A router device applicable to IoT devices
By introducing the main communication control module and authentication module that supports multi-communication protocols into the routing system of IoT devices, the security vulnerabilities in IoT devices are solved and higher security and data protection are achieved.
Patent Information
- Application Number
- CN202210585657.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2016-12-22
- Filing Date
- 2017-12-21
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2037-12-21
AI Technical Summary
There are security vulnerabilities in routing systems in existing Internet of Things (IoT) devices that hackers may exploit to hack controlled devices and main communication controllers, causing security issues.
A secure routing system is designed, including a main communication control module that supports multiple communication protocols, a multi-input multiple output (MIMO) unit, a switching module, a control module, a storage module and an authentication module. The system uses the identity authentication module to perform encryption operations and message encryption and decryption to ensure the security of data transmission.
It effectively alleviates security vulnerabilities in IoT devices, enhances system security, prevents hackers, and ensures the security of devices and data.
Smart Images

Figure CN114866980B_ABST
Abstract
Description
[0001] The original basis of this divisional application is a patent application with the application number 201780073691.X, the application date of December 21, 2017, and the invention title of "Secure Routing System for IoT Devices", which claims the priority of a patent application with the application number US62 / 438150, and the priority date of December 22, 2016. Technical Field
[0002] The present invention relates to a routing system, and more particularly to a router device suitable for IoT devices. Background Art
[0003] In traditional Internet of Things applications, mobile communication devices are often connected to network-enabled devices (articles), such as smart locks, smart devices, and autonomous vehicles, through, for example, the WiFi module, Bluetooth module, BLE (Bluetooth Low Energy), Zigbee module, baseband module (2G / 3G / 4G / 5G LTE / NB-IoT (Narrowband IoT)) of the network-enabled device, which is used as its main communication controller, so as to perform operation control on the controlled device of the network-enabled device (the component that performs the normal operation and function of the network-enabled device, such as the physical lock of the smart lock, the air-conditioning component of the smart air conditioner, and the engine control unit (ECU) of the autonomous vehicle) through a mobile network or the Internet.
[0004] However, there may be security vulnerabilities in the controlled device and the main communication controller, especially for open-source operating systems (OS), such as Linux and Android, that is, real-time operating systems (RTOS), etc. Hackers may take advantage of the security vulnerabilities to invade the controlled device and the main communication controller, resulting in major problems. Summary of the Invention
[0005] Therefore, how to enhance the security of Internet of Things applications in open-source operating systems that may be beneficial to the development of Internet of Things technology is the goal of the relevant industry.
[0006] Therefore, the object of the present invention is to provide a routing system that can mitigate at least one drawback of the prior art.
[0007] According to the present invention, the secure routing system is applicable to Internet of Things (IoT) devices, and includes a main communication control module that supports multiple communication protocols and a controlled device. The secure routing system includes a router device, and the router device includes a multiple-input multiple-output (MIMO) unit, a switching module, a control module, a storage module, and an authentication module.
[0008] The MIMO unit complies with the communication protocol and includes a plurality of input / output (I / O) ports. The I / O ports include a first I / O port to be electrically connected to the main communication control module and support protocol conversion for any message from the main communication control module, and a second I / O port to be electrically connected to the controlled device and support protocol conversion for any message from the controlled device.
[0009] The switching module is electrically connected to the MIMO unit and is operable to selectively establish a communication path between the I / O ports.
[0010] The control module is electrically connected to the switching module to control its switching operation and support multi-channel operation.
[0011] The storage module is electrically connected to the control module and includes a program area storing a plurality of applications respectively corresponding to different application program identifiers, a setting area storing environment setting information related to the MIMO unit, and a status area storing status information indicating the current execution state of the router device. The environment setting information includes application program identifier information indicating the application program identifier corresponding to the application program that can be used through the I / O port and priority information indicating the priority of the I / O port.
[0012] The authentication module is electrically connected to the control module and stores authentication data, password data related to the authentication of at least one user device connecting to the main communication control module or at least one user of the at least one user device, and key data for encryption operations of message transmission and encryption and decryption operations of the message.
[0013] When the control module receives an input message through a source port among the switching module and the I / O ports, the control module determines whether to execute a routing process related to the input message according to the environment setting information stored in the setting area, the status information stored in the status area, and a predetermined conflict management mechanism.
[0014] When the control module decides not to execute the routing process related to the input message, the control module controls the switching operation of the switching module to transmit a busy response notifying one of the busy state and waiting for instructions to the source port through the switching module.
[0015] When the control module decides to execute the routing process related to the input message, the control module executes the routing process related to the input message.
