Information processing device, mobile device, and communication system for session key update
The present disclosure relates to an information processing device, a mobile device, and a communication system capable of updating a session key. A first secret is derived from a key schedule by using first communication including transmission or reception of a command for controlling second communication faster than the first communication or a response to the command, a first session key related to the first secret is derived, the first session key is used for encryption or message authentication of the first communication, a second session key is received, transmitted, or derived by using the first communication, the second session key is used for encryption or message authentication of the second communication, a third session key is received, transmitted, or derived by using the first communication, and the third session key is used instead of the second session key.
1 . An information processing device, comprising:
a central processing unit (CPU) configured to:
execute at least one of first communication or second communication, wherein, in the second communication, the CPU is further configured to one of transmit or receive a first frame including an extended packet header and first packet data;
derive a first secret from a key schedule based on the first communication;
derive a first session key related to the first secret;
protect the first communication based on the derived first session key;
one of:
receive a second session key based on the protected first communication;
one of derive or generate the second session key, and transmit the second session key, wherein the second session key is transmitted based on the protected first communication; or
derive a second secret from the key schedule and derive the second session key related to the second secret;
protect the second communication based on:
a value of a source ID,
one of a value of a virtual channel or an extended virtual channel,
one of a value of a frame counter or a value of an additional frame number, and
the second session key; and
one of transmit or receive, in the protected second communication, the first frame that further includes a frame end, wherein
the frame end includes a first extended packet footer including a first message authentication code (MAC) value for:
at least one of a part or a whole of the extended packet header, and
at least one of a part or a whole of the first packet data, and the first MAC value is based on the second session key.
2 . The information processing device according to claim 1 , wherein
the CPU is further configured to protect the second communication based on an initialization vector and the second session key, and
the initialization vector includes a value of the source ID, one of a value of the virtual channel or the extended virtual channel, and one of a value of the frame counter or a value of the additional frame number.
3 . The information processing device according to claim 1 , wherein
the first packet data stores embedded data,
the CPU is further configured to one of transmit or receive, in the protected second communication, a second extended packet footer of the embedded data including a second MAC value for at least one of a part or a whole of the embedded data, and
the second MAC value is based on the second session key.
4 . The information processing device according to claim 1 , wherein
the CPU is further configured to:
one of transmit or receive, in the second communication, a second frame including a packet header and second packet data, wherein the second packet data stores first embedded data; and
one of transmit or receive, in the protected second communication, a second MAC value for at least a part of the second packet data,
the second MAC value is based on the second session key, and
one of the transmission or the reception of the second MAC value is via the first embedded data.
5 . The information processing device according to claim 4 , wherein
the second packet data further stores second embedded data,
the CPU is further configured to one of transmit or receive, in the protected second communication, a third MAC value for at least a part of the second embedded data,
the third MAC value is based on the second session key,
one of the transmission or the reception of the third MAC value is via the second embedded data,
the second frame further includes a frame start, at least one of image data or user defined data, and a frame end,
the second embedded data is transmitted or received between the frame start and at least one of the image data or the user defined data, and
the first embedded data is transmitted or received between at least one of the image data or the user defined data and the frame end.
6 . The information processing device according to claim 4 , wherein the second frame further includes the extended packet header.
7 . The information processing device according to claim 1 , wherein
the CPU is further configured to:
one of transmit or receive, in the second communication, a line including the extended packet header and the first packet data; and
one of transmit or receive, in the protected second communication, the line that further includes the first extended packet footer including the first MAC value.
8 . The information processing device according to claim 1 , wherein
the first packet data stores first embedded data,
the CPU is further configured to one of transmit or receive, in the protected second communication, related information of a MAC mode that protects the second communication, and
one of the transmission or the reception of the related information is via one of the extended packet header protected by the second session key, or the first embedded data of the first packet data protected by the second session key.
9 . The information processing device according to claim 8 , wherein
the CPU is further configured to:
one of transmit or receive, in the second communication, the first frame that further includes a frame start; and
select a mode from at least two of a first MAC mode, a second MAC mode, or a non-MAC mode start as the MAC mode for protection of at least one of the part or the whole of the first packet data of the first frame, and
the selection of the mode is before completion of the transmission of the frame start.
10 . The information processing device according to claim 1 , wherein
the CPU is further configured to:
one of transmit or receive, in the protected first communication, a first key ID indicating a number of a key slot corresponding to the second session key; and
one of transmit or receive, in the protected second communication, related information of the first key ID,
the related information indicates that the second communication is protected by the second session key,
the second communication is faster than the first communication, and
the related information of the first key ID has a smaller data amount than a data amount of the first key ID.
11 . The information processing device according to claim 1 , wherein
the CPU is further configured to one of transmit or receive, in the protected second communication, first embedded data protected by the second session key,
the first embedded data includes related information of a first key ID, and
the related information of the first key ID indicates that the second communication is protected by the second session key.
12 . The information processing device according to claim 11 , wherein
the CPU is further configured to:
one of:
receive a third session key based on the protected first communication;
one of derive or generate the third session key, and transmit the third session key, wherein the third session key is transmitted based on the protected first communication; or
derive a third secret from the key schedule and derive the third session key related to the third secret;
use the third session key, instead of the second session key, for the protection of the second communication; and
one of transmit or receive, in the second communication protected by the third session key, second embedded data protected by the third session key, the second embedded data includes related information of a second key ID, and
the related information of the second key ID indicates that the second communication is protected by the third session key.
