Network system and packet relay method
The network system facilitates conditional access to external devices from closed networks by using a repeater and monitoring device for IP address and DNS conversion, addressing security and complexity issues in existing systems, suitable for small-scale institutions.
Patent Information
- Application Number
- JP2023215768
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2043-12-21
AI Technical Summary
Existing network systems in medical institutions and other closed networks face challenges in allowing conditional access to external devices while maintaining high security, requiring complex and expensive configurations that are difficult to implement without skilled engineers.
A network system comprising a repeater, terminal devices, and a monitoring device that enables access to external devices by relaying packets through a broadband router, using IP address conversion and DNS record storage to ensure legitimate connections, with monitoring for validity of connection destinations.
Enables simple and inexpensive conditional access to external devices from closed networks, suitable for small-scale institutions without specialized technical expertise, preventing accidental information leakage.
Smart Images

Figure 2025099254000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a network system and a packet relay method that enable conditional access to an external device from a terminal device connected to a closed network and having restricted access to devices on an external network.
Background Art
[0002] Conventionally, in medical institutions such as hospitals, it is necessary to prevent the intrusion of malicious programs from an external network into the in-hospital network and the accidental leakage of information to the external network. For this reason, in medical institutions, in principle, the in-hospital network is a closed network, and access to the outside of the medical institution is limited to regional medical cooperation, etc. (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, these days, with the progress of the information society, there are cases where medical personnel such as doctors want to access an HTTP server connected to an external network from a terminal device connected to the in-hospital network.
[0005] In addition, a mechanism that partially permits access from a closed network to an external network has a complex and expensive configuration in order to ensure high security, and thus is realized only in a closed network with highly skilled engineers and large-scale facilities.
[0006] Therefore, while restricting access to the external network, it has become an issue how to implement a mechanism that allows access from the in-hospital network to the external network as needed. Such an issue occurs not only in the network of a medical institution but also in a closed network of an enterprise that needs to maintain high security.
[0007] The present invention has been made to solve the problems (issues) of the above prior art, and an object thereof is to provide a network system and a packet relay method that enable conditional access to an external device from a terminal device connected to a closed network and having restricted access to a device on the external network.
Means for Solving the Problem
[0008] In order to solve the above-described problems and achieve the object, the present invention provides a network system including a terminal device connected to a closed network and having restricted access to the external network, a broadband router that enables access to a predetermined HTTP server via the external network, a repeater interposed between the broadband router and the closed network, and a monitoring device that monitors the terminal device. The terminal device registers the IP address of the repeater and the first connection destination information of the HTTP server in a predetermined host table. If the repeater receives a packet addressed to itself from the terminal device, the repeater relays the packet toward the HTTP server included in the first connection destination information in the packet. The monitoring device includes an acquisition unit that acquires the host table from the terminal device, a storage unit that stores the second connection destination information of a legitimate HTTP server accessible from the terminal device, a determination unit that determines whether the first connection destination information is legitimate based on the first connection destination information acquired by the acquisition unit and the second connection destination information stored in the storage unit, and a notification unit that performs a predetermined notification when the first connection destination information is not legitimate.
[0009] Further, in the present invention, in the above invention, the first connection destination information and the second connection destination information are IP addresses, and when the repeater receives the packet addressed to itself from the terminal device, the repeater relays the packet to the HTTP server of the IP address included in the packet.
[0010] Further, in the present invention, in the above invention, the first connection destination information and the second connection destination information are domain names, and the repeater includes a storage unit that stores a DNS record acquired from a predetermined domain name server, and when the repeater receives the packet addressed to itself from the terminal device, a conversion unit that converts the destination IP address portion of the packet to the IP address of the HTTP server based on the DNS record stored in the storage unit, and a transmission unit that transmits the packet to the HTTP server of the IP address converted by the conversion unit.
[0011] Further, in the present invention, in the above invention, the monitoring device further includes a deletion instruction unit that issues a deletion instruction for the first connection destination information to the terminal device when the first connection destination information is not valid. The network system according to claim 1, characterized in that.