[0016] The routing process includes: when it is determined that the input message includes a multi-channel management instruction, opening a specific channel corresponding to a specific core according to the multi-channel management instruction, closing other corresponding channels corresponding to the specific core, controlling the switching operation of the switching module so as to transmit the channel management result to the source port through the switching module, and updating the status information stored in the status area according to the channel management result; when it is determined that the input message includes a user-device authentication instruction related to the user device to be authenticated that generates the input message, transmitting the input message to the authentication module, and cooperating with the authentication module to execute a verification process corresponding to the user-device authentication instruction according to the authentication data, the password data, and the input message, and when receiving a successful verification result from the authentication module, controlling the switching operation of the switching module to transmit the successful verification result to the source port; and when it is determined that the input message is related to one of an application program instruction and an application program authentication instruction, performing a specific operation.
[0017] The specific operation includes: an operation of executing one of the application programs stored in the program area corresponding to the instruction to obtain an execution result; when it is determined that the application program corresponding to the instruction includes a control instruction related to another I / O port in the I / O ports, an operation of controlling the switching operation of the switching module to transmit the control instruction to the another I / O port through the switching module and updating the status information stored in the status area; and when it is determined that the execution result does not contain any error message or exception message, an operation of controlling the switching operation of the switching module to transmit a completion response corresponding to the input message to the source port for notifying that the routing process has been completed. Brief Description of the Drawings
[0018] Other features and effects of the present invention will be clearly presented in the following detailed description of the embodiments with reference to the drawings, wherein:
[0019] Figure 1 is a block diagram illustrating a first embodiment of a routing system according to the present invention;
[0020] Figure 2 and Figure 3 cooperatively form a flowchart illustrating the steps of secure routing performed by the routing system of the present invention;
[0021] Figure 4 is a block diagram illustrating a variant implementation aspect of the first embodiment;
[0022] Figure 5 is a block diagram illustrating another variant implementation aspect of the first embodiment;
[0023] Figure 6 is a block diagram illustrating a second embodiment of the routing system according to the present invention;
[0024] Figure 7 is an illustrative variation of the second embodiment; and
[0025] Figure 8 is a block diagram illustrating a third embodiment of the routing system according to the present invention. DETAILED DESCRIPTION
[0026] Before the present invention is described in detail, it should be noted that, where considered appropriate, like reference numerals or portions of reference numerals are reused in the figures to indicate corresponding or similar elements, which may optionally have similar features.
[0027] Referring to Figure 1 , a first embodiment of a secure routing system according to the present invention is applicable to intelligent Internet of Things (IoT) devices (e.g., unmanned aerial vehicles (UAVs), intelligent vehicles, intelligent devices, remote medical devices, network camera devices, etc.). In this embodiment, the intelligent IoT device includes a main communication control module 200 for receiving instructions from a user terminal (e.g., a smart phone, not shown) and a controlled device 300 (a part that performs normal operations and functions of the intelligent IoT device, such as an engine control unit (ECU) of an unmanned aerial vehicle or an intelligent vehicle, a refrigeration component of an intelligent refrigerator, a component for diagnostic and / or treatment purposes of a remote medical device, etc., and configured to be controlled by instructions provided by the user terminal). The controlled device 300 is not limited to the above examples. The main communication control module 200 supports multiple communication protocols, each of which can be selected from, for example, WiFi, BLE, Zigbee, 2G, 3G, 4G LTE (4G Long Term Evolution), NB-IoT (Narrow Band Internet of Things), LoRa (Long Range), etc., but the present invention is not limited in this regard. In this embodiment, the main communication control module 200 also provides power (e.g., sourced from a power outlet, a battery, etc.) and a clock signal required for the operation of the secure routing system 100, and includes a secure router device 10.
[0028] The security router device 10 has a virtual machine architecture, which is exemplified as conforming to the GlobalPlatform architecture and capable of over-the-air (OTA) updates. Note that in this embodiment, the security router device 10 is configured to conform to a general specification standard equal to or higher than the Evaluation Assurance Level 4 (EAL 4) level in terms of both hardware and software, so as to ensure the security of operations, and the security router device 10 can be regarded as a security element. In this embodiment, the security router device 10 includes a multiple-input multiple-output (MIMO) unit 1, a storage module 2, a switching module 3, an authentication module 4, a control module 5, and an antenna module 6.
[0029] The MIMO unit 1 conforms to the communication protocol supported by the main communication control module 200 and includes a plurality of input / output (I / O) ports, which include a first I / O port 11, a second I / O port 12, and a third I / O port 13, but the present invention is not limited thereto. The first I / O port 11 is electrically coupled to the main communication control module 200 and supports protocol conversion of any message from the main communication control module 200. For clarity, the first I / O port 11 may have an interface conforming to the ISO7816 specification or the Universal Asynchronous Receiver-Transmitter (UART) specification, the second I / O port 12 may have an interface conforming to the UART specification, the third I / O port 13 may have an interface conforming to the ISO 14443 specification, and Figure 1 other I / O ports not shown may each be configured as a general-purpose input / output (GPIO) port, or have an interface conforming to the Internal Integrated Circuit (I2C) specification, the Serial Peripheral Interface (SPI) specification, the Pulse Width Modulation (PWM) specification, etc., but the present invention is not limited in this regard.
