Remote management system, router and remote management method

The remote management system, which generates UDP port numbers and authentication keys through network devices, solves the problems of high security risks and network path dependence in existing technologies, and achieves secure and convenient remote management.

CN121750252APending Publication Date: 2026-03-27ELECOM CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing technologies require an internet connection to remotely manage network devices connected to a private network, which leads to higher security risks and necessitates additional network paths, such as wireless communication networks or local area networks, increasing costs and complexity.

Method used

The network device randomly generates a UDP port number and authentication key, and uses a secure path to send them along with the device's inherent information to the remote management server in advance. The remote management server sends the authentication key when needed to establish a secure communication session. The network device establishes communication when the authentication key matches, avoiding port scanning and reliance on wireless communication networks.

Benefits of technology

This approach reduces security risks, simplifies user operations, and improves the security and reliability of remote management without adding extra network paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750252A_ABST
    Figure CN121750252A_ABST
Patent Text Reader

Abstract

The invention provides a remote management system, which is used for constructing a communication session with relatively low security risk with network equipment and carrying out remote management. A remote management system (100) includes a network device (20) connected to a private network (10), a router (30), and a remote management server (50) and an operation terminal (60) connected to the Internet (40); the network equipment randomly generates a UDP port number and an authentication key, and sends the UDP port number and the authentication key to the remote management server in advance; when the operation terminal requests the remote management server to operate the network device, the remote management server sends an authentication key to the network device, and the network device constructs a communication session between the network device and the remote management server under the condition that the received authentication key is consistent with a pre-sent authentication key. And the operation terminal carries out remote management on the network equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a remote management system and a remote management method for remotely managing network devices connected to a dedicated network via the Internet. Background Technology

[0002] The following inventions have been disclosed regarding the remote management of network devices and the communication required to initiate remote management.

[0003] Patent document 1 (Japanese Patent Publication No. 2023-61252) discloses an information processing system, information processing device, management server, and program that can collect and retrieve logs of a device through remote maintenance operations when the device makes a support request. In the information processing system described in Patent Document 1, a communication session is established between the target device and the management server. Upon receiving a request from the management server that has established the communication session, the target device responds to the request and sends out specified information. The management server or the target device's termination processing unit discards the established communication session when specified termination conditions are met.

[0004] In addition, Patent Document 2 (Japanese Patent Publication No. 2023-52288) discloses a relay method that enables secure access to a target terminal for remote management. In the relay method described in Patent Document 2, when the connection management device of the relay system obtains terminal identification information for identifying a target terminal from the client terminal, it determines a first relay device for relay communication and determines connection information required for the client terminal to connect to the first relay device. The connection management device associates the determined connection information with the terminal identification information and stores it in a storage unit, while simultaneously notifying the client terminal of the determined connection information. When the determined first relay device receives an access request from the client terminal based on the connection information, it relays the communication between the client terminal and the target terminal based on the terminal identification information associated with the connection information.

[0005] In addition, Patent Document 3 (Japanese Patent Publication No. 2020-160984) discloses a data collection device, represented by an Internet of Things (ITO) device, which can reduce security risks without compromising user convenience. Patent Document 3 describes a data collection side device comprising: a command receiving unit for receiving a port opening command specifying a port from a data utilization side device via a wireless communication network; an authentication processing unit for performing authentication processing on the data utilization side device that sent the port opening command; a command execution unit for executing the port opening command to open the port when the data utilization side device successfully authenticates the port; and a data communication unit for performing data communication using the port according to a request from the data utilization side device.

[0006] In addition, Patent Document 4 (International Publication No. 2016 / 207927) discloses a network connection technology used for remote control of a device located at a remote location via a network. Patent Document 4's remote maintenance system includes: a maintenance management device connected to a user device, and a communication relay device connected to a remotely operated device. The maintenance management device sends message data to the communication relay device using pre-assigned mobile network identification information as the destination address. In conjunction with receiving the message data, the communication relay device notifies the maintenance management device of its dynamically assigned IP address. Using this notified IP address as the destination address, the maintenance management device sends remote operation-related information received from the user device to the communication relay device; the communication relay device then relays the remote operation-related information received from the maintenance management device to the remotely operated device.

