Method and system for secure communication in near field communication network
Abstract
This record has no abstract on file.
Term
Projected expiry 28 November 2028.
- Priority
- Filed
- Granted
- Today
- Projected expiry
26 claims: 2 independent, 24 dependent
- 1近距離無線通信(NFC)ネットワークにおける複数の電子装置間の安全な通信を行う方法であって、 第1の電子装置で遂行される方法は、 前記複数の電子装置のうち少なくとも一つの装置と複数のキーを共有するステップと、 前記複数のキーの中で第1のキーを選択するステップと、 前記複数の電子装置のうち少なくとも一つの装置と前記選択された第1のキーに基づいて暗号化されたデータを交換するステップと、 少なくとも一つの所定基準が満足された後に前記データを交換する間に前記第1のキーを前記複数のキーのうち少なくとも一つ のキーを選択するステップと、前記少なくとも一つのキーに対する情報を含むキー変更要請を前記少なくとも一つの装置に伝送するステップと、 前記キー変更要請を承認する応答を前記少なくとも一つの装置から受信すると、前記少なくとも一つのキーに基づいて暗号化されたデータを交換するステップと、 前記キー変更要請に対する承認を拒否する応答を前記少なくとも一つの装置から受信すると、続けて前記第1のキーに基づいて暗号化されたデータを交換するステップと を具備することを特徴とする方法。
- 2前記複数のキーのうち少なくとも一つのキーを複数のアプリケーションのうち少なくとも一つと関連させるステップをさらに具備することを特徴とする請求項1に記載の方法。
- 3前記複数のキーのうち少なくとも一つのキーを複数のデータフォーマットのうち少なくとも一つと関連させるステップをさらに具備することを特徴とする請求項1に記載の方法。
- 4前記少なくとも一つの所定基準は、所定の時間間隔であることを特徴とする請求項1に記載の方法。
- 5前記少なくとも一つの所定基準は、所定の交換されたデータの量であることを特徴とする請求項1に記載の方法。
- 6前記少なくとも一つの所定基準は、所定の交換されたデータの個数であることを特徴とする請求項1に記載の方法。
- 7前記NFCセキュリティ(NFC-SEC)層の安全チャンネルサービスに基づいて一つの通信チャンネルを設定するステップをさらに具備することを特徴とする請求項1に記載の方法。
- 8前記NFC-SEC層の共有秘密サービスに基づいて一つの通信チャンネルを設定するステップをさらに具備することを特徴とする請求項1に記載の方法。
- 9前記第1のキーを交換するステップは、NFC-SECプロトコルデータユニット(PDU)に基づいて前記第1のキーを変更することを特徴とする請求項1に記載の方法。
- 10前記第1のキーを交換するステップは、パラメーター交換(PAX)プロトコルデータユニット(PDU)に基づいて前記第1のキーを変更することを特徴とする請求項1に記載の方法。
- 11前記第1のキーに基づいて前記データを交換するステップは、前記データを前記第1のキーで暗号化することを特徴とする請求項1に記載の方法。
- 12前記第1のキーに基づいて前記データを交換するステップは、前記データを前記第1のキーで復号化することを特徴とする請求項1に記載の方法。
- 13前記複数の電子装置のうち少なくとも一つで前記データを交換するステップ以前に前記データを認証するステップをさらに具備することを特徴とする請求項1に記載の方法。
- 14近距離無線通信(NFC)ネットワークにおける複数の電子装置間の安全な通信を行うシステムであって、 複数のキーを複数の電子装置のうち少なくとも一つと共有し、第1のキーに基づいてデータを前記複数の電子装置のうち前記少なくとも一つと交換する送受信器と、 前記複数のキーの中で前記第1のキーを選択し、少なくとも一つの所定基準が満足された後に前記データを交換する間に前記第1のキーを前記複数のキーのうち少なくとも一つ のキーを選択し、前記少なくとも一つのキーに対する情報を含むキー変更要請を前記少なくとも一つの装置に伝送し、前記キー変更要請を承認する応答を前記少なくとも一つの装置から受信すると、前記少なくとも一つのキーに基づいて暗号化されたデータを交換し、前記キー変更要請に対する承認を拒否する応答を前記少なくとも一つの装置から受信すると、続けて前記第1のキーに基づいて暗号化されたデータを交換する プロセッサと、 から構成される第1の電子装置を含むことを特徴とするシステム。
- 15前記第1の電子装置は、前記複数のキーのうち少なくとも一つのキーを複数のアプリケーションのうち少なくとも一つと関連させることを特徴とする請求項14に記載のシステム。
- 16前記第1の電子装置は、前記複数のキーのうち少なくとも一つのキーを複数のデータフォーマットのうち少なくとも一つと関連させることを特徴とする請求項14に記載のシステム。
- 17前記少なくとも一つの所定基準は、所定の時間間隔であることを特徴とする請求項14に記載のシステム。
- 18前記少なくとも一つの所定基準は、所定の交換されたデータの量であることを特徴とする請求項14に記載のシステム。
- 19前記少なくとも一つの所定基準は、所定の交換されたデータの個数であることを特徴とする請求項14に記載のシステム。
- 20前記第1の電子装置は、前記NFCセキュリティ(NFC-SEC)層の安全チャンネルサービスに基づいて一つの通信チャンネルを設定することを特徴とする請求項14に記載のシステム。
- 21前記第1の電子装置は、前記NFC-SEC層の共有秘密サービスに基づいて一つの通信チャンネルを設定することを特徴とする請求項14に記載のシステム。
- 22前記第1の電子装置は、NFC-SECプロトコルデータユニット(PDU)に基づいて前記第1のキーを変更することを特徴とする請求項14に記載のシステム。
- 23前記第1の電子装置は、パラメーター交換(PAX)プロトコルデータユニット(PDU)に基づいて前記第1のキーを変更することを特徴とする請求項14に記載のシステム。
- 24前記第1の電子装置は、前記データを前記第1のキーで暗号化することを特徴とする請求項14に記載のシステム。
- 25前記第1の電子装置は、前記データを前記第1のキーで復号化することを特徴とする請求項14に記載のシステム。
- 26前記第1の電子装置は、前記複数の電子装置のうち少なくとも一つで前記データを交換するステップ以前に前記データを認証することを特徴とする請求項14に記載のシステム。
Independent claims26
55 paragraphs, as filed
The present invention relates to a short-range wireless communication network, particularly to secure communication in short-range communication.
