Relay device

The relay device automates activation processing based on connection and registration criteria, ensuring timely software updates and proper license management, addressing issues of delayed activation and outdated software operation.

JP2025103346APending Publication Date: 2025-07-09SAXA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023220689
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-07-09

AI Technical Summary

Technical Problem

Existing relay devices, such as UTM and GW devices, face issues with activation processing timing, leading to shortened license periods if not executed promptly after installation, and potential operation with outdated software due to user forgetfulness or lack of knowledge about necessary activation operations.

Method used

A relay device that includes connection terminal counting, activation request means, and determination mechanisms to automatically initiate activation processing when a predetermined condition is met, such as multiple connected terminal devices, prolonged session duration, and registration confirmation, ensuring timely software updates and license management.

Benefits of technology

Ensures activation processing occurs at appropriate times post-installation, maintaining device functionality with the latest software and accurate license period management, preventing premature expiration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025103346000001_ABST
    Figure 2025103346000001_ABST
Patent Text Reader

Abstract

To enable execution of activation processing at an appropriate timing without performing activation operation by a user, after a relay device is installed in user environment.SOLUTION: A UTM device 1 relays between a WAN 4 and a LAN 2. A connection terminal counting part 131 counts the number of terminal devices starting communication through the WAN 4, in terminal devices connected to own machine through the LAN 2. A control part 102 determines whether or not the number of terminal devices counted by the connection terminal counting part 132 is equal to or greater than N (integer equal to or greater than 2). When it is determined by the control part 102 that it is equal to or greater than N, an activation request part requests a permission to make the terminal devices operable by using a latest software, to a license server connected to the WAN 4.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a relay device that relays between different networks, such as a UTM (Unified Threat Management) device or a GW (Gateway) device. [Background technology]

[0002] UTM devices (Unified Threat Management Devices), which integrate multiple different security functions into a single piece of hardware and perform centralized security management for networks, etc., are becoming more widely used by companies and other organizations. UTM devices are installed between a Wide Area Network (WAN), which is mainly the Internet, and a Local Area Network (LAN), and are equivalent to so-called relay devices that monitor, control, and manage communications between the WAN and LAN. GW devices also have the function of relaying networks with different protocols, and are equivalent to so-called relay devices. Such relay devices require activation processing before they can be used.

[0003] Activation processing means that a user who has installed a relay device performs an activation operation to carry out a specified process, release functional restrictions, and make all functions available. More specifically, by performing an activation operation on a relay device, the relay device requests authentication from a license server operated by the manufacturer. If authentication is obtained through the license server, the relay device is provided with the latest software (signature file, definition file) that is updated periodically or as needed, and is enabled to operate using this software. Note that the activation operation is often a simple operation such as a long press of a specified button switch provided on the relay device. The expiration date of the relay device is determined based on the date of the activation operation, and is managed by the license server.

[0004] Patent Document 1 described later discloses an invention related to a connection method by activation processing of IoT device equipment. Patent Document 1 describes that at the timing of turning on the power of the IoT gateway device, the activation processing server uses the activation hyperlink issued by the IoT system administrator or the like to perform processing for activating the IoT gateway device. The invention disclosed in Patent Document 1 can relatively easily perform the setting (activation) of the IoT gateway device and can prevent unauthorized access in advance.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] In the case of the invention disclosed in Patent Document 1 described above, the timing of turning on the power of the IoT gateway device is used as an opportunity to perform the activation processing. However, before installing the relay device that requires activation processing in the user environment, for example, in many cases, the person in charge at the sales store of the relay device turns on the power of the relay device for the purpose of data setting and uses it temporarily. In such a case, if the activation processing is executed at the timing when the person in charge at the sales store turns on the power of the relay device, the license period is determined based on this point. Therefore, if the installation of the relay device in the user environment is delayed, there will be a problem that the user's license period is shortened.

[0007] Therefore, a mechanism that executes activation processing cannot be adopted when the power is turned on or network communication is executed, and it is necessary to execute activation processing after the relay device is installed in the user environment. However, there are cases where the user of the relay device forgets to perform the activation processing operation, or does not even know that the activation processing operation is necessary. Thus, if the user starts operating the relay device without performing the activation operation, the relay device will not operate with the latest software, and the relay device will be used in a state where functions and security are insufficient. Also, the manufacturer side will not be able to grasp the usage status of the user, that is, when the operation starts and when the license expiration date is.

[0008] In view of the above, an object of the present invention is to enable activation processing to be executed at an appropriate timing even if a user or the like does not perform an activation operation after the relay device is installed in the user environment.

Means for Solving the Problem

[0009] To solve the above problems, the relay device of the invention according to claim 1 is a relay device that relays between a wide area network and a LAN (Local Area Network), connection terminal counting means for counting the number of terminal devices connected to itself through the LAN that have started communication through the wide area network; connection terminal number determination means for determining whether the number of terminal devices counted by the connection terminal counting means is N (an integer of 2 or more) or more; activation request means for requesting permission to be operable using the latest software from a license server connected to the wide area network when the connection terminal number determination means determines that the number is N or more characterized by comprising.

[0010] According to the relay device of the invention described in claim 1, the relay device relays between a wide area network and a LAN (Local Area Network). The connection terminal counting means counts the number of terminal devices that have started communication through the wide area network among the terminal devices connected to itself through the LAN. The connection terminal number determination means determines whether the number of the terminal devices counted by the connection terminal counting means is N (an integer of 2 or more) or more. The activation request means requests permission from the license server connected to the wide area network to be operable using the latest software when it is determined by the connection terminal number determination means that the number is N or more.

