Communication method
The HTTP Proxy Service (HPS) method for IoT devices addresses the construction load and security risks by enabling secure, efficient setup through short-range wireless communication with data partitioning and authentication.
Patent Information
- Application Number
- JP2023190960
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-08
- Publication Date
- 2025-05-20
AI Technical Summary
The initial setup of IoT devices, such as water heating apparatuses, requires on-site input of confidential settings via LAN, leading to a heavy construction load and security risks due to exposure of network information.
A communication method using HTTP Proxy Service (HPS) for short-range wireless communication between a control device and a terminal device, involving data partitioning and authentication to enhance security and accommodate larger data sizes.
Reduces construction load and enhances security by enabling secure, efficient setup of IoT devices through short-range wireless communication without modifying existing API specifications.
Smart Images

Figure 2025078411000001_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a communication technology, and more particularly to a communication method using an HTTP Proxy Service (HPS). [Background technology]
[0002] The water heating apparatus is linked to an information terminal by connecting to the Internet and using IoT (Internet of Things). The information terminal remotely controls the water heating apparatus from outside the home and views information such as usage history. When the occupants of a rental house change frequently, the user of the water heating apparatus installed in the house changes each time. If a person moves out without disconnecting the information terminal from the water heating apparatus, the person may continue to view information on the water heating apparatus and remotely control it. In order to prevent such a deterioration in security, when an IoT device such as a water heating apparatus receives an instruction to establish a new connection from an information terminal different from an information terminal that has already established a connection (hereinafter referred to as an "old connection"), the IoT device requests the user to initialize the old connection (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2021-145246 A Summary of the Invention [Problem to be solved by the invention]
[0004] The initial settings of IoT devices are generally performed by inputting confidential initial setting data, including settings unique to the property's resident, at the installation site. In such cases, the initial setting data is often input to the IoT device via a Local Area Network (LAN). However, when initial setting IoT devices using a LAN, the work must be done while the resident is present, which creates an issue of a heavy construction load.
[0005] The present disclosure has been made in consideration of these circumstances, and has a purpose to provide a technique for reducing the load of equipment construction work. [Means for solving the problem]
[0006] In order to solve the above problems, a communication method according to an embodiment of the present disclosure includes a step of executing pairing for short-range wireless communication between a control device and a terminal device connectable to one or more devices, and a step of the paired control device and terminal device transmitting and receiving data by an HTTP Proxy Service (HPS). The size of the data is larger than the size that can be stored in a packet for short-range wireless communication, and the data includes authentication data for the control device and the terminal device.
[0007] Another aspect of the present disclosure is also a communication method. This method includes the steps of transmitting and receiving authentication data between an HPS (HTTP Proxy Service) client and an HPS server via short-range wireless communication, transmitting and receiving HTTPS communication data used to execute HTTPS communication between the HPS client and the HPS server via short-range wireless communication, the HPS server sending an HTTPS request to the HTTPS server using the authentication data and the HTTPS communication data, the HTTPS server sending an HTTPS response to the HTTPS request to the HPS server, and the HPS server sending the HTTPS response to the HPS client via short-range wireless communication. The size of the authentication data and the size of the HTTPS communication data are larger than the size that can be stored in a packet for short-range wireless communication, and the authentication data and the HTTPS communication data are divided into multiple pieces.
