Remote safety control system and method for router
By designing a router remote security control system containing multiple security modules, the shortcomings of the router remote control system in the prior art in terms of security protection are solved, and higher identity authentication accuracy, data transmission security and network security threat response capabilities are achieved.
Patent Information
- Application Number
- CN202510561077.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-06-24
AI Technical Summary
The existing router remote control system has shortcomings in security protection, which is difficult to resist complex network attacks, there is a risk of being cracked during data transmission, and the ability to prevent illegal user intrusions is limited.
A remote security control system for routers is designed, including identity authentication module, data encryption module, access control module, security monitoring module, key management module, logging module and remote management module. A two-factor authentication algorithm is used to combine biometrics and dynamic passwords, and a hybrid encryption algorithm combined with AES and RSA, anomaly detection algorithm based on machine learning, and a key hierarchical management structure to ensure the security and reliability of the system.
The two-factor authentication algorithm improves the accuracy and security of identity authentication, and the hybrid encryption algorithm ensures the security of data transmission. The machine learning-based exception detection algorithm and a complete access control mechanism can promptly detect and respond to network security threats, ensure the stable operation of routers and user network security.
Smart Images

Figure CN120200834A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of router remote control, and specifically provides a remote security control system and method for a router. Background Technique
[0002] With the rapid development of Internet technology, routers, as core devices for network connection, have been widely used in scenarios such as homes and enterprises. Users' demand for remotely managing and controlling routers is increasing day by day. However, there are many security problems in current router remote control. For example, during the remote access process, it is vulnerable to network attacks, data transmission may be stolen or tampered with, and illegal users may obtain control of the router, resulting in network security risks and threatening users' privacy and network usage security.
[0003] Taking the Chinese patent CN114785668A "A Router Remote Control System" as an example, although this patent realizes the remote control of the router, in terms of security protection, it only uses conventional user authentication and encrypted transmission, which is difficult to resist increasingly complex network attack means, and there is still a risk of being cracked during data transmission. Another example is the patent CN110278092A "Router Remote Control Method and System Based on MQTT Protocol", whose design in terms of security is also not perfect, and its ability to prevent illegal user intrusion is limited.
[0004] Therefore, it is of great practical significance to design a secure and reliable router remote security control system and method. Summary of the Invention
[0005] The purpose of the present invention is to provide a remote security control system and method for a router to solve the problems raised in the above background technique.
[0006] To achieve the above purpose, the present invention provides the following technical solution: A remote security control system for a router includes an identity authentication module, a data encryption module, an access control module, a security monitoring module, a key management module, a log recording module, and a remote management module;
[0007] The identity authentication module is used to authenticate the identity of users remotely accessing the router;
[0008] The data encryption module is responsible for encrypting the data transmitted during the remote control process;
[0009] The access control module performs access control on various functions of the router according to the identity and permissions of the user;
[0010] The security monitoring module is used to monitor the running status of the router and the network security situation in real time;
[0011] The key management module is responsible for generating, storing, updating, and destroying the keys used in the system;
[0012] The log recording module is used to record important events occurring in the system, including user logins, access operations, and security events;
[0013] The remote management module is used to implement the remote management and control functions of the user for the router.
[0014] Preferably, the identity authentication module specifically adopts a two-factor authentication algorithm combining biometrics and dynamic passwords; when a user first registers, the fingerprint and face biometric information of the user are collected and bound to the initial password set by the user; when the user initiates a remote access request, the system first requires the user to input a dynamic password, which is generated by a time synchronization algorithm and updated every 60 seconds; at the same time, the user needs to provide biometric information through a camera or fingerprint recognition device; the system compares the received dynamic password and biometric information with the information stored in the server, and only when both match is the user allowed to pass the identity authentication;
[0015] The generation formula of the dynamic password: The dynamic password is generated by a time synchronization algorithm. Let the current time be T in seconds, the password update period be P = 60 seconds, and the initial time of the server be T0, then the dynamic password
[0016] OTP = hash((T - T0) / P)
[0017] where hash() is a hash function, and a dynamically changing password is obtained by performing a hash operation on the time factor;
[0018] The matching algorithm for biometrics is that for the collected fingerprint and face biometric information, it is transformed into a feature vector through a feature extraction algorithm; let the biometric vector stored by the user in the server be B server , and the biometric vector currently input by the user be B input , and the Euclidean distance between the two is calculated
[0019]
[0020] where n is the dimension of the feature vector, and when d is less than a pre-set threshold θ, it is determined that the biometric match is successful.