[0007] Patent document 5 (Japanese Patent Publication No. 2013-201621) discloses a port opening and closing control system that enables remote access to the port from a user terminal in accordance with the usual Internet usage process while avoiding unnecessary opening of the port of the gateway device in the home to the Internet. In the port opening / closing control system described in Patent Document 5, the gateway device in a residence closes its port to the Internet. If the instruction device has a DNS content server unit and executes the normal Internet usage procedure where the user terminal specifies the hostname of the gateway device (GW device), the terminal sends a name resolution request. Upon receiving the name resolution request, the instruction device replies with a DNS response specifying a TTL (Time To Live) of 0 seconds, and, referring to the management table of the gateway device's hostname and LAN address, sends a port opening request to the gateway device via the LAN. The terminal accesses the gateway device's port using the global IP address obtained in the DNS response, and when the access ends, the gateway device closes its port.

[0008] In addition, Patent Document 6 (Japanese Patent Application Publication No. 2013-206260) discloses an authentication method that can initiate communication based on an external request in a way that has lower security risks when initiating communication required for remote management. The authentication method described in Patent Document 6 involves pre-recording a pre-defined authentication format in a relay device. The external requesting terminal divides the authentication data according to its authentication format into packets that can be embedded into TCP or UDP data packets, embeds them into the port number portion of a series of data packets, and sends them sequentially to the device. The device with communication capabilities monitors the continuous pattern of the port numbers of the data packets received at the firewall and, referring to the pre-recorded authentication format, opens the corresponding port of the firewall to accept access or starts the corresponding software to process the access request when the pattern is detected to match the authentication format. Existing technical documents Patent documents

[0009] Patent Document 1: Japanese Patent Publication No. 2023-61252 Patent Document 2: Japanese Patent Publication No. 2023-52288 Patent Document 3: Japanese Patent Publication No. 2020-160984 Patent Document 4: International Publication No. 2016 / 207927 Patent Document 5: Japanese Patent Publication No. 2013-201621 Patent Document 6: Japanese Patent Publication No. 2013-206260 Summary of the Invention The problem that the invention aims to solve

[0010] Network devices connected to a private network are typically configured to connect to servers on the Internet, but not to connect to the network device from servers on the Internet, in order to avoid security risks from the outside. However, when support departments need to remotely manage network devices connected to a private network, they need to connect to the network devices from a server on the Internet. Numerous patent documents disclose methods for connecting to network devices connected to a private network from a server on the Internet.

[0011] In the information processing system described in Patent Document 1, when a support personnel instructs a user to perform a specified support request operation on the operating unit of the target device (e.g., long press a button), a communication session is established between the target device and the management server, after which the management server can communicate with the target device. This method carries lower security risks because it only requires the user to perform the specified support request action on the target device's operating system, thus avoiding the establishment of a communication session. However, it requires additional steps for users contacting support via telephone, which can be burdensome for those unfamiliar with network device operation.

[0012] Therefore, patent documents 2 to 6 describe methods for establishing communication sessions between network devices and external management servers without requiring users to make support request operations. In Patent Document 2, when the connection management device notifies the relay device of relay information containing the port number of the target terminal associated with the relay device, the relay device establishes a connection between the relay device and the target terminal based on terminal identification information different from the dedicated address and the port number used by the target terminal for communication. While this method is relatively easy, the port number is in the range of 0 to 65535, and security may be compromised if the port number is detected through port scanning or if the port number happens to match.

[0013] In contrast, in Patent Document 3, the data utilization side device sends a port open command to the data collection side device through a wireless communication network. If the data utilization side device, which is the source of the port open command, is successfully authenticated, the security risks faced by the data collection side device are mitigated by opening the port. However, in this case, the data utilization device needs to connect to a wireless communication network in addition to the regular Internet.