[0012] Further, the present invention is a network system including a terminal device connected to a closed network and having restricted access to an external network, a broadband router that enables access to a predetermined HTTP server via the external network, a repeater interposed between the broadband router and the closed network and assigned a plurality of IP addresses, and a monitoring device that monitors the terminal device. The terminal device associates the plurality of IP addresses assigned to the repeater with the first connection destination information of the HTTP server corresponding to each IP address and registers them in a predetermined host table. If the repeater receives a packet addressed to any of the plurality of IP addresses assigned to the repeater from the terminal device, the repeater relays the packet to the HTTP server of the first connection destination information included in the packet. The monitoring device includes an acquisition unit that acquires the host table from the terminal device, a storage unit that stores the second connection destination information of a plurality of legitimate HTTP servers accessible from the terminal device, and a determination unit that determines whether the plurality of first connection destination information is legitimate based on the plurality of first connection destination information included in the host table acquired by the acquisition unit and the plurality of legitimate second connection destination information of the HTTP servers stored in the storage unit, and a notification unit that performs a predetermined notification when the plurality of first connection destination information is not legitimate.
[0013] In addition, the present invention relates to a packet relay method in a network system including a terminal device connected to a closed network and having restricted access to an external network, a broadband router enabling access to a predetermined HTTP server via the external network, a repeater interposed between the broadband router and the closed network, and a monitoring device for monitoring the terminal device. The method includes: a registration step in which the terminal device registers the IP address of the repeater and first connection destination information of the HTTP server in a predetermined host table; a relay step in which, when the repeater receives a packet addressed to itself from the terminal device, the repeater relays the packet toward the HTTP server included in the first connection destination information contained in the packet; an acquisition step in which the monitoring device acquires the host table from the terminal device; a storage step in which the monitoring device stores second connection destination information of a legitimate HTTP server accessible from the terminal device in a predetermined storage unit; a determination step in which the monitoring device determines whether the first connection destination information is legitimate based on the first connection destination information acquired in the acquisition step and the second connection destination information stored in the storage unit; and a notification step in which, when the first connection destination information is not legitimate, a predetermined notification is performed.
Effects of the Invention
[0014] According to the present invention, it is possible to conditionally enable access to an external device from a terminal device connected to a closed network and having restricted access to devices on the external network.
[0015] In particular, since it is possible to realize a mechanism that partially allows access from a closed network to an external network with simple and inexpensive devices and configurations, even in small-scale medical institutions such as hospitals and clinics that do not require the intervention of highly skilled technicians, it is possible to provide conditional connection to an external device from a terminal device connected to an in-hospital network, which is a closed network.
Brief Description of the Drawings
[0016]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
[0017] Hereinafter, embodiments of the network system and the packet relay method according to the present invention will be described in detail with reference to the drawings.
[0018] [Embodiment 1] <Overview of Network System 10> First, an overview of the network system 10 according to Embodiment 1 will be described. Here, a network will be described in which the network system 10 can be connected to the external network N without installing a DNS (Domain Name System) server, and the terminal device connected to the closed network A cannot access unnecessary network devices on the external network.
[0019] FIG. 1 is a diagram showing an overview of the network system according to Embodiment 1. As shown in FIG. 1, in the network system 10 according to the present Embodiment 1, a repeater 20 is connected to a closed network A, and a plurality of terminal devices 30a, 30b, 30c (hereinafter, may be collectively referred to as "terminal device 30") are connected to the closed network A.
[0020] Further, the repeater 20 is connected to a broadband router 40 via a closed network B in order to transmit the packet received from the closed network A to the external network N. Here, the closed network A and the closed network B are networks constructed using private IP addresses defined by the IETF (Internet Engineering Task Force) or the like. Also, the external network N is a network constructed using global IP addresses defined by the IETF or the like.
[0021] The broadband router 40 is connected to the external network N, and a DNS server 60, an HTTP server 50, etc. are connected to the external network N.
[0022] The repeater 20 is a device for relaying packets that receives packets transmitted from the terminal device 30 connected to the closed network A and transmits them to the external network N, or receives packets from an HTTP server 50 or the like connected to the external network N and transmits them to the terminal device 30 connected to the closed network A.
[0023] Here, in order for other network devices connected to the closed network A to access the repeater 20, the repeater 20 is assigned two private IP addresses on the closed network A side: an IP address 10.128.10.1 / 24 (IP-A) and a relay private IP address 10.128.10.10 / 24 (IP-B) for relaying packets from the closed network A to the external network N. Also, the repeater 20 is assigned a private IP address 192.168.38.100 / 24 (IP-C) on the closed network B side.
[0024] The terminal device 30a is connected to the closed network A and is assigned a private IP address 10.128.10.100 / 24 (IP-W). Also, the terminal device 30a stores in its host table an FQDN (Full Qualified Domain Name: domain name) (first connection destination information) and an IP address associated with the domain name. Here, for the domain name: www.abc123.com, the relay private IP address 10.128.10.10 / 24 of the repeater 20 is stored.
