Information processing system, information processing apparatus and method, program, and recording medium
19 claims: 11 independent, 8 dependent
- 1認証機関により発行された公開鍵を表す第1の発光パターンで発光する発光部と、 前記認証機関から認証を受けたことを表すシンボルマーク、前記認証機関から認証を受けた認証日、及び前記認証の有効期限を提示する提示部と、 前記公開鍵で暗号化された暗号鍵を受信する受信部と を含む受信装置。
- 2前記公開鍵に対応する秘密鍵を用いて、暗号化された前記暗号鍵を復号する復号部を さらに含む請求項1に記載の受信装置。
- 3前記受信部が受信する、前記公開鍵で暗号化された前記暗号鍵は、前記発光部による前記第1の発光パターンから前記公開鍵を読取り、読取った前記公開鍵で前記暗号鍵を暗号化する送信装置から送信されたものである 請求項2に記載の受信装置。
- 4前記発光部は、さらに、前記受信装置にアクセスするためのアドレス値を表す第2の発光パターンで発光する 請求項3に記載の受信装置。
- 5前記発光部は、前記受信装置により提供される情報に関係する物体を照明する照明器具とされる 請求項4に記載の受信装置。
- 6前記発光部に電力を供給する電力線を介して、前記発光部を制御する発光制御部を さらに含む請求項5に記載の受信装置。
- 7前記受信部は、前記送信装置から近距離通信により送信される、暗号化された前記暗号鍵を受信する 請求項3乃至6に記載の受信装置。
- 8前記発光部は、可視光または赤外光を発生するLED(Light Emitting Diode)である 請求項1乃至6に記載の受信装置。
- 9発光部と、提示部と、受信部とを有する受信装置の受信方法において、 前記発光部が、認証機関により発行された公開鍵を表す第1の発光パターンで発光し、 前記提示部が、前記認証機関から認証を受けたことを表すシンボルマーク、前記認証機関から認証を受けた認証日、及び前記認証の有効期限を提示し、 前記受信部が、前記公開鍵で暗号化された暗号鍵を受信する ステップを含む受信方法。
- 10発光部と、提示部と、受信部とを有する受信装置の前記発光部に、認証機関により発行された公開鍵を表す第1の発光パターンで発光させ、 前記受信装置の前記提示部に、前記認証機関から認証を受けたことを表すシンボルマーク、前記認証機関から認証を受けた認証日、及び前記認証の有効期限を提示させ、 前記受信装置の前記受信部に、前記公開鍵で暗号化された暗号鍵を受信させる ステップを含む処理を実行させるためのプログラム。
- 11請求項10に記載のプログラムが記録されている記録媒体。
- 12認証機関により発行された公開鍵を表す第1の発光パターンで発光する発光部の撮像を行う撮像部と、 前記撮像部の撮像により得られた撮像画像を分析して得られる前記第1の発光パターンから、前記公開鍵を読取る読取部と、 アクセスポイントとの間で情報を授受するための共通鍵として用いられる暗号鍵を、読取られた前記公開鍵で暗号化する暗号化部と、 暗号化された前記暗号鍵を、前記アクセスポイントに送信する送信部と を含 み、 前記撮像部は、前記アクセスポイントにアクセスするためのアドレス値を表す第2の発光パターンでも発光する前記発光部の撮像を行い、 前記読取部は、前記撮像部の撮像により得られた撮像画像を分析して得られる前記第2の発光パターンから、前記アドレス値も読取る 送信装置。
- 13読取られた前記アドレス値に対応するアイコンを、前記撮像画像とともに表示させる表示制御部をさらに含み、 前記撮像部は、ユーザの選択操作により、前記アイコンが選択されたことに対応して前記第1の発光パターンで発光する前記発光部の撮像を行う 請求項 12 に記載の送信装置。
- 14前記暗号鍵を前記共通鍵として用いることにより、前記アクセスポイントとの間で情報を授受する授受部を さらに含む請求項12 又は13 に記載の送信装置。
- 15撮像部と、読取部と、暗号化部と、送信部とを有する送信装置の送信方法において、 前記撮像部が、認証機関により発行された公開鍵を表す第1の発光パターンで発光する発光部の撮像を行い、 前記読取部が、前記撮像部の撮像により得られた撮像画像を分析して得られる前記第1の発光パターンから、前記公開鍵を読取り、 前記暗号化部が、アクセスポイントとの間で情報を授受するための共通鍵として用いられる暗号鍵を、読取られた前記公開鍵で暗号化し、 前記送信部が、暗号化された前記暗号鍵を、前記アクセスポイントに送信する ステップを含 み、 前記撮像部は、前記アクセスポイントにアクセスするためのアドレス値を表す第2の発光パターンでも発光する前記発光部の撮像を行い、 前記読取部は、前記撮像部の撮像により得られた撮像画像を分析して得られる前記第2の発光パターンから、前記アドレス値も読取る 送信方法。
- 16撮像部と、読取部と、暗号化部と、送信部とを有する送信装置の前記撮像部に、認証機関により発行された公開鍵を表す第1の発光パターンで発光する発光部の撮像を行わせ、 前記送信装置の前記読取部に、前記撮像部の撮像により得られた撮像画像を分析して得られる前記第1の発光パターンから、前記公開鍵を読取らせ、 前記送信装置の前記暗号化部に、アクセスポイントとの間で情報を授受するための共通鍵として用いられる暗号鍵を、読取られた前記公開鍵で暗号化させ、 前記送信装置の前記送信部に、暗号化された前記暗号鍵を、前記アクセスポイントに送信させる ステップを含 み、 前記送信装置の前記撮像部に、前記アクセスポイントにアクセスするためのアドレス値を表す第2の発光パターンでも発光する前記発光部の撮像を行わせ、 前記送信装置の前記読取部に、前記撮像部の撮像により得られた撮像画像を分析して得られる前記第2の発光パターンから、前記アドレス値も読取らせる 処理を実行させるためのプログラム。
- 17請求項 16 に記載のプログラムが記録されている記録媒体。
- 18暗号鍵を送信する送信装置と、前記送信装置からの前記暗号鍵を受信する受信装置により構成される通信システムにおいて、 前記受信装置は、 認証機関により発行された公開鍵を表す第1の発光パターンで発光する発光部と、 前記認証機関から認証を受けたことを表すシンボルマーク、前記認証機関から認証を受けた認証日、及び前記認証の有効期限を提示する提示部と、 前記公開鍵で暗号化された暗号鍵を受信する受信部と を含み、 前記送信装置は、 前記発光部の撮像を行う撮像部と、 前記撮像部の撮像により得られた撮像画像を分析して得られる前記第1の発光パターンから、前記公開鍵を読取る読取部と、 前記受信装置との間で情報を授受するための共通鍵として用いられる暗号鍵を、読取られた前記公開鍵で暗号化する暗号化部と、 暗号化された前記暗号鍵を、前記受信装置に送信する送信部と を含む通信システム。
- 19暗号鍵を送信する送信装置と、前記送信装置からの前記暗号鍵を受信する受信装置により構成される通信システムの通信方法において、 前記受信装置は、発光部と、提示部と、受信部とを有し、 前記発光部が、認証機関により発行された公開鍵を表す第1の発光パターンで発光し、 前記提示部が、前記認証機関から認証を受けたことを表すシンボルマーク、前記認証機関から認証を受けた認証日、及び前記認証の有効期限を提示し、 前記受信部が、前記公開鍵で暗号化された暗号鍵を、前記送信装置から受信し、 前記送信装置は、撮像部と、読取部と、暗号化部と、送信部とを有し、 前記撮像部が、前記発光部の撮像を行い、 前記読取部が、前記撮像部の撮像により得られた撮像画像を分析して得られる前記第1の発光パターンから、前記公開鍵を読取り、 前記暗号化部が、前記受信装置との間で情報を授受するための共通鍵として用いられる暗号鍵を、読取られた前記公開鍵で暗号化し、 前記送信部が、暗号化された前記暗号鍵を、前記受信装置に送信する ステップを含む通信方法。
Independent claims19
94 paragraphs, as filed
The present invention<u style="single">, Receive</u>apparatus<u style="single">, Receive</u>Method,<u style="single">Transmitter, transmission method,</u>program<u style="single">、</u>recoding media<u style="single">, Communication system, and communication method</u>In particular, we have made it possible to exchange information quickly, freely, and more safely.<u style="single">Receive</u>apparatus<u style="single">, Receive</u>Method,<u style="single">Transmitter, transmission method,</u>program<u style="single">、</u>recoding media<u style="single">, Communication system, and communication method</u>Regarding.
