WO2024009355A1 - 認証システム、認証方法、プログラム - Google Patents
認証システム、認証方法、プログラム Download PDFInfo
- Publication number
- WO2024009355A1 WO2024009355A1 PCT/JP2022/026598 JP2022026598W WO2024009355A1 WO 2024009355 A1 WO2024009355 A1 WO 2024009355A1 JP 2022026598 W JP2022026598 W JP 2022026598W WO 2024009355 A1 WO2024009355 A1 WO 2024009355A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- authentication information
- external system
- unit
- slave
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/321—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority
- H04L9/3213—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving a third party or a trusted authority using tickets or tokens, e.g. Kerberos
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3228—One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
- H04L9/3268—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/30—Services specially adapted for particular environments, situations or purposes
- H04W4/40—Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
- H04W4/46—Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P] for vehicle-to-vehicle communication [V2V]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
Definitions
- the present invention relates to an authentication system, an authentication method, and a program for authenticating an unmanned aircraft.
- unmanned aerial vehicles vehicles or transportation machines without humans on board
- the possibility of grouping unmanned aerial vehicles together to provide services is being considered, and there will be a need to securely manage a huge number of unmanned aerial vehicles in the future. is expected to appear.
- Non-Patent Document 1 As a method for realizing the authentication of IoT devices and unmanned aerial vehicles, a system (Non-Patent Document 1) has been disclosed in which electronic certificates and private keys are distributed from the central system side to IoT devices and unmanned aerial vehicles.
- Figure 1 shows an example of the configuration of a service provision system using unmanned aerial vehicles that may be realized in the future.
- a central control system 92 there are a central control system 92, N groups 93 including a base unit 931 and a slave unit 932 (93-1,..., 93-n,..., 93-N, N is integer greater than or equal to 1).
- the parent device 931 belonging to the n-th group is expressed as a parent device 931-n.
- the number of slave units 932 in each group is M (M is an integer of 1 or more), but the number of slave units 932 may be different for each group.
- a slave unit 932 that belongs to the n-th group and is the m-th unit within the group is expressed as a slave unit 932-nm. This notation method is also followed in the examples described below.
- an object of the present invention is to provide an authentication system that can centrally manage authentication information and authority even when there are a huge number of unmanned aircraft or groups of unmanned aircraft to be managed.
- the authentication system of the present invention includes a certification authority, a central control system, a group including a master drone and a slave drone, a management system, and an external system.
- the central control system includes a first authentication information transmitter that transmits the first authentication information received from the certificate authority to the base device.
- the base unit includes an authentication unit that performs authentication with slave units belonging to the same group, and transmits a first token with an expiration date and second authentication information including the first authentication information to the authenticated slave unit.
- a second authentication information transmitter is included.
- the management system includes an authentication unit that performs authentication with the external system, and a third authentication unit that sends the second token and third authentication information including the first authentication information received from the authentication authority to the authenticated external system. Contains an information transmitter.
- the slave device and the external system include an authentication unit that performs authentication based on the second authentication information and the third authentication information.
- the authentication system of the present invention even if there are a huge number of unmanned aerial vehicles or groups of unmanned aerial vehicles to be managed, their authentication information and authority can be centrally managed.
- FIG. 1 is a diagram illustrating a configuration example of a service providing system using an unmanned vehicle that may be realized in the future.
- 1 is a block diagram showing a functional configuration of an authentication system according to a first embodiment
- FIG. FIG. 2 is a block diagram showing the functional configuration of a certification authority according to the first embodiment.
- 1 is a block diagram showing the functional configuration of a central control system according to a first embodiment
- FIG. FIG. 2 is a block diagram showing the functional configuration of a master device according to the first embodiment.
- FIG. 2 is a block diagram showing the functional configuration of a handset according to the first embodiment.
- 1 is a block diagram showing a functional configuration of a management system according to a first embodiment;
- FIG. 3 is a block diagram showing the functional configuration of an external system according to the first embodiment.
- FIG. 2 is a diagram schematically showing the operation of the authentication system according to the first embodiment.
- FIG. 3 is a sequence diagram showing the operation of the authentication system according to the first embodiment.
- FIG. 2 is a block diagram showing the functional configuration of an authentication system according to a second embodiment.
- FIG. 2 is a block diagram showing the functional configuration of a certificate authority according to a second embodiment.
- FIG. 3 is a block diagram showing the functional configuration of a central control system according to a second embodiment.
