An internet of things device
By introducing a secure routing system into IoT devices, and utilizing a combination of MIMO units, switching modules, control modules, and authentication modules, the security vulnerabilities in IoT devices are addressed, improving the security of device authentication and information transmission, and preventing hacking and key leakage.
Patent Information
- Application Number
- CN202210902599.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2016-12-22
- Filing Date
- 2017-12-21
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2037-12-21
AI Technical Summary
Security vulnerabilities exist in IoT devices, especially in open-source operating systems such as Linux and Android. Hackers may exploit these vulnerabilities to infiltrate the main communication controller and obtain the keys of the quantum communication QKD module, thus affecting device security.
A secure routing system was designed, comprising a MIMO unit, a switching module, a control module, a storage module, and an authentication module. Through multiple input/multiple output ports and protocol conversion, it realizes authentication, encryption/decryption operations, and routing process control, thereby enhancing device security.
It effectively mitigates the security risks of IoT devices, improves the security of device authentication and information transmission, and prevents hacking and key leakage.
Smart Images

Figure CN115278581B_ABST
Abstract
Description
[0001] The original basis for this divisional application is patent application No. 201780073691.X, filed on December 21, 2017, entitled "Secure Routing System for IoT Devices", which claims priority to patent application No. 62 / 438150, with a priority date of December 22, 2016. Technical Field
[0002] This invention relates to routing systems, and more particularly to security methods for various Internet of Things (IoT) smart devices and network camera devices. Background Technology
[0003] In traditional IoT applications, mobile communication devices often connect to network-enabled devices (items), such as smart locks, smart devices, and autonomous vehicles. These network-enabled devices use modules such as WiFi, Bluetooth, BLE (Bluetooth Low Energy), Zigbee, and baseband modules (2G / 3G / 4G / 5G LTE / NB-IoT (Narrowband IoT)) as their main communication controllers. This allows them to control the controlled devices (components that perform the normal operation and functions of the network-enabled devices, such as the physical lock of a smart lock, the air conditioning component of a smart air conditioner, and the engine control unit (ECU) of an autonomous vehicle) via mobile networks or the Internet.
[0004] However, security vulnerabilities may exist in the controlled devices and the main communication controller, especially for open-source operating systems (OS) such as Linux and Android, i.e., real-time operating systems (RTOS). Hackers could exploit these vulnerabilities to compromise the controlled devices and the main communication controller, leading to serious problems.
[0005] From the textbook *Introduction to Quantum Secure Communication* (ISBN: 978-7-5640-2928-9, published January 2010, authored by Chen Hui et al.), we know that quantum channels can be used in optical fibers, free space, and deep water. Currently, so-called "quantum secure communication" is mainly based on quantum key distribution (QKD) or related applications (e.g., one-time pad scrambling based on quantum keys). Encrypted messages are not transmitted through quantum channels. Quantum communication is still related to general-purpose computing terminals and IoT terminals. PCs (main communication modules), besides connecting to QKD modules to handle quantum distribution, still need to address classical encryption and communication issues. The core issue lies in the problems that classical encryption and channels encounter, as described in the background of this case. Currently, quantum computing and general-purpose computing still face security architecture challenges that traditional encryption needs to overcome. Security vulnerabilities may exist in the main communication controller, especially for open-source operating systems (OS), such as Linux and Android, i.e., real-time operating systems (RTOS). Hackers could exploit security vulnerabilities to infiltrate the main communication controller and further obtain keys for quantum communication QKD modules, etc. Summary of the Invention
[0006] Therefore, enhancing the security of IoT applications within open-source operating systems that could benefit the development of IoT technology is a goal for relevant industries.
[0007] Therefore, the object of the present invention is to provide a routing system that can mitigate at least one of the disadvantages of the prior art.
[0008] According to the present invention, the secure routing system is applicable to Internet of Things (IoT) devices, and includes a main communication control module supporting multiple communication protocols and a controlled device. The secure routing system includes a router device, which includes a multiple-input multiple-output (MIMO) unit, a switching module, a control module, a storage module, and an authentication module.
[0009] The MIMO unit conforms to the communication protocol and includes multiple input / output (I / O) ports, including a first I / O port for electrically connecting to the main communication control module and supporting protocol conversion of any messages from the main communication control module, and a second I / O port for electrically connecting to the controlled device and supporting protocol conversion of any messages from the controlled device.
[0010] The switching module is electrically connected to the MIMO unit and can be operated to selectively establish communication paths between the I / O ports.
[0011] The control module is electrically connected to the switch module to control its switching operation and support multi-channel operation.
[0012] The storage module is electrically connected to the control module and includes a program area storing multiple applications corresponding to different application identifiers, a setting area storing environment setting information related to the MIMO unit, and a status area storing status information indicating the current execution state of the router device. The environment setting information includes application identifier information indicating the application identifier corresponding to the application that can be used through the I / O port, and priority information indicating the priority of the I / O port.
[0013] The authentication module is electrically connected to the control module and stores authentication data and password data related to the authentication of at least one user device connected to the main communication control module or at least one user of the at least one user device, as well as key data for encryption operations and encryption / decryption operations of the messages.
[0014] When the control module receives an input message through the switch module and the source port of the I / O port, the control module determines whether to execute the routing process related to the input message based on the environment setting information stored in the setting area, the status information stored in the status area, and the predetermined conflict management mechanism.