[0021] Preferably, the data encryption module adopts a hybrid encryption algorithm combining AES and RSA; before data transmission, the data is encrypted using the AES algorithm, and the key of the AES algorithm is encrypted and transmitted to the receiving party using the RSA algorithm; the receiving party decrypts with its own private key to obtain the AES key, and then decrypts the data with the AES key to ensure the security and confidentiality of the data during transmission.
[0022] Preferably, the access control module establishes a user-role-permission mapping relationship; the system administrator can assign different roles to different users, such as ordinary users, senior administrators, etc., and each role corresponds to a different set of permissions. For example, ordinary users can only view the basic running status information of the router, while senior administrators can perform configuration modifications, firmware upgrades, etc.; when the user passes the identity authentication, the access control module determines the functions and resources that the user can access according to the user's role, and restricts the user's access to other functions.
[0023] Preferably, the security monitoring module uses an anomaly detection algorithm based on machine learning. By collecting the network traffic data and system log information of the router, it establishes a behavior model under normal running conditions; when there is a large deviation between the actual data detected and the model, it is judged as an abnormal behavior and an alarm is issued in a timely manner. At the same time, this module also detects network attacks, such as DDoS attacks, port scans, etc. Once an attack behavior is detected, corresponding protection measures are immediately taken, such as blocking the source IP address of the attack, etc.;
[0024] The core algorithm formula of the anomaly detection algorithm based on machine learning is:
[0025]
[0026] where h(x) represents the average value of the path length of sample x, n is the number of isolation trees constructed, and path_length(x,T i ) is the path length of sample x in the i-th isolation tree.
[0027] Preferably, the key management module adopts a hierarchical key management structure. The master key is generated and stored by the hardware security module HSM and is used to encrypt and protect other keys; other keys such as AES keys, RSA keys, etc. are encrypted by the master key and stored in the key database; the keys are updated regularly. When the key reaches the expiration date or there is a security risk, it is destroyed and regenerated in a timely manner to ensure the security and effectiveness of the key.
[0028] Preferably, the log records in the log recording module include the time when the event occurred, user information, and detailed information about the operation content; the above log information is used for security auditing and troubleshooting. When a security problem or system failure occurs, the administrator can quickly locate the cause of the problem by viewing the log records and take corresponding solutions.
[0029] Preferably, in the remote management module, the user sends a remote control instruction through a mobile phone APP or a Web interface. After receiving the instruction, the remote management module parses and verifies the instruction to ensure the legality and security of the instruction. Then, the instruction is forwarded to the corresponding function module of the router to perform the corresponding operation, and the operation result is returned to the user.
[0030] A control method for a remote security control system of a router includes the following steps:
[0031] Step 1: User identity authentication: The user initiates a request to remotely access the router. The identity authentication module requires the user to input a dynamic password and provide biometric information to authenticate the user. If the authentication is successful, proceed to the next step; if the authentication fails, reject the user's access and record the login failure log.
[0032] Step 2: Data encrypted transmission: Before data transmission, the data encryption module encrypts the data using the AES algorithm, and then encrypts the AES key using the RSA algorithm. The encrypted data and key are transmitted to the receiving party. The receiving party decrypts the AES key using the RSA private key and then decrypts the data using the AES key.
[0033] Step 3: Access control: The access control module determines the router functions and resources that the user can access based on the user's identity and permissions. The user can only operate on the functions within the authorized scope. If the user attempts to access unauthorized functions, the access will be rejected and the violation operation log will be recorded.
[0034] Step 4: Security monitoring and protection: The security monitoring module monitors the running status of the router and the network security status in real time. When abnormal behavior or a network attack is detected, an alarm is immediately issued and corresponding protection measures are taken.
[0035] Step 5: Key management: The key management module generates, updates, and destroys keys regularly according to the key hierarchical management structure to ensure the security and effectiveness of the keys.
[0036] Step 6: Log recording and auditing: The log recording module records important events that occur in the system. The administrator conducts security audits and troubleshooting by viewing the log records.