- FIG. 2 is a block diagram showing the functional configuration of a master device according to a second embodiment.
- FIG. 3 is a block diagram showing the functional configuration of a slave device according to a second embodiment.
- FIG. 2 is a block diagram showing the functional configuration of a management system according to a second embodiment.
- FIG. 3 is a block diagram showing the functional configuration of an external system according to a second embodiment.
- FIG. 3 is a sequence diagram showing the operation of the authentication system according to the second embodiment.
- FIG. 3 is a block diagram showing the functional configuration of an authentication system according to a third embodiment.
- FIG. 1 is a diagram showing an example of a functional configuration of a computer.
- the authentication system 1 of this embodiment includes a certification authority 11, a central control system 12, a master device 131, a slave device 132, a management system 14, and an external system 15.
- the base unit 131, slave unit 132, and external system 15 are placed in a secure environment such as TEE or SE, and each block is shown enclosed in square brackets to indicate that they are placed in the secure environment. .
- this system has N groups 13 (groups 13-1,..., groups 13-n,..., groups 13-N, where N is 1 or more) including one base unit 131 and M slave units 132. (integer)).
- a plurality of base devices 131 may belong to one group.
- the number of slave units 132 may be different for each group.
- the base unit 131 that belongs to the n-th group is expressed as base unit 131-n
- the slave unit 132 that belongs to the n-th group and corresponds to the m-th unit in the group is expressed as slave unit 132-nm.
- the certificate authority 11 includes a first authentication information issue request receiving section 111, a first authentication information transmitting section 112, a first authentication information issuing request receiving section 113, and a first authentication information transmitting section 134.
- the central control system 12 includes a first authentication information issue request transmitting section 121, a first authentication information receiving section 122, and a first authentication information transmitting section 123.
- each component 121 to 123 may be a separate device. Further, it may be configured by a device having two functions among the constituent features and a device having one function among the constituent features.
- Base device 131 includes a first authentication information receiving section 1311, an authentication section 1312, and a second authentication information transmitting section 1313.
- Handset 132 includes an authentication section 1321 , a second authentication information reception section 1322 , a communication request transmission section 1323 , an authentication section 1324 , and a service provision section 1325 .
- the management system 14 includes a first authentication information issue request transmitting section 141, a first authentication information receiving section 142, an authentication section 143, and a third authentication information transmitting section 144.
- each component 141 to 144 may be a separate device. Further, it may be configured by a device having functions of two or more of the constituent elements and a device functioning as the other constituent elements.
- the external system 15 includes an authentication section 151 , a third authentication information reception section 152 , a communication request reception section 153 , an authentication section 154 , and a service reception section 155 .
- each component 151 to 155 may be a separate device. Further, it may be configured by a device having functions of two or more of the constituent elements and a device functioning as the other constituent elements.
- the base unit 131 is equipped with a secure environment such as SE (Secure Element) and TEE (Trusted Execution Environment), and manages and distributes the authentication information (second authentication information 6, shown in the figure) of the slave unit 132.
- SE Secure Element
- TEE Trusted Execution Environment
- Only authentication information (fourth authentication information 7, shown in the figure) that allows the base unit 131 and the slave unit 132 to mutually confirm that they are legitimate terminals is distributed to the slave unit 132 in advance.
- the fourth authentication information 7 include image recognition using a pre-shared key and physical characteristics. For example, as illustrated in the same figure, when the slave unit 132-1-M that belonged to group 13-1 is reassigned to group 13-n, the base unit 131-n of group 13-n is The fourth authentication information 7 is distributed in advance to the newly assigned handset 132-1-M so that they can mutually confirm that it is a legitimate terminal.
- the management system 14 distributes authentication information (fifth authentication information A, shown in the figure) used for authentication with the external system 15 in advance.
- the first authentication information issuance request transmitting unit 121 of the central control system 12 transmits a first authentication information issuance request to the certification authority 11 (S121).
- the first authentication information issuance request receiving unit 111 of the certificate authority 11 receives the first authentication information issuance request from the central control system 12 (S111).
- the first authentication information transmitting unit 112 of the certificate authority 11 issues first authentication information and transmits it to the central control system 12 (S112).
- the first authentication information receiving unit 122 of the central control system 12 receives the first authentication information from the certificate authority 11 (S122).
- the first authentication information transmitting unit 123 of the central control system 12 transmits the first authentication information received from the certificate authority 11 to the base device 131 (S123).