[0015] When the control module decides not to execute the routing process related to the input message, the control module controls the switching operation of the switch module so that the busy response, either a notification of busy status or a waiting instruction, is transmitted to the source port through the switch module.
[0016] When the control module decides to execute a routing process related to the input message, the control module executes the routing process related to the input message.
[0017] The routing process includes: when it is determined that the input message contains a multi-channel management instruction, opening a specific channel corresponding to a specific core and closing other corresponding channels corresponding to the specific core according to the multi-channel management instruction, controlling the switching operation of the switch module to transmit the channel management result to the source port through the switch module, and updating the status information stored in the status area according to the channel management result; when it is determined that the input message contains a user-device authentication instruction related to the user device to be authenticated that generated the input message, transmitting the input message to the authentication module, cooperating with the authentication module to execute the authentication procedure corresponding to the user-device authentication instruction according to the authentication data, the password data, and the input message, and controlling the switching operation of the switch module to transmit the successful authentication result to the source port when a successful authentication result is received from the authentication module; and performing a specific operation when it is determined that the input message is related to either an application instruction or an application authentication instruction.
[0018] The specific operations include: executing one of the applications stored in the program area corresponding to the instruction to obtain an execution result; when it is determined that the application corresponding to the instruction contains a control instruction related to another I / O port among the I / O ports, controlling the switching operation of the switch module to transmit the control instruction to the other I / O port through the switch module and update the status information stored in the status area; and when it is determined that the execution result does not contain any error message or exception message, controlling the switching operation of the switch module to transmit a completion response corresponding to the input message to the source port to notify that the routing process has been completed. Attached Figure Description
[0019] Other features and effects of the present invention will be clearly presented in the following detailed embodiments with reference to the drawings, wherein:
[0020] Figure 1 This is a block diagram illustrating a first embodiment of the routing system according to the present invention;
[0021] Figure 2 and Figure 3 Collaboratively develop a flowchart illustrating the steps of secure routing performed by the routing system of the present invention;
[0022] Figure 4 This is a block diagram illustrating variations of the first embodiment;
[0023] Figure 5 This is a block diagram illustrating another variation of the first embodiment;
[0024] Figure 6 This is a block diagram illustrating a second embodiment of the routing system according to the present invention;
[0025] Figure 7 This describes variations of the second embodiment; and
[0026] Figure 8 This is a block diagram illustrating a third embodiment of the routing system according to the present invention. Detailed Implementation
[0027] Before the invention is described in detail, it should be noted that reference numerals or the end portions of reference numerals are used repeatedly in the drawings where deemed appropriate to indicate corresponding or similar elements, which may optionally have similar features.
[0028] See Figure 1 The first embodiment of the secure routing system according to the present invention is applicable to smart IoT devices (e.g., unmanned aerial vehicles (UAVs), smart vehicles, smart devices, telemedicine devices, network camera devices, etc.). In this embodiment, the smart IoT device includes a main communication control module 200 for receiving instructions from a user terminal (e.g., a smartphone, not shown) and a controlled device 300 (a part that performs the normal operation and functions of the smart IoT device, such as the engine control unit (ECU) of an UAV or smart vehicle, the refrigeration component of a smart refrigerator, the component of a telemedicine device for diagnostic and / or therapeutic purposes, etc., and configured to be controlled by instructions provided by the user terminal). The controlled device 300 is not limited to the examples described above. The main communication control module 200 supports multiple communication protocols, each of which can be selected from, for example, WiFi, BLE, Zigbee, 2G, 3G, 4G LTE (4G Long Term Evolution), NB-IoT (Narrowband Internet of Things), LoRa (Long Range), etc., but the present invention is not limited to this aspect. In this embodiment, the main communication control module 200 also provides power (e.g., from a power outlet, battery, etc.) and clock signals required for the operation of the secure routing system 100, and includes a secure router device 10.
[0029] The secure router device 10 has a virtual machine architecture, exemplified as conforming to the GlobalPlatform architecture, and is capable of over-the-air (OTA) updates. Note that in this embodiment, the secure router device 10 is configured to meet general specification standards at or above Evaluation Assurance Level 4 (EAL 4) in both hardware and software, thereby ensuring operational security and enabling the secure router device 10 to be considered a secure element. In this embodiment, the secure router device 10 includes a Multiple-Input Multiple-Output (MIMO) unit 1, a storage module 2, a switching module 3, an authentication module 4, a control module 5, and an antenna module 6.
[0030] The MIMO unit 1 conforms to the communication protocol supported by the main communication control module 200 and includes multiple input / output (I / O) ports, including a first I / O port 11, a second I / O port 12, and a third I / O port 13, but the invention is not limited thereto. The first I / O port 11 is electrically coupled to the main communication control module 200 and supports protocol conversion for any messages from the main communication control module 200. For clarity, the first I / O port 11 may have an interface conforming to the ISO 7816 standard or the Universal Asynchronous Receiver-Transmitter (UART) standard, the second I / O port 12 may have an interface conforming to the UART standard, and the third I / O port 13 may have an interface conforming to the ISO 14443 standard. Figure 1 Other I / O ports not shown can be configured as general purpose input / output (GPIO) ports, or have interfaces that conform to internal integrated circuit (I2C) specifications, serial peripheral interface (SPI) specifications, pulse width modulation (PWM) specifications, etc., but the present invention is not limited to this aspect.
