RTP/SIP authentication in client server systems
Abstract
This record has no abstract on file.
Term
Term ended
Expired 28 July 2026, 0.2 years ago.
- Priority and filed
- Granted
- Expired
- Today
42 claims: 5 independent, 37 dependent
- 1A client-server distributed system that supports the SIP (Session Initiation Protocol) protocol that connects to the Internet, intranet, and LAN (Local Area Network), and is located between the SIP protocol-compatible client device and the SIP protocol-compatible server device. Authentication is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the server deviceButA means for setting one or more types of RTP encryption information used for sending and receiving RTP packets between the client devices for each client device and managing them as encryption capability information of the client device, and each occurrence of RTP communication between the client devices. Has a means for determining one type of RTP encryption information to be used between the client devices and a means for creating a SIP message to which the determined RTP encryption information is added and notifying the client device.With, The client deviceBut, A means for setting the RTP encryption information added to the SIP message when the SIP message is received from the server device as the RTP encryption information used when sending and receiving RTP packets with another client device.Have,The client deviceRTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information added to the SIP message received from the server device during the RTP communication.Means to doReceives an encrypted RTP packet from the opposite client device and decrypts it.Including meansA client-server distributed system characterized by this. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムであって、 前記SIPプロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置との間の認証が完了し、前記クライアント装置間のRTP(Real-time Transport Protocol)接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、 前記サーバ装置が、前記クライアント装置間のRTPパケット送受信の際に用いるRTP暗号情報を前記クライアント装置単位に1種類以上設定して該クライアント装置の暗号能力情報として管理する手段と、前記クライアント装置間のRTP通信発生毎に前記クライアント装置間で使用するRTP暗号情報を1種類決定する手段と、その決定したRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する手段とを有するとともに、 前記クライアント装置が、前記サーバ装置から前記SIPメッセージを受信した時に当該SIPメッセージに付加されたRTP暗号情報を他のクライアント装置とのRTPパケット送受信の際に用いるRTP暗号情報として設定する手段を有し、前記クライアント装置は、前記RTP通信に際して前記サーバ装置から受信したSIPメッセージに付加されたRTP暗号情報にしたがって前記クライアント装置間のP2P(Peer-to-Peer)で対向クライアント装置にRTPパケットを暗号化して送信する手段と、前記対向クライアント装置から暗号化されたRTPパケットを受信して復号化する手段とを含むことを特徴とするクライアント・サーバ型分散システム。
- 3In the RTP communication encryption method between the client devices, the client device has means for managing the presence / absence of encryption and the priority of the cryptographic rules used for the RTP communication as RTP encryption capability information, and its own device for the server device. The server device manages the RTP encryption capability information received from the client device, and the server device holds the RTP encryption capability information. Select the function to compare and edit the information and the RTP encryption capability information of each of the client devices facing each other when making an RTP call connection, select whether to encrypt the RTP packet and the encryption rule used for encryption, and select the encryption key. Claim 1 or claim comprising a function of determining the RTP encryption information by randomly generating the RTP encryption information, creating a SIP message to which the determined RTP encryption information is added, and notifying the client device. The client-server type distributed system described in Section 2. 前記クライアント装置間のRTP通信暗号方式において、 前記クライアント装置は、暗号有無と前記RTP通信に使用する暗号則の優先順位とをRTP暗号能力情報として管理する手段と、 前記サーバ装置に対して自装置のRTP暗号能力情報を予め通知する手段とを含み、 前記サーバ装置は、前記クライアント装置から受信した前記RTP暗号能力情報を管理し、当該RTP暗号能力情報を前記サーバ装置が保持しているRTP暗号情報と比較して編集する機能と、 RTP呼接続を行う際に対向する前記クライアント装置各々のRTP暗号能力情報からRTPパケットの暗号有無と暗号化に使用する暗号則とを選択し、暗号鍵をランダムに生成することで前記RTP暗号情報を決定し、その決定済みのRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する機能とを含むことを特徴とする請求項1または請求項2記載のクライアント・サーバ型分散システム。
- 22A client-to-client RTP (Real-time Transport Protocol) encryption method used for SIP (Session Initiation Protocol) protocol-compatible client-server distributed systems that connect to the Internet, intranet, and LAN (Local Area Network). Authentication between the client device and the server device compatible with the SIP protocol is completed, and the RTP connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the process of setting one or more types of RTP encryption information used by the server device for sending and receiving RTP packets between the client devices for each client device and managing the information as encryption capability information of the client device, and the client device. Each time RTP communication occurs between the client devices, one type of RTP encryption information to be used between the client devices is determined, and a SIP message to which the determined RTP encryption information is added is created and notified to the client device.With, A process of setting the RTP encryption information added to the SIP message when the client device receives the SIP message from the server device as RTP encryption information used when sending and receiving RTP packets with another client device.To run、The client deviceRTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information added to the SIP message received from the server device during the RTP communication.Processing to do andA client-to-client RTP encryption method, which comprises performing a process of receiving an encrypted RTP packet from the opposite client device and decrypting the packet. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムに用いるクライアント間RTP(Real-time Transport Protocol)暗号方法であって、 前記SIPプロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置との間の認証が完了し、前記クライアント装置間のRTP接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、 前記サーバ装置が、前記クライアント装置間のRTPパケット送受信の際に用いるRTP暗号情報を前記クライアント装置単位に1種類以上設定して該クライアント装置の暗号能力情報として管理する処理と、前記クライアント装置間のRTP通信発生毎に前記クライアント装置間で使用するRTP暗号情報を1種類決定する処理と、その決定したRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する処理とを実行するとともに、 前記クライアント装置が、前記サーバ装置から前記SIPメッセージを受信した時に当該SIPメッセージに付加されたRTP暗号情報を他のクライアント装置とのRTPパケット送受信の際に用いるRTP暗号情報として設定する処理を実行し、前記クライアント装置は、前記RTP通信に際して前記サーバ装置から受信したSIPメッセージに付加されたRTP暗号情報にしたがって前記クライアント装置間のP2P(Peer-to-Peer)で対向クライアント装置にRTPパケットを暗号化して送信する処理と、前記対向クライアント装置から暗号化されたRTPパケットを受信して復号化する処理とを実行することを特徴とするクライアント間RTP暗号方法。
- 41A client-server type distributed system that supports the SIP (Session Initiation Protocol) protocol that connects to the Internet, intranet, and LAN (Local Area Network). It is a program that is executed by the server device that supports the SIP protocol, and is a client that supports the SIP protocol. Authentication between the device and the server device is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the process of setting one or more types of RTP encryption information used for sending and receiving RTP packets between client devices for each client device and managing them as encryption capability information of the client devices, and generating RTP communication between the client devices. It is characterized by including a process of determining one type of RTP encryption information to be used between the client devices for each, and a process of creating a SIP message to which the determined RTP encryption information is added and notifying the client device. program. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムにおいて前記SIPプロトコル対応のサーバ装置に実行させるプログラムであって、 前記SIPプロトコル対応のクライアント装置と前記サーバ装置との間の認証が完了し、前記クライアント装置間のRTP(Real-time Transport Protocol)接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、 前記クライアント装置間のRTPパケット送受信の際に用いるRTP暗号情報を前記クライアント装置単位に1種類以上設定して該クライアント装置の暗号能力情報として管理する処理と、前記クライアント装置間のRTP通信発生毎に前記クライアント装置間で使用するRTP暗号情報を1種類決定する処理と、その決定したRTP暗号情報を付加したSIPメッセージを作成して前記クライアント装置に通知する処理とを含むことを特徴とするプログラム。
- 42A program to be executed by the SIP protocol-compatible client device in a SIP (Session Initiation Protocol) protocol-compatible client-server distributed system connected to the Internet, intranet, or LAN (Local Area Network). The client device and the SIP. Authentication with the protocol-compatible server device is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device.In the sequenceIn the process of setting the RTP encryption information added to the SIP message when the SIP message is received from the server device as the RTP encryption information used when sending and receiving RTP packets with another client device, and the above-mentioned RTP communication. RTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information received from the server device.Processing to do andA program including a process of receiving an encrypted RTP packet from the opposite client device and decrypting the packet. インタネット・イントラネット・LAN(Local Area Network)に接続するSIP(Session Initiation Protocol)プロトコル対応のクライアント・サーバ型分散システムにおいて前記SIPプロトコル対応のクライアント装置に実行させるプログラムであって、 前記クライアント装置と前記SIPプロトコル対応のサーバ装置との間の認証が完了し、前記クライアント装置間のRTP(Real-time Transport Protocol)接続が前記サーバ装置を介してSIP呼接続制御されるシーケンス内において、前記サーバ装置からSIPメッセージを受信した時に当該SIPメッセージに付加されたRTP暗号情報を他のクライアント装置とのRTPパケット送受信の際に用いるRTP暗号情報として設定する処理と、 前記RTP通信に際して前記サーバ装置から受信した前記RTP暗号情報にしたがって前記クライアント装置間のP2P(Peer-to-Peer)で対向クライアント装置にRTPパケットを暗号化して送信する処理と、前記対向クライアント装置から暗号化されたRTPパケットを受信して復号化する処理とを含むことを特徴とするプログラム。
Independent claims5
236 paragraphs, as filed
The present invention relates to a client-server distributed system, a server device, a client device, and an inter-client RTP encryption method used for them, and particularly RTP (Real-time) between clients in a client-server distributed system compatible with the SIP (Session Initiation Protocol) protocol. Transport Protocol) Regarding encryption method.
In a client-server distributed system that supports the SIP protocol, it is necessary to ensure security because it is a system connected on a LAN (Local Area Network), and as a countermeasure, an encryption method for RTP packets between clients is defined. Has been done.
SSL / TLS (Secure Socket Layer / Transport Layer Security) and the like are defined as general encryption methods (see, for example, Non-Patent Document 1), and SRTP (Secure Real-time Transport Protocol) is defined as the RTP encryption method. It is defined (see, for example, Non-Patent Document 2).
In addition, as a procedure for distributing an encryption key in SRTP, MIKEY (Multimedia Internet KEYing) (for example, see Non-Patent Document 3), ZRTP (Extensions to RTP for Diffie-Hellman Key Agreement for SRTP) (for example, Non-Patent Document 3). 4) etc. are defined.
In the SSL / TLS method, certificates are required for each other, so it is necessary to distribute the certificate to the client device in advance. In addition, it is necessary to prepare an authentication server in the system and authenticate the certificate for distributing the encryption key for each call.
Since TCP (Transmission Control Protocol) is used as the layer 4 protocol, it is not optimal for VoIP (Voice over Internet Protocol) communication where real-time performance is important. Generally, UDP (User Datagram Protocol) is adopted as the protocol for VoIP communication. ing.
In the MIKEY method, which is defined as a general key distribution method in SRTP, a Pre-shared Key is set for each communication combination, or the key is distributed by encrypting with a public key. When using a pre-shared key, it is necessary to distribute the key to each client device in advance, and when using a public key, authentication using a digital signature is required.
In this case as well, it is necessary to distribute the certificate to the client device in advance, and it is also necessary to prepare an authentication server and authenticate the certificate in order to distribute the encryption key for each call. Public key cryptography is not optimal for VoIP communication, where real-time performance is important, because it takes time to process.
In the ZRTP method, it is necessary to perform authentication using the Short Authentication String (SAS) that has End to End, prepare a SAS distribution and authentication server in advance, and distribute the encryption key for each call. You need to authenticate. Authentication execution for each call is redundant and is not optimal for VoIP communication where real-time performance is important.
In addition, key management uses RTP packets and is completely P2P. Since the encryption starts after the start of RTP communication and the encryption setting is performed by RTP communication without encryption, there is a weak point in terms of security.
