Management device, program, system, and method
Abstract
Problem to be solved.To efficiently transmit information to a plurality of devices. A management device according to an embodiment is a management device that can be connected to a plurality of devices via a network. The management device includes a tree storage unit, a similarity calculation unit, an allocation unit, and an allocation transmission unit. The tree storage unit stores the management tree information in which the node key is assigned to the node and the device is assigned to the leaf node. The similarity calculation unit calculates the similarity between the attribute information representing the attribute of the new device and the attribute information of the device assigned to the management tree information. The allocation unit determines the leaf node to which the new device is assigned in the management tree information based on the similarity. The allocation transmitter transmits at least one node key assigned to the path from the root node to the corresponding leaf node in the management tree information to the new device. [Selection diagram] Fig. 5

Term
Projected expiry 2 November 2037.
- Priority and filed
- Published
- Today
- Projected expiry
8 claims: 5 independent, 3 dependent
- 1複数の機器にネットワークを介して接続可能な管理装置であって、 第1の機器の属性情報である第1属性情報を受け取り、 第1のリーフノードより最も近い第2のリーフノードに割り当てることで構成された木構造のグラフのルートノードから前記第2のリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信し、 前記第1のリーフノードは第2の機器が割り当てられたノードであり、 前記第2の機器は、前記第2の機器の属性情報である第2属性情報が前記第1属性情報と一致する機器である 管理装置。
- 2前記木構造のグラフのルートノードから前記第1のリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を更に送信する 請求項1に記載の管理装置。
- 3複数の機器にネットワークを介して接続可能な管理装置であって、 前記複数の機器の少なくとも1以上の機器の属性情報を受け取り、 木構造のグラフのルートノードから各リーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信し、 前記木構造のグラフは、前記複数の機器のうち、前記受け取った属性情報が一致する機器を第1のリーフノードに割り当てられたものであり、かつ、前記複数の機器のうち、前記受け取った属性情報が一致しない機器を第2のリーフノードに割り当てられたものである 管理装置。
- 4複数の機器にネットワークを介して接続可能な管理装置であって、 第1の機器の識別情報を受け取り、前記第1の機器の識別情報と、1以上の第2の機器の識別情報に基づき構成された木構造のグラフのルートノードからリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信する 管理装置。
- 5複数の機器にネットワークを介して接続可能な管理装置であって、 第1の機器の属性情報を受け取り、前記第1の機器の属性情報と、1以上の第2の機器の属性情報に基づき構成された木構造のグラフのルートノードからリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信する 管理装置。
- 6情報処理装置を、請求項1から5の何れか1項に記載の管理装置として機能させるためのプログラム。
- 7請求項1から5の何れか1項に記載の管理装置と、ネットワークを介して接続可能な複数の機器とを備えるシステム。
- 8複数の機器にネットワークを介して接続可能な管理装置において実行される方法であって、 前記管理装置が、第1の機器の属性情報である第1属性情報を受け取り、 前記管理装置が、第1のリーフノードより最も近い第2のリーフノードに割り当てることで構成された木構造のグラフのルートノードから前記第2のリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信し、 前記第1のリーフノードは第2の機器が割り当てられたノードであり、 前記第2の機器は、前記第2の機器の属性情報である第2属性情報が前記第1属性情報と一致する機器である 方法。
Independent claims8
170 paragraphs, as filed
0001Embodiments of the present invention relate to management devices, programs, systems and methods.
0002A key shared and held by some of a plurality of devices is called a group key. By encrypting the data using such a group key, the data can be transmitted to the devices belonging to the group and the data can be kept secret from the devices not belonging to the group. Further, the key for distributing the group key to each device, and the key distributed to each device is called a device key.
0003A method of managing a device key using management tree information, which is data representing a graph of a tree structure, is known. In this method, a node key is assigned to each node in the management tree information, and a device is assigned to the leaf node. In this method, all node keys assigned to the path from the root node to the corresponding leaf node are distributed to each device. Then, in this method, the device stores all the distributed node key pairs as device keys. At the time of distribution, the group key is encrypted by any one or more node keys included in the device key.
0004By the way, when a new device is connected in the system, the management device that manages the management tree information must distribute the node key and the group key to the new device. In this case, the management device must assign a new device to the management tree information so that information can be efficiently transmitted to a plurality of devices belonging to the same group.
<p num="0005"><patcit num="1"><text>Japanese Unexamined Patent Publication No. 2012-204897</text></patcit><patcit num="2"><text>International Publication No. 02/080448</text></patcit><patcit num="3"><text>Japanese Patent Application Laid-Open No. 2005-198116</text></patcit></p>
<p num="0006"> An object to be solved by the present invention is to allocate devices to management tree information so that information can be efficiently transmitted to a plurality of devices.</p>
<p num="0007"> The management device according to the embodiment can be connected to a plurality of devices via a network. The management device receives the first attribute information which is the attribute information of the first device. The management device is at least one node assigned to the path from the root node of the tree-structured graph configured by assigning it to the second leaf node closest to the first leaf node to the second leaf node. Send the key. The first leaf node is a node to which a second device is assigned. The second device is a device in which the second attribute information, which is the attribute information of the second device, matches the first attribute information.</p>
0008<figref num="1">The block diagram of the communication system which concerns on embodiment.</figref><figref num="2">The figure which shows an example of management tree information.</figref><figref num="3">The figure which shows an example of a group.</figref><figref num="4">The figure which shows the attribute information which is transmitted from a device to a management device.</figref><figref num="5">The figure which shows the transmission example of the node key determined based on the attribute information.</figref><figref num="6">The figure which shows the structure of the management apparatus.</figref><figref num="7">The figure which shows the structure of a device.</figref><figref num="8">The figure which shows the element included in the attribute information.</figref><figref num="9">The sequence diagram of the communication system which concerns on embodiment.</figref><figref num="10">Flowchart of management device allocation process.</figref><figref num="11">The flowchart which shows an example of the process in step S25 of FIG.</figref><figref num="12">The figure which shows the 1st allocation example.</figref><figref num="13">The figure which shows the 2nd allocation example.</figref><figref num="14">The figure which shows the 1st example of the management tree information before expansion.</figref><figref num="15">The figure which shows the example which expanded the upper layer.</figref><figref num="16">The figure which shows the 2nd example of the management tree information before expansion.</figref><figref num="17">The figure which shows the example which expanded the lower layer.</figref><figref num="18">The figure which shows the example which expanded the intermediate layer.</figref><figref num="19">The figure which shows the example which expanded the lower layer of one leaf node.</figref><figref num="20">The figure which shows the example which extended the layer between one leaf node and root node.</figref><figref num="21">The figure which shows the management tree information before reconstruction.</figref><figref num="22">The figure which shows the management tree information after reconstruction.</figref><figref num="23">The figure which shows the hardware configuration of a management device.</figref>
0009Hereinafter, the communication system according to the embodiment will be described in detail with reference to the drawings. In the transmission system according to the present embodiment, devices can be assigned to the management tree information so that information such as a group key can be efficiently transmitted to a plurality of devices.
0010In this embodiment, an encryption key for encrypting data is used. As an algorithm for encrypting and decrypting data with an encryption key, a symmetric key cryptosystem such as AES may be used, or an asymmetric key cryptosystem (public key cryptosystem) may be used.
0011FIG. 1 is a diagram showing a configuration of a communication system 10 according to an embodiment. The communication system 10 includes a management device 20 and a plurality of devices 30 (30-A to 30-F).
0012The management device 20 and the plurality of devices 30 can be connected to each other via a network. The network is, for example, a LAN formed in the home. Further, the network may include a public line such as the Internet or a VPN (Virtual Private Network). Further, as the physical layer and the link layer, various forms such as wireless LAN conforming to IEEE802.11, Ethernet (registered trademark), and IEEE1394 can be applied to the network.
0013The management device 20 is an information processing device such as a computer. The management device 20 executes a predetermined program on the operating system, and is always running, for example.
0014The device 30 is a device having a communication function and an information processing function. For example, the device 30 may be an electric appliance (air conditioner, television device, refrigerator, etc., which can be connected to a network) used at home. Further, the device 30 may be a portable information device such as a smartphone, a tablet or a notebook computer.