[0025] The terminal device 30b is connected to the closed network A and is assigned a private IP address 10.128.10.101 / 24 (IP-X). Also, the terminal device 30c is connected to the closed network A and is assigned a private IP address 10.128.10.102 / 24 (IP-Y).
[0026] The broadband router 40 is a device that relays packets transmitted from the closed network B to network devices on the external network N and packets from network devices on the external network N to the closed network B.
[0027] Specifically, in the case of a packet from the closed network B to a network device on the external network N, the broadband router 40 converts the source IP address assigned to the packet from the private IP address to the public IP address assigned to the broadband router 40, and transmits the packet to the external network N. Also, in the case of a packet from a network device on the external network N to a network device on the closed network B, the broadband router 40 converts the destination IP address assigned to the packet from the public IP address assigned to the broadband router 40 to the private IP address of a network device (for example, the repeater 20) on the closed network B, and transmits the packet to the closed network B.
[0028] The HTTP server 50 is a web server that provides WWW (World Wide Web) services and is connected to the external network N. The HTTP server 50 has a domain name: www.abc123.com and is assigned a global IP address: 54.211.112.33 (IP-Z).
[0029] When the DNS server 60 receives a DNS request from another network device, it returns the global IP address assigned to the domain from the domain name in the DNS request.
[0030] For example, when the terminal device 30a wants to connect to the HTTP server 50 in the network system 10 according to the first embodiment, the terminal device 30a transmits a packet of a connection request to the relay private IP address (IP-B) for relaying the packet to the external network N of the repeater 20. Then, the repeater 20 converts the source IP address and the destination IP address of the received connection request packet into predetermined IP addresses, and transmits the packet to the HTTP server 50 via the broadband router 40. Then, the response packet from the HTTP server 50 is transmitted to the terminal device 30a along the reverse route described above.
[0031] Specifically, as shown in FIG. 2, if the operator inputs "HTTPS: / / www.abc123.com" into the terminal device 30a and the terminal device 30a receives a connection request to www.abc123.com (S1), the terminal device 30a refers to the host table (S2). Then, based on the host table, the IP address of www.abc123.com is the relay private IP address of the repeater 20: 10.128.10.10 / 24 (IP-B). Therefore, the terminal device 30a generates and transmits a packet with the source IP address: IP-W and the destination IP address: IP-B (S3).
[0032] The repeater 20 receives the packet from the terminal device 30a (S4). Since the received packet is a packet transmitted to the relay private IP address: IP-B for relaying from the terminal device 30a to the external network N of the repeater 20, the repeater 20 converts the source IP address: IP-W and the destination IP address: IP-B of the packet transmitted from the terminal device 30a to the source IP address: IP-C and the destination IP address: IP-Z (S5). Then, the repeater 20 transmits the packet after address conversion to the HTTP server 50 via the broadband router 40 through the broadband router 40 (S6).
[0033] Then, the HTTP server 50 receives the packet from the repeater 20 (S7). The response packet from the HTTP server 50 is transmitted to the requesting terminal device 30a by performing address conversion reverse to the above-described process.
[0034] In this way, the network system 10 according to the present invention transmits a packet of a connection request from the terminal device 30 connected to the closed network A to the HTTP server 50 connected on the external network to the relay private IP address of the repeater 20. The repeater 20 converts the source IP address and the destination IP address of the packet into predetermined IP addresses and transmits them to the HTTP server 50 on the external network, thereby enabling the terminal device 30 connected to the closed network A to connect to the HTTP server 50 on the external network N.
[0035] In addition, even if the terminal device 30 connected to the closed network A makes a connection request to an HTTP server not stored in the host table 35a, the terminal device 30 cannot connect to the HTTP server. Therefore, accidental information leakage to the external network can be prevented.
[0036] In particular, since it is possible to realize a mechanism that partially allows access from the closed network A to the external network N with simple and inexpensive devices and configurations, even in small-scale medical institutions such as hospitals and clinics that do not require the intervention of highly skilled technicians, it is possible to provide conditional connection from the terminal device 30 connected to the closed network (intra-hospital network) A to the HTTP server 50.
[0037] <Configuration of the Repeater 20> Next, the configuration of the repeater 20 shown in FIG. 1 will be described. FIG. 3 is a functional block diagram showing the configuration of the repeater 20 shown in FIG. 1. As shown in FIG. 3, the repeater 20 includes a communication I / F unit 23, a storage unit 24, and a control unit 25. The communication I / F unit 23 is a communication interface unit for communicating with the terminal devices 30a, 30b, 30c via the closed network A and with the broadband router 40 via the closed network B.
