Client server distributed system, client apparatus, server apparatus, and message encryption method used therefor
88 claims: 50 independent, 38 dependent
- 1A client-server type distribution in which a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol are each connected to a network and the SIP protocol operates on the UDP (User Datagram Protocol) protocol. In the system, the server device is a means for setting the encryption information used when sending and receiving a SIP message to and from the client device in the own device, and a SIP including the encryption information.requestA means for creating a message and notifying the client device, and when transmitting the SIP message to the client device after setting the encryption information, based on the encryption information.The relevantA means for encrypting and transmitting a SIP message, a means for decrypting the SIP message based on the encrypted information when the encrypted SIP message is received from the client device, and the decryption thereof.SIP messageThe client device has a means for performing control according to the content, and the client device is described as described above.SIP request messageIs received from the server deviceIncluded in SIP request messageA means for setting the encryption information in the own device, and when transmitting the SIP message to the server device after setting the encryption information, based on the encryption information.The relevantA means for encrypting a SIP message, a means for decrypting the SIP message based on the encrypted information when the encrypted SIP message is received from the server device, and the decryption thereof.SIP messageA client-server distributed system characterized by having a means for performing control according to the content. SIP(Session Initiation Protocol)プロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置とをそれぞれネットワークに接続して構成され、前記SIPプロトコルがUDP(User Datagram Protocol)プロトコル上で動作するクライアント・サーバ型分散システムであって、 前記サーバ装置は、前記クライアント装置とのSIPメッセージの送受信時に用いる暗号情報を自装置に設定する手段と、当該暗号情報を含むSIPリクエストメッセージを作成して前記クライアント装置に通知する手段と、前記暗号情報の設定後に前記クライアント装置に対して前記SIPメッセージを送信する際、前記暗号情報に基づいて当該SIPメッセージを暗号化して送信する手段と、暗号化されたSIPメッセージを前記クライアント装置から受信した時に当該SIPメッセージを前記暗号情報に基づいて復号化する手段と、その復号化されたSIPメッセージの内容に応じた制御を行う手段とを有し、 前記クライアント装置は、前記SIPリクエストメッセージを前記サーバ装置から受信した時に当該SIPリクエストメッセージに含まれる暗号情報を自装置に設定する手段と、前記暗号情報の設定後に前記サーバ装置に対して前記SIPメッセージを送信する際、前記暗号情報に基づいて当該SIPメッセージを暗号化する手段と、暗号化されたSIPメッセージを前記サーバ装置から受信した時に当該SIPメッセージを前記暗号情報に基づいて復号化する手段と、その復号化されたSIPメッセージの内容に応じた制御を行う手段とを有することを特徴とするクライアント・サーバ型分散システム。
- 23A client-server type distribution in which a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol are each connected to a network and the SIP protocol operates on the UDP (User Datagram Protocol) protocol. A message encryption method used in the system, in which the server device sets the encryption information used when sending and receiving a SIP message to and from the client device in its own device, and the SIP including the encryption information.requestA process of creating a message and notifying the client device, and a process of encrypting and transmitting the SIP message based on the encrypted information when transmitting the SIP message to the client device after setting the encryption information. When an encrypted SIP message is received from the client device, the SIP message is decrypted based on the encrypted information, and the decryption is performed.SIP messageThe client device executes the process of performing control according to the content, and the client device performs the process.SIP request messageIs received from the server deviceIncluded in SIP request messageIt is encrypted with a process of setting the encryption information in the own device and a process of encrypting the SIP message based on the encryption information when the SIP message is transmitted to the server device after the encryption information is set. A process of decrypting the SIP message based on the encrypted information when the SIP message is received from the server device, and the decryption thereof.SIP messageA message encryption method characterized by executing a process that controls according to the content. SIP(Session Initiation Protocol)プロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置とをそれぞれネットワークに接続して構成され、前記SIPプロトコルがUDP(User Datagram Protocol)プロトコル上で動作するクライアント・サーバ型分散システムに用いるメッセージ暗号方法であって、 前記サーバ装置が、前記クライアント装置とのSIPメッセージの送受信時に用いる暗号情報を自装置に設定する処理と、当該暗号情報を含むSIPリクエストメッセージを作成して前記クライアント装置に通知する処理と、前記暗号情報の設定後に前記クライアント装置に対して前記SIPメッセージを送信する際、前記暗号情報に基づいて前記SIPメッセージを暗号化して送信する処理と、暗号化されたSIPメッセージを前記クライアント装置から受信した時に当該SIPメッセージを前記暗号情報に基づいて復号化する処理と、その復号化されたSIPメッセージの内容に応じた制御を行う処理とを実行し、 前記クライアント装置が、前記SIPリクエストメッセージを前記サーバ装置から受信した時に当該SIPリクエストメッセージに含まれる暗号情報を自装置に設定する処理と、前記暗号情報の設定後に前記サーバ装置に対して前記SIPメッセージを送信する際、前記暗号情報に基づいて前記SIPメッセージを暗号化する処理と、暗号化されたSIPメッセージを前記サーバ装置から受信した時に当該SIPメッセージを前記暗号情報に基づいて復号化する処理と、その復号化されたSIPメッセージの内容に応じた制御を行う処理とを実行することを特徴とするメッセージ暗号方法。
- 28A process in which the server device sets an encryption rule input from the outside and used for darkening the SIP message in the own device, and a SIP including the encryption rule.requestA process of creating a message and notifying the client device, and a process of encrypting and transmitting the SIP message to the client device using the encryption rule in transmission / reception when the SIP message is encrypted. , The process of decrypting the SIP message received from the client device and encrypted using the encryption rule is executed, and the client device performs the process of decrypting the SIP message.SIP request messageIs received from the server deviceIncluded in SIP request messageThe process of setting the encryption rule in the own device, the process of encrypting and transmitting the SIP message to the server device using the encryption rule in the transmission / reception when the SIP message is encrypted, and the process of transmitting the SIP message. 23 or 24, wherein in transmission / reception with encryption, a process of decrypting a SIP message received from the server device and encrypted using the encryption rule is executed. Message encryption method. 前記サーバ装置が、外部から入力されかつ前記SIPメッセージの暗合化に用いる暗号則を自装置に設定する処理と、前記暗号則を含むSIPリクエストメッセージを作成して前記クライアント装置に通知する処理と、前記SIPメッセージの暗号化ありの場合の送受信において前記クライアント装置に対して前記SIPメッセージに前記暗号則を使用して暗号化して送信する処理と、前記クライアント装置から受信しかつ前記暗号則を使用して暗号化されたSIPメッセージを復号化する処理とを実行し、 前記クライアント装置が、前記SIPリクエストメッセージを前記サーバ装置から受信した時に当該SIPリクエストメッセージに含まれる暗号則を自装置に設定する処理と、前記SIPメッセージの暗号ありの場合の送受信において前記サーバ装置へのSIPメッセージを前記該暗号則を使用して暗号化して送信する処理と、前記SIPメッセージの暗号ありの場合の送受信において前記サーバ装置から受信しかつ前記暗号則を使用して暗号化されたSIPメッセージを復号化する処理とを実行することを特徴とする請求項23または請求項24記載のメッセージ暗号方法。
- 42Any of claims 23 to 41, wherein the server device executes a process of setting the encryption information of the SIP message for each client device for a plurality of client devices existing in the system. Described message encryption method. 前記サーバ装置が、システム内に複数存在するクライアント装置に対して当該クライアント装置毎の前記SIPメッセージの暗号情報の設定を行う処理を実行することを特徴とする請求項23から請求項41のいずれか記載のメッセージ暗号方法。
- 43A client-server type distribution in which a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol are respectively connected to a network and the SIP protocol operates on the UDP (User Datagram Protocol) protocol. A program to be executed by the central processing device of the server device in the system, which is a process of setting the encryption information used when sending and receiving a SIP message to and from the client device in the server device, and a SIP including the encryption information.requestA process of creating a message and notifying the client device, and a process of encrypting and transmitting the SIP message based on the encrypted information when transmitting the SIP message to the client device after setting the encryption information. When an encrypted SIP message is received from the client device, the SIP message is decrypted based on the encrypted information, and the decryption is performed.SIP messageA program characterized by including a process of performing control according to the content. SIP(Session Initiation Protocol)プロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置とをそれぞれネットワークに接続して構成され、前記SIPプロトコルがUDP(User Datagram Protocol)プロトコル上で動作するクライアント・サーバ型分散システムにおいて前記サーバ装置の中央処理装置に実行させるプログラムであって、 前記クライアント装置とのSIPメッセージの送受信時に用いる暗号情報を前記サーバ装置に設定する処理と、当該暗号情報を含むSIPリクエストメッセージを作成して前記クライアント装置に通知する処理と、前記暗号情報の設定後に前記クライアント装置に対して前記SIPメッセージを送信する際、前記暗号情報に基づいて前記SIPメッセージを暗号化して送信する処理と、暗号化されたSIPメッセージを前記クライアント装置から受信した時に当該SIPメッセージを前記暗号情報に基づいて復号化する処理と、その復号化されたSIPメッセージの内容に応じた制御を行う処理とを含むことを特徴とするプログラム。
- 44A client-server type distribution in which a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol are each connected to a network and the SIP protocol operates on the UDP (User Datagram Protocol) protocol. A program that is executed by the central processing device of the client device in the system, and is a SIP that includes encrypted information.requestWhen a message is received from the server device, the relevant message is received.Included in SIP request messageThe process of setting the encryption information in the client device and the server device after setting the encryption information.SIP messageA process of encrypting the SIP message based on the encrypted information and a process of decrypting the SIP message based on the encrypted information when the encrypted SIP message is received from the server device. , Its decryptedSIP messageA program characterized by including a process of performing control according to the content. SIP(Session Initiation Protocol)プロトコル対応のクライアント装置と前記SIPプロトコル対応のサーバ装置とをそれぞれネットワークに接続して構成され、前記SIPプロトコルがUDP(User Datagram Protocol)プロトコル上で動作するクライアント・サーバ型分散システムにおいて前記クライアント装置の中央処理装置に実行させるプログラムであって、 暗号情報を含むSIPリクエストメッセージを前記サーバ装置から受信した時に当該SIPリクエストメッセージに含まれる暗号情報を前記クライアント装置に設定する処理と、前記暗号情報の設定後に前記サーバ装置に対してSIPメッセージを送信する際、前記暗号情報に基づいて前記SIPメッセージを暗号化する処理と、暗号化されたSIPメッセージを前記サーバ装置から受信した時に当該SIPメッセージを前記暗号情報に基づいて復号化する処理と、その復号化されたSIPメッセージの内容に応じた制御を行う処理とを含むことを特徴とするプログラム。
Independent claims6
407 paragraphs, as filed
The present invention relates to a client-server distributed system, a client device, a server device, a message encryption method used therein, and a program thereof. In particular, SIP between clients and servers of a client-server distributed system compatible with the SIP (Session Initiation Protocol) protocol. Regarding the message encryption method.
In a client-server distributed system that supports the SIP protocol, it is necessary to ensure security because it is a system connected on a LAN (Local Area Network). As a countermeasure, SIP messages that control between the client and server The encryption method of is defined. Generally, SSL / TLS (Secure Socket Layer / Transport Layer Security) and the like are defined as the SIP message encryption method.
Since the SSL / TLS method requires mutual certificates (see, for example, Non-Patent Document 1), when applied to the above-mentioned client-server distributed system, a certificate is given to the client-server device in advance. Need to be distributed. In addition, it is necessary to prepare an authentication server in the above-mentioned client-server distributed system and authenticate the certificate in order to distribute the encryption key.
Furthermore, in the above-mentioned client-server type distributed system, when encrypting a SIP message, the entire SIP message is encrypted. Therefore, in a network in which a network device such as SIP-NAT (Network Address Translator) exists, SIP- Cannot communicate via NAT.
Since TCP (Transmission Control Protocol) is used as the layer 4 protocol, it is not optimal for VoIP (Voice over Internet Protocol) communication where real-time performance is important. Generally, UDP (User Datagram Protocol) protocol is adopted for VoIP communication. Has been done.
As a method of delivering an encryption key used for authentication in a network, the methods shown in Patent Documents 1 to 5 below have been proposed.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2004-302846</text></patcit><patcit num="2"><text>Japanese Unexamined Patent Publication No. 2004-343782</text></patcit><patcit num="3"><text>Japanese Patent Application Laid-Open No. 2005-045473</text></patcit><patcit num="4"><text>Japanese Patent Application Laid-Open No. 2005-051680</text></patcit><patcit num="5"><text>Japanese Patent Application Laid-Open No. 2005-216188</text></patcit><nplcit num="1"><text>"Introduction to Cryptographic Technology-Alice in the Secret Country, Chapter 14 SSL / TLS" (Hiroshi Yuki, published by Softbank Publishing, September 27, 2003, pp.346-367)</text></nplcit>
<p> In the above-mentioned conventional client-server distributed system that supports the SIP protocol, when encrypting a SIP message between client-server, it is necessary to authenticate with a certificate to notify the encryption key, so the client-server model There is a problem that it is necessary to distribute the certificate to the device, a certificate management function is required, and the labor of the maintainer increases.</p><p> In addition, in the conventional client-server type distributed system, when encrypting a SIP message, the entire SIP message is encrypted. Therefore, in a network where a network device such as SIP-NAT exists, the SIP-NAT is used. There is a problem that communication cannot be performed and network expandability is low.</p><p> Further, since the conventional client-server distributed system uses TCP as the layer 4 protocol, there is a problem that it is difficult to ensure real-time performance in VoIP communication.</p><p> Therefore, in the conventional technology, there is a problem that the man-hours of the maintainer are required for certificate management and the cost is high to realize the cryptographic security function such as the need for the authentication server for authentication. There is. Further, in the conventional technology, since the global address and the local address cannot be read by using the SIP-NAT function, there is a problem that it is difficult to secure the expandability of the network construction by assigning the address.</p><p> Further, the conventional technology has a problem that it is difficult to ensure real-time performance when applied as security for VoIP communication. Furthermore, the conventional technology has a function to update the encryption key when the communication becomes long, but other encryption information (encryption presence / absence, encryption rule, encryption range) cannot be changed, so that all encryption information There is a problem that the cryptographic security function level is lower than that of sending and receiving SIP messages while changing. It is difficult to solve these problems even if the encryption key delivery method used for authentication or the like described in the above-mentioned Patent Documents 1 to 5 is used.</p><p> Therefore, an object of the present invention is to solve the above problems without requiring a certificate authentication function for distributing an encryption key, holding or managing a certificate, installing an authentication server in the system, or the like. It is an object of the present invention to provide a client-server type distributed system, a client device, a server device, a message encryption method used for them, and a program thereof, which can realize a cryptographic security function at low cost.</p>
<p> The client-server type distributed system according to the present invention is configured by connecting a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol to a network, respectively, and the SIP protocol is UDP (User Datagram Protocol). ) A client-server distributed system that runs on the protocol The server device has a means for setting encryption information used when sending and receiving a SIP message with the client device in its own device, and a SIP including the encryption information.<u style="single">request</u>A means for creating a message and notifying the client device, and when transmitting the SIP message to the client device after setting the encryption information, based on the encryption information.<u style="single">The relevant</u>A means for encrypting and transmitting a SIP message, a means for decrypting the SIP message based on the encrypted information when the encrypted SIP message is received from the client device, and the decryption thereof.<u style="single">SIP message</u>Equipped with means to control according to the content The client device is the<u style="single">SIP request message</u>Is received from the server device<u style="single">Included in SIP request message</u>A means for setting the encryption information in the own device, and when transmitting the SIP message to the server device after setting the encryption information, based on the encryption information.<u style="single">The relevant</u>A means for encrypting a SIP message, a means for decrypting the SIP message based on the encrypted information when the encrypted SIP message is received from the server device, and the decryption thereof.<u style="single">SIP message</u>It is equipped with a means for controlling according to the content.</p><p> The client device according to the present invention includes the means described in the above-mentioned client-server distributed system.</p><p> The server device according to the present invention includes the means described in the above-mentioned client-server distributed system.</p><p> The message encryption method according to the present invention is configured by connecting a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol to a network, respectively, and the SIP protocol is on the UDP (User Datagram Protocol) protocol. A message encryption method used for client-server distributed systems that operate on The process of setting the encryption information used by the server device when sending and receiving SIP messages to and from the client device in its own device, and the SIP including the encryption information.<u style="single">request</u>A process of creating a message and notifying the client device, and a process of encrypting and transmitting the SIP message based on the encrypted information when transmitting the SIP message to the client device after setting the encryption information. When an encrypted SIP message is received from the client device, the SIP message is decrypted based on the encrypted information, and the decryption is performed.<u style="single">SIP message</u>Execute the process that controls according to the content, The client device<u style="single">SIP request message</u>Is received from the server device<u style="single">Included in SIP request message</u>It is encrypted with a process of setting the encryption information in the own device and a process of encrypting the SIP message based on the encryption information when the SIP message is transmitted to the server device after the encryption information is set. A process of decrypting the SIP message based on the encrypted information when the SIP message is received from the server device, and the decryption thereof.<u style="single">SIP message</u>It is executing a process that controls according to the content.</p><p> The program according to the present invention is configured by connecting a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol to a network, respectively, and the SIP protocol operates on the UDP (User Datagram Protocol) protocol. A program to be executed by the central processing device of the server device in the client-server type distributed system. The process of setting the encryption information used when sending and receiving SIP messages to and from the client device in the server device, and the SIP including the encryption information.<u style="single">request</u>A process of creating a message and notifying the client device, and a process of encrypting and transmitting the SIP message based on the encrypted information when transmitting the SIP message to the client device after setting the encryption information. When an encrypted SIP message is received from the client device, the SIP message is decrypted based on the encrypted information, and the decryption is performed.<u style="single">SIP message</u>It is characterized by including a process of performing control according to the content.</p><p> Another program according to the present invention is configured by connecting a client device compatible with the SIP (Session Initiation Protocol) protocol and a server device compatible with the SIP protocol to a network, respectively, and the SIP protocol is on the UDP (User Datagram Protocol) protocol. It is a program to be executed by the central processing device of the client device in the client-server type distributed system that operates in. SIP containing cryptographic information<u style="single">request</u>When a message is received from the server device, the relevant message is received.<u style="single">Included in SIP request message</u>The process of setting the encryption information in the client device and the server device after setting the encryption information.<u style="single">SIP message</u>A process of encrypting the SIP message based on the encrypted information and a process of decrypting the SIP message based on the encrypted information when the encrypted SIP message is received from the server device. , Its decrypted<u style="single">SIP message</u>It is characterized by including a process of performing control according to the content. </p><p> That is, the client-server type distributed system of the present invention is a system compatible with the SIP (Session Initiation Protocol) protocol that connects to the Internet, the intranet, and the LAN (Local Area Network), and is a layer 4 protocol called UDP (User Datagram Protocol). It is a system that communicates with.</p><p> The client-server type distributed system of the present invention has a maintenance interface in which a SIP protocol-compatible server device is connected by a LAN or a serial interface in the above system, and the maintenance interface is connected to a SIP protocol-compatible client device. The encryption information (whether or not to encrypt, the protocol, and the encryption range) for realizing the SIP message encryption function when sending and receiving SIP messages is entered and set.</p><p> When sending and receiving SIP messages to and from the client device, this server device uses the SIP protocol without executing authentication such as the encryption presence / absence, encryption rule, encryption range, and encryption key of the SIP message to the connecting client device. The SIP message is encrypted and decrypted according to the set encryption presence / absence / encryption rule / encryption range / encryption key, and the encryption presence / absence / encryption rule / encryption range / encryption key is updated arbitrarily or periodically. , The encryption information is operated with different settings for each connected client device.</p><p> The above client device sets the encryption information when the server device instructs the encryption information (encryption presence / absence, encryption rule, encryption range, encryption key) for realizing the SIP message encryption function when sending and receiving SIP messages. To do. When sending and receiving SIP messages to and from the server device, the client device uses the SIP protocol without executing authentication such as the presence / absence of encryption, encryption rules, encryption range, and encryption key of the SIP message with the server device to be connected. The SIP message is encrypted and decrypted according to the set encryption presence / absence / encryption rule / encryption range / encryption key, and the encryption presence / absence / encryption rule / encryption range / encryption key is updated.</p><p> As a result, in the client-server type distributed system of the present invention, the certificate authentication function for distributing the encryption key is not required, the certificate is not retained or managed, and the authentication server is prepared in the system. It is possible to realize a cryptographic security function at low cost.</p><p> Further, in the client-server type distributed system of the present invention, by making the encryption range of the SIP message variably set, encryption can be performed even in a network configuration such as a SIP-NAT (Network Address Translator) in the network. It is possible to strengthen the cryptographic security function.</p><p> Further, in the client-server distributed system of the present invention, by using UDP as a layer 4 protocol, the cryptographic security function can be realized without impairing the real-time property which is important for VoIP (Voice over Internet Protocol) communication. Is possible.</p><p> Furthermore, in the client-server type distributed system of the present invention, it is possible to update encryption information (encryption presence / absence, encryption rule, encryption range) other than the encryption key, and it is possible to set different encryption information for each device. By performing arbitrary or periodic automatic update of information, it is possible to prevent the cryptographic state from being inferred, and it is possible to strengthen the cryptographic security function.</p>
<p> The present invention has the above configuration and operation, and does not require a certificate authentication function for distributing an encryption key, holding or management of a certificate, installation of an authentication server in the system, or the like. , The effect that the cryptographic security function can be realized at low cost can be obtained.</p>
Next, examples of the present invention will be described with reference to the drawings.