Effect of the Invention

[0011] According to this invention, after the relay device is installed in the user environment, the activation process can be executed at an appropriate timing without the user or the like performing an activation operation. Thereby, the user of the relay device can operate the relay device using the latest software without performing a so-called activation operation. Further, when there is a license period, on the provider side of the relay device, the license period can be appropriately managed based on the time point when the activation process is executed.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Embodiments for Carrying Out the Invention

[0013] Hereinafter, with reference to the drawings, an embodiment of the relay device according to the present invention will be described. In the embodiments described below, the wide area network means WAN (Wide Area Network). WAN means a network that covers a wider range compared to LAN and MAN (Metropolitan Area Network), and broadly corresponds to the Internet. Therefore, in the following description, the wide area network is described as WAN. Also, in the embodiments described below, LAN is formed within a company, for example. Therefore, in the following description, the relay device is a GW device or a UTM device that relays between WAN and LAN. In the following description, for the sake of clarity, the case where the relay device is a UTM device will be described as an example.

[0014] [Description of Network System] FIG. 1 is a diagram for explaining a configuration example of the network system according to the embodiment. As shown in FIG. 1, the UTM device 1 is connected to WAN4 and LAN2 and functions as a relay device that relays between WAN4 and LAN2. In this embodiment, LAN2 is a network formed within a company as described above, and through LAN2, a plurality of PCs (Personal Computers) 3(1), 3(2), 3(3),..., 3(n) used by employees are connected to the UTM device 1.

[0015] On the other hand, as shown in Fig. 1, a customer management server 5, a license server 6, a remote maintenance server 7, an update server 8, and a dealer PC 9 are connected to the WAN 4. The customer management server 5, the license server 6, the remote maintenance server 7, and the update server 8 are each a server group (cloud system) operated by the manufacturer that produced the UTM device 1. The server group performs license authentication for the UTM device 1 and properly manages the license period. Furthermore, the server group manages whether the UTM device 1 is operating normally at all times during the license period, and also realizes the function of providing the UTM device 1 with the latest software (including signature files and definition files).

[0016] In this embodiment, the software (including signature files and definition files) used by the UTM device 1 is intended to identify known unauthorized communications and attack patterns, and to prevent unauthorized communications and attacks. For this reason, the software (including signature files and definition files) used by the UTM device 1 may be collectively referred to as a signature. Although a signature originally meant a "signature" or "the directions and precautions written on a medicine container," in the IT (information technology) field it may also mean a set of rules for identifying known unauthorized communications and attack patterns.

[0017] In this specification, the process of making the UTM device 1 ready to receive the latest software and the like from license authentication is referred to as activation processing. In other words, the activation processing is the process of removing functional restrictions on the UTM device 1, making all functions available, and enabling the UTM device 1 to function properly and effectively.

[0018] In addition, in order to execute this activation process, the person in charge at the store that sells the UTM device 1 needs to register customer management information with the customer management server 5 and set detailed information in the UTM device 1 before installing the UTM device 1 in the user environment. In this case, the store PC 9 is used to register the customer management information. Note that the customer management information includes, for example, the manufacturing number of the UTM device 1, the MAC (Media Access Control) address, the customer name, the customer identification number, and the registration date.

[0019] The UTM device 1 can execute the activation process in response to a user's activation operation, but it is also configured to be able to automatically execute the activation process by satisfying a predetermined condition. First, the operation in the normal case where the activation process is executed in response to a user's activation operation will be described.

[0020] [Execution operation of activation process according to user operation (normal operation)] FIG. 2 is a block diagram for explaining the operation when performing an activation process in response to a user operation in the network system of the embodiment. As shown on the left end side of FIG. 2, before the UTM device 1 is installed in the user environment, the person in charge at the store that sells the UTM device 1 uses the store PC 9 to perform a process of registering customer management information with the customer management server 5 (step S1). Here, "install the UTM device 1 in the user environment" means that the UTM device 1 can be installed and used at a predetermined location in the company where it is introduced. The person in charge at the store connects the UTM device 1 before installation in the user environment to the WAN 4 at a predetermined work location, connects the store PC 9 to the UTM device 1, and turns on the power to the UTM device 1 and the store PC 9.

[0021] The person in charge at the store can access a predetermined web page using the store PC9 and input the necessary information to register the customer management information in the customer management server 5. Also, the person in charge at the store issues instructions via the web page through the store PC9, downloads the necessary information, and performs the process of setting it in the UTM device 1. As a result, the person in charge at the store does not need to go to the installation location themselves. If the installation operator transports the UTM device 1 to the user's company and installs it, and makes connections to the WAN 4 and the LAN 2, the usage environment can be prepared.

[0022] After the UTM device 1 is installed in the user environment in this way, the user turns on the power to the UTM device 1. In this case, the UTM device 1 automatically accesses the remote maintenance server 7 and automatically connects a session (step S2). As a result, the remote maintenance server 7 can monitor the operating state of the UTM device 1 and manage whether it is operating normally and what state it is in. If a malfunction of the UTM device 1 is detected in the remote maintenance server 7, it becomes possible to perform recovery by remote operation or send a manufacturer's technician to the company where the UTM device 1 is installed to handle it.

[0023] Next, the user manually performs an activation operation on the UTM device 1 (step S3). Specifically, an operation such as long-pressing a predetermined button switch provided on the UTM device 1 for, for example, 3 seconds or more will be performed. Note that the long-pressing of the button switch is an example of an operation. Therefore, in the UTM device 1, it is possible to adopt various activation operations such as pressing two button switches simultaneously or tilting and then returning a lever switch.

[0024] When the UTM device 1 receives an activation operation by the user, it forms an activation request and transmits this to the license server 6 (step S4). The activation request includes, for example, identification information of the UTM device 1 such as the MAC address and the manufacturing number of the UTM device 1. Assuming that the license server 6 has received the activation request. In this case, the license server 6 uses the identification information of the UTM device 1 such as the MAC address included in the activation request to confirm with the customer management server 5 whether the UTM device 1 is a legitimate one with proper registration of customer management information (step S5).