[0038] The storage unit 24 is a storage device such as a hard disk device or a non-volatile memory, and stores a DNS record 24a and relay rule data 24b. The DNS record 24a is correspondence data between a domain name and a global IP address.
[0039] The relay rule data 24b is data that associates the global IP address of an HTTP server or the like on the externally permitted external network N with the private IP address for packet relay of the repeater 20 based on the DNS record 24a. For example, in Embodiment 1, the private IP address for packet relay of the repeater 20: 10.128.10.10 / 24 is associated with the global IP address of the HTTP server 50: 54.211.112.33.
[0040] The control unit 25 is a control unit that controls the entire repeater 20, and includes a DNS data acquisition unit 25a, a packet reception unit 25b, an address conversion unit 25c, and a packet transmission unit 25d. Actually, by loading these programs into the CPU and executing them, processes corresponding to the DNS data acquisition unit 25a, the packet reception unit 25b, the address conversion unit 25c, and the packet transmission unit 25d will be executed respectively.
[0041] The DNS data acquisition unit 25a is a processing unit that connects to the DNS server 60 on the external network N and acquires data of the domain name and the corresponding global IP address. The acquired data is stored in the storage unit 24 as the DNS record 24a.
[0042] The packet reception unit 25b is a processing unit that receives packets transmitted to the private IP addresses (IP-A, IP-B, IP-C) assigned to the repeater 20.
[0043] The address conversion unit 25c performs a process of address-converting the source IP address and the destination IP address of a packet transmitted to the relay private IP address: IP-B for relaying to the external network N for the external network N, and a process of address-converting the source IP address and the destination IP address of a packet transmitted from the HTTP server 50 on the external network N for the closed network A. Note that the address conversion in the address conversion unit 25c is performed with reference to the relay rule data 24b.
[0044] As an example, the IP address of the packet for the HTTP server 50 on the external network N transmitted from the terminal device 30a (source IP address: IP-X, destination IP address: IP-B) is converted into a relay IP address (source IP address: IP-C, destination IP address: IP-Z).
[0045] Also, the address conversion unit 25c converts the IP address of the response packet from the HTTP server 50 (source IP address: IP-Z, destination IP address: IP-C) into an IP address for the closed network A (source IP address: IP-B, destination IP address: IP-W).
[0046] The packet transmission unit 25d is a processing unit that transmits the packet whose address has been converted. Note that the repeater 20 may be provided with a relay unit that integrates the functions of the address conversion unit 25c and the packet transmission unit 25d.
[0047] <Configuration of the terminal device 30a> Next, the configuration of the terminal device 30a shown in FIG. 1 will be described. FIG. 4 is a functional block diagram showing the configuration of the terminal device 30a shown in FIG. 1. As shown in FIG. 4, the terminal device 30a includes a display unit 31, an input unit 32, a communication I / F unit 34, a storage unit 35, and a control unit 36. The display unit 31 is a display device such as a liquid crystal display that displays various information. The input unit 32 is an input device such as a mouse or a keyboard. The communication I / F unit 34 is a communication interface unit for communicating with the repeater 20 via the closed network A.
[0048] The storage unit 35 is a storage device such as a hard disk device or a non-volatile memory, and stores a host table 35a. The host table 35a is correspondence data between the domain name of the HTTP server and the relay private IP address of the repeater 20. Here, the relay private IP address of the repeater 20: IP-B and the domain name of the HTTP server 50 on the external network N: www.abc123.com are associated with each other.
[0049] The control unit 36 is a control unit that controls the entire terminal device 30a, and includes a reference unit 36a, a packet transmission unit 36b, a packet reception unit 36c, and a display control unit 36d. Actually, by loading and executing these programs on the CPU, processes corresponding to the reference unit 36a, the packet transmission unit 36b, the packet reception unit 36c, and the display control unit 36d are executed respectively.
[0050] The reference unit 36a is a processing unit that refers to the host table 35a and obtains the corresponding IP address from the input domain name. The packet transmission unit 36b is a processing unit that transmits packets. The packet reception unit 36c is a processing unit that receives packets addressed to the private IP address of the terminal device 30a. The display control unit 36d is a processing unit that controls the display of the content of the received packet on a predetermined display unit 31.