FIG. 1 is a block diagram showing a configuration of a client-server distributed system compatible with the SIP (Session Initiation Protocol) protocol according to the first embodiment of the present invention. In FIG. 1, the client-server type distributed system according to the first embodiment of the present invention includes a SIP protocol-compatible server device (hereinafter referred to as a server device) 1, a local maintenance console 2, and a SIP protocol-compatible client device (hereinafter referred to as a server device). It consists of 3-1 to 3-3 (which is a client device) and maintenance console 4. In addition, server device 1, client devices 3-1 to 3-3, and maintenance console 4 are each connected to LAN (Local Area Network) 100.
The server device 1 includes at least the encryption information setting unit 11, the encryption information input interface unit 12, the SIP interface unit 13, the SIP message creation unit 14, the SIP message analysis unit 15, the SIP message encryption / decryption unit 16, and the like. It is composed of a call control unit 17, and a local maintenance console 2 is connected to the server device 1 by a serial cable or the like. The local maintenance console 2 is temporarily installed during the construction period of the server device 1, and does not have to be connected during operation.
Further, in the server device 1, the above-mentioned encryption information setting unit 11, encryption information input interface unit 12, SIP interface unit 13, SIP message creation unit 14, SIP message analysis unit 15, SIP message encryption / decryption unit 16, and call control unit Each of 17 can be realized by executing a program by a CPU (Central Processing Unit) (not shown).
The client device 3-1 is composed of at least the encryption information setting unit 31, the SIP interface unit 33, the SIP message creation unit 34, the SIP message analysis unit 35, the SIP message encryption / decryption unit 36, and the call control unit 37. It is configured. Further, in the client device 3-1 the above-mentioned encryption information setting unit 31, SIP interface unit 33, SIP message creation unit 34, SIP message analysis unit 35, SIP message encryption / decryption unit 36, and call control unit Each of 37 can be realized by executing a program by a CPU (not shown). Further, the client devices 3-2 and 3-3 have the same configuration as the above client device 3-1.
By configuring the server device 1 and the client devices 3-1 to 3-3 as described above, the SIP message can be encrypted during communication between the server device 1 and the client devices 3-1 to 3-3. The security of SIP message control on the IP (Internet Protocol) network can be strengthened.
2 to 4 are sequence charts showing the operation of the client-server distributed system according to the first embodiment of the present invention. The operation of the client-server distributed system according to the first embodiment of the present invention will be described with reference to FIGS. 1 to 4. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 2 to 4 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the local maintenance console 2 connected to the server device 1 inputs in advance the presence or absence of SIP message encryption when sending and receiving SIP messages to and from the client device 3-1 and the encryption rules and encryption range when there is encryption (a11 in Fig. 2). ), The encryption information input interface unit 12 receives the setting request including the information, and when the normality of the setting request can be confirmed, transmits the information to the encryption information setting unit 11. The encryption information setting unit 11 stores the information including the encryption key (hereinafter, the information group including the encryption key is referred to as encryption information) (a21 in FIG. 2).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the encryption information (a22 in FIG. 2). The SIP message creation unit 14 creates a SIP request message based on the instruction, and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (a23 in FIG. 2).
The SIP interface unit 33 of the client device 3-1 receives the SIP request message containing the encrypted information, transmits the received SIP request message to the SIP message analysis unit 35, and the SIP message analysis unit 35 normalizes the encrypted information. When the sex can be confirmed, the encrypted information is transmitted to the encrypted information setting unit 31. The encryption information setting unit 31 stores the encryption information, sets the encryption information in the SIP message encryption / decryption unit 36 (a41 in FIG. 2), and notifies the SIP message creation unit 34 of the completion of the encryption information setting after the setting is completed. Instruct to create a SIP response message (a42 in Figure 2). The SIP message creation unit 34 creates a SIP response message based on the instruction, and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (a43 in FIG. 2).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the completion of the encryption information setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits the encryption information setting completion notification on the client device 3-1 side to the encryption information setting unit 11, the encryption information setting unit 11 recognizes the completion of the encryption information setting, and the SIP message encryption / decryption unit Instruct 16 to set the encryption information (a24 in FIG. 2), and after the setting is completed, the encryption information input interface unit 12 transmits the setting completion to the local maintenance console 2 (a25 in FIG. 2). The local maintenance console 2 displays the completion of encryption information setting (a13 in Fig. 2).
When the server device 1 makes a request to send a SIP request message to the client device 3-1 after the encryption information is set in the SIP message encryption / decryption unit 16 (a27 in Fig. 2), the SIP message creation unit 14 uses SIP. A request message is created, and the created SIP request message is encrypted by the SIP message encryption / decryption unit 16 using the encrypted information (a28, a29 in FIG. 2). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (a30 in FIG. 3).
When the SIP interface unit 33 receives the encrypted SIP request message from the server device 1 after the encryption information is set in the SIP message encryption / decryption unit 36, the SIP interface unit 33 encrypts the received SIP message by SIP message encryption. -Transfer to the decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message using the currently set encryption information (a44 in FIG. 3).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (a45 in FIG. 3). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (a46 in FIG. 3). The SIP response message created by the SIP message creation unit 34 is encrypted using the encryption information currently set by the SIP message encryption / decryption unit 36 (a47 in FIG. 3), and is encrypted via the SIP interface unit 33. It is transmitted to the SIP interface section 13 of the server device 1 (a48 in Fig. 3).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16, and the SIP message encryption / decryption unit 16 is currently set. The SIP response message is decrypted using the encrypted information (a31 in Fig. 3), the decrypted SIP response message is analyzed by the SIP message analysis unit 15, and the call control is executed by the call control unit 17 depending on the content of the message. Is done (a32 in Figure 3).
Conversely, when a request to send a SIP request message to server device 1 occurs on client device 3-1 (a49 in Fig. 3), the SIP message creation unit 34 creates a SIP request message and uses the created SIP request message as a SIP. The message encryption / decryption unit 36 encrypts the encryption information using the encrypted information (a50 and a51 in FIG. 3). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (a52 in FIG. 3).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1 the SIP interface unit 13 transfers the received SIP message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP request message using the currently set encryption information (a33 in FIG. 3).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (a34 in FIG. 3). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (a35 in FIG. 4). The SIP message creation unit 14 creates a SIP response message, and encrypts the created SIP response message using the encryption information currently set in the SIP message encryption / decryption unit 16 (a36 in FIG. 4). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (a37 in FIG. 4).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP response message using the currently set encryption information (a53 in Fig. 4). The decrypted SIP response request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (a54 in FIG. 4).
As described above, in this embodiment, the SIP message is encrypted according to the encryption information arbitrarily set by the maintainer, so that the security on the IP network can be strengthened and the maintenance of the server device 1 can be performed. It is possible to distribute the encryption information used for encrypting / decrypting the SIP message set by the system maintainer to the client devices 3-1 to 3-3 via the interface, and set the encryption capability in consideration of the entire system. It can be performed uniformly from one place, and maintenance work can be simplified and maintenance manpower can be reduced.
In addition, SSL / TLS (Secure Socket Layer / Transport Layer Security) is generally used as a security method in conventional SIP. However, in this embodiment, there is no need to distribute the certificate to each device, the certificate management function, or the certificate authentication by the authentication server, and the encryption function can be realized by a simpler procedure than the SSL / TLS method. In addition, since UDP (User Datagram Protocol) is used as the layer 4 protocol, real-time performance can be ensured and security can be enhanced. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
5 to 7 are sequence charts showing the operation of the client-server distributed system according to the second embodiment of the present invention. The client-server distributed system according to the second embodiment of the present invention has the same configuration as the client-server distributed system according to the first embodiment of the present invention shown in FIG. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the second embodiment of the present invention will be described with reference to FIGS. 1 and 5 to 7. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 5 to 7 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the maintenance console 4 that connects to the server device 1 via LAN100 inputs in advance the presence or absence of SIP message encryption when sending and receiving SIP messages to and from the client device 3-1 and the encryption rules and encryption range when there is encryption (Fig.) 5 b11), the encryption information input interface unit 12 receives the setting request including the information (b12 in FIG. 5), and when the normality of the information is confirmed, transmits the information to the encryption information setting unit 11. .. The encryption information setting unit 11 stores the information including the encryption key (hereinafter, the information group including the encryption key is referred to as encryption information) (b21 in FIG. 5).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the encryption information (b22 in FIG. 5). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (b23 in FIG. 5).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message containing the encrypted information, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the encryption information, the SIP message analysis unit 35 transmits the encryption information to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption information, sets the encryption information in the SIP message encryption / decryption unit 36 (b41 in FIG. 5), and notifies the SIP message creation unit 34 of the completion of the encryption information setting after the setting is completed. Instruct to create a SIP response message (b42 in Figure 5). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (b43 in FIG. 5).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the completion of the encryption information setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits the encryption information setting completion notification on the client device 3-1 side to the encryption information setting unit 11, and the encryption information setting unit 11 recognizes the completion of the encryption information setting and encrypts / decrypts the SIP message. Instruct the unit 16 to set the encryption information (b24 in FIG. 5), and after the setting is completed, the encryption information input interface unit 12 transmits the setting completion to the maintenance console 4 (b25 in FIG. 5). The maintenance console 4 displays the completion of encryption information setting (b13 in Fig. 5).
In FIGS. 5 to 7, the operations after the completion of setting the encryption information for the server device 1 and the client device 3-1 are b26 to b29 in FIG. 5, b30 to b34 in FIG. 6, b44 to b52 in FIG. 7, and b35 in FIG. Since the processing operations of b37, b53, and b54 are the same operations as those of the first embodiment of the present invention shown in FIGS. 2 to 4 above, the description thereof will be omitted.
Therefore, in this embodiment, the server device 1 can be set using both the local maintenance console 2 connected by the encryption information input interface unit 12 with a serial cable or the like and the maintenance console 4 connected with the LAN interface. Therefore, the ease of maintenance can be ensured. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
FIG. 8 is a block diagram showing a configuration of a client-server distributed system according to a third embodiment of the present invention. In FIG. 8, the client-server distributed system according to the third embodiment of the present invention is connected to the local maintenance console 2 connected to the server device 1a and the LAN 100, except for the encrypted information input interface unit 12 of the server device 1a. Except for the maintenance console 4, the configuration is the same as that of the client-server distributed system according to the first embodiment of the present invention shown in FIG. 1, and the same components are designated by the same reference numerals. There is.
In the client-server type distributed system according to the third embodiment of the present invention, it is assumed that the encryption information has already been set in the SIP message encryption / decryption unit 16 of the server device 1a, and the SIP message encryption / decryption unit of the client device 3-1. It is assumed that the encryption information has already been set in 36.
By realizing the above configuration, in this embodiment, when communicating between the server device 1a and the client device 3-1 the arbitrary range of the SIP message is encrypted and the SIP message is controlled on the IP network. Security can be strengthened.
9 and 10 are sequence charts showing the operation of the client-server distributed system according to the third embodiment of the present invention. The operation of the client-server distributed system according to the third embodiment of the present invention will be described with reference to FIGS. 8 to 10. The processing of the server device 1a and the processing of the client device 3-1 shown in FIGS. 9 and 10 are realized by executing the programs by the CPUs of the server device 1a and the client device 3-1.
With the encryption information set in the SIP message encryption / decryption unit 16 of the server device 1a and the SIP message encryption / decryption unit 36 of the client device 3-1 (c10 in Fig. 9), the client device 3- When a request to send a SIP request message to 1 occurs (c11 in Fig. 9), the SIP message creation unit 14 creates a SIP request message, and the created SIP request message is encrypted by the SIP message encryption / decryption unit 16. Encrypt according to the specified encryption range using (c12, c13 in Fig. 9). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (c14 in FIG. 9).
When the SIP interface unit 33 receives a SIP request message in which the set encryption range is encrypted from the server device 1a, the SIP interface unit 33 transfers the received SIP message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message according to the specification of the encryption range by using the currently set encryption information (c31 in FIG. 9).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (c32 in FIG. 9). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (c33 in FIG. 9). The SIP message creation unit 34 creates a SIP response message, and encrypts the created SIP response message according to the specification of the encryption range using the encryption information currently set in the SIP message encryption / decryption unit 36 (Fig. 9 c34). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1a via the SIP interface unit 33 (c35 in FIG. 9).
When the SIP interface unit 13 of the server device 1a receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP response message according to the specification of the encryption range using the currently set encryption information (c15 in FIG. 9). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (c16 in FIG. 9).
Conversely, when a request to send a SIP request message to server device 1a occurs on client device 3-1 (c36 in Fig. 10), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. The message encryption / decryption unit 36 uses the encryption information to encrypt according to the specification of the encryption range (c37, c38 in FIG. 10). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the service b device 1a via the SIP interface unit 33 (c39 in FIG. 10).
When the SIP interface unit 13 receives a SIP request message in which the set encryption range is encrypted from the client device 3-1 the SIP interface unit 13 transfers the received SIP message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP request message according to the specification of the encryption range by using the currently set encryption information (c17 in FIG. 10).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (c18 in FIG. 10). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (c19 in FIG. 10). The SIP message creation unit 14 creates a SIP response message, and encrypts the created SIP response message according to the specification of the encryption range using the encryption information currently set in the SIP message encryption / decryption unit 16 (Fig.). 10 c20). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (c21 in FIG. 10).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP response message according to the specification of the encryption range using the currently set encryption information. The decrypted SIP response message is analyzed by the SIP message analysis unit 35 (c40 in FIG. 10), and call control is executed by the call control unit 37 according to the content of the message (c41 in FIG. 10).
In this embodiment, the SIP message control on the IP network is performed by encrypting an arbitrary range of the SIP message during communication between the server device 1a and the client device 3-1 by the above operation. Security can be strengthened. An example of the encryption range to be set will be described below.
11 and 12 are diagrams showing an example of a cryptographic range according to a third embodiment of the present invention. Figure 11 shows an example of a cryptographic range that encrypts the entire SIP message. The shaded area in Fig. 11 is the data range to be encrypted. In the case of this encryption range example, the SIP header A2 and SDP (Session Description Protocol) data A3 of the SIP message are all encrypted, so the data is over the IP network. It is possible to enhance security against eavesdropping and data tampering when SIP messages are played.
Figure 12 is an example of a cryptographic range that encrypts any part of a SIP message. The shaded area in Fig. 12 is the data range to be encrypted. In this encryption range example, only an arbitrary range of SIP messages (SDP data B4 only) is encrypted, so the SIP header depends on the encryption range selection status. It is also possible to set so that B2 and SDP data B3 and B5 can be operated via network devices such as SIP-NAT without encryption, and important data parts that require encryption can be set. Since it is possible to perform transmission / reception with encryption, it is possible to strengthen the encryption security as well as the network function.
In this way, in this embodiment, when encrypting the entire SIP message including the SIP header and SDP data, it is possible to realize strong cryptographic security against eavesdropping and data tampering during communication on the IP network. it can. When encrypting any part of a SIP message, it is possible to operate via a network device such as SIP-NAT without encrypting the SIP header or SDP data depending on the encryption range selection state. Since it is possible to set and send / receive important data parts that require encryption by encrypting them, it is possible to strengthen the encryption security and the network function.
Further, the effect of the SIP message encryption function according to the present embodiment is the same as that of the first and second embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
FIG. 13 is a block diagram showing a configuration of a client-server distributed system according to a fourth embodiment of the present invention. In FIG. 13, the client-server distributed system according to the fourth embodiment of the present invention is the client-server model according to the first embodiment of the present invention shown in FIG. 1, except for the maintenance console 4 connected to the LAN 100. It has the same configuration as the server-type distributed system, and the same components are designated by the same code.
In this embodiment, by realizing the above configuration, the SIP message is encrypted during communication between the server device 1 and the client device 3-1 to enhance the security of SIP message control on the IP network. be able to.
14 to 16 are sequence charts showing the operation of the client-server distributed system according to the fourth embodiment of the present invention. The operation of the client-server distributed system according to the fourth embodiment of the present invention will be described with reference to FIGS. 13 to 16. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 14 to 16 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the encryption range of the SIP message when sending and receiving the SIP message with the client device 3-1 is input in advance from the local maintenance console 2 connected to the server device 1 (d11 in FIG. 14), the encryption information input interface unit 12 is said to be the same. When the setting request including the encryption range is received (d12 in FIG. 14) and the normality of the setting request can be confirmed, the encryption range is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 stores the encryption range (d21 in FIG. 14).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the encryption range (d22 in FIG. 14). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (d23 in FIG. 14).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message including the encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the encryption range, the SIP message analysis unit 35 transmits the encryption range to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption range, sets the encryption range in the SIP message encryption / decryption unit 36 (d41 in FIG. 14), and notifies the SIP message creation unit 34 of the completion of the encryption range setting after the setting is completed. Instruct to create a SIP response message (d42 in Figure 14). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (d43 in FIG. 14).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the completion of the encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits the encryption range setting completion notification on the client device 3-1 side to the encryption information setting unit 11, and the encryption information setting unit 11 recognizes the completion of the encryption range setting and encrypts / decrypts the SIP message. Instruct unit 16 to set the encryption range (d24 in FIG. 14), and after the setting is completed, the encryption information input interface unit 12 transmits the setting completion to the local maintenance console 2 (d25 in FIG. 14). Local maintenance console 2 displays the completion of encryption range setting (d13 in Figure 14).
When a request to send a SIP request message to the client device 3 occurs on the server device 1 after the encryption range is set in the SIP message encryption / decryption section 16 (d27 in FIG. 14), the SIP message creation section 14 sends the SIP request message. Is created, and the created SIP request message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP request message according to the current encryption range setting (d28, d29 in FIG. 14). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3 via the SIP interface unit 13 (d30 in FIG. 15).
When the SIP interface unit 33 receives the encrypted SIP request message from the server device 1 after the encryption range is set in the SIP message encryption / decryption unit 36, the received SIP request message is sent to the SIP message encryption / decryption unit 36. Transfer to. The SIP message encryption / decryption unit 36 decrypts the encryption range of the SIP request message according to the current encryption range setting (d44 in FIG. 15).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (d45 in FIG. 15). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (d46 in FIG. 15). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 according to the current encryption range setting (Fig. 15). D47). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (d48 in FIG. 15).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP response message according to the currently set encryption range setting (d31 in FIG. 15). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (d32 in FIG. 15).
Conversely, when client device 3 makes a request to send a SIP request message to server device 1 (d49 in FIG. 15), the SIP message creation unit 34 creates a SIP request message and encrypts the created SIP request message with SIP message encryption. -The decryption unit 36 encrypts the encryption range of the SIP request message according to the current encryption range setting (d50, d51 in FIG. 15). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (d52 in FIG. 15).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP request message according to the current encryption range setting (d33 in FIG. 15).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (d34 in FIG. 15). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (d35 in FIG. 16). The SIP message creation unit 14 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 16 according to the current encryption range setting (Fig. 16). D36). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3 via the SIP interface unit 13 (d37 in FIG. 16).
When the SIP interface unit 33 of the client device 3 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the encryption range of the SIP response message according to the current encryption range setting (d53 in FIG. 16). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (d54 in FIG. 16).
As described above, in this embodiment, local maintenance is performed in a system that supports both a method of encrypting the entire SIP message and a method of encrypting an arbitrary part of the SIP message in the encryption range of the SIP message. By making it possible to arbitrarily select the range of encryption from console 2, both cryptographic security and network functionality are satisfied in the system where network devices such as SIP-NAT exist, and the current network configuration. It is possible to select and realize the optimum security level for.
Further, in this embodiment, by setting the encryption information to the client devices 3-1 to 3-3 from the server device 1, it is possible to realize system uniformity and easy maintenance of the maintainer. Further, in this embodiment, the effect of the SIP message encryption function using the set encryption range information is the same as that of the first to third embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
17 to 19 are sequence charts showing the operation of the client-server distributed system according to the fifth embodiment of the present invention. Since the client-server distributed system according to the fifth embodiment of the present invention has the same configuration as the client-server distributed system according to the fourth embodiment of the present invention shown in FIG. 13, the configuration thereof will be described. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the fifth embodiment of the present invention will be described with reference to FIGS. 13 and 17 to 19. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 17 to 19 are realized by executing programs by the CPUs of the server device 1 and the client device 3-1.
When the presence / absence of encryption of the SIP message when sending / receiving the SIP message to / from the client device 3 is input in advance from the local maintenance console 2 connected to the server device 1 (e11 in FIG. 17), the encryption information input interface unit 12 has the presence / absence of the encryption. (E12 in FIG. 17), and when the normality of the setting request is confirmed, the presence or absence of the encryption is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 stores the presence / absence of the encryption (e21 in FIG. 17).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the presence or absence of encryption (e22 in FIG. 17). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3 via the SIP interface unit 13 (e23 in FIG. 17).
