Abstract: The present invention relates to a mutual authentication method and an authentication device for providing the method, and an authentication device of the present invention comprises: an authentication communication unit for receiving first identification information from an electronic device that requests primary authentication; an authentication storage unit for storing second identification information, a one-way encryption algorithm, a random number generation algorithm, and an initial vector inputted during operation of the random number generation algorithm; and an authentication control unit, which compares the first identification information with the second identification information to verify the first identification information, and determines whether to approve the primary authentication according to the verification result, wherein, if the primary authentication is approved, the authentication control unit encrypts the second identification information with the one-way encryption algorithm to generate authentication encryption text, and transmits the authentication encryption text to the electronic device to request secondary authentication, and, if a first random number is received from the electronic device in response to the secondary authentication request, inputs the second identification information and the initial vector into the random number generation algorithm to generate a second random number, compares the first random number with the second random number to verify the first random number, and determines whether to approve the secondary authentication according to the verification result.
TITLE OF THE INVENTION
“CROSS CERTIFICATION METHOD AND CERTIFYING DEVICE FOR
PROVIDING THE METHOD”
5 BACKGROUND OF THE INVENTION
(a) Field of the Invention
CROSS-REFERENCE TO RELATED APPLICATION
This application claims priority to and the benefit of Korean Patent
Application No. 10-2020-0121338 filed in the Korean Intellectual Property Office
10 on September 21, 2020, the entire contents of which are incorporated herein by
reference.
The present invention relates to a cross certification method and a
certifying device for providing the method.
(b) Description of the Related Art
15 Recently, rechargeable batteries are widely used in mobile devices such
as laptops or mobile phones, various power transportation vehicles such as
electric bicycles, electric vehicles, or hybrid vehicles, power backup devices for
supplying power in case of blackouts, and large-capacity power storage devices
for storing large-capacity power in advance and supplying power to other
20 devices.
Particularly, regarding devices for supplying a huge amount of power or
storing the same such as for electric vehicles (EV) or energy storage systems
(ESS), a battery is configured with a battery cell that is a rechargeable battery, a
battery module in which a plurality of battery cells are connected in series, and
3
a battery pack in which a plurality of battery modules are connected in series
and/or in parallel.
Particularly, the battery pack is managed by a battery management
system (BMS). The battery management system (BMS) maintains and
5 manages the battery by monitoring a voltage, a current, and a temperature of
the battery pack. The battery management system (BMS) manages the
battery system including the battery and its peripheral devices by, for example,
predicting a replacement time of the battery and checking battery drawbacks in
advance.
10 There are attempts to store various data collected by the battery
management system (BMS) for the purpose of research and development in a
remote central server. However, transmission and storage of data through a
radio network have problems such as security and certification. That is,
solutions to the drawbacks including certifying of a data transmitting device and
15 a data receiving and storing device, and security against external malicious
attacks are needed.
SUMMARY OF THE INVENTION
The present invention has been made in an effort to provide a cross
certification method for an electronic device and a certifying device to
20 respectively request a certification, approve the requested certification, and
accordingly perform a cross certification, and a certifying device for providing
the method.
An embodiment of the present invention provides a certifying device
including: a certification communication unit configured to receive first
4
identification information from an electronic device requesting a first
certification; a certification storage unit configured to store second identification
information, a unidirectional encryption algorithm, a random number generating
algorithm, and an initial vector that is input when the random number generating
5 algorithm is operated; and a certification control unit configured to compare the
first identification information and the second identification information to verify
the first identification information, and determine whether to approve the first
certification according to a result of the verification, wherein when the first
certification is approved, the certification control unit encrypts the second
10 identification information with the unidirectional encryption algorithm to generate
a certification cryptogram, and transmits the certification cryptogram to the
electronic device to request a second certification, when receiving a first
random number from the electronic device in response to the request for the
second certification, the certification control unit inputs the second identification
15 information and the initial vector to the random number generating algorithm to
generate a second random number, and the certification control unit compares
the first random number and the second random number to verify the first
random number, and determines whether to approve the second certification
according to a result of the verification.
20 The certification control unit may decrypt data that are encrypted with a
first key of a bidirectional encryption algorithm with a second key of the
bidirectional encryption algorithm, and may transmit the data encrypted with the
second key to the electronic device.
The first key may be a private key, and the second key may be a public
5
key.
The first identification information and the second identification
information may respectively include a serial number of the electronic device
and a serial number of the certifying device.
5 The certification control unit may block a network access to the
electronic device when the first identification information and the second
identification information do not correspond to each other or when the first
random number and the second random number do not correspond to each
other.
10 Another embodiment of the present invention provides a cross
certification method for a certifying device to perform a cross certification with
an electronic device including same certification information, the method
including: receiving first identification information from the electronic device
requesting a first certification; comparing the first identification information and
15 stored second identification information to verify the first identification
information; when the first identification information and the second
identification information are found to correspond to each other and pass
verification according to a result of the comparison, encrypting the second
identification information with a unidirectional encryption algorithm to generate a
20 certification cryptogram; transmitting the certification cryptogram to the
electronic device to request a second certification; receiving a first random
number from the electronic device in response to the request for the second
certification; inputting an initial vector that is input when a random number
generating algorithm is operated and the second identification information to the
6
random number generating algorithm to generate a second random number;
comparing the first random number and the second random number; and when
the first random number and the second random number are found to
correspond to each other according to a result of the comparison, determining
5 whether to approve the second certification.
