TWI760240B - Authentication and authorization plug-in system - Google Patents
Authentication and authorization plug-in system Download PDFInfo
- Publication number
- TWI760240B TWI760240B TW110119530A TW110119530A TWI760240B TW I760240 B TWI760240 B TW I760240B TW 110119530 A TW110119530 A TW 110119530A TW 110119530 A TW110119530 A TW 110119530A TW I760240 B TWI760240 B TW I760240B
- Authority
- TW
- Taiwan
- Prior art keywords
- encryption
- decryption
- information
- packet
- authentication
- Prior art date
Links
- 238000013475 authorization Methods 0.000 title claims abstract description 25
- 238000012795 verification Methods 0.000 claims abstract description 49
- 230000002159 abnormal effect Effects 0.000 claims abstract description 17
- 238000000034 method Methods 0.000 claims abstract description 9
- 230000005540 biological transmission Effects 0.000 claims description 18
- 238000012545 processing Methods 0.000 claims description 13
- 238000012546 transfer Methods 0.000 claims description 12
- 238000004891 communication Methods 0.000 claims description 6
- 230000008569 process Effects 0.000 abstract description 3
- 238000004519 manufacturing process Methods 0.000 description 20
- 230000007246 mechanism Effects 0.000 description 16
- 238000010586 diagram Methods 0.000 description 10
- 238000013461 design Methods 0.000 description 6
- 238000005516 engineering process Methods 0.000 description 4
- 238000007726 management method Methods 0.000 description 4
- 206010000117 Abnormal behaviour Diseases 0.000 description 2
- 238000001914 filtration Methods 0.000 description 2
- 230000006855 networking Effects 0.000 description 2
- 238000001514 detection method Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000007613 environmental effect Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000004044 response Effects 0.000 description 1
Images
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
本發明是有關一種認證授權外掛系統,特別是一種能夠外掛配置一對一的加/解密器之系統,其中搭配分享共用同一組的金鑰,並將兩端傳送出來的封包透過加/解密器及同一組金鑰進行加密,並當送出至另一端的加/解密器後,則會透過同一組金鑰解密,並進行驗證時間戳記,以確認封包的完整度與安全性。The present invention relates to an authentication and authorization plug-in system, in particular to a system capable of plug-in configuration of a one-to-one encryption/decryptor, in which the pair shares and shares the same group of keys, and transmits packets sent from both ends through the encryption/decryptor and the same set of keys for encryption, and when sent to the encryption/decryptor at the other end, it will be decrypted by the same set of keys, and the timestamp will be verified to confirm the integrity and security of the packet.
目前因為科技的進步,物聯網版圖也愈來愈密集,許多工控設備的溝通技術也愈來愈成熟,機台連上網路的需求也漸漸的普及。許多的受訪結果表示,物聯網的環境投資,其重點是在繁雜的導入中,「提高安全性」是評估專案成功與否最關鍵的指標。傳統的資訊安全技術,其防護觀念基於在一般電腦設備上,認為只有電腦和伺服器才會需要考慮資安的種種防護措施,尤其在網路環境中,從傳統 Client-Server 架構,演化到萬物連網的複雜環境,加速設備進入物聯網時代;在物聯網的時代,舉凡只要涉及資料運算與儲存的裝置,包含工具機台和製造設備,都應有資安方案的部署。環境趨於複雜,駭客攻擊手法多變,物聯網資安議題趨於嚴峻。傳統在工安環境中,只需考量本地端的工安議題,但在未來的工業製造的環境中,更要面對連網以及新型態的資安威脅。At present, due to the advancement of science and technology, the layout of the Internet of Things is becoming more and more dense, the communication technology of many industrial control equipment is also becoming more and more mature, and the need for machines to connect to the Internet has gradually become popular. Many respondents indicated that the focus of IoT environmental investment is in the complex introduction, and "improving security" is the most critical indicator for evaluating the success of the project. The protection concept of traditional information security technology is based on general computer equipment. It is believed that only computers and servers need to consider various protection measures for information security, especially in the network environment, from the traditional Client-Server architecture to everything. The complex environment of networking has accelerated the entry of equipment into the era of the Internet of Things; in the era of the Internet of Things, as long as devices that involve data computing and storage, including tool machines and manufacturing equipment, should have information security solutions deployed. The environment is becoming more complex, hacker attack methods are changing, and IoT information security issues are becoming more serious. Traditionally, in the industrial safety environment, only the local end of the industrial safety issues needs to be considered, but in the future industrial manufacturing environment, it is even more necessary to face the threat of networking and new types of information security.
針對層出不窮的資安問題,在物聯網的環境中,隨著技術的創新,不斷地浮現;因此,美國家標準協會擬定 IEC62443 的標準,以期能給予智慧製造資安的框架,擬定出符合本地企業的工控安全環境。駭客若是為了能竊取到實用資訊或是勒索大筆的金錢,也逐漸將目標轉移至相對缺乏資安保護意識與措施的製造業與醫療業等 B2B 工業應用領域,導致資安威脅升高。In response to the emerging information security problems, in the Internet of Things environment, with the technological innovation, they continue to emerge; therefore, the American National Standards Institute has formulated the IEC62443 standard, in order to provide a framework for information security of smart manufacturing, and to formulate solutions that meet the needs of local enterprises. industrial control security environment. In order to steal useful information or extort large sums of money, hackers gradually shift their targets to B2B industrial applications such as manufacturing and medical industries that lack information security protection awareness and measures, resulting in increased information security threats.