When the SIP interface unit 33 of the client device 3 receives the SIP request message including the presence or absence of encryption, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 can confirm the normality of the encryption presence / absence, the SIP message analysis unit 35 transmits the encryption presence / absence to the encryption information setting unit 31. The encryption information setting unit 31 stores the presence / absence of the encryption, sets the presence / absence of the encryption in the SIP message encryption / decryption unit 36 (e41 in FIG. 17), and notifies the SIP message creation unit 34 of the completion of the encryption presence / absence setting after the setting is completed. Instruct to create a SIP response message (e42 in Figure 17). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (e43 in FIG. 17).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the completion of the encryption presence / absence setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of completion of encryption presence / absence setting on the client device 3 side to the encryption information setting unit 11, and the encryption information setting unit 11 recognizes the completion of the encryption presence / absence setting, and the SIP message encryption / decryption unit 16 Is instructed to set the presence / absence of the encryption (e24 in FIG. 17), and after the setting is completed, the encryption information input interface unit 12 transmits the setting completion to the local maintenance console 2 (e25 in FIG. 17). The local maintenance console 2 displays the completion of encryption setting (e13 in Fig. 17).
When a request to send a SIP request message to the client device 3 occurs on the server device 1 after the encryption / non-encryption is set in the SIP message encryption / decryption section 16 (e27 in FIG. 17), the SIP message creation section 14 performs the SIP request message. Is created, and the created SIP request message is transmitted to the SIP message encryption / decryption unit 16 (e28 in FIG. 17). The SIP message encryption / decryption unit 16 encrypts the SIP request message when there is encryption (e29 in FIG. 17) according to the current encryption presence / absence setting (e30 in FIG. 17). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3 via the SIP interface unit 13 (e31 in FIG. 18).
When the SIP interface unit 33 receives the encrypted SIP request message from the server device 1 after the encryption presence / absence is set in the SIP message encryption / decryption unit 36, the received SIP request message is sent to the SIP message encryption / decryption unit 36. Transfer to. The SIP message encryption / decryption unit 36 decrypts the SIP request message when there is encryption (e44 in FIG. 18) according to the current encryption presence / absence setting (e45 in FIG. 18).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (e46 in FIG. 18). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (e47 in FIG. 18). The SIP message creation unit 34 creates a SIP response message, and transmits the created SIP response message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the SIP response message when there is encryption (e48 in FIG. 18) according to the current encryption presence / absence setting (e49 in FIG. 18). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (e50 in FIG. 18).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP response message when there is encryption (e32 in FIG. 18) according to the currently set encryption presence / absence setting (e33 in FIG. 18). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (e34 in FIG. 18).
Conversely, when client device 3 makes a request to send a SIP request message to server device 1 (e51 in FIG. 18), the SIP message creation unit 34 creates a SIP request message and encrypts the created SIP request message with SIP message encryption. -Transmit to the decoding unit 36. The SIP message encryption / decryption unit 36 encrypts the SIP request message when there is encryption according to the current encryption presence / absence setting (e52 in FIG. 18 and e53 in FIG. 19). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (e55 in FIG. 19).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP request message when there is encryption (e35 in FIG. 19) according to the current encryption presence / absence setting (e36 in FIG. 19).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (e37 in FIG. 19). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (e38 in FIG. 19). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP response message when there is encryption (e39 in FIG. 19) according to the current encryption presence / absence setting (e3a in FIG. 19). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3 via the SIP interface unit 13 (e3b in FIG. 19).
When the SIP interface unit 33 of the client device 3 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP response message when there is encryption (e56 in FIG. 19) according to the current encryption presence / absence setting (e57 in FIG. 19). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (e58 in FIG. 19).
As described above, in this embodiment, the maintainer can arbitrarily set the presence or absence of encryption of the SIP message via the server device 1. Therefore, when the setting is made with encryption, the encryption security function on the network is realized. In addition to being able to do this, it is possible to make different settings that do not require encryption depending on the network configuration, and for maintenance work, it is easy to make settings without encryption when collecting SIP message logs, etc. Simplification can be realized.
Further, in this embodiment, system uniformity can be realized by setting the encryption information in the client device 3-1 from the server device 1. Further, in this embodiment, by having a function of selecting the presence or absence of encryption, compatibility with the client device 3-1 having no encryption function can be ensured.
In this embodiment, the effect of the SIP message encryption function using the set encryption presence / absence information is the same as that of the first and second embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
20 to 22 are sequence charts showing the operation of the client-server distributed system according to the sixth embodiment of the present invention. Since the client-server distributed system according to the sixth embodiment of the present invention has the same configuration as the client-server distributed system according to the fourth embodiment of the present invention shown in FIG. 13, the configuration thereof will be described. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the sixth embodiment of the present invention will be described with reference to FIGS. 13 and 20 to 22. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 20 to 22 are realized by executing programs by the CPUs of the server device 1 and the client device 3-1.
When the encryption rule of the SIP message when sending and receiving the SIP message to and from the client device 3-1 is input in advance from the local maintenance console 2 connected to the server device 1 (f11 in FIG. 20), the encryption information input interface unit 12 is said to be the same. A setting request including a cryptographic rule is received (f12 in FIG. 20), and when the normality of the setting request is confirmed, the cryptographic rule is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 stores the encryption rule (f21 in FIG. 20).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including a cryptographic rule (f22 in FIG. 20). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (f23 in FIG. 20).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message including the encryption rule, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the encryption rule, the SIP message analysis unit 35 transmits the encryption rule to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption rule, sets the encryption rule in the SIP message encryption / decryption unit 36 (f41 in FIG. 20), and notifies the SIP message creation unit 34 of the completion of the encryption rule setting after the setting is completed. Instruct to create a SIP response message (f42 in Figure 20). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (f43 in FIG. 20).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the completion of the encryption rule setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of completion of encryption rule setting on the client device 3-1 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of the encryption rule setting, instructs the SIP message encryption / decryption unit 16 to set the encryption rule (f24 in FIG. 20), and after the setting is completed, the encryption information input interface unit 12 starts. Send the setting completion to the local maintenance interface 2 (f25 in Figure 20). Local maintenance console 2 displays the completion of cipher rule setting (f13 in Fig. 20).
After the encryption rule is set in the SIP message encryption / decryption unit 16, when the server device 1 makes a request to send a SIP request message to the client device 3-1 (f27 in Fig. 20), the SIP message creation unit 14 is SIP. Create a request message and transmit the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message according to the current encryption rule settings (f28, f29 in FIG. 20). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (f30 in FIG. 21).
When the SIP interface unit 33 receives the encrypted SIP request message from the server device 1 after the encryption rule is set in the SIP message encryption / decryption unit 36, the received SIP message is transmitted to the SIP message encryption / decryption unit 36. Forward. The SIP message encryption / decryption unit 36 decrypts the SIP request message according to the current encryption rule setting (f44 in FIG. 21).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (f45 in FIG. 21). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (f46 in FIG. 21). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 according to the current encryption rule settings (f47 in FIG. 21). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (f48 in FIG. 21).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP response message according to the currently set encryption rule settings (f31 in FIG. 21). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (f32 in FIG. 21).
Conversely, when a request to send a SIP request message to server device 1 occurs on client device 3-1 (f49 in Fig. 21), the SIP message creation unit 34 creates a SIP request message and uses the created SIP request message as a SIP. The message encryption / decryption unit 36 encrypts according to the current encryption rule settings (f50, f51 in FIG. 21). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (f52 in FIG. 21).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the SIP request message according to the current encryption rule setting (f33 in FIG. 21).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (f34 in FIG. 21). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (f35 in FIG. 22). The SIP message creation unit 14 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 16 according to the current encryption rule settings (f36 in FIG. 22). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (f37 in FIG. 22).
When the SIP interface unit 33 of the SIP protocol-compatible client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP response message according to the current encryption rule setting (f53 in FIG. 22). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (f54 in FIG. 22).
As described above, in this embodiment, the cryptographic security function on the network can be realized by encrypting the SIP message, and it is possible to set different cryptographic rules for each network configuration, and further, cryptographic security. Can be strengthened. Further, in this embodiment, system uniformity can be realized by setting the encryption rule for the client device 3-1 from the server device 1.
Further, in this embodiment, in the future, when adding a cryptographic rule that can be operated by the system, the new cryptographic rule can be used without additional development of the cryptographic rule selection interface, so that the maintenance interface change is minimized. It can be limited and facilitate development. Furthermore, in this embodiment, the effect of the SIP message encryption function using the set cryptographic rule information is the same as that of the first and second embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
23 to 25 are sequence charts showing the operation of the client-server distributed system according to the seventh embodiment of the present invention. Since the client-server distributed system according to the seventh embodiment of the present invention has the same configuration as the client-server distributed system according to the fourth embodiment of the present invention shown in FIG. 13, the configuration thereof will be described. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the seventh embodiment of the present invention will be described with reference to FIGS. 13 and 23 to 25. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 23 to 25 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the encryption presence / absence / encryption range of the SIP message when sending / receiving the SIP message to / from the client device 3-1 is input in advance from the local maintenance console 2 connected to the server device 1 (g11 in Fig. 23), the encryption information input interface section 12 receives a setting request including the encryption presence / absence / encryption range (g12 in FIG. 23), and when the normality of the setting request is confirmed, transmits the encryption presence / absence / encryption range to the encryption information setting unit 11. The encryption information setting unit 11 stores the presence / absence of encryption and the encryption range (g21 in FIG. 23).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the presence / absence of encryption and the encryption range (g22 in FIG. 23). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (g23 in FIG. 23).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message including the presence / absence of encryption and the encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 can confirm the presence / absence of encryption / normality of the encryption range, the SIP message analysis unit 35 transmits the presence / absence of encryption / encryption range to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption presence / absence / encryption range, sets the encryption presence / absence / encryption range in the SIP message encryption / decryption unit 36 (g41 in FIG. 23), and after the setting is completed, the SIP message creation unit 34 Instructs to create a SIP response message to notify the completion of encryption / encryption range setting (g42 in Fig. 23). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (g43 in FIG. 23).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the presence / absence of encryption and the completion of the encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of the completion of setting the encryption presence / absence / encryption range on the SIP protocol-compatible client device 3-1 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of the encryption presence / absence / encryption range setting, instructs the SIP message encryption / decryption unit 16 to set the encryption presence / absence / encryption range (g24 in FIG. 23), and after the setting is completed, encrypts. The information input interface section 12 sends the setting completion to the local maintenance console 2 (g25 in Fig. 23). Local maintenance console 2 displays the presence / absence of encryption and the completion of encryption range setting (g13 in Fig. 23).
When a request to send a SIP request message to client device 3-1 occurs on server device 1 after the encryption presence / absence / encryption range is set in the SIP message encryption / decryption section 16 (g27 in Fig. 23), the SIP message creation section 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP request message when there is encryption (g28, g29 in FIG. 23) according to the current encryption presence / absence / encryption range setting (g30 in FIG. 23). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (g31 in FIG. 24).
When the SIP interface unit 33 receives the encrypted SIP request message from the server device 1 after the encryption presence / absence is set in the SIP message encryption / decryption unit 36, the received SIP message is transmitted to the SIP message encryption / decryption unit 36. Forward. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption presence / absence / encryption range setting (g44 in FIG. 24), the SIP message encryption / decryption unit 36 decrypts the encryption range in the SIP request message (g45 in FIG. 24).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (g46 in FIG. 24). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (g47 in FIG. 24). The SIP message creation unit 34 creates a SIP response message, and transmits the created SIP response message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP response message when there is encryption according to the current encryption presence / absence / encryption range setting (g48 in FIG. 24). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (g50 in FIG. 24).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP response message when there is encryption according to the currently set encryption presence / absence / encryption range setting (g32 in FIG. 24) (g33 in FIG. 24). .. The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (g34 in FIG. 24).
Conversely, when a request to send a SIP request message to server device 1 occurs on client device 3-1 (g51 in Fig. 24), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. It is transmitted to the message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP request message when there is encryption according to the current encryption presence / absence / encryption range setting (g52 in FIG. 24, g53 in FIG. 25). g54). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (g55 in FIG. 25).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption presence / absence / encryption range setting (g35 in FIG. 25), the SIP message encryption / decryption unit 16 decrypts the encryption range in the SIP request message (g36 in FIG. 25).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (g37 in FIG. 25). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (g38 in FIG. 25). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP response message when there is encryption according to the current encryption presence / absence / encryption range setting (g39 in FIG. 25) (g3a in FIG. 25). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (g3b in FIG. 25).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption presence / absence / encryption range setting (g56 in FIG. 25), the SIP message encryption / decryption unit 36 decrypts the encryption range in the SIP response message (g57 in FIG. 25). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (g58 in FIG. 25).
As described above, in this embodiment, the local maintenance console 2 is used in a system that supports both a method of encrypting the entire SIP message and a method of encrypting an arbitrary part of the SIP message in the encryption range of the SIP message. By making it possible to arbitrarily select the range of encryption from, it satisfies both cryptographic security and network functionality in the system where network devices such as SIP-NAT exist, and is optimal for the current network configuration. Security level can be selected and realized.
Further, in this embodiment, since the maintainer can arbitrarily set the presence / absence of encryption of the SIP message via the server device 1, when the setting is made with encryption, the encryption security function on the network can be realized. At the same time, it is possible to make different settings that do not require encryption depending on the network configuration, and it is easy to make settings without encryption when collecting SIP message logs for maintenance work, which facilitates maintenance by the maintainer. It can be realized.
Further, in this embodiment, by setting the encryption information in the client device 3-1 from the server device 1, it is possible to realize system uniformity and easy maintenance of the maintainer. Furthermore, in this embodiment, by having a function of selecting the presence or absence of encryption, compatibility with a client device having no encryption function can be ensured.
In this embodiment, the effect of the SIP message encryption function using the set encryption presence / absence / encryption range information is the same as that of the first to fifth embodiments of the present invention described above. Further, although the operation of the client devices 3-2 and 3-3 is not described, the same effect as the case of using the client device 3-1 can be obtained.
26 to 28 are sequence charts showing the operation of the client-server distributed system according to the eighth embodiment of the present invention. Since the client-server distributed system according to the eighth embodiment of the present invention has the same configuration as the client-server distributed system according to the fourth embodiment of the present invention shown in FIG. 13, the configuration thereof will be described. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the eighth embodiment of the present invention will be described with reference to FIGS. 13 and 26 to 28. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 26 to 28 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the encryption presence / absence / encryption rule of the SIP message when sending / receiving the SIP message to / from the client device 3-1 is input in advance from the local maintenance console 2 connected to the server device 1 (h11 in Fig. 26), the encryption information input interface section 12 receives a setting request including the encryption presence / absence / encryption rule (h12 in FIG. 26), and when the normality of the setting request can be confirmed, transmits the encryption presence / absence / encryption rule to the encryption information setting unit 11. The encryption information setting unit 11 stores the presence / absence of encryption and the encryption rule (h21 in FIG. 26).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the presence / absence of encryption and the encryption rule (h22 in FIG. 26). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (h23 in FIG. 26).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message including the presence / absence of encryption and the encryption rule, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 can confirm the presence / absence of encryption / normality of the encryption rule, the SIP message analysis unit 35 transmits the presence / absence of encryption / encryption rule to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption presence / absence / encryption rule, sets the encryption presence / absence / encryption rule in the SIP message encryption / decryption unit 36 (h41 in FIG. 26), and after the setting is completed, the SIP message creation unit 34 Instructs to create a SIP response message to notify the completion of encryption / encryption rule setting (h42 in Fig. 26). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (h43 in FIG. 26).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the presence / absence of encryption and the completion of the encryption rule setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of the presence / absence of encryption / encryption rule setting completion on the client device 3-1 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of the encryption presence / absence / encryption rule setting, instructs the SIP message encryption / decryption unit 16 to set the encryption presence / absence / encryption rule (h24 in FIG. 26), and after the setting is completed, encrypts. The information input interface unit 12 sends the setting completion to the local maintenance console 2 (h25 in Fig. 26). The local maintenance console 2 displays the presence / absence of encryption and the completion of encryption rule setting (h13 in Fig. 26).
When a request to send a SIP request message to client device 3-1 occurs in server device 1 after the encryption presence / absence / encryption rules are set in the SIP message encryption / decryption section 16 (h27 in Fig. 26), the SIP message creation section The SIP request message created by 14 is transmitted to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption presence / absence / encryption rule setting (h28, h29 in FIG. 26), the SIP request message is encrypted by the encryption rule (h30 in FIG. 26). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (h31 in FIG. 27).
When the SIP interface unit 33 receives an encrypted SIP request message from the server device 1 after the encryption presence / absence / encryption rule is set in the SIP message encryption / decryption unit 36, the received SIP message is encrypted / decrypted by the SIP message. Transfer to part 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption presence / absence / encryption rule setting (h44 in FIG. 27), the SIP request message is decrypted by the encryption rule (h45 in FIG. 27).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (h46 in FIG. 27). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (h47 in FIG. 27). The SIP message creation unit 34 creates a SIP response message, and transmits the created SIP response message to the SIP message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption presence / absence / encryption rule setting (h48 in FIG. 27), the SIP response message is encrypted by the encryption rule (h49 in FIG. 27). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (h50 in FIG. 27).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the currently set encryption presence / absence / encryption rule setting (h32 in FIG. 27), the SIP response message is decrypted by the encryption rule (h33 in FIG. 27). .. The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (h34 in FIG. 27).
Conversely, when a request to send a SIP request message to server device 1 occurs on client device 3-1 (h51 in Fig. 27), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. It is transmitted to the message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the SIP request message with the encryption rule when there is encryption according to the current encryption presence / absence / encryption rule setting (h52 in FIG. 27, h53 in FIG. 28). h54). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (h55 in FIG. 28).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption presence / absence / encryption rule setting (h35 in FIG. 28), the SIP request message is decrypted by the encryption rule (h36 in FIG. 28).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (h37 in FIG. 28). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (h38 in FIG. 28). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption presence / absence / encryption rule setting (h39 in FIG. 28), the SIP response message is encrypted by the encryption rule (h3a in FIG. 28). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (h3b in FIG. 28).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption presence / absence / encryption rule setting (h56 in FIG. 28), the SIP response message is decrypted by the encryption rule (h57 in FIG. 28). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (h58 in FIG. 28).
As described above, in this embodiment, the maintainer can arbitrarily set the presence or absence of encryption of the SIP message via the server device 1. Therefore, when the setting is made with encryption, the encryption security function on the network is realized. In addition to being able to do this, it is possible to make different settings depending on the network configuration, and it is easy to make settings without encryption when collecting SIP message logs for maintenance work. Can be realized.
Further, in this embodiment, by having a function of selecting the presence or absence of encryption, compatibility with a client device having no encryption function can be ensured. Further, in this embodiment, by encrypting the SIP message, it is possible to realize the cryptographic security function on the network, and it is possible to set different cryptographic rules for each network configuration, and further to provide cryptographic security. Can be strengthened.
Furthermore, in this embodiment, when adding a cryptographic rule that can be operated in the system in the future, the new cryptographic rule can be used without additional development of the cryptographic rule selection interface, so that the maintenance interface is changed. Can be minimized and development can be facilitated.
On the other hand, in this embodiment, system uniformity can be realized by setting the encryption information in the client device 3-1 from the server device 1. Further, in this embodiment, the effects of the SIP message encryption function using the set encryption presence / absence / encryption rule information are described in detail with the first, second, fifth, and sixth embodiments of the present invention, respectively. It has a similar effect. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
29 to 31 are sequence charts showing the operation of the client-server distributed system according to the ninth embodiment of the present invention. Since the client-server distributed system according to the ninth embodiment of the present invention has the same configuration as the client-server distributed system according to the fourth embodiment of the present invention shown in FIG. 13, the configuration thereof will be described. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the ninth embodiment of the present invention will be described with reference to FIGS. 13 and 29 to 31. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 29 to 31 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the encryption rule / encryption range of the SIP message when sending / receiving the SIP message to / from the client device 3-1 is input in advance from the local maintenance console 2 connected to the server device 1 (i11 in Fig. 29), the encryption information input interface section 12 receives a setting request including the encryption rule / encryption range (i12 in FIG. 29), and when the normality of the setting request is confirmed, transmits the encryption rule / encryption range to the encryption information setting unit 11. .. The encryption information setting unit 11 stores the encryption rule / encryption range (i21 in FIG. 29).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the encryption rule / encryption range (i22 in FIG. 29). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (i23 in FIG. 29).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message including the encryption rule / encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the encryption rule / encryption range, the SIP message analysis unit 35 transmits the encryption rule / encryption range to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption rule / encryption range, sets the encryption rule / encryption range in the SIP message encryption / decryption unit 36 (i41 in FIG. 29), and after the setting is completed, the SIP message creation unit 34 Instructs to create a SIP response message notifying the completion of encryption rule / encryption range setting (i42 in Fig. 29). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (i43 in FIG. 29).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the completion of the encryption rule / encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of completion of setting of the encryption rule / encryption range on the SIP protocol compatible client device 3 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes that the setting of the encryption rule / encryption range is completed, instructs the SIP message encryption / decryption unit 16 to set the encryption rule / encryption range (i24 in FIG. 29), and after the setting is completed, encrypts. The information input interface unit 12 sends the setting completion to the local maintenance console 2 (i25 in Fig. 29). The local maintenance console 2 displays the completion of encryption rule / encryption range setting (i13 in Fig. 29).