[0051] Note that the terminal devices 30b and 30c also have the same configuration as the terminal device 30a, but the terminal devices 30b and 30c that do not need to be connected to the external network N do not have the host table 35a in the storage unit 35. If the terminal devices 30b and 30c receive an input of a domain name when trying to access the HTTP server 50 on the external network N, since the information of the destination IP address cannot be obtained, the display control is performed to display that the connection cannot be made on the predetermined display unit 31.
[0052] <Processing procedure of the network system 10> Next, the processing procedure of the network system 10 shown in FIG. 1 will be described. FIG. 5 is a sequence diagram for explaining the processing procedure of the network system 10 shown in FIG. 1. As shown in FIG. 5, the terminal device 30a receives a connection request to the HTTP server on the external network N from the operator (step S101). Then, with respect to the domain name of the HTTP server included in the connection request, the host table 35a is referred to in order to obtain the corresponding relay private IP address (step S102).
[0053] The terminal device 30a sets the destination IP address of the packet to be transmitted to the address of the repeater 20 (step S103). Then, the terminal device 30a transmits the packet (step S104).
[0054] The repeater 20 receives the packet from the terminal device 30a (step S105). Then, the repeater 20 converts the address of the packet (step S106). Specifically, it converts the source IP address of the received packet to the IP address assigned to the repeater 20, and converts the destination IP address to the address of the HTTP server 50 on the external network N. After that, the repeater 20 transmits the packet with the address converted (step S107).
[0055] The HTTP server 50 receives the packet with the address converted transmitted from the repeater 20 (step S108). Then, the HTTP server 50 creates a response packet corresponding to the received packet (step S109). After that, the HTTP server 50 transmits the response packet (step S110).
[0056] The repeater 20 receives the response packet from the HTTP server 50 (step S111). Then, the repeater 20 converts the address of the response packet (step S112). Specifically, it converts the source IP address of the response packet to the private IP address assigned to the repeater 20, and converts the destination IP address to the private IP address assigned to the terminal device 30a.
[0057] After that, the repeater 20 transmits the packet with the address converted (step S113). The terminal device 30a receives the packet transmitted by the repeater 20 (step S114).
[0058] As described above, in the first embodiment, the network system 10 includes a repeater 20, terminal devices 30a, 30b, 30c, and a broadband router 40. When the terminal device 30a connects to an HTTP server on the external network N, the terminal device 30a refers to the host table 35a and transmits a packet with the relay private IP address of the repeater 20 corresponding to the domain name as the destination IP address to the repeater 20. The repeater 20 converts the source IP address and the destination IP address of the packet transmitted to the relay private IP address into predetermined IP addresses and transmits the packet to the HTTP server 50. Further, the repeater 20 converts the source IP address and the destination IP address of the packet received from the HTTP server 50 into predetermined IP addresses in the closed network A and transmits the converted packet, enabling the terminal device 30a in the closed network A without a DNS server to connect to the HTTP server 50 on the external network N.
[0059] <Modification Example 1> In the above-described first embodiment, the case where the repeater 20 is assigned one relay IP address has been described. In the modification example, the case where two relay private IP addresses are assigned will be described.
[0060] FIG. 6 is a diagram showing an overview of a network system 70 according to Modification Example 1. Note that the same reference numerals are assigned to the same parts as in the first embodiment, and detailed descriptions thereof are omitted. As shown in FIG. 6, in the network system 70, the repeater 20 is connected to the closed network A, and a plurality of terminal devices 30a, 30b, 30c are connected to the closed network A.
[0061] Further, the repeater 20 is connected to the broadband router 40 via the closed network B in order to transmit the packet received from the closed network A to the external network N. The broadband router 40 is connected to the external network N, and a DNS server 60, an HTTP server 50, an HTTP server 51, etc. are connected to the external network N.
[0062] In order for other network devices connected to the closed network A to access the repeater 20, the repeater 20 is assigned an IP address: 10.128.10.1 / 24 (IP-A) on the closed network A side, and two private IP addresses for relaying packets from the closed network A to the external network N (IP address: 10.128.10.10 / 24 (IP-B), IP address: 10.128.10.11 / 24 (IP-D)). Also, the repeater 20 is assigned a private IP address of 192.168.38.100 / 24 (IP-C) on the closed network B side.
[0063] The terminal device 30a is connected to the closed network A and is assigned a private IP address of 10.128.10.100 / 24 (IP-W). Also, the terminal device 30a stores in its host table a domain name and a private IP address for relaying associated with the domain name. Here, for the domain name: www.abc123.com, the IP address: 10.128.10.10 / 24 is stored, and for the domain name: www.def345.co.jp, the IP address: 10.128.10.11 / 24 is stored.