[0030] The storage module 2 includes a program area 21, a setting area 22, and a status area 23. The program area 21 stores a plurality of application programs respectively corresponding to different application program identifiers (AIDs). The setting area 22 stores environment setting information related to the MIMO unit 1. The status area 23 stores status information indicating the current execution state of the virtual machine structure of the security router device 10. The application programs include one or more application program instructions (e.g., Java applets) related to the operation of the controlled device 300, and one or more SIM (Subscriber Identity Module) application toolkits. The environment setting information includes application identifier information indicating the application identifiers corresponding to the application programs that can be used by the I / O ports 11-13, and priority information indicating the priorities of the I / O ports 11-13. The user can define the priorities of the I / O ports 11-13 according to the characteristics and functions of the controlled device 300, and / or the device providing input to the security router device 10. In this embodiment, the status information includes, for example: channel flag information indicating the channel registration situation currently registered by one of the request ports of the I / O ports; application program execution information indicating the application identifier corresponding to the application program currently executed through the currently registered channel; I / O port occupancy information indicating the occupancy situation of the I / O ports; and channel status information indicating the status of the channels currently registered by the executed program.
[0031] The switching module 3 is electrically connected to the MIMO unit 1 and operates to selectively establish communication paths among the I / O ports 11-13.
[0032] The authentication module 4 stores therein authentication data and password data related to the authentication of a user device (connected to the main communication control module 200; examples of the user device include a smart phone, a smart watch, etc.) and a user of (the user device) (the term "user" may refer to a virtual user, such as a cloud service of a service provider, or a physical user, such as the owner of the user device or a government agency), for authenticating the identity of the user device, and key data for performing encryption operations on the transmission of messages (e.g., Secure Sockets Layer (SSL), Transport Layer Security (TLS), etc.) and encryption and decryption operations on messages (e.g., symmetric key algorithms such as Advanced Encryption Standard (AES), Data Encryption Standard (DES), and Blowfish, or asymmetric key algorithms such as Public Key Infrastructure (PKI), Elliptic Curve Cryptography (ECC), and SM2-ECC). In this embodiment, the authentication module 4 can be used as a SIM verification module for a user identity module (SIM), which can be used in verification systems in the public or private sectors, such as for banking, public security, transportation, medical insurance, etc.).
[0033] The control module 5 is electrically connected to the MIMO unit 1, the storage module 2, the switching module 3, and the authentication module 4, controls the switching operation of the switching module 3, and supports multi-channel operation. In this embodiment, the control module 5 includes an encryption / decryption circuit 51 and an error / exception handling circuit 52. The encryption / decryption circuit 51 is configured to perform encryption and decryption operations according to the key data stored in the authentication module 4 and one or more of the above symmetric key algorithms and asymmetric key algorithms. The error / exception handling circuit 52 is configured to analyze an adverse event, which may be an error / false event or an abnormal event, and determine an operation corresponding to the analyzed adverse event. In one embodiment, the control module 5 also uses a check algorithm (e.g., Secure Hash Algorithm (SHA), Message Digest Algorithm 5 (MD5), Cyclic Redundancy Check (CRC), etc.) to check whether the encrypted message has been tampered with before the encryption / decryption circuit 51 performs a decryption operation on the encrypted message, and the encryption / decryption circuit 51 performs a decryption operation only when the encrypted message is checked as not being tampered with.
[0034] In this embodiment, the antenna module 6 is electrically connected to the third I / O port 13, supports Radio Frequency Identification (RFID) technology, and complies with the ISO 14443 specification. The antenna module 6 serves as an alternative communication device for the secure routing system 100. In other embodiments, the antenna module 6 and the third I / O port 13 may be omitted according to user requirements.
[0035] In this embodiment, the control module 5 and the switching module 3 are configured as two independent hardware units. In other embodiments, the control module 5 and the switching module 3 may be integrated into a single-core unit or a multi-core unit by hardware, software, or a combination thereof.
[0036] Note that when the main communication control module 200 connected to the first I / O port 11 is initialized (e.g., during the initialization process for the security router device 10 during factory manufacturing), the control module 5 can use the over-the-air technology to load the application program and the environment setting information from a data source terminal (not shown) into the storage module 2 through the main communication control module 200 connected to the first I / O port 11, and load the authentication data, the password data, and the key data from the data source terminal into the authentication module 4 through the main communication control module 200. The operating system and related management settings for the security router device 10 can also be loaded into the security router device 10 during the initialization process. Additionally, when the security router device 10 is reset, or in response to an update instruction received from one of the I / O ports 11-13 and verified by the control module 5, the control module 5 is allowed to update the environment setting information.
[0037] See Figures 1 to 3 , which illustrates the steps for the security router device 10 to perform secure routing.