0015In the communication system 10, data is transmitted between the management device 20 and the device 30, or between the device 30 and the device 30. The data to be transmitted is, for example, a control command for controlling the operation of the device 30, a key value used by the management device 20 or the device 30 for encryption or authentication, key identifier information, and the management device 20 or the device 30. Identification information (MAC address, IP address, etc.), etc. Further, the transmitted data may be moving image data, audio data, text data, program code, or the like.
0016Such data is encrypted with a group key. The group key is a key commonly held by the devices 30 belonging to the group.
0017The management device 20 sets a group for a plurality of devices 30 connected to the network according to, for example, an instruction from a user or a preset rule. The management device 20 may set a plurality of groups. Further, the management device 20 may make one device 30 belong to a plurality of groups. In addition, there may be a device 30 that does not belong to the group. The management device 20 assigns a unique group key to each group. By encrypting the data with the group key and transmitting the data to the network, the management device 20 can have the device 30 belonging to the group acquire the data and conceal the data from the device 30 not belonging to the group.
0018Further, the management device 20 encrypts the group key with the node key assigned to each device 30 and gives the group key to the device 30. The node key is a key shared by the management device 20 and the device 30. One device 30 holds at least one set of node keys as a device key. The management device 20 manages the node keys held by each device 30 by using the management tree information representing the tree structure (undirected graph having no loop). The management device 20 may encrypt the data with the node key and transmit the data to the device 30.
0019FIG. 2 is a diagram showing an example of management tree information. The management tree information includes a plurality of nodes (circled in FIG. 2) and a plurality of edges connecting the nodes. One node at the top of the tree structure is called the root node. In addition, each node arranged at the end (lowest layer) of the tree structure is called a leaf node.
0020Each node is assigned a unique node number. In the example of FIG. 2, the numbers in the circles indicate the node numbers.
0021The management device 20 assigns a node key to each node. The node key is different for each node. In the example of FIG. 2, the management device 20 assigns the node keys of K1 to K15 to the nodes having the node numbers 1 to 15.
0022Further, the management device 20 assigns each device 30 to any leaf node. The management device 20 allocates one device 30 to one leaf node, and does not allocate a plurality of devices 30 to one leaf node in duplicate. The management tree information may include an empty leaf node to which none of the devices 30 is assigned. In the example of FIG. 2, the management device 20 assigns the device 30 of the identification information A, B, C, D, E, F to the node of the node number 8,9,10,11,13,15.
0023Further, the management device 20 is assigned to each device 30 at least one node key (for example, the root node) assigned to the path from the root node in the management tree information to the corresponding leaf node to which the device 30 is assigned. Sends all node keys assigned to the path from to to the corresponding leaf node). The device 30 stores at least one set of node keys transmitted from the management device 20 as a device key. For example, the management device 20 transmits the node keys of K1, K2, K4, and K8 to the device 30 of the identification information A assigned to the node number 8. Note that the management device 20 does not have to transmit all the node keys of the path from the root node to the corresponding leaf node if at least the node key assigned to the leaf node is transmitted.
0024The management tree information is not limited to a binary tree, but may be a ternary tree or more. In addition, the management tree information may have a non-complete tree structure or various structures.
0025FIG. 3 is a diagram showing an example of a group. The management device 20 generates a unique group key for each group. The management device 20 transmits at least one ciphertext generated by encrypting one group key with at least one node key to each device 30 belonging to the group. Specifically, the management device 20 uses at least one node key so that all the devices 30 belonging to the group can decrypt any of the ciphertexts and transmit the least number of ciphertexts. select. Then, the management device 20 generates and transmits a ciphertext with each selected node key.
0026In the example of FIG. 3, the devices 30 of the identification information A and B form the group α. The node key K4 is commonly possessed by the devices 30 of the identification information A and B, but is not possessed by the other devices 30. Therefore, the management device 20 encrypts the group key GKα of the group α with the node key K4. As a result, the management device 20 can efficiently transmit the group key GKα to the two devices 30 forming the group α.
0027Further, in the example of FIG. 3, the devices 30 of the identification information A, B, C, and D form the group β. The node key K2 is commonly possessed by the devices 30 having the identification information A, B, C, and D, but is not possessed by the other devices 30. Therefore, the management device 20 encrypts the group key GKβ of the group β with the node key K2. As a result, the management device 20 can efficiently transmit the group key GKβ to the four devices 30 forming the group β.
0028Further, in the example of FIG. 3, the devices 30 of the identification information E and F form the group γ. The node key K3 is commonly possessed by the device 30 of the identification information E and F, but is not possessed by the other devices 30. Therefore, the management device 20 encrypts the group key GKγ of the group γ with the node key K3. As a result, the management device 20 can efficiently transmit the group key GKγ to the two devices 30 forming the group γ.
0029FIG. 4 is a diagram showing the attribute information transmitted from the device 30 to the management device 20 and the node key determined based on the attribute information transmitted from the management device 20 to the device 30. FIG. 5 is a diagram showing the attribute information and another transmission example of the node key determined based on the attribute information.
0030The device 30 transmits attribute information representing the attributes of the device 30 to the management device 20. The attribute information includes at least one element information. The attribute information includes, for example, identification information, vendor name, type, average power consumption, most frequent command name, and the like as element information. The details of the attribute information will be described later with reference to FIG.
0031The management device 20 determines one or more node keys to be assigned to each device 30 based on such attribute information, and transmits the node keys to the device 30. In addition, as shown in Fig. 5, the management device 20 changes the node key assignment of other devices 30-2 due to the node key assignment to the device 30-1. Send the changed node key to.
0032Here, the management device 20 receives the attribute information of the first device 30, and the root of the management tree information configured based on the attribute information of the first device 30 and the attribute information of one or more second devices 30. Send at least one node key assigned to the path from node to leaf node.
0033More specifically, the management device 20 receives the first attribute information, which is the attribute information of the first device 30, and assigns it to the second leaf node closest to the first leaf node. Send at least one node key assigned to the path from the root node of the information to the second leaf node. The first leaf node is a node to which the second device 30 is assigned. Further, the second device 30 is a device 30 in which the second attribute information, which is the attribute information of the second device 30, matches the first attribute information. Further, in this case, the management device 20 may further transmit at least one node key assigned to the path from the root node of the management tree information to the first leaf node.
0034In addition, the management device 20 receives the attribute information of at least one or more devices 30 of the plurality of devices 30 and transmits at least one node key assigned to the path from the root node of the management tree information to each leaf node. May be good. In this case, the management tree information is the device 30 having the same received attribute information among the plurality of devices 30 assigned to the first leaf node, and the received attributes among the plurality of devices 30. The device 30 whose information does not match is assigned to the second leaf node.
0035Further, for example, when the management device 20 allocates a new device 30 to the management tree information, the management device 20 determines the allocation position (position of the leaf node) based on the attribute information of the new device 30. More specifically, the management device 20 determines the allocation position of the new device 30 so that the devices 30 having similar attribute information are close to each other and the devices 30 having dissimilar attribute information are far from each other. As a result, the management device 20 can efficiently transmit information such as a group key to a plurality of devices 30 belonging to the same group with a small amount of information (number of ciphertexts).
0036FIG. 6 is a diagram showing a configuration of the management device 20. The management device 20 includes a tree storage unit 41, a group storage unit 42, an attribute storage unit 43, a device discovery unit 44, a device authentication unit 45, an attribute acquisition unit 46, a similarity calculation unit 47, and an allocation unit. It has 48, an allocation transmission unit 49, a group key transmission unit 50, a generation unit 51, an extension unit 52, a reconstruction unit 53, an encryption unit 54, and a first communication unit 55.
0037The tree storage unit 41 stores the management tree information in which the node key is assigned to the node and the device 30 is assigned to the leaf node. The group storage unit 42 stores the group identification information, the group key, and the list of the devices 30 to which the group belongs 30 for each group. The attribute storage unit 43 stores attribute information for each device 30.