When a request to send a SIP request message to client device 3-1 occurs on server device 1 after the encryption rule / encryption range is set in the SIP message encryption / decryption section 16 (i27 in Fig. 29), the SIP message creation section 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16 (i28 in FIG. 29). The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP request message according to the current encryption rule / encryption range setting (i29 in FIG. 29). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (i30 in FIG. 30).
When the SIP interface unit 33 receives an encrypted SIP request message from the server device 1 after the encryption rule / encryption range is set in the SIP message encryption / decryption unit 36, the received SIP message is encrypted / decrypted by the SIP message. Transfer to part 36. The SIP message encryption / decryption unit 36 decrypts the encryption range of the SIP request message according to the current encryption rule / encryption range setting (i44 in FIG. 30).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (i45 in FIG. 30). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (i46 in FIG. 30). The SIP message creation unit 34 creates a SIP response message, and transmits the created SIP response message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP response message according to the current encryption rule / encryption range setting (i47 in FIG. 30). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (i48 in FIG. 30).
When the SIP interface unit 13 of the server device 1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP response message according to the currently set encryption rule / encryption range setting (i31 in FIG. 30). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (i32 in FIG. 30).
Conversely, when a request to send a SIP request message to server device 1 occurs on client device 3-1 (i49 in Fig. 30), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. It is transmitted to the message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP request message according to the current encryption rule / encryption range setting (i50, i51 in FIG. 30). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (i52 in FIG. 30).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP request message according to the current encryption rule / encryption range setting (i33 in FIG. 30).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (i34 in FIG. 30). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (i35 in FIG. 31). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP response message according to the current encryption rule / encryption range setting (i36 in FIG. 31). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (i37 in FIG. 31).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the encryption range of the SIP response message according to the current encryption rule / encryption range setting (i53 in FIG. 31). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (i54 in FIG. 31).
As described above, in this embodiment, the local maintenance console is used in a system that supports both a method of encrypting the entire SIP message and a method of encrypting an arbitrary part of the SIP message in the encryption range of the SIP message. By making it possible to select the range of encryption arbitrarily from 2, it satisfies both cryptographic security and network functionality in the system where network devices such as SIP-NAT exist, and is optimal for the current network configuration. Security level can be selected and realized.
Further, in this embodiment, the encryption security function on the network can be realized by encrypting the SIP message, and it is possible to set different encryption rules and encryption ranges for each network configuration. Cryptographic security can be strengthened. Further, in this embodiment, by setting the encryption rule / encryption range to the client device 3-1 from the server device 1, it is possible to realize system uniformity and easy maintenance of the maintainer.
Furthermore, in this embodiment, when adding a cryptographic rule that can operate in the system in the future, the new cryptographic rule can be used without additional development of the cryptographic rule selection interface, so that the maintenance interface is changed. Can be minimized and development can be facilitated. In this embodiment, the effect of the SIP message encryption function using the set encryption rule / encryption range information is the same as that of the first to fourth and sixth embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
32 to 34 are sequence charts showing the operation of the client-server distributed system according to the tenth embodiment of the present invention. Since the client-server distributed system according to the tenth embodiment of the present invention has the same configuration as the client-server distributed system according to the fourth embodiment of the present invention shown in FIG. 13, the configuration thereof will be described. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the tenth embodiment of the present invention will be described with reference to FIGS. 13 and 32 to 34. The processing of the server device 1 and the processing of the client device 3-1 shown in FIGS. 32 to 34 are realized by executing the programs by the CPUs of the server device 1 and the client device 3-1.
When the encryption presence / absence, encryption rule, and encryption range of the SIP message when sending / receiving the SIP message to / from the client device 3-1 are input in advance from the local maintenance console 2 connected to the server device 1 (j11 in Fig. 32), the encryption information The input interface unit 12 receives a setting request including the presence / absence of encryption / encryption rule / encryption range (j12 in FIG. 32), and when the normality of the setting request can be confirmed, the presence / absence of encryption / encryption rule / encryption range is determined. It is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 stores the presence / absence of encryption, the encryption rule, and the encryption range (j21 in FIG. 32).
The encryption information setting unit 11 of the server device 1 instructs the SIP message creation unit 14 to create a SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range (j22 in FIG. 32). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (j23 in FIG. 32).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the presence / absence of encryption, the encryption rule, and the normality of the encryption range, the SIP message analysis unit 35 transmits the presence / absence of encryption, the encryption rule, and the encryption range to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption presence / absence / encryption rule / encryption range, sets the encryption presence / absence / encryption rule / encryption range in the SIP message encryption / decryption unit 36 (j41 in FIG. 32), and after the setting is completed, Instruct the SIP message creation unit 34 to create a SIP response message that notifies the presence / absence of encryption, encryption rules, and completion of encryption range setting (j42 in Fig. 32). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (j43 in FIG. 32).
When the SIP interface unit 13 of the server device 1 receives the SIP response message notifying the presence / absence of encryption, the encryption rule, and the completion of the encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of the completion of setting the encryption presence / absence / encryption rule / encryption range on the client device 3-1 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of setting the encryption presence / absence / encryption rule / encryption range, and instructs the SIP message encryption / decryption unit 16 to set the encryption presence / absence / encryption rule / encryption range (j24 in FIG. 32). After the setting is completed, the encryption information input interface unit 12 sends the setting completion to the local maintenance console 2 (j25 in Fig. 32). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (j13 in Fig. 32).
When a request to send a SIP request message to client device 3-1 occurs on server device 1 after the encryption presence / absence / encryption rule / encryption range is set in the SIP message encryption / decryption unit 16 (j27 in Fig. 32), SIP The message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16 (j28 in FIG. 32). The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP request message with the encryption rule when there is encryption according to the current encryption presence / absence, encryption rule, and encryption range setting (j29 in FIG. 32). 32 j30). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (j31 in FIG. 33).
When the SIP interface unit 33 receives an encrypted SIP request message from the server device 1 after the encryption presence / absence / encryption rule / encryption range is set in the SIP message encryption / decryption unit 36, the received SIP request message is SIP. Transfer to the message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption / presence / encryption rule / encryption range setting (j44 in FIG. 33), the SIP message encryption / decryption unit decrypts the encryption range of the SIP request message according to the encryption rule (j44 in FIG. 33). J45 in Figure 33).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (j46 in FIG. 33). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (j47 in FIG. 33). The SIP message creation unit 34 creates a SIP response message, and transmits the created SIP response message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP response message with the encryption rule when there is encryption according to the current encryption presence / absence / encryption rule / encryption range setting (j48 in FIG. 33). 33 j49). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (j50 in FIG. 33).
The SIP interface unit 13 of the server device 1 that received the encrypted SIP response message transmits the received SIP response message to the SIP message encryption / decryption unit 16, and the SIP message encryption / decryption unit 16 uses the currently set encryption. If there is encryption based on the presence / absence / encryption rule / encryption range setting (j32 in FIG. 33), the encryption range of the SIP response message is decrypted according to the encryption rule (j33 in FIG. 33). The decrypted SIP response request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (j34 in FIG. 33).
Conversely, when a request to send a SIP request message to server device 1 occurs on client device 3-1 (j51 in Fig. 33), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. It is transmitted to the message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption presence / absence / encryption rule / encryption range setting (j52 in FIG. 33, j53 in FIG. 34), the encryption range of the SIP request message is set by the encryption rule. Encrypt (j54 in Figure 34). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1 via the SIP interface unit 33 (j55 in FIG. 34).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1, the SIP interface unit 13 transfers the received SIP message to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption / presence / encryption rule / encryption range setting (j35 in FIG. 34), the SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP request message according to the encryption rule (Fig. 34). 34 j36).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (j37 in FIG. 34). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (j38 in FIG. 34). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. SIP message encryption and decryption unit 16 current crypto presence-encoding rule, encryption range setting case with the encryption according to a constant (J39 in Figure 34), encrypted with the encryption rule the encryption range of the SIP response message ( J3a) in Figure 34. The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (j3b in FIG. 34).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption / presence / encryption rule / encryption range setting (j56 in FIG. 34), the SIP message encryption / decryption unit decrypts the encryption range of the SIP response message according to the encryption rule (Fig. 34). 34 j57). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (j58 in FIG. 34).
As described above, in this embodiment, since the maintainer can arbitrarily set whether or not to encrypt the SIP message via the server device 1, the encryption security function on the network is realized when the encryption is set. In addition to being able to do this, it is possible to make different settings depending on the network configuration, and it is easy to make settings without encryption when collecting SIP message logs for maintenance work. Can be realized.
Further, in this embodiment, by having a function of selecting the presence or absence of encryption, compatibility with a client device having no encryption function can be ensured. Further, in this embodiment, the local maintenance console 2 is used in a system that supports both a method of encrypting the entire SIP message and a method of encrypting an arbitrary part of the SIP message in the encryption range of the SIP message. By making it possible to arbitrarily select the range of encryption, it satisfies both cryptographic security and network functionality in a system in which network devices such as SIP-NAT exist, and is optimal for the current network configuration. You can select and realize the security level.
Furthermore, in this embodiment, the encryption security function on the network can be realized by encrypting the SIP message, and it is possible to set different encryption rules and encryption ranges for each network configuration. Furthermore, cryptographic security can be strengthened.
On the other hand, in this embodiment, by setting the encryption information in the client device 3-1 from the server device 1, it is possible to realize system uniformity and ease of maintenance by the maintainer. Further, in this embodiment, when adding a cryptographic rule that can be operated by the system in the future, the new cryptographic rule can be used without additional development of the cryptographic rule selection interface, so that the maintenance interface is changed. Can be minimized and development can be facilitated.
In this embodiment, the effect of the SIP message encryption function using the set encryption presence / absence / encryption rule / encryption range information is the same as that of the first to ninth embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
FIG. 35 is a block diagram showing a configuration of a client-server distributed system according to the eleventh embodiment of the present invention. In FIG. 35, in the client-server type distributed system according to the eleventh embodiment of the present invention, except that the server device 1b and the client devices 3a-1 to 3a-3 are provided with the encryption key creation units 18 and 38 (client device). The encryption key creation unit 38 of 3a-2 and 3a-3 is not shown), and has the same configuration as the client-server type distributed system according to the fourth embodiment of the present invention shown in FIG. 13, and has the same components. Have the same code. Further, the operation of the same component is the same as that of the fourth embodiment of the present invention.
In this embodiment, by realizing the above configuration, the SIP message is encrypted during communication between the server device 1b and the client devices 3a-1 to 3a-3, and the SIP message control on the IP network is performed. Security can be strengthened.
36 to 39 are sequence charts showing the operation of the client-server distributed system according to the eleventh embodiment of the present invention. The operation of the client-server distributed system according to the eleventh embodiment of the present invention will be described with reference to FIGS. 35 to 39. The processing of the server device 1b and the processing of the client device 3a-1 shown in FIGS. 36 to 39 are realized by executing programs by the CPUs of the server device 1b and the client device 3a-1.
When the initial server access request from the client device 3a-1 to the server device 1b occurs (k41 in Fig. 36), the SIP message creation unit 34 creates a SIP request message, and the created SIP request message is sent via the SIP interface unit 33. Is sent to the SIP interface section 13 of the server device 1b (k42 in Fig. 36).
Upon receiving the SIP request message, the SIP interface unit 13 of the server device 1b recognizes the initial access from the client device 3a-1 and transmits it to the encryption information setting unit 11. The encryption information setting unit 11 creates and stores a random parameter for generating an encryption key used for encrypting a SIP message between the server device 1b and the client device 3a-1 (k21 in FIG. 36), and randomly generates the encryption key. Instruct the SIP message creation unit 14 to create a SIP response message with parameters added. The SIP message creation unit 14 creates a SIP response message and sends the created SIP response message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (k22 in FIG. 36).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP response message to which the random parameter for encryption key generation is added, the received random parameter for encryption key generation is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the random parameter for generating the encryption key (k43 in FIG. 36).
When there is no encryption between the server device 1b and the client device 3a-1 (k23 in Fig. 36), the SIP message sent / received from the local maintenance console 2 connected to the server device 1b to the client device 3a-1. When the encryption presence / absence / encryption rule / encryption range of the message is input (k11 in FIG. 36), the encryption information input interface unit 12 receives a setting request including the encryption presence / absence / encryption rule / encryption range (k12 in FIG. 36). ), When the normality of the setting request can be confirmed, the presence / absence of encryption, the encryption rule, and the encryption range are transmitted to the encryption information setting unit 11. The encryption information setting unit 11 stores the presence / absence of encryption, the encryption rule, and the encryption range (k24 in FIG. 36).
The encryption information setting unit 11 of the server device 1b instructs the SIP message creation unit 14 to create a SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range (k25 in FIG. 36). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (k26 in FIG. 36).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the presence / absence of encryption, the encryption rule, and the normality of the encryption range, the SIP message analysis unit 35 transmits the presence / absence of encryption, the encryption rule, and the encryption range to the encryption information setting unit 31. The encryption information setting unit 31 stores the presence / absence of encryption, the encryption rule, and the encryption range, and the encryption key creation unit 38 generates an encryption key from the stored random parameters for encryption key generation (k44 in FIG. 36), and SIP. The presence / absence of the encryption, the encryption rule, the encryption range, and the encryption key are set in the message encryption / decryption unit 36 (k45 in FIG. 36).
After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of encryption presence / absence / encryption rule / encryption range setting (k46 in FIG. 36). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (k47 in FIG. 36).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the presence / absence of encryption, the encryption rule, and the completion of the encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of completion of setting of encryption presence / absence, encryption rule, and encryption range on the SIP protocol compatible client device 3a-1 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of setting of the presence / absence of encryption, the encryption rule, and the encryption range, and the encryption key creation unit 18 generates an encryption key from the stored random parameters for encryption key generation (k27 in FIG. 37). ), Instruct the SIP message encryption / decryption unit 16 to set the encryption presence / absence, encryption rule, encryption range, and encryption key (k28 in FIG. 37).
After the setting is completed, the encryption information setting unit 11 transmits the setting completion to the local maintenance console 2 from the encryption information input interface unit 12 (k29 in FIG. 37). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (k13 in Fig. 37).
When a request to send a SIP request message to the client device 3a-1 occurs on the server device 1b after the encryption presence / absence / encryption rule / encryption range / encryption key is set in the SIP message encryption / decryption unit 16 (k31 in Fig. 37). ), The SIP message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16 (k32 in FIG. 37).
The SIP message encryption / decryption unit 16 sets the current encryption / presence / encryption rules / encryption range / encryption key.<u style="single">In response to the</u>When there is encryption (k33 in FIG. 37), the encryption range of the SIP request message is encrypted with the encryption rule and the encryption key (k34 in FIG. 37). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (k35 in FIG. 37).
When the SIP interface unit 33 receives an encrypted SIP request message from the server device 1b after the encryption presence / absence / encryption rule / encryption range is set in the SIP message encryption / decryption unit 36, the received SIP<u style="single">request</u>Send the message to the SIP message encryption / decryption unit 36<u style="single">Forward.</u>The SIP message encryption / decryption unit 36 sets the current encryption / presence / encryption rules / encryption range.<u style="single">In response to the</u>When there is encryption (k48 in FIG. 37), the encryption range of the SIP request message is decrypted by the encryption rule (k49 in FIG. 37).
Decryption<u style="single">Be done</u>The SIP request message is analyzed by the SIP message analysis unit 35, and is analyzed.<u style="single">That</u>Call control is executed by the call control unit 37 depending on the content of the message (k50 in FIG. 37). From the call control unit 37 according to the call control result<u style="single">Is</u>The SIP message creation unit 34 is instructed to create a SIP response message.<u style="single">Ru</u>(K51 in Fig. 38)<u style="single">.. SIP message composer 34 composes a SIP response message and</u>Created SIP response message<u style="single">To</u>SIP message encryption / decryption unit 36<u style="single">introduce. SIP message encryption / decryption unit 36</u>Current encryption presence / absence / encryption rule / encryption range setting<u style="single">In response to the</u>With encryption (k52 in Figure 38), the encryption range of the SIP response message is encrypted with the encryption rule.<u style="single">To do</u>(K53 in Figure 38)<u style="single">.. The encrypted SIP response message</u>It is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (k54 in FIG. 38).
When the SIP interface unit 13 of the server device 1b receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP response message according to the currently set encryption presence / absence / encryption rule / encryption range setting (k36 in FIG. 38). (K37 in Figure 38). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (k38 in FIG. 38).
Conversely, when a request to send a SIP request message to server device 1b occurs on client device 3a-1 (k55 in Fig. 38), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. It is transmitted to the message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP request message with the encryption rule when there is encryption according to the current encryption presence / absence / encryption rule / encryption range setting (k56, k57 in FIG. 38). (K58 in Figure 38). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (k59 in FIG. 38).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3a-1, the received SIP request message is transferred to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption / presence / encryption rule / encryption range setting (k39 in FIG. 39), the SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP request message according to the encryption rule (Fig. 39). 39 k3a).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (k3b in FIG. 39). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (k3c in FIG. 39). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the current encryption / presence / encryption rule / encryption range setting (k3d in FIG. 39), the encryption range of the SIP response message is encrypted by the encryption rule (Fig. 39). 39 k3e). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (k3f in FIG. 39).
When the SIP interface unit 33 of the client device 3a-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the current encryption / presence / encryption rule / encryption range setting (k5a in FIG. 39), the SIP message encryption / decryption unit decrypts the encryption range of the SIP response message according to the encryption rule (Fig. 39). 39 k5b). The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (k5c in FIG. 39).
As described above, in this embodiment, in the system in which the SIP message is transmitted and received without encryption, when the encryption function is started, the encryption information other than the encryption key is transmitted from the server device to the client device without being encrypted. However, the encryption key has a function that enables both the server device and the client device to generate a synchronized encryption key, and the server does not notify the encryption key via the IP network. It is possible to set common cryptographic information between the device and the client device, and it is possible to strengthen the cryptographic security function after the cryptographic information is set.
Further, in the present embodiment, the effect of the SIP message encryption function using the set encryption information is the same as that of the first to tenth embodiments of the present invention described above. Further, in this embodiment, since the encryption key is generated by using the random parameter determined at the first access from the client device to the server device, the regularity of the generated encryption key can be eliminated, and the encryption security function can be obtained. Can be strengthened.
Furthermore, in this embodiment, the effect of the SIP message encryption function using the set encryption information is the same as that of the first to tenth embodiments of the present invention described above. Although the operation of the client devices 3a-2 and 3a-3 is not described, the same effect as when the client device 3a-1 is used can be obtained.
FIG. 40 is a block diagram showing a configuration of a client-server distributed system according to a twelfth embodiment of the present invention. In FIG. 40, the client-server distributed system according to the twelfth embodiment of the present invention is a client according to the fourth embodiment of the present invention shown in FIG. 13, except that the server device 1b is provided with the encryption key creation unit 18. -It has the same configuration as the server-type distributed system, and the same components are given the same code. Further, the operation of the same component is the same as that of the fourth embodiment of the present invention.
The encryption information has already been set in the server device 1b and the client devices 3-1 to 3-3, and the encryption / decryption processing is performed when the SIP message is transmitted / received in the state with the encryption. Hereinafter, the set encryption information is described as the old encryption information.
In this embodiment, by realizing the above configuration, the SIP message is encrypted during communication between the server device 1b and the client devices 3-1 to 3-3, and the SIP message control on the IP network is performed. Security can be strengthened.
41 to 44 are sequence charts showing the operation of the client-server distributed system according to the twelfth embodiment of the present invention. The operation of the client-server distributed system according to the twelfth embodiment of the present invention will be described with reference to FIGS. 40 to 44. The processing of the server device 1b and the processing of the client device 3-1 shown in FIGS. 41 to 44 are realized by executing the programs by the CPUs of the server device 1b and the client device 3-1.
When the encryption information between the server device 1b and the client device 3-1 is set to be encrypted (l20 in Fig. 41), the local maintenance console 2 connected to the server device 1b to the client device 3-1 When the encryption presence / absence / encryption rule / encryption range of the SIP message is input when sending / receiving the SIP message with (l11 in Fig. 41), the encryption information input interface unit 12 requests a setting including the encryption presence / absence, the encryption rule, and the encryption range. (L12 in FIG. 41), and when the normality of the setting request can be confirmed, the presence / absence of encryption, the encryption rule, and the encryption range are transmitted to the encryption information setting unit 11.
The encryption information setting unit 11 instructs the encryption key creation unit 18 to generate an encryption key to be used for sending and receiving SIP messages with the client device 3-1 (l21 in FIG. 41). When the encryption key creation unit 18 creates an encryption key, the encryption information setting unit 11 stores the encryption key created by the encryption key creation unit 18 and the encryption presence / absence / encryption rule / encryption range input from the local console 2 (Fig. 41). L22).
The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including a new encryption presence / absence, an encryption rule, an encryption range, and an encryption key (hereinafter referred to as new encryption information) (l23 in FIG. 41). .. The SIP message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message with the old encryption information (l24 in FIG. 41). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (l25 in FIG. 41).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (l41 in Fig. 41). The decrypted SIP request message is transmitted to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31.