[0025] Based on the identification information of the UTM device 1 from the license server 6, the customer management server 5 refers to the customer management information it holds and transmits a result return (confirmation result) to the license server 6 (step S6). The result return is information indicating authentication permission when the customer management information has been properly registered with the customer management server 5 and there is customer management information corresponding to the identification information of the UTM device 1. Also, the result return is information indicating non - authentication when the customer management information has not been properly registered with the customer management server 5 and there is no customer management information corresponding to the identification information of the UTM device 1.

[0026] The license server 6 performs a process of forming a result return according to the result return from the customer management server 5 and providing this to the UTM device 1 (step S7). Specifically, when the result return from the customer management server 5 is information indicating non - authentication, in step S7, a result return indicating non - authentication is transmitted to the UTM device 1. Also, when the result return from the customer management server 5 is information indicating authentication permission, in step S7, information indicating authentication permission and authentication information (information unique to the UTM device 1 indicating that authentication has been permitted) are provided to the UTM device 1. When the UTM device 1 obtains the authentication information, it holds this in itself. Thereby, the UTM device 1 becomes in a state where authentication is obtained and it can receive the provision of the latest software.

[0027] The UTM device 1 periodically forms a signature update check and transmits this to the update server 8 (step S8). The signature update check is for verifying whether there is the latest information necessary for the normal operation of the UTM device 1, such as updated software and definition files, and when authentication information has been obtained in step S7, it includes this. The update server 8 applies the latest signature update or rejects the application of the update (step S9).

[0028] That is, when the signature update check from the UTM device 1 does not include appropriate authentication information, the UTM device 1 is a device for which authentication has not been obtained. For this reason, in step S8, the update server 8 forms information for notifying of the update rejection and provides this to the UTM device 1. On the other hand, when the signature update check from the UTM device 1 includes appropriate authentication information, the UTM device 1 is a device for which authentication has been obtained. Therefore, in step S8, the update server 8 provides the latest software it holds to the UTM device 1.

[0029] Here, it has been described that when the signature update check from the UTM device 1 does not include appropriate authentication information, the update server 8 forms information for notifying of the update rejection and provides this to the UTM device 1, but it is not limited to this. When the signature update check is transmitted from the UTM device 1, the update server 8 provides the latest software to the UTM device 1, and on the UTM device 1 side, when authentication information has not been obtained from the license server 6, the latest software may be discarded and the update may be rejected. That is, depending on whether activation processing has been performed and the UTM device 1 has acquired appropriate authentication information, it is possible for the UTM device 1 or the update server 8 to determine whether to permit the update of the latest software or reject the update.

[0030] Thus, in the UTM device 1, when the activation process is properly executed and authentication information is obtained, the latest software that is updated periodically and as needed can be downloaded from the update server 8 and used. As a result, the UTM device 1 can always function properly. However, in FIG. 2, as shown in step S3, when the manual activation operation is not performed, the activation process is not executed. In this case, the oldest software is used and operates indefinitely, and proper operation cannot be guaranteed. Therefore, in the UTM device 1 of this embodiment, the activation process can be automatically executed at an appropriate timing.

[0031] [Configuration Example of UTM Device 1] FIG. 3 is a block diagram for explaining a configuration example of the UTM device 1 according to the embodiment. The connection terminal 101T constitutes a connection end with the WAN 4. The communication I / F (Interface) 101 is a part that performs communication processing through the WAN 4. That is, the communication I / F 101 converts a signal addressed to itself transmitted via the WAN 4 into a signal in a form that can be processed by the device itself and captures it. In addition, the communication I / F 101 converts a signal transmitted from the device itself into a signal in a transmission format and sends it to the WAN 4 for transmission to the counterpart. Therefore, when communicating with a counterpart connected to the WAN 4, it is performed through the connection terminal 101T and the communication I / F 101.

[0032] The control unit 102 is a microprocessor configured with a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), non-volatile memory, etc., although not shown in the figure, and controls each part of the UTM device 1. In, for example, the non-volatile memory of the control unit 102, the MAC address, manufacturing number, etc. of the UTM device 1 are stored and held. In addition, as described above, when the activation process is executed and authentication information is provided from the license server 6, this is stored and held. The storage device 103 is a device unit composed of a recording medium and its driver, such as an HDD (Hard Disk Drive) or SSD (Solid State Drive), and performs recording, reading, changing, deleting, etc. of various data to / from the recording medium. The storage device 103 stores and holds necessary data and programs, and is also used as a work area for temporarily storing intermediate data generated in various processes.

[0033] The operation unit 104 is a part configured with several button switches, etc., receives an operation input from the user, forms an electrical signal corresponding to the operation input, and notifies the control unit 102. Thereby, the control unit 102 controls each part according to the operation input from the user received through the operation unit 104, and the user can execute the processing they desire on the UTM device 1. Note that the user can start the activation process under the control of the control unit 102 by, for example, long-pressing a predetermined button switch provided on the operation unit 104.

[0034] The address DB (Data Base) 105 stores and retains the MAC addresses and IP addresses of the PCs 3(1), 3(2), 3(3), …, 3(n) under the UTM device 1 connected to the UTM device 1 through the LAN2. Similar to the storage device 103 described above, the address DB 105 is formed in a device unit consisting of a recording medium such as an HDD or an SSD and its driver. Note that if there is a free space in the storage device 103, the address DB 105 can also be formed in the free space of the storage device 103. The clock circuit 106 provides the current year, month, day, current day of the week, and current time.

[0035] The connection terminal 107T constitutes the connection end with the LAN2. The LAN I / F (Interface) 107 is a part that performs communication processing through the LAN2. That is, the LAN I / F 107 converts a signal addressed to itself transmitted through the LAN2 into a signal in a form that can be processed by the local device and captures it. Also, the LAN I / F 107 converts a signal transmitted from the local device into a signal in a transmission format and sends it to the LAN2 for transmission to the other party. Therefore, when communicating with the PCs 3(1), 3(2), 3(3), …, 3(n) connected to the LAN2, it is performed through the connection terminal 107T and the LAN I / F 107.