[0031] The storage module 2 includes a program area 21, a setting area 22, and a status area 23. The program area 21 stores multiple applications, each corresponding to a different Application Identifier (AID). The setting area 22 stores environment setting information related to the MIMO unit 1. The status area 23 stores status information indicating the current execution state of the virtual machine architecture of the security router device 10. The applications include one or more application instructions (e.g., Java applets) related to the operation of the controlled device 300, and one or more SIM (User Identity Module) application toolkits. The environment setting information includes application identifier information indicating application identifiers corresponding to applications usable by the I / O ports 11-13, and priority information indicating the priority of the I / O ports 11-13. Users can define the priority of the I / O ports 11-13 according to the characteristics and functions of the controlled device 300 and / or the means by which input is provided to the security router device 10. In this embodiment, the status information includes, for example: channel flag information, which indicates the channel registration status currently registered by one of the request ports of the I / O ports; application execution information, which indicates the application identifier corresponding to the application currently being executed through the currently registered channel; I / O port occupancy information, which indicates the occupancy status of the I / O port; and channel status information, which indicates the status of the channel currently registered by the executing program.
[0032] The switch module 3 is electrically connected to the MIMO unit 1 and operates to selectively establish a communication path between the I / O ports 11-13.
[0033] The authentication module 4 stores authentication data and password data (the term "user" can refer to a virtual user, such as a cloud service provider, or a physical user, such as the owner of the user device or a government agency) related to the authentication of the user device (connected to the main communication control module 200; examples of user devices include smartphones, smartwatches, etc.) and the user of the user device, used to verify the identity of the user device, as well as key data for performing encryption operations on message transmission (e.g., Secure Sockets Layer (SSL), Transport Layer Security (TLS), etc.) and message encryption and decryption operations (e.g., symmetric key algorithms such as Advanced Encryption Standard (AES), Data Encryption Standard (DES), and Blowfish, or asymmetric key algorithms such as Public Key Infrastructure (PKI), Elliptic Curve Cryptography (ECC), and SM2-ECC). In this embodiment, the authentication module 4 can be used as a SIM authentication module for verifying the user identity module (SIM), which can be used in authentication systems in the public or private sectors, such as for banking, public safety, transportation, and health insurance.
[0034] The control module 5 is electrically connected to the MIMO unit 1, the storage module 2, the switching module 3, and the authentication module 4, controls the switching operation of the switching module 3, and supports multi-channel operation. In this embodiment, the control module 5 includes an encryption / decryption circuit 51 and an error-exception handling circuit 52. The encryption / decryption circuit 51 is configured to perform encryption / decryption operations based on key data stored in the authentication module 4 and one or more of the aforementioned symmetric key algorithms and asymmetric key algorithms. The error-exception handling circuit 52 is configured to analyze adverse events, which may be errors / false events or abnormal events, and determine the operation corresponding to the analyzed adverse event. In one embodiment, before the encryption / decryption circuit 51 performs the decryption operation on the encrypted message, the control module 5 also uses a checking algorithm (e.g., Secure Hash Algorithm (SHA), Message Digest Algorithm 5 (MD5), Cyclic Redundancy Check (CRC), etc.) to check whether the encrypted message has been tampered with, and the encryption / decryption circuit 51 only performs the decryption operation if the encrypted message is checked to be untampered with.
[0035] In this embodiment, the antenna module 6 is electrically connected to the third I / O port 13, supports radio frequency identification (RFID) technology, and conforms to the ISO 14443 standard. The antenna module 6 serves as an alternative communication device for the secure routing system 100. In other embodiments, the antenna module 6 and the third I / O port 13 may be omitted according to user requirements.
[0036] In this embodiment, the control module 5 and the switch module 3 are configured as two independent hardware units. In other embodiments, the control module 5 and the switch module 3 can be integrated into a single-core unit or a multi-core unit through hardware, software, or a combination thereof.
[0037] Note that when the main communication control module 200 connected to the first I / O port 11 is initialized (e.g., during the initialization process of the security router device 10 during factory manufacturing), the control module 5 can use over-the-air (OTA) download technology to load the application and environment setting information from the data source terminal (not shown) into the storage module 2 via the main communication control module 200 connected to the first I / O port 11, and load the authentication data, password data, and key data from the data source terminal into the authentication module 4 via the main communication control module 200. The operating system and related management settings for the security router device 10 can also be loaded into the security router device 10 during the initialization process. Additionally, when the security router device 10 is reset, or in response to an update command received from one of the I / O ports 11-13 and verified by the control module 5, the control module 5 is allowed to update the environment setting information.
[0038] See Figures 1 to 3 This describes the steps for performing secure routing by the secure router device 10.