<nplcit num="1"><text>"Introduction to Cryptographic Technology-Alice in the Secret Country, Chapter 14 SSL / TLS" (Hiroshi Yuki, published by Softbank Publishing, September 27, 2003, pp.346-367)</text></nplcit><nplcit num="2"><text>"The Secure Real-time Transport Protocol (SRTP)" (RFC3711, March 2004)</text></nplcit><nplcit num="3"><text>"MIKEY: Multimedia Internet KEYing" (RFC3830, August 2004)</text></nplcit><nplcit num="4"><text>"ZRTP: Extensions to RTP for Diffie-Hellman Key Agreement for SRTP draft-zimmermann-avt-zrtp-01" (AVT WG Internet-Draft Expirres: September 6, 2006) (http://www.ietf.org/internet- drafts / draft-zimmermann-avt-zrtp-01)</text></nplcit>
<p> In the conventional client-to-client RTP encryption method described above, when the SSL / TLS method is used, it is necessary to authenticate with a certificate for each call in order to notify the encryption key, so it is necessary to distribute the certificate to the client device. Therefore, there is a problem that a certificate management function is required and the man-hours of the maintainer increase.</p><p> In addition, in the MIKEY method defined in SRTP, it is necessary to distribute the Pre-shared Key in advance when distributing the key by Pre-shared Key, and when using the public key, authentication by digital signature is required. Therefore, it is necessary to distribute the certificate in advance, and there is a problem that the man-hours of the maintainer increase.</p><p> Similarly, since ZRTP also authenticates using SAS, there is a problem that it is necessary to distribute SAS in advance and the man-hours of the maintainer increase. In addition, since TCP is used as the layer 4 protocol, there is a problem that it is difficult to ensure real-time performance in VoIP communication.</p><p> Therefore, in the conventional technology, the man-hours of the maintainer are required for certificate management, and the authentication server that authenticates each call is required. Therefore, the cost is high to realize the cryptographic security function. There is a problem of becoming. Further, the conventional technology has a problem that it is difficult to secure real-time performance when applied as security of VoIP communication.</p><p> Therefore, an object of the present invention is to solve the above problems, do not require a certificate authentication function for distributing an encryption key, need to hold or manage a certificate, and need to prepare an authentication server in the system. It is an object of the present invention to provide a client-server distributed system, a server device, a client device, and an inter-client RTP encryption method used for them, which can eliminate and realize a cryptographic security function at low cost.</p>
<p> The client-server distributed system according to the present invention is a client-server distributed system compatible with the SIP (Session Initiation Protocol) protocol connected to the Internet, intranet, and LAN (Local Area Network). Authentication between the SIP protocol-compatible client device and the SIP protocol-compatible server device is completed, and the RTP (Real-time Transport Protocol) connection between the client devices is controlled by SIP call connection via the server device. Ru<u style="single">In the sequence</u>In The server device<u style="single">But</u>A means for setting one or more types of RTP encryption information used for sending and receiving RTP packets between the client devices for each client device and managing them as encryption capability information of the client device, and each occurrence of RTP communication between the client devices. Is provided with a means for determining one type of RTP encryption information to be used between the client devices and a means for creating a SIP message to which the determined RTP encryption information is added and notifying the client device.<u style="single">With</u>, The client device<u style="single">But</u>, A means for setting the RTP encryption information added to the SIP message when the SIP message is received from the server device as the RTP encryption information used when sending and receiving RTP packets with another client device.<u style="single">With</u><u style="single">The client device</u>RTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information added to the SIP message received from the server device during the RTP communication.<u style="single">Means to do</u>Receives an encrypted RTP packet from the opposite client device and decrypts it.<u style="single">Including means</u>There is.</p><p> The server device according to the present invention includes the means and functions of the above-mentioned client-server distributed system.</p><p> The client device according to the present invention includes the means and functions of the above-mentioned client-server distributed system.</p><p> The client-to-client RTP encryption method according to the present invention is a client-to-client RTP (Real-time Transport Protocol) used in a client-server distributed system that supports the SIP (Session Initiation Protocol) protocol connected to the Internet, intranet, and LAN (Local Area Network). It's a cryptographic method Authentication between the SIP protocol-compatible client device and the SIP protocol-compatible server device is completed, and the RTP connection between the client devices is controlled by SIP call connection via the server device.<u style="single">In the sequence</u>In A process in which one or more types of RTP encryption information used by the server device for sending and receiving RTP packets between the client devices are set for each client device and managed as encryption capability information of the client device, and between the client devices. Each time RTP communication occurs, a process of determining one type of RTP encryption information to be used between the client devices and a process of creating a SIP message to which the determined RTP encryption information is added and notifying the client device are executed.<u style="single">With</u>, A process of setting the RTP encryption information added to the SIP message when the client device receives the SIP message from the server device as RTP encryption information used when sending and receiving RTP packets with another client device.<u style="single">To run</u>、<u style="single">The client device</u>RTP packets are encrypted and transmitted to the opposite client device by P2P (Peer-to-Peer) between the client devices according to the RTP encryption information added to the SIP message received from the server device during the RTP communication.<u style="single">Processing to do and</u>A process of receiving an encrypted RTP packet from the opposite client device and decrypting it is being executed. </p><p> That is, the client-server distributed system of the present invention is a client-server distributed system compatible with the SIP (Session Initiation Protocol) protocol connected to the Internet, intranet, and LAN (Local Area Network).</p><p> In the client-server distributed system of the present invention, the authentication between the client device and the server device supporting the SIP protocol has been completed, and the RTP (Real-time Transport Protocol) connection between the client devices is SIP via the server device. Call connection is controlled.</p><p> In the client-server distributed system of the present invention, the server device receives RTP encryption information (encryption / absence, encryption rule) including encryption presence / absence and encryption rule used when sending / receiving RTP packets between client devices and input from the outside. A means for setting one or more types for each device, a means for determining one type of RTP encryption information to be used between client devices each time RTP communication occurs between client devices, and a means for generating an encryption key and setting it as RTP encryption information. A means for the purpose and a means for notifying the client device of RTP encryption information including an encryption key are provided.</p><p> Further, in the client-server distributed system of the present invention, a means for receiving and setting RTP encryption capability information from the client device in the server device and RTP encryption information between the client devices for each RTP communication between the client devices are RTP. A means is provided for determining from the encryption information and the RTP encryption capability information and notifying both of the opposing client devices.</p><p> In the client-server distributed system of the present invention, in the server device, the RTP encryption information between the client devices is changed for each call or at an arbitrary timing, or for each combination of the connecting client device and the communication timing. There is a means to operate with different RTP encryption information settings for each.</p><p> The client device receives and sets the RTP encryption information used when sending and receiving RTP packets with other client devices from the server device, and the client device and the client device according to the RTP encryption information received from the server device during RTP communication. It is provided with a function of encrypting and transmitting an RTP packet to the opposite client device by P2P (Peer to Peer) between and, and receiving and decrypting the encrypted RTP packet from the opposite client device.</p><p> As a result, in the client-server distributed system of the present invention, it is not necessary to execute authentication for each call for encryption key distribution, it is necessary to prepare an authentication server in the system, and authentication information such as a certificate is distributed in advance. It is possible to provide a cryptographic security function at low cost by eliminating the need to do so.</p><p> Further, in the client-server distributed system of the present invention, by using UDP (User Datagram Protocol) as a layer 4 protocol, a cryptographic security function can be provided without impairing the real-time property that is important for VoIP (Voice over Internet Protocol) communication. It will be possible to realize.</p><p> Further, in the client-server distributed system of the present invention, it is possible to update the RTP encryption information (encryption presence / absence, encryption rule, encryption key) from the server device, and it is possible to set different RTP encryption information for each device. By performing call-by-call or arbitrary or periodic automatic update of the cryptographic information, it is possible to prevent the cryptographic state from being inferred and strengthen the cryptographic security function.</p><p> Furthermore, in the client-server distributed system of the present invention, the client device can notify the server device of the cryptographic ability (presence or absence of encryption / priority of usable cryptographic rules) regardless of whether or not there is a difference in RTP cryptographic ability of the device. It enables the highest level of RTP encryption settings that can be combined, and enhances the encryption security function.</p>
<p> The present invention has the above configuration and operation, does not require a certificate authentication function for distributing an encryption key, needs to hold or manage a certificate, and needs to prepare an authentication server in the system. It is possible to obtain the effect that the cryptographic security function can be realized at low cost.</p>
Next, examples of the present invention will be described with reference to the drawings.
FIG. 1 is a block diagram showing a configuration of a client-server distributed system compatible with the SIP (Session Initiation Protocol) protocol according to the first embodiment of the present invention. In FIG. 1, the client-server type distributed system according to the first embodiment of the present invention includes a SIP protocol-compatible server device (hereinafter referred to as a server device) 1, a local maintenance console 2, and a SIP protocol-compatible client device (hereinafter referred to as a server device). It consists of 3-1 to 3-3 (which is a client device) and maintenance console 4. In addition, the server device 1, the client devices 31 to 3-3, and the maintenance console 4 are each connected to LAN (Local Area Network) 100. In this embodiment, connection examples of three client devices 31 to 3-3 are shown, but other connections, for example, two or four or more, are also possible. Further, in this embodiment, the local maintenance console 2 and the maintenance console 4 are provided, but it can be applied even when these input / output means are not provided.
The server device 1 has at least the encryption information setting unit 11, the SIP interface unit 13, the SIP message creation unit 14, the SIP message analysis unit 15, the call control unit 16, the encryption / decryption unit 17, and the encryption capability management unit. It consists of 18 and the cryptographic information table 20. Figure 4 shows a configuration example of the encryption information table 20 on the server device 1 side. Note that FIG. 4 shows a case where only one set of encryption presence / absence, encryption rule, and encryption key is stored in the encryption information table 20 as an example, but it is also possible to store a plurality of sets. In that case, it is possible to select from a plurality of stored sets based on a preset priority, or to select at random.
Further, in the server device 1, the above-mentioned encryption information setting unit 11, SIP interface unit 13, SIP message creation unit 14, SIP message analysis unit 15, call control unit 16, encryption / decryption unit 17, encryption capability management unit 18, encryption It is possible to manage each of the information tables 20 by executing a program by a CPU (central processing unit) (not shown).
The client device 3-1 has at least the encryption information setting unit 31, the SIP interface unit 33, the SIP message creation unit 34, the SIP message analysis unit 35, the call control unit 36, the encryption / decryption unit 37, and the encryption capability. It is composed of a management unit 38, an RTP (Real-time Transport Protocol) control unit 39, and an encryption information table 40. Figure 5 shows a configuration example of the encryption information table 40 on the client device 3-1 side. Although FIG. 5 shows a case where only one set of encryption presence / absence, encryption rule, and encryption key is stored in the encryption information table 40 as an example, it is possible to store a plurality of sets. In that case, it is possible to select from a plurality of stored sets based on a preset priority, or to select at random.
In the client device 3-1 the above-mentioned encryption information setting unit 31, SIP interface unit 33, SIP message creation unit 34, SIP message analysis unit 35, call control unit 36, encryption / decryption unit 37, and encryption capability management unit 38. , RTP control unit 39, and encryption information table 40 can be managed by executing a program by a CPU (not shown). Further, the client devices 3-2 and 3-3 have the same configuration as the above client device 3-1.
By configuring the server device 1 and the client devices 3-1 to 3-3 as described above, the encryption information of the RTP packet encryption when performing RTP communication between the client devices 3-1 to 3-3 is stored in the server. Device 1 manages and automatically selects, and it is possible to securely execute the settings for client devices 3-1 to 3-3, and security can be strengthened.
2 and 3 are sequence charts showing the operation of the client-server distributed system according to the first embodiment of the present invention. The operation of the client-server distributed system according to the first embodiment of the present invention will be described with reference to FIGS. 1 to 3. The processing of the server device 1 and the processing of the client devices 3-1 and 3-2 shown in FIGS. 2 and 3 are performed by the CPUs of the server device 1 and the client devices 3-1 and 3-2 executing the programs. It will be realized.