0038The device discovery unit 44 discovers the device 30 existing on the network. The device authentication unit 45 performs an authentication process with the device 30 and confirms whether the device 30 of the communication partner has the proper authority.
0039The attribute acquisition unit 46 acquires attribute information from the authenticated device 30. For example, when a new device 30 is connected to the network, the attribute acquisition unit 46 acquires attribute information from the new device 30. Further, the attribute acquisition unit 46 may periodically acquire element information of the attribute information that changes with time from each device 30. The attribute acquisition unit 46 stores the acquired attribute information in the attribute storage unit 43.
0040The similarity calculation unit 47 calculates the similarity of the attribute information of the two devices 30. For example, when a new device 30 is connected to the network and the new device 30 is assigned to the management tree information, the similarity calculation unit 47 has already assigned the attribute information of the new device 30 and the management tree information. The degree of similarity with the attribute information of each device 30 is calculated.
0041The allocation unit 48 allocates a new device 30 to the management tree information stored in the tree storage unit 41. In this case, the allocation unit 48 assigns the new device 30 (leaf node position) based on the similarity between the attribute information of the new device 30 and the attribute information of the existing device 30 already assigned to the management tree information. ) Is determined. More specifically, the allocation unit 48 determines the position of the leaf node to which the new device 30 is assigned so that the devices 30 having high similarity are arranged in a close range. For example, the allocation unit 48 has a predetermined number of edges from the leaf node to which the device 30 having a higher similarity to the attribute information of the new device 30 (for example, the device 30 having the highest similarity) is assigned. Allocate a new device 30 to an empty reachable leaf node.
0042When a new device 30 is assigned to the management tree information, the allocation transmission unit 49 encrypts at least one node key with the key shared by the authentication process and transmits the new device 30 to the new device 30. More specifically, the allocation transmission unit 49 transmits at least one node key assigned to the path from the root node in the management tree information to the leaf node corresponding to the new device 30 to the new device 30. .. The new device 30 stores at least one set of received node keys as a device key. Further, the allocation transmission unit 49 may encrypt and transmit the allocation position and the node key identification information in the management tree information to the new device 30.
0043The group key transmission unit 50 generates a group key when a new group is formed. Then, the group key transmission unit 50 transmits the group key to all the devices 30 belonging to the formed new group. In this case, in the group key transmission unit 50, all the devices 30 belonging to the group have at least one of them, the devices 30 not belonging to the group do not have, and the number of ciphertexts is large. Select one or more node keys that will be the least. Then, the group key transmission unit 50 encrypts the group key with the selected one or a plurality of node keys and transmits one or a plurality of ciphertexts.
0044Further, when a new device 30 is assigned to the management tree information and the new device 30 is added to any group, the group key transmission unit 50 transmits the corresponding group key to the new device 30. .. In this case, the group key transmission unit 50 encrypts the corresponding group key with a node key owned by the new device 30 and not owned by the device 30 not belonging to the group.
0045The generation unit 51 generates new management tree information and stores it in the tree storage unit 41. For example, when the new device 30 is first connected to the network and the management information to be assigned does not exist in the tree storage unit 41, the generation unit 51 generates new management tree information and stores it in the tree storage unit 41. ..
0046When the number of empty leaf nodes in the management tree information is less than a predetermined number, the extension unit 52 expands the management tree information stored in the tree storage unit 41. For example, the expansion unit 52 expands the management tree information when a new device 30 is connected to the network and the management tree information stored in the tree storage unit 41 does not have an empty leaf node. In addition, expanding the management tree information means adding new nodes and edges so that the number of leaf nodes included in the management tree information increases.
0047The reconstruction unit 53 reconstructs the management tree information stored in the tree storage unit 41. For example, the reconstruction unit 53 changes the allocation position of the device 30 to the leaf node in the management tree information so that the devices 30 having high similarity are arranged in a close range. More specifically, for example, in the reconstruction unit 53, the allocation position of the device 30 to the leaf node in the management tree information is predetermined for the devices 30 having a similarity degree of the attribute information equal to or higher than a predetermined value. Change so that it belongs to the reachable range by the number of edges. The reconstruction unit 53 executes reconstruction, for example, when a periodic or predetermined event occurs.
0048When transmitting data from the management device 20 to any device 30, the encryption unit 54 encrypts the target data using the group key or the node key. When the encryption unit 54 collectively transmits data to the devices 30 belonging to the designated group, the encryption unit 54 encrypts the target data with the group key. Further, when transmitting data to any one or more designated devices 30, the encryption unit 54 is a node owned by the designated device 30 and not owned by the other device 30. Select a key to encrypt the target data.
0049The first communication unit 55 communicates with the device 30 via the network. The first communication unit 55 executes layer processing such as a physical layer and a data link layer for communicating with the device 30, for example.
0050FIG. 7 is a diagram showing the configuration of the device 30. The device 30 includes an information storage unit 61, a fixed attribute storage unit 62, an attribute measurement unit 63, a management device discovery unit 64, a request unit 65, a management device authentication unit 66, an attribute transmission unit 67, and allocation reception. It has a unit 68, a group key receiving unit 69, a decoding unit 70, and a second communication unit 71.
0051The information storage unit 61 stores a device key, which is a set of at least one node key assigned to the device 30. Further, the information storage unit 61 may store the allocation position in the identification information and the management tree information of each node key. Further, the information storage unit 61 stores the group key of the group to which the device 30 belongs and the identification information of the group.
0052The fixed attribute storage unit 62 stores element information that does not change with time among the element information included in the attribute information. The attribute measurement unit 63 measures the element information that changes with time among the element information included in the attribute information. The attribute measuring unit 63 may measure periodically or may measure when a predetermined event occurs.
0053The management device discovery unit 64 discovers the management device 20 existing on the network. The requesting unit 65 requests the management device 20 to allocate the management tree information and issue at least one node key set. The requesting unit 65 requests the issuance of at least one node key pair, for example, when the device 30 is newly connected to the network. The management device authentication unit 66 performs an authentication process with the management device 20 and confirms whether the management device 20 of the communication partner has the proper authority.
0054The attribute transmission unit 67 transmits the attribute information to the management device 20. The attribute transmission unit 67 transmits the attribute information to the management device 20 at the time of requesting the allocation to the management tree information and the issuance of at least one node key set, for example. Further, the attribute transmission unit 67 may transmit the time-varying element information among the element information included in the attribute information to the management device 20 when a periodic or predetermined event occurs.
0055The allocation receiving unit 68 receives at least one node key transmitted from the management device 20. The allocation receiving unit 68 stores the received at least one set of node keys in the information storage unit 61 as a device key. In addition, the allocation receiving unit 68 receives the allocation position in the management tree information of the device 30 and the identification information of each node key. The allocation receiving unit 68 stores the received information in the information storage unit 61. When the device 30 is newly connected to the network, the node key, the assigned position, and the identification information of the node key are encrypted by the key shared by the authentication process with the management device 20. The allocation receiving unit 68 decrypts the node key, the allocation position, and the identification information of the node key by using this shared key.
0056The group key receiving unit 69 receives the encrypted group key from the management device 20. The group key is encrypted by one of the node keys of at least one node key set included in the device key held by the device 30. Therefore, the group key receiving unit 69 selects one of the node keys of at least one node key set included in the device key stored in the information storage unit 61, and uses the selected node key. Decrypt the group key. The group key receiving unit 69 stores the decrypted group key in the information storage unit 61.
0057The decryption unit 70 decodes the data transmitted from the management device 20 by using the group key or any node key included in the device key. The second communication unit 71 communicates with the management device 20 and other devices 30 via the network. The second communication unit 71 executes layer processing such as a physical layer and a data link layer for communicating with the management device 20 or another device 30, for example.
0058FIG. 8 is a diagram showing elements included in the attribute information. The attribute information includes element information that does not change with time (fixed element information) and element information that changes with time (element information that changes with time). The attribute information may include either fixed element information or element information that changes with time.
0059The fixed element information is, for example, identification information, vendor name, type, memory amount, maximum power consumption, and the like. The identification information is information for uniquely identifying the device 30 on the network, such as the MAC address, IP address, or serial number of the device 30. The vendor name is the name of the manufacturing company or the name of the sales company of the device 30. The type is a name indicating the product function of the device 30. Specifically, for example, an air conditioner, a television device, a refrigerator, or the like is described as the type.