[0014] In the remote maintenance system of Patent Document 4, the maintenance management device also utilizes the SMS function of the mobile communication network to send a connection request message to a communication relay device that has been pre-assigned with the inherent identification information of the mobile communication network. In Patent Document 4, a dynamically changing IP address is received from the communication relay device each time a connection request message is sent, and information related to remote operation is relayed to the communication relay device based on the received IP address, thereby further mitigating security risks. However, in this case, in addition to connecting to the regular Internet, the maintenance and management device also needs a wireless communication network.

[0015] Similarly, in the port opening and closing control system of Patent Document 5, the residential gateway device does not directly accept the opening request from the user terminal. Instead, the instruction device stores the local area network address of the residential gateway device in association with the hostname of the DNS registration request. When a name resolution request for the hostname is received from the Internet, a port opening request is sent to the local area network address of the residential gateway device that corresponds to and is stored in association with the hostname, thereby opening the usable port of the residential gateway device. In this case, similarly, in addition to the regular Internet, a local area network is also required between the command device and the home gateway device.

[0016] The authentication method of Patent Document 6 involves recording a predefined authentication format in an external requesting terminal attempting to access an external network and a communication-enabled device equipped with a firewall and capable of accepting access. The external requesting terminal divides the authentication data into packets that can be embedded into port numbers such as TCP or UDP data packets, embeds them into the port number portion of a series of data packets, and sends them sequentially to the aforementioned device. The communication-enabled device monitors the continuous pattern of the port numbers of the received data packets to perform authentication. This method reduces security risks compared to authentication methods such as Patent Document 2, which rely on IP addresses or port numbers for authentication, because it does not require a wireless communication network or local area network and performs authentication by monitoring the continuous pattern of port numbers of received data packets. However, in this case, the authentication data embedded in the port number needs to be sent sequentially. Sometimes authentication takes time, and in the Internet environment, the order in which the authentication data is received may not be consistent with the order in which it is sent, so authentication may fail.

[0017] The main objective of this invention is to provide a remote management system and a remote management method that can establish a low-security communication session with network devices without requiring users to perform special support request operations, thereby enabling remote management of network devices. Another objective of this invention is to provide a remote management system and a remote management method thereof, which can build a communication session with low security risk without adding any communication path other than the Internet, so as to realize remote management of network devices. Methods for solving problems (1) According to one aspect of a remote management system, the system includes network devices connected to a private network, routers relaying between the private network and the Internet, a remote management server connected to the Internet, and operating terminals. The network devices randomly generate UDP port numbers and authentication keys, and pre-send these, along with the network devices' inherent information, to the remote management server via a secure path. If the remote management server receives the UDP port number, authentication key, and the network devices' inherent information, it saves these information. When an operating terminal requests operation from the remote management server, the remote management server sends the authentication key to the UDP port of the network device corresponding to its inherent information. If the authentication key received by the network device at the UDP port matches the pre-sent authentication key, a communication session is established between the network device corresponding to its inherent information and the remote management server. The operating terminal performs remote management of the network devices through the remote management server and the communication session.

[0019] Typically, routers used to relay private networks to the Internet allow communication from the private network side toward the Internet, but do not allow communication from the Internet side toward the private network unless the communication is a response to a communication initiated by the private network side toward the Internet. Therefore, establishing a secure communication session using TLS or similar methods between a network device and a remote management server requires the network device to initiate the communication session with the remote management server. This necessitates certain actions from the network device user. However, many network device users are unfamiliar with its operation, making the process of establishing the communication session a significant burden for them.

[0020] In this scenario, to avoid burdening users, one could consider allowing communication from the internet to the private network by sharing the IP addresses and port numbers of the source and / or destination. However, relying solely on port numbers carries the risk of detection through methods such as port scanning, making it insufficient as a measure to mitigate security risks. Alternatively, instructions authorizing communication from the internet to the dedicated network could be sent via a wireless communication network or local area network (LAN), instead of the regular internet. However, this would require a wireless communication network or LAN between the remote management server and the network devices, increasing costs.