The authentication process between the server device 1 and the client device 3-1 and 3-2 has been completed in advance (a11 and a12 in Fig. 2), and the server device between the server device 1 and the client device 3-1. Secure SIP message transmission / reception is possible between 1 and client device 3-2.
The encryption capability management unit 18 of the server device 1 lists the encryption information table 20 with the presence / absence of encryption when the client device 3-1 performs RTP communication, and the encryption rules / encryption keys used when there is encryption (hereinafter, RTP encryption information). It holds one or more types of RTP cryptographic ability information including a list of cryptographic rules prioritizing the RTP cryptographic rules to be used (a13 in Fig. 2). Similarly, the encryption information table 20 of the server device 1 stores the RTP encryption capability information of the client device 3-2 (a14 in FIG. 2).
When a communication call is made from the client device 3-1 to the client device 3-2 (a31 in Fig. 2), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (a32 in FIG. 2). ..
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20 for both the client devices 3-1 and 3-2. It is determined based on the RTP encryption capability information of the above and transmitted to the encryption information setting unit 11. In addition, the encryption capability management unit 18 stores the determined RTP encryption information in the encryption information table 20 as the RTP encryption information of each of the client devices 3-1 and 3-2 (a15 in FIG. 2).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the determined client device 3-1 and the client device 3-2, and the call control unit 16 adds the received RTP encryption information to the client. Instruct the SIP message creation unit 14 to create a SIP message for device 3-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (a16 in FIG. 2).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (a33 in FIG. 2).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which the RTP encryption information between the client device 3-1 and the client device 3-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (a17 in FIG. 3).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (a41 in FIG. 3).
After the call control sequence between the client device 3-1 and the client device 3-2 is completed (a18 in FIG. 3), the RTP control unit 39 of the client device 3-1 and the RTP control unit 39 of the client device 3-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information set from the server device 1 (a34 in Fig. 3).
In this embodiment, with the above configuration and operation, it is not necessary to perform call-by-call authentication for RTP encryption key distribution, it is necessary to prepare an authentication server in the system, and authentication of certificates, etc. It has the effect of eliminating the need to pre-distribute the information and realizing the cryptographic security function at low cost.
Further, in this embodiment, the server device 1 manages the RTP encryption capability information of the client devices 3-1 and 3-2, and automatically opposes each other during the RTP communication between the client devices 3-1 and 3-2. It is possible to instruct RTP encryption information between client devices 3-1 and 3-2, and client devices 3-1 and 3-2 between client devices 3-1 and 3-2 with multiple types of encryption capabilities. There is an effect that the highest level of cryptographic security function can be realized regardless of the difference in cryptographic ability.
Although the operation and operation of the client device 3-3 are not described in the above description, the same effect as the case of using the client devices 3-1, 3-2 as described above can be obtained.
FIG. 6 is a block diagram showing a configuration of a client-server distributed system according to a second embodiment of the present invention. In FIG. 6, in the client-server distributed system according to the second embodiment of the present invention, the encrypted information input interface unit 12 is added to the server device 1a, and the encrypted information input / output interface unit 32 is added to the client device 3a-1. Except for the above, the configuration is the same as that of the client-server distributed system according to the first embodiment of the present invention shown in FIG. 1, and the same components are designated by the same reference numerals.
In this embodiment, with the above configuration, the maintainer sets the encryption information for RTP packet encryption when performing RTP communication between the client devices 3a-1 to 3a-3 based on the system design. , The encrypted information input interface unit 12 can be securely executed from the outside via the server device 1a, and the security enhancement and the maintainability can be improved at the same time.
Further, in this embodiment, the encryption information setting of the RTP packet encryption can be executed from the outside by the encryption information input / output interface unit 32 via the client device 3a-1, further improving the maintainability. be able to.
7 and 8 are sequence charts showing the operation of the client-server distributed system according to the second embodiment of the present invention. The operation of the client-server distributed system according to the second embodiment of the present invention will be described with reference to FIGS. 6 to 8. The processing of the server device 1a and the processing of the client devices 3a-1 and 3a-2 shown in FIGS. 7 and 8 are performed by executing the program by each CPU of the server device 1a and the client devices 3a-1, 3a-2. It will be realized. Further, FIGS. 7 and 8 show an example of setting from the server device 1a side.
The authentication process between the server device 1a and the client devices 3a-1 and 3a-2 has been completed in advance (b21 and b22 in Fig. 7), and the server between the server device 1a and the client device 3a-1. Secure SIP message transmission / reception is possible between device 1a and client device 3a-2.
From the local maintenance console 2 connected to the server device 1a, the presence / absence of encryption when the client device 3a-1 performs RTP communication, and the encryption rules / encryption keys used when there is encryption (hereinafter referred to as RTP encryption information) When one or more types are input (b11, b12 in FIG. 7), the encryption information input interface unit 12 receives the setting request including the RTP encryption information, and when the normality of the setting request can be confirmed. The RTP encryption information is transmitted to the encryption capability management unit 18.
Upon receiving the RTP encryption information, the encryption capability management unit 18 creates RTP encryption capability information including the RTP encryption rule list held by the client device 3a-1 and transmits the RTP encryption capability information to the encryption information setting unit 11. Further, the encryption capability management unit 18 stores the RTP encryption capability information in the encryption information table 20 (b23 in FIG. 7), and notifies the local maintenance console 2 of the completion of the setting via the encryption information input interface unit 12 (b23 in FIG. 7). B24 in Figure 7).
When the encryption information of one or more types of client devices 3a-2 is set from the local maintenance console 2 by the same procedure as above (b13, b14 in Fig. 7), the client is entered in the encryption information table 20 of the server device 1a. The RTP encryption capability information of the device 3a-2 is created and stored (b25 in FIG. 7), and the completion of the setting is notified to the local maintenance console 2 via the encryption information input interface unit 12 (b26 in FIG. 7).
Since the operation when a communication call is generated from the client device 3a-1 to the client device 3a-2 is the same as that in the first embodiment, the description of the operation (operation shown in FIG. 8) will be omitted.
FIG. 9 is a sequence chart showing the operation of the client-server distributed system according to the second embodiment of the present invention. An example of setting from the client device 3a-1 side will be described with reference to FIG.
In this case as well, the authentication process between the server device 1a and the client devices 3a-1 and 3a-2 has been completed in advance (c21 and c22 in FIG. 9), and the server device 1a and the client device 3a-1 During that time, secure SIP messages can be sent and received between the server device 1a and the client device 3a-2.
From the maintenance console 4 connected to the client device 3a-1, the presence or absence of encryption when the client device 3a-1 performs RTP communication, and the encryption rule / encryption key used when there is encryption (hereinafter, RTP encryption information) When one or more types are input (c11, c12 in FIG. 9), the encryption information input / output interface unit 32 receives the setting request including the RTP encryption information, and the normality of the setting request can be confirmed. In some cases, the RTP encryption information is transmitted to the encryption capability management unit 38.
Upon receiving the RTP encryption information, the encryption capability management unit 38 updates the RTP encryption capability information including the RTP encryption rule list held by the client device 3a-1 and transmits the RTP encryption capability information to the encryption information setting unit 31. In addition, the cryptographic ability management unit 38 stores the RTP cryptographic ability information in the cryptographic information table 40 (c31 in FIG. 9).
The encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP message with RTP encryption capability information added, and the SIP message creation unit 34 issues a SIP message with RTP encryption capability information added based on the instruction. The created and created SIP message is transmitted to the SIP interface unit 13 of the server device 1a via the SIP interface unit 33 (c32 in FIG. 9).
When the SIP interface unit 13 of the server device 1a receives the SIP message to which the RTP encryption capacity information is added, the SIP message is transmitted to the SIP message analysis unit 15, and the SIP message analysis unit 15 determines the normality of the RTP encryption capacity information. If it can be confirmed, the RTP encryption capability information is notified to the encryption capability management unit 18. The cryptographic ability management unit 18 stores the received RTP cryptographic ability information in the cryptographic information table 20 (c23 in FIG. 9).
Further, in the same procedure as above, the RTP encryption capability information of the client device 3a-2 is stored in the encryption information table 40 of the client device 3a-2 (c13, c14, c41 in FIG. 9), and the server device 1a It is stored in the cryptographic information table 20 (c41, c24 in Fig. 9).
The sequence chart of the operation when a communication call is generated from the client device 3a-1 to the client device 3a-2 is the same as in FIG. 8, and the detailed operation description is the same as in the first embodiment. , The description is omitted.
Therefore, in this embodiment, the server device 1a can input and manage the RTP encryption capability information of the client devices 3a-1 and 3a-2 from the outside, and the maintainer can input and manage the client device 3a based on the system design concept. Since it is possible to set the cryptographic information between -1,3a-2, there is an effect that the highest level cryptographic security function can be easily realized.
Further, in this embodiment, the RTP encryption capability information of the client devices 3a-1,3a-2 can be input and managed from the outside of the client devices 3a-1,3a-2, so that maintenance is easy. There is an effect that it can be further improved.
Further, in this embodiment, the effect of the RTP encryption function based on the set RTP encryption information is the same as that of the first embodiment of the present invention described above. Although the operation and operation of the client device 3a-3 are not described, the same effect as the case of using the client devices 3a-1 and 3a-2 as described above can be obtained.
10 and 11 are sequence charts showing the operation of the client-server distributed system according to the third embodiment of the present invention. Since the client-server distributed system according to the third embodiment of the present invention has the same configuration as the client-server distributed system according to the first embodiment of the present invention shown in FIG. 1, the configuration will be described. Is omitted. Hereinafter, the operation of the client-server distributed system according to the third embodiment of the present invention will be described with reference to FIGS. 1, 10 and 11. The processing of the server device 1 and the processing of the client devices 3-1 and 3-2 shown in FIGS. 10 and 11 are performed by the CPUs of the server device 1 and the client devices 3-1 and 3-2 executing the programs. It will be realized.
In this embodiment, by realizing the above configuration and operation, the client device 3-1 notifies the server device 1 of the encryption information that can be used for RTP encryption, and the server device 1 notifies the client device 3-1. , 3-2 RTP encryption capability information is managed, and during RTP communication between client devices 3-1 and 3-2, the client automatically performs RTP encryption between the opposite client devices 3-1 and 3-2. It is possible for both devices 3-1 and 3-2 to instruct feasible RTP encryption information, and the user can specify the cryptographic rules between client devices 3-1 and 3-2 with multiple types of RTP encryption capabilities. The cryptographic security function can be efficiently realized without being aware of it.
Authentication between server device 1 and client device 3-1 and between server device 1 and client device 3-2 is completed at any time from the start of operation of client devices 3-1 and 3-2 to this point. (D21, d22 in Fig. 10). Further, it is assumed that the encryption capability management unit 38 of the client devices 3-1 and 3-2 stores the RTP encryption capability information in the client-side encryption information table 40.
The SIP message creation unit 34 of the client device 3-1 creates a SIP message with RTP encryption capability information added (d41 in FIG. 10), and the created SIP message is sent to the SIP of the server device 1 via the SIP interface unit 33. It is transmitted to the interface unit 13 (d42 in Fig. 10).
The SIP interface unit 13 of the server device 1 transmits the SIP message received from the client device 3-1 to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the RTP encryption capability information, the RTP Notify the encryption capability management unit 18 of the encryption capability information.
The encryption capability management unit 18 checks whether the RTP encryption capability information of the client device 3-1 has been set in the encryption information table 20 (d23 in Fig. 10), and if there is the set RTP encryption capability information, that RTP. The encryption capability information is compared and edited with the RTP encryption capability information received from the client device 3-1 to create a new RTP encryption capability information that allows the client device 3-1 to operate reliably (d24 in Fig. 10). The encryption capability information is stored in the encryption information table 20 (d25 in FIG. 10), and the encryption information setting unit 11 is notified. If there is no set RTP encryption capability information, the encryption capability management unit 18 stores the RTP encryption capability information received from the client device 3-1 in the encryption information table 20 (d25 in FIG. 10).
