Communication system, remote terminal device and authentication method thereof
By setting a trigger unit in the processing module of the remote terminal device to control the trust establishment process, the problem of not being able to effectively ensure the trust of the input and output module in the prior art is solved, and effective trust verification and protection of the input and output modules are realized.
Patent Information
- Application Number
- CN202311683838.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-15
- Filing Date
- 2023-12-08
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art cannot effectively ensure that the external input and output module of the remote terminal device is a trusted device, and it is difficult to effectively verify whether the connected device is fake, resulting in the risk of stealing or modifying data.
By setting a processing module in the remote terminal device, including a first processing unit and a first storage device, in response to the activation and disability of the trigger unit, the processing module can allow the input and output module to establish trust with it in the configuration mode, and prohibit the connection of the input and output modules that have not yet established trust in the operation mode.
Trust establishment and verification of input and output modules is realized, ensuring that only trusted devices can communicate with the processing modules, effectively preventing counterfeiting and data theft.
Smart Images

Figure CN120017294A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a device, and in particular to a communication system, a remote terminal device and an authentication method thereof. Background Art
[0002] In order to prevent the remote terminal unit (RTU) from being attacked by malicious programs or stealing data, how to ensure that the external input and output modules are trusted devices is an important issue in the current field. Although a variety of communication security protocols have been developed in the field of communication, it is still impossible to achieve effective device-to-device authentication, and it is also impossible to effectively verify whether the connected device is counterfeited and steals or modifies data. Summary of the invention
[0003] The present invention is directed to a communication system, a remote terminal device and an authentication method thereof, which can effectively ensure that an external input and output module is a trustworthy device.
[0004] According to an embodiment of the present invention, the remote terminal device of the present invention includes a processing module. The processing module includes a first processing unit and a first storage device. The first storage device is coupled to the first processing unit. In response to the trigger unit being enabled, the first processing unit operates in a configuration mode to allow the input-output module to establish trust with the processing module. In response to the trigger unit being disabled, the first processing unit operates in a running mode to prohibit another input-output module that has not yet established trust from connecting to the processing module.
[0005] According to an embodiment of the present invention, the authentication method of the present invention is applicable to a remote terminal device. The remote terminal device includes a processing module. The authentication method includes the following steps: in response to the trigger unit being enabled, the first processing unit of the processing module operates in a configuration mode to allow the input-output module to establish trust with the processing module; and in response to the trigger unit being disabled, the first processing unit of the processing module operates in an operation mode to prohibit another input-output module that has not established trust from connecting with the processing module.
[0006] According to an embodiment of the present invention, a communication system of the present invention includes a remote terminal device and an expansion device. The remote terminal device includes a processing module. The expansion device includes an input-output module and is coupled to the remote terminal device. In response to a trigger unit of the processing module being enabled, the processing module operates in a configuration mode to allow the input-output module to establish trust with the processing module. In response to the trigger unit being disabled, the processing module operates in a running mode to prohibit another input-output module that has not yet established trust from connecting to the processing module.
[0007] Based on the above, the communication system, the remote terminal device and the authentication method thereof can effectively establish trust with the input and output modules.
[0008] In order to make the above features and advantages of the present invention more clearly understood, embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 is a schematic diagram of a communication system according to an embodiment of the present invention;
[0010] Figure 2 is a schematic diagram of a processing module and an input / output module according to an embodiment of the present invention;
[0011] Figure 3 is a flow chart of an authentication method for a remote terminal device according to an embodiment of the present invention;
[0012] Figure 4 is a schematic diagram of initialization of an embodiment of the present invention;
[0013] Figure 5 is a schematic diagram of a configuration mode of an embodiment of the present invention;
[0014] Figure 6 is a flow chart of obtaining the counterparty's credentials according to an embodiment of the present invention;
[0015] Figure 7 is a schematic diagram of an operating mode of an embodiment of the present invention;
[0016] Figure 8 is a flow chart of a handshake procedure according to an embodiment of the present invention.