[0021] In one aspect of a remote management system, a network device randomly generates its UDP port number and authentication key, and shares these along with the network device's inherent information with a remote management server via a secure path. Then, when a communication session needs to be established, the remote management server sends the authentication key to the pre-shared UDP port of the network device. The network device authenticates the key, thereby transmitting a communication session establishment request from the remote management server on the Internet to the network device. The network device then establishes a communication session with the remote management server. In this scenario, since not only the port number but also the authentication key must be consistent, the risk of incorrectly constructing a communication session due to network attacks or other reasons can be reduced. In addition, the authentication key is preferably composed of binary data of 256 bits or more. (2) According to the remote management system of the second invention, in one aspect of the remote management system, when UDP packets are sent from the Internet side to the UDP port of the network device, the network device can be configured not to respond or send any data.

[0023] When a UDP packet is sent to a UDP port shared with a remote management server, if a network device responds or sends data, and the port is scanned, the scanner will know that the port is in a listening and waiting state, and may be subject to illegal intrusion using so-called DoS attacks or similar methods. In the remote management system of the second invention, in order to prevent the outside world from noticing that the corresponding port is in a listening and waiting state, the network device does not respond or send any data even when the port is being scanned. (3) According to the remote management system of the third invention, in the remote management system from one aspect to the second invention, the network device can be a wireless LAN access point or a network access server (NAS).

[0025] In this scenario, the remote management system can remotely manage wireless LAN access points or network access servers (NAS). Additionally, other network devices such as network cameras and network game consoles can also be used. (4) According to the remote management system of the fourth invention, in one aspect of the remote management system of the second invention, the network device may include the function of a router.

[0027] This includes network devices such as wireless LAN routers with router functionality, or standalone routers. In this case, a remote management system can remotely manage the router. (5) According to the remote management system of the fifth invention, in the remote management system from one aspect to the fourth invention, TLS (Transport Layer Security) can be used in the secure path and the communication session.

[0029] TLS is a widely adopted security protocol, used for communication between network devices and the AWS cloud (AWS IoT Core). By using TLS, secure two-way communication between network devices and remote management servers can be achieved. (6) According to the remote management system of the sixth invention, in the remote management system of the fifth invention, the remote management server or network device can discard the established communication session when the specified termination conditions are met.

[0031] Although the communication session constructed by this invention has a low security risk, maintaining the communication session in the constructed state still carries security risks. Therefore, it is preferable to discard the communication session when the remote management operation of the network device ends. As a condition for termination in this situation, examples could be the completion of necessary remote operations or the elapsed time since the network device stopped responding. (7) In contrast, other types of routers relay between private networks and the Internet. They randomly generate UDP port numbers and authentication keys on the Internet side, and send the generated UDP port numbers, authentication keys, and their own device information to a remote management server through a secure path. On the UDP port corresponding to the UDP port number, when an authentication key sent from the remote management server is received, and the received authentication key matches the authentication key sent by the router, a communication session is established with the remote management server, and the router receives remote operations from the operating terminal through the communication session.

[0033] According to other aspects of routers, this invention relates to a router corresponding to a network device in a remote management system that includes router functionality. (8) According to other remote management methods, this is a remote management method that performs remote management in a remote management system including network devices connected to a private network, routers relaying between the private network and the Internet, a remote management server connected to the Internet, and an operating terminal. This method includes: a security information sending step whereby the network device randomly generates its UDP port number and authentication key, and sends them along with the network device's inherent information to the remote management server via a secure path; a security information saving step whereby the remote management server, upon receiving the UDP port number, authentication key, and the network device's inherent information, saves the received UDP port number, authentication key, and network device's inherent information; a remote operation request step whereby the operating terminal requests operation on the network device from the remote management server, and the remote management server sends the authentication key to the UDP port of the network device corresponding to the network device's inherent information; a communication session construction step whereby, if the authentication key received by the network device from the UDP port matches the pre-sent authentication key, a communication session is established between the network device corresponding to its inherent information and the remote management server; and a remote management execution step whereby the operating terminal remotely manages the network device through the remote management server and the communication session.