0060The amount of memory is the capacity value of the memory included in the device 30. The amount of memory is not limited to the capacity value, and may be information such as whether or not the capacity value is larger than a predetermined threshold value. The maximum power consumption is the maximum value of the power consumed by the device 30.
0061The element information of the change with time is, for example, the average power consumption, the most frequent command name, the command frequency, and the like. The average power consumption is the average value of the power consumed by the device 30 in a certain period (for example, from the start of operation to the present time). The most frequent command name is the name of the most frequent control command executed by the device 30 in a certain period (for example, from the start of operation to the present time). The command frequency is the frequency at which the device 30 executes the control command in a certain period (for example, from the start of operation to the present time).
0062In addition to these, the element information included in the attribute information includes, for example, the model name, the cache amount of the device, the name of the CPU (Central Processing Unit), the rated power consumption, the communication method, the network topology, and the device from the management device 20. The number of hops until reaching 30, the radio strength, the date of manufacture of the device 30, the installation location of the device 30, whether the device 30 is movable or fixed, the identification information of the peripheral device to be connected, etc. There may be. Further, the combination of the element information included in the attribute information may be any combination.
0063FIG. 9 is a sequence diagram of the communication system 10 according to the embodiment. In the communication system 10, when a new device 30 is connected to the network, processing is executed according to the sequence shown in FIG.
0064First, in step S11, the management device 20 and the device 30 discover each other's devices via the network. Subsequently, in step S12, the device 30 requests the management device 20 to assign the management tree information and issue at least one node key set (device key).
0065Subsequently, in step S13, the management device 20 and the device 30 perform authentication processing with each other to confirm whether the communication partner has a legitimate authority. The management device 20 may execute the authentication process for determining whether to connect to the device 30 in step S13 in combination with the process in step S11 or step S12.
0066The management device 20 and the device 30 are certified by using a method such as ISO / IEC9798-1 or ISO / IEC9798-3. Further, the management device 20 and the device 30 may be authenticated by a method using a public key certificate. Further, the management device 20 and the device 30 may generate a key used for authentication based on a password shared in advance, or use a private key embedded in the device 30 at the time of shipment from the factory as the key used for authentication. You may.
0067Subsequently, when it is confirmed that the other party is a legitimate management device 20, the device 30 transmits the attribute information in step S14. In this case, the device 30 transmits element information that does not change with time. Further, the device 30 may also transmit the time-changing element information when the time-changing element information has already been measured.
0068The device 30 may transmit the attribute information at any time before the next allocation process (S15). For example, when the device 30 uses UPnP SSDP for the discovery process (S11), the device 30 may send the attribute information included in one entry of the device description. Further, when HTTP is used as the protocol of request processing (S12), the device 30 may define a dedicated field as one entity of the HTTP request header and send the attribute information, or the HTTP GET request. The URL may include the storage location of the attribute information.
0069Subsequently, in step S15, the management device 20 executes an allocation process for allocating the device 30 to any leaf node in the management tree information. The allocation process will be described later with reference to FIG.
0070Subsequently, in step S16, the management device 20 transmits the allocation information obtained by the allocation process in step S15 to the device 30. The allocation information includes at least one node key pair (device key) assigned to the corresponding device 30. Further, the allocation information may include the allocation position in the management tree information and the identification information of each node key. Further, the management device 20 encrypts the allocation information with the key shared by the authentication process and transmits the allocation information to the device 30.
0071Subsequently, in step S17, the management device 20 acquires the group key of the group to which the corresponding device 30 belongs, and any one or more nodes of at least one node key transmitted to the device 30 in step S16. Encrypt with a key. In this case, the management device 20 encrypts the group key with a node key that is not owned by the device 30 other than the group.
0072Subsequently, in step S18, the encrypted group key is transmitted to the device 30. Subsequently, in step S19, the device 30 receives the encrypted group key from the management device 20 and selects one of the node keys of at least one node key set (device key) that it holds. And decrypt with the selected node key. Through the above processing, the device 30 can acquire at least one node key set (device key) and a group key from the management device 20.
0073FIG. 10 is a flowchart of the allocation process of the management device 20. The management device 20 executes the process shown in FIG. 10 in the allocation process (S15).
0074First, in step S21, the generation unit 51 of the management device 20 determines whether or not the management tree information exists in the tree storage unit 41. When the management tree information does not exist (No in S21), in step S22, the generation unit 51 generates new management tree information and stores it in the tree storage unit 41. In this case, the generation unit 51 generates i-stage management tree information in which the hierarchy is predetermined (i is an integer of 2 or more). The hierarchy of management tree information represents the number of edges of the route from the root node to the leaf node. Subsequently, in step S23, the allocation unit 48 of the management device 20 allocates a new device 30 to any leaf node in the new management tree information. Then, when the step S23 is completed, the management device 20 ends the allocation process.
0075On the other hand, when the management tree information exists (Yes in S21), in step S24, the similarity calculation unit 47 of the management device 20 has the attribute information of the new device 30 and the respective management tree information already assigned. Calculate the degree of similarity with the attribute information of the device 30.
0076When calculating the similarity between two attribute information, the similarity calculation unit 47 compares, for example, whether the corresponding element information is the same or the difference between the values is within a certain range. For example, the similarity calculation unit 47 determines whether the vendor names are the same, the types are the same, the difference in memory amount is within a certain range, the difference in maximum power consumption is within a certain range, and the average. Compare whether the difference in power consumption is within a certain range, the most frequent command names are the same, the difference in command frequency is within a certain range, and so on.
0077Then, the similarity calculation unit 47 calculates the similarity by synthesizing the comparison results for each of the plurality of element information. For example, the similarity calculation unit 47 is 1 point when the element information is the same or the difference in value is within a certain range, and 0 when the element information is not the same or the difference in value exceeds a certain range. It is defined as a point, and the value obtained by summing the scores of a plurality of element information is defined as the similarity.
0078Further, the similarity calculation unit 47 may extract and compare a predetermined specific one or a plurality of element information instead of comparing all the element information of the attribute information. For example, the similarity calculation unit 47 may compare the type with the average power consumption and combine these comparison results to calculate the similarity.
0079Further, the similarity calculation unit 47 may synthesize by changing the weight of the comparison result according to the element information. The similarity calculation unit 47 has, for example, 5 points when the types match, 2 points when the vendor names match, and 4 points when the difference in average power consumption values is within a certain range. You may change the weight to. The similarity calculation unit 47 may calculate the similarity by another calculation method instead of the above calculation method.
0080Subsequently, in step S25, the allocation unit 48 allocates a new device 30 to any leaf node in the management tree information based on the calculated similarity. In this case, the allocation unit 48 allocates a new device 30 to any empty leaf node so that similar devices 30 are concentrated close to each other. For example, the allocation unit 48 allocates the new device 30 from the device 30 having the highest similarity to the attribute information of the new device 30 to an empty leaf node that can be reached within a certain number of edges. In addition, if there is no empty leaf node that can be reached within a certain number of edges from the device 30 with the highest similarity, the allocation unit 48 extends the management tree information to the expansion unit 52 and then uses the new device. You may assign 30.
0081Then, when the step S25 is completed, the management device 20 ends the allocation process.
0082FIG. 11 is a flowchart showing an example of the process in step S25 of FIG. In step S25 of FIG. 10, the allocation unit 48 may execute, for example, the process shown in FIG.
0083First, in step S31, the allocation unit 48 detects the leaf node to which the device 30 having the highest similarity to the attribute information of the new device 30 is assigned among the devices 30 already assigned to the management tree information. ..
0084Subsequently, in step S32, the allocation unit 48 determines whether or not an empty leaf node exists within nth degree from the leaf node to which the device 30 having the highest similarity is assigned. Here, a leaf node within the nth degree (n is an integer of 1 or more) means another leaf node that can be reached by the number of edges n times or less from the leaf node to which a certain device 30 is assigned. .. For example, in the example shown in FIG. 2, the number of relatives between leaf node 8 and leaf node 9 is 2. The number of relatives between leaf node 8 and leaf node 12 is 6.
