communication system including an access point device according to an embodiment of the wireless communication device of the present invention. This communication system is composed of a notebook PC (Personal Computer) 10, an access point device 11 that communicates with the notebook PC 10 by wireless LAN, and a network 13 that is connected to the access point device 11 via a wired LAN cable 12. To. In this communication system, wireless communication between the notebook PC 10 and the access point device 11 is performed in accordance with the IEEE802.11, IEEE802.11a, and IEEE802.11i standards.
The notebook PC 10 performs wireless communication with the access point device 11 by wireless LAN. The notebook PC1-can be connected to the network 13 via the access point device 11, and can receive and view video data transmitted from the access point device 11. The notebook PC 10 has a function of encrypting and decrypting data when exchanging data with the access point device 11.
The access point device 11 is a relay device that relays between the notebook PC 10 and the network 13, and while forming a wireless service area for wireless LAN for the notebook PC 10, it is accommodated in the network 13 by a wired LAN cable 12. There is. It has a function to encrypt and decrypt data when sending and receiving data to and from the notebook PC 10.
Further, an analog TV signal can be input to the access point device 11. The notebook PC 10 can receive and view video data by the analog TV signal by wireless LAN communication. The channel of the analog TV signal input to the access point device 11 is switched by the remote controller 14.
FIG. 2 is a block diagram showing the configuration of the access point device 11. The access point device 11 is input with an MPU (Micro Processing Unit) 20, a ROM (Read Only Memory) 21, a RAM (Random Access Memory) 22, an RTC (Real Time Clock) 23 for generating time information, and an analog TV signal. It consists of a TV tuner unit 24, an encoder 25 that converts and encodes analog TV signals to digital, a remote control interface 26, a wired LAN interface 27, and a wireless LAN interface 28.
The MPU20 is a processor provided to comprehensively control the operation of the entire access point device 11, has a function of authenticating the notebook PC 10 via the wireless LAN interface 28, and encrypts / decrypts data sent / received to / from the notebook PC 10. Function, a control function that decodes the operation signal input from the remote control interface 26 and switches the channel of the TV tuner unit 24, and notes the video data created by the encoder 25 via the wireless LAN interface 28 according to the request of the notebook PC 10. Execute various programs that have a function to control transmission to PC10.
ROM 21 is a non-volatile memory in which the above program is stored, and RAM 22 is used as a work memory in executing the above program. RTC23 is an IC (Integrated Circuite) dedicated to timekeeping and generates time information. The MPU20 records the time when communication with the notebook PC 10 is started in RAM22, and by comparing this communication start time with the time information generated by RTC23, the elapsed time from the start of connection with the notebook PC10 is calculated. Can be calculated.
The TV tuner unit 24 switches the channel of the analog TV signal input from the outside and selects only one. This switching is controlled by the MPU 20 in response to an operation by the user's remote controller 14.
The encoder 25 is an encoder IC for digitally converting an analog TV signal input via the TV tuner unit 24, performing A / D conversion and performing encoding processing for data compression. The created video data is, for example, encoded in MPEG2 (Moving Picture Experts Group phase 2).
The remote control interface 26 is an interface for receiving an infrared remote control signal based on an operation performed by the user by the remote control 14 and transmitting the infrared remote control signal to the MPU 20. When the user switches the channel with the remote controller 14, the remote controller interface 26 receives the remote controller signal and transmits the remote controller signal to the MPU 20. The MPU2- switches the channel of the TV tuner unit 24 based on this.
The wired LAN interface 27 is an interface for connecting to the network 13 via the wired LAN cable 12. The wireless LAN interface 28 is an interface for communicating with the notebook PC 10 by wireless LAN. Under the control of the MPU 20, the wireless LAN interface 28 transmits data from the network 13 connected by the wired LAN interface 27 to the notebook PC 10, and transmits video data encoded by the encoder 25 to the notebook PC 10.