[0035] According to other remote management methods, it is an invention of a remote management method corresponding to a remote management system in one aspect. Attached Figure Description

[0036] Figure 1 This is a schematic diagram representing the overall structure of the remote management system. Figure 2 It is a schematic block diagram representing the structure of a router. Figure 3 This is a schematic block diagram representing the structure of a remote management server. Figure 4 It is a schematic block diagram representing the structure of a network device (wireless LAN access point). Figure 5 It is a schematic block diagram representing the structure of the operating terminal. Figure 6 It is a flowchart illustrating the process of secure information sharing. Figure 7 It is a flowchart that shows the remote operation request and remote management process. Figure 8 It is a flowchart illustrating the remote management process that accompanies the restart of network devices. Figure 9 It is a flowchart illustrating the remote operation request and remote management process of the variant example. Detailed Implementation

[0037] Embodiments of the present invention will now be described with reference to the accompanying drawings. In the following description, the same components are denoted by the same symbols. Furthermore, when the symbols are the same, the names and functions are also the same. Therefore, their detailed descriptions will not be repeated.

[0038] [structure] Figure 1 This is a schematic structural diagram representing the overall structure of the remote management system 100. Figure 1 In the remote management system 100, there are network devices 20 connected to the private network 10, routers 30 relaying between the private network 10 and the Internet 40, and remote management servers 50 and operation terminals 60 connected to the Internet 40. In this embodiment, the example described is that the remotely operated object is network device 20, but the present invention also includes the case where the remotely operated object is router 30. When the remotely operated object is network device 20, the pre-shared UDP port number (as well as the authentication key and device-specific information) is the UDP port number (as well as the authentication key and device-specific information) of network device 20 located within the private network 10; furthermore, when the remotely operated object is router 30, the pre-shared UDP port number (as well as the authentication key and device-specific information) is the UDP port number (as well as the authentication key and device-specific information) of the WAN side of router 30. In addition, Figure 1 In this configuration, router 30 connects to one network device 20, but multiple network devices 20 can also be connected to router 30. Furthermore, in... Figure 1 In this case, there is one private network 10 and one router 30 connected to the Internet 40, but it is also possible to have multiple private networks 10 and multiple routers 30 connected to the Internet 40. Figure 2 This is a schematic block diagram representing the structure of router 30. Figure 2 In this router 30, there are WAN-side communication units 31, LAN-side communication units 32, control units 33, storage units 34, display units 35, and operation units 36. The WAN-side communication unit 31 is connected to the Internet 40, and the LAN-side communication unit 32 is connected to the dedicated network 10. The display unit 35 is composed of, for example, a small liquid crystal display or LEDs, and the operation unit 36 ​​is composed of, for example, a toggle switch or a push-button switch. Figure 3 This is a schematic block diagram representing the structure of the remote management server 50. Figure 3 In this remote management server 50, there are a communication unit 51, a control unit 53, a storage unit 54, a display unit 55, and an operation unit 56. The communication unit 51 is connected to the Internet 40. The remote management server 50 can be a personal computer. In addition, communication devices such as routers may also be connected between the communication unit 51 and the Internet 40.

[0039] Figure 4 This is a schematic block diagram representing the structure of network device 20. Figure 4 The network device 20 mentioned is a wireless LAN access point, but network device 20 can also be a NAS (Network Access Server), a network camera, a network game console, etc. In addition, network device 20 with router 30 functions (such as a wireless LAN router), as well as a single router 30, are also included in network device 20. Figure 4 The network device 20 (wireless LAN access point) includes a wireless communication unit 41, a LAN-side communication unit 42, a control unit 43, a storage unit 44, a display unit 45, and an operation unit 46. The display unit 45 may be composed of, for example, a small LCD display or LEDs; the operation unit 46 may be composed of, for example, a toggle switch or a push-button switch. Alternatively, the wireless LAN access point may be integrated with the router 30 to form a wireless LAN router. Figure 5 This is a schematic block diagram representing the structure of the operating terminal. Figure 5 In this system, the operating terminal 60 includes a communication unit 61, a control unit 63, a storage unit 64, a display unit 65, and an operation unit 66. The communication unit 61 is connected to the Internet 40. The operating terminal 60 can be a personal computer. Furthermore, a communication device such as a router may also be connected between the communication unit 61 and the Internet 40.