Further, in the same procedure as above, the RTP encryption capability information of the client device 3-2 is stored in the encryption information table 1a of the server device 1 (d51, d52, d26 to d28 in FIG. 10).
When a communication call is made from the client device 3-1 to the client device 3-2 (d43 in Fig. 11), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (d44 in FIG. 11). ..
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on this instruction, the cryptographic ability management unit 18 stores the RTP encryption information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20 for each of the client devices 3-1 and 3-2. It is determined by the RTP cryptographic ability information and transmitted to the cryptographic information setting unit 11. In addition, the encryption capability management unit 18 stores the determined RTP encryption information in the encryption information table 20 as the RTP encryption information of each of the client devices 3-1 and 3-2 (d29 in FIG. 11).
The encryption information setting unit 11 generates an encryption key used for RTP encryption between the client device 3-1 and the client device 3-2, and sets the encryption information table as the RTP encryption information of each of the client devices 3-1 and 3-2. Remember in 20.
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the client device 3-1 and the client device 3-2 including the generated encryption key, and the call control unit 16 adds this RTP encryption information. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (d30 in FIG. 11).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (d45 in FIG. 11).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which the RTP encryption information between the client device 3-1 and the client device 3-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (d31 in FIG. 11).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (d53 in FIG. 11).
After the call control sequence between the client device 3-1 and the client device 3-2 is completed (d32 in FIG. 11), the RTP control unit 39 of the client device 3-1 and the RTP control unit 39 of the client device 3-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information set from the server device 1 (d46 in Fig. 11).
In this embodiment, with the above configuration and operation, the client device 3-1 notifies the server device 1 of the encryption information that can be used for RTP encryption, and the server device 1 notifies the client device 3-1. Manages RTP encryption capability information between 3-2 and automatically performs RTP encryption between client devices 3-1 and 3-2 during RTP communication between client devices 3-1 and 3-2. Since it is possible for both 3-1, 3-2 to instruct feasible RTP cryptographic information, the user is aware of the cryptographic rules between client devices 3-1, 3-2 with multiple types of cryptographic capabilities. There is an effect that the cryptographic security function can be efficiently realized without doing so.
Further, in the present embodiment, the set RTP encryption information has the same effect as the first and second embodiments of the present invention described above. Although the operation and operation of the client device 3-3 are not described, the same effect as the case of using the client devices 3-1 and 3-2 as described above can be obtained.
12 and 13 are sequence charts showing the operation of the client-server distributed system according to the fourth embodiment of the present invention. Since the client-server distributed system according to the fourth embodiment of the present invention has the same configuration as the client-server distributed system according to the first embodiment shown in FIG. 1, the description thereof will be omitted. .. Hereinafter, the operation of the client-server distributed system according to the fourth embodiment of the present invention will be described with reference to FIGS. 1, 12 and 13. The processing of the server device 1 and the processing of the client devices 3-1 and 3-2 shown in FIGS. 12 and 13 are performed by the CPUs of the server device 1 and the client devices 3-1 and 3-2 executing the programs. It will be realized.
In this embodiment, with the above configuration and operation, it is possible to securely notify the RTP encryption key when performing RTP communication between the client devices 3-1 to 3-3, so security is provided. Can be strengthened.
The authentication process between the server device 1 and the client device 3-1 and 3-2 has been completed in advance (e11 and e13 in Fig. 12), and the server between the server device 1 and the client device 3-1. SIP message encryption information is set between the device 1 and the client device 3-2 (e12 and e14 in FIG. 12), and secure SIP message encryption transmission / reception is possible according to the SIP message encryption information. In this case, the cryptographic information table 20 of the server device 1 has the cryptographic ability information of the client devices 3-1, 3-2 set in advance (e15, e16 in FIG. 12).
When a communication call is made from the client device 3-1 to the client device 3-2 (e31 in Fig. 12), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (e32 in FIG. 12). ..
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, it transmits the received SIP message to the SIP message analysis unit 15, and the SIP message analysis unit 15 can confirm the normality of the SIP message. , The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on this instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20 for each of the client devices 3-1 and 3-2. It is determined by the RTP encryption ability information of the above, and it is transmitted to the encryption information setting unit 11. In addition, the encryption capability management unit 18 stores the determined RTP encryption information in the encryption information table 20 as the RTP encryption information of each of the client devices 3-1 and 3-2 (e17 in FIG. 12).
When the determined RTP encryption capability information is transmitted, the encryption information setting unit 11 generates an encryption key used for RTP encryption between the client device 3-1 and the client device 3-2, and the client device 3-1 , 3-2 Store each RTP encryption information in the encryption information table 20 (e18 in Fig. 12).
The encryption information setting unit 11 instructs the encryption / decryption unit 17 to encrypt the generated encryption key, and the encryption / decryption unit 17 uses the SIP message encryption information used for SIP message encryption with the client device 3-1 to obtain the encryption key. Is encrypted (e19 in Figure 12).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the client device 3-1 and the client device 3-2 including the encrypted encryption key, and the call control unit 16 receives the RTP encryption. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3-1 to which the information is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (e20 in FIG. 13).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information is added, the SIP message is transmitted to the SIP message analysis unit 35, and the SIP message analysis unit 35 normalizes the RTP encryption information. If the nature can be confirmed, the encryption / decryption unit 37 is instructed to decrypt the encrypted encryption key in the received RTP encryption information. The encryption / decryption unit 37 decrypts the encrypted encryption key (e33 in FIG. 13), and transmits the RTP encryption information including the decrypted encryption key to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (e34 in FIG. 13).
The encryption information setting unit 11 instructs the encryption / decryption unit 17 to encrypt the generated encryption key, and the encryption / decryption unit 17 uses the encryption key according to the SIP message encryption information used for SIP message encryption with the client device 3-2. Is encrypted (e19 in Figure 12).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the client device 3-1 and the client device 3-2 including the encrypted encryption key, and the call control unit 16 transmits the RTP encryption information. Instruct the SIP message creation unit 14 to create a SIP message for the added client device 3-2. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (e21 in FIG. 13).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the RTP encryption information is added, the SIP message unit transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 normalizes the RTP encryption information. If the nature can be confirmed, the encryption / decryption unit 37 is instructed to decrypt the encrypted encryption key in the received RTP encryption information. The encryption / decryption unit 37 decrypts the encrypted encryption key (e41 in FIG. 13), and transmits the RTP encryption information including the decrypted encryption key to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (e42 in FIG. 13).
After the call control sequence between the client device 3-1 and the client device 3-2 is completed (e22 in FIG. 13), the RTP control unit 39 of the client device 3-1 and the RTP control unit 39 of the client device 3-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information set from the server device 1 (e35 in Fig. 13).
In this embodiment, with the above configuration and operation, the RTP encryption key can be securely notified in the RTP encryption information notification from the server device 1, so that security can be enhanced. effective.
Further, in the present embodiment, the effect of the RTP encryption function based on the set RTP encryption information is the same as that of the first embodiment of the present invention described above. Although the operation and operation of the client device 3-3 are not described, the same effect as the case of using the client devices 3-1 and 3-2 as described above can be obtained.
FIG. 14 is a diagram showing a configuration example of an encryption information table on the server device side of the client-server distributed system according to the fifth embodiment of the present invention, and FIG. 15 is a diagram showing a configuration example of the encryption information table according to the fifth embodiment of the present invention. It is a figure which shows the configuration example of the encryption information table on the client device side of a type distribution system. The client-server distributed system according to the fifth embodiment of the present invention has the same configuration as the client-server distributed system according to the first embodiment shown in FIG. 1, and the client-server distributed system according to the fifth embodiment of the present invention. Since the operation of the server-type distributed system is the same as the operation of the fourth embodiment of the present invention shown in FIGS. 12 and 13, the description of the configuration and operation will be omitted.
In FIG. 14, the encryption information table 20 of the server device 1 has a cryptographic rule used for SIP message encryption / decryption processing in addition to the information stored in the encryption information table 20 according to the first embodiment of the present invention shown in FIG. And the encryption key are stored, and the encryption / decryption unit 17 is set to use the encryption rule and the encryption key when performing SIP message encryption / decryption.
The encryption information table 20 is the same as the encryption information table 20 according to the first embodiment of the present invention shown in FIG. 4, and includes a cipher rule list used for RTP encryption / decryption processing, an encryption presence / absence, an encryption rule used, and an encryption key. The encryption / decryption unit 17 is set to use the encryption rule list, the presence / absence of the encryption, the encryption rule to be used, and the encryption key when performing RTP encryption / decryption. As an example, FIG. 14 shows a case where only one set of encryption presence / absence, encryption rule, and encryption key used for SIP message encryption / decryption processing and RTP encryption / decryption processing is stored in the encryption information table 20. , It is also possible to store multiple sets. In that case, it is possible to select from a plurality of stored sets based on a preset priority, or to select at random.
The encryption information table 40 of the client devices 3-1 and 3-2 is used for SIP message encryption / decryption processing in addition to the information stored in the encryption information table 40 according to the first embodiment of the present invention shown in FIG. The encryption rule and the encryption key are stored, and the encryption / decryption unit 37 is set to use the encryption rule and the encryption key when performing SIP message encryption / decryption.
Further, the encryption information table 40 of the client devices 3-1 and 3-2 is a cipher rule list used for the RTP encryption / decryption process, similarly to the encryption information table 40 according to the first embodiment of the present invention shown in FIG. The encryption / decryption unit 37 stores the encryption / presence / absence, the encryption rule to be used, and the encryption key. It is set to use an encryption key. As an example, FIG. 5 shows a case where only one set of encryption presence / absence, encryption rule, and encryption key used for SIP message encryption / decryption processing and RTP encryption / decryption processing is stored in the encryption information table 40. , It is also possible to store multiple sets. In that case, it is possible to select from a plurality of stored sets based on a preset priority, or to select at random.
In this embodiment, the encryption information table configuration as described above allows the SIP message encryption information and RTP communication when transmitting and receiving SIP messages between the server device 1 and the client devices 3-1 to 3-3. It is possible to set the encryption information independently of the RTP encryption information when performing the above, and it is possible to strengthen the security.
In this embodiment, by configuring the encryption information tables 20 and 40 and setting the encryption information as described above, when SIP messages are transmitted and received between the server device 1 and the client devices 3-1 to 3-3. Since the SIP message encryption information and the RTP encryption information at the time of RTP communication can be set as independent encryption information, there is an effect that security can be strengthened. Further, in the present embodiment, the set RTP encryption information has the same effect as that of the first embodiment of the present invention described above.
16 to 19 are sequence charts showing the operation of the client-server distributed system according to the sixth embodiment of the present invention. Since the client-server distributed system according to the sixth embodiment of the present invention has the same configuration as the client-server distributed system according to the first embodiment of the present invention shown in FIG. 1, the configuration will be described. Is omitted. Hereinafter, the operation of the client-server distributed system according to the sixth embodiment of the present invention will be described with reference to FIGS. 1 and 16 to 19. The processing of the server device 1 and the processing of the client devices 3-1 and 3-3 shown in FIGS. 16 to 19 are performed by each CPU of the server device 1 and the client devices 3-1 to 3-3 executing the program. It is realized by.
The authentication process between the server device 1 and the client devices 3-1 to 3-3 has been completed in advance (Fig. 16f11 to f13), and between the server device 1 and the client device 3-1 the server device 1 SIP message encryption information is set between the server device 3 and the client device 3-2, and between the server device 1 and the client device 3-3, and secure SIP message encryption transmission / reception is possible according to the SIP message encryption information. is there. In this case, the encryption capability information of each of the client devices 3-1 to 3-3 is already set in the encryption information table 20 of the server device 1 (Fig. 16f14).
When a communication call is made from the client device 3-1 to the client device 3-2 (f31 in Fig. 16), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (f32 in FIG. 16).