- the first authentication information transmitting unit 1311 of the base device 131 receives the first authentication information from the central control system 12 (S1311).
- the authentication unit 1312 of the base device 131 performs authentication with the slave device 132 belonging to the same group (S1312).
- the aforementioned fourth authentication information 7 (FIG. 9) is used for authentication. It is preferable that the base unit 131 performs authentication with the slave unit 132 using close proximity communication (Bluetooth (registered trademark), NFC, etc.).
- This system has the feature that the base unit 131, which is an unmanned aircraft, functions as an intermediate certification authority, which is a feature not found in conventional authentication systems. , flight) and establish close proximity communication in close proximity to the handset 132, reducing the risk of spoofing and operational errors, and establishing secure communication using a method not available in conventional authentication systems. be able to.
- the authentication unit 1321 of the slave device 132 performs authentication with the base device 131 belonging to the same group (S1321).
- the aforementioned fourth authentication information 7 (FIG. 9) is used for authentication. It is preferable that the slave device 132 performs authentication with the base device 131 using proximity communication.
- the second authentication information transmitting unit 1313 of the base device 131 transmits the second authentication information including the first token with an expiration date and the first authentication information to the slave device 132 that has been authenticated in steps S1312 and S1321 ( S1313). It is preferable that the second authentication information transmitting unit 1313 of the base device 131 transmits the second authentication information to the slave device 132 using close proximity communication.
- the first token is a one-time token that the base unit 131 pays out to the slave unit 132. Authentication/authorization information and an expiration date are written in the one-time token so that it can be confirmed that the external system 15 is a legitimate partner.
- the first token may be the ID of the slave device 132.
- the second authentication information receiving unit 1322 of the handset 132 that has been authenticated in steps S1312 and S1321 receives the second authentication information from the base device 131 (S1322). It is preferable that the second authentication information receiving unit 1322 receives the second authentication information using close proximity communication.
- the first authentication information issuance request transmitting unit 141 of the management system 14 transmits a first authentication information issuance request to the certification authority 11 (S141).
- the first authentication information issuance request receiving unit 113 of the certificate authority 11 receives the first authentication information issuance request from the management system 14 (S113).
- the first authentication information transmitting unit 114 of the certificate authority 11 issues first authentication information and transmits it to the management system 14 (S114).
- the first authentication information receiving unit 142 of the management system 14 receives the first authentication information from the certificate authority 11 (S142).
- the authentication unit 151 of the external system 15 performs authentication with the management system 14 (S151).
- the fifth authentication information A (FIG. 9) described above is used for authentication.
- the authentication unit 143 of the management system 14 performs authentication with the external system 15 (S143).
- the fifth authentication information A (FIG. 9) described above is used for authentication.
- the third authentication information transmitting unit 144 of the management system 14 transmits third authentication information including the second token and the first authentication information received from the certificate authority 11 to the authenticated external system 15 (S144).
- the second token may be set to be the ID of the external system 15.
- the third authentication information receiving unit 152 of the external system 15 receives the third authentication information from the management system 14 (S152).
- the communication request transmitting unit 1323 of the handset 132 transmits a communication request to the external system 15 (S1323).
- the communication request receiving unit 153 of the external system 15 receives the communication request from the handset 132 (S153).
- the authentication unit 154 of the external system 15 performs authentication with the slave device 132, which is the source of the communication request, based on the second authentication information and the third authentication information (S154). For example, when a system is configured using an ID-based encryption method, authentication can be performed using the ID of the handset 132, the ID of the external system 15, and the private key using the method described in Reference Patent Document 1.
- Reference Patent Document 1 Japanese Unexamined Patent Publication No. 2021-019223
- the authentication unit 1324 of the handset 132 performs authentication with the external system 15, which is the destination of the communication request, based on the second authentication information and the third authentication information (S1324). Similar to step S154, when the system is configured using an ID-based encryption method, authentication can be performed using the method described in Reference Patent Document 1.
- the service providing unit 1325 of the authenticated handset 132 provides a service to the authenticated external system (S1325).
- a typical example of a service is a logistics service.
- a specific example of the external system 15 may be a baggage storage system.
- the service receiving unit 155 of the authenticated external system 15 receives the service from the authenticated handset 132 (S155). In the case of a logistics service, this operation corresponds to receiving a package.
- the authentication system 1 of this embodiment includes a certification authority 21, a central control system 22, a master device 231, a slave device 232, a management system 24, and an external system 25.