[0040] [Action Flow] The following is a flowchart illustrating the remote management action process in the remote management system 100. Figure 6 It is a flowchart illustrating the process of secure information sharing. Figure 7 It is a flowchart illustrating remote operation requests and remote management processes. Figure 8 This is a flowchart illustrating the remote management process accompanying the restart of network device 20. In the remote management system 100 of the present invention, the network device 20 and the remote management server 50 pre-share the security information (UDP port number, authentication key, and device-specific information) of the network device 20. When the support department of the network device 20 sends a remote operation request for the network device 20 corresponding to the specific device-specific information to the remote management server 50 from the operation terminal 60, the remote management server 50 sends the authentication key to the UDP port of the network device 20. If the authentication key is consistent with the pre-shared authentication key, the network device 20 establishes a communication session for remote operation between the network device 20 and the remote management server 50. The support department then remotely manages the network device 20 from the operation terminal 60 through the communication session. Remote management, for example, refers to obtaining the logs of network device 20, and performing operations such as restarting network device 20 and confirming settings as needed.

[0041] First, based on Figure 6 The flowchart illustrates the process of secure information sharing step by step. (S1) Network device 20 generates UDP port number and authentication key. The UDP port number is the number of the UDP port used by the remote management server 50 to send the authentication key to the network device 20. It is randomly selected from 32768 to 60999. The authentication key is preferably composed of binary data of 256 bits or more. (S2) Network device 20 sends its UDP port number, authentication key, and device-specific information to the remote management server 50 via a secure path in advance. Alternatively, if network device 20 does not include the functionality of router 30, but is connected to the private network 10 side of router 30, then the UDP port number, authentication key, and device-specific information of network device 20 are sent to the remote management server 50 after NAPT conversion by router 30. In this case, router 30 preferably opens the WAN-side port for connecting network device 20 in advance. As inherent information, such as the model number, serial number, and MAC address of network device 20 (in the case of a fixed MAC address), can be used. As a secure path, MQTT communication with enhanced security via TLS (Transport Layer Security) is preferred. Steps S1 to S2 correspond to the security information sending steps. (S3) The remote management server 50 stores the received UDP port number, authentication key and the device-specific information of the network device 20 in the storage unit 54. Step S3 is equivalent to the security information storage step.

[0042] The preferred time for sharing security information (pre-sharing of UDP port numbers, authentication keys, etc.) is when network device 20 is installed in private network 10 and has access to the Internet (WAN). Alternatively, security information can be shared when the WAN or private IP address changes, or periodically, such as daily, weekly, or monthly.

[0043] Next, based on Figure 7 The flowchart illustrates the process of remote operation requests and remote management. (S4) The operation terminal 60 sends a remote operation request for a specific network device 20 to the remote management server 50. (S5) The remote management server 50 retrieves the UDP port number and authentication key corresponding to the device-specific information of the network device 20 that received the remote operation request from the storage unit 54, and sends the authentication key to the corresponding UDP port of the router 30. In this case, if the network device 20 is also a network device 20 connected to the private network 10 side of the router 30, it will be sent to the network device 20 after being converted by the router 30 using NAPT. Steps S4 to S5 correspond to the remote operation request steps. (S6) Network device 20 confirms whether the authentication key sent to the UDP port corresponding to the pre-sent number is consistent with the pre-sent authentication key. (S7, S8) If the authentication keys match, network device 20 establishes a communication session for remote operation between network device 20 and remote management server 50; otherwise, the process ends. Steps S6 to S8 are equivalent to the communication session construction steps. (S9) The operation terminal 60 sends instructions to the remote management server 50 to perform necessary remote operations through a communication session. Step S9 is equivalent to the remote management execution step. (S10, S11) When the necessary remote operation is completed, the network device 20 discards the communication session. In addition, the termination of the communication session conforms to normal TCP operations. For example, even if network device 20 stops responding for some reason, the communication session will terminate after a specified time. Therefore, the termination of necessary remote operations, or the elapsed time since network device 20 stopped responding, is equivalent to the prescribed termination condition.