Recently, many access points have been arranged so that users can access the Internet at any place. The user can connect to the Internet from an access point on the go. A method of authenticating using a password and a user ID at an access point has been proposed (for example, Non-Patent Document 1).
The operation of the access point that authenticates using a password and a user ID will be described with reference to FIG. In the system of FIG. 1, communication between the client 1 and the access point 2 is performed by wireless radio waves, and communication between the access point 2 and the authentication server 3 is performed by wired communication.
When each user accesses the Internet using an access point on the go, he / she completes user registration in advance and receives a password and a user ID. Then, in step S1, the client 1 sends a connection request to the access point 2.
When the access point 2 receives the connection request from the client 1 in step S21, the access point 2 forwards the connection request to the authentication server 3 in step S22. When the authentication server 3 receives this connection request in step S51, it determines whether or not a response can be made now, and in step S52, outputs a connection response corresponding to the determination result to the access point 2. Upon receiving this connection response in step S23, the access point 2 forwards it to client 1 in step S24. In step S2, client 1 receives the connection response.
Further, in step S53, the authentication server 3 transmits the public key and the certificate issued in advance by the authentication authority (not shown) to the access point 2. Upon receiving this public key and certificate in step S25, the access point 2 sends it to client 1 in step S26. The client 1 receives the public key and the certificate sent from the access point 2 in step S3.
The certificate is given plaintext data such as standard version, serial number, public key owner, and public key, as well as a digital signature based on these. Client 1 compares the content obtained by decrypting the digital signature with the public key with the already obtained standard version of plain text, serial number, public key owner, public key, etc. It can be verified that the key and its certificate were sent from a genuine authentication server, that is, from an administrator authenticated by a certificate authority. Therefore, the user can connect to the Internet via the authentication server with peace of mind.
In step S4, the client 1 generates an encryption key used as a common key for exchanging information with the authentication server 3, encrypts it with the public key received from the access point 2, and sends it to the access point 2. .. When the access point 2 receives the encryption key in step S27, it sends the encryption key to the authentication server 3 in step S28. In step S54, the authentication server 3 receives the encryption key, decrypts the encryption key with the private key corresponding to the public key, and uses the encryption key as the common key.
On the other hand, in step S5, the client 1 transmits the user ID with the encryption key, and further, in step S6, the password is encrypted with the encryption key and transmitted. The access point 2 receives the user ID in step S29 and the password in step S31. The access point 2 transmits the user ID to the authentication server 3 in step S30, and transmits the password to the authentication server 3 in step S32. The authentication server 3 receives the user ID in step S55 and the password in step S56. The authentication server 3 verifies the received user ID and password with the encryption key received in step S54 to confirm that the user ID and password belong to the already registered user.
If it can be confirmed from the user ID and password that the client 1 is a legitimate user, the client 1 in step S7 and the authentication server 3 in step S57 mutually perform the connection procedure via the access point 2. Complete. Therefore, after that, the client 1 can connect to the Internet via the access point 2 and the authentication server 3 and access necessary information as appropriate.
Since the access points 2 are distributed in many places, users can connect to the Internet from outside via the access points 2 and the authentication server 3 as needed, and receive various services from there. It becomes possible.<nplcit num="1"><text>"802.11 High-speed Wireless LAN Textbook" (pages 334, 335)</text></nplcit>
<p> However, in a conventional system, in order for a user to connect to the Internet using an access point, it is necessary to register in advance and receive an ID and password. Therefore, it is difficult for the provider to provide information promptly and freely, and it is difficult for the user to receive information promptly and freely.</p><p> Therefore, it is conceivable to omit the pre-registration and the use of the certificate. However, in that case, there is a risk of being victimized by wireless LAN phishing scams. That is, a person who intends to perform phishing sends an illegal radio wave within the service range of the access point, causes the client of the user who receives the illegal radio wave to display a fake web page, and the user displays the fake web page. There are cases where the virus is automatically downloaded no matter where you click.</p><p> The present invention has been made in view of such a situation, and makes it possible to exchange information quickly, freely, and safely.</p>
<p> First aspect of the present invention<u style="single">Receiver</u>Is<u style="single">A light emitting unit that emits light in the first light emitting pattern representing a public key issued by a certification body, a symbol mark indicating that certification has been obtained from the certification body, a certification date that has been certified by the certification body, and the certification. A receiving device including a presenting unit that presents the expiration date of the above and a receiving unit that receives the authentication key encrypted with the public key.</u>Is.</p><p><u style="single">Encryption using the private key corresponding to the public key</u>Said<u style="single">Cryptography</u>Decrypt the key<u style="single">Su</u>Decryption<u style="single">To provide more parts</u>Can be done.</p><p><u style="single"> The public key encrypted by the public key received by the receiving unit reads the public key from the first light emitting pattern by the light emitting unit, and encrypts the encryption key with the read public key. It can be as if it was transmitted from a transmitter.</u></p><p> Said<u style="single">Light emitting part</u>Is<u style="single">Further, for accessing the receiving device</u>Address value<u style="single">It can emit light with the second emission pattern represented.</u></p><p><u style="single"> The light emitting unit can be a luminaire that illuminates an object related to the information provided by the receiving device.</u></p><p><u style="single"> A light emitting control unit that controls the light emitting unit may be further provided via a power line that supplies power to the light emitting unit.</u></p><p><u style="single"> The receiving unit can receive the encrypted encryption key transmitted from the transmitting device by short-range communication.</u></p><p><u style="single"> The light emitting unit may be an LED (Light Emitting Diode) that generates visible light or infrared light.</u></p><p><u style="single"> The receiving method of the first aspect of the present invention is a receiving method of a receiving device having a light emitting unit, a presenting unit, and a receiving unit, and the light emitting unit represents a public key issued by a certification body. It emits light in the light emission pattern of 1, and the presenting unit presents a symbol mark indicating that the certification has been obtained from the certification body, the certification date of certification from the certification body, and the expiration date of the certification, and receives the above. The unit is a receiving method including a step of receiving an authentication key encrypted with the public key.</u><u style="single"> The program of the first aspect of the present invention and the program recorded on the recording medium are public keys issued by a certification body to the light emitting unit of a receiving device having a light emitting unit, a presenting unit, and a receiving unit. The first light emitting pattern representing the above is emitted, and the presenting portion of the receiving device is marked with a symbol mark indicating that the certification body has been certified, the certification date obtained from the certification body, and the validity of the certification. It is a program for presenting a deadline and causing the receiving unit of the receiving device to execute a process including a step of receiving an authentication key encrypted with the public key.</u></p><p> First aspect of the present invention<u style="single">According to the above, a symbol mark indicating that the public key issued by the certification body is emitted by the first light emission pattern and has been certified by the certification body, the certification date obtained by the certification body, and the above. The expiration date of the authentication is presented, and the encryption key encrypted with the public key is received.