0085If there is an empty leaf node within n degrees of the leaf node to which the device 30 with the highest similarity is assigned (Yes in S32), in step S33, the allocation unit 48 will perform an empty leaf within that n degrees. Assign a new device 30 to the node. That is, the allocation unit 48 allocates a new device 30 from the leaf node to which the device 30 having the highest similarity is assigned to an empty leaf node that can be reached by a predetermined number of edges. As a result, the allocation unit 48 can allocate the new device 30 to a position in the management tree information that is closest to the existing device 30 whose attribute information is most similar.
0086In step S31, the allocation unit 48 may detect the leaf node to which the device 30 having the highest similarity among the reference values or more is assigned. In this case, if there is no device 30 whose similarity is equal to or higher than the reference value, the allocation unit 48 may conversely allocate a new device 30 to an empty leaf node far from the nth degree. As a result, the allocation unit 48 can allocate the new device 30 to a distant position of the existing device 30 whose attribute information is not similar in the management tree information.
0087Then, when the management device 20 ends step S33, the process returns to the flow of FIG.
0088On the other hand, if there is no empty leaf node within nth degree from the leaf node to which the device 30 with the highest similarity is assigned (No in S32), in step S34, the allocation unit 48 is empty in the management tree information. Determine if a leaf node exists. When the management tree information does not have an empty leaf node (No in S34), the allocation unit 48 proceeds to step S35, and when the management tree information has an empty leaf node (Yes in S34), the processing proceeds. Proceed to step S36.
0089In step S35, the extension unit 52 extends the tree structure of the management tree information. As a result, the extension unit 52 can create an empty leaf node in the management tree information. Then, after expanding the management tree information, the expansion unit 52 returns the process to step S32 to repeat the process. The expansion unit 52 may proceed to step S36 after expanding the management tree information. The expansion process of the management tree information will be described later with reference to FIGS. 14 to 20.
0090Further, in step S36, the allocation unit 48 allocates a new device 30 to any of the empty leaf nodes. Then, when the management device 20 ends step S36, the process returns to the flow of FIG.
0091In step S34, the allocation unit 48 determines whether or not there are more than a predetermined number of empty leaf nodes in the management tree information instead of whether or not there are empty leaf nodes in the management tree information. You may judge. In this case, the allocation unit 48 advances the process to step S35 if there are not more than a predetermined number of empty leaf nodes, and proceeds to step S36 if there are.
0092FIG. 12 is a diagram showing an example of the first allocation of the device 30 to the management tree information. For example, as shown in FIG. 12, the management tree information has a structure of a complete binary tree with two layers, the first device 30-A is assigned to the leaf node of node number 4, and the leaf node of node number 6 is assigned. The second device 30-B is assigned to, and the third device 30-C is assigned to the leaf node of node number 7. Further, in the example of FIG. 12, the first device 30-A holds a set (device key) of three node keys K1, K2, and K4. The second device 30-B holds a set (device key) of three node keys K1, K3, and K6. The third device 30-C holds a set (device key) of three node keys K1, K3, and K7.
0093In the example of FIG. 12, when the first device 30-A and the second device 30-B execute the control command CMD, the management device 20 generates and transmits two ciphertexts represented by the following equations. To do. As a result, the first device 30-A and the second device 30-B can hold the group key GK. Note that E (K, M) represents a ciphertext in which data M is encrypted using the key K. C1 = E (K4, GK) C2 = E (K6, GK)
0094Subsequently, the management device 20 encrypts the control command CMD using the group key GK as represented by the following equation, and multicasts the ciphertext. C3 = E (GK, CMD)
0095The first device 30-A and the second device 30-B decrypt the received ciphertext using the group key GK. As a result, the first device 30-A and the second device 30-B can execute the control command CMD. In this way, when the management tree information is configured as shown in FIG. 12, the management device 20 sends three ciphertexts to the first device 30-A and the second device 30-B. The control command CMD can be executed.
0096In the example of FIG. 12, the management device 20 can also cause the first device 30-A and the second device 30-B to execute the control command CMD without transmitting the group key GK. In this case, the management device 20 generates and transmits a ciphertext represented by the following equation. When the group key GK is not transmitted, the management device 20 can cause the first device 30-A and the second device 30-B to execute the control command CMD by transmitting two ciphertexts. .. C1 ́ = E (K4, CMD) C2 ́ = E (K6, CMD)
0097FIG. 13 is a diagram showing an example of the second allocation of the device 30 to the management tree information. The management tree information shown in FIG. 13 differs from FIG. 12 in that the second device 30-B is assigned to the node with node number 5. In the example of FIG. 13, the second device 30-B holds a set (device key) of three node keys K1, K2, and K5.
0098In the example of FIG. 13, in order to cause the first device 30-A and the second device 30-B to execute the control command CMD, the management device 20 first generates a ciphertext represented by the following equation. , Multicast transmission. As a result, the first device 30-A and the second device 30-B can hold the group key GK. C1 ́ ́ = E (K2, GK)
0099Subsequently, the management device 20 encrypts the control command CMD using the group key GK as represented by the following equation, and multicasts the ciphertext. C3 = E (GK, CMD)
0100The first device 30-A and the second device 30-B decrypt the received ciphertext using the group key GK. As a result, the first device 30-A and the second device 30-B can execute the control command CMD. As described above, when the management tree information is configured as shown in FIG. 13, the management device 20 transmits the two ciphertexts to transmit the first device 30-A and the second device 30-B. Can execute the control command CMD.
0101Further, in the example of FIG. 13, the management device 20 can cause the first device 30-A and the second device 30-B to execute the control command CMD without transmitting the group key GK. In this case, the management device 20 generates a ciphertext represented by the following equation and transmits it by multicast. When the group key GK is not transmitted in this way, the management device 20 causes the first device 30-A and the second device 30-B to execute the control command CMD by transmitting one ciphertext. be able to. C1 ́ ́ ́ = E (K2, CMD)
0102As described above, when the same control command CMD is executed by the first device 30-A and the second device 30-B, the management tree information in FIG. 13 is better than the management tree information in FIG. The amount of data transmitted can be reduced, which is efficient.
0103Here, the management tree information of FIG. 12 and the management tree information of FIG. 13 are compared. In the management tree information shown in FIG. 12, the distance between the leaf node to which the first device 30-A is assigned and the leaf node to which the second device 30-B is assigned is the fourth degree distance. On the other hand, the management tree information in FIG. 13 shows that the distance between the leaf node to which the first device 30-A is assigned and the leaf node to which the second device 30-B is assigned is the second degree distance. It has become. That is, in the management tree information of FIG. 13, the first device 30-A and the second device 30-B are assigned in a range closer than the management tree information of FIG. From this, the management tree information is the amount of information (the number of ciphertexts) to be transmitted when the devices 30 belonging to one group are assigned to the near leaf node than when they are assigned to the far leaf node. ) Can be reduced.
0104Further, the management device 20 has a high possibility of simultaneously transmitting the same data to a plurality of devices 30 having a high degree of similarity in attribute information. For example, when suppressing the overall power consumption of the communication system 10, the management device 20 is likely to simultaneously transmit a control command or the like for reducing the power consumption to a plurality of air conditioners. Therefore, the management device 20 can reduce the amount of information (the number of ciphertexts) to be transmitted by allocating a plurality of devices 30 having a high degree of similarity in attribute information to leaf nodes within a predetermined range in the management tree information. ..
0105The management device 20 according to the present embodiment allocates devices 30 having a high degree of similarity in attribute information to close positions in the management tree information. Therefore, according to the management device 20, data can be efficiently transmitted to the plurality of devices 30 with a small amount of information.
0106(Expansion of management tree information) In the case where the extension unit 52 allocates a new device 30 to the management tree information, for example, when the number of empty leaf nodes in the management tree information is less than a predetermined number (for example, when there is no empty leaf node). ), Extend the management tree information.