Subsequently, the processing flow of the access point device 11 related to the connection and communication with the notebook PC 10 will be described. FIG. 3 is a flowchart showing a flow of processing related to connection and communication with the notebook PC 10 of the program controlling the access point device 11. In the description in this figure, TCP / IP (Transmission Control Protocol / Internet Protocol) and HTTP (HyperText Transfer Protocol) are used for data transmission / reception. It is assumed that the IP address has a preset value that can be interconnected.
First, the access point device 11 receives the connection request from the notebook PC 10 by the wireless LAN interface 28 (step 301). This connection process is a wireless connection specified by IEEE 802.11, and connection requests are made in the flow of join, authentication, and association. Here, join is a process of synchronizing the notebook PC 10 and the access point device 11, and authentication is an open system authentication. The association completes the logical connection.
After the logical connection is established in step 301, authentication and encryption key generation are performed. (Step 302, Step 303). This authentication and encryption key generation are the authentication encryption methods specified in IEEE802.11i, and EAP-TLS authentication using digital certificates and session encryption key generation and encryption keys called 4-way handshake and group key handshake. Has a delivery step. In 4-way handshake, the key information used for one-to-one communication with the notebook PC 10 is generated, and in group way handshake, the encryption key used for broadcast communication is generated by MPU20 of the access point device 11. And deliver it to the notebook PC 11.
After generating the encryption key, the communication start time with the notebook PC 10, that is, the use start time of the encryption key created in step 303 is recorded in RAM22 with reference to RTC23 (step 304). By comparing this start time with RTC23, it is possible to know the usage time of the encryption key.
Next, based on the encryption key created in step 303, a TCP connection is established between the wireless LAN interface 28 and the notebook PC 10 (step 305). By establishing a TCP connection, data can be exchanged with and from the notebook PC 10.
After the TCP connection is established, if the GET command, which is a data request command defined by HTTP, is received from the notebook PC 10 on the wireless LAN interface 28 (step 306), the data is transmitted from the wireless LAN interface 28 in response to this. Start (step 307). Here, it is assumed that the data transmitted from the wireless LAN interface 28 is the video data in which the analog TV signal is encoded by the encoder 25 and encrypted by using the encryption key created in step 303.
After transmitting the data, it is determined whether or not the ACK indicating that the data has been received is received from the notebook PC 10 via the wireless LAN interface 28 (step 308). If no ACK is returned (No in step 308), wait for ACK to be received. If it receives an ACK (Yes in step 308), it determines if there is more data to send to the notebook PC 10 (Step 309). If there is no subsequent data (No in step 309), the process ends.
If there is still data to be sent to the notebook PC 10 (Yes in step 309), whether or not the encryption key created in step 303 has been used for a predetermined time or more, or whether or not the user has switched channels. Determine (step 310). The elapsed time can be calculated by comparing the communication start time recorded in the RAM in step 304 (that is, the use start time of the encryption key) with the time of RTC23. Further, the channel switching is determined by whether or not the remote control signal related to the channel switching is received by the remote control interface 26. When the remote control signal for channel switching is received by the remote control interface 26, the channel of the TV tuner unit 24 is switched in response to this remote control signal.
According to the judgment in step 310, if the predetermined time has not passed and the channel has not been switched (No in step 310), it is judged that the encryption key does not need to be updated yet, and the subsequent data is transmitted. (Step 307). When the predetermined time has elapsed, or when the channel is switched (Yes in step 310), the process for updating the encryption key is started. First, the communication start time recorded in the RAM 22 (that is, the use start time of the encryption key created in step 303) is deleted (step 311).
Then, the data in which the flag (no-data) indicating that there is no more data is set in the header is transmitted from the wireless LAN interface 28 to the notebook PC 10 (step 312). After that, it is determined whether or not the ACK indicating that this data has been received is returned from the notebook PC 10 to the wireless LAN interface 28 (step 313). If ACK is not returned (No in step 313), wait for ACK to be received. If an ACK is returned from the notebook PC 10 (Yes in step 313), the TCP connection with the notebook PC 10 is disconnected (step 314), and after authentication (step 302), a new encryption key is generated (step 303). , TCP communication based on this new encryption key is performed with the notebook PC 10.