</u></p><p> The transmitter of the second aspect of the present invention includes an imaging unit that captures an image of a light emitting unit that emits light with a first emission pattern representing a public key issued by a certification body, and an imaging unit obtained by imaging the imaging unit. From the first light emission pattern obtained by analyzing an image, the public key used as a common key for exchanging information between the reading unit that reads the public key and the access point is read. Includes an encryption unit that encrypts with a key and a transmission unit that transmits the encrypted encryption key to the access point.<u style="single">Then, the imaging unit captures an image of the light emitting unit that emits light even in a second light emitting pattern representing an address value for accessing the access point, and the reading unit captures an image obtained by imaging the imaging unit. The address value is also read from the second light emission pattern obtained by analyzing the image.</u>It is a transmitter.</p><p><u style="single"> A display control unit that displays the icon corresponding to the read address value together with the captured image can be further provided, and the imaging unit responds to the selection of the icon by the user's selection operation. It is possible to take an image of the light emitting unit that emits light in the first light emission pattern.</u></p><p><u style="single"> By using the encryption key as the common key, it is possible to further provide an exchange unit for exchanging information with the access point.</u></p><p> The transmission method of the second aspect of the present invention is a transmission method of a transmission device having an imaging unit, a reading unit, an encryption unit, and a transmitting unit, and the imaging unit is issued by a certification body. The light emitting unit that emits light with the first light emitting pattern representing the public key is imaged, and the reading unit analyzes the captured image obtained by the imaging of the imaging unit to obtain the first light emitting pattern. The public key is read, and the encryption unit encrypts the encryption key used as a common key for exchanging information with and from the access point with the read public key, and the transmission unit is encrypted. Including the step of transmitting the encryption key to the access point.<u style="single">Then, the imaging unit captures an image of the light emitting unit that emits light even in a second light emitting pattern representing an address value for accessing the access point, and the reading unit captures an image obtained by imaging the imaging unit. The address value is also read from the second light emission pattern obtained by analyzing the image.</u>It is a transmission method. The program of the second aspect of the present invention and the program recorded on the recording medium are subjected to the imaging unit of the transmission device having an imaging unit, a reading unit, an encryption unit, and a transmitting unit by a certification body. The light emitting unit that emits light with the first light emitting pattern representing the issued public key is imaged, and the reading unit of the transmitting device analyzes the captured image obtained by the imaging of the imaging unit. From the first light emission pattern, the public key is read, and the encryption unit of the transmission device reads the encryption key used as a common key for exchanging information with the access point. A step of encrypting with a public key and causing the transmitting unit of the transmitting device to transmit the encrypted encryption key to the access point is included.<u style="single">Then, the imaging unit of the transmitting device is made to image the light emitting unit that emits light even in the second light emitting pattern representing the address value for accessing the access point, and the reading unit of the transmitting device is made to perform the image. The address value is also read from the second light emission pattern obtained by analyzing the captured image obtained by the imaging of the imaging unit.</u>It is a program for executing processing.</p><p> According to the second aspect of the present invention, the light emitting portion that emits light with the first light emitting pattern representing the public key issued by the certification body is imaged, and the captured image obtained by the imaging is analyzed. From the first light emission pattern, the public key is read, and the encryption key used as a common key for exchanging information with and from the access point is encrypted and encrypted with the read public key. The encryption key is transmitted to the access point.<u style="single">In the imaging of the light emitting unit, the light emitting unit that emits light even in the second light emitting pattern representing the address value for accessing the access point is imaged. In addition, the address value is also read from the second light emission pattern obtained by analyzing the captured image obtained by the imaging of the imaging unit.</u> The communication system of the third aspect of the present invention is a communication system including a transmitting device that transmits a cryptographic key and a receiving device that receives the cryptographic key from the transmitting device, and the receiving device is authenticated. A light emitting unit that emits light in the first light emitting pattern representing a public key issued by the institution, a symbol mark indicating that the certification has been obtained from the certification body, a certification date that has been certified by the certification body, and the certification. The transmitting device includes an imaging unit that presents an expiration date and a receiving unit that receives an encryption key encrypted with the public key. From the first light emission pattern obtained by analyzing the obtained captured image, a cryptographic key used as a common key for exchanging information between the reading unit that reads the public key and the receiving device is used. It is a communication system including an encryption unit that encrypts with the read public key and a transmission unit that transmits the encrypted encryption key to the receiving device. The communication method of the third aspect of the present invention is a communication method of a communication system including a transmitting device for transmitting an encryption key and a receiving device for receiving the encryption key from the transmitting device, and the receiving device. Has a light emitting unit, a presenting unit, and a receiving unit, the light emitting unit emits light in a first light emitting pattern representing a public key issued by a certification body, and the presenting unit emits light from the certification body. The symbol mark indicating that the certification has been obtained, the certification date of the certification from the certification body, and the expiration date of the certification are presented, and the receiving unit transmits the encryption key encrypted with the public key. The transmitting device includes an imaging unit, a reading unit, an encryption unit, and a transmitting unit, including a receiving unit that receives from the device, and the imaging unit captures an image of the light emitting unit and reads the image. The unit reads the public key from the first light emission pattern obtained by analyzing the captured image obtained by the imaging of the imaging unit, and the encryption unit exchanges information with the receiving device. This is a communication method including a step of encrypting an authentication key used as a common key for performing the cryptography with the read public key, and having the transmitting unit transmit the encrypted encryption key to the receiving device. In the third aspect of the present invention, in the receiving device, the light is emitted in the first light emitting pattern representing the public key issued by the certification body, and the symbol mark indicating that the certification has been obtained from the certification body, the certification. The authentication date obtained from the institution and the expiration date of the authentication are presented, and the encryption key encrypted with the public key is received from the transmission device. In addition, the public key is read from the first light emission pattern obtained by performing imaging in the transmitting device and analyzing the captured image obtained by the imaging, and information is exchanged with the receiving device. The encryption key used as the common key for the purpose is encrypted with the read public key, and the encrypted encryption key is transmitted to the receiving device.</p>
<p> As mentioned above, this<u style="single">Ming</u>According to, information can be exchanged. Especially from the main<u style="single">Ming</u>According to this, information can be exchanged quickly, freely, and more safely.</p>
Embodiments of the present invention will be described below, and the correspondence between the constituent requirements of the present invention and the embodiments described in the detailed description of the invention will be illustrated as follows. This description is for confirming that the embodiments supporting the present invention are described in the detailed description of the invention. Therefore, even if there is an embodiment that is described in the detailed description of the invention but is not described here as an embodiment corresponding to the constituent elements of the present invention, that is the case. It does not mean that the embodiment does not correspond to the constituent requirements. On the contrary, even if the embodiment is described here as corresponding to the constituent requirements, it means that the embodiment does not correspond to the constituent requirements other than the constituent requirements. It's not something to do.