Wireless communication devices, such as mobile phones, personal digital assistants (PDAs), smart tags, audio / video devices, and set-top boxes, are often used for communication. used. Typical communication devices can communicate with each other through short-range wireless communication. For example, a mobile phone is one or more such as short-range radio (eg, Bluetooth®), infrared (IR), and Near Field Communication (hereinafter referred to as NFC). It is possible to communicate with the set-top box using the short-range wireless communication system of.
Near field communication (NFC) is called contactless short field communication technology. NFC uses the 13.56 MHz frequency band to transmit data at a maximum transmission rate of 424 Kbps. Communication equipment in NFC operates at close range, eg, within 10 centimeters, and consumes very low power. As a result, NFC is widespread for exchanging and sharing information, and many devices incorporate such NFC systems to become NFC exchange communication devices.
NFC compatible communication equipment adheres to the International Organization for Standardization (ISO) 18092 standard. In Near Field Communication (NFC), the communication devices can communicate with each other in active and / or passive modes. In active mode, an NFC device, eg, a first device, has its own power source and can generate a radio frequency (RF) field for the transmission of data frames. In passive mode, the first NFC device does not have its own power source. Therefore, communication is always initiated by another NFC device known as the initiator.
In NFC, the target device cannot initiate a command word by itself, regardless of whether the communication is in active or passive mode. In passive mode, the initiating device first sends a request message to carry out communication with the first device (commonly referred to as the target device). This creates an RF field between the starting device and the target device. The RF field then triggers the receiving circuit in the target device. This target device responds in a load-modulated manner.
In general, communications using NFC technology are inherently secure as they occur between communication devices over very short distances (eg, about 10 centimeters). However, since communication is through wireless media, a security framework must be provided to ensure confidentiality, integrity, and reliability. Various standards have been developed to provide a security framework for NFC communication. This security framework is supported by the NFC Security (NFC-SEC) layer. The NFC-SEC layer provides security services to the application layer and the media access control (hereinafter referred to as "MAC") layer, thereby providing privacy and security functions in communication devices.
The two basic services provided by the NFC-SEC layer are the secure channel service and the shared secret service. In the safety channel service, the link key is used to set the safety channel. The link encryption key and the link integrity key are then generated from the link key. Therefore, all data frames received from different applications use the same link key during communication.
