Information collection system and a connection control method in the information collection system

US2016294558A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016294558-A1
Application numberUS-201615075306-A
CountryUS
Kind codeA1
Filing dateMar 21, 2016
Priority dateMar 31, 2015
Publication dateOct 6, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An information collection system includes an information processing system and a gateway connected with the information processing system via a network. The information processing system includes a first server being an initial connection destination of the gateway and holding a sever certificate, a second sever being a transmission destination of measured data from the gateway, and a third server managing the first server and the second server. The third server creates a first authentication code and transmits it to the first server. The gateway creates a second authentication code and acquires the server certificate from the first server when the second authentication code matches the first authentication code.

First claim

Opening claim text (preview).

What is claimed is: 1 . An information collection system comprising: an information processing system; and a gateway connected with the information processing system via a network, wherein the information processing system includes: a first server being an initial connection destination of the gateway; a second sever being a transmission destination of measured data from the gateway; and a third server managing the first server and the second server, wherein the gateway is configured to hold: gateway information managing an identifier of the gateway and apparatus specific information of the gateway; first server connection destination information; and first server management information managing a created random number and a common key outputted in accordance with a common rule, wherein the first server is configured to hold a server certificate, wherein the third server is configured to hold gateway management information including, for each gateway, apparatus specific information, an identifier and a common key outputted in accordance with a common rule, wherein the gateway is configured to transmit a server authentication request including the created random number and the identifier of the gateway to the first server, wherein the third server is configured to: receive the server authentication request transferred from the first server and create a first authentication code based on the random number contained in the server authentication request and a common key associated with the gateway in the gateway information; and transmit a server authentication response containing first authentication code to the first server, and wherein the gateway is configured to: receive the server authentication response transferred from the first server and create a second authentication code based on the created random number and the common key in the first server management information; make first determination whether the second authentication code matches the first authentication code contained in the server authentication response; and acquire the server certificate from the first server and store the server certificate in the first server management information when the second authentication code matches the first authentication code contained in the server authentication response in the first determination. 2 . The information collection system according to claim 1 , wherein the gateway and the third server each configured to hold the common rule in advance, wherein the gateway, after activation, is configured to store the common key created based on the common rule and the apparatus specific information in the gateway information in the first server management information, and wherein the third server, after activation of the gateway, is configured to create the common key based on the common rule and the apparatus specific information of the gateway contained in the gateway management information, and store the created common key in the gateway management information. 3 . The information collection system according to claim 2 , wherein the apparatus specific information is a MAC address, and wherein the common key is an HMAC key. 4 . The information collection system according to claim 2 , wherein, the gateway is configured to: refer to the first server connection destination information and connect to the first server before transmitting the server authentication request; maintain connection between the gateway and the first server when the second authentication code matches the first authentication code in the first determination; and release the connection between the gateway and the first server when the second authentication code does not match the first authentication code in the first determination. 5 . The information collection system according to claim 2 , wherein the third server is configured to: receive the server authentication request transferred from the first server and make a second determination whether the identifier contained in the server authentication request matches an identifier in the gateway management information; create the first authentication code when the identifier contained in the server authentication request matches an identifier in the gateway management information in the second determination; and skip creating the first authentication code when the identifier contained in the server authentication request does not match any identifier in the gateway management information in the second determination. 6 . The information collection system according to claim 1 , further comprising a sensor node transmitting the measured data to the gateway. 7 . The information collection system according to claim 2 , wherein the gateway information includes a password created in accordance with a common rule, wherein the gateway is configured to transmit an entry request containing the password and the identifier of the gateway to the first server after storing the server certificate, wherein the gateway management information of the third server includes a password created in accordance with a common rule for each gateway, wherein the third server is configured to: receive the entry request transferred from the first server and make a third determination whether the password contained in the entry request matches the password for the gateway in the gateway management information; permit the gateway to enter the information processing system when the password contained in the entry request matches the password for the gateway in the gateway management information in the third determination; and prohibit the gateway from entering the information processing system when the password contained in the entry request does not match the password for the gateway in the gateway management information in the third determination. 8 . The information collection system according to claim 7 , wherein the gateway, after activation, is configured to create the password based on the common rule and the apparatus specific information of the gateway in the gateway information, and store the password in the gateway information, and wherein, after the gateway is activated, the third server is configured to create the password based on the common rule and the apparatus specific information of the gateway in the gateway management information, and store the password in the gateway management information. 9 . The information collection system according to claim 8 , wherein the third server is configured to: make a fourth determination whether the identifier of the gateway contained in the entry request matches an identifier in the gateway management information; make the third determination when the identifier of the gateway contained in the entry request matches an identifier in the gateway management information in the fourth determination; and skip making the third determination when the identifier of the gateway contained in the entry request does not match any identifier in the gateway management information in the fourth determination. 10 . The information collection system according to claim 8 , wherein the third server is configured to transmit an entry response indicating permission to the first server when permitting the gateway to enter the information processing system, wherein the gateway is configured to receive the entry response indicating permission transferred from the first server and transmit to the first server a configuration acquisition request for acquiring configuration information including connection information with the second server, wherein the third server is configured to: receive the configuration acq

Assignees

Inventors

Classifications

  • Arrangements for connecting between networks having differing types of switching systems, e.g. gateways · CPC title

  • involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements (network architectures or network communication protocols for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title

  • specially adapted for file transfer, e.g. file transfer protocol [FTP] · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • H04L9/3242Primary

    involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016294558A1 cover?
An information collection system includes an information processing system and a gateway connected with the information processing system via a network. The information processing system includes a first server being an initial connection destination of the gateway and holding a sever certificate, a second sever being a transmission destination of measured data from the gateway, and a third ser…
Who is the assignee on this patent?
Hitachi Ltd
What technology area does this patent fall under?
Primary CPC classification H04L9/3242. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 06 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).