13 . The information processing device according to claim 1 , wherein
the CPU is further configured to one of transmit or receive, in the protected first communication, one of a write command or a read response protected by the first session key,
one of the write command or the read response includes related information of a first key ID, and
the related information includes an indication to start usage of the second session key for the second communication.
14 . The information processing device according to claim 13 , wherein
the CPU is further configured to:
one of:
receive a third session key based on the protected first communication;
one of derive or generate the third session key, and transmit the third session key, wherein the third session key is transmitted based on the protected first communication; or
derive a third secret from the key schedule and derive the third session key related to the third secret; and
one of transmit or receive, in the protected first communication, one of the write command or the read response protected by the first session key,
one of the write command or the read response further includes related information of a second key ID,
the related information of the second key ID includes an indication to start usage of the third session key for the second communication, and
the second communication is protected based on the third session key, instead of the second session key.
15 . The information processing device according to claim 1 , wherein
the CPU is further configured to:
one of:
receive a third session key based on the protected first communication;
one of derive or generate the third session key, and transmit the third session key, wherein the third session key is transmitted based on the protected first communication; or
derive a third secret from the key schedule and derive the third session key related to the third secret; and
one of transmit or receive, in the protected second communication, a use start timing designation of the third session key, and
the second communication is protected based on the third session key, instead of the second session key.
16 . The information processing device according to claim 1 , wherein
the CPU is further configured to:
one of:
receive a third session key based on the protected first communication;
one of derive or generate the third session key, and transmit the third session key, wherein the third session key is transmitted based on the protected first communication; or
derive a third secret from the key schedule and derive the third session key related to the third secret; and
start usage of the third session key, instead of the second session key, for calculation of a second MAC value for at least a part of embedded data.
17 . The information processing device according to claim 1 , wherein
the CPU is further configured to:
one of:
receive a third session key based on the protected first communication;
one of derive or generate the third session key, and transmit the third session key, wherein the third session key is transmitted based on the protected first communication; or
derive a third secret from the key schedule and derive the third session key related to the third secret; and
alternately update the second session key and the third session key.
18 . A mobile device, comprising:
a central processing unit (CPU) configured to:
execute at least one of first communication or second communication, wherein, in the second communication, the CPU is further configured to one of transmit or receive a frame including an extended packet header and packet data;
derive a first secret from a key schedule based on the first communication;
derive a first session key related to the first secret;
protect the first communication based on the derived first session key;
one of:
receive a second session key based on the protected first communication;
one of derive or generate the second session key, and transmit the second session key, wherein the second session key is transmitted based on the protected first communication; or
derive a second secret from the key schedule and derive the second session key related to the second secret;
protect the second communication based on:
a value of a source ID,
one of a value of a virtual channel or an extended virtual channel,
one of a value of a frame counter or a value of an additional frame number, and
the second session key; and
one of transmit or receive, in the protected second communication, the frame that further includes a frame end, wherein
the frame end includes a first extended packet footer including a first message authentication code (MAC) value for:
at least one of a part or a whole of the extended packet header, and
at least one of a part or a whole of the packet data, and
the first MAC value is based on the second session key.
19 . A communication system, comprising:
a central processing unit (CPU) configured to:
execute at least one of first communication or second communication, wherein, in the second communication, the CPU is further configured to one of transmit or receive a frame including an extended packet header and packet data;
derive a first secret from a key schedule based on the first communication;
derive a first session key related to the first secret;
protect the first communication based on the derived first session key;
one of:
receive a second session key based on the protected first communication;
one of derive or generate the second session key, and transmit the second session key, wherein the second session key is transmitted based on the protected first communication; or
derive a second secret from the key schedule and derive the second session key related to the second secret;
protect the second communication based on:
a value of a source ID,
one of a value of a virtual channel or an extended virtual channel,
one of a value of a frame counter or a value of an additional frame number, and
the second session key; and
one of transmit or receive, in the protected second communication, the frame that further includes a frame end, wherein
the frame end includes a first extended packet footer including a first message authentication code (MAC) value for:
at least one of a part or a whole of the extended packet header, and
at least one of a part or a whole of the packet data, and
the first MAC value is based on the second session key.
20 . An information processing device, comprising:
a central processing unit (CPU) configured to:
execute at least one of first communication or second communication;
derive a first secret from a key schedule based on the first communication;
derive a first session key related to the first secret;
protect the first communication based on the first session key;
one of:
receive a second session key based on the protected first communication;
one of derive or generate the second session key, and transmit the second session key, wherein the second session key is transmitted based on the protected first communication; or
derive a second secret from the key schedule and derive the second session key related to the second secret;
protect the second communication based on:
a value of a source ID,
one of a value of a virtual channel or an extended virtual channel,
one of a value of a frame counter or a value of an additional frame number, and
the second session key; and
one of transmit or receive, in the protected second communication, embedded data protected by the second session key, wherein
the embedded data includes related information of a first key ID, and
the related information of the first key ID indicates that the second communication is protected by the second session key.