In the shared secret service, the shared secret is agreed between multiple devices. Keys are generated and / or selected based on shared secrets. This shared secret and key are associated with applications that exist on multiple communication devices. Therefore, application-related data frame transmissions are based on shared keys. This shared secret service allows each application to use a different key for transmitting data frames.
The NFC device in each data frame transmission maintains and increments a Sequence Number (hereinafter referred to as SN) counter. The NFC-SEC layer then inserts the SN value into the SN field of the request and response commands exchanged between the devices in communication. This SN is 3 bytes (24 bits) in the request and response commands. The application service and / or safety channel service used by the NFC link has a maximum frame limit (eg 2).<sup>24</sup>Use the same key for request and response commands for frames). Before inserting a new value in the SN field, the NFC device compares the counter with the maximum limit. After that, the counter is cycled and reset when the SN reaches the maximum limit. Data link communication is terminated and a new key set is determined for the next communication.
<p num="0010"> However, since the same key is used to exchange a large number of data frames, there is a possibility of an indiscriminate attack in which communication is damaged during transmission. In addition, the NFC-SEC layer suspends communication and stops data frame exchange when the SN counter is reset. Therefore, this leads to a sudden discontinuity in NFC communication. Higher tier connections may also experience discontinuities in this link before NFC-SEC re-exemplifies a new set of keys and starts with a new initial value for the SN.</p><p num="0011"> Therefore, there is a need to establish secure and continuous communication between NFC communication devices.</p>
<p num="0012"> According to one aspect of the present invention, it is a method of performing secure communication between a plurality of electronic devices in a short-range wireless communication (NFC) network, and the first electronic device is used to perform at least one of the plurality of electronic devices. Encryption based on a step of sharing multiple keys with a device, a step of selecting the first key among multiple keys, and at least one of the devices and the selected first key It is characterized by comprising a step of exchanging data and a step of exchanging a first key with at least one of a plurality of keys while exchanging data after at least one predetermined criterion is satisfied. ..</p><p num="0013"> According to another aspect of the present invention, it is a system that performs secure communication between a plurality of electronic devices in a short-range wireless communication (NFC) network, and shares a plurality of keys with at least one of the plurality of electronic devices. A transmitter / receiver that exchanges data with at least one of a plurality of electronic devices based on the first key, and data after selecting the first key among the keys and satisfying at least one predetermined criterion. It is characterized by including a first electronic device composed of a processor that dynamically exchanges a first key with at least one of a plurality of keys during exchange.</p><p num="0014"> The above and other aspects, features, and advantages of the present invention will become more apparent from the detailed description that follows with the accompanying drawings as follows.</p>
<p num="0015"> The present invention provides a method for secure communication in an NFC communication network. This method provides protection from indiscriminate and repetitive attacks by dynamically changing the keys used for encryption and decryption. This method also prevents abrupt termination of service when the NFC-SEC layer sets a new key and / or a new value for the sequence number (SN) field. In addition, this method saves additional processing during communication because the current command in LLCP and NFC-SEC is used to establish communication with a new key for all communicating devices. .. Note that this method can be used to change the key even when there is an upper layer on the NFC-SEC layer.</p>
<figref num="1">It is a figure which shows the exemplary environment in which various embodiments of this invention can be carried out.</figref><figref num="2">It is a figure which shows the 1st electronic device by embodiment of this invention.</figref><figref num="3">It is a figure which shows the frame format in which data is exchanged by embodiment of this invention.</figref><figref num="4">It is a flowchart which shows the method for establishing the secure communication in the short-range communication (NFC) network by embodiment of this invention.</figref><figref num="5">It is a figure which shows the message flow which shows the method for establishing the secure communication in the short-range communication (NFC) network by embodiment of this invention.</figref>
Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings.
Therefore, although the embodiments of the present invention are described in various and detailed ways to aid understanding, these explanations are considered as almost typical examples. It is also apparent to those with ordinary knowledge in the art that various modifications and modifications of the invention described below are possible without departing from the scope and spirit of the invention. Specific description of known functions or configurations will be omitted for clarity and brevity.
It will be appreciated by those skilled in the art that the "a", "an", and "the", or singular forms, described in the English specification include the plural form unless otherwise specified in the context. Thus, for example, the description "a component surface" includes one or more surfaces.