[0017] Description of Reference Numerals
[0018] 100: communication system;
[0019] 110: Remote terminal device;
[0020] 111, 210: processing module;
[0021] 112_1~112_M, 122_1~122_N, 220: input and output modules;
[0022] 120: expansion device;
[0023] 130: server;
[0024] 211: first processing unit;
[0025] 212: a first storage device;
[0026] 213: trigger unit;
[0027] 221: second processing unit;
[0028] 222: second storage device;
[0029] 401: Communication connection;
[0030] 411: Processing module key data;
[0031] 412, 423: Processing module credential data;
[0032] 413, 422: input and output module voucher data;
[0033] 414: first handshake data;
[0034] 421: Input and output module key data;
[0035] 424: second handshake data;
[0036] S310~S340, S610~S640, S810~S830: steps. DETAILED DESCRIPTION
[0037] Reference will now be made in detail to exemplary embodiments of the present invention, examples of which are illustrated in the accompanying drawings. Whenever possible, the same reference numerals are used in the drawings and the description to refer to the same or like parts.
[0038] Figure 1 FIG. 1 is a schematic diagram of a communication system according to an embodiment of the present invention. Figure 1 , the communication system 100 includes a remote terminal device 110, an expansion device 120 and a server 130. The remote terminal device 110 includes a processing module 111 and a plurality of input / output (I / O) modules 112_1 to 112_M, where M is a positive integer. The remote terminal device 110 can be coupled to the expansion device 120 in a wired form (for example, through a cable). The remote terminal device 110 and the expansion device 120 can be respectively set in different application fields with a considerable distance, and the present invention is not limited thereto. The expansion device 120 includes another plurality of input / output modules 122_1 to 122_N, where N is a positive integer. The expansion device 120 can also be another remote terminal device. The remote terminal device 110 can be used to implement related applications of monitoring, control or data acquisition.
[0039] In this embodiment, the processing module 111 can be used to manage, control or monitor the input / output modules 112_1-112_M, 122_1-122_N, and is connected to the server 130 via a wired or wireless method. The processing module 111 can collect data provided by the input / output modules 112_1-112_M, 122_1-122_N, or send relevant data to the input / output modules 112_1-112_M, 122_1-122_N.
[0040] In the present embodiment, the processing module 111 may include relevant processing and computing circuits, such as a central processing unit (CPU), but the present invention is not limited thereto. The input / output modules 112_1-112_M, 122_1-122_N may be different types of sensors, IoT devices, valve units, control units, and the like, and the present invention is not limited thereto. In the present embodiment, the input / output modules 112_1-112_M, 122_1-122_N may have a hot swapping function, so that they can be selectively installed in the remote terminal device 110 or the expansion device 120 when the remote terminal device 110 (i.e., the processing module 111) is in the operating mode, or selectively removed from the remote terminal device 110 or the expansion device 120 according to different usage states.
[0041] Specifically, assuming that the input / output modules 112_1-112_M, 122_1-122_N and the processing module 111 have not established trust, when any one of the input / output modules 112_1-112_M, 122_1-122_N is temporarily installed in the remote terminal device 110 or the expansion device 120, the processing module 111 can establish trust with it. Moreover, after a certain input / output module has established trust with the processing module 111 of the remote terminal device 110, when this input / output module is installed in the remote terminal device 110 or the expansion device 120 at any time, the processing module 111 can automatically establish a connection with this input / output module. In contrast, when an input / output module that has not established trust with the processing module 111 is installed in the remote terminal device 110 or the expansion device 120, the processing module 111 can effectively and immediately identify it, so as to directly refuse the input / output module that has not established trust to connect to the processing module 111.