[0038] When the control module 5 receives an input message through the switching module 3 and a source port that is one of the I / O ports 11-13 (step S201), the control module 5 determines whether to execute a routing process related to the input message according to the environment setting information stored in the setting area 22, the status information stored in the status area 23, and a predetermined conflict management mechanism (step S202). When the control module 5 determines not to execute the routing process related to the input message, the control module 5 controls the switching operation of the switching module 3 to transmit a busy response applicable to one of the busy state and waiting for instructions to the source port through the switching module 3 (step S203), and waits to receive an acknowledgment response from the source port corresponding to the busy response. When the control module 5 determines to execute the routing process related to the input message, the control module 5 executes the routing process related to the input message, and the process enters step S204. Specifically, in step S202, when the control module 5 determines according to the priority information that the priority of the source port is higher than that of the (current) request port (which is the other one of the I / O ports 11-13), and determines according to the predetermined conflict management mechanism and the I / O port occupancy information that the source port is not occupied, the control module 5 determines to execute the routing process related to the input message, pauses and temporarily stores all applications executed through the currently registered channel, and correspondingly updates the status information; when the control module 5 determines according to the priority information that the priority of the source port is lower than that of the request port, the control module 5 determines not to execute the routing process related to the input message; and when the control module 5 determines according to the predetermined conflict management mechanism and the I / O port occupancy information that the source port is occupied, the control module 5 determines not to execute the routing process related to the input message.
[0039] Table 1 below exemplarily shows the application identifier information and the priority information.
[0040] Table 1
[0041]
[0042]
[0043] According to Table 1, when the input message corresponds to the NB-IoT protocol, the priority information corresponding to Case 1 is adapted, and the first I / O port 11 connected to the main communication control module 200 has the first priority (highest priority); when the input message corresponds to the WiFi protocol, the priority information corresponding to Case 2 is adapted, and the first I / O port 11 connected to the main communication control module 200 has the first priority; and when the intelligent IoT device is a fire alarm device, the priority information corresponding to Case 3 is adapted, and the second I / O port 12 connected to the controlled device 300 (e.g., a fire alarm) has the first priority.
[0044] Table 2 exemplarily shows the state information, which includes channel flag information (see the "Flag" column), application execution information (see the "AID" column), I / O port occupancy information, and channel status information. The channel flag information indicates the registered channels related to the first I / O port 11 (I / O port 1) and marked as "current channel" and "virtual channel" respectively (that is, channels 0 and 1). The application execution information indicates the application identifiers corresponding to the applications executed through channels 0 and 1 (that is, "AID001" and "AID003"). The I / O port occupancy information indicates the application that calls another application (see the "Request I / O" column), and the occupancy conditions of the I / O ports that can be used as request ports (see the "Request I / O" column) or output ports (see the "Output I / O" column), where the output port can be used to output the execution results of the executed applications. The channel status information indicates the status of channels 0 and 1, as shown in the "Channel Status" column. Note that the status of "registered / suspended" means that the channel is registered by the currently executing application, but the channel is temporarily suspended, and the status of "registered / executing" means that the channel has been registered by the currently executing application and the channel is currently used to execute the application.
[0045] Table 2
[0046]
[0047] Based on the exemplary conditions shown in Tables 1 and 2, in the first case where the input message comes from the second I / O port 12 to call the application "AID002" and adapts to the priority information of Case 3, the control module 5 determines to execute the routing process related to the input message in step S202 because the priority of the second I / O port 12 is higher than that of the first I / O port 11 in Case 3, and the application "AID002" called by the input message is different from the currently executed applications "AID001" and "AID003", which does not violate the predetermined conflict management mechanism. In the second case where the input message comes from the second I / O port 12 to call the application "AID001" and adapts to the priority information of Case 3, the control module 5 determines not to execute the routing process related to the input message in step S202 because the application "AID001" called by the input message is currently being executed, which violates the predetermined conflict management mechanism (although according to the priority information, the priority of the second I / O port 12 is higher than that of the first I / O port 11).
[0048] In this embodiment, the routing process related to the input message includes the following steps S204 to S219.
[0049] In step S204, the control module 5 determines whether the input message includes a multi-channel management instruction. When it is determined in step S204 that the input message includes a multi-channel management instruction, the control module 5 opens a specific channel corresponding to a specific core according to the multi-channel management instruction, closes other channels corresponding to the specific core, controls the switching operation of the switching module 3 to transmit the channel management result to the source port through the switching module 3, and updates the status information stored in the status area 23 according to the channel management result (step S205). Then, the source port becomes the current request port.
[0050] After the above first case, when it is determined that the input message includes a multi-channel management instruction, the control module 5 updates the status information corresponding to Table 2 to the conditions shown in Table 3.
[0051] Table 3
[0052]
[0053] In Table 3, the specific channel (that is, Channel 2) is opened, other channels corresponding to the same core as Channel 2 (that is, Channels 0 and 1) are closed, and Channels 0, 1, and 2 are respectively marked as "sleep channel", "virtual channel 1", and "current channel".