<u style="single"> The first aspect of the present invention is a light emitting unit (for example, LED 32 in FIG. 2) that emits light in a first light emitting pattern representing a public key (for example, the public key K1 in FIG. 2) issued by a certification body, and the above. The symbol mark indicating that the certification has been obtained from the certification body (for example, Certification shown in FIG. 15), the certification date obtained from the certification body (for example, the certification date shown in FIG. 15: 2005.6.28), and Receives the presentation unit (for example, the bulletin board 171 in FIG. 15) that presents the expiration date of the authentication (for example, the expiration date shown in FIG. 15: 2006.6.27) and the encryption key encrypted with the public key. It is a receiving device (for example, the connection service device 13 of FIG. 2) including a receiving unit (for example, the communication unit 71 of FIG. 4).</u>
<u style="single"> A decryption unit that decrypts the encrypted encryption key using the private key corresponding to the public key (for example, the decryption unit 144 of FIG. 8 that executes step S78 of FIG. 12 and step S178 of FIG. 20) Further can be provided.</u>
<u style="single"> The public key encrypted by the public key received by the receiving unit reads the public key from the first light emitting pattern by the light emitting unit, and encrypts the encryption key with the read public key. It was transmitted from a transmitting device (for example, client 12 in FIG. 2).</u>
<u style="single"> The light emitting unit can further emit light in a second light emitting pattern representing an address value for accessing the receiving device (for example, step S42 in FIG. 11 and step S141 in FIG. 19).</u>
<u style="single"> The light emitting unit can be a luminaire (eg, luminaire 202, 203 of FIG. 16) that illuminates an object (eg, poster 204, 205 of FIG. 16) related to information provided by the receiver.</u>
<u style="single"> A light emitting control unit that controls the light emitting unit can be further provided via a power line that supplies power to the light emitting unit (for example, the power line 201 in FIG. 16).</u>
<u style="single"> The receiving unit can receive the encrypted encryption key transmitted from the transmitting device by short-range communication (for example, step S47 in FIG. 11 and step S148 in FIG. 19).</u>
<u style="single"> The light emitting unit may be an LED (Light Emitting Diode) (for example, LED 32 in FIG. 2) that generates visible light or infrared light.</u>
<u style="single"> Further, the receiving method of the first aspect of the present invention includes a light emitting unit (for example, LED32 in FIG. 2), a presenting unit (for example, a bulletin board unit 171 in FIG. 15), and a receiving unit (for example, a communication unit in FIG. 4). 71) is a receiving method of a receiving device (for example, the connection service device 13 of FIG. 2), wherein the light emitting unit represents a public key issued by an authentication authority (for example, the public key K1 of FIG. 2). It emits light in the first light emission pattern (for example, step S42 in FIG. 11 and step S147 in FIG. 19), and is shown by a symbol mark (for example, FIG. 15) indicating that the presenting unit has been certified by the certification body. Certification), the certification date certified by the certification body (eg, the certification date shown in FIG. 15: 2005.6.28), and the expiration date of the certification (eg, the expiration date shown in FIG. 15: 2006.6.27). Is presented, and the receiving unit receives the authentication key encrypted with the public key (for example, step S47 in FIG. 11 and step S146 in FIG. 19).</u><u style="single"> Further, the program of the first aspect of the present invention and the program recorded on the recording medium include a light emitting unit (for example, LED32 in FIG. 2), a presenting unit (for example, a bulletin board unit 171 in FIG. 15), and receiving. The light emitting unit of the receiving device (for example, the connection service device 13 of FIG. 2) having the unit (for example, the communication unit 71 of FIG. 4) emits light with the first light emitting pattern representing the public key issued by the certification authority. (For example, step S42 in FIG. 11 and step S147 in FIG. 19), the presenting portion of the receiving device is marked with a symbol mark (for example, Certification shown in FIG. 15) indicating that the certification body has been certified. Have the certification body present the certification date (for example, the certification date shown in FIG. 15: 2005.6.28) and the expiration date of the certification (for example, the expiration date shown in FIG. 15: 2006.6.27). , A program for causing the receiving unit of the receiving device to execute a process including a step of receiving an authentication key encrypted with the public key (for example, step S47 in FIG. 11 and step S146 in FIG. 19). ..</u>
The transmitter of the second aspect of the present invention (for example, the client 12 in FIG. 2) is an imaging unit (for example, an imaging unit that images a light emitting unit that emits light with a first light emitting pattern representing a public key issued by a certification authority). From the imaging unit 101) of FIG. 6 that executes step S11 of FIG. 10 and step S108 of FIG. 18 and the first light emission pattern obtained by analyzing the image captured by the imaging of the imaging unit, the publication An encryption key used as a common key for exchanging information between a reader that reads a key (for example, a reader 102 of FIG. 6 that executes step S12 of FIG. 10 and step S108 of FIG. 18) and an access point. The encrypted unit that encrypts the read public key with the public key (for example, the transmitter 107 of FIG. 6 that executes step S19 of FIG. 10 and step S110 of FIG. 18) and the encrypted encryption key. Including a transmitter for transmitting to the access point (for example, a transmitter 107 in FIG. 6 for executing step S19 in FIG. 10 and step S110 in FIG. 18).<u style="single">The image pickup unit captures an image of the light emitting unit that emits light even in a second light emission pattern representing an address value for accessing the access point, and the reading unit captures an image obtained by imaging the image pickup unit. The address value is also read from the second light emission pattern obtained by analyzing the image (for example, the reading unit 102 of FIG. 6 for executing step S12 of FIG. 10 and step S102 of FIG. 18).</u>It is a transmitter.