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20 for each of the client devices 3-1 and 3-2. It is determined as RTP encryption information # 1 based on the RTP encryption ability information of the above, and it is transmitted to the encryption information setting unit 11. In addition, the encryption capability management unit 18 stores the determined RTP encryption information # 1 in the encryption information table 20 as the RTP encryption information of each of the client devices 3-1 and 3-2 (f15 in FIG. 16).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information # 1 between the determined client device 3-1 and the client device 3-2, and the call control unit 16 adds the RTP encryption information # 1. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (f16 in FIG. 16).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information # 1 is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the RTP encryption. When the normality of the information # 1 is confirmed, the RTP encryption information # 1 is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information # 1 in the encryption information table 40, and sets the RTP encryption information # 1 in the encryption / decryption unit 37 (f33 in FIG. 16).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which the RTP encryption information # 1 between the client device 3-1 and the client device 3-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (f17 in FIG. 17).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the RTP encryption information # 1 is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the RTP encryption. When the normality of the information # 1 is confirmed, the RTP encryption information # 1 is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information # 1 in the encryption information table 40, and sets the RTP encryption information # 1 in the encryption / decryption unit 37 (f51 in FIG. 17).
After the call control sequence between client device 3-1 and client device 3-2 is completed (f18 in FIG. 17), RTP control unit 39 of client device 3-1 and RTP control unit 39 of client device 3-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information # 1 set from the server device 1 (f34 in Fig. 17).
When communication is restored from client device 3-1 to client device 3-2 (f35 in Fig. 17) and a new communication call occurs (f36 in Fig. 17), the call control unit of client device 3-1 36 instructs the SIP message creation unit 34 to create a SIP message for a call connection, the SIP message creation unit 34 creates a SIP message based on the instruction, and the created SIP message is sent to the server device 1 via the SIP interface unit 33. (F37 in Fig. 17).
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, transmits the received SIP message to the SIP message analysis unit 15, and the SIP message analysis unit 15 can confirm the normality of the SIP message. , The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP encryption information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20 for each of the client devices 3-1 and 3-2. RTP encryption information # 2 is determined based on the RTP encryption capability information, and it is transmitted to the encryption information setting unit 11. In addition, the cryptographic ability management unit 18 stores the determined RTP cryptographic information # 2 in the cryptographic information table 20 as RTP cryptographic information for each of the client devices 3-1 and 3-2 (f19 in FIG. 17).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information # 2 between the determined client device 3-1 and the client device 3-2, and the call control unit 16 adds the RTP encryption information # 2. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (f20 in FIG. 17).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information # 2 is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the RTP encryption. When the normality of the information # 2 is confirmed, the RTP encryption information # 2 is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information # 2 in the encryption information table 40, and sets the RTP encryption information # 2 in the encryption / decryption unit 37 (f38 in FIG. 17).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which the RTP encryption information # 2 between the client device 3-1 and the client device 3-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (f21 in FIG. 18).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the RTP encryption information # 2 is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the RTP encryption. When the normality of the information # 2 is confirmed, the RTP encryption information # 2 is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information # 2 in the encryption information table 40, and sets the RTP encryption information # 2 in the encryption / decryption unit 37 (f52 in FIG. 18).
After the call control sequence between client device 3-1 and client device 3-2 is completed (f22 in FIG. 18), RTP control unit 39 of client device 3-1 and RTP control unit 39 of client device 3-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information # 2 set from the server device 1 (f39 in Fig. 18).
When a communication call is made from the client device 3-1 to the client device 3-3 (f41 in Fig. 18), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (f42 in FIG. 18). ..
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-3, and the encryption capability management unit 18 is contacted with the client device 3-1 and the client device 3-3. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3-1 and the client device 3-3 in the cryptographic information table 20 for each of the client devices 3-1 and 3-3. It is determined as RTP encryption information # 3 based on the RTP encryption ability information of the above, and it is transmitted to the encryption information setting unit 11. In addition, the cryptographic ability management unit 18 stores the determined RTP cryptographic information 3 in the cryptographic information table 40 as RTP cryptographic information for each of the client devices 3-1 and 3-3 (f23 in FIG. 18).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information # 3 between the determined client device 3-1 and the client device 3-3, and the call control unit 16 adds the RTP encryption information # 3. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (f24 in FIG. 18).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information # 3 is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the RTP encryption. When the normality of the information # 3 is confirmed, the RTP encryption information # 3 is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information # 3 in the encryption information table 40, and sets the RTP encryption information # 3 in the encryption / decryption unit 37 (f42 in FIG. 18).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-3 to which the RTP encryption information # 3 between the client device 3-1 and the client device 3-3 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-3 via the SIP interface unit 13 (f25 in FIG. 19).
When the SIP interface unit 33 of the client device 3-3 receives the SIP message to which the RTP encryption information # 3 is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the SIP message. When the normality of the information # 3 is confirmed, the RTP encryption information # 3 is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information # 3 in the encryption information table 40, and sets the RTP encryption information # 3 in the encryption / decryption unit 37 (f61 in FIG. 18).
After the call control sequence between client device 3-1 and client device 3-3 is completed (f26 in FIG. 18), RTP control unit 39 of client device 3-1 and RTP control unit 39 of client device 3-3 Is to execute encrypted RTP transmission / reception using RTP encryption information # 3 set from server device 1 (f43 in Fig. 18).
In this embodiment, with the above configuration and operation, the RTP encryption information when performing RTP communication between the client devices 3-1 to 3-3 can be changed for each call, so it can be changed from the outside. It makes it difficult to guess RTP encrypted information and can strengthen security against eavesdropping. Further, in the present embodiment, the set RTP encryption information has the same effect as that of the first embodiment of the present invention described above.
FIG. 20 is a block diagram showing a configuration of a client-server distributed system according to a seventh embodiment of the present invention. In FIG. 20, the client-server distributed system according to the seventh embodiment of the present invention has the first embodiment of the present invention shown in FIG. 1, except that the encryption information update timer control unit 21 is added to the server device 1b. It has the same configuration as the client-server distributed system by, and the same components are given the same reference numerals.
In this embodiment, with the above configuration and operation, the RTP encryption information when performing RTP communication between the client devices 3-1 to 3-3 is periodically stored using the encryption information update timer control unit 21. Since it is possible to change the RTP encryption information from the outside, it is difficult to guess the RTP encrypted information from the outside, and the security against eavesdropping etc. can be strengthened.
21 to 23 are sequence charts showing the operation of the client-server distributed system according to the seventh embodiment of the present invention. Hereinafter, the operation of the client-server distributed system according to the seventh embodiment of the present invention will be described with reference to FIGS. 20 to 23. The processing of the server device 1b and the processing of the client devices 3-1 and 3-2 shown in FIGS. 21 to 23 are performed by the CPUs of the server device 1b and the client devices 3-1 and 3-2 executing the programs. It will be realized.
The authentication process between the server device 1b and the client device 3-1 and 3-2 has been completed in advance (g11, f12 in Fig. 21), and the server between the server device 1b and the client device 3-1. SIP message encryption information is set between the device 1b and the client device 3-2, respectively, and secure SIP message encryption transmission / reception is possible according to the SIP message encryption information. In this case, the encryption capability information of the client devices 3-1 and 3-2 is already set in the encryption information table 20 of the server device 1b (g13 in Fig. 21).
When a communication call is made from the client device 3-1 to the client device 3-2 (g31 in Fig. 21), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (g32 in FIG. 21). ..
When the SIP interface unit 13 of the server device 1b receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the encryption capability management unit 18 stores the RTP encryption information between the client device 3-1 and the client device 3-2 in the encryption information table 20 for each of the client devices 3-1 and 3-2. It is determined by the RTP encryption ability information of the above, and it is transmitted to the encryption information setting unit 11. In addition, the encryption capability management unit 18 stores the determined RTP encryption information in the encryption information table 20 as the RTP encryption information of each of the client devices 3-1 and 3-2 (g14 in FIG. 21).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the determined client device 3-1 and the client device 3-2, and the call control unit 16 adds the RTP encryption information to the client device 3 Instruct the SIP message creation unit 14 to create a SIP message for -1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (g15 in FIG. 21).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (g33 in FIG. 21).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which the RTP encryption information between the client device 3-1 and the client device 3-2 is added. SIP message forming unit 14 Waso creates the SIP message based on the instruction of the SIP message created via the SIP interface unit 13 transmits to the SIP interface unit 33 of the client apparatus 3-2 (g16 in Fig. 22).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the received SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the received SIP message to the SIP message analysis unit 35. When the normality of the above is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (g41 in FIG. 22).
After the call control sequence between the client device 3-1 and the client device 3-2 is completed (g17 in FIG. 22), the RTP control unit 39 of the client device 3-1 and the RTP control unit 39 of the client device 3-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information set from the server device 1b (g34 in Fig. 22).
The encryption information update timer control unit 21 of the server device 1b initializes and starts the encryption information update timer having an arbitrary timer value (g18 in FIG. 22). After that, the encryption information update timer control unit 21 continuously repeats updating the encryption information update timer and monitoring the timeout (g19, g20 in FIG. 22).
When the encryption information update timer control unit 21 recognizes the timeout of the encryption information update timer, the encryption information update timer control unit 21 notifies the encryption information setting unit 11 of the timeout of the encryption information update timer. The cryptographic information setting unit 11 instructs the cryptographic ability management unit 18 to determine a new RTP cryptographic information to be used between the client device 3-1 and the client device 3-2.
Based on the instruction, the cryptographic ability management unit 18 stores the new RTP cryptographic information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20. It is determined by each RTP cryptographic ability information and transmitted to the cryptographic information setting unit 11. In addition, the encryption capability management unit 18 stores the determined new RTP encryption information in the encryption information table 20 as the RTP encryption information of each of the client devices 3-1 and 3-2 (g21 in FIG. 22).
The encryption information setting unit 11 notifies the call control unit 16 of the new RTP encryption information between the determined client device 3-1 and the client device 3-2, and the call control unit 16 adds the new RTP encryption information to the client. Instruct the SIP message creation unit 14 to create a SIP message for device 3-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (g22 in FIG. 22).
When the SIP interface unit 33 of the client device 3-1 receives the SIP message to which the new RTP encryption information is added, the SIP message is transmitted to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the new RTP encryption. When the normality of the information is confirmed, the new RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the new RTP encryption information in the encryption information table 40, and sets the new RTP encryption information in the encryption / decryption unit 37 (g35 in FIG. 22).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which the new RTP encryption information between the client device 3-1 and the client device 3-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (g23 in FIG. 23).
When the SIP interface unit 33 of the client device 3-2 receives the SIP message to which the new RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the new RTP encryption. When the normality of the information is confirmed, the new RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the new RTP encryption information in the encryption information table 40, and sets the new RTP encryption information in the encryption / decryption unit 37 (g42 in FIG. 23).
After the call control sequence between client device 3-1 and client device 3-2 is completed (g24 in FIG. 23), RTP control unit 39 of client device 3-1 and RTP control unit 39 of client device 3-2 Is to continue the encrypted RTP transmission / reception using the new RTP encryption information set from the server device 1 (g36 in Fig. 23).
After that, in this embodiment, the periodic update of the RTP encryption information of the client devices 3-1 and 3-2 is repeated by controlling the above encryption information update timer and changing the setting to the new RTP encryption information (g25 in FIG. 23). ..
In this embodiment, with the above configuration and operation, the RTP encryption information when performing RTP communication between the client devices 3-1 and 3-2 can be changed periodically, so it can be changed from the outside. It has the effect of making it difficult to guess RTP encrypted information and strengthening security against eavesdropping.
Further, in the present embodiment, the set RTP encryption information has the same effect as that of the first embodiment of the present invention described above. Although the operation and operation of the client device 3-3 are not described, the same effect as the case of using the client devices 3-1 and 3-2 as described above can be obtained.