[0039] When the control module 5 receives input messages through the switch module 3 and the source port of one of the I / O ports 11-13 (step S201), the control module 5 determines whether to execute a routing process related to the input messages based on the environment setting information stored in the setting area 22, the status information stored in the status area 23, and a predetermined conflict management mechanism (step S202). When the control module 5 determines not to execute a routing process related to the input messages, the control module 5 controls the switching operation of the switch module 3 to transmit a busy response, which is either a busy state or a waiting instruction, to the source port through the switch module 3 (step S203), and waits to receive an acknowledgment response from the source port corresponding to the busy response. When the control module 5 determines to execute a routing process related to the input messages, the control module 5 executes the routing process related to the input messages, and the process proceeds to step S204. Specifically, in step S202, when the control module 5 determines, based on the priority information, that the priority of the source port is higher than that of the (current) request port (which is one of the I / O ports 11-13), and based on the predetermined conflict management mechanism and the I / O port occupancy information, determines that the source port or the planned destination port is not occupied, the control module 5 determines to execute the routing process related to the input message, suspends and temporarily stores all applications executed through the currently registered channel, and updates the status information accordingly; when the control module 5 determines, based on the priority information, that the priority of the source port is lower than that of the request port, the control module 5 determines not to execute the routing process related to the input message; and when the control module 5 determines, based on the predetermined conflict management mechanism and the I / O port occupancy information, that the source port has been occupied, the control module 5 determines not to execute the routing process related to the input message.
[0040] Table 1 below provides an example of application identifier information and priority information.
[0041] Table 1
[0042]
[0043] According to Table 1, when the input message corresponds to the NB-IoT protocol, the priority information corresponding to case 1 is adapted, and the first I / O port 11 connected to the main communication control module 200 has the first priority (highest priority); when the input message corresponds to the WiFi protocol, the priority information corresponding to case 2 is adapted, and the first I / O port 11 connected to the main communication control module 200 has the first priority; and when the smart IoT device is a fire alarm device, the priority information corresponding to case 3 is adapted, and the second I / O port 12 connected to the controlled device 300 (e.g., a fire alarm) has the first priority.
[0044] Table 2 exemplarily illustrates the status information, which includes channel flag information (see the "Flag" column), application execution information (see the "AID" column), I / O port occupancy information, and channel status information. The channel flag information indicates the registered channels associated with the first I / O port 11 (I / O port 1) and marked as "Current Channel" and "Virtual Channel" (i.e., channels 0 and 1), respectively. The application execution information indicates the application identifiers (i.e., "AID001" and "AID003") corresponding to the applications executed through channels 0 and 1. The I / O port occupancy information indicates the application calling another application (see the "Request I / O" column), and the occupancy status of I / O ports that can be used as request ports (see the "Request I / O" column) or output ports (see the "Output I / O" column), wherein the output port can be used to output the execution results of the executed application. The channel status information indicates the status of channels 0 and 1, as shown in the "Channel Status" column. Please note that the "Registered / Paused" status indicates that the channel has been registered by the currently running application, but the channel is temporarily paused. The "Registered / Running" status indicates that the channel has been registered by the currently running application, and the channel is currently being used to run the application.
[0045] Table 2
[0046]
[0047] Based on the exemplary conditions shown in Tables 1 and 2, in the first case where the input message originates from the second I / O port 12 to call application "AID002" and the priority information of case 3 is adapted, the control module 5 determines to execute the routing process related to the input message in step S202 because the priority of the second I / O port 12 is higher than the priority of the first I / O port 11 in case 3, and the application "AID002" called by the input message is different from the currently executing applications "AID001" and "AID003", which does not violate the predetermined conflict management mechanism. In the second case where the input message originates from the second I / O port 12 to call application "AID001" and the priority information of case 3 is adapted, the control module 5 determines not to execute the routing process related to the input message in step S202 because the application "AID001" called by the input message is currently being executed, which violates the predetermined conflict management mechanism (although, according to the priority information, the second I / O port 12 has a higher priority than the first I / O port 11).
[0048] In this embodiment, the routing process related to the input message includes the following steps S204 to S219.
[0049] In step S204, the control module 5 determines whether the input message includes a multi-channel management instruction. If it is determined in step S204 that the input message includes a multi-channel management instruction, the control module 5 opens a specific channel corresponding to a specific core and closes other channels corresponding to the specific core according to the multi-channel management instruction. It then controls the switching operation of the switch module 3 to transmit the channel management result to the source port through the switch module 3, and updates the status information stored in the status area 23 according to the channel management result (step S205). Then, the source port becomes the currently requested port.
[0050] After the first scenario described above, when it is determined that the input message includes a multi-channel management instruction, the control module 5 updates the status information corresponding to Table 2 to the conditions shown in Table 3.
[0051] Table 3
[0052]
[0053] In Table 3, the specific channel (that is, channel 2) is turned on, and other channels corresponding to the same core as channel 2 (that is, channel 0 and channel 1) are turned off, and channels 0, 1 and 2 are labeled as "sleep channel", "virtual channel 1" and "current channel" respectively.
[0054] When the determination made in step S204 is successful, the process proceeds to step S206, where the control module 5 determines whether the input message includes a user-device authentication instruction related to the user device to be authenticated that generated the input message. Before making the determination, if the input message also includes ciphertext (i.e., encrypted message), it may be necessary to use the encryption / decryption circuit 51 to decrypt the ciphertext after successfully performing a check to confirm that the password has not been tampered with. When it is determined that the input message includes a user-device authentication instruction related to the user device to be authenticated that generated the input message, the control module 5 transmits the (decrypted) input message to the authentication module 4 and cooperates with the authentication module 4 to execute a verification procedure corresponding to the user-device authentication instruction based on the authentication data, the password data, and the input message (step S207). In step S208, the control module 5 determines whether the verification corresponding to the user-device authentication instruction is successful based on whether a successful verification result is received from the authentication module 4. When a successful verification result is received from the authentication module, the control module 5 controls the switching operation of the switch module 3 to transmit the successful verification result to the source port (step S209). When the control module 5 receives a failed verification result (a predetermined type of adverse event) from the authentication module 4 in step S208 (that is, the control module 5 determines that the verification corresponding to the user-device authentication command is unsuccessful), the process proceeds to step S216.