[0037] Compared with the prior art, the beneficial effects of the present invention are:
[0038] The present invention adopts a two-factor authentication algorithm, combines biometric features with dynamic passwords, greatly improves the accuracy and security of user identity authentication, and effectively prevents illegal users from accessing the router. The application of the hybrid encryption algorithm gives full play to the high efficiency of the AES algorithm and the security of the RSA algorithm, ensuring that data is not stolen or tampered with during transmission. The anomaly detection algorithm based on machine learning and the perfect access control mechanism can timely detect and respond to network security threats, ensuring the stable operation of the router and the network security of users. The key hierarchical management and regular update mechanism enhance the security of the keys and reduce the risk of key leakage. The detailed log recording and auditing functions provide strong support for the traceability of security incidents and troubleshooting, facilitating administrators to discover and solve problems in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is the system schematic diagram of the present invention;
[0040] Figure 2 is the method flowchart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0042] Please refer to Figure 1-2 , the present invention provides a remote security control system for a router, including an identity authentication module, a data encryption module, an access control module, a security monitoring module, a key management module, a log recording module, and a remote management module;
[0043] The identity authentication module is used to authenticate the users who remotely access the router;
[0044] The data encryption module is responsible for encrypting the data transmitted during the remote control process;
[0045] The access control module performs access control on the various functions of the router according to the identity and permissions of the users;
[0046] The security monitoring module is used to monitor the running status of the router and the network security status in real time;
[0047] The key management module is responsible for generating, storing, updating, and destroying the keys used in the system;
[0048] The log recording module is used to record the important events that occur in the system, including user logins, access operations, and security events;
[0049] The remote management module is used to implement the remote management and control functions of the router by users.
[0050] The identity authentication module specifically adopts a two-factor authentication algorithm combining biometrics and dynamic passwords; when a user registers for the first time, the fingerprint and face biometric information of the user are collected and bound to the initial password set by the user; when the user initiates a remote access request, the system first requires the user to input a dynamic password, which is generated by a time synchronization algorithm and updated every 60 seconds; at the same time, the user needs to provide biometric information through a camera or fingerprint recognition device; the system compares the received dynamic password and biometric information with the information stored in the server, and only when both match, the user is allowed to pass the identity authentication;
[0051] The generation formula of the dynamic password: The dynamic password is generated by a time synchronization algorithm. Let the current time be T in seconds, the password update period be P = 60 seconds, and the initial time of the server be T0. Then the dynamic password
[0052] OTP = hash((T - T0) / P)
[0053] where hash() is a hash function, and a dynamically changing password is obtained by performing a hash operation on the time factor;
[0054] The matching algorithm for biometrics is that for the collected fingerprint and face biometric information, it is transformed into a feature vector through a feature extraction algorithm; let the biometric feature vector stored by the user in the server be B server , and the biometric feature vector currently input by the user be B input , and the Euclidean distance between the two is calculated
[0055]
[0056] where n is the dimension of the feature vector. When d is less than a pre-set threshold θ, it is determined that the biometric match is successful.
[0057] The data encryption module adopts a hybrid encryption algorithm combining AES and RSA; before data transmission, the AES algorithm is used to encrypt the data, and the key of the AES algorithm is encrypted by the RSA algorithm and transmitted to the receiving party; the receiving party uses its own private key to decrypt to obtain the AES key, and then uses the AES key to decrypt the data, thus ensuring the security and confidentiality of the data during transmission.
[0058] The access control module establishes the mapping relationship of user-role-permission; the system administrator can assign different roles to different users, such as ordinary users, senior administrators, etc., and each role corresponds to a different set of permissions. For example, ordinary users can only view the basic operating status information of the router, while senior administrators can perform operations such as configuration modification and firmware upgrade; when the user passes the identity authentication, the access control module determines the accessible functions and resources according to the user's role and restricts the user's access to other functions.
[0059] The security monitoring module adopts an anomaly detection algorithm based on machine learning. By collecting the network traffic data and system log information of the router, it establishes a behavior model under normal operating conditions; when there is a large deviation between the actual data detected and the model, it is judged as an abnormal behavior and an alarm is issued in a timely manner. At the same time, this module also detects network attacks, such as DDoS attacks, port scans, etc. Once an attack behavior is detected, corresponding protection measures are immediately taken, such as blocking the source IP address of the attack, etc.;
[0060] The core algorithm formula of the anomaly detection algorithm based on machine learning is:
[0061]
[0062] Among them, h(x) represents the average value of the path length of sample x, n is the number of isolation trees constructed, and path_length(x,T i ) is the path length of sample x in the i-th isolation tree.
[0063] The key management module adopts a hierarchical key management structure. The master key is generated and stored by the hardware security module HSM and is used to encrypt and protect other keys; other keys such as AES keys and RSA keys are encrypted by the master key and stored in the key database; the keys are updated regularly. When the key reaches the expiration date or there is a security risk, it is destroyed and regenerated in a timely manner to ensure the security and effectiveness of the key.
[0064] The log records in the log recording module include the time when the event occurred, user information, and detailed information about the operation content; the above log information is used for security auditing and troubleshooting. When a security problem or system failure occurs, the administrator can quickly locate the cause of the problem by viewing the log records and take corresponding solutions.