<u style="single"> A display control unit for displaying the icon corresponding to the read address value (for example, the icon 23 in FIG. 2) together with the captured image can be further provided, and the imaging unit can be operated by the user's selection operation to display the icon. Corresponding to the selection of, the light emitting portion that emits light in the first light emitting pattern can be imaged.</u>
<u style="single"> An exchange processing unit 108 that executes information in and from the access point by using the encryption key as the common key (for example, step S20 in FIG. 10 and step S111 in FIG. 18). Can be further provided.</u>
Further, the transmission method of the second aspect of the present invention includes an imaging unit (for example, the imaging unit 101 in FIG. 6), a reading unit (for example, the reading unit 102 in FIG. 6), and an encryption unit (for example, FIG. 6). A transmission method of a transmission device having a transmission unit 107) and a transmission unit (for example, the transmission unit 107 in FIG. 6), wherein the imaging unit represents a public key issued by a certification body. An image of a light emitting unit that emits light in a pattern is performed (for example, step S11 in FIG. 10 and step S108 in FIG. 18), and the reading unit analyzes the captured image obtained by imaging the imaging unit. The public key is read from the light emission pattern of 1 (for example, step S12 in FIG. 10 and step S108 in FIG. 18), and the encryption unit is used as a common key for exchanging information with and from the access point. The encryption key is encrypted with the read public key (for example, step S19 in FIG. 10 and step S110 in FIG. 18), and the transmitter transmits the encrypted encryption key to the access point (for example, step S19 in FIG. 10 and step S110 in FIG. 18). For example, step S19 in FIG. 10 and step S110 in FIG. 18) are included.<u style="single">Then, the imaging unit captures an image of the light emitting unit that emits light even in a second light emitting pattern representing an address value for accessing the access point, and the reading unit captures an image obtained by imaging the imaging unit. The address value is also read from the second emission pattern obtained by analyzing the image (for example, step S12 in FIG. 10 and step S102 in FIG. 18).</u>It is a transmission method. Further, the program of the second aspect of the present invention and the program recorded on the recording medium include an imaging unit (for example, the imaging unit 101 of FIG. 6) and a reading unit (for example, the reading unit 102 of FIG. 6). , A public key issued by a certification body to the imaging unit of a transmitter having an encryption unit (for example, transmission unit 107 in FIG. 6) and a transmission unit (for example, transmission unit 107 in FIG. 6). An image of the light emitting unit that emits light with the light emission pattern of 1 is performed (for example, step S11 in FIG. 10 and step S108 in FIG. The public key is read from the first light emission pattern obtained by analyzing the above (for example, step S12 in FIG. 10 and step S108 in FIG. 18), and the encryption unit of the transmission device is subjected to an access point. The encryption key used as a common key for exchanging information between the two is encrypted with the read public key (for example, step S19 in FIG. 10 and step S110 in FIG. 18), and the transmission of the transmission device. The unit includes a step of transmitting the encrypted encryption key to the access point (for example, step S19 in FIG. 10 and step S110 in FIG. 18).<u style="single">Then, the imaging unit of the transmitting device is made to image the light emitting unit that emits light even in the second light emitting pattern representing the address value for accessing the access point, and the reading unit of the transmitting device is made to perform the image. The address value is also read from the second light emission pattern obtained by analyzing the captured image obtained by the imaging of the imaging unit (for example, step S12 in FIG. 10 and step S102 in FIG. 18).</u>It is a program for executing processing. The communication system of the third aspect of the present invention is a connection between a transmitting device that transmits a cryptographic key (for example, the client 12 in FIG. 2) and a receiving device that receives the cryptographic key from the transmitting device (for example, FIG. 2). A communication system composed of a service device 13), wherein the receiving device emits light in a first light emitting pattern representing a public key issued by a certification body (for example, the public key K1 in FIG. 2). For example, LED32 in FIG. 2), a symbol mark indicating that the certification body has been certified (for example, Certification shown in FIG. 15), and a certification date obtained from the certification body (for example, FIG. 15). Certification date: 2005.6.28), a presentation unit (for example, posting unit 171 in FIG. 15) that presents the expiration date of the certification (for example, the expiration date shown in FIG. 15: 2006.6.27), and the public key. Including a receiving unit (for example, the communication unit 71 in FIG. 4) that receives the encryption key encrypted in the above, the transmitting device includes an imaging unit (for example, the imaging unit 101 in FIG. 6) that images the light emitting unit. And the reading unit (for example, the reading unit 102 in FIG. 6) that reads the public key from the first light emission pattern obtained by analyzing the captured image obtained by the imaging of the imaging unit, and the receiving device. An encryption unit (for example, transmission unit 107 in FIG. 6) that encrypts an encryption key used as a common key for exchanging information between the two with the read public key, and the encrypted encryption key. Is a communication system including a transmission unit (for example, transmission unit 107 in FIG. 6) that transmits the above to the receiving device. The communication method of the third aspect of the present invention is a connection between a transmitting device that transmits an authentication key (for example, the client 12 in FIG. 2) and a receiving device that receives the encryption key from the transmitting device (for example, FIG. 2). A communication method for a communication system composed of a service device 13), wherein the receiving device has a light emitting unit, a presenting unit, and a receiving unit, and the light emitting unit is a public key issued by a certification body. (For example, step S42 in FIG. 11 and step S147 in FIG. 19), the presenting unit is a symbol mark indicating that the certification body has been certified by the certification body, and certification is performed by the certification body. Presenting the received authentication date and the expiration date of the authentication, the receiving unit receives the encryption key encrypted with the public key from the transmitting device (for example, step S47 in FIG. 11, FIG. 19). Step S146), the transmitting device includes an imaging unit, a reading unit, an encryption unit, and a transmitting unit, and the imaging unit captures an image of the light emitting unit (for example, step S11 in FIG. 10). , FIG. 18 step S108), the reading unit reads the public key from the first light emitting pattern obtained by analyzing the captured image obtained by the imaging of the imaging unit (for example, the step of FIG. 10). S12, step S108 in FIG. 18, the encryption unit encrypts the encryption key used as a common key for exchanging information with the receiving device with the read public key (for example, FIG. 10 step S19, FIG. 18 step S110), the transmitter transmits the encrypted encryption key to the receiver (for example, step S19 of FIG. 10, step S110 of FIG. 18). It is a communication method.
Hereinafter, embodiments of the present invention will be described with reference to the drawings.
FIG. 2 shows the configuration of an information providing system as an information processing system according to the embodiment of the present invention. This information providing system 1 is composed of the Internet 11, the client 12, the connection service device 13, and the servers 14 and 15. Although only one client 12 is shown in FIG. 2, a plurality of clients 12 are connected to one access point 31. In addition, any number of access points 31 are distributed in necessary locations.
The client 12, which is a PDA (Personal Digital Assistants), has an LCD (Liquid Crystal Display) 21. Necessary images are appropriately displayed on this LCD 21. The camera 22 of the client 12 takes an image of the subject and displays the image of the subject on the LCD 21.
The connection service device 13 is composed of an access point 31 and a server 34. The access point 31 has an LED (Light Emitting Diode) 32 that blinks light (visible light or infrared light) to transmit an optical signal, and an antenna 33 that is used for wireless short-range communication. There is. The access point 31 and the server 34 are connected to each other by wire or wirelessly. Server 34 is also connected to Internet 11. Servers 14, 15 and the like that provide various types of information are connected to the Internet 11.
For short-range communication between the client 12 and the access point 31, for example, IEEE (Institute of Electrical and Electronic Engineers) 802.11b / a / g, UWB (Ultra Wide Band), Bluetooth (registered trademark), ZigBee, etc. It is possible to use. The short-range communication here refers to communication at a distance that can receive and decode a signal due to a change in light. Specifically, it refers to wireless communication at a distance of several meters to several tens of meters.
The detailed operation will be described later with reference to FIGS. 9 and 11, but the LED 32 of the access point 31 transmits the address of the access point 31 and the public key K1 by blinking the light. This public key K1 is issued to the administrator of the connection service device 13 together with the corresponding private key by a predetermined authentication authority, or is independently created by the access point operator. The client 12 captures an image of the access point 31 with the camera 22 and displays the image on the LCD 21. The user selects the access point by instructing the icon 23 indicating the existence of the access point issuing the public key K1 displayed in the displayed image. When the client 12 extracts the public key K1 from the received image, the client 12 encrypts the encryption key K2 generated by itself with the public key K1 and transmits the encryption key K2 to the access point 31 by radio waves (short-range communication).
The access point 31 transfers the encryption key K2 encrypted with the public key K1 to the server 34. As a result, the server 34 can share the encryption key K2 with the client 12 as a shared key, and can be used when exchanging information with each other.
FIG. 3 shows the configuration of the client 12. The image pickup unit 51 corresponds to the camera 22, captures a subject, and outputs a corresponding image signal. The image processing unit 52 processes the image signal output from the image pickup unit 51, outputs the image signal to the display unit 53, and displays the image signal. The display unit 53 corresponds to the LCD 21.
The control unit 55 is composed of, for example, a microcomputer or the like, and controls the operation of the image pickup unit 51, the image processing unit 52, the display unit 53, and the like. The input unit 54 is composed of a switch, various buttons, and the like, and when operated by the user, outputs a signal corresponding to the operation to the control unit 55. The communication unit 56 communicates with the access point 31 by radio waves.
The removable media 57 is appropriately attached to the client 12 and supplies necessary programs and data to the control unit 55.