24 to 26 are sequence charts showing the operation of the client-server distributed system according to the eighth embodiment of the present invention. Since the client-server distributed system according to the eighth embodiment of the present invention has the same configuration as the client-server distributed system according to the second embodiment of the present invention shown in FIG. 6, the configuration will be described. Is omitted. Hereinafter, the operation of the client-server distributed system according to the eighth embodiment of the present invention will be described with reference to FIGS. 6 and 24 to 26. The processing of the server device 1a and the processing of the client devices 3a-1 and 3a-2 shown in FIGS. 24 to 26 are performed by each CPU of the server device 1a and the client devices 3a-1, 3a-2 executing a program. It will be realized.
The authentication process between the server device 1a and the client devices 3a-1,3a-2 has been completed in advance (h21, h22 in FIG. 24), and the server between the server device 1a and the client device 3a-1. SIP message encryption information is set between the device 1a and the client device 3a-2, respectively, and secure SIP message encryption transmission / reception is possible according to the SIP message encryption information. In this case, the encryption capability information of the client devices 3a-1 and 3a-2 is already set in the encryption information table 20 of the server device 1a (h23 in FIG. 24).
When a communication call is generated from the client device 3a-1 to the client device 3a-2 (h41 in FIG. 24), the call control unit 36 of the client device 3a-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1a via the SIP interface unit 33 (h42 in FIG. 24). ..
When the SIP interface unit 13 of the server device 1a receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that the communication is RTP communication between the client device 3a-1 and the client device 3a-2, and causes the encryption capability management unit 18 to communicate with the client device 3a-1 and the client device 3a-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3a-1 and the client device 3a-2 in the cryptographic information table 20 for each of the client devices 3a-1 and 3a-2. It is determined by the RTP encryption ability information of the above, and it is transmitted to the encryption information setting unit 11. In addition, the cryptographic ability management unit 18 stores the determined RTP cryptographic information in the cryptographic information table 20 as RTP cryptographic information for each of the client devices 3a-1 and 3a-2 (h24 in FIG. 24).
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the determined client device 3a-1 and the client device 3a-2, and the call control unit 16 adds the RTP encryption information to the client device 3a. Instruct the SIP message creation unit 14 to create a SIP message for -1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (h25 in FIG. 24).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (h43 in FIG. 24).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-2 to which the RTP encryption information between the client device 3a-1 and the client device 3a-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and transmits the created SIP message to the SIP interface unit 33 of the client device 3a-2 via the SIP interface unit 13 (h26 in FIG. 24).
When the SIP interface unit 33 of the client device 3a-2 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (h51 in FIG. 24).
After the call control sequence between the client device 3a-1 and the client device 3a-2 is completed (h27 in FIG. 24), the RTP control unit 39 of the client device 3a-1 and the RTP control unit 39 of the client device 3a-2 Is to execute encrypted RTP transmission / reception using the RTP encryption information set from the server device 1a (h44 in Fig. 24).
As shown in Fig. 25, when the new RTP encryption information setting is executed by external input to the server unit 1a, the new RTP encryption information of the client unit 3a-1 is input from the local maintenance console 2 connected to the server unit 1a. Then (h11, h12 in FIG. 25), the encryption information input interface unit 12 receives the setting request including the RTP encryption information, and when the normality of the setting request can be confirmed, the encryption ability of the RTP encryption information is obtained. Communicate to management department 18.
The cryptographic ability management unit 18 that has received the RTP cryptographic information edits the RTP cryptographic ability information including the RTP cryptographic rule list held by the client device 3a-1, creates new RTP cryptographic ability information, and goes to the cryptographic information setting unit 11. introduce. In addition, the encryption capability management unit 18 stores the new RTP encryption capability information in the encryption information table 20 (h28 in FIG. 25), and notifies the local maintenance console 2 that the setting is completed (h29 in FIG. 25).
Further, the cryptographic ability management unit 18 compares the RTP cryptographic information set between the client device 3a-1 and the client device 3a-2 in communication with the new RTP cryptographic ability information, and compares the RTP cryptographic information with the client device 3a-1. Determine the new RTP cryptographic information with the client device 3a-2 and record it in the cryptographic information table 20 (h30 in Figure 25). In this case, the encryption capability management unit 18 notifies the encryption information setting unit 11 of the new RTP encryption information.
The encryption information setting unit 11 notifies the call control unit 16 of the new RTP encryption information between the determined client device 3a-1 and the client device 3a-2, and the call control unit 16 adds the new RTP encryption information to the client. Instruct the SIP message creation unit 14 to create a SIP message for device 3a-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (h31 in FIG. 25).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP message to which the new RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the new RTP encryption. When the normality of the information is confirmed, the new RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the new RTP encryption information in the encryption information table 40, and sets the new RTP encryption information in the encryption / decryption unit 37 (h45 in FIG. 25).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-2 to which the new RTP encryption information between the client device 3a-1 and the client device 3a-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-2 via the SIP interface unit 13 (h32 in FIG. 25).
When the SIP interface unit 33 of the client device 3a-2 receives the SIP message to which the new RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the new RTP encryption. When the normality of the information is confirmed, the new RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the new RTP encryption information in the encryption information table 40, and sets the new RTP encryption information in the encryption / decryption unit 37 (h52 in FIG. 25).
After the call control sequence between the client device 3a-1 and the client device 3a-2 is completed, the RTP control unit 39 of the client device 3a-1 and the RTP control unit 39 of the client device 3a-2 are connected from the server device 1a. Executes encrypted RTP transmission / reception using the set new RTP encryption information (h46 in Fig. 25).
As shown in FIG. 26, when executing the new RTP encryption information setting by external input to the client device 3a-1, from the button interface of the maintenance console 4 or the client device 3a-1 connected to the client device 3a-1. When the new RTP cryptographic ability information of the client device 3a-1 is input (i11, a12 in FIG. 26), the cryptographic information input / output interface unit 32 receives the setting request including the RTP cryptographic ability information, and receives the setting request of the setting request. When the normality is confirmed, the RTP cryptographic ability information is transmitted to the cryptographic ability management unit 38.
Upon receiving the RTP encryption capability information, the encryption capability management unit 38 edits the RTP encryption capability information including the RTP encryption rule list held by the client device 3a-1, creates new RTP encryption capability information, and creates a new RTP encryption capability information 31. Communicate to. In addition, the encryption capability management unit 38 stores the new RTP encryption capability information in the encryption information table 40 (i31 in FIG. 26), and notifies the button interface of the maintenance console 4 or the client device 3a-1 that the setting is completed. (I32 in Figure 25).
Further, the cryptographic ability management unit 38 compares the RTP cryptographic information set between the client device 3a-1 and the client device 3a-2 in communication with the new RTP cryptographic ability information, and compares the RTP cryptographic information with the client device 3a-1. Determine the new RTP cryptographic information with the client device 3a-2 and record it in the cryptographic information table 40. In addition, the new RTP encryption information is notified to the encryption information setting unit 31.
The SIP message creation unit 34 of the client device a3-1 creates a SIP message to which the new RTP encryption capability information is added (i33 in FIG. 26), and the created SIP message is transmitted to the server device 1a via the SIP interface unit 33. It is transmitted to the SIP interface unit 13 (i34 in Fig. 26).
When the SIP interface unit 13 of the server device 1a receives the SIP message to which the new RTP encryption capacity information is added, the SIP message is transmitted to the SIP message analysis unit 15, and the SIP message analysis unit 15 determines the normality of the RTP encryption capacity information. If it can be confirmed, the new RTP encryption capability information is notified to the encryption capability management unit 18.
The cryptographic capability management unit 18 updates the RTP cryptographic capability information of the client device 3a-1 in the cryptographic information table 40, and the RTP cryptographic information used between the client device 3a-1 and the client device 3a-2 and the new client. Compare with the cryptographic capability information of device 3a-1 (i22 in Figure 26) to determine new RTP cryptographic information if changes are needed. In addition, the cryptographic ability management unit 18 stores new RTP cryptographic information in the cryptographic information table 40 and notifies the cryptographic information setting unit 11 of the new RTP cryptographic information. However, if the encryption capability management unit 18 does not need to be changed, the RTP encryption information is not changed (i23 in FIG. 26).
The encryption information setting unit 11 notifies the call control unit 16 of the new RTP encryption information between the determined client device 3a-1 and the client device 3a-2, and the call control unit 16 adds the new RTP encryption information to the client. Instruct the SIP message creation unit 14 to create a SIP message for device 3a-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (i24 in FIG. 26).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP message to which the new RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the new RTP encryption. When the normality of the information is confirmed, the new RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the new RTP encryption information in the encryption information table 40, and sets the new RTP encryption information in the encryption / decryption unit 37 (i35 in FIG. 26).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-2 to which the new RTP encryption information between the client device 3a-1 and the client device 3a-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-2 via the SIP interface unit 13 (i25 in FIG. 26).
When the SIP interface unit 33 of the client device 3a-2 receives the SIP message to which the new RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 transmits the new RTP encryption. When the normality of the information is confirmed, the new RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the new RTP encryption information in the encryption information table 40, and sets the new RTP encryption information in the encryption / decryption unit 37 (i41 in FIG. 26).
After the new RTP encryption information is set in both the client device 3a-1 and the client device 3a-2, the RTP control unit 39 of the client device 3a-1 and the RTP control unit 39 of the client device 3a-2 are the server devices. Executes encrypted RTP transmission / reception using the new RTP encryption information set from 1a (i36 in Fig. 26).
In this embodiment, with the above configuration and operation, the RTP encryption information when performing RTP communication between the client devices 3a-1 and 3a-2 can be changed at any time. It has the effect of making it difficult to infer RTP encrypted information from the outside and strengthening security against eavesdropping. Further, in the present embodiment, since the maintainer can change the encrypted information at an arbitrary timing, there is an effect that the maintainability can be enhanced.
Further, in this embodiment, the effect of the set RTP encryption information is the same as that of the first embodiment of the present invention described above. Although the operation and operation of the client device 3-3 are not described, the same effect as the case of using the client devices 3a-1 and 3a-2 as described above can be obtained.
27 to 29 are sequence charts showing the operation of the client-server distributed system according to the ninth embodiment of the present invention. Since the client-server distributed system according to the ninth embodiment of the present invention has the same configuration as the client-server distributed system according to the second embodiment of the present invention shown in FIG. 6, the configuration will be described. Is omitted. Hereinafter, the operation of the client-server distributed system according to the ninth embodiment of the present invention will be described with reference to FIGS. 6 and 27 to 29. The processing of the server device 1a and the processing of the client devices 3a-1 and 3a-2 shown in FIGS. 27 to 29 are performed by each CPU of the server device 1a and the client devices 3a-1, 3a-2 executing a program. It will be realized.
When the client device 3a-1 instructs the cryptographic information input / output interface section 32 to display the RTP cryptographic ability information that can be realized by the cryptographic ability information management unit 38 by an external instruction or at an arbitrary timing (j41 in FIG. 27). ), The cryptographic information input / output interface unit 32 requests the maintenance console 4 to output and display the cryptographic ability information of the client device 3a-1 (j42 in FIG. 27).
When the maintainer changes the presence or absence of encryption in the encryption capability information displayed from the maintenance console 4 or inputs the priority of the encryption rule to be used (j11 in Fig. 27), the maintenance console 4 has the RTP encryption capability. Notify the encryption information input / output interface unit 32 of the client device 3a-1 of the information (encryption presence / absence, encryption rule priority) setting request (j12 in FIG. 27).
The cryptographic information input / output interface unit 32 transmits the received RTP cryptographic ability information to the cryptographic ability management unit 38, and the cryptographic ability management unit 38 creates a cryptographic rule list from the received RTP cryptographic ability information and sends it to the cryptographic information setting unit 31. Notice. The cryptographic information setting unit 31 stores the received RTP cryptographic ability information in the cryptographic information table 40 (j43 in FIG. 27).
In the same procedure as above, the client device 3a-2 requests the maintenance console 4 to output and display the encryption capability information (j51, j52 in Fig. 27), receives the RTP encryption capability information of its own device from the maintenance console 4, and encrypts the encryption information. Store in table 3a (j13, j14, j53 in Figure 27).