- the unmanned aircraft (base unit 231, slave unit 232) is a drone
- the management system 24 is a smart locker management system
- the external system 25 is a smart locker.
- the first authentication information is a private key
- the first token is the ID of the handset
- the second token is the ID of the external system
- the handset 232 and the external system 25 are 232
- the ID of the external system 25, and a secret key authentication is performed using an ID-based encryption method.
- Figures 12 to 17 show the functional configuration of each device and system.
- the names of the constituent elements of each device and system are the same as in the first embodiment, and some of the symbols have been changed.
- the certificate authority 21 includes a first authentication information issue request receiving section 211, a first authentication information transmitting section 212, a first authentication information issuing request receiving section 213, and a first authentication information transmitting section 234.
- the central control system 22 includes a first authentication information issue request transmitting section 221, a first authentication information receiving section 222, and a first authentication information transmitting section 223, and the base device 231 includes a first authentication information receiving section 2311 and a first authentication information receiving section 223.
- an authentication section 2312, a second authentication information transmission section 2313, and the handset 232 includes an authentication section 2321, a second authentication information reception section 2322, a communication request transmission section 2323, an authentication section 2324, and a service provision section.
- the management system 24 includes a first authentication information issue request sending unit 241, a first authentication information receiving unit 242, an authentication unit 243, and a third authentication information sending unit 244, and the external system 25 includes 251 , a third authentication information receiving section 252 , a communication request receiving section 253 , an authentication section 254 , and a service receiving section 255 .
- the base unit 231, slave unit 232, and external system 25 are placed in a secure environment such as TEE or SE, and each block is shown enclosed in square brackets to indicate that they are placed in the secure environment.
- an intermediate key issuing authority (intermediate KGC) under the certification authority 21 which is a root key issuing authority (KGC) is located within the secure environment of the base device 231 and in the management system 24.
- steps S121, S111, S112, S122, S123, and S1311 of the first embodiment the operations in which the first authentication information is replaced with the private key are executed according to the components with the same names.
- Steps S2312, S2321 The same operations as steps S1312 and S1321 in the first embodiment are respectively executed by constituent elements with the same names.
- Steps S2313, S2322> the operation of reading the first token ⁇ delivery host information, the ID (public key) of the handset 232 incorporating the authority expiration date, and the first authentication information ⁇ private key is the same name. Each is executed according to its configuration requirements.
- Steps S241, S213, S214, S242> In steps S141, S113, S114, and S142 of the first embodiment, the operations in which the first authentication information is replaced with the private key are executed by the components with the same name.
- Steps S251, S243> The same operations as steps S151 and S143 in the first embodiment are respectively executed by constituent elements with the same names.
- Steps S244, S252 In steps S144 and S152 of the first embodiment, the operations in which the second token is replaced with the ID of the external system 25 (smart locker) and the first authentication information are replaced with the private key are executed according to the components with the same name.
- Steps S2323, S253 The same operations as steps S1323 and S153 in the first embodiment are respectively executed by constituent elements with the same names.
- Steps S2325, S255> The same operations as steps S1325 and S155 in the first embodiment are respectively executed by constituent elements with the same names.
- the content of the service is the delivery of packages by a drone formation, this corresponds to delivery and receipt of the delivered items.
- the unmanned aircraft (base unit and slave unit) that appeared in Examples 1 and 2 are not autonomously moving drones, but are replaced with fixedly installed IoT devices 331 and 332. Good too.
- the authentication system 3 of the third embodiment is configured by replacing the unmanned devices (base unit, slave unit) in the first embodiment with IOT devices (base unit 331, slave unit 332).
- Authentication systems 1 to 3 in Examples 1 to 3 are not limited to hierarchical ID-based encryption, and may be configured to provide other authentication means, including, for example, hierarchical ID-based encryption with a revocation function.
- a configuration may be used in which a public key infrastructure is utilized and an intermediate CA is placed in the parent device, or it may be realized by a unique authentication method in which the parent device can issue authentication information.
- the device of the present invention includes, as a single hardware entity, an input section to which a keyboard or the like can be connected, an output section to which a liquid crystal display or the like can be connected, and a communication device (for example, a communication cable) capable of communicating with the outside of the hardware entity.
- a communication unit that can be connected to a CPU (Central Processing Unit, which may include cache memory, registers, etc.), RAM and ROM that are memories, external storage devices that are hard disks, and their input units, output units, and communication units. , CPU, RAM, ROM, and an external storage device.