[0042] Figure 2 FIG. 1 is a schematic diagram of a processing module and an input / output module according to an embodiment of the present invention. Figure 2 , Figure 1 The processing module 111 may implement the processing module 210 of the present embodiment, and Figure 1Any one of the input / output modules 112_1-112_M, 122_1-122_N can also implement the input / output module 220 of the present embodiment. In the present embodiment, the processing module 210 includes a first processing unit 211, a first storage device 212, and a trigger unit 213. The first processing unit 211 is coupled to the first storage device 212 and the trigger unit 213. The input / output module 220 includes a second processing unit 221 and a second storage device 222.
[0043] In the present embodiment, the first processing unit 211 and the second processing unit 221 may be, for example, a central processing unit (CPU), a graphics processing unit (GPU), or other programmable general-purpose or special-purpose microprocessors, digital signal processors (DSP), programmable controllers, application-specific integrated circuits (ASIC), programmable logic devices (PLD), other similar processing units, or combinations of these units. In the present embodiment, the first storage device 212 and the second storage device 222 may include, for example, memory, flash memory, or non-volatile random access memory (NVRAM).
[0044] Figure 3 FIG. 1 is a flowchart of a remote terminal device authentication method according to an embodiment of the present invention. Figure 2 as well as Figure 3, the processing module 210 may perform the following steps S310 to S340. In step S310, the trigger unit 999 may be enabled (or triggered). In step S320, in response to the trigger unit 213 being enabled, the first processing unit 211 of the processing module 210 may operate in a provision mode to allow the input-output module 220 to establish trust with the processing module 210. In step S330, the trigger unit 213 may be disabled. In step S340, in response to the trigger unit 213 being disabled, the first processing unit 211 of the processing module 210 may operate in a running mode to prohibit another input-output module that has not established trust from connecting to the processing module 210. In the running mode, the processing module 210 may communicate and transmit data with the input-output module 220 that has established trust.
[0045] In this embodiment, the trigger unit 213 is a physical button and is disposed in the processing module 210. Figure 1 The remote terminal device 110 shown can be set in a high-security machine room, for example. Alternatively, in one embodiment, the trigger unit 213 itself can be set in a high-security facility through an external pull line to enhance protection through a high-security machine room, but the present invention is not limited to this. In another embodiment, the trigger unit 213 can also be a virtual button, and can be remotely operated to enable or disable, for example, by a remote network interface or a network management tool.
[0046] Specifically, when the input / output module 220 is installed in Figure 1 When the processing module 210 is in the remote terminal device 110 or the expansion device 120 shown, since trust has not been established between the processing module 210 and the input-output module 220, the processing module 210 will first prohibit the input-output module 220 from connecting to the processing module 210. Then, when the user enables the trigger unit 213 (for example, manually triggering a physical button, or remotely operating through a virtual button), the processing module 210 will start to establish trust with the input-output module 220. In this way, the processing module 210 can implement a highly secure communication protection mechanism, and in the case of hot plugging the input-output module 220, trust can also be dynamically established according to user operations. In addition, how the processing module 210 establishes a trusted input-output module 220 will be described in detail by the following multiple embodiments.
[0047] Figure 4 FIG. 1 is a schematic diagram of initialization of an embodiment of the present invention. Figure 2 as well as Figure 4In the device initialization stage, the processing module 210 may establish a unique processing module key data (private key) 411 and a unique processing module credential data 412, and store the processing module key data 411 and the processing module credential data 412 in the first storage device 212. The input-output module 220 may establish a unique input-output module key data (private key) 421 and a unique input-output module credential data 422, and store the input-output module key data 421 and the input-output module credential data 422 in the second storage device 222. It should be noted that the processing module 210 and the input-output module 220 may establish random key data and credential data respectively, but the key data and credential data established by different modules are all different (i.e., non-repeating). In the present embodiment, the processing module 210 may, for example, store the processing module key data 411 in a secure storage space of the first storage device 212, such as a specific area of a memory or a hardware security module (HSM), but the present invention is not limited thereto. The input-output module 220 may also store the input-output module key data 421 in the secure storage space of the second storage device 222 .