[0008] Any combination of the above components, or conversion of the present disclosure into a method, device, system, computer program, or recording medium having a computer program recorded thereon, is also valid as an aspect of the present disclosure. Effect of the Invention
[0009] According to the present disclosure, the load of equipment construction can be reduced. [Brief description of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram showing a configuration of a control system according to an embodiment. [Diagram 2] FIG. 2 is a diagram illustrating the configuration of a control device and a terminal device in FIG. [Diagram 3] FIG. 3 is a sequence diagram showing the communication procedures performed by the HPS client processing unit, HPS server processing unit, and HTTPS server processing unit in FIG. 2. [Figure 4] 4(a)-(c) are diagrams showing data formats used in the communication procedure of FIG. [Diagram 5] 5(a)-(b) are diagrams showing the data structures of Service and Characteristic in the HPS server processing unit of FIG. [Figure 6] 6(a)-(b) are sequence diagrams showing the communication procedures performed by the HPS client processor, HPS server processor, and HTTPS server processor according to a modified example. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Before specifically describing an embodiment of the present disclosure, an overview of the embodiment will be described. The embodiment relates to a control system that controls the operation of devices such as lighting devices and air conditioners in facilities such as detached houses, condominiums, and apartments, and manages the power consumed in the facilities. The control system is, for example, a Home Energy Management System (HEMS). In the HEMS, devices such as lighting devices and air conditioners are connected to a control device via a network, and the control device controls the devices through communication between the control device and the devices.
[0012] There is a demand for the control device in such a control system to have the construction completed before the resident moves into the facility. When construction is performed using the network function of the control device, the construction company connects the construction company's terminal device to the control device via wireless LAN. At that time, the SSID (Service Set Identifier) and password assigned to the control device are set in the terminal device. Therefore, the SSID and password of the control device are known by the construction company as well as the resident, which poses a security risk.
[0013] To avoid such security risks, the connection between the control device and the terminal device is replaced from wireless LAN to short-range wireless communication such as Bluetooth Low Energy (registered trademark). Even if information at the time of establishing short-range wireless communication remains in the terminal device, the information also remains in the control device, and security risks are avoided by deleting the information in the control device. Even if short-range wireless communication is used instead of wireless LAN, it is required that the specifications are those established for construction and that the specifications of the API (Application Programming Interface) by HTTPS communication be reused without modification.
[0014] When using short-range wireless communication to connect a control device and a terminal device, the following issues arise. The security of short-range wireless communication is generally limited to pairing and data encryption. Therefore, there is no function for terminal authentication or user authentication, and security is insufficient. In addition, the security specifications defined in HPS include a "Security Characteristic" that obtains the authentication result of the server of a specified URI (Uniform Resource Identifier) from the HPS server. Since this only obtains the authentication result, if the communication partner is an unauthorized HPS server, there is a risk of obtaining a tampered authentication result or an unauthorized result sent without authentication. In addition, the data size of HTTPS communication exceeds the data size that can be handled by short-range wireless communication.
[0015] In this embodiment, in order to solve the above problems, the HPS is improved as follows. The first improvement is to define authentication data for executing terminal authentication, user authentication, and server authentication, and to transmit and receive the authentication data between the terminal device and the control device before the HPS. The second improvement is to divide data and transmit and receive it so that the data size can be handled by short-range wireless communication.
[0016] The control system according to this embodiment will be described below in the order of (1) basic processing and (2) construction processing. (1) Basic processing FIG. 1 shows the configuration of a control system 1000. The control system 1000 includes a first device 100a, a second device 100b, a network 200, and a control device 300, which are collectively referred to as devices 100. The number of devices 100 included in the control system 1000 is not limited to "1". In addition, a terminal device 400 can be connected to the control device 300. The control device 300 and the terminal device 400 may be referred to as a communication system. The terminal device 400 is not used in (1) basic processing, but is used in (2) construction processing, and therefore will not be described here.
[0017] The control system 1000 is installed in a facility. The facility is a building to be controlled by the control system 1000, for example, a detached house. The facility is not limited to a detached house, and may be an apartment building, an office building, a commercial facility, etc. The device 100 is, for example, a lighting device or an air conditioner. The first device 100a and the second device 100b are connected to the control device 300 via a network 200. The network 200 is compatible with a standard protocol such as ECHONET Lite (registered trademark).
[0018] The control device 300 has a function as, for example, an HEMS controller, and controls the operation of the first device 100a and the second device 100b. The control device 300 may be a single device, or may be a connection of multiple devices. FIG. 2 shows the configuration of the control device 300 and the terminal device 400. The control device 300 includes a first communication unit 310, a second communication unit 312, a control unit 314, a storage unit 316, a reception unit 320, and a display unit 322, and the control unit 314 includes an HPS server processing unit 330 and an HTTPS server processing unit 332. Here, a description of the terminal device 400 is omitted.