[0054] When the determination made in step S204 is yes, the process proceeds to step S206, where the control module 5 determines whether the input message includes a user-device authentication instruction related to the user device to be authenticated that generated the input message. Before making the determination, if the input message further includes a ciphertext (i.e., an encrypted message), it may be necessary to use the encryption / decryption circuit 51 to decrypt the ciphertext after successfully performing a check to confirm that the password has not been tampered with. When it is determined that the input message includes a user-device authentication instruction related to the user device to be authenticated that generated the input message, the control module 5 transmits the (decrypted) input message to the authentication module 4 and cooperates with the authentication module 4 to execute a verification procedure corresponding to the user-device authentication instruction based on the authentication data, the password data, and the input message (step S207). In step S208, the control module 5 determines whether the verification corresponding to the user-device authentication instruction is successful based on whether a successful verification result is received from the authentication module 4. When a successful verification result is received from the authentication module, the control module 5 controls the switching operation of the switching module 3 to transmit the successful verification result to the source port (step S209). When the control module 5 receives a failed verification result (an adverse event of a predetermined type) from the authentication module 4 in step S208 (i.e., the control module 5 determines that the verification corresponding to the user-device authentication instruction is unsuccessful), the process proceeds to step S216.
[0055] When it is determined in step S206 that the input message does not include a user-device authentication instruction related to the user device to be authenticated that generated the input message, the process proceeds to step S210, where the control module 5 determines whether the input message relates to either an application program (e.g., a Java applet) instruction or an application program authentication (e.g., Java authentication) instruction. If the determination made in step S210 is affirmative, the control module 5 executes the application program stored in the program area 21 and corresponding to either the application program instruction or the application program authentication instruction and obtains the execution result (step S211). When the determination made in step S210 is negative (i.e., the control module 5 determines that the input message is not related to an application program instruction or an application program authentication instruction), the control module 5 determines that the input message is an error instruction (an adverse event of a predetermined type), and the process proceeds to step S216.
[0056] In step S212, the control module 5 determines whether the application program executed in step S211 includes a control instruction related to another one of the I / O ports 11-13 other than the source port. When it is determined that the application program executed in step S211 includes a control instruction related to another one of the I / O ports 11-13, the control module 5 controls the switching operation of the switching module 3 to transmit the control instruction to the other one of the I / O ports 11-13 through the switching module 3, and updates the status information stored in the status area 21 (for example, adds the other one of the I / O ports 11-13 to the "output I / O" column in the status information) (step S213). For example, when the intelligent IoT device is an intelligent air conditioner device and the input message is received from the first I / O port 11 (source port) and is related to an application program (such as a Java applet) for temperature control of an air conditioner (the controlled device 300) of the intelligent air conditioner device, when the control module 5 determines that the application program (such as a Java applet) includes a control instruction related to the temperature control of the air conditioner, the control module 5 transmits the control instruction to the second I / O port (the other one of the I / O ports), so that the air conditioner performs an operation related to temperature control according to the control instruction received from the second I / O port 12. When the control module 5 determines that the input message does not include any control instruction related to the other one of the I / O ports 11-13, the process proceeds to step S214.
[0057] In step S214, the control module 5 determines whether the execution result obtained in step S211 contains an error message or an exception message. When it is determined that the execution result does not contain any error message or exception message, the control module 5 controls the switching operation of the switching module 3 to transmit a completion response corresponding to the input message to the source port for notifying that the routing process has been completed (step S215), and waits for an acknowledgment response corresponding to the completion response from the source port. When the control module 5 determines that the execution result contains an error message or an exception message (a predetermined type of adverse event), the process proceeds to step S216.
[0058] In step S216, the error-exception handling circuit 52 of the control module 5 analyzes the adverse event to obtain an analysis result, and records the analysis result in a specific application program (step S216).
[0059] In step S217, the control module 5 determines whether the occurrence of an adverse event satisfies a predetermined warning condition. When the determination made in step S217 is negative, the control module 5 controls the switching operation of the switching module 3 to transmit an event response related to the adverse event to the source port through the switching module 3 (step S218) for notifying the occurrence of the adverse event and waits to receive an acknowledgment response corresponding to the event response from the source port. The predetermined warning condition may be, for example, a predetermined number of event occurrences related to the cumulative number of occurrences of the same type of adverse event. In this case, when the occurrence of an adverse event causes the cumulative number of occurrences of the same type of adverse event to reach the predetermined number of event occurrences, the error-exception handling circuit 52 determines that the occurrence of the predetermined adverse event satisfies the predetermined warning condition, but the present invention is not limited to this aspect. For example, in other embodiments, the predetermined warning condition may relate to the number of times the I / O ports 11-13 do not respond normally, or the number of other interrupt service dispatches (such as timeout interrupts, busy green interrupts, etc.). Note that the error-exception handling circuit 52 may include an artificial intelligence or deep learning mechanism, which may be implemented in the form of a circuit or by executing a software program to learn and / or evolve over time, so as to converge abnormal and / or attack patterns, but the present invention is not limited to this aspect. When the determination made in step S217 is positive, the control module 5 controls the switching operation of the switching module 3 to selectively transmit an operation warning message to one specific one of the source port and the I / O ports 11-13 (which may be predefined in the corresponding application program according to user requirements) (step S219). For example, when the control module 5 determines to transmit an operation warning message to a specific I / O port, the operation warning message may be transmitted to the management server side and / or the vendor server side through a communication module (not shown) electrically connected to the specific I / O port. Specifically, when the adverse event is caused by a malicious attack, the operation warning message can be effectively and timely reported to the administrator and / or vendor of the intelligent IoT device for subsequent handling of this situation.