The term "substantially" does not require the presented features, parameters, or values to be set accurately, but is known to those skilled in the art of tolerances, measurement errors, measurement accuracy limits, and Alternatively, it means that deviations or changes including elements obtained by those skilled in the art without experimentation occur to the extent that these properties do not preclude the effect they seek to provide.
FIG. 1 shows an exemplary environment 100 in which various embodiments of the present invention can be implemented. Environment 100 includes a plurality of electronic devices, such as electronic device 105 and electronic device 110. Although only two electronic devices are shown in Environment 100, it is self-evident to those skilled in the art that Environment 100 can include more electronic devices. Examples of electronic devices 105,110 include, but are not limited to, mobile phones, smart tags, PDAs, and computers. A plurality of electronic devices can communicate with each other through a communication network.
In one embodiment, the electronic devices 105, 110 are capable of communicating with each other through short-range wireless communication technology. Examples of near field communication technologies include, but are not limited to, near field radio (eg, Bluetooth), infrared (IR), and near field communication (NFC). In one embodiment, the electronic devices 105, 110 are capable of communicating with each other through Near Field Communication (NFC) technology. Therefore, the electronic devices 105 and 110 are NFC compatible electronic devices. For the purposes and clarity of this description, the electronic devices 105, 110 will be referred to as the NFC device 105 and the NFC device 110.
A pair of NFC devices, such as NFC device 105 and NFC device 110, can operate in one of operating modes, such as read / write mode, peer-to-peer mode, and card emulation mode. The different modes of operation are based on the well-known MAC protocols ISO / IEC18092NFCIP-1 and ISO / IEC14443 non-contact smart card standards and do not need to be discussed in detail here.
In read / write mode, the NFC device can read the NFC forum instruction tag type. In this mode the tag can be active or passive. However, if the reading NFC device is adjacent to the tag and is initialized to read the signal, the tag becomes active for communication. In card emulation mode, the NFC device operates as an NFC tag to operate as a general non-contact smart card, and the other NFC devices operate as a read / write device. In peer-to-peer mode operation, the legacy NFC device performs half-duplex mode operation using a protocol that allows peer-to-peer mode operation. The NFC device that initiates communication in this mode of operation is called the Initiator, and the device that establishes communication is known as the target.
In NFC, the NFC-SEC protocol can be used to provide a secure channel framework for data exchange when communication links are established. In NFC-SEC, multiple keys are agreed between multiple devices, namely NFC device 105 and NFC device 110. Next, NFC-SEC maintains a table for multiple keys on a basis for each key, called the key index. The first key is then selected from multiple keys using the NFC-SEC command, and the first key is on NFC-SEC as the first key used to secure data exchange on the link. Be maintained.
The data is then exchanged between NFC devices 105 and 110 based on a first key to provide security. In one embodiment, the key facilitates encryption of data. In other embodiments, the key facilitates authentication of the data. In one embodiment, a Message Authentication Code (MAC) is added to each data frame exchanged between NFC devices to provide data frame security and protect integrity. In one embodiment, security standards such as Advanced Encryption Standard (AES) are used to calculate the MAC. The sequence number (SN) is also added to each frame to provide message sequence integrity and prevent repeated data attacks. In one embodiment, sequence numbers are used to identify data manipulation attacks.
The first key is then dynamically changed based on the first predetermined criterion. In one embodiment, the first key is dynamically exchanged for the second key. The second key is selected from a plurality of key sets previously agreed between the NFC device 105 and the NFC device 110. In one embodiment, the first predetermined criterion is based on the number of data frames exchanged between NFC devices. In other embodiments, the first predetermined criterion is based on the amount of time elapsed while communicating with the current key. In other embodiments, the first predetermined criterion is based on the identification of security threat attacks.
FIG. 2 shows a first electronic device according to an embodiment of the present invention. Reference is made to FIG. 1 to illustrate the first electronic device. However, it is clear to those of ordinary skill in the art that embodiments of the present invention can be described using other adapted embodiments. For this explanation, the first electronic device is referred to as the NFC device 105.