As described above, according to the present embodiment, the encryption key is updated based on the reception of the remote control signal related to the channel switching on the remote control interface 26. Since the video data does not have continuity at the time of channel switching, it is possible to suppress the hindrance to the user's data transmission / reception by simultaneously disconnecting the TCP connection and updating the encryption key at this timing.
In addition, the user is forced to update the encryption key not only when the channel is switched but also when the elapsed time from the start of using the encryption key exceeds a certain predetermined time. Even if the user continues to watch the video data of the same channel, the encryption key is updated regularly, which can improve the security.
Instead of time, the number of packets of data sent from the wireless LAN interface 28 to the notebook PC 10 may be measured by a program executed by the MPU 20. In this case as well, the same effect can be obtained by forcibly updating the encryption key when a certain number of packets is exceeded.
In this embodiment, authentication is performed every time the encryption key is updated, and the encryption key is regenerated. Therefore, compared with a method in which one key is selected from several predetermined keys for communication. It is safer.
In this embodiment, only the analog TV signal is accepted, but other than that, for example, switching between a video signal and a TV signal may be used. Alternatively, it is possible that the input video signal is digital, in which case the encoder 25 is not always necessary.
Alternatively, it does not necessarily have to be video data, and may be audio data such as radio data. Further, in this embodiment, the analog TV signal channel of the TV tuner unit 24 is switched by transmitting the remote control signal from the remote control 14 to the remote control interface 26, but in addition, wireless from the notebook PC 10 by wireless LAN communication. It may be possible to control via the LAN interface 28.
<figref num="1">The figure which shows the structure of the communication system including the access point apparatus which concerns on Example 1 of this invention.</figref><figref num="2">The block diagram which shows the structure to the access point apparatus which concerns on Example 1 of this invention.</figref><figref num="3">The flowchart which shows the flow of the process which concerns on connection and communication with a notebook PC of the program which controls the access point apparatus which concerns on Example 1 of this invention.</figref>
Code description
10 Notebook PC 11 Access point device 12 Remote control 13 Wired LAN cable 14 Network 20 MPU21 ROM22 RAM23 RTC24 TV Tuner unit 25 Encoder 26 Remote control interface 27 Wired LAN interface 28 Wireless LAN interface
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2010245839A | Cited by | Japan | Examiner |
| JP2018061118A | Cited by | Japan | Search report |
| JP2008042490A | Cited by | Japan | Search report |
| JP2008011176A | Cited by | Japan | Search report |
| JP2011087249A | Cited by | Japan | Search report |
| JP2008042490A | Cited by | Japan | Search report |
| JP2011087249A | Cited by | Japan | Search report |
| JP2011087249A | Cited by | Japan | Examiner |
| JP2011507318A | Cited by | Japan | Examiner |
| US8515073B2 | Cited by | United States of America | Applicant |
| JP2004254286A | Cites | Japan | Examiner |
| JPH07274084A | Cites | Japan | Examiner |
| JPH1084536A | Cites | Japan | Examiner |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004375445 | Japan | A | |
| JP20040375445 | – | – | – |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalA02 | A02 | |
| Notification of reasons for refusalA131 | A131 | |
| Written amendmentA521 | A521 | |
| Notification of acceptance of power of attorneyRD02 | RD02 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 | |
| Written amendmentA521 | A521 | |
| Written request for application examinationA621 | A621 | |
| Notification of acceptance of power of attorneyRD02 | RD02 |
Numbers
- Publication
- 2006186470
- Publication, DOCDB
- 2006186470
- Publication, EPODOC
- JP2006186470
- Application
- 375445
- Application, DOCDB
- 2004375445
- Application, EPODOC
- JP20040375445
Titles3
- Japanese
- 無線通信機器、プログラム、及び無線通信方法
- English
- Wireless communication devices, programs, and wireless communication methods
- English
- WIRELESS COMMUNICATION DEVICE, PROGRAM AND METHOD
Classification
- CPC, 3
- H04L9/0891
- H04L9/321
- H04L2209/80
- IPC, 1
- H04L9 16