Communication system, remote terminal device, and authentication method thereof

The communication system addresses the challenge of authenticating remote terminal devices and input/output modules by using a processing module that establishes trust through a trigger-activated provisioning mode, ensuring secure and reliable communication.

JP2025081185AActive Publication Date: 2025-05-27MOXA INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023204979
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-15
Filing Date
2023-12-04
Publication Date
2025-05-27
Estimated Expiration
2043-12-04

AI Technical Summary

Technical Problem

Existing communication systems struggle to effectively authenticate remote terminal devices and external input/output modules, making it difficult to ensure the reliability and security of these devices against malicious attacks or data theft.

Method used

A communication system that includes a remote terminal device with a processing module capable of operating in provisioning and operation modes. The processing module establishes trust with an input/output module upon activation of a trigger unit and prohibits untrusted modules from connecting when the trigger is deactivated.

Benefits of technology

This solution effectively establishes and maintains a trust relationship with input/output modules, ensuring that only trusted devices can communicate with the processing module, thereby enhancing the security and reliability of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025081185000001_ABST
    Figure 2025081185000001_ABST
Patent Text Reader

Abstract

To provide a communication system, a remote terminal device, and an authentication method thereof that effectively guarantee that an external input / output module is a trustworthy device.SOLUTION: A remote terminal device includes a processing module. The processing module includes a first processing unit and a first storage unit. The first storage unit is connected to the first processing unit. In response to a trigger unit being enabled, the first processing unit operates in a provisioning mode to enable an input / output module and the processing module to establish trust. In response to the trigger unit being disabled, the first processing unit operates in an operational mode to prohibit another input / output module that has not yet established trust from connecting to the processing module.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus, and more particularly to a communication system, a remote terminal device, and an authentication method thereof.

Background Art

[0002] In order to prevent a remote terminal unit (RTU) from being attacked by a malicious program or having its data stolen, how to ensure that an external input / output module is a reliable device has become an important issue in this field at present. Although various communication security protocols have been developed in the communication field, effective authentication between devices has still not been achieved, and it is not possible to effectively verify whether a connected device has been forged or whether data has been stolen or tampered with.

Summary of the Invention

Problems to be Solved by the Invention

[0003] The present invention provides a communication system, a remote terminal device, and an authentication method thereof that can effectively guarantee that an external input / output module is a reliable device.

Means for Solving the Problems

[0004] The remote terminal device of the present invention includes a processing module. The processing module includes a first processing unit and a first storage unit. The first storage unit is connected to the first processing unit. In response to the activation of the trigger unit, the first processing unit operates in a provisioning mode to enable the input / output module and the processing module to establish trust. In response to the deactivation of the trigger unit, the first processing unit operates in an operation mode to prohibit another input / output module that has not yet established trust from connecting to the processing module.

[0005] The authentication method of the present invention is applied to a remote terminal device. The remote terminal device includes a processing module. The authentication method includes the following steps. In response to the activation of the trigger unit, the first processing unit of the processing module operates in the provisioning mode to enable the input / output module and the processing module to establish trust. In response to the deactivation of the trigger unit, the first processing unit of the processing module operates in the operation mode to prohibit another input / output module that has not yet established trust from connecting to the processing module.

[0006] The communication system of the present invention includes a remote terminal device and an expansion device. The remote terminal device includes a processing module. The expansion device includes an input / output module and is connected to the remote terminal device. In response to the activation of the trigger unit of the processing module, the processing module operates in the provisioning mode to enable the input / output module and the processing module to establish trust. In response to the deactivation of the trigger unit, the processing module operates in the operation mode to prohibit another input / output module that has not yet established trust from connecting to the processing module.

[0007] Based on the above, the communication system, the remote terminal device, and its authentication method can effectively establish a trust relationship with the input / output module.