Authentication between server device 1a and client device 3a-1 and between server device 1a and client device 3a-2 is completed at any time from the start of operation of client devices 3a-1 and 3a-2 to this point. (J21, j22 in Fig. 28).
The SIP message creation unit 34 of the client device 3a-1 creates a SIP message with RTP encryption capability information added, and sends the created SIP message to the SIP interface unit 13 of the server device 1a via the SIP interface unit 33 ( J44 in Figure 28).
When the SIP interface unit 13 of the server device 1a receives the SIP message to which the RTP encryption capacity information is added, the SIP message is transmitted to the SIP message analysis unit 15, and the SIP message analysis unit 15 determines the normality of the RTP encryption capacity information. If it can be confirmed, the RTP encryption capability information is notified to the encryption capability management unit 18.
The encryption capability management unit 18 checks whether the RTP encryption capability information of the client device 3a-1 has been set in the encryption information table 20 (j23 in Fig. 28), and if there is the set RTP encryption capability information, it receives it. Compare and edit with the RTP encryption capability information to create a new RTP encryption capability information that allows the client device 3a-1 to operate reliably (j24 in Fig. 28), and store the RTP encryption capability information in the encryption information table 20 (). Notify the encryption information setting unit 11 of j25) in FIG. 28. If there is no set RTP cryptographic ability information, the cryptographic ability management unit 18 stores the received RTP cryptographic ability information in the cryptographic information table 20 (j25 in FIG. 28).
Further, in the same procedure as above, the client device 3-2 creates a SIP message to which the RTP encryption capability information is added and sends it to the SIP interface section 13 of the server device 1a (j54 in FIG. 28). Therefore, the RTP encryption capability The information is stored in the cryptographic information table 20 of the server device 1 (j26 to j28 in FIG. 28).
When a communication call is made from the client device 3a-1 to the client device 3a-2 (j46 in FIG. 29), the call control unit 36 of the client device 3a-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1a via the SIP interface unit 33 (j47 in FIG. 29). ..
When the SIP interface unit 13 of the server device 1a receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that the communication is RTP communication between the client device 3a-1 and the client device 3a-2, and causes the encryption capability management unit 18 to communicate with the client device 3a-1 and the client device 3a-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3a-1 and the client device 3a-2 in the cryptographic information table 20 for each of the client devices 3a-1 and 3a-2. It is determined by the RTP encryption ability information of the above, and it is transmitted to the encryption information setting unit 11. In addition, the cryptographic ability management unit 18 stores the determined RTP cryptographic information in the cryptographic information table 20 as RTP cryptographic information for each of the client devices 3a-1 and 3a-2 (j29 in FIG. 29).
The encryption information setting unit 11 generates an encryption key used for RTP encryption between the client device 3a-1 and the client device 3a-2, and sets the encryption information table as the RTP encryption information of each of the client devices 3a-1 and 3a-2. Remember in 1a.
The encryption information setting unit 11 notifies the call control unit 16 of the RTP encryption information between the client device 3a-1 and the client device 3a-2 including the generated encryption key, and the call control unit 16 adds the RTP encryption information. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3a-1. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (j30 in FIG. 29).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (j47 in FIG. 29).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-2 to which the RTP encryption information between the client device 3a-1 and the client device 3a-2 is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-2 via the SIP interface unit 13 (j31 in FIG. 29).
When the SIP interface unit 33 of the client device 3a-2 receives the SIP message to which the RTP encryption information is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 receives the RTP encryption information. When the normality is confirmed, the RTP encryption information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the RTP encryption information in the encryption / decryption unit 37 (j56 in FIG. 29).
After the call control sequence between the client device 3a-1 and the client device 3a-2 is completed (j32 in FIG. 29), the RTP control unit 39 of the client device 3a-1 and the RTP control unit 39 of the client device 3a-2. Is to execute encrypted RTP transmission / reception using the RTP encryption information set from the server device 1a (j48 in Fig. 29).
In this embodiment, by realizing the above configuration and operation, the maintenance person or the user notifies the server device 1a from the client device 3a-1 of the encryption information that can be used for RTP encryption, and the server device 1a sends the encryption information. It manages RTP encryption capability information between client devices 3a-1 and 3a-2, and automatically operates between client devices 3a and 3a-2 during RTP communication between client devices 3a and 3a-2. It is possible to instruct each of the client devices 3a-1,3a-2 to the RTP encryption information that can be realized without fail, and the client devices 3a-1,3a-2 have multiple types of encryption capabilities. The cryptographic security function can be efficiently realized without the user being aware of the cryptographic rules.
Further, in the present embodiment, the set RTP encryption information has the same effect as the first and second embodiments of the present invention described above. Although the operation and operation of the client device 3a-3 are not described, the same effect as the case of using the client devices 3a-1 and 3a-2 as described above can be obtained.
FIG. 30 is a sequence chart showing the operation of the client-server distributed system according to the tenth embodiment of the present invention. Since the client-server distributed system according to the tenth embodiment of the present invention has the same configuration as the client-server distributed system according to the first embodiment of the present invention shown in FIG. 1, the configuration will be described. Is omitted. Hereinafter, the operation of the client-server distributed system according to the tenth embodiment of the present invention will be described with reference to FIGS. 1 and 30. The processing of the server device 1 and the processing of the client devices 3-1 and 3-2 shown in FIG. 30 are realized by executing the programs by the CPUs of the server device 1 and the client devices 3-1 and 3-2. ..
The authentication process between the server device 1 and the client device 3-1 and 3-2 has been completed in advance (k11 and k12 in Fig. 30), and the server between the server device 1 and the client device 3-1. SIP message encryption information is set between the device 1 and the client device 3-2, respectively, and secure SIP message encryption transmission / reception is possible according to the SIP message encryption information. In this case, the encryption capability information of the client devices 3-1 and 3-2 is already set in the encryption information table 20 of the server device 1 (k13 in FIG. 30).
When a communication call is made from the client device 3-1 to the client device 3-2 (k21 in Fig. 30), the call control unit 36 of the client device 3-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (k22 in FIG. 30). ..
When the SIP interface unit 13 of the server device 1 receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that it is RTP communication between the client device 3-1 and the client device 3-2, and causes the encryption capability management unit 18 to communicate with the client device 3-1 and the client device 3-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3-1 and the client device 3-2 in the cryptographic information table 20 for each of the client devices 3-1 and 3-2. When a selection is made based on the RTP encryption capability information of the above and as a result, no encryption is determined, it is transmitted to the encryption information setting unit 11. In addition, the encryption capability management unit 18 stores the determined non-encryption as the RTP encryption information of each of the client devices 3-1 and 3-2 in the encryption information table 20 (k14 in FIG. 30).
The encryption information setting unit 11 notifies the call control unit 16 of the unencrypted information between the determined client device 3-1 and the client device 3-2, and the call control unit 16 notifies the unencrypted information (call connection not possible). ) Is added to the client device 3-1 to instruct the SIP message creation unit 14 to create a SIP message. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (k15 in FIG. 30).
When the SIP interface unit 33 of the client device 3-1 receives a SIP message to which unencrypted information (call connection is not possible) is added, the SIP message is transmitted to the SIP message analysis unit 35 and sent to the SIP message analysis unit 35. When the normality of the unencrypted information can be confirmed, the unencrypted information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the information without the encryption in the encryption / decryption unit 37 (k33 in FIG. 30).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3-2 to which unencrypted information (call connection is not possible) between the client device 3-1 and the client device 3-2 is added. To do. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3-2 via the SIP interface unit 13 (k16 in FIG. 30).
When the SIP interface unit 33 of the client device 3-2 receives a SIP message to which unencrypted information (call connection is not possible) is added, the received SIP message is transmitted to the SIP message analysis unit 35, and the SIP message analysis unit 35 When the normality of the information without encryption can be confirmed in, the information without encryption is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the information without encryption in the encryption information table 40, and sets the information without encryption in the encryption / decryption unit 37 (k31 in FIG. 30).
After the call control sequence between client device 3-1 and client device 3-2 is completed (k17 in FIG. 30), RTP control unit 39 of client device 3-1 and RTP control unit 39 of client device 3-2 Since the call connection failure is notified, RTP communication is not executed.
In this embodiment, with the above configuration and operation, the server device 1 determines whether or not there is encryption when performing RTP communication between the client devices 3-1 and 3-2, and the encryption is performed. Since the client devices 3-1, 3-2 are notified that the call connection is not possible in the case of none, in an environment in which the client device having the function of the present invention and the client device not having the function of the present invention coexist. However, there is an effect that it can be easily dealt with by controlling the server device 1.
Further, in the present embodiment, the set RTP encryption information has the same effect as that of the first embodiment of the present invention described above. Although the operation and operation of the client device 3-3 are not described, the same effect as the case of using the client devices 3-1 and 3-2 as described above can be obtained.
31 to 33 are sequence charts showing the operation of the client-server distributed system according to the eleventh embodiment of the present invention. Since the client-server distributed system according to the eleventh embodiment of the present invention has the same configuration as the client-server distributed system according to the second embodiment of the present invention shown in FIG. 6, the configuration will be described. Is omitted. Hereinafter, the operation of the client-server distributed system according to the eleventh embodiment of the present invention will be described with reference to FIGS. 6 and 31 to 33. The processing of the server device 1a and the processing of the client devices 3a-1 and 3a-2 shown in FIGS. 31 to 33 are performed by each CPU of the server device 1a and the client devices 3a-1, 3a-2 executing a program. It will be realized. Further, FIGS. 31 to 33 show an example of setting from the server device 1a side.
The authentication process between the server device 1a and the client devices 3a-1,3a-2 has been completed in advance (l21, l22 in Fig. 31), and the server between the server device 1a and the client device 3a-1. SIP message encryption information is set between the device 1a and the client device 3a-2, respectively, and secure SIP message encryption transmission / reception is possible according to the SIP message encryption information.
When the enable / disable setting of RTP unencrypted communication of client device 3a-1 is input in advance from the local maintenance console 2 connected to server device 1a (l11, l12 in Fig. 31), the encrypted information input interface section 12 receives the setting request including the RTP encryption information, and transmits the RTP encryption information to the encryption ability management unit 18 when the normality of the setting request can be confirmed.
Upon receiving the RTP encryption information, the encryption capability management unit 18 creates RTP encryption capability information including the enable / disable setting of the RTP-unencrypted communication of the client device 3a-1 and transmits the RTP encryption capability information to the encryption information setting unit 11. In addition, the encryption capability management unit 18 stores the RTP encryption capability information in the encryption information table 20 (b23 in FIG. 7), and notifies the local maintenance console 2 of the completion of the setting via the encryption information input interface unit 12 (b23 in FIG. 7). L24 in Figure 31).
In addition, when the enable / disable of RTP-unencrypted communication of the client device 3a-1 is set from the local maintenance console 2 by the same procedure as above (l13, l14 in FIG. 31), the encryption information table 20 of the server device 1a is set. The RTP encryption capability information of the client device 3a-2 is created and stored in (l25 in Fig. 31), and the completion of the setting is notified to the local maintenance console 2 via the encryption information input interface unit 12 (l26 in Fig. 31). ).
When a communication call is made from the client device 3a-1 to the client device 3a-2 (l41 in FIG. 32), the call control unit 36 of the client device 3a-1 creates a SIP message for the call connection to the SIP message creation unit 34. 34, the SIP message creation unit 34 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 13 of the server device 1a via the SIP interface unit 33 (l42 in FIG. 32).
When the SIP interface unit 13 of the server device 1a receives the SIP message of the call connection, it transmits the SIP message to the SIP message analysis unit 15, and when the SIP message analysis unit 15 can confirm the normality of the SIP message, The SIP message is transmitted to the call control unit 16. The call control unit 16 recognizes that the communication is RTP communication between the client device 3a-1 and the client device 3a-2, and causes the encryption capability management unit 18 to communicate with the client device 3a-1 and the client device 3a-2. Instructs the determination of RTP cryptographic information to be used between.