[0065] In the remote management module, the user sends remote control instructions through the mobile phone APP or the Web interface. After receiving the instructions, the remote management module parses and verifies the instructions to ensure the legality and security of the instructions; then it forwards the instructions to the corresponding function module of the router, executes the corresponding operations, and returns the operation results to the user.
[0066] A control method for a remote security control system of a router, comprising the following steps:
[0067] Step 1, user identity authentication: The user initiates a request to remotely access the router. The identity authentication module requires the user to input a dynamic password and provide biometric information to authenticate the user. If the authentication is successful, proceed to the next step; if the authentication fails, deny the user access and record the login failure log.
[0068] Step 2, data encrypted transmission: Before data transmission, the data encryption module encrypts the data using the AES algorithm, and then encrypts the AES key using the RSA algorithm, and transmits the encrypted data and key to the receiving party. The receiving party decrypts the AES key using the RSA private key, and then decrypts the data using the AES key.
[0069] Step 3, access control: The access control module determines the router functions and resources that the user can access according to the user's identity and permissions. The user can only operate on the functions within the authorized scope. If the user attempts to access unauthorized functions, the access will be denied and the illegal operation log will be recorded.
[0070] Step 4, security monitoring and protection: The security monitoring module monitors the running status of the router and the network security status in real time. When detecting abnormal behaviors or network attacks, it immediately issues an alarm and takes corresponding protection measures.
[0071] Step 5, key management: The key management module generates, updates, and destroys keys regularly according to the key hierarchical management structure to ensure the security and effectiveness of the keys.
[0072] Step 6, log recording and auditing: The log recording module records important events that occur in the system. The administrator conducts security audits and troubleshooting by viewing the log records.
[0073] Embodiment:
[0074] In practical applications, the user first registers in the system, enters biometric information such as fingerprints and faces, and sets an initial password. When the user needs to remotely access the router, open the mobile APP or log in to the Web interface. The system prompts the user to input the dynamic password and perform biometric identification. The identity authentication module compares the information input by the user with the information stored in the server. If the authentication is successful, the user can enter the remote management interface.
[0075] During the remote management process, the control instructions sent by the user are encrypted and transmitted through the data encryption module. For example, when the user wants to modify the wireless network password of the router, the instruction is first encrypted by the AES algorithm, and the AES key is then encrypted by the RSA algorithm and sent to the router. After receiving the data, the router uses its own RSA private key to decrypt and obtain the AES key, then decrypts the instruction with the AES key, executes the corresponding operation, and encrypts and returns the operation result to the user.
[0076] The access control module restricts the user's operation permissions according to the user's role. Suppose the user is an ordinary user. In the remote management interface, they can only view information such as the network connection status and device list of the router, and cannot perform advanced operations such as configuration modification.
[0077] The security monitoring module monitors the running status of the router in real time. If it is found that the network traffic suddenly increases abnormally, suspected of being under a DDoS attack, the security monitoring module immediately issues an alarm, automatically blocks the source IP address of the attack, and records the relevant security event logs at the same time.
[0078] The key management module updates the keys according to the set period. For example, new AES keys and RSA key pairs are generated every 30 days, the old keys are destroyed, and the new keys are used to encrypt and decrypt the data.
[0079] The log recording module details and records information such as each user login, operation, and security events that occur in the system. The administrator can view the log records within a specific time period through the log query function for security auditing and troubleshooting.
[0080] Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A remote security control system for a router, characterized in that: It includes identity authentication module, data encryption module, access control module, security monitoring module, key management module, log recording module and remote management module; The identity authentication module is used to authenticate the identity of the user who remotely accesses the router; The data encryption module is responsible for encrypting the data transmitted during the remote control process; The access control module performs access control on various functions of the router according to the identity and authority of the user; The security monitoring module is used to monitor the running status and network security status of the router in real time; The key management module is responsible for generating, storing, updating and destroying keys used in the system; The logging module is used to record important events that occur in the system, including user logins, access operations, and security events; The remote management module is used to implement the user's remote management and control function of the router.
2. A remote security control system for a router according to claim 1, characterized in that: The identity authentication module specifically adopts a two-factor authentication algorithm based on the combination of biometrics and dynamic passwords; when a user registers for the first time, the user's fingerprint and face biometric information are collected and bound to the initial password set by the user; when the user initiates a remote access request, the system first requires the user to enter a dynamic password, which is generated by a time synchronization algorithm and updated every 60 seconds; at the same time, the user needs to provide biometric information through a camera or fingerprint recognition device; the system compares the received dynamic password and biometric information with the information stored in the server, and only when the two match will the user be allowed to pass the identity authentication; The formula for generating a dynamic password is: the dynamic password is generated using a time synchronization algorithm. Assume that the current time is T, in seconds, the password update cycle is P = 60 seconds, and the server initial time is T0, then the dynamic password OTP = hash ((T-T0) / P) Where hash() is a hash function, which obtains a dynamically changing password by performing a hash operation on the time factor; The biometric matching algorithm is to convert the collected fingerprint and face biometric information into feature vectors through feature extraction algorithm; The biometric vector stored by the user on the server is B server , the biometric vector currently input by the user is B input , by calculating the Euclidean distance between the two Where n is the dimension of the feature vector, and when d is less than a preset threshold θ, the biometric match is determined to be successful.