[0055] When it is determined in step S206 that the input message does not include a user-device authentication instruction related to the user device to be authenticated that generated the input message, the process proceeds to step S210, where the control module 5 determines whether the input message involves either an application (e.g., a Java applet) instruction or an application authentication (e.g., Java authentication) instruction. If the determination made in step S210 is affirmative, the control module 5 executes the application stored in the program area 21 that corresponds to either the application instruction or the application authentication instruction, and obtains the execution result (step S211). When the determination made in step S210 is negative (that is, the control module 5 determines that the input message is unrelated to the application instruction or the application authentication instruction), the control module 5 determines that the input message is an erroneous instruction (a predetermined type of adverse event), and the process proceeds to step S216.
[0056] In step S212, the control module 5 determines whether the application executed in step S211 includes control instructions related to one of the I / O ports 11-13 other than the source port. If it is determined that the application executed in step S211 includes control instructions related to one of the I / O ports 11-13, the control module 5 controls the switching operation of the switch module 3 to transmit the control instructions to the other I / O port 11-13 via the switch module 3, and updates the status information stored in the status area 21 (e.g., adding the other I / O port 11-13 to the "Output I / O" column of the status information) (step S213). For example, if the smart IoT device is a smart air conditioner and the input message is received from the first I / O port 11 (source port) and relates to an application (e.g., a Java applet) for temperature control of the air conditioner (the controlled device 300) of the smart air conditioner, when the control module 5 determines that the application (e.g., the Java applet) includes control instructions related to the temperature control of the air conditioner, the control module 5 transmits the control instructions to the second I / O port (the other of the I / O ports), causing the air conditioner to perform temperature control-related operations according to the control instructions received from the second I / O port 12. When the control module 5 determines that the input message does not include any control instructions related to the other of the I / O ports 11-13, the process proceeds to step S214.
[0057] In step S214, the control module 5 determines whether the execution result obtained in step S211 contains an error message or an exception message. If it is determined that the execution result does not contain any error message or exception message, the control module 5 controls the switching operation of the switch module 3 to transmit the completion response corresponding to the input message to the source port to notify that the routing process has been completed (step S215), and waits to receive an acknowledgment response corresponding to the completion response from the source port. When the control module 5 determines that the execution result contains an error message or an exception message (a predetermined type of adverse event), the process proceeds to step S216.
[0058] In step S216, the error-exception handling circuit 52 of the control module 5 analyzes adverse events to obtain analysis results and records the analysis results in a specific application (step S216).
[0059] In step S217, the control module 5 determines whether the occurrence of an adverse event meets a predetermined warning condition. When the determination in step S217 is negative, the control module 5 controls the switching operation of the switch module 3 to transmit the event response related to the adverse event to the source port through the switch module 3 (step S218), to notify that an adverse event has occurred, and waits to receive an acknowledgment response corresponding to the event response from the source port. The predetermined warning condition may be, for example, a predetermined number of events related to the cumulative occurrence of the same type of adverse event. In this case, when the occurrence of an adverse event causes the cumulative occurrence of the same type of adverse event to reach the predetermined number of events, the error-exception handling circuit 52 determines that the occurrence of the predetermined adverse event meets the predetermined warning condition, but the present invention is not limited to this aspect. For example, in other embodiments, the predetermined warning condition may involve the number of times the I / O ports 11-13 fail to respond normally, or the number of times other interrupt services are issued (e.g., timeout interrupt, busy-green interrupt, etc.). Note that the error-anomaly handling circuit 52 may include artificial intelligence or deep learning mechanisms, which may be implemented in the form of circuits or by executing software programs to learn and / or evolve over time, thereby converging anomaly and / or attack patterns, but the present invention is not limited to this aspect. When the determination made in step S217 is affirmative, the control module 5 controls the switching operation of the switch module 3 to selectively transmit the operation warning message to a specific one of the source port and the I / O ports 11-13 (which can be predefined in the corresponding application according to user requirements) via the switch module 3 (step S219). For example, when the control module 5 determines to transmit the operation warning message to a specific I / O port, the operation warning message can be transmitted to the management server and / or the supplier server via a communication module (not shown) electrically connected to the specific I / O port. Specifically, when an adverse event is caused by a malicious attack, the operation warning message can be effectively and promptly reported to the administrator and / or supplier of the smart IoT device for subsequent handling of the situation.
[0060] After the routing process is completed (e.g., steps S215, S218 or S219), the control module 5 waits for the next input message after the status information has been updated (if necessary, such as steps S205 and S213).
[0061] It should be noted that in other embodiments, the error-exception handling circuit 52 may be replaced by a software program that may be executed by the control module 5 to perform the same function.