[0060] After the routing process ends (for example, steps S215, S218, or S219), the control module 5 waits for the next input message after the status information has been updated (if necessary, such as steps S205 and S213).
[0061] It should be noted that in other embodiments, the error-exception handling circuit 52 may be replaced by a software program that can be executed by the control module 5 to perform the same function.
[0062] Figure 4 A variant of the first embodiment is shown, which is related to Figure 1The difference from the first embodiment shown is that: the error - exception handling circuit 52 (see Figure 1 ) is omitted; the secure routing system 100 further includes an error - exception handling module 7, whose function is similar to that of the above - mentioned error - exception handling circuit 52, and is electrically connected to the fourth I / O port 14, which is one of the I / O ports of the MIMO unit 1 and serves as the reporting port for the control module 5 and the error - exception handling module 7. The fourth I / O port 14 can be a GPIO port, but the present invention is not limited thereto. Thus, in this variant, the routing process is jointly executed by the secure router device 10 and the error - exception handling module 7, and the steps S216 - 219 of the routing process as Figure 3 shown can be changed as described below.
[0063] In this variant, when an adverse event occurs, the control module 5 controls the switching operation of the switching module 3 to transmit event information related to the adverse event to the error - exception handling module 7 through the switching module 3 and the reporting port, so that the error - exception handling module 7 can then execute step S216 to analyze the adverse event based on the event information to obtain an analysis result and store it in, for example, a specific application. In step S217, the error - exception handling module 7 executes the specific application to determine whether the occurrence of the adverse event meets a predetermined warning condition to obtain a determination result, and transmits the determination result to the reporting port. When the control module 5 receives a determination result indicating that the occurrence of the adverse event does not meet the predetermined warning condition, the control module 5 executes step S218. When the control module 5 receives a determination result indicating that the occurrence of the adverse event meets the predetermined warning condition, the control module 5 executes step S219.
[0064] Figure 5 Another variant of the first embodiment is shown, which is different from Figure 1 the first embodiment shown in that the secure router device 10 further includes a near - field communication (NFC) module 8 electrically connected between the antenna module 6 and the third I / O port 13, and serves as another communication device of the secure router device 10.
[0065] Figure 6FIG. 0 shows a second embodiment of the secure routing system 100 according to the present invention. The second embodiment is similar to the first embodiment, except that the secure routing system 100 further includes a main communication control module 200, wherein the main communication control module 200 is operable between a secure service mode and a normal service mode. The normal service mode and the secure service mode are different / independent service instances of the main communication control module 200. Even if the main communication control module 200 is attacked in the normal service mode such that the service provided in the normal service mode is interrupted or the necessary functional services cannot be provided in the normal service mode, the activation of the secure service mode will not be affected. In this embodiment, the first I / O port 11 can be implemented as an internal bus, so as to more effectively integrate the secure router device 10 and the main communication control module 200.
[0066] When a predetermined abnormal situation occurs, the control module 5 marks a flag indicating the abnormal communication status of the main communication control module 200, and controls the switching operation of the switching module 3 to transmit a reset signal to the main communication control module 200 through a reset port, where the reset port is an I / O port other than the first I / O port 11 among the I / O ports and can be connected to the main communication control module 200 (for example, the fourth I / O port 14, which can be but is not limited to a GPIO port). In this embodiment, the reset signal can be generated by a reset circuit included in the control module 5, or generated by a reset signal generation program executed by the control module 5. The predetermined abnormal condition can be: the condition that the control module does not receive an acknowledgment response related to the notification response (such as a busy response, a completion response, an event response) previously output by the control module 5 through the source port; or, the condition that the first I / O port 11 continuously receives messages (such as malicious packets), where the amount of data included in the messages exceeds the processing limit of the routing system 100 (that is, exceeds the processing capacity of the routing system 100), or exceeds a predetermined amount within a predetermined time length.
[0067] Then, the main communication control module 200 executes a reset program in response to the reset signal it receives. When the main communication control module 200 is being reset, the main communication control module 200 can communicate with the security router device 10 to cause the control module 5 to perform corresponding reset operations. After the main communication control module 200 finishes executing the reset program (that is, after the control module 5 is reset), when the control module 5 determines that the flag is still marked as abnormal, the control module 5 transmits a communication warning message indicating abnormal communication conditions to the first I / O port 11 through the switching module 3, so that the main communication control module 200 switches its operation from the normal service mode of the current operation to the security service mode in response to the communication warning message it receives. When the main communication control module 200 operates in the security service mode, the main communication control module 200 still allows the security router device 10 to perform limited communication with the cloud management terminal 500 through the main communication control module 200, so that the current status information of the security router device 10 and specific information required by the cloud management terminal 500 can be provided to the cloud management terminal 500, but the present invention is not limited to this aspect.