傳統的工業控制系統(ICS)只佈局於本地端,授權與認證機制建立在區域網路中;在封閉式網路中,對外通訊的管道為有限,在管控上較好控管,然而,隨著網路的發達,從單點的資料傳輸到多點設備的資訊傳送,甚至到任何設備都能廣播自身的資料,傳統資料認證機制,將因溝通管道變多,而不在適用,也因為溝通管道變多,工業控制系統(ICS)反而成為駭客重點攻擊的目標,在工業物聯網的環境,由於欠缺網路攻擊的抵禦經驗,促使駭客可以輕易破壞工具設備或是竊取重要資料,而最常見的攻擊途徑即是利用內外部網路間連接的安全漏洞,去破壞工業的環境。The traditional industrial control system (ICS) is only deployed at the local end, and the authorization and authentication mechanism is established in the regional network; in the closed network, the external communication channels are limited, and the management and control are better controlled. With the development of the network, from single-point data transmission to multi-point device information transmission, and even to any device that can broadcast its own data, the traditional data authentication mechanism will become more and more communication channels. With the increase of pipelines, industrial control systems (ICS) have instead become the key targets of hackers. In the environment of the Industrial Internet of Things, due to the lack of experience in defending against cyber attacks, hackers can easily destroy tools and equipment or steal important data. The most common attack vector is to exploit the security gap between the internal and external network connections to damage the industrial environment.
而針對智慧製造環境中,生產設備一般往往基於生產彈性與生產規劃,進而忽視了對於機台的生產管理機制之控管,而在工安需求的需求下,工控設備只針對機台的異常行為做偵測,從中控設備進行權限控管與追蹤,而操作人只具有操控製造機台的權限。然而,在製造機台出現異常狀態時,卻難以追蹤出異常行為的資料,又因為即時提供可用性之需求以解決工安所發生的問題,使得一旦造成嚴重的財產損失,甚至是工安意外時,無法根本性的了解事件發生的根因。In the smart manufacturing environment, production equipment is generally based on production flexibility and production planning, and thus ignores the control of the production management mechanism of the machine. Under the needs of industrial safety requirements, the industrial control equipment only targets the abnormal behavior of the machine. For detection, the central control equipment performs authority control and tracking, and the operator only has the authority to control the manufacturing machine. However, when the manufacturing machine is in an abnormal state, it is difficult to track the data of the abnormal behavior, and because of the need to provide immediate availability to solve the problem of industrial safety, once serious property damage is caused, even in the event of an industrial safety accident , unable to fundamentally understand the root cause of the incident.
因此,本案在 M2M 環境中設計一具遠端存取控制之穩健認證機制,將針對傳統的認證機制進行強化,並結合 IEC 62443 的標準,使得設備在網路環境中,能兼具良好的資安設計,達到安全生產與機台的保護。在智慧製造環境中,為了使生產彈性提高,在製造機台間往往選擇忽視認證的機制,促使生產彈性與生產速度大幅提升,並會在針對製造機台所產生的資料,在智慧製造環境中,做保護加密機制。Therefore, in this case, a robust authentication mechanism for remote access control is designed in the M2M environment, which will strengthen the traditional authentication mechanism and combine with the IEC 62443 standard, so that the device can have good information in the network environment. Safe design to achieve safe production and machine protection. In the smart manufacturing environment, in order to improve the production flexibility, the authentication mechanism is often ignored among the manufacturing machines, which greatly improves the production flexibility and production speed. Do protection encryption mechanism.
而本案在資安設計上,協助製造業與相關供應鏈業者,清楚界定資安威脅的屬性與來源,協助改良工安環境,並同時強化物聯網環境架構設計,提供良好的資安設計機制作為解決的方案;而企業內部也應加強人員使用連網設備的管控,完善技術面與管理面的配套措施,才能有效降低工業物聯網的資安威脅所帶來的工安意外,因此本發明應為一最佳解決方案。In terms of information security design, this case helps manufacturers and related supply chain operators to clearly define the attributes and sources of information security threats, help improve the industrial security environment, and at the same time strengthen the design of the Internet of Things environment, providing a good information security design mechanism. In addition, the enterprise should also strengthen the management and control of the use of networked equipment by personnel, and improve the supporting measures on the technical and management aspects, so as to effectively reduce the industrial safety accidents caused by the information security threat of the Industrial Internet of Things. Therefore, the present invention should for the best solution.
本發明認證授權外掛系統,係設置於能夠傳送封包之第一設備與第二設備間,而該第一設備與第二設備之間更具有一封包轉傳設備,其中該第一設備與第二設備皆能夠朝向該封包轉傳設備傳出一封包資訊,其中該認證授權外掛系統係包含:一第一加/解密裝置,係以網路連接方式連接於該第一設備與該封包轉傳設備之間,而該第一加/解密裝置內係儲存有至少一組的共用金鑰,且該第一加/解密裝置係用以攔截該第一設備或是該封包轉傳設備所傳送出來的封包資訊;以及一第二加/解密裝置,係以網路連接方式連接於該第二設備與該封包轉傳設備之間,而該第二加/解密裝置亦與該第一加/解密裝置共用並儲存有該共用金鑰,且該第二加/解密裝置係用以攔截該第二設備或是該封包轉傳設備所傳送出來的封包資訊;其中該第一加/解密裝置與該第二加/解密裝置,能夠對於攔截之封包資訊以該共用金鑰解密,不論是否解密成功,皆會進行雜湊比較與時間戳記驗證,若認證成功則將解密後的資訊直接傳出,若驗證未完成則取出一組時間戳記與進行雜湊處理後、並再以共用金鑰進行加密後傳出,其中該第一設備與第二設備接收之資訊若無法辨識且需要以該共用金鑰解密,則會判斷為異常封包並進行過濾。The authentication and authorization plug-in system of the present invention is arranged between a first device capable of transmitting packets and a second device, and a packet transfer device is further provided between the first device and the second device, wherein the first device and the second device All devices can transmit a packet of information toward the packet forwarding device, wherein the authentication and authorization plug-in system includes: a first encryption/decryption device, which is connected to the first device and the packet forwarding device by means of a network connection between, and the first encryption/decryption device stores at least one set of common keys, and the first encryption/decryption device is used to intercept the first device or the packet transmission device. packet information; and a second encryption/decryption device connected between the second device and the packet transfer device in a network connection mode, and the second encryption/decryption device is also connected to the first encryption/decryption device The shared key is shared and stored, and the second encryption/decryption device is used to intercept the packet information sent by the second device or the packet forwarding device; wherein the first encryption/decryption device and the first encryption/decryption device are The second encryption/decryption device can decrypt the intercepted packet information with the shared key. Regardless of whether the decryption is successful or not, hash comparison and timestamp verification will be performed. If the authentication is successful, the decrypted information will be sent out directly. After completion, a set of time stamps are extracted and hashed, and then encrypted with the common key and sent out. If the information received by the first device and the second device cannot be identified and needs to be decrypted with the common key, then It will be judged as an abnormal packet and filtered.