The NFC device 105 includes a transmitter / receiver 205 and a processor 210. The transmitter / receiver 205 can share a plurality of keys between a plurality of electronic devices, for example, the NFC device 105 and the NFC device 110. The processor 210 then selects a first key from a plurality of shared keys and assembles the data to be exchanged based on the selected first key. In one embodiment, the processor 210 uses the first key to encrypt the data and the transmitter / receiver 205 transmits the encrypted data. In one embodiment, the processor receives the encrypted data from the transmitter / receiver 205 and decrypts it with the first key.
The transmitter / receiver 205 exchanges encrypted data between the NFC devices 105 and 110 using the first key. In one embodiment, the transmitter / receiver 205 can exchange data based on the functions and commands supported by the NFC standard. In other embodiments, the transmitter / receiver can exchange data based on an agreed security key using multiple Parameter Exchange (PAX) Protocol Data Unit (PDU) commands. is there. Processor 210 can also dynamically initiate an agreement on the keys used by the application and / or link layer. In one embodiment, processor 210 modifies the first key based on a predetermined criterion.
In another embodiment, the processor 210 dynamically exchanges the first key with the second key while communication is in progress. Therefore, the processor 210 dynamically changes the first key to the second key without pausing and / or stopping communication between the NFC device 105 and the NFC device 110. In one embodiment, the processor 210 selects a second key from a plurality of keys shared between the NFC devices 105, 110.
On the other side, the processor 210 can provide message sequence integrity and add a sequence number (SN) to each frame to prevent repeated data attacks. The processor 210 also maintains a counter for the SN.
FIG. 3 shows a frame format in which data is exchanged according to an embodiment of the present invention. In one embodiment, the frame format used by the NFC-SEC protocol is the NFC-SEC Protocol Data Unit (PDU). This frame NFC-SEC is used to transmit the NFC IP-1 (NFC Interface and Protocol-1) Data Exchange Protocol (DEP) in a secure manner. In one embodiment, the data format corresponds to a protocol developed by the NFC IP-1 security service and the ECMA (European Computer Manufacturers Association) standard body. The frame format has a plurality of fields for carrying various information. For example, the frame format is SEP (Secure Exchange). It is shown to include the Protocol) field, NFC-SEC-01 field, SN field, DataLen field, EncData field, and MAC field. Although the figure 3 contains 6 fields, it does not limit the scope of the invention, whereby the frame format can have more or less fields.
Field 305 is a secure exchange protocol (SEP) field. The SEP field is used to identify the exchange protocol used during communication. Field 310 is the NFC-SEC-01 field. The NFC-SEC-01 field contains a 1-byte Packet Identifier field that identifies the ciphertext standard used to provide security. Field 315 is a sequence number (SN) field. The SN field is NFC-SEC Indicates the PDU sequence number. Field 320 is a Data Len field. The DataLen field is used to represent the number of bytes of encoded data transmitted within a data frame. Field 325 contains an EncData field. This EncData field provides details about the encrypted data. Field 330 is for the message authentication code (MAC). MAC fields are used to verify authentication and message integrity.
FIG. 4 is a flowchart showing a method for establishing secure communication in short-range communication (NFC) according to the embodiment of the present invention. See FIGS. 1 and 2 to illustrate method 400. However, it is self-evident to those with ordinary knowledge in the art that this embodiment can be explained using other adapted embodiments of the present invention. The method 400 can also include more than one step or less than a step as shown in FIG. In addition, the order of the steps can be changed.
At step 405, method 400 is started. A first electronic device, such as the NFC device 105 (FIG. 1), sends instructions to another electronic device, such as the NFC device 110, to establish a communication link. In one embodiment, when the first electronic device is moved within a predetermined distance from the other electronic device, the instruction is automatically transmitted to the other electronic device. For example, if the NFC device 105 is adjacent to the NFC device 110, for example, within 10 centimeters of the NFC device 110, the instruction is transmitted to the NFC device 110.
When the initial communication link is established, the NFC device is activated to exchange data. At step 410, the plurality of keys are first exchanged between the NFC device 105 and the NFC device 110. At step 415, the first key is selected from a plurality of keys for exchanging data. The plurality of keys are arranged in the order of a plurality of devices corresponding to at least one key index. For example, the first key is an index '1' for each of a predetermined key index, eg, a plurality of NFC devices communicating with each other. Then, in step 420, data is exchanged between the NFC device 105 and the NFC device 110 based on the first key.