FIG. 4 shows the configuration of the access point 31. The light emitting unit 73 corresponds to the LED 32, is controlled by the control unit 72, and outputs a signal by changing the light level (for example, outputs a blinking signal of light). The communication unit 71 wirelessly communicates with the client 12 via the antenna 33. The communication unit 71 also communicates with the server 34. The storage unit 74 stores the address to be transmitted to the client 12 and the public key K1.
For example, the removable media 74 is appropriately connected to the control unit 72 configured by a microcomputer or the like. The removable media 75 stores programs and data necessary for the control unit 72 to operate.
FIG. 5 shows the configuration of the server 34. The communication unit 81 communicates with other devices via the access point 31 and the Internet 11. The storage unit 82 stores the public key and the like supplied to the access point 31. The display unit 83 displays necessary images and information. The control unit 85 composed of a microcomputer or the like controls the operation of each unit. The input unit 84 is composed of a keyboard, a mouse, and the like, and when operated by a user, supplies a signal corresponding to the operation to the control unit 85.
The removable media 86 is connected to the server 34 as needed, and supplies programs, data, and the like to the control unit 85 as appropriate.
The control unit 55 of the client 12 has a functional configuration as shown in FIG. Although not shown, each part can send and receive signals as needed. This also applies to FIGS. 7 and 8 described later.
The imaging unit 101 captures an image of the subject. The reading unit 102 reads the address value and the public key from the image obtained by imaging. The display unit 103 controls the display of an image on the display unit 53. The determination unit 104 performs various determination processes. The request unit 105 requests the access point to connect. The reading unit 106 executes a process of reading the encryption key. The transmission unit 107 executes a process of transmitting the encryption key encrypted with the public key to the access point 31. The transfer processing unit 108 executes a process of exchanging information between the access point 31 and the servers 14 and 15 via the server 34.
FIG. 7 shows the functional configuration of the control unit 72 of the access point 31. The receiving unit 121 receives the public key from the server 34. The transmitter 122 sends an address value and a public key, sends a connection request to the server 34, and sends a connection response to the client 12. Further, the transmission unit 122 transmits the encryption key to the server 34. The determination unit 123 executes various determination processes. The storage unit 124 stores the address value and the public key. The transfer processing unit 125 mediates the transfer of information between the client 12 and the server 34.
FIG. 8 shows the functional configuration of the control unit 85 of the server 34. The transmission unit 141 transmits the public key to the access point 31 and transmits the connection response to the access point 31. The receiving unit 142 receives the connection request from the access point 31. The determination unit 143 executes various determination processes. The decryption unit 144 executes a process of decrypting the encryption key with the private key. The transfer processing unit 145 executes a process of mediating the transfer of information between the access point 31 and the servers 14 and 15.
Next, referring to the flowcharts of FIGS. 9 to 12, the process when the client 12 connects to the server 34 via the access point 31 and receives the necessary information from the servers 14 and 15 via the Internet 11. Will be described. Note that FIG. 9 shows the overall operation of the client 12, the access point 31, and the server 34, FIG. 10 shows the operation of the client 12, FIG. 11 shows the operation of the access point 31, and FIG. 12 shows the operation of the server 34. Represents.
In step S71, the transmitter 141 of the server 34 transmits the public key to the access point. Specifically, the communication unit 81 reads the public key stored in the storage unit 82 and transmits it to the access point 31.
In step S41, the receiving unit 121 of the access point 31 receives the public key. Then, in step S42, the transmission unit 141 transmits the public key received in step S41 to the client 12 together with the address value.
Specifically, the control unit 72 of the access point 31 has a public key transmitted from the server 34 received by the communication unit 71 and a pre-stored address value read from the storage unit 74 (to the access point 31). The address value for access) is transmitted (broadcast) as a blinking signal of light by controlling the light emitting unit 73.
The transmitted signal is Manchester-encoded as shown in FIG. In this Manchester coding, the rising edge (transition from the state where the LED 32 is off to the state where it is on) is set to 0, and the falling edge (the state where the LED 32 is on is off) is set to 0. Transition) is 1. As a result, as shown in FIG. 14, for example, a code string of data such as "010011" is transmitted as a blinking signal of light (of course, it is necessary that light is not completely generated even if it is turned off. Instead, the level of light may vary between higher and lower levels, i.e. change the light to the extent that it can be detected by the receiver).
In this way, the access point 31 constantly broadcasts its own address value and public key by blinking the LED 32 (light, thus publicly distributing the address value and public key).
Then, the user points the camera 22 of the client 12 toward the access point 31 that wants to access, and operates the input unit 54 to instruct the image of the access point 31 that wants to access. At this time, in step S11, the imaging unit 101 executes an imaging process. Specifically, the access point 31 is imaged by the image capturing unit 51, the image signal is processed by the image processing unit 52, and then output to the display unit 53 (LCD21) for display.
Since the light has straightness, only the access point 31 in the directed direction is imaged by the camera 22, and even if there is an access point in the direction in which the camera 22 is not directed, the access point is not imaged. Therefore, the user receives light from an unintended access point and is prevented from being victimized by phishing scams.
When the access point operator uses a public key issued by a predetermined certificate authority, for example, as shown in FIG. 15, the access point 31 has a predetermined authentication on the bulletin board 171 of the access point 31. The symbol mark 172 is posted as information indicating that the certification has been obtained from the institution (in the example of FIG. 15, the characters "Certification" are displayed). In addition, the certification date "June 28, 2005" and the expiration date "June 27, 2006" are posted on this bulletin board 171 together with the symbol mark 172. Therefore, the user can confirm that the access point 31 is a properly authenticated genuine access point by confirming the symbol mark 172, the authentication date, and the expiration date from the displayed image. .. From this as well, safety can be ensured.
In step S12, the reading unit 102 reads (extracts) the address value and the public key from the blinking signal by analyzing the image captured by the imaging unit 101 (by decoding the blinking signal (Manchester code)). .. Then, in step S13, the display unit 103 causes the LCD 21 to display an icon as a symbol corresponding to the (extracted) address value read in the process of step S12. As a result, as shown in FIG. 2, for example, the corresponding address address1 is displayed on the LCD 21 as an icon 23 in the vicinity of the image 31A of the access point 31.
From this address (icon), the user reconfirms whether the access point is the access point desired to access, and specifies the confirmed icon with a finger or the like to specify the access point to be accessed. Therefore, in step S14, the determination unit 104 determines whether the icon has been selected by the user. If the icon is not selected, in step S15, the determination unit 104 determines whether the end is instructed. If the user has not yet instructed the end, the process returns to step S11, and the subsequent processes are repeatedly executed. That is, the processes of steps S11 to S15 are repeatedly executed until the icon 23 is selected.
When the icon 23 is selected by the user, in step S16, the requesting unit 105 requests the access point to connect. That is, the communication unit 56 is controlled by the control unit 55, and wirelessly transmits a signal requesting connection to the access point 31 by short-range communication.
In step S43, the access point 31 determines whether the connection request has been received by the determination unit 123. If the connection request has not yet been received by the receiving unit 121, the process returns to step S41, and the subsequent processes are repeatedly executed.
If it is determined in step S43 that the connection request has been received by the receiving unit 121, the transmitting unit 122 transfers the connection request to the server in step S44. That is, the communication unit 71 of the access point 31 forwards the connection request received from the client 12 to the server 34.
In the server 34, the determination unit 143 determines whether the connection request has been received from the access point in step S72, and if not yet received, the process returns to step S71 until the connection request is received from the access point. The processes of steps S71 and S72 are repeatedly executed.