更具體的說,所述第一加/解密裝置係能夠與該第二加/解密裝置進行連線或是同步資料處理,以使該第一加/解密裝置與該第二加/解密裝置能夠取得相同的共用金鑰。More specifically, the first encryption/decryption device can be connected to or synchronize data processing with the second encryption/decryption device, so that the first encryption/decryption device and the second encryption/decryption device can Get the same shared key.
更具體的說,所述第一設備或該第二設備所傳出的原始資訊能夠以AES 硬體加解密方式進行加密之後,再轉成SSHV2的封包資訊傳送出來,而該第二設備或該第一設備所接收認證成功直接傳出之解密後的資訊,則能夠以AES 硬體加解密方式進行解密,以取得另一端正確所傳出的原始資訊。More specifically, the original information sent by the first device or the second device can be encrypted by AES hardware encryption and decryption, and then converted into SSHV2 packet information for transmission, and the second device or the second device can be encrypted. The decrypted information received by the first device that is successfully authenticated and directly transmitted can be decrypted by AES hardware encryption and decryption, so as to obtain the original information correctly transmitted from the other end.
更具體的說,所述解密成功後,若解密後的資訊內包含了一原始資訊、一原始資訊的雜湊資訊及一時間戳記,則能夠對該原始資訊進行雜湊處理後,再與原始資訊的雜湊資訊進行比對是否相同,且再對時間戳記進行驗證,以驗證該時間戳記是否過期,若雜湊比對相同且時間戳記沒有過期,則判斷為認證成功,之後則能將解密後的資訊直接傳出。More specifically, after the decryption is successful, if the decrypted information includes an original information, a hashed information of the original information, and a timestamp, the original information can be hashed, and then combined with the original information. Check whether the hash information is the same, and then verify the timestamp to verify whether the timestamp has expired. If the hash comparison is the same and the timestamp has not expired, it is judged that the authentication is successful, and then the decrypted information can be directly outgoing.
更具體的說,所述認證授權外掛系統,係應用於一開放式平台通訊統一架構內。More specifically, the authentication and authorization plug-in system is applied in an open platform communication unified architecture.
更具體的說,所述第一加/解密裝置與該第二加/解密裝置係皆至少包含有至少一個處理器及至少一個電腦可讀取記錄媒體,該等電腦可讀取記錄媒體儲存有至少一個加解密應用程式,其中該電腦可讀取記錄媒體更進一步儲存有電腦可讀取指令,當由該等處理器執行該等電腦可讀取指令時,能夠使該加解密應用程式進行運作,進行攔截該第一設備或是該封包轉傳設備所傳送出來的封包資訊,並使用該共用金鑰解密並進行雜湊比較與時間戳記驗證,若認證成功則將解密後的資訊直接傳出,若驗證未完成則取出一組時間戳記與進行雜湊處理後、並再以共用金鑰進行加密後傳出。More specifically, both the first encryption/decryption device and the second encryption/decryption device include at least one processor and at least one computer-readable recording medium, and the computer-readable recording medium stores the At least one encryption/decryption application program, wherein the computer-readable recording medium further stores computer-readable instructions, which, when executed by the processors, enable the encryption/decryption application program to operate , intercept the packet information sent by the first device or the packet forwarding device, and use the shared key to decrypt and perform hash comparison and timestamp verification. If the authentication is successful, the decrypted information will be transmitted directly. If the verification is not completed, a set of time stamps are extracted and hashed, and then encrypted with the shared key and sent out.
更具體的說,所述加解密應用程式係至少包含有:一封包攔截單元,用以攔截該第一設備或是該封包轉傳設備所傳送出來的封包資訊;一共用金鑰存放單元,用以接收儲存有該共用金鑰;一解密單元,係與該封包攔截單元及該共用金鑰存放單元相連接,用以依據該共用金鑰對所攔截的封包資訊進行解密,而不論是否解密成功,皆會把解密後的資訊傳出;一驗證比對單元,係與該解密單元相連接,用以將該解密單元解密後的資訊進行雜湊比較與時間戳記驗證,其中能夠對解密後的資訊進行雜湊處理後,再比對雜湊結果是否相同,並亦對時間戳記進行驗證,以驗證該時間戳記是否過期,若雜湊比對相同且時間戳記沒有過期,則判斷為認證成功;一封包傳送單元,係與該驗證比對單元相連接,用以接收已完成雜湊比較與時間戳記驗證之解密後的資訊,並將解密後的資訊直接傳送出去;以及一加密單元,係與該共用金鑰存放單元、驗證比對單元及該封包傳送單元相連接,用以接收沒有完成雜湊比較或是時間戳記驗證之解密後的資訊,並取出一組時間戳記與進行雜湊處理後,再依據該共用金鑰進行解密,最後再由該封包傳送單元傳送出去。More specifically, the encryption/decryption application program includes at least: a packet interception unit for intercepting the packet information sent by the first device or the packet forwarding device; a common key storage unit for to receive and store the shared key; a decryption unit is connected to the packet interception unit and the shared key storage unit for decrypting the intercepted packet information according to the shared key, regardless of whether the decryption is successful or not , will transmit the decrypted information; a verification and comparison unit is connected to the decryption unit, and is used for hash comparison and timestamp verification of the information decrypted by the decryption unit, which can verify the decrypted information. After hash processing, compare whether the hash results are the same, and also verify the timestamp to verify whether the timestamp has expired. If the hash comparison is the same and the timestamp has not expired, it is judged that the authentication is successful; a packet transmission unit , which is connected with the verification and comparison unit to receive the decrypted information that has completed hash comparison and timestamp verification, and transmits the decrypted information directly; and an encryption unit, which is stored with the shared key The unit, the verification and comparison unit and the packet transmission unit are connected to receive the decrypted information without hash comparison or timestamp verification, take out a set of timestamps and perform hash processing, and then use the shared key It is decrypted, and finally sent out by the packet transmission unit.