The encryption information setting unit 31 stores the new encryption information, sets the new encryption information in the SIP message encryption / decryption unit 36 (l42 in FIG. 41), and after the setting is completed, sets the new encryption information in the SIP message creation unit 34. Instructs to create a SIP response message to notify the completion (l43 in Figure 41). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (l44 in FIG. 41). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (l45 in FIG. 41).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (l26 in FIG. 42). The SIP message encryption / decryption unit 16 decrypts the SIP response message, and transmits the decrypted SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits the new encryption information setting completion notification on the client device 3-1 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of the new encryption information setting, instructs the SIP message encryption / decryption unit 16 to set the new encryption information (l27 in FIG. 42), and after the setting is completed, the encryption information input interface unit 12 Sends the setting completion to the local maintenance console 2 (l28 in Figure 42). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (l13 in Fig. 42).
When a request to send a SIP request message to client device 3-1 occurs on server device 1b after the new encryption information is set in the SIP message encryption / decryption section 16 (l30 in Fig. 42), the SIP message creation section 14 Create a SIP request message and transmit the created SIP request message to the SIP message encryption / decryption unit 16 (l31 in Fig. 42). When the SIP message encryption / decryption unit 16 has encryption according to the new encryption information (encryption / absence / encryption rule / encryption range / encryption key) setting (l32 in FIG. 42), the encryption range of the SIP request message is set to the encryption rule. And the encryption key are used for encryption (l33 in Fig. 42). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (l34 in FIG. 42).
After the new encryption information is set in the SIP message encryption / decryption unit 36, when the SIP interface unit 33 receives the encrypted SIP request message from the server device 1b, the SIP request message received is sent to the SIP message encryption / decryption unit. Transfer to 36. When the SIP message encryption / decryption unit 36 has encryption according to the new encryption information (encryption / absence / encryption rule / encryption range / encryption key) setting (l46 in FIG. 42), the encryption range of the SIP request message is encrypted. Decrypt with the rule and the encryption key (l47 in FIG. 42).
The decrypted SIP request message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (l48 in FIG. 42). According to the call control result, the call control unit 37 instructs the SIP message creation unit 34 to create a SIP response message (l49 in FIG. 42). The IP message creation unit 34 creates a SIP response message, and transmits the created SIP response message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 encrypts the encryption range of the SIP response message with the encryption rule and the encryption key when there is encryption according to the new encryption information setting (l50 in FIG. 43) (FIG. 43). l51). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (l52 in FIG. 43).
When the SIP interface unit 13 of the server device 1b receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the new encryption information setting (l35 in FIG. 43), the SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP response message with the encryption rule and the encryption key (FIG. 43). l36). The decrypted SIP response message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (l37 in FIG. 43).
Conversely, when a request to send a SIP request message to server device 1b occurs on client device 3-1 (l53 in Fig. 43), the SIP message creation unit 34 creates a SIP request message and SIPs the created SIP request message. It is transmitted to the message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the new encryption information setting (l54, l55 in FIG. 43), the SIP request message encrypts the encryption range with the encryption rule and the encryption key (Fig. 43). 43 l56). The encrypted SIP request message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (l57 in FIG. 43).
When the SIP interface unit 13 receives the encrypted SIP request message from the client device 3-1, the SIP interface unit 13 transfers the received SIP request message to the SIP message encryption / decryption unit 16. When the SIP message encryption / decryption unit 16 has encryption according to the new encryption information setting (l38 in FIG. 44), the SIP message encryption / decryption unit 16 decrypts the encryption range of the SIP request message with the encryption rule and the encryption key (FIG. 44). l39).
The decrypted SIP request message is analyzed by the SIP message analysis unit 15, and call control is executed by the call control unit 17 according to the content of the message (l3a in FIG. 44). According to the call control result, the call control unit 17 instructs the SIP message creation unit 14 to create a SIP response message (l3b in FIG. 44). The SIP message creation unit 14 creates a SIP response message and transmits the created SIP response message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the encryption range of the SIP response message with the encryption rule and the encryption key when there is encryption according to the new encryption information setting (l3c in FIG. 44) (FIG. 44). l3d). The encrypted SIP response message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (l3e in FIG. 44).
When the SIP interface unit 33 of the client device 3-1 receives the encrypted SIP response message, the received SIP response message is transmitted to the SIP message encryption / decryption unit 36. When the SIP message encryption / decryption unit 36 has encryption according to the new encryption information setting (l58 in FIG. 44), the SIP message encryption / decryption unit 36 decrypts the encryption range of the SIP response message with the encryption rule and the encryption key (FIG. 44). l59). The decrypted SIP response message is analyzed by the SIP message analysis unit 35, and call control is executed by the call control unit 37 according to the content of the message (l5a in FIG. 44).
As described above, in this embodiment, in the system in which the SIP message is transmitted / received in the state where the encryption is set, the encryption information is already set between the client device and the server device when the encryption information is changed. Since it is transmitted in a state encrypted by the encryption information of, the encryption security can be strengthened.
Further, in this embodiment, the maintainer can arbitrarily set the encryption information other than the encryption key among the newly set encryption information from the local maintenance console 2, so that the system construction is unified. In addition, if the maintainer wants to log the SIP message communication status, it can be changed without encryption, so the ease of maintenance can be ensured. Further, in this embodiment, since the same encryption key can be changed at any time by the maintainer without using the same encryption key for a long time, security against hacking of encrypted information can be strengthened.
Furthermore, in this embodiment, the server device 1 randomly generates the encryption key and distributes it to the client device 3-1. Therefore, the encryption key set by a third party including the maintainer is unknown. It is possible to prevent human error and leakage of the encryption key, and it is possible to further strengthen the encryption security.
In this embodiment, the effect of the SIP message encryption function after setting the new encryption information is the same as that of the first to tenth embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
FIG. 45 is a flowchart showing the operation of the server device and the client device according to the thirteenth embodiment of the present invention. The client-server distributed system according to the thirteenth embodiment of the present invention has the same configuration as the client-server distributed system according to the twelfth embodiment of the present invention shown in FIG. 40. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the thirteenth embodiment of the present invention will be described with reference to FIGS. 40 and 45.
The processing of the server device 1b or the client device 3-1 shown in FIG. 45 is realized by executing the program by each CPU of the server device 1b or the client device 3-1. The process shown in FIG. 45 shows the operation when the encrypted SIP message reception in the encrypted information setting state is used as a trigger, and both the server device 1b and the client device 3-1 perform the same operation. In the following description, the operation of the server device 1b will be described.
In a system that has been encrypted with the old encryption information (m1 in Fig. 45), when a SIP message encrypted with the old encryption information is received from the opposite device, the server device 1b decrypts the received SIP message according to the old encryption information. And control according to the content of the message (m2 in Fig. 45). When sending a SIP message, the server device 1b creates a SIP message, encrypts it according to the old encryption information, and sends it to the opposite device (m3 in Fig. 45).
When the setting of the new encryption information is completed between the own device and the opposite device (m4 in Fig. 45), the server device 1b is old to set the time during which only the SIP message encrypted by the old encryption information can be received. Set the encryption information valid timer and start it (m5 in Fig. 45).
When a SIP message encrypted with the old encryption information is received (m6 in Fig. 45), the server device 1b checks the timeout of the old encryption information valid timer (m7 in Fig. 45), and retains it if it has not timed out. The SIP message is decrypted and controlled according to the old encrypted information (m8 in Fig. 45). If the old encryption information valid timer has timed out, the server device 1b discards the received SIP message without decrypting it (m9 in Fig. 45).
When sending a SIP message, the server device 1b creates a SIP message (m10 in Fig. 45), encrypts it according to the new encryption information, and sends it to the opposite device (m11 in Fig. 45). When a SIP message encrypted with the new encryption information is received from the opposite device (m12 in Fig. 45), the server device 1b decrypts the received SIP message according to the new encryption information and controls according to the content of the message (Fig. 45). 45 m13). When transmitting a SIP message, the server device 1b creates a SIP message, encrypts it according to the new encryption information, and sends it to the opposite device.
As described above, in this embodiment, after changing to the new encryption information, it is possible to receive and decrypt the SIP message encrypted by the old encryption information for a certain period of time, so that the information is transmitted and received during the change of the encryption information. The encryption information can be changed without compromising the validity of the SIP message, and the encryption information can be changed at any time. Further, in the present embodiment, the effect of the SIP message encryption function using the set encryption information is the same as that of the first to eleventh embodiments of the present invention.
46 and 47 are sequence charts showing the operation of the client-server distributed system according to the 14th embodiment of the present invention. The client-server distributed system according to the 14th embodiment of the present invention has the same configuration as the client-server distributed system according to the 12th embodiment of the present invention shown in FIG. 40. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the 14th embodiment of the present invention will be described with reference to FIGS. 40, 46, and 47.
The processing of the server device 1b and the client device 3-1 shown in FIGS. 46 and 47 is realized by executing the program by each CPU of the server device 1b and the client device 3-1. In addition, encryption information has already been set in the server device 1b and the client device 3-1 respectively, and encryption / decryption processing is performed when sending / receiving a SIP message with encryption. Hereinafter, the set encryption information is described as the old encryption information.
When the encryption information set between the server device 1b and the client device 3-1 is set to have encryption (n20 in Fig. 46), the local maintenance console 2 connected to the server device 1b connects to the client device 3-1. When the encryption presence / absence / encryption rule / encryption range of the SIP message at the time of sending / receiving the SIP message is input (n11 in FIG. 46), the encryption information input interface unit 12 requests a setting including the encryption presence / absence, the encryption rule, and the encryption range. (N12 in FIG. 46), and when the normality of the setting request can be confirmed, the presence / absence of encryption, the encryption rule, and the encryption range are transmitted to the encryption information setting unit 11.
The encryption information setting unit 11 instructs the encryption key creation unit 18 to generate an encryption key to be used for sending and receiving SIP messages with the client device 3-1 (n21 in FIG. 46), and the encryption created by the encryption key creation unit 18 The key and the encryption presence / absence / encryption rule / encryption range input from the local console 2 are stored (n22 in Fig. 46). The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including a new encryption presence / absence, an encryption rule, an encryption range, and an encryption key (hereinafter referred to as new encryption information) (n23 in FIG. 46). .. In this case, it is assumed that the encryption key created by the encryption key creation unit 18 is encrypted according to the old encryption information. The SIP message creation unit 14 creates a SIP request message including new encryption information, and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message according to the old encryption information (n24 in FIG. 46). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (n25 in FIG. 46).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (n41 in FIG. 46). The decrypted SIP request message is transmitted to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31. The encryption information setting unit 31 stores the new encryption information, and sets the new encryption information in the SIP message encryption / decryption unit 36 (n42 in FIG. 46).
After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of the new encryption information setting (n43 in FIG. 46). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (n44 in FIG. 46). The encrypted SIP response message is sent to the SIP interface section 13 of the server device 1b via the SIP interface section 33 (n45 in FIG. 46).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (n26 in FIG. 47). The SIP message encryption / decryption unit 16 decrypts the SIP response message. The decrypted SIP response message is transmitted to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a new encryption information setting completion notification on the client device 3-1 side to the encryption information setting unit 11, and the encryption information setting unit 11 recognizes the completion of the new encryption information setting and encrypts / decrypts the SIP message. Instruct unit 16 to set the new encryption information (n27 in FIG. 47).
After the setting is completed, the encryption information setting unit 11 transmits the setting completion to the local maintenance console 2 from the encryption information input interface unit 12 (n28 in FIG. 47). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (n29 in Fig. 47).
In this embodiment, the operations of encryption / decryption after the new encryption information setting in the server device 1b and the client device 3-1 are the same as those in the twelfth embodiment of the present invention described above. And the description will be omitted.
As described above, in this embodiment, when the encryption key to be used is distributed from the server device 1b to the client device 3-1 in the system in which the SIP message is transmitted / received in the state where the encryption is set, the encryption key is always distributed. Since the communication on the IP network is performed in the encrypted state of the encryption key, it is possible to prevent the leakage of the encryption key and strengthen the encryption security function when encrypting the SIP message.
Further, in the present embodiment, the effect of the SIP message encryption function using the set encryption information is the same as that of the twelfth embodiment of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
48 and 49 are sequence charts showing the operation of the client-server distributed system according to the fifteenth embodiment of the present invention. The client-server distributed system according to the fifteenth embodiment of the present invention has the same configuration as the client-server distributed system according to the twelfth embodiment of the present invention shown in FIG. 40. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the fifteenth embodiment of the present invention will be described with reference to FIGS. 40, 48, and 49.
The processing of the server device 1b and the client device 3-1 shown in FIGS. 48 and 49 is realized by executing the program by each CPU of the server device 1b and the client device 3-1. Further, in the present embodiment, encryption information has already been set in each of the server device 1b and the client device 3-1 and the encryption / decryption processing is performed when the SIP message is transmitted / received with the encryption. Hereinafter, the set encryption information is described as the old encryption information.
When the encryption information set between the server device 1b and the client device 3-1 is set to have encryption (o20 in Fig. 48), the local maintenance console 2 connected to the server device 1b to the client device 3-1 When the encryption presence / absence / encryption rule / encryption range of the SIP message is input when sending / receiving the SIP message with (o11 in Fig. 48), the encryption information input interface unit 12 requests a setting including the encryption presence / absence, the encryption rule, and the encryption range. (O12 in FIG. 48), and when the normality of the setting request can be confirmed, the presence / absence of encryption, the encryption rule, and the encryption range are transmitted to the encryption information setting unit 11.
The encryption information setting unit 11 instructs the encryption key creation unit 18 to generate an encryption key to be used for sending and receiving SIP messages with the client device 3-1 (o21 in FIG. 48), and the encryption created by the encryption key creation unit 18 The key and the encryption presence / absence / encryption rule / encryption range input from the local console 2 are memorized (o22 in Fig. 48).
The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including a new encryption presence / absence, an encryption rule, an encryption range, and an encryption key (hereinafter referred to as new encryption information) (o23 in FIG. 48). .. The SIP message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message according to the old encryption information (o24 in Fig. 48). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3-1 via the SIP interface unit 13 (o25 in FIG. 48).
When the SIP interface unit 33 of the client device 3-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (o41 in Fig. 48). The decrypted SIP request message is transmitted to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31. The encryption information setting unit 31 stores the new encryption information, and sets the new encryption information in the SIP message encryption / decryption unit 36 (o42 in FIG. 48).
After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of the new encryption information setting (o43 in FIG. 48). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (o44 in FIG. 48). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (o45 in FIG. 48).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (o26 in FIG. 49). The SIP message encryption / decryption unit 36 decrypts the SIP response message. The decrypted SIP response message is transmitted to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a new encryption information setting completion notification on the client device 3-1 side to the encryption information setting unit 11, and the encryption information setting unit 11 recognizes the completion of the new encryption information setting and encrypts / decrypts the SIP message. Instruct unit 16 to set the new encryption information (o27 in FIG. 49).
After the setting is completed, the encryption information setting unit 11 sends the setting completion to the local maintenance console 2 from the encryption information input interface unit 12 (o28 in FIG. 49). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (o13 in Fig. 49).
In this embodiment, the operations of encryption / decryption after the new encryption information setting in the server device 1b and the client device 3-1 are the same as those in the twelfth embodiment of the present invention described above. And the description will be omitted.
As described above, in this embodiment, when the encrypted information to be used is distributed from the server device 1b to the client device 3-1 in the system in which the SIP message is transmitted / received in the state where the encryption is set, the encryption is always performed. If communication is performed on the IP network with the key encrypted, it is possible to prevent the leakage of the encryption key and strengthen the encryption security function when encrypting the SIP message. By encrypting and distributing encryption information other than the encryption information (encryption / non-encryption, encryption rule, encryption range), it becomes difficult to guess the encryption key, and the encryption security can be further strengthened.
Further, in this embodiment, the effect of the SIP message encryption function using the set encryption information is the same as that of the eleventh and twelfth embodiments of the present invention described above. Although the operation of the client devices 3-2 and 3-3 is not described, the same effect as when the client device 3-1 is used can be obtained.
50 to 54 are sequence charts showing the operation of the client-server distributed system according to the 16th embodiment of the present invention. The client-server distributed system according to the 16th embodiment of the present invention has the same configuration as the client-server distributed system according to the 11th embodiment of the present invention shown in FIG. 35. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the 16th embodiment of the present invention will be described with reference to FIGS. 35 and 50 to 54. The processing of the server device 1b and the client device 3a-1 shown in FIGS. 50 to 54 is realized by executing a program by each CPU of the server device 1b and the client device 3a-1.
When the initial server access request from the client device 3a-1 to the server device 1b occurs (p41 in Fig. 50), the SIP message creation unit 34 creates a SIP request message, and the created SIP request message is sent via the SIP interface unit 33. Is sent to the SIP interface section 13 of the server device 1b (p42 in Fig. 50).
When the SIP interface unit 13 of the server device 1b receives the SIP request message, it recognizes the first access from the client device 3a-1 and transmits it to the encryption information setting unit 11. The encryption information setting unit 11 creates and stores a random parameter for generating an encryption key used for encrypting a SIP message between the server device 1b and the client device 3a-1 (p21 in FIG. 50), and the random for generating the encryption key. Instruct the SIP message creation unit 14 to create a SIP response message with parameters added. The SIP message creation unit 14 creates a SIP response message and sends the created SIP response message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (p22 in FIG. 50).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP response message to which the random parameter for encryption key generation is added, the received random parameter for encryption key generation is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the random parameter for generating the encryption key (p43 in FIG. 50). As a result, the encryption setting is completed (without or with) between the server device 1b and the client device 3a-1 (p23 in Fig. 50).
When the encryption presence / absence, encryption rule, and encryption range of the SIP message when sending / receiving the SIP message to / from the client device 3a-1 are input from the local maintenance console 2 connected to the server device 1b (p11 in Fig. 50), the encryption information input interface Part 12 receives a setting request including the encryption presence / absence / encryption rule / encryption range (p12 in FIG. 50), and when the normality of the setting request can be confirmed, the encryption presence / absence / encryption rule / encryption range is encrypted. It is transmitted to the setting unit 11. The encryption information setting unit 11 stores the presence / absence of encryption, the encryption rule, and the encryption range (p24 in FIG. 50).
The encryption information setting unit 11 of the server device 1b instructs the SIP message creation unit 14 to create a SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range (p25 in FIG. 50). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (p26 in FIG. 50).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the presence / absence of encryption, the encryption rule, and the normality of the encryption range, the SIP message analysis unit 35 transmits the presence / absence of encryption, the encryption rule, and the encryption range to the encryption information setting unit 31. The encryption information setting unit 31 stores the presence / absence of encryption, the encryption rule, and the encryption range, and the encryption key creation unit 38 generates an encryption key from the stored random parameters for encryption key generation (p44 in FIG. 50), and SIP. The presence / absence of the encryption, the encryption rule, the encryption range, and the encryption key are set in the message encryption / decryption unit 36 (p45 in FIG. 50).
After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of encryption presence / absence / encryption rule / encryption range setting (p46 in FIG. 50). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (p47 in FIG. 50).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the presence / absence of encryption, the encryption rule, and the completion of the encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of completion of setting of encryption presence / absence, encryption rule, and encryption range on the SIP protocol compatible client device 3 side to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the completion of setting of the presence / absence of encryption, the encryption rule, and the encryption range, and the encryption key creation unit 18 generates an encryption key from the stored random parameters for generation of the encryption key (p27 in FIG. 51). ), Instruct the SIP message encryption / decryption unit 16 to set the encryption presence / absence, encryption rule, encryption range, and encryption key (p28 in FIG. 51). As a result, the server device 1b and the client device 3a-1 are in the set state with encryption (old encryption information) with the set encryption information (p29 in FIG. 51).
After the encryption presence / absence / encryption rule / encryption range / encryption key is set in the SIP message encryption / decryption unit 16, the following flow will be described using the set encryption information as the old encryption information.
The encryption information setting unit 11 instructs the encryption key creation unit 18 to generate an encryption key to be used for sending and receiving SIP messages with the SIP protocol compatible client device 3 (p30 in FIG. 51), and the encryption key creation unit 18 creates the encryption key. The encryption key and the encryption presence / absence / encryption rule / encryption range of the old encryption information are stored (p31 in Fig. 51).
The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including a new encryption presence / absence, an encryption rule, an encryption range, and an encryption key (hereinafter referred to as new encryption information) (p32 in FIG. 51). .. The SIP message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message according to the old encryption information (p33 in FIG. 51). The encrypted SIP request message is sent to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (p34 in FIG. 51).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (p48 in FIG. 51). The decrypted SIP request message is transmitted to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31.
The encryption information setting unit 31 stores the new encryption information, sets the new encryption information in the SIP message encryption / decryption unit 36 (p49 in FIG. 51), and after the setting is completed, sets the new encryption information in the SIP message creation unit 34. Instructs to create a SIP response message to notify the completion (p50 in Figure 51). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (p51 in FIG. 51). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (p52 in FIG. 52).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (p35 in FIG. 52). The SIP message encryption / decryption unit 16 decrypts the SIP response message, and transmits the decrypted SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a new encryption information setting completion notification on the SIP protocol compatible client device 3a-1 side to the encryption information setting unit 11.