- the hardware entity may be provided with a device (drive) that can read and write a recording medium such as a CD-ROM.
- a physical entity with such hardware resources includes a general-purpose computer.
- the external storage device of the hardware entity stores the program required to realize the above-mentioned functions and the data required for processing this program (not limited to the external storage device, for example, when reading the program (It may be stored in a ROM, which is a dedicated storage device.) Further, data obtained through processing of these programs is appropriately stored in a RAM, an external storage device, or the like.
- each program stored in an external storage device or ROM, etc.
- the data necessary for processing each program are read into memory as necessary, and are interpreted and executed and processed by the CPU as appropriate.
- the CPU realizes predetermined functions (each of the constituent elements expressed as . . . units, . . . means, etc.).
- the processing functions of the hardware entity (device of the present invention) described in the above embodiments are realized by a computer, the processing contents of the functions that the hardware entity should have are described by a program. By executing this program on a computer, the processing functions of the hardware entity are realized on the computer.
- a program that describes this processing content can be recorded on a computer-readable recording medium.
- the computer-readable recording medium may be of any type, such as a magnetic recording device, an optical disk, a magneto-optical recording medium, or a semiconductor memory.
- magnetic recording devices include hard disk drives, flexible disks, magnetic tapes, etc.
- optical disks include DVDs (Digital Versatile Discs), DVD-RAMs (Random Access Memory), and CD-ROMs (Compact Discs Read Only). Memory), CD-R (Recordable)/RW (ReWritable), etc. as magneto-optical recording media, MO (Magneto-Optical disc), etc. as semiconductor memory, EEP-ROM (Electrically Erasable and Programmable-Read Only Memory), etc. can be used.
- this program is performed, for example, by selling, transferring, lending, etc. portable recording media such as DVDs and CD-ROMs on which the program is recorded. Furthermore, this program may be distributed by storing the program in the storage device of the server computer and transferring the program from the server computer to another computer via a network.
- a computer that executes such a program for example, first stores a program recorded on a portable recording medium or a program transferred from a server computer in its own storage device. When executing a process, this computer reads a program stored in its own recording medium and executes a process according to the read program. In addition, as another form of execution of this program, the computer may directly read the program from a portable recording medium and execute processing according to the program, and furthermore, the program may be transferred to this computer from the server computer. The process may be executed in accordance with the received program each time.