[0062] Figure 4 A variation of the first embodiment is shown, which is similar to... Figure 1The first embodiment shown differs in that the error-exception handling circuit 52 (see...) Figure 1 The following is omitted: The secure routing system 100 further includes an error-exception handling module 7, which functions similarly to the error-exception handling circuit 52 described above, and is electrically connected to a fourth I / O port 14. The fourth I / O port 14 is one of the I / O ports of the MIMO unit 1 and serves as a reporting port for the control module 5 and the error-exception handling module 7. The fourth I / O port 14 may be a GPIO port, but the invention is not limited to this. Therefore, in this variant, the routing process is collaboratively executed by the secure router device 10 and the error-exception handling module 7, and as... Figure 3 Steps S216-219 of the routing process shown can be modified as follows.
[0063] In this variant, when an adverse event occurs, the control module 5 controls the switching operation of the switch module 3 to transmit event information related to the adverse event to the error-exception handling module 7 via the switch module 3 and the reporting port. This allows the error-exception handling module 7 to subsequently execute step S216 to analyze the adverse event based on the event information, obtain analysis results, and store them, for example, in a specific application. In step S217, the error-exception handling module 7 executes the specific application to determine whether the occurrence of the adverse event meets predetermined warning conditions, obtains a judgment result, and transmits the judgment result to the reporting port. When the control module 5 receives a judgment result indicating that the occurrence of the adverse event does not meet the predetermined warning conditions, the control module 5 executes step S218. When the control module 5 receives a judgment result indicating that the occurrence of the adverse event meets the predetermined warning conditions, the control module 5 executes step S219.
[0064] Figure 5 Another variation of the first embodiment is shown, which differs from... Figure 1 The first embodiment shown is characterized in that the security router device 10 further includes a near field communication (NFC) module 8 electrically connected between the antenna module 6 and the third I / O port 13, and serves as another communication device for the security router device 10.
[0065] Figure 6A second embodiment of the secure routing system 100 according to the present invention is shown. The second embodiment is similar to the first embodiment, except that the secure routing system 100 further includes a main communication control module 200, which can operate between a secure service mode and a normal service mode. The normal service mode and the secure service mode are different / independent service instances of the main communication control module 200. Even if the main communication control module 200 is attacked in the normal service mode, causing the service provided in the normal service mode to be interrupted or unable to provide necessary functional services in the normal service mode, the startup of the secure service mode will not be affected. In this embodiment, the first I / O port 11 can be implemented as an internal bus, thereby enabling more efficient integration of the secure router device 10 and the main communication control module 200.
[0066] When a predetermined abnormal situation occurs, the control module 5 flags an abnormal communication status indicating that the main communication control module 200 is in a faulty communication state, and controls the switching operation of the switch module 3 to transmit a reset signal to the main communication control module 200 through a reset port. The reset port is an I / O port other than the first I / O port 11 that can be connected to the main communication control module 200 (e.g., a fourth I / O port 14, which may be, but is not limited to, a GPIO port). In this embodiment, the reset signal may be generated by a reset circuit included in the control module 5, or by a reset signal generation program executed by the control module 5. The predetermined abnormal condition may be: the control module does not receive an acknowledgment response related to a notification response (e.g., busy response, completion response, event response) previously output by the control module 5 through the source port; or, the first I / O port 11 continuously receives messages (e.g., malicious packets), wherein the amount of data included in the message exceeds the processing limit of the routing system 100 (that is, exceeds the processing capacity of the routing system 100), or exceeds a predetermined amount within a predetermined time period.
[0067] Then, the main communication control module 200 executes a reset procedure in response to the received reset signal. While the main communication control module 200 is being reset, it can communicate with the security router device 10 to cause the control module 5 to perform a corresponding reset operation. After the main communication control module 200 completes the reset procedure (that is, after the control module 5 is reset), when the control module 5 determines that the flag is still marked as abnormal, it transmits a communication warning message indicating abnormal communication conditions to the first I / O port 11 via the switch module 3, causing the main communication control module 200 to switch its operation from the normal service mode to the secure service mode in response to the received communication warning message. When the main communication control module 200 operates in the security service mode, the main communication control module 200 still allows the security router device 10 to have limited communication with the cloud management terminal 500 through the main communication control module 200, so that the current status information of the security router device 10 and the specific information required by the cloud management terminal 500 can be provided to the cloud management terminal 500. However, the present invention is not limited to this aspect.
[0068] In a secure service mode (e.g., the main communication control module 200 stops all services provided in normal service mode except for communication with the management terminal, in order to provide it with important / necessary information, such as for troubleshooting purposes), the main communication control module 200 sends a security notification indicating a security problem to the cloud management terminal 500, a user terminal (not shown), or both via the communication network 400. If the main communication control module 200 still has normal external communication capabilities, the security notification can be successfully transmitted to the cloud management terminal 500, and in response to the security notification, the cloud management terminal 500 can send a security notification response message back to the main communication control module 200, indicating that the main communication control module 200 is communicating normally. Upon receiving the security notification response message, the main communication control module 200 switches its operation from the secure service mode back to the normal service mode and transmits the security notification response message to the first I / O port 11, so that the control module 5 cancels the abnormal flag when it receives the security notification response message from the main communication control module 200 through the first I / O port 11. Through the above operation, the normal communication capability of the main communication control module 200 can be confirmed, and malicious attacks can be effectively eliminated. If the external communication capability of the main communication control module 200 is abnormal due to, for example, damage to the WiFi module (not shown) of the main communication control module 200, resulting in the security notification not being successfully transmitted to the cloud management terminal 500, and the main communication control module 200 does not receive the security notification response message within a predetermined time period from the time the security notification was sent, the main communication control module 200 repeatedly resets the procedure. When the reset procedure has been executed a predetermined number of times, the main communication control module 200 can, for example, communicate with the control module 5 to allow the control module 5 to send an abnormal communication message to a communication module (not shown) electrically connected to another I / O port via the switch module 3. The communication module can then send the abnormal communication message to the cloud management terminal 500 via another communication network (not shown), but the invention is not limited to this aspect.