Advantages of the Invention

[0008] To make the features and advantages of the present invention easier to understand, the following specific embodiments will be described in detail in conjunction with the drawings.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Mode for Carrying Out the Invention

[0010] Next, exemplary embodiments of the present invention will be referred to in detail, and examples thereof will be shown in the drawings. As much as possible, the same reference numerals are used in the drawings and the description to indicate the same or similar parts.

[0011] FIG. 1 is a schematic diagram of a communication system according to an embodiment of the present invention. Referring to FIG. 1, the communication system 100 includes a remote terminal device 110, an expansion device 120, and a server 130. The remote terminal device 110 includes a processing module 111 and a plurality of input / output (I / O) modules 112_1 to 112_M. Here, M is a positive integer. The remote terminal device 110 may be connected to the expansion device 120 via a wired method (for example, a cable). The remote terminal device 110 and the expansion device 120 can be arranged at a considerable distance in different application areas, but the present invention is not limited thereto. The expansion device 120 includes other input / output modules 122_1 to 122_N. Here, N is a positive integer. The expansion device 120 may be another remote terminal device. The remote terminal device 110 may be used to implement related applications for monitoring, control, or data collection.

[0012] In this embodiment, the processing module 111 may be used to manage, control, or monitor the input / output modules 112_1 to 112_M and 122_1 to 122_N, and is connected to the server 130 through a wired or wireless method. The processing module 111 can collect the information provided by the input / output modules 112_1 to 112_M and 122_1 to 122_N respectively, or transmit related information to the input / output modules 112_1 to 112_M and 122_1 to 122_N.

[0013] In this embodiment, the processing module 111 may include related processing and calculation circuits including, for example, a central processing unit (CPU), but the present invention is not limited thereto. The input / output modules 112_1 to 112_M and 122_1 to 122_N may each be different types of sensors, IoT (Internet of Things) devices, valve parts, control parts, and similar input / output parts, but the present invention is not limited thereto. In this embodiment, the input / output modules 112_1 to 112_M and 122_1 to 122_N may have a hot swapping function so that they can be selectively attached to or removed from the remote terminal device 110 (that is, the processing module 111) when the remote terminal device 110 is in an operating mode according to different usage states.

[0014] Specifically, assuming that there is no established trust between the input / output modules 112_1 to 112_M and 122_1 to 122_N and the processing module 111, if any of the input / output modules 112_1 to 112_M and 122_1 to 122_N is temporarily attached to the remote terminal device 110 or the expansion device 120, the processing module 111 can establish trust with it. Also, after a certain input / output module has established trust with the processing module 111 of the remote terminal device 110, if that input / output module is attached to the remote terminal device 110 or the expansion device 120 at any time, its processing module 111 can automatically establish a connection with the input / output module. In contrast, when an input / output module that has not established a trust relationship with the processing module 111 is attached to the remote terminal device 110 or the expansion device 120, the processing module 111 can effectively and immediately identify and directly reject the connection of the input / output module that has not established trust with the processing module 111.

[0015] Figure 2 is a schematic diagram of a processing module and an input / output module according to an embodiment of the present invention. Referring to Figure 2, the processing module 111 in Figure 1 can be implemented as the processing module 210 in this embodiment, and any of the input / output modules 112_1 to 112_M and 122_1 to 122_N in Figure 1 can be implemented as the input / output module 220 in this embodiment. In this embodiment, the processing module 210 includes a first processing unit 211, a first storage unit 212, and a trigger unit 213. The first processing unit 211 is connected to the first storage unit 212 and the trigger unit 213. The input / output module 220 includes a second processing unit 221 and a second storage unit 222.

[0016] In this embodiment, the first processing device 211 and the second processing device 221 may each be, for example, a central processing unit (CPU), a graphics processing unit (GPU), other programmable general-purpose or special-purpose microprocessors, a digital signal processor (DSP), a programmable controller, an application specific integrated circuit (ASIC), a programmable logic device (PLD), other similar processing units, or a combination of units. In this embodiment, the first storage unit 212 and the second storage unit 22 may include, for example, a flash memory and a non-volatile random access memory (NVRAM).