Based on the instruction, the cryptographic ability management unit 18 stores the RTP cryptographic information between the client device 3a-1 and the client device 3a-2 in the cryptographic information table 20 for both the client devices 3a-1 and 3a-2. It is determined that there is no encryption based on the RTP encryption ability information of the above and transmitted to the encryption information setting unit 11. In addition, the cryptographic ability management unit 18 stores the determined RTP cryptographic information in the cryptographic information table 20 as RTP cryptographic information for each of the client devices 3a-1 and 3a-2 (l27 in FIG. 32).
The encryption information setting unit 11 determines whether or not RTP encryption-less communication is possible or not for each of the client devices 3a-1 and 3a-2 stored in the encryption information table 20 (l28 in FIG. 32), and the client device 3a-1. Alternatively, if unencrypted communication of the client device 3a-2 is possible, the RTP encryption information (no encryption) between the determined client device 3a-1 and the client device 3a-2 is notified to the call control unit 16 to control the call. Unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-1 to which the RTP encryption information (no encryption) is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (l29 in FIG. 32).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP message to which the RTP encrypted information (no encryption) is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 performs the SIP message. When the normality of the RTP encrypted information is confirmed, the RTP encrypted information (without encryption) is transmitted to the encrypted information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information (without encryption) in the encryption information table 40, and sets the RTP encryption information (without encryption) in the encryption / decryption unit 37 (l43 in FIG. 32).
On the other hand, the call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-2 to which the RTP encryption information (no encryption) between the client device 3a-1 and the client device 3a-2 is added. To do. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-2 via the SIP interface unit 13 (l30 in FIG. 32).
When the SIP interface unit 33 of the client device 3a-2 receives the SIP message to which the RTP encrypted information (no encryption) is added, the SIP interface unit 33 transmits the SIP message to the SIP message analysis unit 35, and the SIP message analysis unit 35 performs the SIP message. When the normality of the RTP encrypted information is confirmed, the RTP encrypted information (without encryption) is transmitted to the encrypted information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information (no encryption) in the client-side encryption information table 40, and sets the RTP encryption information (no encryption) in the encryption / decryption unit 37 (l51 in FIG. 32).
After the call control sequence between the client device 3a-1 and the client device 3a-2 is completed (l31 in FIG. 32), the RTP control unit 39 of the client device 3a-1 and the RTP control unit 39 of the client device 3a-2. Is to execute RTP communication without encryption using the RTP encryption information (without encryption) set from the server device 1a (l44 in Fig. 32).
The encryption information setting unit 11 determines whether or not RTP encryption-less communication is possible or not for each of the client devices 3a-1 and 3a-2 stored in the encryption information table 20 (l28 in FIG. 32), and the client device 3a-1. Alternatively, if unencrypted communication of the client device 3a-2 is not possible, the determined unencrypted information between the client device 3a-1 and the client device 3a-2 is notified to the call control unit 16, and the call control unit 16 notifies the call control unit 16. Instruct the SIP message creation unit 14 to create a SIP message for the client device 3a-1 to which the unencrypted information (call connection is not possible) is added. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (l29 in FIG. 32).
When the SIP interface unit 33 of the client device 3a-1 receives a SIP message to which unencrypted information (call connection is not possible) is added, the SIP message is transmitted to the SIP message analysis unit 35 and sent to the SIP message analysis unit 35. When the normality of the unencrypted information can be confirmed, the unencrypted information is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the RTP encryption information in the encryption information table 40, and sets the information without the encryption in the encryption / decryption unit 37 (l45 in FIG. 33).
The call control unit 16 instructs the SIP message creation unit 14 to create a SIP message for the client device 3a-2 to which unencrypted information (call connection is not possible) between the client device 3a-1 and the client device 3a-2 is added. To do. The SIP message creation unit 14 creates a SIP message based on the instruction, and sends the created SIP message to the SIP interface unit 33 of the client device 3a-2 via the SIP interface unit 13 (l33 in FIG. 33).
When the SIP interface unit 33 of the client device 3a-2 receives a SIP message to which unencrypted information (call connection is not possible) is added, the received SIP message is transmitted to the SIP message analysis unit 35, and the SIP message analysis unit 35 When the normality of the information without encryption can be confirmed in, the information without encryption is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the information without encryption in the encryption information table 40, and sets the information without encryption in the encryption / decryption unit 37 (l52 in FIG. 33).
After the call control sequence between the client device 3a-1 and the client device 3a-2 is completed (l34 in FIG. 33), the RTP control unit 39 of the client device 3a-1 and the RTP control unit 39 of the client device 3a-2. Since the call connection failure is notified, RTP communication is not executed.
In this embodiment, with the above configuration and operation, unencrypted communication is enabled / disabled from the local maintenance console 2 to the server device 1 when performing RTP communication between the client devices 3a-1 and 3a-2. Since the client devices 3a-1 and 3a-2 are notified that the call connection is not possible when communication is not possible without encryption, the client device having the function of the present invention and the client device not having the function of the present invention are set. Even in an environment where the above is mixed, there is an effect that it is possible to easily respond according to the setting of the client devices 3a-1 and 3a-2 for unencrypted communication / non-communications.
Further, in the present embodiment, the set RTP encryption information has the same effect as that of the first embodiment of the present invention described above. Although the operation and operation of the client device 3a-3 are not described, the same effect as the case of using the client devices 3a-1 and 3a-2 as described above can be obtained.
In the present invention, the client device displays the encrypted state, displays that RTP encrypted communication is in progress during RTP encrypted communication, and warns that RTP encrypted communication is in progress during RTP encrypted communication. It is also possible to display it.
Further, in the present invention, in the client device, when the server device determines that there is no RTP encryption at the start of RTP communication and instructs the client device for RTP communication instruction without encryption, the client device is instructed to perform RTP communication without encryption. A client that displays a request for communication start permission, notifies the server device of the RTP communication start permission setting when the RTP communication start permission setting is input from the outside, and connects to the RTP according to the received RTP communication start permission setting in the server device. If all the devices have RTP communication permission, the RTP communication is started, and if any of the client devices to be connected to RTP does not allow RTP communication, the RTP call connection fails and the RTP communication is performed. It is also possible to set it so that it does not exist.
Further, in the present invention, when the client device performs RTP communication to a plurality of RTP communication opposite devices at the same time, it is possible to set different RTP encryption information for each RTP communication opposed device. It is also possible to set and change the RTP encryption information and the SIP message encryption information set in the client device and the server device at independent timings.
<figref num="1">It is a block diagram which shows the structure of the client-server type distributed system corresponding to the SIP protocol by 1st Embodiment of this invention.</figref><figref num="2">It is a sequence chart which shows the operation of the client-server distributed system by 1st Embodiment of this invention.</figref><figref num="3">It is a sequence chart which shows the operation of the client-server distributed system by 1st Embodiment of this invention.</figref><figref num="4">It is a figure which shows the configuration example of the encryption information table of the server apparatus of FIG.</figref><figref num="5">It is a figure which shows the configuration example of the encryption information table of the client apparatus of FIG.</figref><figref num="6">It is a block diagram which shows the structure of the client-server type distributed system corresponding to the SIP protocol by the 2nd Example of this invention.</figref><figref num="7">It is a sequence chart which shows the operation of the client-server distributed system by 2nd Embodiment of this invention.</figref><figref num="8">It is a sequence chart which shows the operation of the client-server distributed system by 2nd Embodiment of this invention.</figref><figref num="9">It is a sequence chart which shows the operation of the client-server type distributed system by 2nd Embodiment of this invention.</figref><figref num="10">It is a sequence chart which shows the operation of the client-server type distributed system by the 3rd Example of this invention.</figref><figref num="11">It is a sequence chart which shows the operation of the client-server type distributed system by the 3rd Example of this invention.</figref><figref num="12">It is a sequence chart which shows the operation of the client-server type distributed system by 4th Embodiment of this invention.</figref><figref num="13">It is a sequence chart which shows the operation of the client-server type distributed system by 4th Embodiment of this invention.</figref><figref num="14">It is a figure which shows the configuration example of the encryption information table on the server apparatus side of the client-server type distributed system by 5th Embodiment of this invention.</figref><figref num="15">It is a figure which shows the configuration example of the encryption information table on the client apparatus side of the client-server type distributed system by 5th Embodiment of this invention.</figref><figref num="16">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="17">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="18">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="19">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="20">It is a block diagram which shows the structure of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="21">It is a sequence chart which shows the operation of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="22">It is a sequence chart which shows the operation of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="23">It is a sequence chart which shows the operation of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="24">It is a sequence chart which shows the operation of the client-server type distributed system by 8th Embodiment of this invention.</figref><figref num="25">It is a sequence chart which shows the operation of the client-server type distributed system by 8th Embodiment of this invention.</figref><figref num="26">It is a sequence chart which shows the operation of the client-server type distributed system by 8th Embodiment of this invention.</figref><figref num="27">It is a sequence chart which shows the operation of the client-server type distributed system by the 9th Example of this invention.</figref><figref num="28">It is a sequence chart which shows the operation of the client-server type distributed system by the 9th Example of this invention.</figref><figref num="29">It is a sequence chart which shows the operation of the client-server type distributed system by the 9th Example of this invention.</figref><figref num="30">It is a sequence chart which shows the operation of the client-server type distributed system by 10th Embodiment of this invention.</figref><figref num="31">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="32">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="33">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref>
Code description
1,1a, 1b SIP protocol compatible server device 2 Local maintenance console 3-1 ~ 3-3, 3a-1 ~ 3a-3 SIP protocol compatible client device 4 Maintenance console 11,31 Cryptographic information setting section 12,32 Cryptographic information input interface 13,33 SIP interface section 14,34 SIP message composer 15,35 SIP Message Analysis Department 16,36 Call control unit 17,37 Cryptography / decryption unit 18,38 Cryptographic Capacity Management Department 20,40 Cryptographic information table 21 Cryptographic information update timer control unit 39 RTP control unit 100 LAN
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2004192134A | Cites | Japan |
| JP2005303485A | Cites | Japan |
| JP2005346556A | Cites | Japan |
| JP2006054876A | Cites | Japan |
| JP200632997A | Cites | Japan |
14 members in 7 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2006206689 | Japan | A | |
| JP20060206689 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| GB0714737D0 | United Kingdom | D0 | |
| NL1034193A1 | Netherlands (Kingdom of the) | A1 | |
| US2008025516A1 | United States of America | A1 | |
| GB2440653A | United Kingdom | A | |
| AU2007203552A1 | Australia | A1 | |
| JP2008035235A | Japan | A | |
| CN101155188A | China | A | |
| HK1116954A1 | Hong Kong, China | A1 | |
| GB2440653B | United Kingdom | B | |
| JP4267008B2This record | Japan | B2 | |
| NL1034193C2 | Netherlands (Kingdom of the) | C2 | |
| US7965846B2 | United States of America | B2 | |
| AU2007203552B2 | Australia | B2 | |
| CN101155188B | China | B |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written notification of registration of transferR350 | R350 | |
| Written request for registration of change of nameS533 | S533 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer of reconsideration by examiner before appeal (zenchi)AppealA911 | A911 | |
| Written amendmentA521 | A521 | |
| Decision of refusalA02 | A02 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 |
Numbers
- Publication
- 4267008
- Publication, DOCDB
- 4267008
- Publication, EPODOC
- JP4267008B
- Application
- 206689
- Application, DOCDB
- 2006206689
- Application, EPODOC
- JP20060206689
Titles2
- Japanese
- クライアント・サーバ分散システム、サーバ装置、クライアント装置及びそれらに用いるクライアント間RTP暗号方法
- English
- Client-server distributed system, server device, client device and client-to-client RTP encryption method used for them
Classification
- CPC, 5
- H04L63/0428
- H04L63/0823
- H04L63/166
- H04L65/1104
- H04L65/65
- IPC, 2
- H04L9 14
- H04L12 22