[0069] Figure 7 A variation of the second embodiment is shown, which is similar to... Figure 6The illustrated embodiment differs in that the secure routing system 100 further includes a reset module 9 electrically connected between the reset port (the fourth I / O port 14) and the main communication control module 200. The reset module 9 generates a reset signal in response to a received drive signal and transmits the reset signal to the main communication control module 200, so that the main communication control module 200 executes a reset procedure in response to the received reset signal. The control module 5 is configured to generate the drive signal when a predetermined abnormal condition occurs and control the switching operation of the switch module 3 to transmit the drive signal to the reset module 9 through the switch module 3 and the reset port.
[0070] Figure 8 A third embodiment of the secure routing system 100 according to the present invention is shown, which is similar to the first embodiment. In the third embodiment, the smart IoT device is implemented as a network camera device, and the controlled device 300 includes a network camera module 302 and a stream encryption module 301.
[0071] In this embodiment, the secure routing system 100 further includes the main communication control module 200, and the communication protocol supported by the main communication control module 200 includes a streaming protocol for external communication, which is related to a streaming service. The key data stored in the authentication module 4 also includes multiple streaming encryption keys for streaming encryption and multiple streaming decryption keys for streaming decryption. The streaming decryption keys correspond to the streaming encryption keys respectively.
[0072] In use, when a request for a distributed key is received from the remote user terminal 600, the main communication control module 200 transmits the request to the first I / O port 11. In this case, the request for the distributed key is used as an input message, and the first I / O port 11 is used as the source port. Then, the control module 5 can determine in step S210 that the request for the distributed key received through the switch module 3 and the first I / O port 11 is related to an application authentication (e.g., Java authentication) instruction (see...). Figure 2 In step S211, one of the applications corresponding to the application authentication (e.g., Java authentication) instructions is executed (see [link to application authentication instructions]). Figure 2In step S211, the control module 5 communicates with the authentication module 4 so that, after successfully verifying the identity of the remote user terminal 600, the authentication module 4 provides one or more stream encryption keys and one or more stream decryption keys corresponding to the one or more stream encryption keys as the execution result. Then, the control module 5 controls the switching operation of the switch module 3 to transmit the one or more stream encryption keys to the controlled device 300 through the second I / O port 12, so that the stream encryption module 301 uses the one or more stream encryption keys to encrypt the stream data captured by the network camera module 302, and transmits the encrypted stream data to the main communication control module 200 through another transmission path 303 (e.g., but not limited to, a physical wire / cable directly connected between the controlled device 300 and the main communication control module 200). The control module 5 also encrypts the one or more stream decryption keys using a specific encryption method to obtain, for example, ciphertext, and transmits the ciphertext (that is, the encrypted one or more stream decryption keys) to the main communication control module 200 through the first I / O port 11. The ciphertext serves as a completion response.
[0073] Then, the main communication control module 200 completes the streaming service by transmitting ciphertext received from the first I / O port 11 and encrypted streaming data received from the controlled device 300 to the remote user terminal 600. The remote user terminal 600 can then use a specific decryption method corresponding to the specific encryption method used by the control module 5 to decrypt the ciphertext received from the main communication control module 200 (i.e., one or more encrypted streaming decryption keys) to obtain the one or more streaming decryption keys, and use the one or more streaming decryption keys to decrypt the encrypted streaming data received from the main communication control module 200. As a result, the remote user terminal 600 can reproduce the streaming data using a streaming media player (not shown), allowing the user to view the images / videos captured by the webcam module 302. In this configuration, even if the main communication control module 200, with its open-source system architecture, has security flaws, the secure routing system 100 still ensures the security of communication for streaming data and the encryption / decryption keys, thereby avoiding privacy issues and preventing service key loss.
[0074] In summary, because the secure router device 10 has a virtual machine architecture that conforms to open specifications and meets general specification standards at or above EAL 4 level in terms of hardware and software, it can be used as a hardware firewall between the main communication control module 200 and the controlled device 300. It also provides universality for application development based on reliable security, without being limited by the different hardware architectures or performance of the main communication control module 200 and the controlled device 300, thus enabling its widespread application in various smart IoT devices. Furthermore, the secure router device 10 uses authentication data, password data, key data, and / or the execution of related applications to perform security identification related to input messages and / or the conversion and transmission of instructions for controlling the controlled device 300. The application and key data can be updated via OTA download, thereby reducing update costs. In addition, the secure routing system 100 can effectively detect and collect abnormal situations that may lead to attacks on the main communication control module 200 or the controlled device 300, and promptly issue warning messages to the management and / or supplier ends.