[0068] In the security service mode (e.g., the main communication control module 200 stops providing all services except communication with the management terminal in the normal service mode to provide important / necessary messages to it, such as for troubleshooting purposes), the main communication control module 200 sends a security notification indicating that the main communication control module 200 has a security problem to the cloud management terminal 500, the user terminal (not shown), or both through the communication network 400. If the main communication control module 200 still has normal external communication capabilities, the security notification can be successfully transmitted to the cloud management terminal 500, and in response to the security notification, the cloud management terminal 500 can feedback a security notification response message to the main communication control module 200, which indicates the normal communication of the main communication control module 200. After receiving the security notification response message, the main communication control module 200 switches its operation from the security service mode back to the normal service mode and transmits the security notification response message to the first I / O port 11, so that the control module 5 cancels the abnormal marking of the flag when receiving the security notification response message from the main communication control module 200 through the first I / O port 11. Through the above operations, the normal communication capabilities of the main communication control module 200 can be confirmed, and malicious attacks can be effectively excluded. In the case where the external communication capabilities of the main communication control module 200 are abnormal because, for example, the WiFi module (not shown) of the main communication control module 200 is damaged and the security notification cannot be successfully transmitted to the cloud management terminal 500, when the main communication control module 200 does not receive the security notification response message within a predetermined time period from the time of sending the security notification, the main communication control module 200 repeats the reset procedure. When the number of times of repeating the reset procedure has reached a predetermined number of resets, the main communication control module 200 can, for example, communicate with the control module 5 to enable the control module 5 to send an abnormal communication message to a communication module (not shown) electrically connected to another I / O port through the switching module 3. Then, the communication module can send the abnormal communication message to the cloud management terminal 500 through another communication network (not shown), but the present invention is not limited to this aspect.
[0069] Figure 7 shows a variant of the second embodiment, which is related to Figure 6The difference of the illustrated embodiment is that: the security routing system 100 further includes a reset module 9, the reset module 9 is electrically connected between the reset port (the fourth I / O port 14) and the main communication control module 200, and the reset module 9 generates the reset signal in response to the received drive signal and transmits the reset signal to the main communication control module 200, so that the main communication control module 200 executes a reset program in response to the received reset signal; and the control module 5 is configured to generate the drive signal when a predetermined abnormal condition occurs and control the switching operation of the switching module 3 to transmit the drive signal to the reset module 9 through the switching module 3 and the reset port.
[0070] Figure 8 A third embodiment of the security routing system 100 according to the present invention is shown, which is similar to the first embodiment. In the third embodiment, the intelligent IoT device is implemented as a network camera device, and the controlled device 300 includes a network camera module 302 and a stream encryption module 301.
[0071] In this embodiment, the security routing system 100 further includes the main communication control module 200, and the communication protocols supported by the main communication control module 200 further include a stream protocol for external communication, and the stream protocol is related to a stream service. The key data stored in the authentication module 4 further includes a plurality of stream encryption keys for stream encryption and a plurality of stream decryption keys for stream decryption. The stream decryption keys respectively correspond to the stream encryption keys.
[0072] In use, when a request for a split key is received from the remote client 600, the main communication control module 200 transmits the request for the split key to the first I / O port 11. In this case, the request for the split key serves as an input message, and the first I / O port 11 serves as a source port. Then, the control module 5 can determine in step S210 that the request for the split key received through the switching module 3 and the first I / O port 11 is related to an application authentication (e.g., Java authentication) instruction (see Figure 2 ), and execute in step S211 one of the applications corresponding to the application authentication (e.g., Java authentication) instruction of the application (see Figure 2)。In step S211, the control module 5 communicates with the authentication module 4 so that after successfully authenticating the identity of the remote client 600, the authentication module 4 provides one or more stream encryption keys and one or more stream decryption keys corresponding to the one or more stream encryption keys as execution results. Then, the control module 5 controls the switching operation of the switching module 3 to transmit the one or more stream encryption keys to the controlled device 300 through the second I / O port 12, so that the stream encryption module 301 uses the one or more stream encryption keys to encrypt the stream data captured by the network camera module 302, and transmits the encrypted stream data to the main communication control module 200 through another transmission path 303 (for example, but not limited to, a physical wire / cable directly connected between the controlled device 300 and the main communication control module 200). The control module 5 also encrypts the one or more stream decryption keys using a specific encryption method to obtain, for example, ciphertext, and transmits the ciphertext (that is, the encrypted one or more stream decryption keys) to the main communication control module 200 through the first I / O port 11. The ciphertext is used as a completion response.