[0036] Although not shown, the security function unit 110 is configured to include, for example, a P2P countermeasure unit, an HP access control unit, a virus countermeasure unit, a mail countermeasure unit, an IPS / IDS unit, and a firewall unit. That is, the security function unit 110 realizes a function of prohibiting P2P connections with parties that have not taken security measures or malicious parties (as a function of the P2P countermeasure unit). Note that "P2P" means "Peer to Peer", which means that peers communicate directly with each other via the Internet.

[0037] In addition, the security function unit 110 realizes a function of prohibiting access to a homepage corresponding to a category by, for example, selecting a target homepage category in advance (function as an HP access control unit). Further, the security function unit 110 performs verification (virus check) of the response of a web page (function as a virus countermeasure unit). More specifically, it realizes a function of monitoring communication when browsing a web page and verifying (checking) whether a virus is mixed in an image to be browsed or a file to be downloaded. Further, the security function unit 110 realizes a function of blocking an e-mail with unnecessary advertisements or viruses attached thereto with respect to the received e-mail (function as a mail countermeasure unit).

[0038] In addition, the security function unit 110 realizes a function of preventing inappropriate intrusion or notifying of inappropriate intrusion (function as an IPS / IDS unit). Here, IPS is an abbreviation for Intrusion Prevention System, and IDS is an abbreviation for Intrusion Detection System. Note that the security function unit 110 can defend against attacks by so-called malware such as worms and Trojan horses. Further, the security function unit 110 determines whether to supply data to LAN2 based on the data communication situation, the software to be used, etc., and realizes a function of defending the own system from attacks and unauthorized access from an external network (function as a firewall unit).

[0039] The proper operation unit 120 is a functional unit for ensuring the proper functioning of the UTM device 1, and includes a maintenance server connection unit 121, an activation request unit 122, and a signature update unit 123. The maintenance server connection unit 121 realizes the function of accessing the remote maintenance server 7 and connecting a session under the control of the control unit 102. Thereby, the remote maintenance server 7 can monitor the operating state of the UTM device 1. In this case, the maintenance server connection unit 121 accesses the remote maintenance server 7 and connects a session using necessary information such as a URL (uniform resource locator) registered in the non-volatile memory of the control unit 102.

[0040] The activation request unit 122 realizes the function of forming an activation request and transmitting this to the license server 6 to execute an activation process under the control of the control unit 102. Also in this case, the activation request unit 122 accesses the license server 6 and transmits an activation request using necessary information such as a URL (uniform resource locator) registered in the non-volatile memory of the control unit 102. As a result of the activation request being made in this way, when receiving the provision of information indicating authentication permission and authentication information from the license server 6, the control unit 102 performs a process of registering at least the authentication information in the non-volatile memory of the control unit 102.

[0041] The signature update unit 123 measures a predetermined period based on the information from the clock circuit 106 under the control of the control unit 102, forms a signature update check at each predetermined timing, and realizes the function of transmitting this to the update server 8. The predetermined timing is, for example, appropriate timings such as once a day, once every two days, once every three days, once a week, etc. Since the signature file is updated frequently, for example, there may be cases where the signature update check is performed at a frequency of once an hour. Therefore, the signature update check of the signature file is performed at a frequency of once an hour, and the signature update check of the software is performed at a frequency of once a day. Depending on the update target, the execution timing of the signature update check may be different, such as this example.

[0042] Such timing of the signature update check is predetermined in advance by the manufacturer side of the UTM device 1. Even in this case, the signature update unit 123 accesses the update server 8 using the necessary information such as the URL registered in the non-volatile memory of the control unit 102, and transmits the signature update check. Also, when the signature update unit 123 collaborates with the control unit 102 and receives the provision of the latest software (including the signature file and the definition file) from the update server 8, it records this in a predetermined area of the storage device 103 so that it can operate using this.

[0043] The automatic activation unit 130 realizes the function of automatically executing the activation process at an appropriate timing even if the user of the UTM device 1 does not perform an activation operation. The automatic activation unit 130 includes a connection terminal count unit 131, a maintenance server connection measurement unit 132, a customer registration confirmation unit 133, and an update rejection count unit 134. The connection terminal count unit 131 counts the number of terminal devices that receive a connection request to the WAN 4 through the connection terminal 107T and the LAN I / F 107 and connect to the WAN 4 to perform communication through the WAN 4, and notifies the control unit 102 of the count result.

[0044] In this case, since the communication process may be completed immediately, the MAC address and IP address included in the connection request are checked. If there is a connection request from a different terminal device registered in the address DB105, the connection count is incremented by "1". That is, the connection terminal count unit 131 also considers the registration information in the address DB105. When a connection request arrives from a terminal device that is a subordinate terminal device of the own device and is other than the terminal device that has already sent a connection request, the connection count is incremented by "1", and the connection count after counting is notified to the control unit 102.

[0045] As described above, at the preparation stage in the store, only one store PC9 is connected to the WAN4 through the UTM device 1, and a plurality of terminal devices are not connected to the WAN4 through the UTM device 1. That is, since it can be determined that the UTM device 1 is installed in the user environment when there are a plurality of terminal devices connected to the WAN4 through the UTM device 1, it can be determined that it is necessary to execute the activation process. However, even if a plurality of terminal devices are simultaneously connected to the WAN4 through the UTM device 1 for communication, it is not known whether the UTM device 1 is surely installed in the user environment and the activation process can be executed. Therefore, the maintenance server connection measurement unit 132, the customer registration confirmation unit 133, and the update rejection count unit 134 function.