0107In addition, the extension unit 52 expands the management tree information when there is no empty leaf node within nth degree from the leaf node of the device 30 with the attribute information having the highest similarity to the new device 30 in the management tree information. You may. Further, the extension unit 52 may extend the management tree information when a periodic or predetermined event occurs and the number of empty leaf nodes in the management tree information is less than a predetermined number. .. Further, the expansion unit 52 may expand the management tree information every time, for example, the number of devices 30 connected to the network exceeds a predetermined number.
0108An example of expanding the management tree information and a method of transmitting the extended node key will be described below.
0109FIG. 14 is a diagram showing a first example of management tree information before expansion. For example, as shown in FIG. 14, the management tree information has a structure of a complete binary tree with one layer, the first device 30-A is assigned to the leaf node of node number 4, and the leaf node of node number 5 is assigned. The second device 30-B is assigned to. In the example of FIG. 14, the first device 30-A holds a set (device key) of two node keys K2 and K4. The second device 30-B holds a set (device key) of two node keys K2 and K5.
0110In such a case, the allocation unit 48 cannot allocate the new device 30 to the management tree information. Therefore, the extension unit 52 adds a node to the upper layer of the existing root node of the management tree information, for example.
0111FIG. 15 is a diagram showing an example in which a new node is added to the upper layer of the root node in the management tree information of FIG. In the example of FIG. 15, the expansion unit 52 adds, for example, a new root node of node number 1 to the upper layer of node number 2 which is the original root node. Further, the extension part 52 adds a subtree of a complete binary tree of one layer to the lower layer of the root node of node number 1. As a result, the extension unit 52 can form two new empty leaf nodes in the management tree information and allocate the new device 30.
0112Subsequently, the allocation transmission unit 49 transmits the new node key assigned to the extended node in the management tree information to the device 30 assigned to the management tree information. In this case, the assigned transmission unit 49 encrypts the new node key assigned to the expanded node with the node key assigned to the existing node and held only by the device 30 to be transmitted. Convert and send.
0113In the example of FIG. 15, the allocation transmission unit 49 uses the node key K1 assigned to the extended node number 1 node as the node key K2 assigned to the existing node number 2 node, as shown in the following equation. Encrypted by and multicast transmission to the first device 30-A and the second device 30-B. C4 = E (K2, K1)
0114As a result, the existing first device 30-A and second device 30-B that were assigned to the management tree information before expansion can be moved from the root node to the corresponding leaf node in the management tree information after expansion. It can hold all the assigned node keys. In the example of FIG. 15, the first device 30-A holds a set (device key) of three node keys K1, K2, and K4, and the second device 30-B has three node keys K1, You can have a set of K2 and K5 (device key).
0115In this way, the allocation transmission unit 49 already holds the new node key assigned to the expanded node in the management tree information in the existing device 30 by extending the management tree information to the upper layer of the root node. It can be encrypted and transmitted using the node key. In particular, in this case, the assigned transmission unit 49 only needs to encrypt the new node key with one node key assigned to the original root node, so that the amount of information to be transmitted can be reduced.
0116FIG. 16 is a diagram showing a second example of management tree information before expansion. For example, as shown in FIG. 16, the management tree information has a structure of a complete binary tree with one layer, the first device 30-A is assigned to the leaf node of node number 2, and the leaf node of node number 3 is assigned. The second device 30-B is assigned to. In the example of FIG. 16, the first device 30-A holds a set (device key) of two node keys K1 and K2. The second device 30-B holds a set (device key) of two node keys K1 and K3.
0117In such a case, the allocation unit 48 cannot allocate the new device 30 to the management tree information. Therefore, the extension unit 52 may add a node to the lower layer of the existing leaf node of the management tree information, for example. Then, in this case, the expansion unit 52 reassigns the device 30 assigned to the existing leaf node to which the node is added to the lower layer to the new leaf node. Further, the extension unit 52 may add additional nodes to the intermediate layer between the existing leaf node and the root node of the management tree information, for example.
0118FIG. 17 is a diagram showing an example in which a new node is added to the lower layer of the leaf node in the management tree information of FIG. In the example of FIG. 17, the extension 52 adds two new leaf nodes, node number 4 and node number 5, to the lower layer of node number 2, which is the original leaf node, for example. Further, the expansion unit 52 adds two new leaf nodes of node number 6 and node number 7 to the lower layer of node number 3.
0119Further, in the example of FIG. 17, the expansion unit 52 reassigns the first device 30-A assigned to the original leaf node node number 2 to the new leaf node of node number 4. In addition, the expansion unit 52 reassigns the second device 30-B, which was assigned to the original leaf node node number 3, to the new leaf node of node number 5. As a result, the extension unit 52 can form two new empty leaf nodes in the management tree information and allocate the new device 30.
0120Further, in the example of FIG. 17, the extension unit 52 reassigns the new node keys K2 ́ and K3 ́ to the nodes of the original leaf nodes node number 2 and node number 3.
0121Subsequently, the assigned transmission unit 49 encrypts and manages the node key to be newly held by the node key assigned to the existing node and held only by the device 30 to be transmitted. Send to the device 30 assigned to the tree information. In the example of FIG. 17, the allocation transmission unit 49 encrypts the new node keys K2 ́, K4 with the node key K2 assigned to the existing node with the node number 2, as shown in the following equation. Send to device 30-A of 1. The node key K2 is possessed only by the first device 30-A to be transmitted, and is not possessed by the second device 30-B. As a result, the first device 30-A can hold a set (device key) of three node keys K1, K2 ́, and K4. C5 = E (K2, K2 ́) C6 = E (K2, K4)
0122Further, in the example of FIG. 17, the allocation transmission unit 49 encrypts the new node keys K2 ́, K5 with the node key K3 assigned to the existing node with the node number 3, as shown in the following equation. , Send to the second device 30-B. The node key K3 is possessed only by the second device 30-B to be transmitted, and is not possessed by the first device 30-A. As a result, the second device 30-B can hold a set (device key) of three node keys K1, K2 ́, and K5. C7 = E (K3, K2 ́) C8 = E (K3, K5)
0123In this way, the allocation transmission unit 49 already holds the new node key assigned to the expanded node in the management tree information in the existing device 30 by extending the management tree information to the lower layer of the leaf node. It can be encrypted and transmitted using the node key. The expansion unit 52 may have K2 ́ = K2. As a result, the allocation transmission unit 49 does not have to transmit the node key K2 to the first device 30-A, so that the amount of information to be transmitted can be further reduced.
0124FIG. 18 is a diagram showing an example in which a new node is added to the layer between the root node and the leaf node in the management tree information of FIG. The extension 52 may add a new node to the layer between the root node and the leaf node of the management tree information, for example.
0125In the example of FIG. 18, the extension unit 52 newly adds the node of the node number 4 to the lower layer of the root node of the node number 1, for example. Then, the extension unit 52 connects the leaf node of node number 2 and the leaf node of node number 3 to the lower layer of the node of node number 4. Further, the extension part 52 adds a subtree of a complete binary tree of one layer to the lower layer of the root node of node number 1. As a result, the extension unit 52 can form two new empty leaf nodes in the management tree information and allocate the new device 30.
0126Subsequently, the allocation transmission unit 49 transmits the node key assigned to the node with the added node number 4 to the first device 30-A and the second device 30-B assigned to the management tree information. .. In the example of FIG. 18, the allocation transmission unit 49 assigns a new node key K4 to the node with the existing node number 2 and the node with the existing node number 3 as shown in the following equation. It is encrypted by the node key K3 assigned to the first device 30-A and the second device 30-B by multicast transmission. As a result, the first device 30-A can hold a set (device key) of three node keys K1, K2, and K4. In addition, the second device 30-B can hold a set of three node keys K1, K3, and K4. C9 = E (K2, K4) C10 = E (K3, K4)
0127In this way, by adding a new node to the layer between the root node and the leaf node of the management tree information, the allocation transmission unit 49 assigns the node key assigned to the added new node to the existing node key. It can be encrypted and sent with the node key assigned to the node. As a result, according to the allocation transmission unit 49, the amount of information to be transmitted can be reduced.