有關於本發明其他技術內容、特點與功效,在以下配合參考圖式之較佳實施例的詳細說明中,將可清楚的呈現。Other technical contents, features and effects of the present invention will be clearly presented in the following detailed description of the preferred embodiments with reference to the drawings.
請參閱第1、2A、2B、3A、3B圖,為本發明認證授權外掛系統之整體架構示意圖、第一加/解密裝置之架構示意圖、第一加/解密裝置之加解密應用程式之架構示意圖、第二加/解密裝置之架構示意圖及第二加/解密裝置之加解密應用程式之架構示意圖,由圖中可知,本系統係設置於能夠傳送封包之第一設備1與第二設備2間,而該第一設備1與第二設備2之間更具有一封包轉傳設備3,其中該第一設備1與第二設備2皆能夠朝向該封包轉傳3設備傳出一封包資訊。Please refer to Figures 1, 2A, 2B, 3A, and 3B, which are the overall architecture diagram of the authentication and authorization plug-in system, the architecture diagram of the first encryption/decryption device, and the architecture diagram of the encryption/decryption application program of the first encryption/decryption device of the present invention. , the schematic diagram of the architecture of the second encryption/decryption device and the architecture diagram of the encryption/decryption application program of the second encryption/decryption device. As can be seen from the figures, the system is set between the
其中該第一設備1與第二設備2係能夠為機台設備或是電腦設備(電腦、智慧型手機、平板電腦),而該封包轉傳設備3係能夠為switch或是router,其中第一加/解密裝置4與第二加/解密裝置5會以網路線與該封包轉傳設備3連接,且第一設備1(第二設備2)與第一加/解密裝置4(第二加/解密裝置5)之間亦能夠透過網路線連接(第一加/解密裝置4(第二加/解密裝置5)會鄰近第一設備1(第二設備2)設置,以避免第一加/解密裝置4(第二加/解密裝置5)被人惡意破壞或破解)。The
其中該認證授權外掛系統係包含一第一加/解密裝置4及一第二加/解密裝置5,該第一加/解密裝置4係能夠與該第二加/解密裝置5進行連線或是同步資料處理,以使該第一加/解密裝置4與該第二加/解密裝置5能夠取得相同的共用金鑰;The authentication and authorization plug-in system includes a first encryption/
該第一加/解密裝置4係以網路連接方式連接於該第一設備1與該封包轉傳設備3之間,而該第一加/解密裝置4內係儲存有至少一組的共用金鑰,且該第一加/解密裝置4係用以攔截該第一設備1或是該封包轉傳設備3所傳送出來的封包資訊;The first encryption/
而該第二加/解密裝置5係以網路連接方式連接於該第二設備2與該封包轉傳設備3之間,而該第二加/解密裝置5亦與該第一加/解密裝置4共用並儲存有該共用金鑰,且該第二加/解密裝置5係用以攔截該第二設備2或是該封包轉傳設備3所傳送出來的封包資訊;The second encryption/
而本案之封包傳送機制有以下幾種:
(1) 第一設備1傳出正常封包,先進入第一加/解密裝置4嘗試解密後,再進行雜湊比較與時間戳記驗證,由於正常封包並未添加時間戳記與雜湊處理,故驗證必然不成功,之後再添加時間戳記與雜湊處理後、並再以共用金鑰進行加密後傳出給該封包轉傳設備3,而之後有兩種情況,說明如下:
(a) 當封包轉傳設備3送給第二加/解密裝置5是正常封包進行添加時間戳記與雜湊處理並加密後,該第二加/解密裝置5會先以共用金鑰解密後,再進行雜湊比較與時間戳記驗證,若驗證成功,則直接將正常封包由第二加/解密裝置5送入第二設備2內。
(b) 當封包轉傳設備3送給第二加/解密裝置5是異常封包,而該第二加/解密裝置5會對異常封包嘗試解密後,再添加時間戳記與雜湊處理後、並再以共用金鑰進行加密後送入該第二設備2,而第二設備2因為不具有共用金鑰能夠解密,故判斷此為異常封包並過濾之。
(2) 第二設備2傳出正常封包,先進入第二加/解密裝置5嘗試解密後,再進行雜湊比較與時間戳記驗證,由於正常封包並未添加時間戳記與雜湊處理,故驗證必然不成功,之後再添加時間戳記與雜湊處理後、並再以共用金鑰進行加密後傳出給該封包轉傳設備3,而之後有兩種情況,說明如下:
(a) 當封包轉傳設備3送給第一加/解密裝置4是正常封包進行添加時間戳記與雜湊處理並加密後,該第一加/解密裝置4會先以共用金鑰解密後,再進行雜湊比較與時間戳記驗證,若驗證成功,則直接將正常封包由第一加/解密裝置4送入第一設備1內。
(b) 當封包轉傳設備3送給第一加/解密裝置4是異常封包,而該第一加/解密裝置4會對異常封包嘗試解密後,再添加時間戳記與雜湊處理後、並再以共用金鑰進行加密後送入該第一設備1,而第一設備1因為不具有共用金鑰能夠解密,故判斷此為異常封包並過濾之。
The packet transmission mechanisms in this case are as follows:
(1) The
而第一設備1或該第二設備2所傳出的原始資訊能夠以AES 硬體加解密方式進行加密之後(或是不以AES 硬體加解密方式加密直接送出),再轉成SSHV2的封包資訊傳送出來(本案亦能夠以其他封包方式實施),而該第二設備2或該第一設備1所接收認證成功直接傳出之解密後的資訊,則能夠以AES 硬體加解密方式進行解密,以取得另一端正確所傳出的原始資訊。The original information transmitted by the