In one embodiment, the transmitter / receiver 205 exchanges encrypted data using a first key. The NFC device 105 then decides to replace the first key with a second key based on predetermined criteria. In one embodiment, the key index is shared among multiple NFC devices. In step 425, the first key is dynamically exchanged with at least one of the plurality of keys, eg, the second key, while exchanging data. NFC devices can exchange data based on a single key that corresponds to a shared key index. In one embodiment, the NFC-SEC layer of the NFC device ensures that all frames are forwarded in the transmission queue before changing the key. After that, method 400 ends at step 430.
In one embodiment, multiple NFC commands and functions are exchanged at different layers within the NFC device to dynamically change keys. In addition, multiple NFC commands and functions are exchanged between multiple NFC devices while communicating with each other. Therefore, for the sake of explanation, this method will be described by two methods described below. The following implementation methods are described for multiple functions and commands. The functions and commands used in the following practices are for clarity purposes only and do not limit the scope of the invention to these practices. Therefore, a person skilled in the art can use other functions or commands to perform the above method.
In the first embodiment, the NFC device, eg, the NFC-SEC layer of the NFC device 105, first generates a local decision to change the key. For example, NFC device 105 decides to change the first key to the second key. In one embodiment, the second key corresponds to a key index shared during communication. Therefore, the NFC-SEC layer in the NFC device 105 issues the CHANGE_KEY_REQ command to the Near Field Link Control protocol (Logical Link Control) in the NFC device 105. Protocol: Send to the layer (hereinafter referred to as "LLCP"). Here, CHANGE_KEY_REQ [key index] is a CHANGE_KEY_REQ command including a key index. In one embodiment, the key index is a unique identifier for a second key stored in a table on the NFC device. In one embodiment, communication at the LLCP layer is a peer-to-peer communication mode for NFC devices as defined by the NFC Forum. The NFC-SEC layer ensures that all data frames in the transmission queue are forwarded before initiating CHANGE_KEY_REQ. In one embodiment, the LLCP in the NFC device 105 transitions the state of the LLCP link from the active state to the configure state upon receipt of this command. Therefore, this stops the transmission of additional data frames sent from the LLCP connection to NFC-SEC.
The change key request is initiated between the NFC devices through the CHANGE_KEY_REQ command and the response is received through the CHANGE_KEY_RSP command. The LLCP layer of the NFC device 105 then sends a PAX request command with a key index corresponding to the second key to another NFC device (eg, NFC device 110). Then, the NFC device waits for a PAX response from the NFC device 110. In one embodiment, the PAX request command is secured using the first key.
In one embodiment, all data frames are exchanged based on the first key until the NFC device 105 receives a success command from the NFC device 110. After receiving the PAX [key index] from the NFC device 105, the LLCP layer in the NFC device 110 sends a CHANGE_KEY_REQ [key index] event to the NFC-SEC layer in the NFC device 110. This PAX [key index] is a PAX command that includes a key index. In one embodiment, the LLCP layer in the NFC device 110 transitions from the active state to the set state. In one embodiment, the NFC-SEC layer completes the transmission of frames held in the transmission queue using the first key.
Moreover, if the key index given by NFC device 105 is known and valid to the NFC-SEC layer of NFC device 110, then the NFC-SEC layer will set CHANGE_KEY_RSP [key index] of NFC device 110. Send to LLCP. This CHANGE_KEY_RSP command is a CHANGE_KEY_RSP with a key index. The LLCP layer of NFC device 110 then sends a PAX [key index] response to NFC device 105 for successful key changes. Therefore, the new transmission is based on the key corresponding to the shared key index. In one embodiment, the LLCP link transitions from the configured state to the active state.
In one embodiment, the PAX command is based on the first key. If the NFC-SEC layer of NFC device 110 does not agree on the requested change of the key, the CHANGE_KEY_RSP command is sent to the LLCP. This CHANGE_KEY_RSP command is a CHANGE_KEY_RSP that contains a failure code. After that, the PAX with the failure code is sent to the NFC device 105. Therefore, the first key is unchanged. The LLCP link then transitions from the configured state to the active state, and communication is continued by the first key to encrypt the next data.
In the second method, dynamic key changes can be handled by commands at the NFC-SEC layer. This method can be used independently of the LLCP layer. After transmitting a random count of data frames, the NFC-SEC layer can be selected to change the safety key used in the secure channel framework. In the embodiment described herein, it is assumed that a set of keys has already been agreed and confirmed between the two NFC devices and their values are stored in the key table referenced by the key index.