0128As shown in the following equation, the allocation transmission unit 49 encrypts the new node key K4 with the node key K1 assigned to the node with the existing node number 1, and performs the first device 30-A and the first device 30-A. It may be configured to transmit multicast to device 30-B of 2. Even with this configuration, the first device 30-A can hold a set (device key) of three node keys K1, K2, and K4. In addition, the second device 30-B can hold a set (device key) of three node keys K1, K3, and K4. Further, as a result, the allocation transmission unit 49 only needs to transmit one ciphertext, so that the amount of information to be transmitted can be further reduced. C11 = E (K1, K4)
0129FIG. 19 is a diagram showing an example in which a new node is added to the lower layer of one leaf node in the management tree information of FIG. The extension 52 may add an additional node to the lower layer of any one of the existing leaf nodes of the management tree information, for example. Then, in this case, the expansion unit 52 reassigns the device 30 assigned to the existing leaf node to which the node is added to the lower layer to the new leaf node.
0130In the example of FIG. 19, the extension 52 adds two new leaf nodes, node number 4 and node number 5, to the lower layer of node number 3, which is the original leaf node, for example. Further, in the example of FIG. 19, the expansion unit 52 reassigns the second device 30-B assigned to the original leaf node node number 3 to the new leaf node of node number 4. As a result, the extension unit 52 can form a new empty leaf node in the management tree information and allocate a new device 30. Further, in the example of FIG. 19, the extension unit 52 reassigns a new node key K3 ́ to the node of node number 3 which is the original leaf node.
0131Subsequently, the allocation transmission unit 49 transmits a node key to be newly held to the second device 30-B whose allocation position has been changed. In the example of FIG. 19, the allocation transmission unit 49 encrypts the new node keys K3 ́, K4 with the node key K3 assigned to the existing node with the node number 3, as shown in the following equation. Send to device 30-B of 2. As a result, the second device 30-B can hold a set (device key) of three node keys K1, K3 ́, K4. C12 = E (K3, K3 ́) C13 = E (K3, K4)
0132In this way, the allocation transmission unit 49 extends the management tree information to the lower layer of one leaf node, and thereby transfers the new node key assigned to the expanded node in the management tree information to the existing device 30. It can be encrypted and transmitted using the node key that you already have. The expansion unit 52 may have K3 ́ = K3. As a result, the allocation transmission unit 49 does not have to transmit the node key K3 to the second device 30-B, so that the amount of information to be transmitted can be reduced.
0133FIG. 20 is a diagram showing an example in which a new node is added to the layer between the root node and one leaf node in the management tree information of FIG. The extension 52 may add a new node to the layer between the root node and one leaf node of the management tree information, for example.
0134In the example of FIG. 20, the extension unit 52 newly adds the node of node number 4 between the root node of node number 1 and the leaf node of node number 3. Then, the extension unit 52 adds a new leaf node of node number 5 to the lower layer of the node of node number 4. As a result, the extension unit 52 can form a new empty leaf node in the management tree information and allocate a new device 30.
0135Subsequently, the allocation transmission unit 49 transmits the node key assigned to the node with the added node number 4 to the second device 30-B assigned to the management tree information. In the example of FIG. 20, the allocation transmission unit 49 encrypts the new node key K4 with the node key K3 assigned to the existing node with the node number 3 as shown in the following equation, and the second device Send to 30-B. As a result, the second device 30-B can hold a set (device key) of the node keys K1, K3, and K4 of the three devices. C14 = E (K3, K4)
0136In this way, by adding a new node to the layer between the root node and the leaf node of the management tree information, the allocation transmission unit 49 assigns the node key assigned to the added new node to the existing node key. It can be encrypted and sent with the node key assigned to the node. As a result, according to the allocation transmission unit 49, the amount of information to be transmitted can be reduced.
0137(Reconstruction of management tree information) Next, a method of reconstructing the management tree information and a method of transmitting the node key after the reconstruction will be described. The reconstruction unit 53 changes the allocation position of the device 30 to the leaf node in the management tree information so that the devices 30 having high similarity are concentrated in the range of the nodes close to each other.
0138The reconstruction unit 53 executes reconstruction, for example, when a periodic or predetermined event occurs. For example, the reconstruction unit 53 may reconstruct the management tree information after the management tree information is expanded by the expansion unit 52. Further, for example, the reconstruction unit 53 manages the management tree when there is no empty leaf node within nth degree from the leaf node of the device 30 having the attribute information having the highest similarity to the new device 30 in the management tree information. The information may be reconstructed. Further, for example, the reconstruction unit 53 may have an empty leaf node within nth degree from the leaf node of the device 30 having the attribute information having the highest similarity to the new device 30 in the management tree information. , The management tree information may be reconstructed.
0139Hereinafter, an example of reconstructing the management tree information by using the element information included in the attribute information that changes with the passage of time as an index of similarity will be described.
0140FIG. 21 is a diagram showing management tree information before reconstruction. In the example of FIG. 21, the management tree information before reconstruction is a structure of a complete binary tree with two layers, the first device 30-A is assigned to the leaf node of node number 4, and the leaf of node number 5 is assigned. Assume that the node is assigned the second device 30-B and the leaf node with node number 6 is assigned the third device 30-C. In the example of FIG. 21, the first device 30-A holds a set (device key) of three node keys K1, K2, and K4. The second device 30-B holds a set (device key) of three node keys K1, K2, and K5. The third device 30-C holds a set (device key) of three node keys K1, K3, and K6.
0141The attribute acquisition unit 46 acquires attribute information from each device 30. The average power consumption of the first device 30-A is 1000 [W], the average power consumption of the second device 30-B is 100 [W], and the average power consumption of the third device 30-C is 1200 [W]. Suppose it was. In this case, the first device 30-A and the third device 30-C have a small difference in average power consumption and a high degree of similarity, so that, for example, a control command instructing to suppress power consumption may be received at the same time. high.
0142When the first device 30-A and the third device 30-C are to execute the control command, the management device 20 first generates and transmits the ciphertext represented by the following equation. As a result, the first device 30-A and the third device 30-C can hold the group key GK. Since the second device 30-B does not have the node keys K4 and K6, the group key GK cannot be obtained. C15 = E (K4, GK) C16 = E (K6, GK)
0143Subsequently, the management device 20 encrypts the control command CMD with the group key GK and transmits it by multicast to the first device 30-A and the third device 30-C as shown in the following equation. C17 = E (GK, CMD)
0144The first device 30-A and the third device 30-C decrypt the received ciphertext with the group key GK and execute the control command CMD. In this way, when the management tree information is configured as shown in FIG. 21, the management device 20 needs to send a control command to the first device 30-A and the third device 30-C. , Three ciphertexts must be generated.
0145FIG. 22 is a diagram showing management tree information after reconstruction. For example, the reconstruction unit 53 reconstructs the management tree information so that the devices 30 having an average power consumption of a certain value or more in the attribute information are arranged in the vicinity. For example, the reconstruction unit 53 reconstructs the management tree information so that the device 30 having an average power consumption of 1000 [W] or more is arranged within the second degree. Therefore, as shown in FIG. 22, the reconstruction unit 53 assigns, for example, the first device 30-A to the leaf node of node number 4 and the third device 30-C to the leaf node of node number 5. , Assign the second device 30-B to the leaf node with node number 6.
0146Further, the reconstruction unit 53 changes the node key assigned to each node according to the change in the allocation of the device 30. In this case, the reconfiguration unit 53 does not have to change the node key held by the device 30 whose assignment has been changed, and does not have to change the node key held by the device 30 whose assignment has been changed. In addition, the reconstruction unit 53 does not have to change the node key that is commonly held by all the devices 30 whose assignments have been changed. In the example of FIG. 22, the reconstruction unit 53 changes the node keys of the node of node number 2, the node of node number 3, the node of node number 5, and the node of node number 6.