- ASP Application Service Provider
- the above-mentioned processing is executed by a so-called ASP (Application Service Provider) service, which does not transfer programs from the server computer to this computer, but only realizes processing functions by issuing execution instructions and obtaining results.
- ASP Application Service Provider
- the hardware entity is configured by executing a predetermined program on a computer, but at least a part of these processing contents may be implemented in hardware.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Lock And Its Accessories (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
まず、中央制御システム12の第1認証情報発行依頼送信部121は、認証局11に第1の認証情報発行依頼を送信する(S121)。
認証局11の第1認証情報発行依頼受信部111は、中央制御システム12から第1の認証情報発行依頼を受信する(S111)。
認証局11の第1認証情報送信部112は第1の認証情報を発行し、中央制御システム12に送信する(S112)。
中央制御システム12の第1認証情報受信部122は、認証局11から第1の認証情報を受信する(S122)。
中央制御システム12の第1認証情報送信部123は、認証局11から受信した第1の認証情報を親機131に送信する(S123)。
親機131の第1認証情報送信部1311は、中央制御システム12から第1の認証情報を受信する(S1311)。
親機131の認証部1312は、同じグループに属する子機132との認証を実行する(S1312)。認証には前述した第4の認証情報7(図9)が用いられる。親機131は近接通信(Bluetooth(登録商標),NFCなど)を用いて子機132との認証を実行すれば好適である。
子機132の認証部1321は、同じグループに属する親機131との認証を実行する(S1321)。認証には前述した第4の認証情報7(図9)が用いられる。子機132は近接通信を用いて親機131との認証を実行すれば好適である。
親機131の第2認証情報送信部1313は、ステップS1312,S1321で認証済みの子機132に有効期限付きの第1のトークンと第1の認証情報を含む第2の認証情報を送信する(S1313)。親機131の第2認証情報送信部1313は、近接通信を用いて子機132に第2の認証情報を送信すれば好適である。
ステップS1312,S1321で認証済みの子機132の第2認証情報受信部1322は、親機131から第2の認証情報を受信する(S1322)。第2認証情報受信部1322は、近接通信を用いて第2の認証情報を受信すれば好適である。
管理システム14の第1認証情報発行依頼送信部141は、認証局11に第1の認証情報発行依頼を送信する(S141)。
認証局11の第1認証情報発行依頼受信部113は、管理システム14から第1の認証情報発行依頼を受信する(S113)。
認証局11の第1認証情報送信部114は第1の認証情報を発行し、管理システム14に送信する(S114)。
管理システム14の第1認証情報受信部142は、認証局11から第1の認証情報を受信する(S142)。
外部システム15の認証部151は、管理システム14との認証を実行する(S151)。認証には前述した第5の認証情報A(図9)が用いられる。
管理システム14の認証部143は、外部システム15との認証を実行する(S143)。認証には前述した第5の認証情報A(図9)が用いられる。
管理システム14の第3認証情報送信部144は、認証済みの外部システム15に第2のトークンと認証局11から受信した第1の認証情報を含む第3の認証情報を送信する(S144)。例えばシステムをIDベース暗号方式で組む場合、第2のトークン=外部システム15のIDとすればよい。
外部システム15の第3認証情報受信部152は、管理システム14から第3の認証情報を受信する(S152)。
子機132の通信依頼送信部1323は、外部システム15に通信依頼を送信する(S1323)。
外部システム15の通信依頼受信部153は、子機132から通信依頼を受信する(S153)。
外部システム15の認証部154は、第2の認証情報と第3の認証情報に基づいて、通信依頼の送信元である子機132との認証を実行する(S154)。例えばシステムをIDベース暗号方式で組む場合、子機132のID、外部システム15のID、秘密鍵を用いて、参考特許文献1に記載の方法で認証を実行することができる。
<子機132-認証部1324>
子機132の認証部1324は、第2の認証情報と第3の認証情報に基づいて、通信依頼の送信先である外部システム15との認証を実行する(S1324)。ステップS154と同様、システムをIDベース暗号方式で組む場合、参考特許文献1に記載の方法で認証を実行することができる。
認証済みの子機132のサービス提供部1325は、認証済みの外部システムに対して、サービスを提供する(S1325)。サービスの典型例として、物流サービスなどがある。外部システム15の具体例として荷物を預かるシステムなどが考えられる。
認証済みの外部システム15のサービス受取部155は、認証済みの子機132からサービスを受け取る(S155)。物流サービスであればこの動作は荷物の受け取りに該当する。
実施例1のステップS121,S111,S112,S122,S123,S1311において、第1の認証情報→秘密鍵と読み替えた動作が、同名の構成要件によりそれぞれ実行される。
実施例1のステップS1312,S1321と同じ動作が、同名の構成要件によりそれぞれ実行される。
実施例1のステップS1313,S1322において、第1のトークン→配送主情報、権限有効期限を組み込んだ子機232のID(公開鍵)、第1の認証情報→秘密鍵と読み替えた動作が、同名の構成要件によりそれぞれ実行される。
実施例1のステップS141,S113,S114,S142において、第1の認証情報→秘密鍵と読み替えた動作が、同名の構成要件によりそれぞれ実行される。
実施例1のステップS151,S143と同じ動作が、同名の構成要件によりそれぞれ実行される。
実施例1のステップS144,S152において、第2のトークン→外部システム25(スマートロッカー)のID、第1の認証情報→秘密鍵と読み替えた動作が、同名の構成要件によりそれぞれ実行される。