3. The remote security control system for a router according to claim 1, characterized in that: The data encryption module adopts a hybrid encryption algorithm combining AES and RSA; before data transmission, the data is encrypted using the AES algorithm, and the key of the AES algorithm is encrypted by the RSA algorithm and transmitted to the receiver; the receiver uses its own private key to decrypt the AES key, and then uses the AES key to decrypt the data, thereby ensuring the security and confidentiality of the data during transmission.
4. The remote security control system for a router according to claim 1, characterized in that: The access control module establishes a mapping relationship between user, role and permission; the system administrator can assign different roles to different users, and each role corresponds to a different set of permissions; when the user passes the identity authentication, the access control module determines the functions and resources that the user can access based on the user's role, and restricts the user's access to other functions.
5. The remote security control system for a router according to claim 1, characterized in that: The security monitoring module uses an anomaly detection algorithm based on machine learning to establish a behavior model under normal operating conditions by collecting network traffic data and system log information of the router. When there is a large deviation between the actual data monitored and the model, it is judged as abnormal behavior and an alarm is issued in time. At the same time, the module will also detect network attacks and take corresponding protective measures immediately once an attack is detected. The core algorithm formula of the anomaly detection algorithm based on machine learning is: Among them, h(x) represents the average path length of sample x, n is the number of isolated trees constructed, path_length(x,T i ) is the path length of sample x in the i-th isolated tree.
6. The remote security control system for a router according to claim 1, characterized in that: The key management module adopts a key hierarchical management structure. The master key is generated and stored by the hardware security module HSM, which is used to encrypt and protect other keys. Other keys are encrypted by the master key and stored in the key database. The keys are updated regularly. When the keys reach their expiration date or there is a security risk, they are destroyed and regenerated in time to ensure the security and effectiveness of the keys.
7. The remote security control system for a router according to claim 1, characterized in that: The log records in the log recording module contain detailed information on the time of event occurrence, user information, and operation content; the above log information is used for security auditing and troubleshooting. When a security problem or system failure occurs, the administrator can quickly locate the cause of the problem by viewing the log records and take corresponding solutions.
8. The remote security control system for a router according to claim 1, characterized in that: In the remote management module, the user sends remote control instructions through a mobile phone APP or a Web interface. After receiving the instructions, the remote management module parses and verifies the instructions to ensure the legitimacy and security of the instructions; then forwards the instructions to the corresponding functional module of the router, performs the corresponding operations, and returns the operation results to the user.
9. A control method for a remote security control system for a router according to any one of claims 1 to 8, characterized in that: The following steps are involved: Step 1: User identity authentication: The user initiates a request to remotely access the router. The identity authentication module requires the user to enter a dynamic password and provide biometric information to authenticate the user. If the verification is successful, proceed to the next step; If the verification fails, the user access is denied and the login failure log is recorded; Step 2: Data encryption transmission: Before data transmission, the data encryption module uses the AES algorithm to encrypt the data, and then uses the RSA algorithm to encrypt the AES key, and transmits the encrypted data and key to the receiver; the receiver uses the RSA private key to decrypt the data to obtain the AES key, and then uses the AES key to decrypt the data; Step 3, access control: The access control module determines the router functions and resources that the user can access based on the user's identity and permissions; the user can only operate the functions within the authorized scope. If the user attempts to access unauthorized functions, access is denied and the illegal operation log is recorded; Step 4: Security monitoring and protection: The security monitoring module monitors the router's operating status and network security in real time. When abnormal behavior or network attacks are detected, an alarm is immediately issued and corresponding protective measures are taken; Step 5: Key management: The key management module regularly generates, updates and destroys keys according to the key hierarchical management structure to ensure the security and effectiveness of the keys; Step 6: Logging and auditing: The logging module records important events that occur in the system. Administrators can perform security audits and troubleshooting by viewing log records.
Citation Information
Patent Citations
Router remote control method and system based on MQTT protocol
CN110278092A
Router remote control system
CN114785668A
Cited By
Instruction operation device and method
CN121278703A