To change the key through this method, the NFC-SEC layer of NFC device 105 first makes a local decision to change the first key to the second key corresponding to the key index. In one embodiment, the NFC-SEC layer ensures that all data frames in the transmit queue are transmitted and all frames in the receive queue are transmitted to the higher layers. After that, after selecting the second key corresponding to the key index, the NFC-SEC layer changes the communication status from the confirmed status to the verified status. The NFC-SEC layer of NFC device 105 sends the data exchange protocol request frame DEP_REQ (VFY_REQ) command to NFC device 110 together with the key index as a parameter to verify whether other devices can use the same key index. Send. In one embodiment, the details of the data exchange protocol and the frame format for DEP_REQ and DEP_RES are used by the Near Field Communication Interface and Protocol (NFCIP-1) ECMA340 standard. Such standards are well known to those of skill in the art and are easily achievable, and detailed description thereof will be omitted here.
Upon receipt of the successful data exchange protocol response frame DEP_RES (VFY_RES), the NFC-SEC layer transitions from the verification state to the confirmation state, switching from using the first key to using the second key. However, if that fails, DEP_RES [error] is received and NFC-SEC returns to idle. The DEP_RES command is a DEP_RES containing an error. In one embodiment, frames received from the upper or lower layers are decoded and buffered or dropped until the sequence of DEP_REQ (VFY_REQ) is complete.
In the NFC device 110, the NFC-SEC layer confirms the key index when receiving the DEP_REQ (VFY_REQ) command from the NFC device 105. If the key index is valid, a DEP_RES (VFY_RES) frame is sent. The state of NFC-SEC is maintained in the confirmed state. Therefore, the key used in the NFC-SEC layer is changed to the second key mentioned by the key index. When DEP_REQ (VFY_REQ) is received, the response is transmitted from the NFC-SEC layer as the next frame. No other frames are transferred in the middle of this sequence. However, if the key index is not valid, the DEP_RES command will be sent to the initiator. The NFC-SEC layer returns to the idle state.
FIG. 5 shows a message flow showing a method for establishing secure communication in a Near Field Communication (NFC) network according to an embodiment of the present invention. In this method, the plurality of applications are first registered with the plurality of electronic devices, such as the electronic device 105 and the electronic device 110. For clarity, the electronic device 105 and the electronic device 110 are referred to as the starting LLCP and the target LLCP, respectively.
First, the NFC device, eg, the NFC-SEC layer in the NFC device 105, makes a local decision to change the key. For example, NFC device 105 decides to change the first key to the use of the second key after at least one known criterion has been met. In one embodiment, the second key corresponds to a key index shared during previous communication. In step 505, the NFC-SEC layer in the NFC device 105 sends a CHANGE_KEY_REQ command to the LLCP layer. In one embodiment, the key index is a unique identifier for a second key stored in each table of multiple NFC devices communicating with each other.
The NFC-SEC layer ensures that all data frames in the transmission queue are forwarded before initiating CHANGE_KEY_REQ. In one embodiment, the LLCP of the NFC device 105 changes the state of the LLCP link from the active state to the set state when a command is received. Therefore, this interrupts the transmission of additional data frames sent from the LLCP connection to NFC-SEC. The change key request is initiated between the NFC devices through the CHANGE_KEY_REQ command and the response is received through the CHANGE_KEY_RSP command.
At step 510, the LLCP layer of the NFC device 105 sends a PAX request command, such as a PAX [key index], along with a key index corresponding to the second key to another NFC device, such as the NFC device 110. The NFC device waits for a PAX response from the NFC device 110. In one embodiment, the PAX request instruction is secured using the first key. In one embodiment, all data frames are exchanged based on the first key until the NFC device 105 receives a success command from the NFC device 110.
In step 515, the LLCP layer of the NFC device 110 sends a CHANGE_KEY_REQ [key index] event to the NFC-SEC layer after receiving the PAX [key index] from the NFC device 105. In one embodiment, the LLCP layer in the NFC device 110 transitions from the active state to the set state after receiving the CHANGE_KEY_REQ [key index]. In one embodiment, the NFC-SEC layer can complete the transmission of frames present in the transmission queue using the first key.