0147Then, the allocation transmission unit 49 transmits the changed node key to the device 30. In the example of FIG. 22, the allocation transmission unit 49 encrypts the node key K2 ́ with the node key K4 and transmits it to the first device 30-A as shown in the following equation. As a result, the first device 30-A can hold a set (device key) of three node keys K1, K2 ́, and K4. C18 = E (K4, K2 ́)
0148Further, the allocation transmission unit 49 encrypts the node keys K2 ́ and K5 ́ with the node key K6 and transmits them to the third device 30-C as shown in the following equation. As a result, the third device 30-C can hold a set (device key) of three node keys K1, K2 ́, K5 ́. C19 = E (K6, K2 ́) C20 = E (K6, K5 ́)
0149Further, the allocation transmission unit 49 encrypts the node keys K3 ́ and K6 ́ with the node key K5 and transmits them to the second device 30-B as shown in the following equation. As a result, the second device 30-B can hold a set (device key) of three node keys K1, K3 ́, K6 ́. C21 = E (K5, K3 ́) C22 = E (K5, K6 ́)
0150Subsequently, when causing the first device 30-A and the third device 30-C to execute the control command, the management device 20 first generates the ciphertext represented by the following equation, and the first device 30 -Multicast to A and the third device 30-C. As a result, the first device 30-A and the third device 30-C can hold the group key GK. C21 = E (K2 ́, GK)
0151Subsequently, the management device 20 encrypts the control command CMD with the group key GK and transmits it by multicast to the first device 30-A and the third device 30-C as shown in the following equation. C22 = E (GK, CMD)
0152That is, when the management tree information is reconstructed as shown in FIG. 22, the management device 20 issues two ciphertexts in order to cause the first device 30-A and the third device 30-C to execute the control command. Just send it. Therefore, the management device 20 can reduce the number of ciphertexts that must be transmitted to cause the first device 30-A and the third device 30-C to execute the control command by one.
0153Note that the management device 20 does not share the group key GK between the first device 30-A and the third device 30-C, but encrypts the control command CMD with the node key K2 ́ and transmits it by multicast. You may. In this case, the management device 20 can send a control command to the first device 30-A and the third device 30-C with one ciphertext.
0154As described above, by reconstructing the management tree information so that the device 30 for which the control command is likely to be transmitted by multicast is contained in a small number of subtrees, the management device 20 determines the number of ciphertexts to be transmitted. It can be reduced, and the amount of information at the time of transmission can be reduced.
0155The reconstruction unit 53 uses the average power consumption as an index of the similarity when reconstructing the management tree information, but is not limited to this, and the element information of the attribute information that does not change with time is used as an index of the similarity. May be. Further, the reconstruction unit 53 may use a value obtained by synthesizing a plurality of types of element information as an index of similarity. Further, the reconstruction unit 53 may use the similarity synthesized by changing the weighting according to the element information as an index.
0156As described above, the management device 20 according to the present embodiment reconfigures the management tree information so that the device 30 in which the control command is likely to be multicast-transmitted fits in the subtree composed of a small number of nodes. As a result, according to the management device 20, the amount of communication for sharing the group key or node key used for encryption or authentication can be reduced. Further, the management device 20 can expand the management tree information as the number of devices 30 increases. Therefore, when the number of devices 30 is small, the management device 20 can reduce the management tree information and reduce the amount of memory and the like.
0157FIG. 23 is a diagram showing an example of the hardware configuration of the management device 20 according to the embodiment. The management device 20 according to the present embodiment is realized by, for example, an information processing device having a hardware configuration as shown in FIG. 23. The device 30 is also realized by an information processing device having the same hardware configuration as the management device 20.
0158This information processing device communicates with a CPU (Central Processing Unit) 201, a RAM (Random Access Memory) 202, a ROM (Read Only Memory) 203, an operation input device 204, a display device 205, and a storage device 206. It is equipped with device 207. Then, each of these parts is connected by a bus.
0159The CPU 201 is a processor that executes arithmetic processing, control processing, and the like according to a program. The CPU 201 executes various processes in cooperation with a program stored in the ROM 203, the storage device 206, or the like, using a predetermined area of the RAM 202 as a work area.
0160RAM202 is a memory such as SDRAM (Synchronous Dynamic Random Access Memory). RAM202 functions as a work area of CPU201. The ROM 203 is a memory that stores programs and various information in a non-rewritable manner.
0161The operation input device 204 is an input device such as a mouse and a keyboard. The operation input device 204 receives the information input from the user as an instruction signal and outputs the instruction signal to the CPU 201.
0162The display device 205 is a display device such as an LCD (Liquid Crystal Display). The display device 205 displays various information based on the display signal from the CPU 201.
0163The storage device 206 is a device that writes and reads data to a storage medium made of a semiconductor such as a flash memory, or a storage medium that can record magnetically or optically. The storage device 206 writes and reads data to and from the storage medium in response to control from the CPU 201. The communication device 207 communicates with an external device via a network according to the control from the CPU 201.
0164The program executed by the management device 20 of the present embodiment is a device discovery module, a device authentication module, an attribute acquisition module, a similarity calculation module, an allocation module, an allocation transmission module, a group key transmission module, a generation module, an extension module, and a re-program. It has a module configuration including a configuration module, an encryption module, and a first communication module. By deploying and executing this program on RAM202 by CPU201 (processor), the information processing device is divided into device discovery unit 44, device authentication unit 45, attribute acquisition unit 46, similarity calculation unit 47, and allocation unit 48. , Assign transmission unit 49, group key transmission unit 50, generation unit 51, extension unit 52, reconstruction unit 53, encryption unit 54, and first communication unit 55.
0165The management device 20 is not limited to such a configuration, and the device discovery unit 44, the device authentication unit 45, the attribute acquisition unit 46, the similarity calculation unit 47, the allocation unit 48, the allocation transmission unit 49, and the group key transmission unit 50. , The generation unit 51, the expansion unit 52, the reconstruction unit 53, the encryption unit 54, and at least a part of the first communication unit 55 may be realized by a hardware circuit (for example, a semiconductor integrated circuit).
0166The programs executed by the device 30 of the present embodiment include an attribute measurement module, a management device discovery module, a request module, a management device authentication module, an attribute transmission module, an allocation reception module, a group key reception module, a decryption module, and a second. It has a module configuration including a communication module. By deploying and executing this program on RAM202 by CPU201 (processor), the information processing device is divided into attribute measurement unit 63, management device discovery unit 64, request unit 65, management device authentication unit 66, and attribute transmission unit. It functions as 67, the assigned receiving unit 68, the group key receiving unit 69, the decoding unit 70, and the second communication unit 71.
0167The device 30 is not limited to such a configuration, and the attribute measurement unit 63, the management device discovery unit 64, the request unit 65, the management device authentication unit 66, the attribute transmission unit 67, the allocation reception unit 68, and the group key reception unit 69. , The decoding unit 70, and at least a part of the second communication unit 71 may be realized by a hardware circuit (for example, a semiconductor integrated circuit).
0168The program executed by the management device 20 of the present embodiment is a file in a computer-installable format or an executable format, such as a CD-ROM, a flexible disk, a CD-R, or a DVD (Digital Versatile Disk). It is recorded and provided on a computer-readable recording medium.
0169Further, the program executed by the management device 20 of the present embodiment may be stored on a computer connected to a network such as the Internet and provided by downloading via the network. Further, the program executed by the management device 20 of the present embodiment may be configured to be provided or distributed via a network such as the Internet. Further, the program executed by the management device 20 may be configured to be provided by incorporating it into a ROM or the like in advance.
0170Although some embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other embodiments, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and modifications thereof are included in the scope and gist of the invention, and are also included in the scope of the invention described in the claims and the equivalent scope thereof.
24 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO02060116A2 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | – |
| WO02080448A1 | Cites | World Intellectual Property Organization (WIPO) | Y | Search report | 1-8 |
| JP2003204321A | Cites | Japan | A | Search report | – |
| JP2005198116A | Cites | Japan | Y | Search report | 1-8 |
| WO2014010087A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | – |
| US6049878A | Cites | United States of America | A | Search report | – |
1 member in 1 office
Members1
| Document | Office | Kind | |
|---|---|---|---|
| JP2018038077AThis record | Japan | A |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2018038077
- Application
- 213108
Titles2
- Japanese
- 管理装置、プログラム、システムおよび方法
- English
- Management equipment, programs, systems and methods
Classification
- IPC, 1
- H04L9 08