[0046] As described above, a session is connected between the UTM device 1 and the remote maintenance server 7 by the maintenance server connection unit 121 of the proper operation unit 120. The maintenance server connection measurement unit 132 measures the duration after a session is connected between the UTM device 1 and the remote maintenance server 7, using the current time from the clock circuit 106, and notifies this to the control unit 102. If the connection duration of the session with the remote maintenance server 7 is equal to or longer than a predetermined time, for example, 24 hours or longer, it is because the UTM device 1 can be determined to be in a state where it is installed in a user environment and operation has started. The control unit 102 can start the activation process when the connection duration of the session with the remote maintenance server 7 is equal to or longer than a predetermined time and, at the same time, there are a plurality of terminal devices connected to the WAN 4 through the UTM device 1. In this case, the control unit 102 controls the activation request unit 122 to send out an activation request.

[0047] The customer registration confirmation unit 133 accesses the customer management server 5, and if customer management information having the same information as the MAC address and manufacturing number of its own device is already registered, it acquires the registration unit and notifies the control unit 102. Thereby, the control unit 102 can refer to the current date and time from the clock circuit 106 and calculate the number of days elapsed from the registration date. If the customer management information of the UTM device 1 is not registered in the customer management server 5, the activation process cannot be executed to acquire the authentication information. It usually takes several days, at least two or three days, to properly register the customer management information and perform the setting process for the UTM device 1 until the UTM device 1 is actually installed in the user environment. Therefore, if the number of days elapsed from the registration date of the customer management information is not more than a certain number of days, the possibility that the UTM device 1 is installed in the user environment is high. For this reason, the control unit 102 can start the activation process when a predetermined number of days have elapsed since the customer management information of its own device was registered in the customer management server 5 and, at the same time, there are a plurality of terminal devices connected to the WAN 4 through the UTM device 1. In this case, the control unit 102 controls the activation request unit 122 to send out an activation request.

[0048] Since the activation process has not been performed and authentication information has not been granted, the update rejection count unit 134 counts the number of times the update is rejected even when checking for signature updates with the update server 8, and notifies the control unit 102 of this. That is, the update rejection count unit 134 realizes the function of counting the number of update rejections due to the non-execution of the activation process and notifying the control unit 102 of the count result. When the number of update rejections counted in this way is equal to or more than a predetermined number of times, the fact that the activation process has not been performed can be surely grasped. Therefore, when the number of update rejections by the update server 8 is equal to or more than a predetermined number of times and at the same time there are a plurality of terminal devices connected to the WAN 4 through the UTM device 1, the control unit 102 can start the activation process. In this case, the control unit 102 controls the activation request unit 122 to send an activation request.

[0049] Note that, as a requirement 1, the connection duration of the session with the remote maintenance server 7 measured by the maintenance server connection measurement unit is equal to or more than a predetermined time. Also, as a requirement 2, the number of days from the registration date of the customer management information having the same information as the MAC address and the manufacturing number of the own device confirmed by the customer registration confirmation unit 133 is equal to or more than a predetermined number of days. Also, as a requirement 3, the number of update rejections due to the non-execution of the activation process counted by the update rejection count unit 134 is equal to or more than a predetermined number of times. When any one or more of these requirements 1, 2, and 3 are satisfied and at the same time there are a plurality of terminal devices connected to the WAN 4 through the UTM device 1, the activation process can also be started.

[0050] That is, when any one of Requirement 1, Requirement 2, and Requirement 3 is satisfied, and furthermore, when there are multiple terminal devices simultaneously connected to WAN4 through UTM device 1, the activation process can be started. Also, when any two of Requirement 1, Requirement 2, and Requirement 3 are satisfied, and furthermore, when there are multiple terminal devices simultaneously connected to WAN4 through UTM device 1, the activation process can be started. Also, when all of Requirement 1, Requirement 2, and Requirement 3 are satisfied, and furthermore, when there are multiple terminal devices simultaneously connected to WAN4 through UTM device 1, the activation process can also be started.

[0051] [Basic Process for Automatically Executing Activation Process in UTM Device 1] FIG. 4 is a sequence diagram for explaining the process (basic process) for starting the activation process when there are multiple terminal devices connected to WAN4 through UTM device 1, which is performed in UTM device 1 of the embodiment. In FIG. 4, LAN control, activation management, and WAN control shown on the upper end side indicate the functional parts of UTM device 1. Specifically, LAN control is the part where LAN I / F 107, control unit 102, and connection terminal count unit 131 cooperate. Also, activation management is the part where control unit 102 and activation request unit 122 cooperate. Also, WAN control is the part where communication I / F 101 and control unit 102 cooperate.

[0052] When the terminal device under the UTM device 1 is not connected to the WAN 4 through the UTM device 1, as shown on the left end side of FIG. 4, assume that a connection request from the PC 3(2) connected to the UTM device 1 through the LAN 2 to the WAN 4 occurs. The said connection request is received through the connection terminal 107T and the LANI / F 107 (step S11), and under the control of the control unit 102, it is sent to the WAN 4 through the communication I / F 101 and the connection terminal 101T (step S12). Thereby, the PC 3(2) can perform processes through the WAN 4, such as accessing a site or sending an e-mail (step S13). In this case, under the control of the control unit 102, the connection terminal count unit 131 functions to count up the number of connected terminal devices to the WAN 4 by "1", notify the control unit 102 that the number of connected units is "1 unit", and the control unit 102 holds this (step S14).

[0053] After this, assume that a connection request from the PC 3(1) connected to the UTM device 1 through the LAN 2 to the WAN 4 occurs. The said connection request is received through the connection terminal 107T and the LANI / F 107 (step S15), and under the control of the control unit 102, it is sent to the WAN 4 through the communication I / F 101 and the connection terminal 101T (step S16). Thereby, the PC 3(1) can perform processes through the WAN 4, such as accessing a site or sending an e-mail (step S17). In this case, the connection terminal count unit 131 functions to count up the number of connected terminal devices to the WAN 4 by 1, notify the control unit 102 that the number of connected units has become "2 units", and the control unit 102 holds this (step S18).