実施例1のステップS1323,S153と同じ動作が、同名の構成要件によりそれぞれ実行される。
ステップS2324、S254については、子機232のID、外部システム25(スマートロッカー)のID、秘密鍵を用いて、参考特許文献1に記載の方法で認証を実行することができる。
実施例1のステップS1325,S155と同じ動作が、同名の構成要件によりそれぞれ実行される。本実施例では、ドローン編隊による荷物の配送をサービスの内容としているため、配送物の引渡、受取に該当する。
実施例1~3の認証システム1~3は、階層型IDベース暗号に限らず、例えば失効機能付き階層型IDベース暗号を含む、他の認証手段を用意する形態でも良い。例えば、公開鍵基盤を活用し、親機に中間CAを配置するような構成でも良いし、親機が認証情報を発行可能な独自の認証方法によって実現されても良い。
本発明の装置は、例えば単一のハードウェアエンティティとして、キーボードなどが接続可能な入力部、液晶ディスプレイなどが接続可能な出力部、ハードウェアエンティティの外部に通信可能な通信装置(例えば通信ケーブル)が接続可能な通信部、CPU(Central Processing Unit、キャッシュメモリやレジスタなどを備えていてもよい)、メモリであるRAMやROM、ハードディスクである外部記憶装置並びにこれらの入力部、出力部、通信部、CPU、RAM、ROM、外部記憶装置の間のデータのやり取りが可能なように接続するバスを有している。また必要に応じて、ハードウェアエンティティに、CD-ROMなどの記録媒体を読み書きできる装置(ドライブ)などを設けることとしてもよい。このようなハードウェア資源を備えた物理的実体としては、汎用コンピュータなどがある。
Claims (8)
- 認証局と、中央制御システムと、親機である無人機と子機である無人機を含むグループと、管理システムと、外部システムを含む認証システムであって、
前記中央制御システムは、
前記認証局から受信した第1の認証情報を前記親機に送信する第1認証情報送信部を含み、
前記親機は、
同じグループに属する前記子機との認証を実行する認証部と、
認証された前記子機に有効期限付きの第1のトークンと前記第1の認証情報を含む第2の認証情報を送信する第2認証情報送信部を含み、
前記管理システムは、
前記外部システムとの認証を実行する認証部と、
認証された前記外部システムに第2のトークンと前記認証局から受信した前記第1の認証情報を含む第3の認証情報を送信する第3認証情報送信部を含み、
前記子機と前記外部システムは、
前記第2の認証情報と前記第3の認証情報に基づいて認証を実行する認証部を含む
認証システム。 - 請求項1に記載の認証システムであって、
前記親機の前記認証部は、
近接通信を用いて前記子機との認証を実行する
認証システム。 - 請求項1に記載の認証システムであって、
前記親機の前記第2認証情報送信部は、
近接通信を用いて前記子機に前記第2の認証情報を送信する
認証システム。 - 請求項2または3に記載の認証システムであって、
前記無人機はドローンであり、
前記外部システムはスマートロッカーである
認証システム。 - 請求項1から3の何れかに記載の認証システムであって、
前記第1の認証情報は秘密鍵であり、
前記第1のトークンは、前記子機のIDであり、
前記第2のトークンは、前記外部システムのIDであり、
前記子機と前記外部システムは、
前記子機のIDと、前記外部システムのIDと、前記秘密鍵に基づいて、IDベース暗号方式により認証を実行する
認証システム。 - 認証局と、中央制御システムと、親機である無人機と、子機である無人機と、管理システムと、外部システムが実行する認証方法であって、
前記中央制御システムは、
前記認証局から受信した第1の認証情報を前記親機に送信するステップを実行し、
前記親機は、
同じグループに属する前記子機との認証を実行するステップと、
認証された前記子機に有効期限付きの第1のトークンと前記第1の認証情報を含む第2の認証情報を送信するステップを実行し、
前記管理システムは、
前記外部システムとの認証を実行するステップと、
認証された前記外部システムに第2のトークンと前記認証局から受信した前記第1の認証情報を含む第3の認証情報を送信するステップを実行し、
前記子機と前記外部システムは、
前記第2の認証情報と前記第3の認証情報に基づいて認証を実行するステップを実行する
認証方法。 - コンピュータを請求項1に記載の中央制御システムとして機能させるプログラム。
- 無人機を請求項1に記載の親機、または子機として機能させるプログラム。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2022/026598 WO2024009355A1 (ja) | 2022-07-04 | 2022-07-04 | 認証システム、認証方法、プログラム |
| JP2024531764A JP7750413B2 (ja) | 2022-07-04 | 2022-07-04 | 認証システム、認証方法、プログラム |
| US18/880,556 US20250392464A1 (en) | 2022-07-04 | 2022-07-04 | Authentication system, authentication method, and program |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2022/026598 WO2024009355A1 (ja) | 2022-07-04 | 2022-07-04 | 認証システム、認証方法、プログラム |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024009355A1 true WO2024009355A1 (ja) | 2024-01-11 |
Family
ID=89452925
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2022/026598 Ceased WO2024009355A1 (ja) | 2022-07-04 | 2022-07-04 | 認証システム、認証方法、プログラム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20250392464A1 (ja) |
| JP (1) | JP7750413B2 (ja) |
| WO (1) | WO2024009355A1 (ja) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2018074253A (ja) * | 2016-10-25 | 2018-05-10 | 国立研究開発法人情報通信研究機構 | 無人航空機を介した暗号鍵共有システム、無人航空機による信号伝送システム、無人航空機 |