本案有以下幾種實施應用,說明如下: (1) 第一個操作方式,本外掛系統可直接作為路由器,針對工業機台,做封包轉送的功能。 (2) 第二個操作方式,本外掛系統可針對工業機台,做加密封包轉送,並可輕易的達到資訊安全中的機密性。 (3) 第三個操作方式,本外掛系統可針對工業機台,釐清機台操作者的責任問題與機台使用者來源的認證機制。 (4) 本案實施方式能夠將此外掛系統,置入不同的工具機系統(CNC、NC)在智慧製造環境中,促使機台在不同環境中,能夠真正地進行輕量化的認證與授權的設計,並可針對不同生產機台,作封包轉送、過濾、加密,讓機台間的敏感資訊,再傳送過程中能夠做到認證,並可以輕易做到資料保護。 The case has the following implementation applications, which are described as follows: (1) The first operation mode, this plug-in system can be directly used as a router to perform packet forwarding function for industrial machines. (2) The second operation method, this plug-in system can be used for industrial machines, and can be forwarded in sealed packages, and can easily achieve confidentiality in information security. (3) The third operation method, this plug-in system can clarify the responsibility of the machine operator and the authentication mechanism of the source of the machine user for industrial machines. (4) The implementation of this case can put the external hanging system into different machine tool systems (CNC, NC) in the intelligent manufacturing environment, so that the machine can truly carry out lightweight authentication and authorization design in different environments , and can perform packet forwarding, filtering, and encryption for different production machines, so that sensitive information between machines can be authenticated during the retransmission process, and data protection can be easily achieved.
而本案以採用樹莓派作為架構來實施舉例,數莓派本身具有路由器的相關應用,透過hostapd可以輕易的實現無線路由器的功能,或是利用OpenWrt做一個適合嵌入式設備的Linux版本的過濾路由,同時可以輕易在樹梅派上作過濾封包,而本次舉例是應用於OPCUA的網路架構中,配置了一對一的加/解密器,並搭配分享共用同一組的金鑰SK(session key),用以將兩端傳送出來的封包透過加密器及同一組金鑰進行加密,並當送出至另一端的加/解密器後,則會透過同一組金鑰解密,並進行驗證時間戳記,以確認封包的完整度與安全性。In this case, the Raspberry Pi is used as an example for implementation. The Raspberry Pi itself has router-related applications. Through hostapd, you can easily implement the function of a wireless router, or use OpenWrt to make a Linux version suitable for embedded devices. Filter routing , and can easily filter packets on the Raspberry Pi, and this example is applied to the OPCUA network architecture, configured with a one-to-one encryption/decryptor, and shared with the same group of keys SK (session key), which is used to encrypt the packets sent from both ends by the encryptor and the same set of keys, and when sent to the encryptor/decryptor at the other end, it will be decrypted by the same set of keys, and the timestamp will be verified. , to confirm the integrity and security of the packet.
而上述舉例的樹莓派架構與OPCUA(開放式平台通訊統一架構)的網路架構,僅是一種實施樣態,但本案實施可能性並不限於此。The Raspberry Pi architecture and the OPCUA (Open Platform Communication Unified Architecture) network architecture mentioned above are only an implementation pattern, but the implementation possibilities of this case are not limited to this.
而進一步說明加密機制,其中m是代表原始資訊或是AES 硬體加解密方式後的資訊,而h(m)是代表對m做hash,而t是代表時間戳記,本案以共用金鑰加密能夠有以下兩種樣態: (1) Esk[m,h(m),t],先將m做hash後,再添加時間戳記後,整包以共用金鑰加密,最後再依據網路協定拆成界定的長度後送出。 (2) Esk[m,t,h(m,t)] ,先添加時間戳記,再將m,t做hash後,整包以共用金鑰加密,最後再依據網路協定拆成界定的長度後送出。 To further explain the encryption mechanism, where m represents the original information or the information after the AES hardware encryption and decryption method, h(m) represents the hash of m, and t represents the timestamp. In this case, the shared key encryption can be used. There are two styles: (1) Esk[m,h(m),t], first hash m, then add a timestamp, encrypt the whole packet with the shared key, and finally split it into a defined length according to the network protocol and send it out. (2) Esk[m,t,h(m,t)] , first add a timestamp, then hash m and t, encrypt the whole package with the shared key, and finally split it into a defined length according to the network protocol sent later.