[0054] When there are two or more terminal devices communicating through the WAN 4, the control unit 102 checks whether authentication information is stored in its non-volatile memory (step S19). That is, the activation state check in step S19 is to confirm whether the authentication information is stored in the non-volatile memory and whether the activation process has been performed. As a result of the activation state check in step S19, assume that the control unit 102 confirms that the authentication information is not recorded and the activation has not been executed (step S20).

[0055] In this case, the control unit 102 controls the activation request unit 122 to perform a process of forming and transmitting an activation request (step S21). The activation request is sent to the WAN 4 through the communication I / F 101 and the connection terminal 101T and transmitted to the license server 6 (step S22). In the license server 6, as described with reference to FIG. 2, it communicates with the customer management server 5 to confirm whether the UTM device 1 is a regular one with appropriate registration of customer management information. As a result of this confirmation, if it can be confirmed that it is a regular one, the license server 6 transmits information indicating authentication permission and authentication information as an activation result (result return) (step S23).

[0056] The activation result transmitted through the WAN 4 is received through the connection terminal 101T and the communication I / F 101 of the UTM device 1 (step S24), and this is recorded in the non-volatile memory of the control unit 102 by the control unit 102 (step S25). Thereby, the activation process between the UTM device 1 and the license server 6 is completed. After this, the UTM device 1 periodically performs a signature update check against the update server 8, and if there is the latest software, it can be downloaded and used. That is, the function limitation of the UTM device 1 is released, and it can use all functions.

[0057] [Summary of the Automatic Activation Process Performed by the UTM Device in the Embodiment] As described with reference to FIG. 4, the UTM device 1 of this embodiment can basically start the activation process when there are multiple terminal devices connected to the WAN 4 through the UTM device 1 at the same time. However, by starting the activation process when a predetermined requirement (prerequisite) is satisfied and there are multiple terminal devices connected to the WAN 4 through the UTM device 1 at the same time, the activation process can be started more appropriately.

[0058] Specifically, as described above, three requirements (three prerequisites) can be defined. That is, Requirement 1 is that the connection duration of the session with the remote maintenance server 7 measured by the maintenance server connection measurement unit is equal to or longer than a predetermined time. Also, Requirement 2 is that the number of days from the registration date of the customer management information having the same information as the MAC address and manufacturing number of the own device confirmed by the customer registration confirmation unit 133 is equal to or longer than a predetermined number of days. Further, Requirement 3 is that the number of update rejections due to the non-execution of the activation process by the update rejection count unit 134 is equal to or more than a predetermined number of times.

[0059] Then, when all of Requirement 1, Requirement 2, and Requirement 3 are satisfied and there are multiple terminal devices connected to the WAN 4 through the UTM device 1, the process when starting the activation process will be specifically described. FIG. 5 is a flowchart for explaining the automatic activation process performed by the UTM device of the embodiment. The process of the flowchart shown in FIG. 5 is executed by the control unit 102 when it is confirmed that the power of the UTM device 1 is turned on, the authentication information is not stored in the non-volatile memory of the control unit 102, and the activation process has not been executed.

[0060] First, the control unit 102 refers to the latest connection duration CT with the remote maintenance server 7 measured by the maintenance server connection measurement unit 132 (step S101). Next, the control unit 102 determines whether the connection duration CT is equal to or greater than a predetermined time T1 (step S102). The predetermined time T1 is determined in advance, for example, 24 hours, 12 hours, 8 hours, etc. In the determination means of step S102, if it is determined that the connection duration CT is not equal to or greater than the predetermined time T1, the control unit 102 repeats the process from step S101.

[0061] In the determination means of step S102, assume that it is determined that the connection duration CT is equal to or greater than the predetermined time T1. The control unit 102 controls the customer registration confirmation unit 133, accesses the customer management server 5, obtains the registration date of the customer management information having information corresponding to the MAC address and manufacturing number of its own device, and calculates the number of days DT from the customer registration date to the current time (step S103).

[0062] Next, the control unit 102 determines whether the number of days DT from the registration date of the customer management information calculated in step S103 to the present is equal to or greater than a predetermined number of days D1 (step S104). The predetermined number of days D1 is determined in advance, for example, 2 days, 3 days, 4 days, etc. In the determination process of step S104, if it is determined that the number of days DT from the registration date of the customer management information to the present is not equal to or greater than the predetermined number of days D1, the control unit 102 repeats the process from step S101.

[0063] In the determination process of step S104, assume that it is determined that the number of days DT from the registration date of the customer management information to the present is equal to or greater than a predetermined number of days D1. In this case, the control unit 102 refers to the latest update rejection count UR due to the non-execution of the activation process counted by the update rejection count unit 134 (step S105). Next, the control unit 102 determines whether the update rejection count UR is equal to or greater than a predetermined number of times U1 (step S106). The predetermined number of times U1 is determined in advance, for example, 3 times, 4 times, 5 times, etc. In the determination process of step S106, if it is determined that the update rejection count UR is less than the predetermined number of times U1, the control unit 102 repeats the process from step S101.

[0064] In the determination process of step S106, assume that the update rejection count UR is equal to or greater than a predetermined number of times U1. In this case, the control unit 102 refers to and grasps the latest number of connected terminals NT counted by the connected terminal count unit 131 (step S107). Next, the control unit 102 determines whether the latest number of connected terminals NT is equal to or greater than a predetermined number of units N1 (step S108). The predetermined number of units N1 is determined in advance as an integer of 2 or more, for example, 2 units, 3 units, 4 units, etc. In the determination process of step S108, when it is determined that the latest number of connected terminals NT is less than the predetermined number of units N1, the process from step S107 is repeated and waits for the number of connected terminals NT to become equal to or greater than the predetermined number of units N1.