[0019] The first communication unit 310 has a communication function of ECHONET Lite (registered trademark), and can communicate with each of the first device 100a and the second device 100b via the network 200. The control unit 314 is configured, for example, by a microcomputer having a processor and a memory. The processor executes a program recorded in the storage unit 316, and various functions of the control unit 314 are realized by the computer system.
[0020] One of the various functions is a function to control the operation of the first device 100a or the second device 100b, and the control device 300 displays an operation screen for receiving an operation for the first device 100a or the second device 100b on the display unit 322. The reception unit 320 is a user interface capable of receiving an operation from a user, for example, a button. The reception unit 320 may also be a touch panel integrated with the display unit 322. The reception unit 320 receives an instruction from the user on the operation screen displayed on the display unit 322. The reception unit 320 outputs the received instruction to the control unit 314. The control unit 314 generates a control command for instructing the operation of the first device 100a or the second device 100b based on the instruction received by the reception unit 320. The first communication unit 310 transmits the control command to the first device 100a or the second device 100b.
[0021] The first device 100a or the second device 100b receives a control command from the control device 300 via the network 200. The first device 100a or the second device 100b executes an operation according to the control command. For example, the first device 100a or the second device 100b turns on or off an operation.
[0022] The first communication unit 310 of the control device 300 may be connected to a smart meter (not shown) and receive power information indicating power consumed in the facility. The control unit 314 generates a control command based on the power information received by the first communication unit 310. For example, when the power becomes greater than a threshold value, the control unit 314 generates a control command to increase the set temperature for cooling in the air conditioner. The first communication unit 310 transmits the control command to the first device 100a or the second device 100b. When the first device 100a or the second device 100b receives the control command from the control device 300, it executes an operation according to the control command, for example, an operation to increase the set temperature for cooling.
[0023] (2) Construction processing The above-mentioned control system 1000 is installed in a facility by construction work before being used as in (1) basic processing. The construction processing includes construction work and processing for setting the control device 300 after the control system 1000 is installed. In this embodiment, the terminal device 400 in Figs. 1 and 2 is used for the construction processing. The terminal device 400 is a communication device used by a construction company, such as a smartphone or a tablet terminal. The construction company executes the construction processing for the control device 300 by accessing the control device 300 using the terminal device 400.
[0024] In order to avoid security risks in the construction process, the control device 300 and the terminal device 400 execute short-distance wireless communication. As described above, the problem with this is that security is insufficient just by pairing and encrypting data, and the data size of HTTPS communication exceeds the data size that can be handled by short-distance wireless communication. The following mainly describes the process for solving these problems.
[0025] The second communication unit 312 of the control device 300 in FIG. 2 has a communication function of short-range wireless communication. The terminal device 400 in FIG. 2 includes a communication unit 410, a control unit 414, a storage unit 416, a reception unit 420, and a display unit 422. The control unit 414 includes an HPS client processing unit 430. The communication unit 410 has a communication function of short-range wireless communication and can communicate with the second communication unit 312 of the control device 300. The terminal device 400 may have a communication function of a mobile phone communication system and a communication function of a wireless LAN in addition to the communication function of short-range wireless communication, but these will not be described here. The control unit 414 is, for example, a microcomputer having a processor and a memory. The processor executes a program recorded in the storage unit 416. An example of a program recorded in the storage unit 416 is a program for construction processing of the control system 1000.
[0026] An operation screen for the program for the construction processing is displayed on the display unit 422. The reception unit 420 is a user interface capable of receiving operations from the user, and is, for example, a button. The reception unit 420 may also be a touch panel integrated with the display unit 422. The reception unit 420 receives instructions from the user on the operation screen displayed on the display unit 422. The reception unit 420 outputs the received instructions to the control unit 414. The control unit 414 generates a signal based on the instructions received by the reception unit 420. The communication unit 410 transmits and receives signals to and from the second communication unit 312 of the control device 300.