[0044] When restarting network device 20 is performed as a remote management operation, the communication session will be discarded. Therefore, remote management requires a special procedure when restarting network device 20. Figure 8 This demonstrates the remote management process accompanying the restart of network device 20: (S21) When the network device 20 is restarted, the network device 20 first saves the data of the communication session. (S22) Restart network device 20. (S23) After a normal restart, network device 20 checks whether there is saved data for communication sessions; if there is no saved data, the process ends. (S24) If there is saved data, the communication session is reconstructed using that data. The subsequent S9~S11 and Figure 7 Same as shown.

[0045] (Security of remote management system 100) For the security of the remote management system 100, it is important that the UDP port number of the network device 20 is not detected externally and that the authentication key is not cracked. Firstly, regarding port number detection, there is a port scanning method. This method detects whether a service is listening or waiting on a target port by sending UDP packets, etc. To address this, network device 20, upon receiving a data packet destined for the corresponding port, will not respond or send anything, thus making it indistinguishable from other non-listening ports. Furthermore, regarding the confidentiality of the authentication key, by constructing the authentication key as binary data of more than 256 bits and sending the authentication key in a random manner, the risk of security being compromised due to the leakage of the authentication key is reduced.

[0046] (A variation to improve safety) Figure 9 It is a flowchart illustrating the remote operation request and remote management process of the variant example. exist Figure 7 In this process, after network device 20 completes authentication using the authentication key sent to the corresponding UDP port, it immediately establishes a communication session. And... Figure 9 In the modified process shown, after network device 20 completes authentication by sending the authentication key to the corresponding UDP port, it generates a new UDP port number and authentication key, and sends them to remote management server 50; then, after completing authentication again by sending the authentication key returned by remote management server 50, a communication session is established. In this scenario, not only does the time required for port number scanning via UDP scanning and authentication key cracking double, but because the second port number and authentication key are generated just before authentication, attackers have almost no time to perform port scanning, key cracking, or information leakage. Therefore, from this perspective, security is further enhanced. Follow the steps below Figure 9 The flowchart is used for illustration. S1~S7 and Figure 7 The flowcharts are the same. (S31) If the authentication keys are consistent, the network device 20 randomly generates a second UDP port number and a second authentication key. (S32) The network device 20 sends the generated second UDP port number and second authentication key, along with the device-specific information of the network device 20, to the remote management server 50 via a secure path. (S33) The remote management server 50 sends the received second authentication key to the corresponding UDP port of the network device 20. (S34, S35) Network device 20 compares the sent second authentication key with the received second authentication key. If they do not match, the process ends. Steps S8 to S11 when the authentication keys match Figure 7 The same as in. By adopting the process of the above-described modified example, the safety level can be further improved.

[0047] (Handling dynamic DNS) In recent years, the global IP addresses of routers and other devices have been reassigned by providers primarily when the router is powered on again or when there has been no communication for a certain period of time. Therefore, in the communication between network device 20 and remote management server 50, the IP addresses of the source and / or destination are also dynamically changing. In this scenario, by specifying domain names instead of IP addresses for the source and / or destination, and utilizing Dynamic Domain Name System (DNS), the IP addresses of the source and / or destination can be reliably specified. In the remote management system 100 of this invention, domain names and Dynamic DNS are also used for communication between the network device 20 and the remote management server 50.