[0017] FIG. 3 is a flowchart of an authentication method for a remote terminal device according to an embodiment of the present invention. Referring to FIGS. 2 and 3, the processing module 210 can execute the following steps S310 to S340. In step S310, the trigger unit 213 can be enabled (or triggered). In step S320, in response to the trigger unit 213 being enabled, the first processing unit 211 of the processing module 210 operates in a provision mode to enable the input / output module 220 and the processing module 210 to establish trust. In step S330, the trigger unit 213 can be disabled. In step S340, in response to the trigger unit 213 being disabled, the first processing unit 211 of the processing module 210 operates in a running mode to prohibit another input / output module that has not yet established trust from connecting to the processing module 210. In the running mode, the processing module 210 can communicate with the input / output module 220 that has established trust and transmit data.

[0018] In this embodiment, the trigger unit 213 is a physical button and is disposed within the processing module 210. Here, the remote terminal device 110 shown in FIG. 1 can be deployed, for example, in a highly secure server room. Alternatively, in one embodiment, the trigger unit 213 can be physically deployed within a highly secure facility through external wiring to enhance protection through a highly secure server room, but the present invention is not limited thereto. In another embodiment, the trigger unit 213 may be a virtual button and may be remotely operated to be enabled or disabled, for example, by a remote network interface or a network management tool.

[0019] Specifically, as shown in FIG. 1, when the input / output module 220 is attached to the remote terminal device 110 or the expansion device 120, since the trust relationship between the processing module 210 and the input / output module 220 has not been established yet, the processing module 210 first prohibits the input / output module 220 from connecting to the processing module 210. Next, when the user enables the trigger unit 213 (for example, by manually triggering a physical button or remotely operating via a virtual button), the processing module 210 and the input / output module 220 start to establish trust. In this way, the processing module 210 can implement a highly secure communication protection mechanism and can dynamically establish trust according to the user's operation when the input / output module 220 is hot-swapped. Further, the method for the processing module 210 to establish a trustworthy input / output module 220 will be described in detail in the following embodiments.

[0020] FIG. 4 is a schematic diagram of initialization according to an embodiment of the present invention. Referring to FIGS. 2 and 4, in the initialization stage of the device, the processing module 210 can establish a unique processing module private key 411 and a unique processing module certificate 412, and store the processing module private key 411 and the processing module certificate 412 in the first storage unit 212. The input / output module 220 can establish a unique input / output module private key 421 and a unique input / output module certificate 422, and store the input / output module private key 421 and the input / output module certificate 422 in the second storage unit 222. Note that the processing module 210 and the input / output module 220 can each establish a random private key and certificate, but it should be noted that all the private keys and certificates established by different modules are unique (i.e., non-duplicating). In this embodiment, the processing module 210 can store the processing module private key 411, for example, in a secure storage space of the first storage unit 212 such as a specific area of the memory or a hardware security module (HSM), but the present invention is not limited thereto. The input / output module 220 can also store the input / output module private key 421 in a secure storage space of the second storage unit 222.

[0021] FIG. 5 is a schematic diagram of the provisioning mode according to an embodiment of the present invention. Referring to FIGS. 2 and 5, after the initialization of the device, when the trigger unit 213 becomes effective, the first processing unit 211 of the processing module 210 operates in the provisioning mode. In this embodiment, the first processing unit 211 can send a notification signal to the input / output module 220 so that the processing module 210 and the input / output module 220 can obtain each other's certificates. The first processing unit 211 can send a notification signal to the input / output module 220 via the Link Layer Discovery Protocol (LLDP). Here, the notification signal may include organization-specific information of the Link Layer Discovery Protocol.