When it is determined that the connection request has been received from the access point 31, the determination unit 143 determines in step S73 whether or not it can respond. That is, it is determined whether the response is difficult because many clients are requesting access now. If a response is possible, in step S74, the transmitter 141 executes a process of transmitting an OK connection response to the access point 31. On the other hand, if it is determined in step S73 that the response is not possible, the transmission unit 141 executes a process of transmitting an NG connection response to the access point in step S75.
In step S45, the determination unit 123 of the access point 31 determines whether or not a connection response has been received from the server, and waits until the connection response is received. When the connection response is received from the server 34, in step S46, the transmission unit 122 transmits the connection response to the accessing client.
In step S17, the determination unit 104 of the client 12 determines whether or not there is a response from the access point, and waits until there is a response from the access point. Then, when there is a response from the access point 31, the reading unit 106 reads the encryption key in step S18. This encryption key may be one that has already been generated, or may be one that is generated by the reading unit 106 each time.
Next, in step S19, the transmission unit 107 executes a process of encrypting the encryption key read in step S18 with the public key and transmitting the encryption key. That is, the encryption key read in step S18 is encrypted by the public key read in step S12 and transmitted to the access point 31.
In step S47, the determination unit 123 of the access point 31 determines whether or not the encryption key has been received, and waits until the encryption key is received. When the encryption key is received, in step S48, the transmission unit 122 transmits the encryption key received in step S47 to the server 34.
The determination unit 143 of the server 34 determines in step S76 whether the encryption key has been received, and if the encryption key has not yet been received, determines in step S77 whether the time is over. That is, in steps S74 and S75, it is determined whether or not a predetermined predetermined time has elapsed after the connection response has been transmitted, and if the predetermined predetermined time has not yet elapsed, the process returns to step S76. , Subsequent processing is repeatedly executed. When it is determined that the preset predetermined time has elapsed, the process is terminated.
If it is determined in step S76 that the encryption key has been received, in step S78, the decryption unit 144 uses the encryption key as the private key.<u style="single">Multiple issue</u>Execute the process to be performed. That is, the encryption key received by the receiving unit 142 in step S76 is decrypted with the private key corresponding to the public key transmitted in step S71. As a result, the encryption key as a common key is shared between the client 12 and the server 34.
Therefore, the transfer processing unit 145 of the server 34 executes information transfer processing in step S79, the transfer processing unit 108 of the client 12 in step S20, and the transfer processing unit 125 of the access point 31 in step S49. Specifically, the transfer processing unit 108 of the client 12 transmits the necessary information to the access point 31 in step S20. The transfer processing unit 125 of the access point 31 transfers the signal from the client 12 to the server 34 in step S49. In step S79, the transfer processing unit 145 of the server 34 accesses, for example, the server 14 via the Internet 11 and connects to the server 14 based on the access information transmitted from the client 12 via the access point 31.
Data transmitted from the server 14, such as a home page, is received by the transfer processing unit 145 of the server 34 via the Internet 11 and transmitted to the access point 31 in step S79. When the transfer processing unit 125 of the access point 31 receives the data from the server 34 in step S49, it transfers the data to the client 12. In step S20, the transfer processing unit 108 of the client 12 outputs the data received from the server 14 via the server 34 and the access point 31 to, for example, the LCD 21 and displays it.
As described above, since the user does not need an ID or password, prior registration is not required. Then, the user can access the Internet 11 from the server 34 via the access point 31 as needed without prior registration. Therefore, the user can quickly and freely access the predetermined servers 14 and 15 via the Internet 11 at any place (however, where the access point 31 exists) and receive necessary information. It becomes. Information providers can also provide information quickly and freely by installing access points at any location.
In addition, since the address value and public key detected from the image captured by the user actually blinking LED32 are used, it is possible to receive illegal radio waves generated at a hidden position and suffer from wireless LAN phishing damage. Is suppressed. Therefore, information can be safely exchanged. Further, since the communication between the client 12 and the server 34 performed via the access point 31 is encrypted with the encryption key K2, confidentiality can be ensured.
Although the access point 31 and the server 34 constituting the connection service device 13 are arranged at distant positions, it is of course possible to integrally configure both.
In the above, the LED 32 as a light source and the access point 31 have been integrated, but the light source can be arranged at a position away from the access point 31. FIG. 16 shows an embodiment in this case. That is, in this embodiment, the lighting fixture 202 made of LEDs illuminates the poster 204, and the lighting fixture 203 made of LEDs illuminates the poster 205. In addition, a lighting fixture 206 made of LEDs illuminates a display shelf 207 displaying various products. The luminaires 202, 203, 206 are supplied with the necessary electric power via the power line 201. The access point 31 is also connected to the power line 201, and the access point 31 controls the luminaires 202, 203, 206 via the power line 201 and blinks them.
In the embodiment of FIG. 16, posters 204 and 205 are imaged by the camera 22 of the client 12. Therefore, the image 204A of the poster 204 and the image 205A of the poster 205 are displayed on the LCD21, and the corresponding icons 23-1 and 23-2 are displayed. The user can select one of the icons by selecting one of the icons with a finger or the like.
In this case, the luminaire 202 provides a URL (Uniform Resource Locator) that provides information about the poster 204 by its blinking signal, and the luminaire 203 also provides a URL related to the poster 205 by its blinking signal. ing. The luminaire 206 provides a URL that provides information about the goods displayed on the display shelf 207 by its blinking signal.
17 to 20 show the operation of still another embodiment. In this embodiment, the access point 31 normally broadcasts only the address, and the public key is transmitted when at least one client 12 accesses it. Other processing is basically the same as the processing in FIGS. 9 to 12.
That is, in more detail, first, among the processes of steps S171 to S179 of FIG. 20 corresponding to steps S71 to S79 of FIG. 12, the transmission process of the public key to the access point performed in step S71 of FIG. 12 is performed. , In the embodiment of FIG. 20, it is performed in step S175 following the process of transmitting the connection response to the access points in steps S173 and S174. Other processing is the same as in FIG.
In the processing of the access point 31 of steps S141 to S150 of FIG. 19 corresponding to steps S41 to S49 of FIG. 11, in the case of FIG. 11, the public key was received in step S41, but the implementation of FIG. In the mode, the process of transmitting the connection response to the client accessed in step S145 is performed, and then the process is performed in step S146. Other processing is the same as in FIG.
Further, in the processing of the client 12 in steps S101 to S111 in FIG. 18 corresponding to steps S11 to S20 in FIG. 10, both the address value and the public key are read in step S12 in FIG. 10 as shown in FIG. However, in step S102 of FIG. 18, only the address value is read. Instead, when it is determined in step S107 of FIG. 18 that there is a response from the access point, the blinking signal of the light transmitted from the access point in the next step S108 is received (imaging) by the imaging unit 101. The process of reading the public key from the received signal by the reading unit 102 is executed. Other processing is the same as in FIG. 10.
Also in this embodiment, the same effect as that of the embodiment of FIG. 9 can be obtained.
In the above, the light is detected on the surface (although it is imaged by the camera), but it may be detected on the point. For example, one infrared light receiving element may receive infrared light and detect a change in the level thereof. Even in this case, since the light has a straightness, the user recognizes which access point is currently receiving the infrared light by checking the direction in which the infrared light receiving unit is directed. be able to. Therefore, it is possible to prevent the victim of phishing scams by receiving the light generated from the hidden position.