[0065] In the determination process of step S108, assume that it is determined that the latest number of connected terminals NT is equal to or greater than a predetermined number of units N1. In this case, the control unit 102 controls the activation request unit 122 to form an activation request, transmits this to the license server 6, and executes the activation process (step S109). After this, the control unit 102 ends the process shown in FIG. 5. Thus, according to the process shown in FIG. 5, all of requirement 1, requirement 2, and requirement 3 are satisfied, and further, when there are a plurality of terminal devices simultaneously connected to the WAN 4 through the UTM device 1, the activation process can be started.

[0066] Note that, as described above, when any one of Requirement 1, Requirement 2, and Requirement 3 is satisfied, and furthermore, there are a plurality of terminal devices simultaneously connected to WAN4 through the UTM device 1, the activation process can be started. In this case, the following three processes can be considered. One is the process of executing steps S101 and S102 in the flowchart of FIG. 5 and not executing steps S103 to S106. One is the process of executing steps S103 and S104 in the flowchart of FIG. 5 and not executing steps S101, S102, S105, and S106. One is the process of executing steps S105 and S106 in the flowchart of FIG. 5 and not executing steps S101 to S104.

[0067] Also, when any two of Requirement 1, Requirement 2, and Requirement 3 are satisfied, and furthermore, there are a plurality of terminal devices simultaneously connected to WAN4 through the UTM device 1, the activation process can be started. In this case, the following three processes can be considered. One is the process of executing steps S101 to S104 in the flowchart of FIG. 5 and not executing steps S105 to S106. One is the process of executing the processes of steps S101 and S102 and steps S105 and S106 in the flowchart of FIG. 5 and not executing steps S103 to S104. One is the process of executing steps S103 to S106 in the flowchart of FIG. 5 and not executing steps S101 to S102.

[0068] Thus, when one or more of the requirements of Requirement 1, Requirement 2, and Requirement 3 as preconditions are satisfied, and furthermore, there are a plurality of terminal devices connected to WAN4 through the UTM device 1, the activation process can be started.

[0069] As described with reference to FIG. 4, when there are a plurality of terminal devices connected to the WAN 4 through the UTM device 1, the activation process can be started. Further, among the requirements 1, 2, and 3 as prerequisite conditions, if any one or more of the requirements are satisfied, and further, when there are a plurality of terminal devices connected to the WAN 4 through the UTM device 1, the activation process can be started. Therefore, when the UTM device 1 is installed in a user environment, the activation process will surely be performed.

[0070] For this reason, when the license server 6 receives an activation request and provides authentication information to the UTM device 1, the time point is regarded as the completion time point of the activation process, and the license server 6 can appropriately manage the license period of the UTM device 1. The license period can be accurately managed from the completion time point of the activation process, for example, for 3 years, 5 years, 6 years, 7 years, etc. More specifically, it is possible to appropriately grasp when, for example, the end time point 3 years after the completion time point of the activation process is.

[0071] [Effects of the Embodiment] In the case of the UTM device 1 of the above-described embodiment, after the UTM device 1 is installed in a user environment, the activation process can be executed at an appropriate timing even if a user or the like does not perform an activation operation. Thereby, the user of the UTM device 1 can automatically perform the activation process without performing the activation operation, and can operate the UTM device 1 using the latest software.

[0072] Also, in the license server 6, the time point when the activation from the UTM device 1 is completed can be set as a reference point for specifying the license period. Thereby, it is possible to prevent the license period of the UTM device 1 from being shortened due to the preparation work on the sales store side, and to appropriately manage the license period of the UTM device 1.

[0073] [Modification Example] In addition, each of the predetermined time T1 for comparison with the connection duration CT, the predetermined number of days D1 for comparison with the number of days DT, and the predetermined number of times U1 for comparison with the update rejection count UR, which are used in the flowchart of FIG. 5, can be set to appropriate values. For this reason, initial values may be set, such as the predetermined time T1 = 24 hours, the predetermined number of days D1 = 2 days, and the predetermined number of times U1 = 5 times. Of course, these initial values may also be made changeable through the operation unit 104.

[0074] In the above-described embodiment, it has been described that the customer management server 5, the license server 6, the remote maintenance server 7, and the update server 8 exist, but the present invention is not limited to this. For example, a server having the functions of the customer management server 5 and the license server 6 and a server having the functions of the remote maintenance server 7 and the update server 8 can be used to configure a server group (cloud system) operated by the manufacturer side of the UTM device 1. That is, the number of servers is not a problem, and a cloud system operated by the manufacturer side may be constructed by one or more servers having the functions of each of the customer management server 5, the license server 6, the remote maintenance server 7, and the update server 8.

[0075] In the above-described embodiment, the PCs 3(1), 3(2), 3(3),..., 3(n) connected to the UTM device 1 via the LAN 2 are shown as being connected by wire, but the present invention is not limited to this. A wireless communication terminal connected to the UTM device 1 through an access point connected to the LAN 2 may of course be connected to the UTM device 1.

[0076] In the above-described embodiment, the case where the relay device is the UTM device 1 has been described as an example, but the present invention is not limited to this. The present invention can be applied to various relay devices, such as a gateway device, that relay between a WAN and a LAN to which a plurality of terminal devices are connected.

[0077] In the above-described embodiment, the point in time when the license server 6 receives an activation request and provides authentication information to the UTM device 1 is defined as the completion point of the activation process, and the license period is determined based on this reference point. However, this is not the only way. For example, it is also possible to define the license period with reference to the point in time when the activation process is properly performed and the UTM device 1 first receives the latest software from the update server 8. In this case, the UTM device 1 notifies the license server 6 that it has received the latest software, enabling management on the license server 6.