而進一步說明解密後驗證機制,有以下兩種樣態: (1) Dsk(Esk[m,h(m),t]),先用共用金鑰解密後,再將m做hash,以與h(m)比對是否正確,之後再確認時間戳記是否有過期,若比對正確與時間戳記沒有過期,則判斷驗證成功,之後將m依據網路協定拆成界定的長度後送出。 (2) Dsk(Esk[m,t,h(m,t]),先用共用金鑰解密後,再將m,t做hash,以與h(m,t)比對是否正確,之後再確認時間戳記是否有過期,若比對正確與時間戳記沒有過期,則判斷驗證成功,之後將m依據網路協定拆成界定的長度後送出。 To further explain the post-decryption verification mechanism, there are the following two modes: (1) Dsk(Esk[m,h(m),t]), first decrypt with the shared key, then hash m to check whether it is correct with h(m), and then confirm whether the timestamp has Expired, if the comparison is correct and the timestamp has not expired, it is judged that the verification is successful, and then m is split into a defined length according to the network protocol and sent. (2) Dsk(Esk[m,t,h(m,t]), first decrypt with the shared key, then hash m,t to check whether it is correct with h(m,t), and then Confirm whether the timestamp has expired. If the comparison is correct and the timestamp has not expired, it is judged that the verification is successful, and then m is split into a defined length according to the network protocol and sent.
其中該第一加/解密裝置4,如第2A及2B圖所示,係包含有至少一個處理器41及至少一個電腦可讀取記錄媒體42,該等電腦可讀取記錄媒體42儲存有至少一個加解密應用程式421,其中該電腦可讀取記錄媒體42更進一步儲存有電腦可讀取指令,當由該等處理器41執行該等電腦可讀取指令時,能夠使該加解密應用程式421進行運作,進行攔截該第一設備1或是該封包轉傳設備3所傳送出來的封包資訊,並使用該共用金鑰解密並進行雜湊比較與時間戳記驗證,若認證成功則將解密後的資訊直接傳出,若驗證未完成則取出一組時間戳記與進行雜湊處理後、並再以共用金鑰進行加密後傳出;The first encryption/
而該加解密應用程式421係至少包含有:
(1) 一封包攔截單元4211,用以攔截該第一設備1或是該封包轉傳設備3所傳送出來的封包資訊;
(2) 一共用金鑰存放單元4212,用以接收儲存有該共用金鑰;
(3) 一解密單元4213,係與該封包攔截單元4211及該共用金鑰存放單元4212相連接,用以依據該共用金鑰對所攔截的封包資訊進行解密,而不論是否解密成功,皆會把解密後的資訊傳出;
(4) 一驗證比對單元4214,係與該解密單元4213相連接,用以將該解密單元4213解密後的資訊進行雜湊比較與時間戳記驗證,其中能夠對解密後的資訊進行雜湊處理後,再比對雜湊結果是否相同,並亦對時間戳記進行驗證,以驗證該時間戳記是否過期,若雜湊比對相同且時間戳記沒有過期,則判斷為認證成功;
(5) 一封包傳送單元4215,係與該驗證比對單元4214相連接,用以接收已完成雜湊比較與時間戳記驗證之解密後的資訊,並將解密後的資訊直接傳送出去;以及
(6) 一加密單元4216,係與該共用金鑰存放單元4212、驗證比對單元4214及該封包傳送單元4215相連接,用以接收沒有完成雜湊比較或是時間戳記驗證之解密後的資訊,並取出一組時間戳記與進行雜湊處理後,再依據該共用金鑰進行解密,最後再由該封包傳送單元4215傳送出去。
And the encryption/
其中該第二加/解密裝置5,如第3A及3B圖所示,係包含有至少一個處理器51及至少一個電腦可讀取記錄媒體52,該等電腦可讀取記錄媒體52儲存有至少一個加解密應用程式521,其中該電腦可讀取記錄媒體52更進一步儲存有電腦可讀取指令,當由該等處理器51執行該等電腦可讀取指令時,能夠使該加解密應用程式521進行運作,進行攔截該第一設備1或是該封包轉傳設備3所傳送出來的封包資訊,並使用該共用金鑰解密並進行雜湊比較與時間戳記驗證,若認證成功則將解密後的資訊直接傳出,若驗證未完成則取出一組時間戳記與進行雜湊處理後、並再以共用金鑰進行加密後傳出;The second encryption/
而該加解密應用程式521係至少包含有:
(1) 一封包攔截單元5211,用以攔截該第一設備1或是該封包轉傳設備3所傳送出來的封包資訊;
(2) 一共用金鑰存放單元5212,用以接收儲存有該共用金鑰;
(3) 一解密單元5213,係與該封包攔截單元5211及該共用金鑰存放單元5212相連接,用以依據該共用金鑰對所攔截的封包資訊進行解密,而不論是否解密成功,皆會把解密後的資訊傳出;
(4) 一驗證比對單元5214,係與該解密單元5213相連接,用以將該解密單元5213解密後的資訊進行雜湊比較與時間戳記驗證,其中能夠對解密後的資訊進行雜湊處理後,再比對雜湊結果是否相同,並亦對時間戳記進行驗證,以驗證該時間戳記是否過期,若雜湊比對相同且時間戳記沒有過期,則判斷為認證成功;
(5) 一封包傳送單元5215,係與該驗證比對單元5214相連接,用以接收已完成雜湊比較與時間戳記驗證之解密後的資訊,並將解密後的資訊直接傳送出去;以及
(6) 一加密單元5216,係與該共用金鑰存放單元5212、驗證比對單元5214及該封包傳送單元5215相連接,用以接收沒有完成雜湊比較或是時間戳記驗證之解密後的資訊,並取出一組時間戳記與進行雜湊處理後,再依據該共用金鑰進行解密,最後再由該封包傳送單元5215傳送出去。
The encryption/
本發明所提供之認證授權外掛系統,與其他習用技術相互比較時,其優點如下:
(1) 本案是於網路架構中,配置了一對一的加/解密器,並搭配分享共用同一組的金鑰,用以將兩端傳送出來的封包透過加/解密器及同一組金鑰進行加密,並當送出至另一端的加/解密器後,則會透過同一組金鑰解密,並進行驗證時間戳記,以確認封包的完整度與安全性。
(2) 本案是透過外掛與工業機台串接,並針對不同生產機台,作封包轉送、過濾、加密,讓機台間的敏感資訊,再傳送過程中能夠做到認證,並可以輕易做到資料保護。
(3) 本案能夠應用於任何能夠連接網路線的老舊機台,即使老舊機台因機台老舊而不具有加密機制,而對於所傳出之封包無法進行加密,故透過本案的外掛系統,則能夠有效解決如此問題,讓老舊機台與老舊系統也能夠做到認證,並可以輕易做到資料保護。
(4) 本案應用於OPCUA的網路架構下時,其機台原廠或是代理商因為了解機台設計原理與封包傳輸機制,故若是透過機台原廠或是代理商提供的軟體機制進行加密時,仍不可避免會被機台原廠或是代理商上傳或破解並竊取資訊,但若是透過本系統的外掛機制,由於會透過加/解密器及同一組金鑰進行加密,而機台原廠或是代理商並不具有金鑰,故必然無法進行解密而進一步取得封包資訊。
(5) 本案之外掛系統,若是當封包轉傳設備遇到middle attack時,若是封包轉傳設備丟出一駭客所準備的異常封包時,由於本案的加/解密器接收到封包解密後,即使對於異常封包無法解密,也會進行雜湊比較與時間戳記驗證,明顯對於異常封包無法驗證成功,之後則會對異常封包添加時間戳記與雜湊處理後再進行加密,而當再往後丟給第一設備1或該第二設備2時,第一設備1或該第二設備2必然無法理解所傳來的封包資訊,如此也就必然去排除掉此異常封包了。
When compared with other conventional technologies, the authentication and authorization plug-in system provided by the present invention has the following advantages:
(1) In this case, a one-to-one encryption/decryptor is configured in the network architecture, and shared with the same set of keys to pass the packets sent from both ends through the encryption/decryptor and the same set of keys. The key is encrypted, and when sent to the encryption/decryptor at the other end, it will be decrypted by the same set of keys, and the timestamp will be verified to confirm the integrity and security of the packet.
(2) In this case, the plug-in is connected to the industrial machine in series, and for different production machines, packet transfer, filtering, and encryption are performed, so that the sensitive information between the machines can be authenticated during the retransmission process, and can be easily done to data protection.