| US20180279105A1 (en) * | 2014-08-19 | 2018-09-27 | Aeryon Labs Inc. | Secure system for emergency-mode operation, system monitoring and trusted access vehicle location and recovery |
| US20200007384A1 (en) * | 2016-07-01 | 2020-01-02 | Intel Corporation | Internet-of-things swarm management |
-
2022
- 2022-07-04 US US18/880,556 patent/US20250392464A1/en active Pending
- 2022-07-04 WO PCT/JP2022/026598 patent/WO2024009355A1/ja not_active Ceased
- 2022-07-04 JP JP2024531764A patent/JP7750413B2/ja active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20180279105A1 (en) * | 2014-08-19 | 2018-09-27 | Aeryon Labs Inc. | Secure system for emergency-mode operation, system monitoring and trusted access vehicle location and recovery |
| US20200007384A1 (en) * | 2016-07-01 | 2020-01-02 | Intel Corporation | Internet-of-things swarm management |
| JP2018074253A (ja) * | 2016-10-25 | 2018-05-10 | 国立研究開発法人情報通信研究機構 | 無人航空機を介した暗号鍵共有システム、無人航空機による信号伝送システム、無人航空機 |
Also Published As
| Publication number | Publication date |
|---|---|
| JPWO2024009355A1 (ja) | 2024-01-11 |
| US20250392464A1 (en) | 2025-12-25 |
| JP7750413B2 (ja) | 2025-10-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Gousteris et al. | Secure distributed cloud storage based on the blockchain technology and smart contracts | |
| CN111541724B (zh) | 区块链一体机及其节点自动加入方法、装置 | |
| KR102205654B1 (ko) | 분산 환경에서의 신원 인증 방법 | |
| US9225693B2 (en) | Major management apparatus, authorized management apparatus, electronic apparatus for delegation management, and delegation management methods thereof | |
| CN111541552B (zh) | 区块链一体机及其节点自动加入方法、装置 | |
| CN112381646A (zh) | 基于区块链的隐私交易及其应用方法和装置 | |
| EP1505509A1 (en) | Information processing device and method, information processing system, recording medium, and program | |
| US20190080299A1 (en) | Cyber ownership transfer | |
| WO2009107351A1 (ja) | 情報セキュリティ装置および情報セキュリティシステム | |
| CN108694330A (zh) | 物联网数据管理方法、平台及设备 | |
| CN111034116A (zh) | 密钥管理装置、通信设备和密钥共享方法 | |
| JP2023027775A (ja) | プライバシーを維持した監査可能アカウントのためのコンピュータ実装方法、コンピュータシステム及びコンピュータプログラム(プライバシーを維持した監査可能アカウント) | |
| KR102263202B1 (ko) | 분산 ID 를 이용한 IoT 디바이스의 인증 방법 및 시스템 | |
| KR20230094891A (ko) | 연합 학습 시스템 및 그 동작 방법 | |
| CN114928617B (zh) | 专网签约数据管理方法、装置、设备及介质 | |
| JP7750413B2 (ja) | 認証システム、認証方法、プログラム | |
| JP6919484B2 (ja) | 暗号通信方法、暗号通信システム、鍵発行装置、プログラム | |
| WO2022166278A1 (zh) | 数据处理方法、装置和存储介质 | |
| JP7327208B2 (ja) | データ記録装置、データ記録方法、データ記録プログラム、システム、方法、および、プログラム | |
| CN101366088A (zh) | 用于提供、分发并刻录数字数据的方法及关联分发服务器 | |
| JP2025092374A (ja) | 車両システム内のデバイスを管理するためのシステムおよび方法 | |
| Pérez‐Solà et al. | BArt: Trading digital contents through digital assets | |
| CN111639352B (zh) | 电子证明的生成方法、装置、电子设备及可读存储介质 | |
| KR102813292B1 (ko) | 콘텐츠 월렛을 활용한 콘텐츠 거래 시스템 및 그 제어 방법 | |
| WO2022264205A1 (ja) | データ処理システム、秘密計算装置、データ処理方法、プログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22950150 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024531764 Country of ref document: JP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18880556 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22950150 Country of ref document: EP Kind code of ref document: A1 |