[0078] In the above-described embodiment, it is assumed that the latest software provided by the update server 8 includes a signature file and a definition file. That is, the latest software provided by the update server 8 includes the software (program) itself and various data necessary for operation. And there may be a case where only the software is provided, a case where only the signature file is provided, or a case where only the definition file is provided. Also, there may be a case where two or more different types of information such as new software, a new signature file, and a definition file are provided.

[0079] [Others] As can be understood from the description of the above-described embodiment, the function of the connection terminal counting means in the claims is realized by the connection terminal counting unit 131 of the UTM device 1, and the function of the connection terminal number determination means in the claims is realized by the control unit 102 of the UTM device 1. Also, the function of the activation request means in the claims is realized by the activation request unit 122 of the UTM device 1.

[0080] Further, the function of the connection measurement means of the claims is realized by the maintenance server connection measurement unit 132 of the UTM device 1, and the function of the measurement time determination means is realized by the control unit 102 of the UTM device 1. Also, the function of the customer registration confirmation means of the claims is realized by the customer registration confirmation unit 133 of the UTM device 1, and the function of the number of days determination means is realized by the control unit 102. Further, the function of the update count means of the claims is realized by the update rejection count unit 134 of the UTM device 1, and the function of the update rejection count determination means of the claims is realized by the control unit 102 of the UTM device 1.

Explanation of Reference Numerals

[0081] 1…UTM device, 101T…connection terminal, 101…communication I / F, 102…control unit, 103…storage device, 104…operation unit, 105…address DB, 106…clock circuit, 107T…connection terminal, 107…LAN I / F, 110…security function unit, 120…proper operation unit, 121…maintenance server connection unit, 122…activation request unit, 123…signature update unit, 130…automatic activation unit, 131…connection terminal count unit, 132…maintenance server connection measurement unit, 133…customer registration confirmation unit, 134…update rejection count unit, 2…LAN, 3(1), 3(2), 3(3), …, 3(n)…PC, 4…WAN, 5…customer management server, 6…license server, 7…remote maintenance server, 8…update server, 9…dealer PC

Claims

1. A relay device that relays between a wide area network and a LAN (Local Area Network), connection terminal counting means for counting the number of terminal devices connected to its own device through the LAN that have started communication through the wide area network; connection terminal number discrimination means for discriminating whether the number of terminal devices counted by the connection terminal counting means is N (an integer of 2 or more) or more; activation request means for, when it is discriminated by the connection terminal number discrimination means that the number is N or more, requesting permission from a license server connected to the wide area network to be operable using the latest software The relay device is characterized by comprising the above.

2. The relay device according to claim 1, a remote maintenance server that connects a session with the relay device and manages the operating state of the relay device is connected to the wide area network, connection measurement means for measuring the time during which communication is performed by connecting a session with the remote maintenance server; measurement time discrimination means for discriminating whether the measurement time by the connection measurement means is a certain time or more comprising, when it is discriminated by the measurement time discrimination means that the measurement time by the connection measurement means is a certain time or more and it is discriminated by the connection terminal number discrimination means that the number is N or more, the activation request means requests permission from the license server to be operable using the latest software The relay device is characterized by the above.

3. The relay device according to claim 1, a customer management server that registers at least the identification information and registration date of the relay device is connected to the wide area network at the start of use of the relay device, customer registration confirmation means for accessing the customer management server and obtaining the registration date of its own identification information; number of days discrimination means for discriminating whether the number of days from the registration date obtained by the customer registration confirmation means to the present time is a certain number of days or more comprising, when it is discriminated by the number of days discrimination means that the number of days from the registration date obtained by the customer registration confirmation means to the present time is a certain number of days or more and it is discriminated by the connection terminal number discrimination means that the number is N or more, the activation request means requests permission from the license server to be operable using the latest software A relay device characterized by the above.

4. The relay device according to claim 1, wherein an update server that provides the latest software in response to a request is connected to the wide area network for a relay device that has obtained permission to operate using the latest software from the license server, update rejection count means for requesting the update server to provide the latest software and counting the number of times of rejection by the update server or rejection by the own device, update rejection count determination means for determining whether or not the number of times counted by the update rejection count means is equal to or more than a certain number of times and comprising wherein when the activation request means determines, by the update rejection count determination means, that the number of times counted by the update rejection count means is equal to or more than a certain number of times and determines, by the connection terminal number determination means, that the number is N or more, the activation request means requests the license server for permission to operate using the latest software A relay device characterized by the above.

5. The relay device according to claim 1, wherein a remote maintenance server that connects a session with the relay device to manage the operating state of the relay device, a customer management server that registers at least the identification information and registration date of the relay device at the start of use of the relay device, and an update server that provides the latest software in response to a request for a relay device that has obtained permission to operate using the latest software from the license server are connected to the wide area network, connection measurement means for connecting a session with the remote maintenance server and measuring the time during which communication is performed, measurement time determination means for determining whether or not the measurement time by the connection measurement means is equal to or more than a certain time, customer registration confirmation means for accessing the customer management server to obtain the registration date of the identification information of the own device, number of days determination means for determining whether or not the number of days from the registration date obtained by the customer registration confirmation means to the current time is equal to or more than a certain number of days, update rejection count means for requesting the update server to provide the latest software and counting the number of times of rejection, update rejection count determination means for determining whether or not the number of times counted by the update rejection count means is equal to or more than a certain number of times and comprising The activation request means satisfies one or more of the following conditions: the discrimination result of the measurement time discrimination means is equal to or longer than a certain time, the discrimination result of the number-of-days discrimination means is equal to or more than a certain number of days, and the discrimination result of the update rejection count discrimination means is equal to or more than a certain number of times. When the connection terminal number discrimination means discriminates that the number is N or more, the license server is requested to permit the relay device to be operable using the latest software. A relay device characterized by the above.

Citation Information

Patent Citations

  • How to connect IoT devices through activation process

    JP6997531B2