[0027] In order to execute the construction processing, an API specification is defined for the HTTPS server processing unit 332 of the control device 300. The construction processing in this embodiment also uses the API specification defined for the HTTPS server processing unit 332 as is via HTTPS communication. The construction processing performed by the terminal device 400 and control device 300 will be explained below with reference to Figure 3. Figure 3 is a sequence diagram showing the communication procedure performed by the HPS client processing unit 430, HPS server processing unit 330, and HTTPS server processing unit 332.
[0028] The communication unit 410 of the terminal device 400 and the second communication unit 312 of the control device 300 execute pairing for short-range wireless communication, thereby pairing the HPS client processing unit 430 and the HPS server processing unit 330 (S10). Since any known technology can be used for pairing in short-range wireless communication, a description thereof will be omitted here. In order to improve the security of short-range wireless communication, the second communication unit 312 of the control device 300 or the HPS server processing unit 330 will refuse to send or receive data to or from the terminal device 400 if encryption has not been performed through pairing.
[0029] After pairing is established, the HPS server processing unit 330 transmits a server certificate by short-range wireless communication (S12, S14). The server certificate corresponds to authentication data for the control device 300. The size of the server certificate is larger than the size that can be stored in a packet for short-range wireless communication. Therefore, as shown in FIG. 3, the server certificate is divided into multiple parts, for example, two parts, and transmitted. FIG. 4(a)-(c) show the format of data used in the communication procedure. Here, as an example, a case where the server certificate is divided into three or more parts is shown. FIG. 4(a) shows the format of the first data. A flag indicating the first data (hereinafter referred to as a "first flag") is added to the first data. FIG. 4(b) shows the format of intermediate data. A flag indicating the intermediate data (hereinafter referred to as a "intermediate flag") is added to the intermediate data. When there are multiple intermediate data, information on the order of the intermediate data may be added together with the intermediate flag. FIG. 4(c) shows the format of the final data. A flag indicating the final data (hereinafter referred to as a "final flag") is added to the final data. When the server certificate is split into two as in Figure 3, the data in Figure 4(a) and the data in Figure 4(c) are sent, and the data in Figure 4(b) is not generated. Return to Figure 3. In order to improve communication speed, the HPS server processing unit 330 successively sends the multiple split server certificates without waiting for a response from the HPS client processing unit 430.
[0030] The HPS client processing unit 430 receives each of the multiple split server certificates from the HPS server processing unit 330. The HPS client processing unit 430 acquires the server certificate by combining the multiple split server certificates based on the flags.
[0031] The HPS client processing unit 430 transmits the client certificate by short-range wireless communication (S16, S18). The client certificate corresponds to the authentication data of the terminal device 400. The size of the client certificate is larger than the size that can be stored in a packet in short-range wireless communication. Therefore, the client certificate is divided into a plurality, for example, two, and transmitted. The formats of the client certificates divided into a plurality are also shown as in FIGS. 4(a)-(c). In order to improve the communication speed, the HPS client processing unit 430 continuously transmits the client certificates divided into a plurality without waiting for a response from the HPS server processing unit 330.
[0032] The HPS server processing unit 330 receives each of the client certificates divided into a plurality from the HPS client processing unit 430. The HPS server processing unit 330 obtains the client certificate by combining the client certificates divided into a plurality based on a flag. The HPS client processing unit 430 transmits the user authentication data to the HPS server processing unit 330 by short-range wireless communication (S20). The HPS server processing unit 330 receives the user authentication data from the HPS client processing unit 430. The server certificate, the client certificate, and the user authentication data are collectively referred to as authentication data.
[0033] After the transmission and reception of the authentication data are completed, the HPS client processing unit 430 and the HPS server processing unit 330 transmit and receive the HTTPS communication data used for executing HTTPS communication by short-range wireless communication. The HTTPS communication data includes a URI (Uniform Resource Identifier), a Header, a Body, and a Method. Further, the HTTPS communication data may include an ack (acknowledgement) for each of the URI, the Header, the Body, and the Method.