[0048] Figure 5 FIG. 1 is a schematic diagram of a configuration mode of an embodiment of the present invention. Figure 2 as well as Figure 5 After the device is initialized, when the trigger unit 213 is enabled, the first processing unit 211 of the processing module 210 will operate in the configuration mode. In this embodiment, the first processing unit 211 can send a notification signal to the input / output module 220 so that the processing module 210 and the input / output module 220 can obtain each other's credentials. The first processing unit 211 can send a notification signal to the input / output module 220 via the Link Layer Discovery Protocol (LLDP). In this regard, the notification signal may include organization-specific information of the Link Layer Discovery Protocol.
[0049] For example, the first processing unit 211 may adopt a custom LLDP type, such as LLDP Type 127, to configure the relevant parameters in the notification signal. In other words, the data format of the notification signal may satisfy LLDP Type 127, wherein the data format may include a destination address (DA), a source address (SA), an Ethernet type (Ether type), an identification code (Chassis ID), a port identification code (Port ID), a time to live (TTL), optional TLVs (Type, Length, Values) and an end frame (End of LLDPDU TLV). In this regard, the identification code, the port identification code, the time to live, the optional TLVs and the end frame may have a variable data length, and the first processing unit 211 may encrypt the relevant data related to the configuration mode into the above data fields based on the basic TLV data format. As a result, when the second processing unit 221 of the input / output module 220 receives the notification signal having the above data format, it can confirm that the first processing unit 211 operates in the configuration mode and synchronously execute the configuration mode.
[0050] In this embodiment, when the processing module 210 has notified the input-output module 220 to perform the configuration mode, the processing module 210 and the input-output module 220 can obtain each other's credentials. In this regard, the processing module 210 and the input-output module 220 can obtain each other's credentials based on the mutual transport layer security (MTLS) communication protocol to establish trust, but the present invention is not limited to this. After the processing module 210 and the input-output module 220 establish trust, a communication connection 401 can be established. In the configuration mode, the processing module 210 and the input-output module 220 can trust the data transmitted to each other by the handshake between the processing module 210 and the input-output module 220.
[0051] Figure 6 FIG. 1 is a flowchart of obtaining the counterparty's credentials according to an embodiment of the present invention. Figure 2 , Figure 5 as well as Figure 6, the processing module 210 and the input / output module 220 may perform the following steps S610 to S640. In step S610, in the configuration mode, the first processing unit 211 of the processing module 210 may send the processing module credential data 412 to the input / output module 220. In step S620, the second processing unit 221 of the input / output module 220 may receive the processing module credential data 412 sent by the processing module 210 to store the processing module credential data 412 in the second storage device 222, i.e. Figure 5 In step S630, the second processing unit 221 of the input-output module 220 may send the input-output module credential data 422 to the processing module 210. In step S640, the first processing unit 211 of the processing module 210 may receive the input-output module credential data 422 sent by the input-output module 220 to store the input-output module credential data 422 in the first storage device 212, i.e. Figure 5 The input and output module credential data 413.
[0052] It is worth noting that the processing module 210 can also store a plurality of different input-output module credential data from different input-output modules in the second storage device 222. Furthermore, when the processing module 210 receives new input-output module credential data sent again by the input-output module that has recorded the credential data, the processing module 210 can copy the new input-output module credential data to the first storage device 212.
[0053] Figure 7 Schematic diagram of an operating mode of an embodiment of the present invention. Figure 2 as well as Figure 7 , when the trigger unit 213 is disabled, the first processing unit 211 of the processing module 210 will operate in the running mode. In this embodiment, the processing module 210 and the input-output module 220 can perform credential confirmation based on a common transport layer security protocol. In this regard, the processing module 210 and the input-output module 220 will handshake to verify whether each other's credential data is verified with each other's pre-saved credential data to establish a communication connection 401. In this embodiment, the aforementioned method of verifying whether each other's credential data is the same as each other's pre-saved credential data can be, for example, performing an asymmetric key authentication (Asymmetric Key Authentication).