(3) This case can be applied to any old machine that can connect to the network line, even if the old machine does not have an encryption mechanism due to the old machine, and the outgoing packets cannot be encrypted, so through the plug-in of this case The system can effectively solve such problems, so that old machines and old systems can also be authenticated, and data protection can be easily achieved.
(4) When this case is applied to the OPCUA network architecture, the original machine manufacturer or the agent understands the machine design principle and packet transmission mechanism, so if the encryption is performed through the software mechanism provided by the original machine manufacturer or the agent , it will inevitably be uploaded or cracked by the original machine manufacturer or the agent and the information will be stolen, but if it is through the plug-in mechanism of this system, it will be encrypted by the encryption/decryptor and the same set of keys, and the original machine or The agent does not have the key, so it must not be able to decrypt and further obtain the packet information.
(5) The plug-in system in this case, if the packet forwarding device encounters a middle attack, if the packet forwarding device throws out an abnormal packet prepared by a hacker, since the encryption/decryptor in this case receives the packet and decrypts it, Even if the abnormal packet cannot be decrypted, hash comparison and timestamp verification will be performed. Obviously, the abnormal packet cannot be successfully verified. After that, the abnormal packet will be encrypted with a timestamp and hash processing. When a
本發明已透過上述之實施例揭露如上,然其並非用以限定本發明,任何熟悉此一技術領域具有通常知識者,在瞭解本發明前述的技術特徵及實施例,並在不脫離本發明之精神和範圍內,當可作些許之更動與潤飾,因此本發明之專利保護範圍須視本說明書所附之請求項所界定者為準。The present invention has been disclosed above through the above-mentioned embodiments, but it is not intended to limit the present invention. Anyone familiar with this technical field with ordinary knowledge can understand the aforementioned technical features and embodiments of the present invention without departing from the present invention. Within the spirit and scope, some changes and modifications can be made, so the scope of patent protection of the present invention shall be determined by the claims attached to this specification.
1:第一設備 2:第二設備 3:封包轉傳設備 4:第一加/解密裝置 41:處理器 42:電腦可讀取記錄媒體 421:加解密應用程式 4211:封包攔截單元 4212:共用金鑰存放單元 4213:解密單元 4214:驗證比對單元 4215:封包傳送單元 4216:加密單元 5:第二加/解密裝置 51:處理器 52:電腦可讀取記錄媒體 521:加解密應用程式 5211:封包攔截單元 5212:共用金鑰存放單元 5213:解密單元 5214:驗證比對單元 5215:封包傳送單元 5216:加密單元 1: The first device 2: Second device 3: Packet forwarding equipment 4: The first encryption/decryption device 41: Processor 42: Computer-readable recording medium 421: Encryption and decryption application 4211: Packet interception unit 4212: Shared key storage unit 4213: Decryption unit 4214: Verify Alignment Unit 4215: Packet transfer unit 4216: encryption unit 5: Second encryption/decryption device 51: Processor 52: Computer-readable recording medium 521: Encryption and decryption application 5211: Packet interception unit 5212: Shared key storage unit 5213: Decryption unit 5214: Verify alignment unit 5215: Packet transfer unit 5216: encryption unit
[第1圖]係本發明認證授權外掛系統之整體架構示意圖。 [第2A圖]係本發明認證授權外掛系統之第一加/解密裝置之架構示意圖。 [第2B圖]係本發明認證授權外掛系統之第一加/解密裝置之加解密應用程式之架構示意圖。 [第3A圖]係本發明認證授權外掛系統之第二加/解密裝置之架構示意圖。 [第3B圖]係本發明認證授權外掛系統之第二加/解密裝置之加解密應用程式之架構示意圖。 [Fig. 1] is a schematic diagram of the overall structure of the authentication and authorization plug-in system of the present invention. [Fig. 2A] is a schematic diagram of the structure of the first encryption/decryption device of the authentication and authorization plug-in system of the present invention. [Fig. 2B] is a schematic diagram of the structure of the encryption/decryption application program of the first encryption/decryption device of the authentication and authorization plug-in system of the present invention. [Fig. 3A] is a schematic diagram of the structure of the second encryption/decryption device of the authentication and authorization plug-in system of the present invention. [Fig. 3B] is a schematic diagram of the structure of the encryption/decryption application program of the second encryption/decryption device of the authentication and authorization plug-in system of the present invention.