[0022] For example, the first processing unit 211 can adopt a custom LLDP type such as LLDP type 127 to configure the relevant parameters in the notification signal. That is, the data format of the notification signal can conform to LLDP type 127. Here, the data format may include a destination address (DA), a source address (SA), an Ethernet type, a chassis identifier, a port identifier, a time to live (TTL), any optional TLV (type, length, value), and an end of LLDP data unit TLV. Here, the chassis identifier, the port ID, the time to live, any optional TLV, and the end of LLDPDU TLV may have variable data lengths, and the first processing unit 211 can encrypt the relevant data regarding the provisioning mode into the above data fields based on the basic TLV data format. In this way, when the second processing unit 221 of the input / output module 220 receives the notification signal in the data format, the second processing unit 221 can confirm that the first processing unit 211 is operating in the provisioning mode and concurrently execute the provisioning mode.

[0023] In this embodiment, when the processing module 210 notifies the input / output module 220 to enter the provisioning mode, the processing module 210 and the input / output module 220 can obtain each other's certificates. Here, the processing module 210 and the input / output module 220 can obtain each other's certificates based on the Mutual Transport Layer Security (MTLS) communication protocol and establish trust, but the present invention is not limited thereto. After the processing module 210 and the input / output module 220 establish trust, the communication connection 401 can be established. In the provisioning mode, the processing module 210 and the input / output module 220 may trust the data transmitted by the handshake between the processing module 210 and the input / output module 220.

[0024] FIG. 6 is a flowchart for obtaining each other's certificates according to an embodiment of the present invention. Referring to FIGS. 2, 5, and 6, the processing module 210 and the input / output module 220 can execute the following steps S610 to S640. In step S610, in the provisioning mode, the first processing unit 211 of the processing module 210 may transmit the processing module certificate 412 to the input / output module 220. In step S620, the second processing unit 221 of the input / output module 220 receives the processing module certificate 412 transmitted by the processing module 210 and may store the processing module certificate 412 in the second storage unit 222, that is, the processing module certificate 423 in FIG. 5. In step S630, the second processing unit 221 of the input / output module 220 may transmit the input / output module certificate 422 to the processing module 210. In step S640, the first processing unit 211 of the processing module 210 receives the input / output module certificate 422 transmitted by the input / output module 220 and may store the input / output module certificate 422 in the first storage unit 212, that is, the input / output module certificate 413 in FIG. 5.

[0025] It is worth noting that the processing module 210 can also store a plurality of different input / output module certificates from different input / output modules in the second storage unit 222. Further, when the processing module 210 receives a new input / output module certificate retransmitted by the input / output module that recorded the certificate, it may copy the new input / output module certificate to the first storage unit 212.

[0026] FIG. 7 is a schematic diagram of an operation mode according to an embodiment of the present invention. Referring to FIGS. 2 and 7, when the trigger unit 213 is invalid, the first processing unit 211 of the processing module 210 operates in the operation mode. In this embodiment, the verification of the certificate can be executed between the processing module 210 and the input / output module 220 based on the mutual transport layer security protocol. Here, the processing module 210 and the input / output module 220 execute a handshake to verify whether their respective certificates and their respective pre-stored certificates pass the verification for establishing the communication connection 401. In this embodiment, the method of verifying whether the mutual certificates are the same as the pre-stored certificates of each other can be performed, for example, by executing asymmetric key authentication.

[0027] FIG. 8 is a flowchart of a handshake procedure according to an embodiment of the present invention. Referring to FIGS. 2, 5, and 6, the processing module 210 and the input / output module 220 can execute the following steps S810 to S830. In step S810, the first processing unit 211 of the processing module 210 transmits the first handshake data 414 to the input / output module 220 and receives the second handshake data from the input / output module 220. The first handshake data 414 may include the processing module certificate 412. The second handshake data 424 may include the input / output module certificate 422.