[0054] Figure 8 FIG. 1 is a flowchart of a handshake procedure according to an embodiment of the present invention. Figure 2 , Figure 5 as well as Figure 6, the processing module 210 and the input / output module 220 may perform the following steps S810-S830. In step S810, the first processing unit 211 of the processing module 210 may send the first handshake data 414 to the input / output module 220, and receive the second handshake data 424 from the input / output module 220. The first handshake data 414 may include the processing module credential data 412. The second handshake data 424 may include the input / output module credential data 422.
[0055] In step S820, the first processing unit 211 of the processing module 210 may decrypt the second handshake data 424 according to the processing module key data 411 stored in the first storage device 212 to obtain the input-output module credential data 422, and verify the input-output module credential data 422 with the input-output module credential data 413 stored in the first storage device 212 to confirm the establishment of trust with the input-output module 220. The first storage device 212 of the processing module 210 may store a plurality of credential data corresponding to different input-output modules, and the first processing unit 211 of the processing module 210 may perform credential search and verification operations according to the input-output module credential data 422. In this regard, if the input-output module credential data 422 and the input-output module credential data 413 are verified, the first processing unit 211 confirms that the input-output module 220 is a trusted device, and the communication connection 401 may be established. On the contrary, if the I / O module credential data 422 and the I / O module credential data 413 fail to be verified, the first processing unit 211 prohibits (or refuses) the I / O module 220 from connecting to the processing module 210 .
[0056] In step S830, the second processing unit 221 of the input / output module 220 may decrypt the first handshake data 414 according to the input / output module key data 421 stored in the second storage device 222 to obtain the processing module credential data 412, and verify the processing module credential data 412 with the processing module credential data 423 stored in the second storage device 222 to confirm whether trust has been established with the processing module 210. In this regard, if the processing module credential data 412 and the processing module credential data 423 are verified, the second processing unit 221 confirms that the processing module 210 is a trustworthy device and may establish a communication connection 401. In this way, the processing module 210 may communicate with the input / output module 220 that has successfully obtained the credential data of the other party in the previous configuration mode, and may refuse to connect with other input / output modules that have not successfully obtained the credential data of the other party.
[0057] In summary, the communication system, remote terminal device and authentication method thereof of the present invention can determine whether to establish trust with the hot-swappable input / output module by operating a trigger unit with a high security feature, and can effectively ensure that the input / output module communicating with the processing module is a trusted device.
[0058] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A remote terminal device, characterized in that: include: Processing module, including: a first processing unit; as well as A first storage device is coupled to the first processing unit. wherein in response to the trigger unit being enabled, the first processing unit operates in a configuration mode to allow the input / output module to establish trust with the processing module, In response to the trigger unit being disabled, the first processing unit operates in a running mode to prohibit another input / output module for which trust has not yet been established from being connected to the processing module.
2. The remote terminal device according to claim 1, characterized in that: In response to the first processing unit operating in the configuration mode, the first processing unit sends a notification signal to the input-output module, so that the processing module and the input-output module acquire each other's credentials.
3. The remote terminal device according to claim 2, characterized in that: The first processing unit sends the notification signal to the input / output module via Link Layer Discovery Protocol (LLDP).
4. The remote terminal device according to claim 3, characterized in that: The notification signal includes organization-specific information of the link layer discovery protocol.
5. The remote terminal device according to claim 2, characterized in that: In response to the processing module and the input-output module acquiring each other's credentials, the first processing unit sends the processing module credential data to the input-output module, and receives the input-output module credential data sent by the input-output module to store the input-output module credential data in the first storage device, and the second processing unit of the input-output module receives the processing module credential data sent by the processing module to store the processing module credential data in the second storage device of the input-output module.