1:第一設備 1: The first device
2:第二設備 2: Second device
3:封包轉傳設備 3: Packet forwarding equipment
4:第一加/解密裝置 4: The first encryption/decryption device
5:第二加/解密裝置 5: Second encryption/decryption device
Claims (7)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| TW110119530A TWI760240B (en) | 2021-05-28 | 2021-05-28 | Authentication and authorization plug-in system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| TW110119530A TWI760240B (en) | 2021-05-28 | 2021-05-28 | Authentication and authorization plug-in system |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| TWI760240B true TWI760240B (en) | 2022-04-01 |
| TW202247019A TW202247019A (en) | 2022-12-01 |
Family
ID=82198764
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| TW110119530A TWI760240B (en) | 2021-05-28 | 2021-05-28 | Authentication and authorization plug-in system |
Country Status (1)
| Country | Link |
|---|---|
| TW (1) | TWI760240B (en) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| TW201535287A (en) * | 2014-02-11 | 2015-09-16 | 智慧通訊公司 | Authentication system and method |
| US9241044B2 (en) * | 2013-08-28 | 2016-01-19 | Hola Networks, Ltd. | System and method for improving internet communication by using intermediate nodes |
| TW201705781A (en) * | 2015-07-12 | 2017-02-01 | 高通公司 | Network architecture and security with encrypted client device context |
| US20170318008A1 (en) * | 2013-04-08 | 2017-11-02 | Titanium Crypt, Inc. | Artificial intelligence encryption model (aiem) with device authorization and attack detection (daaad) |
| CN111177676A (en) * | 2018-11-12 | 2020-05-19 | 群光电子股份有限公司 | Verification system, verification method, and non-transitory computer-readable recording medium |
-
2021
- 2021-05-28 TW TW110119530A patent/TWI760240B/en active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170318008A1 (en) * | 2013-04-08 | 2017-11-02 | Titanium Crypt, Inc. | Artificial intelligence encryption model (aiem) with device authorization and attack detection (daaad) |
| US9241044B2 (en) * | 2013-08-28 | 2016-01-19 | Hola Networks, Ltd. | System and method for improving internet communication by using intermediate nodes |
| TW201535287A (en) * | 2014-02-11 | 2015-09-16 | 智慧通訊公司 | Authentication system and method |
| TW201705781A (en) * | 2015-07-12 | 2017-02-01 | 高通公司 | Network architecture and security with encrypted client device context |
| CN111177676A (en) * | 2018-11-12 | 2020-05-19 | 群光电子股份有限公司 | Verification system, verification method, and non-transitory computer-readable recording medium |
Also Published As
| Publication number | Publication date |
|---|---|
| TW202247019A (en) | 2022-12-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Breiling et al. | Secure communication for the robot operating system | |
| US11316685B1 (en) | Systems and methods for encrypted content management | |
| US10079813B2 (en) | Method and apparatus for secure network enclaves | |
| EP2697931B1 (en) | Qkd key management system | |
| CN109995530B (en) | Safe distributed database interaction system suitable for mobile positioning system | |
| CN101478548B (en) | Data transmission ciphering and integrity checking method | |
| CN111770092B (en) | A kind of numerical control system network security architecture and secure communication method and system | |
| CN107769913A (en) | A kind of communication means and system based on quantum UKey | |
| JP2012050066A (en) | Secure field-programmable gate array (fpga) architecture | |
| CN105991569A (en) | Safe transmission method of TLS communication data | |
| Musa et al. | Secure security model implementation for security services and related attacks base on end-to-end, application layer and data link layer security | |
| CN110300287B (en) | Access authentication method for public safety video monitoring networking camera | |
| CN120433931B (en) | Security communication method and system based on QRNG and Beidou positioning terminal | |
| Li et al. | Lightweight secure communication mechanism towards UAV networks | |
| CN103379103A (en) | Linear encryption and decryption hardware implementation method | |
| CN119210708A (en) | Sensitive data transmission protection system and method based on quantum key distribution | |
| Zhang et al. | Ultra-Low Latency Security Hardening of Modbus/TCP Protocol Based on ZUC Cryptographic Algorithm | |
| CN111917800B (en) | External authorization system and method based on protocol | |
| TW202247019A (en) | Authentication and authorization plug-in system | |
| CN211630188U (en) | Secure encryption switch | |
| Wagner et al. | Madtls: Fine-grained middlebox-aware end-to-end security for industrial communication | |
| CN116055207A (en) | A method and system for encrypting communication data of the Internet of Things | |
| CN113539523A (en) | Internet of things equipment identity authentication method based on domestic commercial cryptographic algorithm | |
| Zhou et al. | A scheme for lightweight SCADA packet authentication | |
| CN119583227B (en) | Shell command encryption remote transmission method and system |