[0034] The HPS client processing unit 430 transmits the URI to the HPS server processing unit 330 via short-range wireless communication (S22). When the HPS server processing unit 330 receives the URI from the HPS client processing unit 430, it transmits an ack for the URI to the HPS client processing unit 430 via short-range wireless communication (S24).
[0035] The HPS client processing unit 430 transmits the Header to the HPS server processing unit 330 via short-range wireless communication (S26). When the HPS server processing unit 330 receives the Header from the HPS client processing unit 430, it transmits an ack for the Header to the HPS client processing unit 430 via short-range wireless communication (S28).
[0036] The HPS client processing unit 430 transmits the multiple divided bodies to the HPS server processing unit 330 via short-range wireless communication (S30, S32, S34). The size of the body is larger than the size that can be stored in a packet for short-range wireless communication. Therefore, the body is divided into multiple bodies, for example, three, and transmitted. The format of the multiple divided bodies is also shown in Figures 4(a)-(c). The HPS server processing unit 330 receives the multiple divided bodies from the HPS client processing unit 430. The HPS server processing unit 330 acquires the body by combining the multiple divided bodies based on the flag. When the HPS server processing unit 330 acquires the body, it transmits an ack for the body to the HPS client processing unit 430 via short-range wireless communication (S36). The HPS server processing unit 330 may transmit an ack for each of the multiple divided bodies to the HPS client processing unit 430 via short-range wireless communication.
[0037] The HPS client processing unit 430 transmits the Method to the HPS server processing unit 330 via short-range wireless communication (S38). When the HPS server processing unit 330 receives the Method from the HPS client processing unit 430, it transmits an ack for the Method to the HPS client processing unit 430 via short-range wireless communication (S40).
[0038] As a result of this processing, the HPS server processing unit 330 obtains the HPS default Service and Characteristic. Figures 5(a)-(b) show the data structures of Services and Characteristics in the HPS server processing unit 330. Figure 5(a) shows the data structure of a conventional Service and Characteristic that is compared to this embodiment. Here, the UUID and attributes are shown only in the URI, but the Header etc. also contains UUIDs and attributes.
[0039] FIG. 5(b) shows the data structures of Service and Characteristic in this embodiment. Due to the transmission and reception of the authentication data described above, the Characteristic includes the client certificate, server certificate, and user authentication data. Furthermore, since the information on Service and Characteristic can be referenced from outside, these names are concealed between the HPS server processing unit 330 and the HPS client processing unit 430 to make it difficult for unauthorized third parties to analyze the data structure. Since the relationship between the concealed name and the original name is held in advance in the HPS server processing unit 330, the HPS server processing unit 330 obtains the original name from the concealed name by referencing this relationship. Return to FIG. 3.
[0040] The HPS server processing unit 330 generates an HTTPS request using the authentication data and the HTTPS communication data shown in Fig. 5(b). At that time, the HTTPS request may be encrypted using an encryption key included in the authentication data. The HPS server processing unit 330 outputs the HTTPS request to the HTTPS server processing unit 332 (S42).
[0041] The HTTPS server processing unit 332 receives an HTTPS request from the HPS server processing unit 330. The HTTPS server processing unit 332 executes processing corresponding to the HTTPS request and generates an HTTPS response for the HTTPS request. The HTTPS server processing unit 332 outputs the HTTPS response to the HPS server processing unit 330 (S44). Known techniques are used for the HTTPS communication that uses the HTTPS request and the HTTPS response.
[0042] The HPS server processing unit 330 transmits the HTTPS response divided into a plurality of parts to the HPS client processing unit 430 by short-range wireless communication (S46, S48). The size of the HTTPS response is larger than the size that can be stored in a packet in short-range wireless communication. Therefore, the HTTPS response is divided into a plurality of parts, for example, two parts and transmitted. The format of the HTTPS response divided into a plurality of parts is also shown as in FIGS. 4(a)-(c). The HPS client processing unit 430 receives the HTTPS response divided into a plurality of parts from the HPS server processing unit 330.