[0028] In step S820, the first processing unit 211 of the processing module 210 decrypts the second handshake data 424 according to the processing module private key 411 stored in the first storage unit 212, obtains the input / output module certificate 422, verifies the input / output module certificate 422 and the input / output module certificate 413 stored in the first storage unit 212, and can confirm whether trust has been established with the input / output module 220. The first storage unit 212 of the processing module 210 may store a plurality of certificates corresponding to different input / output modules, and the first processing unit 211 of the processing module 210 may perform certificate search and verification operations according to the input / output module certificate 422. Here, when the input / output module certificate 422 and the input / output module certificate 413 pass the verification, the first processing unit 211 can confirm that the input / output module 220 is a trustworthy device and establish the communication connection 401. In contrast, when the input / output module certificate 422 and the input / output module certificate 413 do not pass the verification, the first processing unit 211 prohibits (rejects) the connection between the input / output module 220 and the processing module 210.

[0029] In step S830, the second processing unit 221 of the input / output module 220 decrypts the first handshake data 414 according to the input / output module private key 421 stored in the second storage unit 222, obtains the processing module certificate 412, verifies the processing module certificate 412 and the processing module certificate 423 stored in the second storage unit 222, and can confirm whether trust has been established with the processing module 210. Here, when the processing module certificate 412 and the processing module certificate 423 pass the verification, the second processing unit 221 can confirm that the processing module 210 is a trustworthy device and establish the communication connection 401. In this way, the processing module 210 can communicate with the input / output module 220 in a state where the certificates of each other have been normally obtained in the previous provisioning mode, and can reject the connection of other input / output modules that have not normally obtained the certificates of each other.

[0030] In summary, the communication system, remote terminal device, and authentication method of the present invention can determine whether to establish trust with a hot-swapped input / output module by operating the trigger unit with high security, and can effectively ensure that the input / output module communicating with the processing module is a trustworthy device.

[0031] Finally, it should be noted that the above embodiments are only used for explaining the technical solutions of the present invention exclusively and are not restrictive. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can be further modified, or some or all of their technical features can be equivalently replaced. However, such modifications or replacements do not deviate from the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention.

Industrial Applicability

[0032] The communication system, remote terminal device, and authentication method of the present invention can be applied to a remote control system and its communication authentication method.

Explanation of Reference Numerals

[0033] 100: Communication system 110: Remote terminal device 111, 210: Processing module 112_1~112_M, 122_1~122_N, 220: Input / output module 120: Expansion device 130: Server 211: First processing unit 212: First storage unit 213: Trigger unit 221: Second processing unit 222: Second storage unit 401: Communication connection 411: Processing module private key 412, 423: Processing module certificate 413, 422: Input / output module certificate 414: First handshake data 421: Input / output module private key 424: Second handshake data S310~S340, S610~S640, S810~S830: Processes

Claims

1. A first processing unit, a first storage unit connected to the first processing unit, and a processing module including the same, in response to the trigger unit becoming effective, the first processing unit operates in a provisioning mode to enable the input / output module and the processing module to establish trust, in response to the trigger unit becoming ineffective, the first processing unit operates in an operation mode to prohibit another input / output module that has not yet established trust from connecting to the processing module, a remote terminal device.

2. In response to the first processing unit operating in the provisioning mode, the first processing unit transmits a notification signal to the input / output module so that the processing module and the input / output module acquire each other's certificates, the remote terminal device according to claim 1.

3. The first processing unit transmits the notification signal to the input / output module via a Link Layer Discovery Protocol (LLDP), the remote terminal device according to claim 2.

4. The notification signal includes organization-specific information of the Link Layer Discovery Protocol, the remote terminal device according to claim 3.

5. In response to the processing module and the input / output module acquiring each other's certificates, the first processing unit transmits a processing module certificate to the input / output module, receives an input / output module certificate from the input / output module, and stores the input / output module certificate in the first storage unit, a second processing unit of the input / output module receives the processing module certificate from the processing module and stores the processing module certificate in a second storage unit of the input / output module, the remote terminal device according to claim 2.

