IP Library › Granted Patent US 10,116,454
Granted Patent B2
US 10,116,454 · App. 14/930,034 · Granted Oct 30, 2018

Authentication system and authentication method

Inventors: Tomoyuki Haga (Nara, JP); Motoji Ohmori (Osaka, JP); Natsume Matsuzaki (Osaka, JP); Hideki Matsushima (Osaka, JP); Yuji Unagami (Osaka, JP); Manabu Maeda (Osaka, JP); Yoshihiro Ujiie (Osaka, JP)
Assignee: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
H04L9/3268G06F21/33G06F21/44H04L9/14H04L9/30H04L63/06H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,454
App. No.
14/930,034
Granted
Oct 30, 2018
Kind
B2
Abstract

In an authentication method according to the present disclosure, (1) a device transmits device history information with a CRL added thereto (hereinafter, device history information with added CRL) to a controller, (2) the controller transmits the device history information with added CRL to a server, and (3) if the version of the CRL included in the device history information with added CRL is older than the version of the CRL stored on the server, the server judges that the controller is unauthorized.

Claims (39)

1. An authentication method in an authentication system including a server, a device, and a first controller that controls the device, the authentication method comprising:

storing, at the device, a first certificate revocation list and device history information, the first certificate revocation list having first age-identifying information;

storing, at the server, a second certificate revocation list, the second certificate revocation list having second age-identifying information;

transmitting, from the device to the first controller, device history information with the first age-identifying information of the first certificate revocation list;

transmitting, from the first controller to the server, the device history information with the first age-identifying information of the first certificate revocation list and added authentication information;

comparing, at the server, the first age-identifying information of the first certificate revocation list to the second age-identifying information of the second certificate revocation list;

if the first age-identifying information is indicated to be older than the second age-identifying information, judging that the first controller is unauthorized; and

if the first age-identifying information is indicated to be same as or younger than the second age-identifying information, judging that the first controller is authorized and judging that the first controller is set to receive an updated certificate revocation list from the server,

wherein, when the first controller is judged to be unauthorized, the server no longer transmits the updated certificate revocation list to the first controller.

2. The authentication method according to claim 1 , wherein

when the server judges that the first controller is unauthorized,

the server transmits the second certificate revocation list to a second controller connected to the device,

the second controller transmits the second certificate revocation list to the device, and

the device updates the first certificate revocation list with the second certificate revocation list.

3. The authentication method according to claim 1 , wherein

when the server judges that the first controller is unauthorized,

the server

records unauthorized determination information indicating that the first controller is unauthorized,

when there is a process request from the first controller, references the unauthorized determination information, and

rejects the process request from the first controller, such that the server does not perform a process specified in the process request.

4. The authentication method according to claim 1 , wherein

when the server judges that the first controller is unauthorized,

the server transmits the second certificate revocation list to the device, and

the device updates the first certificate revocation list with the second certificate revocation list.

5. The authentication method according to claim 1 , wherein the device history information includes authentication information.

6. The authentication method according to claim 1 , wherein at least one of the first age-identifying information and the second age-identifying information is a time stamp.

7. An authentication system comprising:

a server;

a device; and

a controller that controls the device, wherein

the device stores a first certificate revocation list and device history information, the first certificate revocation list having first age-identifying information,

the server stores a second certificate revocation list, the second certificate revocation list having second age-identifying information,

the device transmits, to the controller, device history information with the first age-identifying information of the first certificate revocation list,

the controller transmits, to the server, the device history information with the first age-identifying information of the first certificate revocation list and added authentication information,

the server compares the first age-identifying information of the first certificate revocation list to the second age-identifying information of the second certificate revocation list,

if the first age-identifying information is indicated to be older than the second age-identifying information, judges that the controller is unauthorized, and

if the first age-identifying information is indicated to be same as or younger than the second age-identifying information, judging that the controller is authorized and judging that the controller is set to receive an updated certificate revocation list from the server,

wherein, when the controller is judged to be unauthorized, the server no longer transmits the updated certificate revocation list to the controller.

8. A device, connected to the authentication system according to claim 7 .

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2020
From: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
To: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
Reel/Frame 053728/0440 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2015
From: HAGA, TOMOYUKI; OHMORI, MOTOJI; MATSUZAKI, NATSUME; MATSUSHIMA, HIDEKI; UNAGAMI, YUJI; MAEDA, MANABU; UJIIE, YOSHIHIRO
To: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
Reel/Frame 037042/0670 →
Continuity (3)
Continuation PCTJP2014004747 · Sep 16, 2014
Provisional Application 61916521 · Dec 16, 2013
Related Publication 20170012785A1 · Jan 12, 2017