[0043] The control unit 314 of the control device 300 defines a session expiration period (a certain period) for the short-range wireless communication between the control device 300 and the terminal device 400. When the second communication unit 312 does not receive data from the terminal device 400 for a certain period, the control unit 314 ends the session with the terminal device 400 for security protection. When the control unit 314 ends the session, it deletes the pairing information, client certificate, and user authentication data with the terminal device 400.
[0044] Within the session expiration period, the control unit 314 resumes data transmission and reception without performing transmission and reception of pairing and authentication data to the terminal device 400 whose short-range wireless communication has been disconnected. This is because within the session expiration period, the pairing information, client certificate, and user authentication data with the terminal device 400 are not deleted.
[0045] The subject of the device, system, or method in the present disclosure includes a computer. The computer executes a program to realize the function of the subject of the device, system, or method in the present disclosure. The computer includes a processor that operates according to a program as a main hardware configuration. The type of the processor does not matter as long as it can realize the function by executing the program. The processor is composed of one or more electronic circuits including a semiconductor integrated circuit (IC) or an LSI (Large Scale Integration). The multiple electronic circuits may be integrated into one chip or may be provided on multiple chips. The multiple chips may be integrated into one device or may be provided on multiple devices. The program is recorded on a non-transitory recording medium such as a computer-readable ROM, an optical disk, or a hard disk drive. The program may be stored in the recording medium in advance, or may be supplied to the recording medium via a wide area communication network including the Internet.
[0046] (Modification) Up until now, HTTPS communication data has been sent and received in the following order: URI, Header, Body, Method. However, the order in which this data is sent and received is arbitrary. Below, two other patterns are explained using Figures 6(a) and 6(b).
[0047] Figures 6(a)-(b) are sequence diagrams showing the communication procedures performed by the HPS client processing unit 430, the HPS server processing unit 330, and the HTTPS server processing unit 332. Figures 6(a)-(b) show the URI, Header, Body, Method, and transmission of the HTTPS request from Figure 3, and omit other parts.
[0048] In Fig. 6(a), the HPS client processing unit 430 sends a Header to the HPS server processing unit 330 via short-range wireless communication (S100), a URI to the HPS server processing unit 330 via short-range wireless communication (S102), and a Body to the HPS server processing unit 330 via short-range wireless communication (S104). Here, the Header, URI, and Body are sent in any order. After these transmissions are completed, the HPS client processing unit 430 sends a Method to the HPS server processing unit 330 via short-range wireless communication (S106). After receiving the URI, Header, and Body from the HPS client processing unit 430 in any order, if the HPS server processing unit 330 receives a Method from the HPS client processing unit 430, it outputs an HTTPS request to the HTTPS server processing unit 332 (S108). In other words, the sending and receiving of the Method is used as a trigger to start HTTPS communication.
[0049] In Figure 6(b), the HPS client processing unit 430 sends the Body to the HPS server processing unit 330 via short-range wireless communication (S150), and the Header to the HPS server processing unit 330 via short-range wireless communication (S152). Following this, the HPS client processing unit 430 sends the Method to the HPS server processing unit 330 via short-range wireless communication (S154), and the URI to the HPS server processing unit 330 via short-range wireless communication (S156). Here, the Body, Header, Method, and URI are sent in no particular order. When the HPS server processing unit 330 receives the Body, Header, Method, and URI from the HPS client processing unit 430 in no particular order, it outputs an HTTPS request to the HTTPS server processing unit 332 (S158). In other words, HTTPS communication is initiated when the HPS server processing unit 330 has received all of the Body, Header, Method, and URI.
[0050] The subject of the device, system, or method in the present disclosure includes a computer. The computer executes a program to realize the function of the subject of the device, system, or method in the present disclosure. The computer includes a processor that operates according to a program as a main hardware configuration. The type of the processor does not matter as long as it can realize the function by executing the program. The processor is composed of one or more electronic circuits including a semiconductor integrated circuit (IC) or an LSI (Large Scale Integration). The multiple electronic circuits may be integrated into one chip or may be provided on multiple chips. The multiple chips may be integrated into one device or may be provided on multiple devices. The program is recorded on a non-transitory recording medium such as a computer-readable ROM, an optical disk, or a hard disk drive. The program may be stored in the recording medium in advance, or may be supplied to the recording medium via a wide area communication network including the Internet.