6. In response to the first processing unit operating in the operation mode, the first processing unit transmits first handshake data to the input / output module and receives second handshake data from the input / output module, the first processing unit decrypts the second handshake data according to a first private key stored in the first storage unit, verifies the input / output module certificate stored in the first storage unit, and checks whether a communication connection with the input / output module has been established, the remote terminal device according to claim 5.

7. The second processing unit of the input / output module decrypts the first handshake data according to the second private key stored in the second storage unit, verifies the processing module certificate stored in the second storage unit, and checks whether a communication connection with the processing module is established. The remote terminal device according to claim 6.

8. The processing module and the input / output module obtain each other's certificates based on the mutual transport layer security communication protocol to establish trust. The remote terminal device according to claim 2.

9. The trigger unit is a physical button and is arranged inside the processing module. The remote terminal device according to claim 1.

10. The trigger unit is a virtual button and is remotely operated by a remote network interface or a network management tool to be enabled or disabled. The remote terminal device according to claim 1.

11. The remote terminal device further includes the input / output module. The remote terminal device according to claim 1.

12. The input / output module is arranged inside the expansion device. The remote terminal device according to claim 1.

13. An authentication method for a remote terminal device including a processing module, In response to the trigger unit becoming enabled, the first processing unit of the processing module operates in a provisioning mode to enable the input / output module and the processing module to establish trust, and In response to the trigger unit becoming disabled, the first processing unit of the processing module operates in an operating mode to prohibit another input / output module that has not yet established trust from connecting to the processing module. An authentication method including.

14. The step in which the first processing unit of the processing module operates in the provisioning mode is In response to the first processing unit operating in the provisioning mode, the first processing unit transmits a notification signal to the input / output module so that the processing module and the input / output module obtain each other's certificates. The authentication method according to claim 13.

15. The first processing unit transmits the notification signal to the input / output module via a link layer detection protocol. The authentication method according to claim 14.

16. The authentication method according to claim 15, wherein the notification signal includes organization-specific information of the link layer detection protocol.

17. The step in which the processing module and the input / output module obtain each other's certificates includes: transmitting a processing module certificate to the input / output module by the first processing unit of the processing module; receiving the processing module certificate transmitted by the processing module by the second processing unit of the input / output module and storing the processing module certificate in the second storage unit of the input / output module; transmitting an input / output module certificate to the processing module by the second processing unit of the input / output module; receiving the input / output module certificate transmitted by the input / output module by the first processing unit of the processing module and storing the input / output module certificate in the first storage unit of the processing module. The authentication method according to claim 14 includes the above.

18. In response to the first processing unit operating in the operation mode, the authentication method includes: transmitting first handshake data to the input / output module by the first processing unit of the processing module and receiving second handshake data from the input / output module; decoding the second handshake data according to the first private key stored in the first storage unit by the first processing unit of the processing module, verifying the input / output module certificate stored in the first storage unit, and confirming whether a communication connection with the input / output module is established; decoding the first handshake data according to the second private key stored in the second storage unit by the second processing unit of the input / output module, verifying the processing module certificate stored in the second storage unit, and confirming whether a communication connection with the processing module is established. The authentication method according to claim 17 further includes the above.

19. The authentication method according to claim 14, wherein the processing module and the input / output module obtain each other's certificates based on a mutual transport layer security communication protocol to establish trust.

20. A remote terminal device including a processing module; An expansion device including an input / output module and connected to the remote terminal device; Comprising: In response to the trigger part of the processing module becoming effective, the processing module operates in a provisioning mode to enable the input / output module and the processing module to establish trust. In response to the trigger part becoming ineffective, the processing module operates in an operation mode, and a communication system that prohibits another input / output module that has not yet established trust from connecting to the processing module.

Citation Information

Patent Citations

  • System upgrading method, terminal and storage medium

    CN111338663A

  • Deploying and receiving software over network susceptible to malicious communication

    JP2006085714A

  • Method and system for securely and remotely startup, boot, and login from mobile device to computer

    JP2011222010A

  • Provisioning

    JP2016032300A

  • Authentication system

    JP2016143396A