The certifying device may decrypt data that are encrypted with a first key
of a bidirectional encryption algorithm with a second key of the bidirectional
encryption algorithm, and may transmit the data encrypted with the second key
to the electronic device.
10 The first key may be a private key, and the second key may be a public
key.
The first identification information and the second identification
information may respectively include a serial number of the electronic device
and a serial number of the certifying device.
15 The cross certification method may further include, after the verifying of
first identification information, blocking a network access to the electronic device
when the first identification information and the second identification information
are found to not correspond to each other according to a result of the
comparison.
20 The cross certification method may further include, after the comparing
of the first random number and the second random number, blocking a network
access to the electronic device when the first random number and the second
random number are found to not correspond to each other.
WHAT IS CLAIMED IS:
1. A certifying device comprising:
a certification communication unit configured to receive first identification
5 information from an electronic device requesting a first certification;
a certification storage unit configured to store second identification
information, a unidirectional encryption algorithm, a random number generating
algorithm, and an initial vector that is input when the random number generating
algorithm is operated; and
10 a certification control unit configured to compare the first identification
information and the second identification information to verify the first
identification information, and determine whether to approve the first
certification according to a result of the verification,
wherein:
15 when the first certification is approved, the certification control
unit encrypts the second identification information with the unidirectional
encryption algorithm to generate a certification cryptogram, and transmits
the certification cryptogram to the electronic device to request a second
certification,
20 when receiving a first random number from the electronic device
in response to the request for the second certification, the certification
control unit inputs the second identification information and the initial
vector to the random number generating algorithm to generate a second
random number, and
27
the certification control unit compares the first random number
and the second random number to verify the first random number, and
determines whether to approve the second certification according to a
result of the verification.
5
2. The certifying device of claim 1, wherein the certification control
unit decrypts data that are encrypted with a first key of a bidirectional encryption
algorithm with a second key of the bidirectional encryption algorithm, and
transmits the data encrypted with the second key to the electronic device.
10
3. The certifying device of claim 2, wherein the first key is a private
key, and the second key is a public key.
4. The certifying device of claim 2, wherein the first identification
15 information and the second identification information respectively include a
serial number of the electronic device and a serial number of the certifying
device.
5. The certifying device of claim 1, wherein the certification control
20 unit blocks a network access to the electronic device when the first identification
information and the second identification information do not correspond to each
other or when the first random number and the second random number do not
correspond to each other.
| # | Name | Date |
|---|---|---|
| 1 | 202217074368-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [21-12-2022(online)].pdf | 2022-12-21 |
| 2 | 202217074368-STATEMENT OF UNDERTAKING (FORM 3) [21-12-2022(online)].pdf | 2022-12-21 |
| 3 | 202217074368-REQUEST FOR EXAMINATION (FORM-18) [21-12-2022(online)].pdf | 2022-12-21 |
| 4 | 202217074368-PROOF OF RIGHT [21-12-2022(online)].pdf | 2022-12-21 |
| 5 | 202217074368-PRIORITY DOCUMENTS [21-12-2022(online)].pdf | 2022-12-21 |
| 6 | 202217074368-POWER OF AUTHORITY [21-12-2022(online)].pdf | 2022-12-21 |
| 7 | 202217074368-NOTIFICATION OF INT. APPLN. NO. & FILING DATE (PCT-RO-105-PCT Pamphlet) [21-12-2022(online)].pdf | 2022-12-21 |
| 8 | 202217074368-FORM 18 [21-12-2022(online)].pdf | 2022-12-21 |
| 9 | 202217074368-FORM 1 [21-12-2022(online)].pdf | 2022-12-21 |
| 10 | 202217074368-DRAWINGS [21-12-2022(online)].pdf | 2022-12-21 |
| 11 | 202217074368-DECLARATION OF INVENTORSHIP (FORM 5) [21-12-2022(online)].pdf | 2022-12-21 |
| 12 | 202217074368-COMPLETE SPECIFICATION [21-12-2022(online)].pdf | 2022-12-21 |
| 13 | 202217074368.pdf | 2022-12-23 |
| 14 | 202217074368-FORM 3 [08-05-2023(online)].pdf | 2023-05-08 |
| 15 | 202217074368-FER.pdf | 2024-02-02 |
| 16 | 202217074368-OTHERS [30-07-2024(online)].pdf | 2024-07-30 |
| 17 | 202217074368-FER_SER_REPLY [30-07-2024(online)].pdf | 2024-07-30 |
| 18 | 202217074368-CLAIMS [30-07-2024(online)].pdf | 2024-07-30 |
| 1 | SearchHistoryE_29-01-2024.pdf |