[0051] According to this embodiment, when the control device 300 and the terminal device 400 transmit and receive data by the HPS, the size of the data is made larger than the size that can be stored in a packet in the short-range wireless communication, and the data includes authentication data, so that short-range wireless communication can be used for the construction of the control system. In addition, since short-range wireless communication is used for the construction of the control system, the load of the construction of the equipment can be reduced. In addition, since the authentication data is transmitted and received before the data for HTTPS communication, the deterioration of security can be suppressed. In addition, since the HTTPS communication is started when the Method is received after the URI, Header, and Body are received in no particular order, the flexibility of the configuration can be improved. In addition, since the URI, Header, Body, and Method are received in no particular order, and the HTTPS communication is started when all of the URI, Header, Body, and Method are received, the flexibility of the configuration can be improved.
[0052] In addition, since data is divided into multiple pieces and transmitted and received, data can be transmitted and received even if the data size is larger than the size that can be stored in a packet for short-distance wireless communication. Furthermore, when data is not received from the terminal device 400 for a certain period of time, the session is terminated and pairing information and authentication data are deleted, so security can be protected. Furthermore, within the session expiration period, data transmission and reception is resumed for the terminal device 400 for which short-distance wireless communication has been disconnected, even if pairing and transmission and reception of authentication data have not been performed, so data transmission and reception can be performed early. Furthermore, when encryption by pairing has not been performed, data transmission and reception is rejected, so security can be protected. Furthermore, since authentication data is transmitted and received by short-distance wireless communication, HTTPS communication data is transmitted and received by short-distance wireless communication, and the authentication data and HTTPS communication data are divided into multiple pieces, short-distance wireless communication can be performed with high security without changing the existing API specifications.
[0053] An outline of one aspect of the present disclosure is as follows. (Item 1) Executing pairing for short-range wireless communication between a control device connectable to one or more devices and a terminal device; The paired control device and the terminal device transmit and receive data via an HTTP Proxy Service (HPS); The size of the data is larger than the size that can be stored in a packet for short-range wireless communication, A communication method, wherein the data includes authentication data for the control device and the terminal device.
[0054] (Item 2) The data further includes HTTPS communication data used to execute the HTTPS communication, 2. The communication method according to item 1, wherein the authentication data is transmitted and received before the HTTPS communication data.
[0055] (Item 3) The HTTPS communication data includes a URI, a header, a body, and a method. 3. The communication method according to item 2, wherein the control device starts HTTPS communication when it receives the URI, the Header, and the Body from the terminal device in any order, and then receives the Method from the terminal device.
[0056] (Item 4) The HTTPS communication data includes a URI, a header, a body, and a method. The communication method according to item 2, wherein the control device receives the URI, the Header, the Body, and the Method from the terminal device in any order, and starts HTTPS communication when the control device has received all of the URI, the Header, the Body, and the Method.
[0057] (Item 5) 5. The communication method according to any one of items 1 to 4, wherein the data is divided into a plurality of pieces and transmitted / received.
[0058] (Item 6) the control device terminates a session with the terminal device when the control device does not receive the data from the terminal device for a certain period of time; 6. The communication method according to any one of claims 1 to 5, further comprising a step in which the control device deletes information on pairing with the terminal device and the authentication data when the control device terminates the session with the terminal device.
[0059] (Item 7) The control device specifies a session expiration time between the control device and the terminal device, and resumes transmission and reception of data with the terminal device with which short-range wireless communication has been disconnected within the session expiration time even if pairing and transmission and reception of the authentication data have not been performed.
[0060] (Item 8) 8. The communication method according to any one of items 1 to 7, wherein the control device rejects transmission and reception of the data if encryption by pairing has not been performed.