[0064] When connecting from the terminal device 30a to the HTTP server 50, the terminal device 30a sends a connection request packet to the private IP address for relaying (IP-B) for relaying packets to the HTTP server 50 on the external network N of the repeater 20. Then, the repeater 20 converts the source IP address and destination IP address of the received connection request packet and sends the packet to the HTTP server 50 via the broadband router 40. Then, the response packet from the HTTP server 50 is sent to the terminal device 30a following the reverse route described above.
[0065] When connecting from the terminal device 30a to the HTTP server 51, the terminal device 30a sends a packet of a connection request to a relay private IP address (IP-D) for relaying the packet to the HTTP server 51 on the external network N of the repeater 20. Then, the repeater 20 converts the source IP address and the destination IP address of the received connection request packet and sends the packet to the HTTP server 51 via the broadband router 40. Then, the response packet from the HTTP server 51 is sent to the terminal device 30a along the reverse route described above.
[0066] In the above-described Modification 1, the case where the repeater 20 assigns two relay private IP addresses to access an HTTP server on the external network N has been described. However, the number of relay private IP addresses may be three or more.
[0067] [Embodiment 2] <Overview of Network System 90> Incidentally, in the above-described Embodiment 1, the case where the host table 35a is stored in the terminal device 30a has been described. In Embodiment 2, the case of monitoring the validity of the host table 35a stored in the terminal device 30a will be described.
[0068] FIG. 7 is a diagram showing an overview of the network system 90 according to Embodiment 2. For parts similar to those in Embodiment 1, the same reference numerals will be given and the detailed description thereof will be omitted. As shown in FIG. 7, in the network system 90 according to the present Embodiment 2, the repeater 20 is connected to the closed network A, and a plurality of terminal devices 30a, 30b, 30c and a monitoring device 80 are connected to the closed network A.
[0069] In addition, the repeater 20 is connected to the broadband router 40 via the closed network B in order to transmit the packets received from the closed network A to the external network N. The broadband router 40 is connected to the external network N, and the DNS server 60, the HTTP server 50, etc. are connected to the external network N.
[0070] The monitoring device 80 stores a master host table 84a that stores legitimate domain names (second connection destination information) such as an HTTP server whose access has been previously permitted and the relay private IP address of the repeater 20 corresponding to the legitimate domain name. Then, it acquires the host table 35a stored in the terminal device 30, compares it with the master host table 84a, and determines whether the data in the host table 35a stored in the terminal device 30 is legitimate. If the monitoring device 80 determines that the determination result is not legitimate, it notifies the terminal device 30 that the host table 35a is illegal.
[0071] <Configuration of the monitoring device 80> Next, the configuration of the monitoring device 80 shown in FIG. 7 will be described. FIG. 8 is a functional block diagram showing the configuration of the monitoring device 80 shown in FIG. 7. As shown in FIG. 8, the monitoring device 80 includes a communication I / F unit 83, a storage unit 84, and a control unit 85, and a display unit 81 and an input unit 82 are connected thereto. The display unit 81 is a display device such as a liquid crystal display for displaying various information. The input unit 82 is an input device such as a mouse or a keyboard. The communication I / F unit 83 is a communication interface unit for communicating with the terminal devices 30a, 30b, and 30c via the closed network A.
[0072] The storage unit 84 is a storage device such as a hard disk device or a non-volatile memory, and stores the master host table 84a. The master host table 84a is correspondence data of the domain name of the HTTP server that is permitted to be connected in advance and the relay private IP address assigned to the repeater 20 for connecting to the domain.
[0073] The control unit 85 is a control unit that controls the entire monitoring device 80, and includes a host table acquisition unit 85a, a determination unit 85b, and a notification unit 85c. Actually, by loading and executing these programs on the CPU, processes corresponding to the host table acquisition unit 85a, the determination unit 85b, and the notification unit 85c will be executed respectively.
[0074] The host table acquisition unit 85a is a processing unit that acquires the host table 35a stored in the terminal device 30 connected to the closed network A.
[0075] The determination unit 85b is a processing unit that compares the domain name (first connection destination information) included in the acquired host table 35a of the terminal device 30 with the legitimate domain name (second connection destination information) included in the master host table 84a, and determines the legitimacy of the host table 35a.
[0076] The notification unit 85c is a processing unit that notifies a warning to the terminal device 30 when the determination result of the determination unit 85b is "not legitimate". When performing notification, it connects to the terminal device 30 to which notification is to be made, and uses a message command or the like to display a warning on a predetermined display unit 31 of the terminal device 30.