[0073] Then, the main communication control module 200 completes the streaming service by transmitting the ciphertext received from the first I / O port 11 and the encrypted stream data received from the controlled device 300 to the remote client 600. Thus, the remote client 600 can use a specific decryption method corresponding to the specific encryption method used by the control module 5 to decrypt the ciphertext (that is, the encrypted one or more stream decryption keys) received from the main communication control module 200 to obtain the one or more stream decryption keys, and use the one or more stream decryption keys to decrypt the encrypted stream data received from the main communication 200. As a result, the remote client 600 can use a stream media player (not shown) to reproduce the stream data, and the user can thus view the image / video captured by the network camera module 302. In this configuration, even if the main communication control module 200 with an open-source system architecture has security flaws, the secure routing system 100 can still ensure the security of the communication for the stream data and the keys for encryption / decryption, thus avoiding privacy issues and preventing the loss of service keys.
[0074] In summary, since the security router device 10 has a virtual machine architecture that conforms to open specifications and meets general specification standards equivalent to or exceeding the EAL 4 level in terms of hardware and software, the security router device 10 can be used as a hardware firewall between the main communication control module 200 and the controlled device 300, and can provide generality for application development on the basis of reliable security, without being limited by the different hardware architectures or performances of the main communication control module 200 and the controlled device 300, so that it can be widely applied to various intelligent IoT devices. In addition, the security router device 10 uses authentication data, password data, key data, and / or the execution of relevant applications to perform security identification related to input messages and / or the conversion and transmission of instructions for controlling the controlled device 300, where the applications and the key data can be updated by OTA download, thereby reducing the cost of updates. Furthermore, the security routing system 100 can effectively detect and collect abnormal conditions that may cause the main communication control module 200 or the controlled device 300 to be attacked, and timely send warning messages to the management side and / or the supplier side.
[0075] In the above description, for purposes of explanation, numerous specific details have been set forth in order to provide a thorough understanding of the embodiments. However, it will be apparent to one skilled in the art that one or more other embodiments may be practiced without some of these specific details. It should also be understood that throughout the specification, references to "one embodiment", "an embodiment", an embodiment with an ordinal indication, etc. mean that a particular feature, structure, or characteristic may be included in the practice of the present invention. It should be further understood that in the specification, in order to simplify the present invention and assist in understanding various inventive aspects, various features are sometimes combined together in a single embodiment, drawing, or description thereof.
[0076] Although the present invention has been described in connection with what is considered to be exemplary embodiments, it should be understood that the present invention is not limited to the disclosed embodiments, but is intended to cover various arrangements included within the spirit and the broadest scope of interpretation to encompass all such modifications and equivalent arrangements.
Claims
1. A router device applicable to IoT devices, characterized in that, The router device includes: a plurality of I / O ports; a control module that determines whether to perform a routing process related to an input message according to environment setting information, status information including I / O port occupancy information, and a predetermined conflict management mechanism, where the environment setting information includes application identifier information indicating an application identifier corresponding to an application that can be used through the I / O port and priority information indicating the priority of the I / O port; when the control module determines according to the priority information that the priority of the source port among the I / O ports is higher than that of other requesting ports, and determines according to the predetermined conflict management mechanism and the I / O port occupancy information that the source port is not occupied, the control module determines to perform the routing process related to the input message.
2. The router device according to claim 1, characterized in that, The router device further includes a switching module. When the control module determines not to perform the routing process related to the input message, the control module controls the switching operation of the switching module so as to transmit a busy response notifying one of the busy state and waiting for an instruction to the source port through the switching module; and when the control module determines to perform the routing process related to the input message, the control module performs the routing process related to the input message.
3. The router device according to claim 1 or 2, characterized in that, when the control module determines according to the priority information that the priority of the source port is lower than that of other requesting ports, the control module determines not to perform the routing process related to the input message; and when the control module determines according to the predetermined conflict management mechanism and the I / O port occupancy information that the source port is occupied, the control module determines not to perform the routing process related to the input message, when the control module determines according to the priority information that the priority of the source port is higher than that of other requesting ports, and determines according to the predetermined conflict management mechanism and the I / O port occupancy information that the source port is not occupied, suspend the execution and temporarily store all applications executed through the currently registered channels, and update the status information accordingly.
4. The router device according to claim 1, characterized in that, The router device has a virtual machine architecture, the application program instructions are applet instructions, and the application program authentication instructions are applet authentication instructions; the router device complies with the Common Criteria CC standard at a level equal to or higher than Evaluation Assurance Level 4EAL 4 in terms of hardware and software; and wherein the virtual machine architecture complies with the GlobalPlatform GP standard of the Global Platform.
5. The router device according to claim 2, characterized in that, The control module and the switching module can be integrated into a single-core unit or a multi-core unit through hardware, software, or a combination thereof.
Citation Information
Patent Citations
Adaptive and asynchronous routing network on 2D-Torus chip and design method thereof
CN104320341A
Control method for hierarchical network-on-chip router based on cache redistribution
CN104780122A