The encryption information setting unit 11 recognizes the completion of the new encryption information setting, instructs the SIP message encryption / decryption unit 16 to set the new encryption information (p36 in FIG. 52), and after the setting is completed, the encryption information input interface unit 12 Sends the setting completion to the local maintenance console 2 (p37 in Figure 52). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (p13 in Fig. 52).
Operation of sending and receiving with encryption / decryption of SIP message after new encryption information is set in SIP message encryption / decryption unit 16 (p39 ~ p3d, p53 ~ p55 in Fig. 52, p3e ~ p3g, p56 ~ p5e in Fig. 53, The operation of p3h to p3n and p5f to p5h in FIG. 54) is the same as that of the eleventh embodiment of the present invention described above, and thus the description thereof will be omitted.
As described above, in this embodiment, when changing from the unencrypted state to the encrypted state, first, the encryption information using the encryption key created synchronously in both the client device 3a-1 and the server device 1b is set. By performing two-step encryption information setting, which is to set the encryption information that uses the encryption key automatically generated by the server device 1b, the server device 1b automatically generates and maintains the actual SIP message encryption. The encryption / decryption is performed using an encryption key that is not recognized by a third party including a person, and the encryption security function can be strengthened. Further, in the present embodiment, since the encryption key for encrypting the transmission and reception of SIP messages is always notified in the encrypted state, the security of the encryption function can be enhanced.
Further, in this embodiment, the effect of the SIP message encryption function using the set encryption information is the same as that of the eleventh to fifteenth embodiments of the present invention described above. Although the operation of the client devices 3a-2 and 3a-3 is not described, the same effect as when the client device 3a-1 is used can be obtained.
FIGS. 55 to 60 are sequence charts showing the operation of the client-server distributed system according to the 17th embodiment of the present invention. The client-server distributed system according to the 17th embodiment of the present invention has the same configuration as the client-server distributed system according to the 11th embodiment of the present invention shown in FIG. 35. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the 17th embodiment of the present invention will be described with reference to FIGS. 35 and 55 to 60. The processing of the server device 1b and the client device 3a-1 shown in FIGS. 55 to 60 is realized by executing a program by each CPU of the server device 1b and the client device 3a-1.
When the initial server access request from the client device 3a-1 to the server device 1b occurs (q41 in Fig. 55), the SIP message creation unit 34 creates a SIP request message, and the created SIP request message is sent via the SIP interface unit 33. Is sent to the SIP interface section 13 of the server device 1b (q42 in Fig. 55).
When the SIP interface unit 13 of the server device 1b receives the SIP request message, it recognizes the first access from the client device 3a-1 and transmits it to the encryption information setting unit 11. The encryption information setting unit 11 creates and stores a random parameter for generating an encryption key used for encrypting a SIP message between the server device 1b and the client device 3a-1 (q21 in FIG. 55), and the random for generating the encryption key. Instruct the SIP message creation unit 14 to create a SIP response message with parameters added. The SIP message creation unit 14 creates a SIP response message and sends the created SIP response message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (q22 in FIG. 55).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP response message to which the random parameter for encryption key generation is added, the received random parameter for encryption key generation is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the random parameter for generating the encryption key (q43 in FIG. 55). As a result, the encryption setting is completed (without or with) between the server device 1b and the client device 3a-1 (q23 in FIG. 55).
After that, the encryption information setting between the server device 1a and the client device 3a-1 is executed. Since this encryption information setting operation is the same as that of the eleventh embodiment of the present invention described above, it is assumed that the description of the encryption information setting operation is omitted and the encryption information setting is completed.
When the encryption presence / absence / encryption rule / encryption range of the SIP message when sending / receiving the SIP message to / from the client device 3a-1 is input from the local maintenance console 2 connected to the server device 1b (q11 in Fig. 55), the encryption information input interface Part 12 receives a setting request including the encryption presence / absence / encryption rule / encryption range (q12 in FIG. 55), and when the normality of the setting request can be confirmed, the encryption presence / absence / encryption rule / encryption range is encrypted. It is transmitted to the setting unit 11.
The encryption information setting unit 11 checks the presence or absence of encryption from the current encryption information (q24 in Fig. 55), and if there is no encryption, the SIP message encryption uses the encryption key created from the stored encryption key generation random parameters. -The encryption key that is automatically generated by the server device 1 is used as the old encryption information by executing the decryption sequence and using the encryption information created from the stored random parameters for encryption key generation. Execute the sequence to set the encryption information (new encryption information).
The encryption information setting unit 11 stores the encryption presence / absence, the encryption rule, and the encryption range (q25 in FIG. 55), and instructs the SIP message creation unit 14 to create a SIP request message including the encryption presence / absence, the encryption rule, and the encryption range. (Q26 in Figure 55). The SIP message creation unit 14 creates a SIP request message and sends the created SIP request message to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (q27 in FIG. 55).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message including the presence / absence of encryption, the encryption rule, and the encryption range, the SIP interface unit 33 transmits the received SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the presence / absence of encryption, the encryption rule, and the normality of the encryption range, the SIP message analysis unit 35 transmits the presence / absence of encryption, the encryption rule, and the encryption range to the encryption information setting unit 31.
The encryption information setting unit 31 stores the presence / absence of encryption, the encryption rule, and the encryption range, and the encryption key creation unit 38 generates an encryption key from the stored random parameters for encryption key generation (q44 in FIG. 55), and SIP. The presence / absence of the encryption, the encryption rule, the encryption range, and the encryption key are set in the message encryption / decryption unit 36 (q45 in FIG. 55). After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of encryption presence / absence / encryption rule / encryption range setting (q46 in FIG. 56). The SIP message creation unit 34 creates a SIP response message and sends the created SIP response message to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (q47 in FIG. 56).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the presence / absence of encryption, the encryption rule, and the completion of the encryption range setting, the SIP interface unit 13 transmits the received SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a notification of completion of setting of encryption presence / absence, encryption rule, and encryption range on the SIP protocol compatible client device 3a-1 side to the encryption information setting unit 11.
The encryption information setting unit 11 recognizes the completion of setting of the presence / absence of encryption, the encryption rule, and the encryption range, and the encryption key creation unit 18 generates an encryption key from the stored random parameters for generation of the encryption key (q28 in FIG. 56). ), Instruct the SIP message encryption / decryption unit 16 to set the encryption presence / absence, encryption rule, encryption range, and encryption key (q29 in FIG. 56). As a result, the setting is completed (old encryption information) with encryption using the above encryption information between the server device 1b and the client device 3a-1 (q30 in FIG. 56).
After the encryption presence / absence / encryption rule / encryption range / encryption key is set in the SIP message encryption / decryption unit 16, the following flow will be described using the set encryption information as the old encryption information.
When the old encryption information is encrypted between the server device 1a and the client device 3a-1 (q31 in Fig. 56), the encryption information setting unit 11 sends the encryption key creation unit 18 to the SIP protocol compatible client device. Instructs the generation of the encryption key used for sending and receiving SIP messages with 3 (q32 in Fig. 56), and stores the encryption presence / absence, encryption rule, and encryption range of the encryption key and old encryption information created by the encryption key creation unit 18 (q32 in Fig. 56). Q33 in Fig. 56).
The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including a new encryption presence / absence, an encryption rule, an encryption range, and an encryption key (hereinafter referred to as new encryption information) (q34 in FIG. 56). .. The SIP message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message according to the old encryption information (q35 in Fig. 56). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (q36 in FIG. 56).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (q48 in FIG. 56), and transmits the decrypted SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31.
The encryption information setting unit 31 stores the new encryption information, and sets the new encryption information in the SIP message encryption / decryption unit 36 (q49 in FIG. 57). After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of the new encryption information setting (q50 in FIG. 57). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (q51 in FIG. 57). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (q52 in FIG. 57).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (q37 in FIG. 57). The SIP message encryption / decryption unit 16 decrypts the SIP response message, and transmits the decrypted SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a new encryption information setting completion notification on the client device 3a-1 side to the encryption information setting unit 11.
The encryption information setting unit 11 recognizes the completion of the new encryption information setting, instructs the SIP message encryption / decryption unit 16 to set the new encryption information (q38 in FIG. 57), and after the setting is completed, the encryption information input interface unit 12 Sends the setting completion to the local maintenance console 2 (q39 in Fig. 57). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (q13 in Fig. 57).
The current encryption checked by the encryption information setting unit 11 after inputting the encryption presence / absence, encryption rule, and encryption range of the SIP message when sending / receiving the SIP message to / from the SIP protocol compatible client device 3 from the local maintenance console 2 connected to the server device 1b. If the information is encrypted or not (q24 in Fig. 55), set the encryption information (new encryption information) that uses the encryption key randomly generated by the server device 1b using the current encryption information as the old encryption information. Execute the sequence to be performed.
The encryption information setting unit 11 instructs the encryption key creation unit 18 to generate an encryption key to be used for sending and receiving SIP messages with the client device 3a-1 (q32 in FIG. 56), and the encryption created by the encryption key creation unit 18 Stores the encryption presence / absence, encryption rules, and encryption range of the key and old encryption information (q33 in Fig. 56). The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including new encryption information (q34 in FIG. 56). The SIP message creation unit 14 creates a SIP request message and transmits the created SIP request message to the SIP message encryption / decryption unit 16. The SIP message encryption / decryption unit 16 encrypts the SIP request message according to the old encryption information (q35 in Fig. 56). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (q36 in FIG. 56).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (q48 in FIG. 56), and transmits the decrypted SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31.
The encryption information setting unit 31 stores the new encryption information, and sets the new encryption information in the SIP message encryption / decryption unit 36 (q49 in FIG. 57). After the setting is completed, the encryption information setting unit 31 instructs the SIP message creation unit 34 to create a SIP response message notifying the completion of the new encryption information setting (q50 in FIG. 57). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (q51 in FIG. 57). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1b via the SIP interface unit 33 (q52 in FIG. 57).
When the SIP interface unit 13 of the server device 1b receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (q37 in FIG. 57). The SIP message encryption / decryption unit 16 decrypts the SIP response message, and transmits the decrypted SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a new encryption information setting completion notification on the client device 3a-1 side to the encryption information setting unit 11.
The encryption information setting unit 11 recognizes the completion of the new encryption information setting, instructs the SIP message encryption / decryption unit 16 to set the new encryption information (q38 in FIG. 57), and after the setting is completed, the encryption information input interface unit 12 Sends the setting completion to the local maintenance console 2 (q39 in Fig. 57). The local maintenance console 2 displays the presence / absence of encryption, the encryption rule, and the completion of setting the encryption range (q13 in Fig. 57).
Operation of sending and receiving SIP messages with encryption / decryption after new encryption information is set in the SIP message encryption / decryption unit 16 (q3b to q3f in Fig. 57, q3g to q3i, q53 to q5b in Fig. 58, q3j in Fig. 59). ~ q3p, p5c ~ p5g, the operation of q5h in FIG. 60) is the same as the eleventh embodiment of the present invention described above, and thus the description thereof will be omitted.
As described above, in this embodiment, the maintenance person can change the encryption information from the local maintenance console 2 via the server device 1b at an arbitrary timing and transmit / receive the SIP message with the new encryption information. , The cryptographic security function of SIP messages can be strengthened.
Further, in this embodiment, since the maintainer can arbitrarily set the presence / absence of encryption of the SIP message via the SIP protocol compatible server device, it is possible to realize the encryption security function on the network when the setting is made with encryption. It is possible to make different settings that do not require encryption depending on the network configuration, and it is easy to make settings without encryption when collecting SIP message logs for maintenance work, etc., and it is easy to manage the maintainer. be able to.
Further, in this embodiment, the optimum procedure of the encryption information change procedure including the encryption key generation method can be automatically selected depending on the content of the change in the presence / absence of encryption, so that the encryption information can be changed securely. In the present embodiment, the effect of performing the SIP message transmission / reception encryption is the same as that of the first to 16th embodiments of the present invention described above. Although the operation of the client devices 3a-2 and 3a-3 is not described, the same effect as when the client device 3a-1 is used can be obtained.
FIG. 61 is a block diagram showing a configuration of a client-server distributed system according to an eighteenth embodiment of the present invention. In FIG. 61, the client-server distributed system according to the eighteenth embodiment of the present invention has the eleventh embodiment of the present invention shown in FIG. 35, except that the server device 1c is provided with the encryption information update timer control unit 19. It has the same configuration as the client-server distributed system by, and the same components are given the same reference numerals. Further, the operation of the same component is the same as that of the eleventh embodiment of the present invention.
In this embodiment, encryption information has already been set in the server device 1c and the client devices 3a-1 to 3a-3, and encryption / decryption processing is performed when sending / receiving a SIP message with encryption. .. Hereinafter, the set encryption information is described as the old encryption information.
In this embodiment, by realizing the above configuration, it is possible to periodically update the encryption information used for SIP message encryption during communication between the server device 1c and the client devices 3a-1 to 3a-3. As a result, the security of SIP message control on the IP network can be strengthened.
62 and 63 are sequence charts showing the operation of the client-server distributed system according to the 18th embodiment of the present invention. The operation of the client-server distributed system according to the eighteenth embodiment of the present invention will be described with reference to FIGS. 61 to 63. The processing of the server device 1c and the client device 3a-1 shown in FIGS. 62 and 63 is realized by executing the programs by the CPUs of the server device 1c and the client device 3a-1.
After setting the encryption information, the encryption information setting unit 11 of the server device 1c instructs the encryption information update timer control unit 19 to control the encryption information update timer, and the encryption information update timer control unit 19 instructs the encryption information update timer control unit 19. Is started (r10, r11 in Fig. 62).
The encryption information update timer control unit 19 periodically updates the encryption information update timer (r12 in FIG. 62) and checks the timeout (r13 in FIG. 62). When the encryption information update timer times out, the server device 1c executes the encryption information update sequence. The update sequence of the encryption information differs depending on whether or not the currently set encryption information is encrypted, but in this embodiment, the sequence when the encryption information is set will be described.
The encryption information setting unit 11 instructs the encryption key creation unit 18 to generate an encryption key to be used for sending and receiving a SIP message with the client device 3a-1 (r14 in FIG. 62), and the encryption created by the encryption key creation unit 18 The presence / absence of encryption, the encryption rule, and the encryption range of the key and the old encryption information are stored as new encryption information (r15 in Fig. 62).
The encryption information setting unit 11 instructs the SIP message creation unit 14 to create a SIP request message including a new encryption presence / absence, an encryption rule, an encryption range, and an encryption key (hereinafter referred to as new encryption information) (r16 in FIG. 62). .. The SIP message creation unit 14 creates a SIP request message, and the created SIP request message is encrypted by the SIP message encryption / decryption unit 16 according to the old encryption information (r17 in FIG. 62). The encrypted SIP request message is transmitted to the SIP interface unit 33 of the client device 3a-1 via the SIP interface unit 13 (r17 in FIG. 62).
When the SIP interface unit 33 of the client device 3a-1 receives the SIP request message, the SIP interface unit 33 transmits the received SIP request message to the SIP message encryption / decryption unit 36. The SIP message encryption / decryption unit 36 decrypts the SIP request message (r31 in FIG. 62), and transmits the decrypted SIP request message to the SIP message analysis unit 35. When the SIP message analysis unit 35 confirms the normality of the new encryption information, the SIP message analysis unit 35 transmits the new encryption information to the encryption information setting unit 31.
The encryption information setting unit 31 stores the new encryption information, sets the new encryption information in the SIP message encryption / decryption unit 36 (r32 in FIG. 62), and after the setting is completed, sets the new encryption information in the SIP message creation unit 34. Instructs to create a SIP response message to notify the completion (r33 in Figure 62). The SIP message creation unit 34 creates a SIP response message, and the created SIP response message is encrypted by the SIP message encryption / decryption unit 36 with the old encryption information (r34 in FIG. 62). The encrypted SIP response message is transmitted to the SIP interface unit 13 of the server device 1c via the SIP interface unit 33 (r35 in FIG. 63).
When the SIP interface unit 13 of the server device 1c receives the SIP response message notifying the completion of the new encryption information setting, it instructs the SIP message encryption / decryption unit 16 to decrypt the SIP response message (r19 in FIG. 63). The SIP message encryption / decryption unit 16 decrypts the SIP response message and transmits the decrypted SIP response message to the SIP message analysis unit 15. The SIP message analysis unit 15 transmits a new encryption information setting completion notification on the client device 3a-1 side to the encryption information setting unit 11, and the encryption information setting unit 11 recognizes the completion of the new encryption information setting and encrypts / decrypts the SIP message. Instruct unit 16 to set the new encryption information (r20 in FIG. 63).
After the new encryption information is set, the SIP message encryption / decryption unit 16 instructs the encryption information update timer control unit 19 to execute the control of the encryption information update timer, and the encryption information update timer control unit 19 instructs the encryption information update timer. Is controlled and executed, and the encryption information update timer is restarted (r21 in Fig. 63, r11 in Fig. 62). Subsequent operations return to the first processing operation of this embodiment, and the above processing operation is repeated.
As described above, in this embodiment, the encryption information can be changed periodically and the SIP message can be transmitted / received using the new encryption information, and the encryption security function of the SIP message can be strengthened. Further, in the present embodiment, the effect of performing the SIP message transmission / reception encryption is the same as that of the above-described first to 16th embodiments of the present invention. Although the operation of the client devices 3a-2 and 3a-3 is not described, the same effect as when the client device 3a-1 is used can be obtained.
FIG. 64 is a block diagram showing a configuration of a server device according to a nineteenth embodiment of the present invention. In FIG. 64, the server device 1d has at least the encryption information setting unit 11, the encryption information input interface unit 12, and the encryption information update timer control unit 19, and the local maintenance console 2 is connected by a serial cable or the like. The local maintenance console 2 is temporarily installed during the construction period of the server device 1d, and does not have to be connected during operation.
In this embodiment, by realizing the above configuration, the periodic update timer of the encryption information used for SIP message encryption during communication between the server device 1d and the client device (not shown) is made variable, and the IP The security of SIP message control on the network can be strengthened.
FIG. 65 is a sequence chart showing the operation of the server device 1d according to the 19th embodiment of the present invention. The operation of the server device 1d according to the 19th embodiment of the present invention will be described with reference to FIGS. 64 and 65. The processing of the server device 1d shown in FIG. 65 is realized by the CPU of the server device 1d executing the program.
When the encryption information update timer value is input from the local maintenance console 2 connected to the server device 1d (s1 in FIG. 65), the encryption information input interface unit 12 receives the setting request including the encryption information update timer value (Fig. 65). In s2) of 65, when the normality of the setting request is confirmed, the encryption information update timer value is transmitted to the encryption information setting unit 11.
The encryption information setting unit 11 stores the encryption information update timer value, notifies the encryption information update timer control unit 19 of the encryption information update timer value, and instructs the activation of the encryption information update timer (s3 in FIG. 65). ~ s6). Since the control operation of the encryption information update timer is the same as the control operation in the 18th embodiment of the present invention, the description thereof will be omitted.
In this way, in this embodiment, by enabling the arbitrary periodic update timer value to be set from the local maintenance console 2, it is possible to change the periodic update interval, and if the periodic update is performed at short intervals, cryptographic security It is also possible to further strengthen the above, and it is also possible to select the optimum periodic update timer value in consideration of the load state of the network.
FIG. 66 is a block diagram showing a configuration of a client-server distributed system according to a twentieth embodiment of the present invention. In FIG. 66, the client-server distributed system according to the twentieth embodiment of the present invention is configured by connecting the server device 1e and the client devices 3b-n to 3b-n + 2 to each other by LAN100.
The server device 1e is composed of at least an encryption information setting unit 11, an encryption information input interface unit 12, a SIP interface unit 13, a SIP message encryption / decryption unit 16, and an encryption information table 20. 2 is connected with a serial cable or the like. The local maintenance console 2 is temporarily installed during the construction period of the server device 1e, and does not have to be connected during operation.
The client device 3b-n is composed of at least an encryption information setting unit 31, a SIP interface unit 33, and a SIP message encryption / decryption unit 36. Although not shown, the client device 3b-n + 1,3b-n + 2 has the same configuration as the client device 3b-n.
In this embodiment, by realizing the above configuration, the encryption information used for SIP message encryption during communication between the server device 1e and the plurality of client devices 3-n to 3b-n + 2 Can be set for each client device 3-n to 3b-n + 2 to enhance the security of SIP message control on the IP network.
FIG. 67 is a sequence chart showing the operation of the client-server distributed system according to the twentieth embodiment of the present invention, and FIG. 68 is a diagram showing a configuration example of the cryptographic information table 20 of FIG. 66. The operation of the client-server distributed system according to the twentieth embodiment of the present invention will be described with reference to FIGS. 66 to 68. The processing of the server device 1e and the client device 3b-n shown in FIG. 67 is realized by executing the programs by the CPUs of the server device 1e and the client device 3b-n. In addition, x client devices (x is a positive integer) can be registered in the server device 1e.
Since the encryption information setting operation between the server device 1e and the client device 3b-n is the same as the encryption information setting operation in the twelfth embodiment of the present invention described above, a detailed description of the encryption information setting operation will be given. Is omitted.
When the encryption information used for sending and receiving SIP message encryption from the local maintenance console 2 via the encryption information input interface unit 12 is set in the server unit 1e (t11 in Fig. 67), the encryption information setting unit If the cryptographic information is cryptographic information that can be set in the server device 1e, 11 stores the cryptographic information in the area of the client device 3b-n in the cryptographic information table 20 (t21 in FIG. 67), and the client device 3b-n. Is notified of the encrypted information (t22, t23 in FIG. 67).