[0077] Next, the processing procedure of the monitoring device 80 will be described. FIG. 9 is a flowchart showing the processing procedure of the monitoring device 80 shown in FIG. 8. As shown in FIG. 9, the monitoring device 80 acquires the host table of the terminal device 30 (step S201). Then, the monitoring device 80 compares the master host table with the host table (S202).
[0078] After that, the monitoring device 80 determines the legitimacy of the host table based on the comparison result (step S203). If the determination result is "legitimate" (step S203: Yes), the monitoring device 80 ends a series of processes. On the other hand, if the determination result is "not legitimate" (step S203: No), the monitoring device 80 notifies a warning to the terminal device 30 (step S204).
[0079] As described above, in the second embodiment, the monitoring device 80 is connected to the closed network A, and by determining whether the host table 35a of the terminal device 30 is legitimate compared with the predetermined master host table 84a, it is possible to prevent the operator from modifying the host table 35a of the terminal device 30.
[0080] <Modification Example 2> By the way, in the second embodiment described above, it has been explained that the monitoring device 80 notifies the terminal device 30 of a warning if the host table 35a of the terminal device 30 is not legitimate. In Modification Example 2, a case where a notification is made and a deletion instruction for the host table 35a is given will be explained.
[0081] FIG. 10 is a functional block diagram for explaining the configuration of the monitoring device 100 according to Modification Example 2. As shown in FIG. 10, the monitoring device 100 includes a communication I / F unit 83, a storage unit 84, and a control unit 85, and a display unit 81 and an input unit 82 are connected thereto.
[0082] The control unit 105 is a control unit that controls the entire monitoring device 100, and includes a host table acquisition unit 85a, a determination unit 85b, a notification unit 85c, and a deletion instruction unit 105a. Actually, by loading these programs into the CPU and executing them, processes corresponding to the host table acquisition unit 85a, the determination unit 85b, the notification unit 85c, and the deletion instruction unit 105a will be executed respectively.
[0083] The deletion instruction unit 105a is a processing unit that accesses the terminal device 30 and instructs the deletion of the host table 35a stored in the storage unit 35 of the terminal device 30 when the determination result of the determination unit 85b is determined to be "not legitimate". When issuing a deletion instruction, connect to the terminal device 30 for which the deletion instruction is to be issued, and use a message command or the like to display a deletion instruction message on a predetermined display unit 31 of the terminal device 30.
[0084] In the above-described Embodiment 1 and Embodiment 2, the case where the terminal device 30 receives a domain name, refers to the host table 35a, and sets the destination IP address to the relay private IP address has been described. However, the terminal device 30 may directly receive the relay private IP address of the repeater 20, set it as the destination IP address, and transmit a packet to the repeater 20.
[0085] Also, in the above-described Embodiment 1 and Embodiment 2, the case where there is one repeater 20 has been described. However, two repeaters 20 may be installed, one as an active device and the other as a standby device, and configured to perform life and death monitoring so that the standby device takes over the function when the active device fails.
[0086] Also, in the above-described Embodiment 1 and Embodiment 2, the case where the repeater 20 converts the source IP address and the destination IP address into a predetermined IP address has been described. However, it may be configured to enable multi-access using a predetermined IP address and port number by applying IP masquerade technology.
[0087] In the above-described Embodiment 2, the case where the monitoring device 80 compares the domain name (first connection destination information) included in the host table 35a of the terminal device 30 with the legitimate domain name (second connection destination information) included in the master host table 84a of the monitoring device 80 to perform validity determination has been described. However, the monitoring device 80 may compare the IP address and domain name of the host table 35a of the terminal device 30 with the IP address and legitimate domain name of the master host table 84a of the monitoring device 80 to perform validity determination.
[0088] Each configuration illustrated in the above-described embodiments is functionally schematic, and it is not necessarily physically configured as illustrated. That is, the form of distribution and integration of each device is not limited to that illustrated, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc.
Industrial Applicability
[0089] The network system and packet relay method according to the present invention are suitable for enabling conditional access to an external device from a terminal device connected to a closed network and having restricted access to a device on an external network.