[0061] (Item 9) transmitting and receiving authentication data between an HPS (HTTP Proxy Service) client and an HPS server via short-range wireless communication; transmitting and receiving HTTPS communication data used for executing HTTPS communication between the HPS client and the HPS server via short-range wireless communication; the HPS server sending an HTTPS request to an HTTPS server using the authentication data and the HTTPS communication data; the HTTPS server sending an HTTPS response to the HTTPS request to the HPS server; the HPS server transmitting the HTTPS response to the HPS client via short-range wireless communication; the size of the authentication data and the size of the HTTPS communication data are larger than the size that can be stored in a packet for short-range wireless communication, The authentication data and the HTTPS communication data are divided into a plurality of parts.
[0062] The present disclosure has been described above based on the embodiments. These embodiments are merely illustrative, and it will be understood by those skilled in the art that various modifications are possible in the combination of each component or each treatment process, and that such modifications are also within the scope of the present disclosure. [Explanation of symbols]
[0063] 100 device, 200 network, 300 control device, 310 first communication unit, 312 second communication unit, 314 control unit, 316 memory unit, 320 reception unit, 322 display unit, 330 HPS server processing unit, 332 HTTPS server processing unit, 400 terminal device, 410 communication unit, 414 control unit, 416 memory unit, 420 reception unit, 422 display unit, 430 HPS client processing unit, 1000 control system.
Claims
1. Executing pairing for short-range wireless communication between a control device connectable to one or more devices and a terminal device; The paired control device and the terminal device transmit and receive data by using an HTTP Proxy Service (HPS), The size of the data is larger than the size that can be stored in a packet for short-range wireless communication, A communication method, wherein the data includes authentication data for the control device and the terminal device.
2. The data further includes HTTPS communication data used to perform the HTTPS communication; The communication method according to claim 1 , wherein the authentication data is transmitted and received before the HTTPS communication data.
3. The HTTPS communication data includes a URI, a Header, a Body, and a Method, The communication method according to claim 2 , wherein the control device starts HTTPS communication when the control device receives the URI, the Header, and the Body from the terminal device in random order and then receives the Method from the terminal device.
4. The HTTPS communication data includes a URI, a Header, a Body, and a Method, The communication method according to claim 2 , wherein the control device receives the URI, the Header, the Body, and the Method from the terminal device in any order, and starts HTTPS communication when the control device has received all of the URI, the Header, the Body, and the Method.
5. The communication method according to claim 1 , wherein the data is transmitted and received in a divided form.
6. the control device terminates a session with the terminal device when the control device does not receive the data from the terminal device for a certain period of time; The communication method according to claim 1 , further comprising the step of: when the control device ends the session with the terminal device, deleting information of pairing with the terminal device and the authentication data.
7. The communication method according to claim 1, wherein the control device specifies a session expiration time between the control device and the terminal device, and within the session expiration time, the control device resumes transmission and reception of the data with the terminal device with which short-range wireless communication has been disconnected, even if pairing and transmission and reception of the authentication data have not been performed.
8. The communication method according to claim 1 , wherein the control device rejects transmission / reception of the data if encryption by pairing has not been performed.
9. transmitting and receiving authentication data between an HTTP Proxy Service (HPS) client and an HPS server via short-range wireless communication; transmitting and receiving HTTPS communication data used for executing HTTPS communication between the HPS client and the HPS server by short-range wireless communication; the HTTPS server sending an HTTPS request to an HTTPS server using the authentication data and the HTTPS communication data; the HTTPS server sending an HTTPS response to the HTTPS request to the HTTPS server; the HTTPS server transmitting the HTTPS response to the HTTPS client via short-range wireless communication; a size of the authentication data and a size of the HTTPS communication data are larger than a size that can be stored in a packet for short-range wireless communication; The authentication data and the HTTPS communication data are divided into a plurality of parts.
Citation Information
Patent Citations
IoT DEVICE AND COMMUNICATION SYSTEM
JP2021145246A