In step 520, if the key index given by NFC device 105 is known and valid in the NFC-SEC layer of NFC device 110, the NFC-SEC layer will CHANGE_KEY_RSP [key index] to the LLCP of NFC device 110. ] Is sent. At step 525, the LLCP layer of NFC device 110 sends a PAX [key index] to NFC device 105. At step 530, the CHANGE_KEY_RSP [key index] is sent from the LLCP of the NFC device 105 to the NFC-SEC layer.
Therefore, any new transmission is based on the key corresponding to the agreed and new shared key index. In one embodiment, the LLCP link transitions from the configured state to the active state. In one embodiment, the PAX command is based on the first key. If the NFC-SEC layer of NFC device 110 does not agree to change the key, the CHANGE_KEY_RSP command is sent to the LLCP. The PAX with the failure code is then sent to the NFC device 105. Therefore, the first key is unchanged. The LLCP link transitions from the configured state to the active state.
The methods according to the invention described above are CD ROMs, RAMs, floppies (registered) to be performed by a general computer or a specific processor, or software capable of programming such as ASIC or FPGA or using dedicated hardware. It can be implemented in hardware, software or computers that can be stored on a recording device such as a disk, hard disk, or disk disk, or downloaded over a network. A computer, processor or programmable hardware is accessible by the computer, processor or programmable hardware and is a memory unit that receives and stores software or computer code for performing the methods according to the invention described above. , For example RAM, ROM, flash, etc.
Although the present invention has been illustrated and described with respect to specific embodiments, various changes in form and details are possible without departing from the spirit and scope of the present invention as defined by the appended claims. It is clear to those with ordinary knowledge in the art.
100 Environment 105, 110 Electronic device 205 Transmitter 210 Processor 305, 310, 315, 320, 325, 330 Field
Every citation, both waysCites: the store holds 14 of 15
| Document | Relation | Office |
|---|---|---|
| JP10242956A | Cites | Japan |
| JP11234260A | Cites | Japan |
| JP2003195750A | Cites | Japan |
| JP2006033266A | Cites | Japan |
| JP2006186470A | Cites | Japan |
| WO2007003429A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2004260367A | Cites | Japan |
| JP2008103988A | Cites | Japan |
| JP2008504788A | Cites | Japan |
| JP2009500735A | Cites | Japan |
| JP60223247A | Cites | Japan |
| JP63151136A | Cites | Japan |
| JP7327029A | Cites | Japan |
| JP2002247542A | Cites | Japan |
| 宇根 正志 他,暗号アルゴリズムにおける2010年問題について,日本銀行金融研究所ディスカッション・ペーパー・シリーズ(2005年収録分),日本銀行,2005年12月16日,p.39 | Non-patent | – |
| 高山 佳久 他,近距離通信(NFC)規格の国際標準化動向,[online],2007年 7月23日,p.1,p.31,[平成24年10月19日検索],インターネット<URL: http://www.itscj.ipsj.or.jp/forum/forum20070723/07023_forum.pdf> | Non-patent | – |
9 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 2840CHE2007 | India | – | |
| 2840CH2007 | India | A | |
| 2840CH2007 | India | A | |
| 2008007054 | Republic of Korea | W | |
| 2008007054 | Republic of Korea | W | |
| 2007CH20072840 | – | – | – |
| 2008007054 | – | – | – |
| IN2007CHE2840 | – | – | – |
| WO2008KR07054 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| KR20090056915A | Republic of Korea | A | |
| US2009144550A1 | United States of America | A1 | |
| WO2009069971A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009069971A3 | World Intellectual Property Organization (WIPO) | A3 | |
| CN101911581A | China | A | |
| JP2011507318A | Japan | A | |
| US8515073B2 | United States of America | B2 | |
| JP5289460B2This record | Japan | B2 | |
| KR101547696B1 | Republic of Korea | B1 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 5289460
- Publication, DOCDB
- 5289460
- Publication, EPODOC
- JP5289460B
- Application
- 2010535882
- Application, DOCDB
- 2010535882
- Application, EPODOC
- JP20100535882
Titles2
- Japanese
- 近距離通信ネットワークにおける安全な通信のためのシステム及び方法
- English
- Systems and methods for secure communication in short-range communication networks
Classification
- CPC, 8
- H04L9/0891
- H04L9/14
- H04L63/068
- H04L9/0838
- H04L9/16
- H04L2209/805
- H04W4/80
- H04L9/00
- IPC, 3
- H04L9 16
- H04L9 08
- H04W4 80