Explanation of Signs
[0090] 10 Network system 20 Repeater 23 Communication I / F unit 24 Storage unit 24a DNS record 24b Relay rule data 25 Control unit 25a DNS data acquisition unit 25b Packet reception unit 25c Address conversion unit 25d Packet transmission unit 30, 30a, 30b, 30c Terminal device 31 Display unit 32 Input unit 34 Communication I / F unit 35 Storage unit 35a Host table 36 Control unit 36a Reference unit 36b Packet transmission unit 36c Packet reception unit 36d Display control unit 36d 40 Broadband router 50, 51 HTTP server 60 DNS server 70 Network system 80 Monitoring device 81 Display unit 82 Input unit 83 Communication I / F unit 84 Storage unit 84a Master host table 85 Control unit 85a Host table acquisition unit 85b Determination unit 85c Notification unit 90 Network system 100 Monitoring device 105 Control unit 105a Deletion instruction unit A, B Closed network N External network
Claims
1. A network system having a terminal device connected to a closed network with restricted access to an external network, a broadband router enabling access to a predetermined HTTP server via the external network, a repeater interposed between the broadband router and the closed network, and a monitoring device for monitoring the terminal device, wherein the terminal device registers the IP address of the repeater and the first connection destination information of the HTTP server in a predetermined host table, the repeater if it receives a packet addressed to itself from the terminal device, relays the packet toward the HTTP server of the first connection destination information included in the packet, the monitoring device an acquisition unit that acquires the host table from the terminal device, a storage unit that stores the second connection destination information of a legitimate HTTP server accessible from the terminal device, a determination unit that determines whether the first connection destination information is legitimate based on the first connection destination information acquired by the acquisition unit and the second connection destination information stored in the storage unit, and a notification unit that performs a predetermined notification when the first connection destination information is not legitimate characterized in that it is provided with.
2. The first connection destination information and the second connection destination information are IP addresses, the repeater if it receives the packet addressed to itself from the terminal device, relays the packet toward the HTTP server of the IP address included in the packet The network system according to claim 1, characterized in that.
3. The first connection destination information and the second connection destination information are domain names, the repeater a storage unit that stores DNS records acquired from a predetermined domain name server, if it receives the packet addressed to itself from the terminal device, a conversion unit that converts the destination IP address part of the packet to the IP address of the HTTP server based on the DNS records stored in the storage unit, and a transmission unit that transmits the packet to the HTTP server of the IP address converted by the conversion unit The network system according to claim 1, characterized in that it is provided with.
4. The monitoring device The network system according to claim 1, further comprising a deletion instruction unit that, when the first connection destination information is not valid, gives an instruction to delete the first connection destination information to the terminal device.
5. A network system including a terminal device connected to a closed network and having restricted access to an external network, a broadband router enabling access to a predetermined HTTP server via the external network, a repeater interposed between the broadband router and the closed network and assigned a plurality of IP addresses, and a monitoring device for monitoring the terminal device, wherein the terminal device associates the plurality of IP addresses assigned to the repeater with first connection destination information of the HTTP server corresponding to each IP address, and registers the association in a predetermined host table, wherein the repeater when receiving a packet addressed to any one of the plurality of IP addresses assigned to the repeater from the terminal device, relays the packet to the HTTP server for the first connection destination information included in the packet, wherein the monitoring device has an acquisition unit that acquires the host table from the terminal device, a storage unit that stores second connection destination information of a plurality of legitimate HTTP servers accessible from the terminal device, a determination unit that determines whether or not the plurality of first connection destination information is legitimate based on the plurality of first connection destination information included in the host table acquired by the acquisition unit and the second connection destination information of the plurality of legitimate HTTP servers stored in the storage unit, and a notification unit that performs a predetermined notification when the plurality of first connection destination information is not legitimate characterized in that it is provided.
6. A packet relay method in a network system including a terminal device connected to a closed network and having restricted access to an external network, a broadband router enabling access to a predetermined HTTP server via the external network, a repeater interposed between the broadband router and the closed network, and a monitoring device for monitoring the terminal device, wherein the terminal device registers the IP address of the repeater and the first connection destination information of the HTTP server in a predetermined host table in a registration step, If the relay device receives a packet addressed to itself from the terminal device, a relay step of relaying the packet toward the HTTP server of the first connection destination information included in the packet An acquisition step in which the monitoring device acquires the host table from the terminal device A storage step in which the monitoring device stores the second connection destination information of a legitimate HTTP server accessible from the terminal device in a predetermined storage unit A determination step in which the monitoring device determines whether or not the first connection destination information is legitimate based on the first connection destination information acquired in the acquisition step and the second connection destination information stored in the storage unit A notification step of performing a predetermined notification when the first connection destination information is not legitimate A packet relay method characterized by including
Citation Information
Patent Citations
Radiation exposure dose management system in regional medical information cooperation center
JP2010079712A