[0075] In the above description, numerous specific details have been set forth for purposes of explanation in order to provide a thorough understanding of the embodiments. However, it will be apparent to those skilled in the art that one or more other embodiments may be practiced without some of these specific details. It should also be understood that references throughout the specification to “an embodiment,” “embodiment,” or ordinal numbers, etc., imply that a particular feature, structure, or characteristic may be included in the practice of the invention. It should be further understood that, in the specification, various features are sometimes combined in a single embodiment, drawing, or description thereof in order to simplify the invention and aid in understanding various aspects of the invention.
[0076] While the invention has been described in conjunction with what are considered exemplary embodiments, it should be understood that the invention is not limited to the disclosed embodiments, but is intended to cover various arrangements and the broadest possible scope of interpretation included within the spirit of the invention, to encompass all such modifications and equivalent arrangements.
Claims
1. A network camera device, comprising: a main communication control module (200), a controlled device (300), and a security router device (10, 100), wherein, The control module (5) of the security router device (10, 100) is electrically connected to the main communication control module (200) and the controlled device (300). Its features are, The remote user terminal (600) can use a specific decryption method corresponding to the specific encryption method used by the control module (5) to decrypt the ciphertext request received from the main communication control module (200) to obtain one or more stream decryption keys, and use the one or more stream decryption keys to decrypt the encrypted stream data received from the main communication control module (200).
2. The network camera device according to claim 1, characterized in that, The authentication module (4) of the security router device (10, 100) communicates with the control module (5) so that after successfully verifying the identity of the remote user terminal (600), the authentication module (4) provides one or more stream encryption keys and one or more corresponding stream decryption keys.
3. The network camera device according to claim 1 or 2, characterized in that, The control module (5) uses the specific encryption method to encrypt the one or more stream decryption keys to obtain ciphertext, and transmits the ciphertext to the main communication control module (200) through the first I / O port (11) of the security router device (10, 100), wherein the ciphertext is the encrypted one or more stream decryption keys.
4. The network camera device according to claim 3, characterized in that, The main communication control module (200) provides streaming services by transmitting to the remote user terminal (600) the ciphertext, which is received from the first I / O port (11) as one or more streaming decryption keys, and the encrypted streaming data received from the controlled device (300).
5. The network camera device according to claim 1, characterized in that, The controlled device (300) includes a network camera module (302) and a streaming encryption module (301).
6. The network camera device according to claim 5, characterized in that, The streaming encryption module (301) uses one or more streaming encryption keys to encrypt the streaming data captured by the network camera module (302), and transmits the encrypted streaming data to the main communication control module (200) through another transmission path (303).
7. The network camera device according to claim 1, characterized in that, The security router devices (10, 100) serve as a hardware firewall between the main communication control module (200) and the controlled device (300).
8. An Internet of Things (IoT) device, the IoT device connected to a remote user terminal (600) comprising: A main communication control module (200) is used to receive encrypted requests from the user terminal; A controlled device (300) uses one or more encryption keys to encrypt data; A security router device (10, 100), wherein the security router device (10, 100) includes a storage module (2), a control module (5), and an authentication module (4); Its features are, The storage module (2) stores multiple applications, each corresponding to a different application identifier. The control module (5) of the security router device (10, 100) is electrically connected to the main communication control module (200), the controlled device (300) and the storage module (2). The security router device (10, 100) can be used as a hardware firewall between the main communication control module (200) and the controlled device (300), and can provide universality for application development on the basis of security. The security router device (10, 100) uses the authentication module (4) to verify identity data, password data, key data and / or the execution of related applications to perform the conversion and transmission of instructions for controlling the controlled device (300).
9. The device according to claim 1 or 8, characterized in that, When a request for a distributed key from a remote user terminal (600) to a controlled device (300) is received, the control module (5) communicates with the authentication module (4) and determines that the received distributed key, encrypted request, and application authentication command are related and that one of the corresponding applications is executed. If so, the control module (5) transmits the encryption key as the execution result to the controlled device (300), enabling the controlled device (300) to use the key to encrypt data and transmit the encrypted data to the remote user terminal (600) via the main communication control module (200) to complete the service. If the corresponding program does not grant permission to transmit the key result to the main communication control module (200), then this encrypted data is ciphertext to the main communication control module (200).
10. The device according to claim 1 or 8, characterized in that, The secure router device (10, 100) also includes a near-field communication module electrically connected between the antenna module (6) and the third I / O port.
11. The device according to claim 1 or 8, characterized in that, The control module (5) performs encryption and decryption operations based on the key data and either the symmetric key algorithm or the asymmetric key algorithm.
12. The device according to claim 1 or 8, characterized in that, The security router devices (10, 100) have a virtual machine architecture, the application instructions are applet instructions, and the application authentication instructions are applet authentication instructions. The security router devices (10, 100) conform to the Common Criterion Standard (CC) in terms of both hardware and software, at a level equal to or higher than Evaluation Assurance Level 4 (EAL4); and The virtual machine architecture conforms to the GlobalPlatform GP standard.
Citation Information
Patent Citations
Encryption and decryption mechanism and internet of things lock system using encryption and decryption mechanism
CN105281909A
Network camera
CN204272253U