6. The remote terminal device according to claim 5, characterized in that: In response to the first processing unit operating in the running mode, the first processing unit sends first handshake data to the input-output module and receives second handshake data from the input-output module. The first processing unit decrypts the second handshake data according to the first key stored in the first storage device, and verifies it with the input-output module credential data stored in the first storage device to confirm the establishment of a communication connection with the input-output module.
7. The remote terminal device according to claim 6, characterized in that: The second processing unit of the input-output module decrypts the first handshake data according to the second key stored in the second storage device, and verifies it with the processing module credential data stored in the second storage device to confirm the establishment of a communication connection with the processing module.
8. The remote terminal device according to claim 2, characterized in that: The processing module and the input / output module acquire each other's credentials based on a common transport layer security communication protocol to establish trust.
9. The remote terminal device according to claim 1, characterized in that: The trigger unit is a physical button and is arranged in the processing module.
10. The remote terminal device according to claim 1, characterized in that: The trigger unit is a virtual button and is remotely enabled or disabled by a remote network interface or a network management tool.
11. The remote terminal device according to claim 1, characterized in that: The remote terminal device further includes the input-output module.
12. The remote terminal device according to claim 1, characterized in that: The input-output module is arranged in the expansion device.
13. A remote terminal device authentication method, characterized in that: The remote terminal device includes a processing module, and the authentication method includes: In response to the trigger unit being enabled, operating the first processing unit of the processing module in a configuration mode to allow the input-output module to establish trust with the processing module; and In response to the trigger unit being disabled, the first processing unit of the processing module operates in a running mode to prohibit another input / output module, for which trust has not yet been established, from being connected to the processing module.
14. The authentication method according to claim 13, characterized in that: The step of operating the first processing unit of the processing module in the configuration mode includes: In response to the first processing unit operating in the configuration mode, the first processing unit sends a notification signal to the input-output module, so that the processing module and the input-output module acquire each other's credentials.
15. The authentication method according to claim 14, characterized in that: The first processing unit sends the notification signal to the input / output module via a link layer discovery protocol.
16. The authentication method according to claim 15, characterized in that: The notification signal includes organization-specific information of the link layer discovery protocol.
17. The authentication method according to claim 14, characterized in that: The step of acquiring the other party's credentials between the processing module and the input / output module includes: Sending processing module credential data to the input-output module through the first processing unit of the processing module; receiving the processing module credential data sent by the processing module through the second processing unit of the input-output module, so as to store the processing module credential data in the second storage device of the input-output module; Sending input-output module voucher data to the processing module via the second processing sheet of the input-output module; and The input-output module credential data sent by the input-output module is received by the first processing unit of the processing module, so as to store the input-output module credential data in the first storage device of the processing module.
18. The authentication method according to claim 17, characterized in that: In response to the first processing unit operating in the running mode, the authentication method further includes: Sending first handshake data to the input-output module through the first processing unit of the processing module, and receiving second handshake data from the input-output module; and decrypting the second handshake data according to the first key stored in the first storage device by the first processing unit of the processing module, and verifying it with the input-output module credential data stored in the first storage device to confirm the establishment of a communication connection with the input-output module; and The first handshake data is decrypted by the second processing unit of the input-output module according to the second key stored in the second storage device, and is verified with the processing module credential data stored in the second storage device to confirm the establishment of a communication connection with the processing module.
19. The authentication method according to claim 14, characterized in that: The processing module and the input / output module acquire each other's credentials based on a common transport layer security communication protocol to establish trust.
20. A communication system, characterized in that: include A remote terminal unit including a processing module; and an expansion device, comprising an input-output module and coupled to the remote terminal device, wherein in response to the trigger unit of the processing module being enabled, the processing module operates in a configuration mode to allow the input / output module to establish trust with the processing module, In response to the trigger unit being disabled, the processing module operates in a running mode to prohibit another input / output module that has not established trust from being connected to the processing module.