[0048] In this invention, the remote management system 100 is equivalent to "remote management system", the dedicated network 10 is equivalent to "dedicated network", the network device 20 is equivalent to "network device", the Internet 40 is equivalent to "Internet", the router 30 is equivalent to "router", the remote management server 50 is equivalent to "remote management server", and the operation terminal 60 is equivalent to "operation terminal".

[0049] A preferred embodiment of the present invention is as described above, but the present invention is not limited thereto. It is understood that various other embodiments are possible without departing from the spirit and scope of the present invention. Furthermore, this embodiment illustrates the functions and effects brought about by the structure of the present invention, but these functions and effects are merely examples and not intended to limit the present invention. Explanation of reference numerals in the attached figures

[0050] 1: Private network; 2: Network equipment; 3: Router; 4: Internet; 5: Remote management server; 6: Operating terminal; 100: Remote management system.

Claims

1. A remote management system, comprising network devices connected to a dedicated network, a router relaying between the dedicated network and the Internet, a remote management server connected to the Internet, and an operating terminal, wherein, The network device randomly generates its UDP port number and authentication key, and sends the UDP port number and authentication key, along with the network device's inherent information, to the remote management server via a secure path in advance. If the remote management server receives the UDP port number, the authentication key, and the device-specific information of the network device, it will save the received UDP port number, the authentication key, and the device-specific information of the network device. When the operating terminal requests operation of the network device from the remote management server, the remote management server sends the authentication key to the UDP port of the network device corresponding to the device's inherent information. When the authentication key received by the network device from the UDP port matches the pre-sent authentication key, the network device establishes a communication session between the network device and the remote management server that corresponds to the device's inherent information. The operating terminal remotely manages the network device through the remote management server and the communication session.

2. The remote management system according to claim 1, wherein, When the UDP packet is sent from the Internet side to the UDP port of the network device, the network device does not respond or send any data.

3. The remote management system according to claim 1, wherein, The network device is a wireless LAN access point or a network access server, i.e., a NAS.

4. The remote management system according to claim 1, wherein, The network device includes the functionality of the router.

5. The remote management system according to claim 1, wherein, The secure path and the communication session use the Transport Layer Security (TLS) protocol.

6. The remote management system according to claim 1, wherein, When the specified termination conditions are met, the remote management server or the network device discards the established communication session.

7. A router that relays data between a private network and the Internet, wherein, Randomly generate the UDP port number and authentication key on the Internet side. The generated UDP port number, the authentication key, and the device's own inherent information are sent to the remote management server via a secure path. On the UDP port of the specified UDP port number, when the authentication key sent from the remote management server is received, and the received authentication key matches the sent authentication key, a communication session is established with the remote management server. The communication session is used to receive remote operations from the operating terminal.

8. A remote management method, wherein the remote management method performs remote management in a remote management system comprising a network device connected to a private network, a router relaying between the private network and the Internet, a remote management server connected to the Internet, and an operating terminal, wherein, The remote management method includes the following steps: In the security information sending step, the network device randomly generates a UDP port number and an authentication key, and sends the UDP port number and the authentication key, together with the network device's inherent information, to the remote management server via a secure path in advance. In the security information storage step, if the remote management server receives the UDP port number, the authentication key, and the device-specific information of the network device, it will save the received UDP port number, the authentication key, and the device-specific information of the network device. In the remote operation request step, the operating terminal requests the remote management server to operate the network device, and the remote management server sends the authentication key to the UDP port of the network device corresponding to the inherent information of the network device. The communication session establishment step involves the network device establishing a communication session between itself and the remote management server, corresponding to the device's inherent information, when the authentication key received from the UDP port matches the pre-sent authentication key. The remote management execution step involves the operating terminal remotely managing the network device through the remote management server and the communication session.

Citation Information

Patent Citations

  • Port open / close control system

    JP2013201621A

  • Authentication method using firewall

    JP2013206260A

  • Data collection side device, data use side device, and communication method

    JP2020160984A

  • Relay method, relay system, and relay program

    JP2023052288A

  • Information processing system, information processing apparatus, management server, and program

    JP2023061252A