The client device 3b-n stores the encryption information in the encryption information setting unit 31, sets the encryption information in the SIP message encryption / decryption unit 36 (t31 in FIG. 67), and notifies the server device 1e of the completion of the encryption information setting. (T32, t33 in Fig. 67).
When the server device 1e receives the encryption information setting completion notification, it sets the encryption information in the SIP message encryption / decryption unit 16 (t24 in FIG. 67), and completes the encryption information setting in the client device 3b-n (FIG. 67). t25, t13).
In the server device 1e, when the encryption information of the client device 3b-n + 1,3b-n + 2 is input from the local maintenance console 2 in the same manner as the above setting operation, the encryption information setting unit 11 performs the encryption information. Are stored in the areas of the SIP protocol-compatible client devices 3b-n + 1 and 3b-n + 2 in the encryption information table 20, and the same encryption information setting sequence as above is executed respectively.
As described above, in this embodiment, the server device 1e can set different encryption information for each client device 3b-n to 3b-n + 2, and each client device 3b-n to 3b-n + 2. Since it is possible to use the encryption rules, encryption range, and encryption key of, it becomes difficult to infer the encryption information between other devices from the encryption status between each client device 3b-n to 3b-n + 2, and encryption security. The function can be enhanced.
Further, in this embodiment, it is not necessary to match the encryption functions of the client devices 3b-n to 3b-n + 2 in the system, and the server device 1e and the client devices 3b-n to 3b-n + 2 possess them. If the cryptographic functions match, the cryptographic functions within the system can be realized. In this embodiment, the effect of performing the SIP message transmission / reception encryption is the same as that of the first to nineteenth embodiments of the present invention described above.
FIG. 69 is a block diagram showing a configuration of a client-server distributed system according to a 21st embodiment of the present invention. In FIG. 69, in the client-server distributed system according to the 21st embodiment of the present invention, the server device 1f and the client devices 3c-1,3c-2,3d-1,3d-2 are connected to each other by LAN100. It is composed of.
The server device 1f is composed of at least the encryption information setting unit 11, the encryption information input interface unit 12, the SIP interface unit 13, the SIP message encryption / decryption unit 16, the encryption key creation unit 18, and the encryption capability management unit 21. It is configured and the local maintenance console 2 is connected with a serial cable or the like. The local maintenance console 2 is temporarily installed during the construction period of the server device 1f, and does not have to be connected during operation.
The client devices 3c-1 and 3c-2 are composed of at least an encryption information setting unit 31, a SIP interface unit 33, a SIP message encryption / decryption unit 36, an encryption key creation unit 38, and an encryption capability management unit 41. , The client devices 3d-1 and 3d-2 are provided with at least the SIP interface unit 33.
In this embodiment, by realizing the above configuration, SIP message encryption during communication between the server device 1f and a plurality of client devices 3c-1, 3c-2, 3d-1, 3d-2 The encryption information used for encryption can be set for each client device 3c-1 and 3c-2, and the optimum security state can be obtained regardless of the difference in encryption capability of the client device.
70 and 71 are sequence charts showing the operation of the client-server distributed system according to the 21st embodiment of the present invention. The operation of the client-server distributed system according to the 21st embodiment of the present invention will be described with reference to FIGS. 69 to 71. The processing of the server device 1f and the client device 3c-1,3c-2,3d-1,3d-2 shown in FIGS. 70 and 71 is performed by the server device 1f and the client device 3c-1,3c-2,3d-. 1,3d-2 It is realized by each CPU executing the program.
When the first server access request from the client device 3c-1 to the server device 1f occurs (u41 in Fig. 70), the encryption capability management unit 41 adds the encryption capability data held by the client device 3c-1 to the SIP request message to be sent. Then, it is transmitted to the SIP interface unit 13 of the server device 1f via the SIP interface unit 33 (u42 in FIG. 70) (u43 in FIG. 70).
When the SIP interface unit 13 of the server device 1f receives the SIP request message, it recognizes the first access from the client device 3c-1 and transmits it to the encryption information setting unit 11. The encryption information setting unit 11 notifies the encryption capacity management unit 21 of the encryption capacity held by the client device 3c-1, and the encryption capacity management unit 21 stores the encryption capacity (u21 in FIG. 70).
In addition, the encryption information setting unit 11 creates and stores a random parameter for generating an encryption key used for SIP message encryption between the server device 1f and the client device 3c-1 (u22 in FIG. 70), and generates the encryption key. A SIP response message to which a random parameter is added is transmitted to the SIP interface section 33 of the client device 3c-1 via the SIP interface section 13 (u23 in FIG. 70).
When the SIP interface unit 33 of the client device 3c-1 receives the SIP response message to which the random parameter for encryption key generation is added, the received random parameter for encryption key generation is transmitted to the encryption information setting unit 31. The encryption information setting unit 31 stores the random parameter for generating the encryption key (u44 in FIG. 70).
On the other hand, when the initial server access request to the server device 1f is generated from the client device 3d-1 (u61 in FIG. 70), the encryption capability data is not added to the SIP request message and the server device 1f is passed through the SIP interface unit 33. It is sent to the SIP interface unit 13 of (Fig. 70, u62).
When the SIP interface unit 13 of the server device 1f receives the SIP request message, it recognizes the first access from the client device 3d-1 and transmits it to the encryption information setting unit 11. Since the encryption capacity data is not added to the SIP request message, the encryption information setting unit 11 notifies the encryption capacity management unit 21 that the encryption capacity of the client device 3d-1 is not present, and the encryption capacity management unit 21 notifies the client device 3d-1. Memorize no encryption (u24 in Figure 70). Further, the encryption information setting unit 11 transmits a SIP response message to the SIP interface unit 33 of the client device 3d-1 via the SIP interface unit 13 without adding the random parameter for encryption key generation (u25 in FIG. 70). ..
When the encryption information of the SIP message when sending and receiving the SIP message to and from the client device 3c-1 is input from the local maintenance console 2 connected to the server device 1f (u11 in FIG. 70), the encryption information input interface unit 12 receives the encryption information. (U12 in FIG. 70), when the normality of the setting request is confirmed, the encryption information is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 instructs the encryption ability management unit 21 to confirm the presence or absence of the encryption ability of the client device 3c-1, and the client device 3c-1 possesses the encryption ability (u26 in FIG. 70). ), The encrypted information is stored (u27 in FIG. 71). The server device 1f sends a SIP request message including encrypted information to the SIP interface section 33 of the client device 3c-1 via the SIP interface section 13.
The SIP interface unit 33 of the client device 3c-1 receives the SIP request message including the encryption information, and transmits the encryption information to the encryption information setting unit 31. The encryption information setting unit 31 stores the encryption information, generates an encryption key from the stored encryption key generation random parameters, sets the encryption information in the SIP message encryption / decryption unit 36, and after the setting is completed, encrypts. A SIP response message notifying the completion of information setting is transmitted to the SIP interface unit 13 of the server device 1f via the SIP interface unit 33.
When the SIP interface unit 13 of the server device 1f receives the SIP response message notifying the presence / absence of encryption, the encryption rule, and the completion of the encryption range setting, the received SIP response message is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 recognizes the notification of the completion of setting the encryption information on the client device 3c-1 side, generates an encryption key from the stored encryption key generation random parameters, and causes the SIP message encryption / decryption unit 16 to perform the encryption. Instructs the information setting, and after the setting is completed, the encryption information input interface unit 12 sends the setting completion to the local maintenance console 2 (u28 in Fig. 71). Local maintenance console 2 displays the completion of encryption information setting (u13 in Fig. 71). After that, when sending and receiving SIP messages, the message is encrypted and decrypted according to the set encryption information (u29 in Fig. 71).
When the encryption information of the SIP message when sending and receiving the SIP message to and from the client device 3d-1 is input from the local maintenance console 2 connected to the server device 1f (u14 in Fig. 71), the encryption information input interface unit 12 receives the encryption information. When the setting request including the above is received (u15 in FIG. 71) and the normality of the setting request can be confirmed, the encrypted information is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 instructs the encryption ability management unit 21 to confirm the presence or absence of the encryption ability of the client device 3d-1 (u30 in FIG. 71), and the client device 3d-1 does not have the encryption ability. Therefore, it recognizes that the encrypted information cannot be set (u31 in FIG. 71).
The encryption information setting unit 11 that recognizes that the encryption information cannot be set in the client device 3d-1 sends a setting failure from the encryption information input interface unit 12 to the local maintenance console 2 (u32 in Fig. 71). Local maintenance console 2 displays a cryptographic information setting failure (u16 in Figure 71). After that, when sending and receiving SIP messages, the messages are sent and received without encryption (u33 in Fig. 71).
As described above, in this embodiment, when the server device 1f has the SIP message encryption / decryption function, the client device 3c-1.3c-2 has the SIP message encryption / decryption function in the system. , When a client device 3d-1.3d-2 that does not have the SIP message encryption / decryption function is mixed, the encryption / decryption function is enabled only for the client devices 3c-1 and 3c-2 that have the encryption / decryption function. Therefore, it is possible to strengthen the encryption security function as a system by enabling the encryption / decryption function only between the devices capable of encryption / decryption without having to make the possessed function levels of the client devices uniform.
Further, in the present embodiment, the effect of performing the SIP message transmission / reception encryption is the same as that of the first and second embodiments of the present invention described above. Although the operation of the client devices 3c-2 and 3d-2 is not described, the same effect as when the client devices 3c-1 and 3d-1 are used can be obtained.
FIG. 72 is a block diagram showing a configuration of a client-server distributed system according to a 22nd embodiment of the present invention. In FIG. 72, in the client-server distributed system according to the 22nd embodiment of the present invention, the server device 1g and the client devices 3c-1,3c-2,3d-1,3d-2 are connected to each other by LAN100. It is composed of.
The server device 1g includes at least a maintenance console interface unit 12 and a SIP interface unit 13, and the local maintenance console 2 is connected by a serial cable or the like. The local maintenance console 2 is temporarily installed during the construction period of the server device 1g, and does not have to be connected during operation.
The client devices 3c-1 and 3c-2 include at least an encryption information setting unit 31, a SIP interface unit 33, a SIP message encryption / decryption unit 36, an encryption key creation unit 38, and an encryption capability management unit 41. There is. Further, the client devices 3d-1 and 3d-2 include at least the SIP interface unit 33.
In this embodiment, by realizing the above configuration, the server device 1g having no encryption function, the client devices 3c-1 and 3c-2 having a plurality of encryption functions, and the client device 3d having no encryption function It is possible to send and receive SIP messages between client devices in which -1,3d-2 are mixed.
73 and 74 are sequence charts showing the operation of the client-server distributed system according to the 22nd embodiment of the present invention. The operation of the client-server distributed system according to the 22nd embodiment of the present invention will be described with reference to FIGS. 72 to 74. The processing of the server device 1g and the client device 3c-1,3c-2,3d-1,3d-2 shown in FIGS. 73 and 74 is performed by the server device 1g and the client device 3c-1,3c-2,3d-. 1,3d-2 It is realized by each CPU executing the program.
When the first server access request from the client device 3c-1 to the server device 1g occurs (v41 in Fig. 73), the encryption capability management unit 41 adds the encryption capability data held by the client device 3c-1 to the SIP request message to be sent. Then, it is transmitted to the SIP interface unit 13 of the server device 1g via the SIP interface unit 33 (v43 in FIG. 73).
When the SIP interface unit 13 of the server device 1g receives the SIP request message, it ignores the encryption capability data attached to the SIP request message (v21 in FIG. 73) and sends the SIP response message to the client device via the SIP interface unit 13. It is transmitted to the SIP interface section 33 of 3c-1 (v22 in Fig. 73).
When the SIP interface unit 33 of the client device 3c-1 receives a SIP response message to which the random parameter for encryption key generation is not added, the encryption information indicates that the random parameter for encryption key generation is not added to the received SIP response message. Communicate to the setting unit 31. The encryption information setting unit 31 recognizes that there is no SIP message transmission / reception encryption between the server device 1g and the client device 3c-1 (v44 in FIG. 73), and stores the no encryption (v45 in FIG. 73).
When the initial server access request to the server device 1g is generated from the client device 3d-1 (v61 in Fig. 73), the SIP request message is not added with the encryption capability data, and the SIP of the server device 1g is performed via the SIP interface unit 33. It is transmitted to the interface unit 13 (v62 in Fig. 73).
When the SIP interface unit 13 of the server device 1g receives the SIP request message, it sends the SIP response message to the SIP interface unit 33 of the client device 3d-1 via the SIP interface unit 13 (v23 in FIG. 73).
When the encryption information of the SIP message when sending and receiving the SIP message to and from the client device 3c-1 is input from the local maintenance console 2 connected to the server device 1g (v11 in Fig. 73), the maintenance console interface unit 12 inputs the encryption information. Receives the including configuration request (v12 in Figure 73) and sends the configuration failure to the local maintenance console 2 (v24 in Figure 73, v25 in Figure 74) because the encryption setting is not possible. Local maintenance console 2 displays a cryptographic information setting failure (v13 in Figure 74). When sending and receiving SIP messages between server device 1g and client device 3c-1, messages are sent and received without encryption (v26 in Fig. 73).
When the encryption information of the SIP message when sending and receiving the SIP message to and from the client device 3d-1 is input from the local maintenance console 2 connected to the server device 1g (v14 in Fig. 74), the maintenance console interface unit 12 inputs the encryption information. Receives the including configuration request (v15 in Figure 74) and sends the configuration failure to the local maintenance console 2 (v27, v28 in Figure 74) because the encryption setting is not possible. Local maintenance console 2 displays a cryptographic information setting failure (v16 in Figure 74). When sending and receiving SIP messages between server device 1g and client device 3d-1, messages are sent and received without encryption (v29 in Figure 73).
As described above, in this embodiment, when the client device 3c-1 has the SIP message encryption / decryption function and the server device 1g that sends / receives the SIP message in the system does not have the SIP message encryption / decryption function. Since the encryption / decryption function can be disabled and operated, SIP messages can be sent and received without having to match the possessed function levels of the client device and the server device. In this embodiment, the effect of performing the SIP message transmission / reception encryption is the same as that of the first and second embodiments of the present invention described above. Although the operation of the client devices 3c-2 and 3d-2 is not described, the same effect as when the client devices 3c-1 and 3d-1 are used can be obtained.
FIG. 75 is a block diagram showing a configuration of a client-server distributed system according to a 23rd embodiment of the present invention. In FIG. 75, the client-server distributed system according to the 23rd embodiment of the present invention is configured by connecting the server device 1f and the client devices 3d-1 to 3d-4 to each other by LAN100.
The server device 1f is composed of at least the encryption information setting unit 11, the encryption information input interface unit 12, the SIP interface unit 13, the SIP message encryption / decryption unit 16, the encryption key creation unit 18, and the encryption capability management unit 21. It is configured and the local maintenance console 2 is connected with a serial cable or the like. The local maintenance console 2 is temporarily installed during the construction period of the server device 1f, and does not have to be connected during operation. Further, the client devices 3d-1 to 3d-4 are provided with at least SIP interface units 33-1 to 33-4.
In this embodiment, by realizing the above configuration, the server is used during communication between the server device 1f and a plurality of client devices 3d-1 to 3d-4 that do not have the SIP message encryption / decryption function. Even if the device 1f has a SIP message encryption / decryption function, it can send and receive SIP messages without encryption.
76 and 77 are sequence charts showing the operation of the client-server distributed system according to the 23rd embodiment of the present invention. The operation of the client-server distributed system according to the 23rd embodiment of the present invention will be described with reference to FIGS. 75 to 77. The processing of the server device 1f and the client devices 3d-1 to 3d-4 shown in FIGS. 76 and 77 is realized by executing the program by each CPU of the server device 1f and the client devices 3d-1 to 3d-4. Will be done.
When the first server access request to the server device 1f occurs from the client device 3d-1 (w31 in Fig. 76), the encryption capability data is not added to the SIP request message and the server device 1f is passed through the SIP interface section 33-1. It is sent to the SIP interface unit 13 of (w32 in Fig. 76).
When the SIP interface unit 13 of the server device 1f receives the SIP request message, it recognizes the first access from the client device 3d-1 and transmits it to the encryption information setting unit 11. Since the encryption capacity data is not added to the SIP request message, the encryption information setting unit 11 notifies the encryption capacity management unit 21 that the encryption capacity of the client device 3d-1 is not present, and the encryption capacity management unit 21 notifies the client device 3d-1. Memorize no encryption (w21 in Figure 76). Further, the encryption information setting unit 11 transmits a SIP response message to the SIP interface unit 33-1 of the client device 3d-1 via the SIP interface unit 13 without adding the random parameter for encryption key generation (FIG. 76). w22).
Even when the initial server access request to the server device 1f is generated from the client device 3d-2 (u61 in Fig. 70), the SIP interface section 33-2 does not have the encryption capability data added to the SIP request message as described above. It is transmitted to the SIP interface unit 13 of the server device 1f via the above (w42 in Fig. 76).
When the SIP interface unit 13 of the server device 1f receives the SIP request message, it recognizes the first access from the client device 3d-2 and transmits it to the encryption information setting unit 11. Since the encryption capacity data is not added to the SIP request message, the encryption information setting unit 11 notifies the encryption capacity management unit 21 that the encryption capacity of the client device 3d-2 is not present, and the encryption capacity management unit 21 notifies the client device 3d-2. Memorize no encryption (w23 in Figure 76). Further, the encryption information setting unit 11 transmits a SIP response message to the SIP interface unit 33-2 of the client device 3d-2 via the SIP interface unit 13 without adding the random parameter for encryption key generation (FIG. 76). w24).
When the encryption information of the SIP message when sending and receiving the SIP message to and from the client device 3d-1 is input from the local maintenance console 2 connected to the server device 1f (w11 in FIG. 76), the encryption information input interface unit 12 receives the encryption information. When the setting request including the above is received (w12 in FIG. 76) and the normality of the setting request can be confirmed, the encrypted information is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 instructs the encryption ability management unit 21 to confirm the presence or absence of the encryption ability of the client device 3d-1 (w25 in FIG. 76), and the client device 3d-1 does not have the encryption ability. Therefore, it recognizes that the encrypted information cannot be set (w26 in FIG. 76).
The encryption information setting unit 11 that recognizes that the encryption information cannot be set in the client device 3d-1 sends a setting failure from the encryption information input interface unit 12 to the local maintenance console 2 (w27 in Fig. 76). Local maintenance console 2 displays a cryptographic information setting failure (w13 in Figure 76). After that, when sending and receiving SIP messages, the messages are sent and received without encryption (w33 in Fig. 76).
When the encryption information of the SIP message when sending and receiving the SIP message to and from the client device 3d-2 is input from the local maintenance console 2 connected to the server device 1f (w14 in FIG. 77), the encryption information input interface unit 12 receives the encryption information. When the setting request including the above is received (w15 in FIG. 77) and the normality of the setting request can be confirmed, the encrypted information is transmitted to the encryption information setting unit 11. The encryption information setting unit 11 instructs the encryption ability management unit 21 to confirm the presence or absence of the encryption ability of the client device 3d-2 (w28 in FIG. 77), and the client device 3d-2 does not have the encryption ability. Therefore, it recognizes that the encrypted information cannot be set (w29 in FIG. 77).
The encryption information setting unit 11 that recognizes that the encryption information cannot be set in the client device 3d-2 sends a setting failure from the encryption information input interface unit 12 to the local maintenance console 2 (w30 in FIG. 77). Local maintenance console 2 displays a cryptographic information setting failure (w16 in Figure 77). After that, when sending and receiving SIP messages, the messages are sent and received without encryption (w43 in Fig. 77).
As described above, in this embodiment, when the server device 1f has the SIP message encryption / decryption function, the client devices 3d-1 to 3d-4 that do not have the SIP message encryption / decryption function in the system. If only exists, SIP messages are sent and received without encryption to and from client devices 3d-1 to 3d-4 that do not have encryption / decryption functions, so there is no need to match the possessed function levels of client devices, and SIP is performed. You can send and receive messages. Although the operation of the client devices 3d-3 and 3d-4 is not described, the same effect as when the client devices 3d-1 and 3d-2 are used can be obtained.
FIG. 78 is a sequence chart showing the operation of the client-server distributed system according to the 24th embodiment of the present invention. The client-server distributed system according to the 24th embodiment of the present invention has the same configuration as the client-server distributed system according to the 21st embodiment of the present invention shown in FIG. 69. The description is omitted. Hereinafter, the operation of the client-server distributed system according to the 24th embodiment of the present invention will be described with reference to FIGS. 69 and 78. The processing of the server device 1f and the client device 3c-1 shown in FIG. 78 is realized by executing the programs by the CPUs of the server device 1f and the client device 3c-1.
The encryption capability management unit 41 of the client device 3c-1 is possessed by the client device 3c-1, and recognizes one or more types (one or more types) of cryptographic rules capable of encryption / decryption processing. It is stored as a cipher rule list.