FIG. 21 is a block diagram showing a configuration of a personal computer that programmatically executes the series of processes described above. The CPU (Central Processing Unit) 221 executes various processes according to a program stored in the ROM (Read Only Memory) 222 or the storage unit 228. The RAM (Random Access Memory) 223 stores programs and data executed by the CPU 221 as appropriate. These CPU 221 and ROM 222, and RAM 223 are connected to each other by bus 224.
The input / output interface 225 is also connected to the CPU 221 via the bus 224. An input unit 226 consisting of a keyboard, mouse, microphone, etc., and an output unit 227 consisting of a display, a speaker, etc. are connected to the input / output interface 225. The CPU 221 executes various processes in response to a command input from the input unit 226. Then, the CPU 221 outputs the processing result to the output unit 227.
The storage unit 228 connected to the input / output interface 225 is composed of, for example, a hard disk, and stores programs executed by the CPU 221 and various data. The communication unit 229 communicates with an external device via a network such as the Internet or a local area network. Further, the program may be acquired via the communication unit 229 and stored in the storage unit 228.
The drive 230 connected to the input / output interface 225 drives removable media 231 such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory when the removable media 231 is attached, and the programs and data recorded therein are driven. And so on. The acquired programs and data are transferred to and stored in the storage unit 228 as needed.
The series of processes described above can be executed by hardware or software. When a series of processes are executed by software, the programs that make up the software execute various functions by installing a computer embedded in dedicated hardware or various programs. It can be installed from a program storage medium, for example, on a general-purpose personal computer.
As shown in FIG. 21, the program storage media for storing the programs installed on the computer and made ready to be executed by the computer are magnetic disks (including flexible disks) and optical disks (CD-ROM (Compact Disc-Read Only)). Removable media 231 which is a package media consisting of Memory), DVD (including Digital Versatile Disc), magneto-optical disc (including MD (Mini-Disc)), or semiconductor memory, or the program is temporary or permanent. It is composed of a ROM 222 stored in the storage unit 228 and a hard disk constituting the storage unit 228. Programs are stored in the program storage medium using a wired or wireless communication medium such as a local area network, the Internet, or digital satellite broadcasting via the communication unit 229, which is an interface such as a router or a modem, if necessary. Will be done.
In the present specification, the steps for describing the program stored in the program storage medium are parallel, not to mention the processes performed in chronological order according to the described order, even if they are not necessarily processed in chronological order. Alternatively, it also includes processes that are executed individually.
Further, in the present specification, the system represents an entire device composed of a plurality of devices.
The embodiment of the present invention is not limited to the above-described embodiment, and various modifications can be made without departing from the gist of the present invention.
<figref num="1">It is a flowchart explaining the operation of the conventional access point.</figref><figref num="2">It is a figure which shows the structure of the information providing system of embodiment of this invention.</figref><figref num="3">It is a block diagram which shows the structure of a client.</figref><figref num="4">It is a block diagram which shows the structure of an access point.</figref><figref num="5">It is a block diagram which shows the structure of a server.</figref><figref num="6">It is a block diagram which shows the functional structure of the control part of a client.</figref><figref num="7">It is a block diagram which shows the functional structure of the control part of an access point.</figref><figref num="8">It is a block diagram which shows the functional structure of the control part of a server.</figref><figref num="9">It is a flowchart explaining the operation of the information provision system of FIG.</figref><figref num="10">It is a flowchart explaining the process of a client.</figref><figref num="11">It is a flowchart explaining operation of an access point.</figref><figref num="12">It is a flowchart explaining the operation of a server.</figref><figref num="13">It is a figure explaining 0 and 1 of Manchester coding.</figref><figref num="14">It is a figure which shows the example of the data coded sequence.</figref><figref num="15">It is a figure which shows the example of posting of the symbol mark of a certification body.</figref><figref num="16">It is a figure which shows the other structure of the Embodiment of this invention.</figref><figref num="17">It is a flowchart explaining the process of embodiment of FIG.</figref><figref num="18">It is a flowchart explaining the process of a client.</figref><figref num="19">It is a flowchart explaining the processing of an access point.</figref><figref num="20">It is a flowchart explaining the process of a server.</figref><figref num="21">It is a block diagram which shows the structure of a personal computer.</figref>
Code description
1 Information system, 11 Internet, 12 Client, 13 Connection service device, 14,15 Server, 21 LCD, 22 Camera, 23 Icon, K1, K2 Encryption key, 31 Access point, 32 LED, 33 Antenna, 34 Server
21 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21
Every citation, both waysCites: the store holds 20 of 21
| Document | Relation | Office |
|---|---|---|
| JP2004228793A | Cites | Japan |
| JP2005012688A | Cites | Japan |
| JP05083707A | Cites | Japan |
| JP05083243A | Cites | Japan |
| JP2001298779A | Cites | Japan |
| JP2002124960A | Cites | Japan |
| JP2003131921A | Cites | Japan |
| JP2004056762A | Cites | Japan |
| JP2004112571A | Cites | Japan |
| JP2004254320A | Cites | Japan |
| JP2004302846A | Cites | Japan |
| JP2004320139A | Cites | Japan |
| JP2005020746A | Cites | Japan |
| JP2005033265A | Cites | Japan |
| JP2005184830A | Cites | Japan |
| JP2005318281A | Cites | Japan |
| JP2002530968A | Cites | Japan |
| JP2005536093A | Cites | Japan |
| JP2005538636A | Cites | Japan |
| WO2004025901A1 | Cites | World Intellectual Property Organization (WIPO) |
| ウォーイック・フォード 他,ディジタル署名と暗号技術,株式会社プレンティスホール出版,1997年12月24日,初版,p.166 | Non-patent | – |
| 吹田 智章,暗号のすべてがわかる本,株式会社技術評論社,1998年 7月25日,初版,p.169~170 | Non-patent | – |
| 黒澤 馨,尾形 わかは,現代暗号の基礎数理,株式会社コロナ社,2004年 3月31日,初版,p.52 | Non-patent | – |
| 野村 拓望 Takumi Nomura,赤外線暗号キー配信による暗号システム,電子情報通信学会2005年総合大会講演論文集 通信1 PROCEEDINGS OF THE 2005 IEICE GENERAL CONFERENCE,社団法人電子情報通信学会,2005年 3月 7日,p.621 | Non-patent | – |
8 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2005223084 | Japan | A | |
| JP20050223084 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| US2007028094A1 | United States of America | A1 | |
| KR20070015880A | Republic of Korea | A | |
| CN1909421A | China | A | |
| JP2007043317A | Japan | A | |
| CN1909421B | China | B | |
| JP4900645B2This record | Japan | B2 | |
| US8190882B2 | United States of America | B2 | |
| KR101314512B1 | Republic of Korea | B1 |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4900645
- Publication, DOCDB
- 4900645
- Publication, EPODOC
- JP4900645B
- Application
- 223084
- Application, DOCDB
- 2005223084
- Application, EPODOC
- JP20050223084
Titles2
- Japanese
- 受信装置、受信方法、送信装置、送信方法、プログラム、記録媒体、通信システム、および通信方法
- English
- Receiver, receiver, transmitter, transmitter, program, recording medium, communication system, and communication method
Classification
- CPC, 5
- H04L9/08
- H04L9/32
- H04L9/0825
- H04B10/85
- H04L9/30
- IPC, 6
- H04L9 08
- H04W12 00
- H04W12 02
- H04W76 02
- H04W84 10
- H04W84 12