By realizing the above configuration, in a client-server distributed system that includes a client device 3c-1 that has one or more types of cryptographic rules that can be used as cryptographic capabilities, the cryptographic rules used from the server device 1f. Can be selected to enable the sending and receiving of encrypted SIP messages between the server device 1f and the client device 3c-1.
When the first server access request from the client device 3c-1 to the server device 1f occurs (x11 in Fig. 78), the encryption capability management unit 41 includes a list of cryptographic rules held by the client device 3c-1 in the SIP request message to be sent. It is added (x12 in FIG. 78) and transmitted to the SIP interface section 13 of the server device 1f via the SIP interface section 33 (x13 in FIG. 78).
When the SIP interface unit 13 of the server device 1f receives the SIP request message, it reads the cipher rule list from the client device 3c-1 and transmits it to the cipher information setting unit 11. The encryption information setting unit 11 notifies the encryption capacity management unit 21 of the cipher rule list held by the client device 3c-1. The cryptographic ability management unit 21 stores the cipher rule list (x1 in FIG. 78). Further, the encryption information setting unit 11 transmits a SIP response message to the SIP interface unit 33 of the client device 3c-1 via the SIP interface unit 13 (x2 in FIG. 78).
The encryption capability management unit 21 of the server device 1 stores the encryption information used for encrypting / decrypting the SIP message when sending / receiving the SIP message to / from the client device 3c-1, if the encryption is present or not. The cipher rule to be used is selected from the cipher rule list, the cipher information including the cipher rule is determined, and the cipher information is transmitted to the cipher information setting unit 11 (x3 in FIG. 78). The encryption information setting unit 11 stores the encryption information.
Since the subsequent processing is the same operation as the encryption information setting sequence from the server device 1 to the client device 3-1 according to the first embodiment of the present invention, the description thereof will be omitted.
As described above, in this embodiment, when the server device 1f and the client device 3c-1 have encryption / decryption functions based on a plurality of types of encryption rules, the server device 1f to the client device 3c-1 It can be determined automatically without instructing to set an unusable cryptographic rule. Further, in the present embodiment, the effect of performing the SIP message transmission / reception encryption is the same as that of the first and second embodiments of the present invention described above. Although the operation of the client device 3c-2 is not described, the same effect as when the client device 3c-1 is used can be obtained.
As described above, in the present invention, in the client / server type distributed system corresponding to the SIP protocol, the security on the IP network is strengthened by encrypting the SIP message according to the encryption information arbitrarily set by the maintainer. In addition to being able to do this, the encryption information used to encrypt / decrypt SIP messages set by the system maintainer can be distributed to the client device via the maintenance console interface section of the server device, and the entire system can be distributed. Considering this, the encryption capability can be set from one place in a unified manner, and maintenance work can be simplified and maintenance manpower can be reduced.
In addition, SSL / TLS is generally used as a security method in conventional SIP, but in the present invention, there is no need to distribute a certificate to each device, a certificate management function, or certificate authentication by an authentication server, and SSL / The encryption function can be realized by a simpler procedure than the TLS method. Further, in the present invention, since UDP is used as the layer 4 protocol, it has the effect of ensuring real-time performance and enhancing security.
In the present invention, the server device can be set by using both the local maintenance console connected by a serial cable or the like and the maintenance console connected by the LAN interface, and the ease of maintenance can be ensured. There is an effect.
In the present invention, when the entire SIP message including the SIP header and SDP data is encrypted, strong cryptographic security can be realized against eavesdropping and data falsification during communication on the IP network. When encrypting any part of a SIP message, it is possible to operate via a network device such as SIP-NAT without encrypting the SIP header or SDP data depending on the encryption range selection state. Since it can be set and important data parts that require encryption can be encrypted for transmission and reception, there is an effect that the network function can be strengthened as well as the encryption security.
In the present invention, since the maintainer can arbitrarily set whether or not to encrypt the SIP message via the server device, it is possible to realize the encryption security function on the network when the encryption is set, and the encryption is required depending on the network configuration. It is possible to make different settings unnecessarily, and it is easy to make unencrypted settings when collecting SIP message logs for maintenance work, which has the effect of facilitating maintenance by the maintainer. There is.
The present invention has an effect that compatibility with a client device having no encryption function can be ensured by having a function of selecting the presence or absence of encryption. Further, in the present invention, the encryption range of the SIP message is arbitrarily encrypted from the maintenance console in a system that supports both a method of encrypting the entire SIP message and a method of encrypting an arbitrary part of the SIP message. By making it possible to select the range to be used, both cryptographic security and network functionality are satisfied in the system where network devices such as SIP-NAT exist, and the optimum security level for the current network configuration can be obtained. It has the effect of being able to be selected and realized.
In the present invention, the encryption security function on the network can be realized by encrypting the SIP message, and it is possible to set different encryption presence / absence, encryption rule, and encryption range for each network configuration. Cryptographic security can be strengthened.
In the present invention, by setting the encryption information in the client device from the server device, there is an effect that system uniformity and easy management of the maintainer can be realized.
In the present invention, when adding a cryptographic rule that can be operated by the system, the new cryptographic rule can be used without additional development of the cryptographic rule selection interface, so that the change of the maintenance interface is minimized. It has the effect of facilitating development.
In the present invention, in a system in which a SIP message is transmitted and received without encryption, when the encryption function is activated, encryption information other than the encryption key is transmitted from the server device to the client device without being encrypted. The encryption key has a function that enables both the server device and the client device to generate a synchronized encryption key, and the server device and the client device do not need to be notified via the IP network of the encryption key. It is possible to set common cryptographic information with and, and there is an effect that the cryptographic security function after the cryptographic information setting can be strengthened.
In the present invention, since the encryption key is generated using a random parameter determined at the first access from the client device to the server device, the regularity of the generated encryption key can be eliminated and the encryption security function is further enhanced. It has the effect of being able to.
In the present invention, in a system in which a SIP message is transmitted / received in a state of being set to have encryption, when changing the encryption information, the encryption information is encrypted by the encryption information set between the client device and the server device. Since it is sent in a encrypted state, it has the effect of strengthening cryptographic security.
In the present invention, it is possible for the maintenance person to arbitrarily set the encryption information other than the encryption key among the newly set encryption information from the maintenance console, to make the system construction uniform, and to have the SIP by the maintenance person. If you want to log the message communication status, you can change it without encryption, so you can ensure ease of maintenance. Further, in the present invention, since the same encryption key can be changed at an arbitrary timing by the maintainer without using the same encryption key for a long time, there is an effect that security against hacking of encrypted information can be enhanced.
In the present invention, since the server device randomly generates the encryption key and distributes it to the client device, the encryption key set by a third party including the maintainer cannot be known, and human error or the encryption key can be detected. It has the effect of preventing leakage and further strengthening cryptographic security.
In the present invention, after changing to the new encrypted information, it is possible to receive and decrypt the SIP message encrypted by the old encrypted information for a certain period of time, so that the SIP message sent and received during the change of the encrypted information is valid. loss sex without Nau, it is possible to change the encryption information, there is an effect that a change in the encryption information can be executed at any timing.
In the present invention, in a system in which a SIP message is sent and received while the encryption key is set, when the encryption key to be used is distributed from the server device to the client device, the IP is always encrypted. Since communication on the network is performed, it is possible to prevent the leakage of the encryption key, and it is possible to strengthen the encryption security function when encrypting the SIP message.
In the present invention, in a system in which a SIP message is transmitted / received in a state where the encryption is set, when the encryption information to be used is distributed from the server device to the client device, the encryption key is always encrypted. By enabling communication on the IP network, it is possible to prevent leakage of the encryption key and strengthen the encryption security function when encrypting SIP messages, but other encryption information (encryption / non-encryption /) By encrypting and distributing the (encryption rule / encryption range), it becomes difficult to guess the encryption key, and there is an effect that the encryption security can be further strengthened.
In the present invention, when changing from an unencrypted state to an encrypted state, first, encryption information using an encryption key created in synchronization with both the client device and the server device is set, and then the server device automatically generates the encryption information. By performing two-step encryption information setting, which is to set the encryption information that uses the encryption key to be used, the server device automatically generates the actual SIP message encryption for transmission and reception, and the encryption is not recognized by third parties including the maintainer. The encryption / decryption is performed using the key, and the encryption security function can be strengthened. Further, in the present invention, since the encryption key for encrypting the transmission and reception of SIP messages is always notified in an encrypted state, there is an effect that the security of the encryption function can be strengthened.
In the present invention, the maintenance person can change the encryption information from the maintenance console via the server device at an arbitrary timing to send and receive the SIP message with the new encryption information, and provide the encryption security function of the SIP message. It has the effect of being able to be strengthened.
In the present invention, since the maintainer can arbitrarily set whether or not to encrypt the SIP message via the server device, it is possible to realize the encryption security function on the network when the encryption is set, and the encryption is required depending on the network configuration. It is possible to make different settings unnecessarily, and it is easy to make unencrypted settings when collecting SIP message logs for maintenance work, which has the effect of facilitating maintenance by the maintainer. There is.
In the present invention, since the optimum procedure of the encryption information change procedure including the encryption key generation method can be automatically selected depending on the content of the change in the presence or absence of encryption, there is an effect that the encryption information can be changed securely. ..
According to the present invention, it is possible to periodically change the cryptographic information and send / receive a SIP message using the new cryptographic information, which has the effect of strengthening the cryptographic security function of the SIP message.
In the present invention, it is possible to change the periodic update interval by making it possible to set an arbitrary periodic update timer value from the maintenance console, and if the periodic update is performed at short intervals, the cryptographic security can be further strengthened. In addition, there is an effect that the optimum periodic update timer value can be selected in consideration of the load state of the network.
In the present invention, since the server device can set different encryption information for each client device and can use the encryption rule, encryption range, and encryption key for each device, the encryption state between each device can be changed between other devices. It becomes difficult to guess the cryptographic information of the above, and there is an effect that the cryptographic security function can be strengthened.
In the present invention, it is not necessary to match the encryption functions of the client device in the system, and there is an effect that the encryption function in the system can be realized if the encryption functions possessed by the server device and the client device match. ..
In the present invention, when the server device has the SIP message encryption / decryption function, the client device in the system has a SIP message encryption / decryption function and a mixture of those that do not have the SIP message encryption / decryption function. Since the encryption / decryption function can be enabled only for the client device that has the encryption / decryption function, it is not necessary to match the possessed function levels of the client devices, and the encryption / decryption is performed only between the devices that can encrypt / decrypt. It has the effect of enabling the encryption function and strengthening the cryptographic security function of the system.
In the present invention, when the client device has the SIP message encryption / decryption function and the server device that sends / receives the SIP message in the system does not have the SIP message encryption / decryption function, the encryption / decryption is performed. Since it is possible to operate by disabling the encryption function, it is not necessary to have the same level of functions possessed by the client device and the server device, and there is an effect that SIP messages can be sent and received.
<figref num="1">It is a block diagram which shows the structure of the client-server type distributed system corresponding to the SIP protocol by 1st Embodiment of this invention.</figref><figref num="2">It is a sequence chart which shows the operation of the client-server type distributed system by 1st Embodiment of this invention.</figref><figref num="3">It is a sequence chart which shows the operation of the client-server type distributed system by 1st Embodiment of this invention.</figref><figref num="4">It is a sequence chart which shows the operation of the client-server type distributed system by 1st Embodiment of this invention.</figref><figref num="5">It is a sequence chart which shows the operation of the client-server type distributed system by 2nd Embodiment of this invention.</figref><figref num="6">It is a sequence chart which shows the operation of the client-server type distributed system by 2nd Embodiment of this invention.</figref><figref num="7">It is a sequence chart which shows the operation of the client-server type distributed system by 2nd Embodiment of this invention.</figref><figref num="8">It is a block diagram which shows the structure of the client-server type distributed system by the 3rd Example of this invention.</figref><figref num="9">It is a sequence chart which shows the operation of the client-server type distributed system by the 3rd Example of this invention.</figref><figref num="10">It is a sequence chart which shows the operation of the client-server type distributed system by the 3rd Example of this invention.</figref><figref num="11">It is a figure which shows the example of the cipher range by the 3rd Example of this invention.</figref><figref num="12">It is a figure which shows the example of the cipher range by the 3rd Example of this invention.</figref><figref num="13">It is a block diagram which shows the structure of the client-server type distributed system by 4th Embodiment of this invention.</figref><figref num="14">It is a sequence chart which shows the operation of the client-server type distributed system by 4th Embodiment of this invention.</figref><figref num="15">It is a sequence chart which shows the operation of the client-server type distributed system by 4th Embodiment of this invention.</figref><figref num="16">It is a sequence chart which shows the operation of the client-server type distributed system by 4th Embodiment of this invention.</figref><figref num="17">It is a sequence chart which shows the operation of the client-server type distributed system by 5th Embodiment of this invention.</figref><figref num="18">It is a sequence chart which shows the operation of the client-server type distributed system by 5th Embodiment of this invention.</figref><figref num="19">It is a sequence chart which shows the operation of the client-server type distributed system by 5th Embodiment of this invention.</figref><figref num="20">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="21">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="22">It is a sequence chart which shows the operation of the client-server type distributed system by the 6th Example of this invention.</figref><figref num="23">It is a sequence chart which shows the operation of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="24">It is a sequence chart which shows the operation of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="25">It is a sequence chart which shows the operation of the client-server type distributed system by 7th Embodiment of this invention.</figref><figref num="26">It is a sequence chart which shows the operation of the client-server type distributed system by 8th Embodiment of this invention.</figref><figref num="27">It is a sequence chart which shows the operation of the client-server type distributed system by 8th Embodiment of this invention.</figref><figref num="28">It is a sequence chart which shows the operation of the client-server type distributed system by 8th Embodiment of this invention.</figref><figref num="29">It is a sequence chart which shows the operation of the client-server type distributed system by the 9th Example of this invention.</figref><figref num="30">It is a sequence chart which shows the operation of the client-server type distributed system by the 9th Example of this invention.</figref><figref num="31">It is a sequence chart which shows the operation of the client-server type distributed system by the 9th Example of this invention.</figref><figref num="32">It is a sequence chart which shows the operation of the client-server type distributed system by 10th Embodiment of this invention.</figref><figref num="33">It is a sequence chart which shows the operation of the client-server type distributed system by 10th Embodiment of this invention.</figref><figref num="34">It is a sequence chart which shows the operation of the client-server type distributed system by 10th Embodiment of this invention.</figref><figref num="35">It is a block diagram which shows the structure of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="36">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="37">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="38">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="39">It is a sequence chart which shows the operation of the client-server type distributed system by 11th Embodiment of this invention.</figref><figref num="40">It is a block diagram which shows the structure of the client-server type distributed system by the twelfth embodiment of this invention.</figref><figref num="41">It is a sequence chart which shows the operation of the client-server type distributed system according to the twelfth embodiment of this invention.</figref><figref num="42">It is a sequence chart which shows the operation of the client-server type distributed system according to the twelfth embodiment of this invention.</figref><figref num="43">It is a sequence chart which shows the operation of the client-server type distributed system according to the twelfth embodiment of this invention.</figref><figref num="44">It is a sequence chart which shows the operation of the client-server type distributed system according to the twelfth embodiment of this invention.</figref><figref num="45">It is a flowchart which shows the operation of the server apparatus and the client apparatus by 13th Embodiment of this invention.</figref><figref num="46">It is a sequence chart which shows the operation of the client-server type distributed system by 14th Embodiment of this invention.</figref><figref num="47">It is a sequence chart which shows the operation of the client-server type distributed system by 14th Embodiment of this invention.</figref><figref num="48">It is a sequence chart which shows the operation of the client-server type distributed system by 15th Embodiment of this invention.</figref><figref num="49">It is a sequence chart which shows the operation of the client-server type distributed system by 15th Embodiment of this invention.</figref><figref num="50">It is a sequence chart which shows the operation of the client-server type distributed system by the 16th Example of this invention.</figref><figref num="51">It is a sequence chart which shows the operation of the client-server type distributed system by the 16th Example of this invention.</figref><figref num="52">It is a sequence chart which shows the operation of the client-server type distributed system by the 16th Example of this invention.</figref><figref num="53">It is a sequence chart which shows the operation of the client-server type distributed system by the 16th Example of this invention.</figref><figref num="54">It is a sequence chart which shows the operation of the client-server type distributed system by the 16th Example of this invention.</figref><figref num="55">It is a sequence chart which shows the operation of the client-server type distributed system by 17th Embodiment of this invention.</figref><figref num="56">It is a sequence chart which shows the operation of the client-server type distributed system by 17th Embodiment of this invention.</figref><figref num="57">It is a sequence chart which shows the operation of the client-server type distributed system by 17th Embodiment of this invention.</figref><figref num="58">It is a sequence chart which shows the operation of the client-server type distributed system by 17th Embodiment of this invention.</figref><figref num="59">It is a sequence chart which shows the operation of the client-server type distributed system by 17th Embodiment of this invention.</figref><figref num="60">It is a sequence chart which shows the operation of the client-server type distributed system by 17th Embodiment of this invention.</figref><figref num="61">It is a block diagram which shows the structure of the client-server type distributed system by 18th Embodiment of this invention.</figref><figref num="62">It is a sequence chart which shows the operation of the client-server type distributed system by 18th Embodiment of this invention.</figref><figref num="63">It is a sequence chart which shows the operation of the client-server type distributed system by 18th Embodiment of this invention.</figref><figref num="64">It is a block diagram which shows the structure of the server apparatus by 19th Embodiment of this invention.</figref><figref num="65">It is a sequence chart which shows the operation of the server apparatus by 19th Embodiment of this invention.</figref><figref num="66">It is a block diagram which shows the structure of the client-server type distributed system by 20th Embodiment of this invention.</figref><figref num="67">It is a sequence chart which shows the operation of the client-server type distributed system by 20th Embodiment of this invention.</figref><figref num="68">It is a figure which shows the configuration example of the encryption information table of FIG.</figref><figref num="69">It is a block diagram which shows the structure of the client-server type distributed system by 21st Embodiment of this invention.</figref><figref num="70">It is a sequence chart which shows the operation of the client-server type distributed system by 21st Embodiment of this invention.</figref><figref num="71">It is a sequence chart which shows the operation of the client-server type distributed system by 21st Embodiment of this invention.</figref><figref num="72">It is a block diagram which shows the structure of the client-server type distributed system by 22nd Embodiment of this invention.</figref><figref num="73">It is a sequence chart which shows the operation of the client-server type distributed system by 22nd Embodiment of this invention.</figref><figref num="74">It is a sequence chart which shows the operation of the client-server type distributed system by 22nd Embodiment of this invention.</figref><figref num="75">It is a block diagram which shows the structure of the client-server type distributed system by 23rd Example of this invention.</figref><figref num="76">It is a sequence chart which shows the operation of the client-server type distributed system by 23rd Example of this invention.</figref><figref num="77">It is a sequence chart which shows the operation of the client-server type distributed system by 23rd Example of this invention.</figref><figref num="78">It is a sequence chart which shows the operation of the client-server type distributed system by 24th Embodiment of this invention.</figref>
Code description
1.1a ~ 1g SIP protocol compatible server device 2 Local maintenance console 3-1 ~ 3-3, 3a-1 ~ 3a-3, 3b-n ~ 3b-n + 2, 3c-1,3c-2, 3d-1 ~ 3d-4 SIP protocol compatible client device 4 Maintenance console 11,31 Cryptographic information setting section 12 Cryptographic information input interface 13,33, 33-1 ~ 33-4 SIP interface section 14,34 SIP message composer 15,35 SIP Message Analysis Department 16,36 SIP message encryption / decryption unit 17,37 Call control unit 18,38 Encryption key creation department 19 Cryptographic information update timer control unit 20 Cryptographic information table 21,41 Cryptographic Capacity Management Department 100 LAN
78 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office |
|---|---|---|
| JP2005160005A | Cites | Japan |
| JP2005072636A | Cites | Japan |
| JP2004192134A | Cites | Japan |
| JP2000324104A | Cites | Japan |
| JP200835235A | Cites | Japan |
| J. Rosenberg et al.,SIP: Session Initiation Protocol,RFC 3261,2002年,URL,http://www.faqs.org/ftp/rfc/pdf/rfc3261.txt.pdf | Non-patent | – |
| Alfred J. Menezes, Paul C. van Oorschot, Scott A. Vanstone,Handbook of Applied Cryptography,CRC Press,1996年,pp. 497-499 | Non-patent | – |
| Mohan Krishna Ranganathan, Liam Kilmartin,Performance analysis of secure session initiation protocol based VoIP networks ,Computer Communications,2003年,Vol. 26, No. 6,pp. 552-565 | Non-patent | – |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2006206687 | Japan | A | |
| JP20060206687 | – | – | – |
18 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 4299846
- Publication, DOCDB
- 4299846
- Publication, EPODOC
- JP4299846B
- Application
- 206687
- Application, DOCDB
- 2006206687
- Application, EPODOC
- JP20060206687
Titles2
- Japanese
- クライアント・サーバ型分散システム、クライアント装置、サーバ装置及びそれらに用いるメッセージ暗号方法
- English
- Client-server distributed system, client device, server device and message encryption method used for them
Classification
- CPC, 5
- H04L9/0838
- H04L63/0428
- H04L9/0891
- H04L65/1104
- H04L65/1101
- IPC, 2
- H04L9 14
- H04L12 22
