Information processing device and system

The described system ensures secure remote maintenance by authenticating and updating network settings of information processing devices, addressing security vulnerabilities in existing remote maintenance techniques.

JP2025173712APending Publication Date: 2025-11-28KK TOSHIBA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024079406
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-15
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

Existing remote maintenance techniques lack security measures to ensure the integrity of network settings during remote access to information processing devices.

Method used

An information processing device receives and authenticates an email with security setting information, which is used to update the gateway and firewall settings of a maintenance target device, enabling secure remote access.

Benefits of technology

Enables secure remote maintenance by ensuring the integrity of network settings through authentication and configuration updates, preventing unauthorized access and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025173712000001_ABST
    Figure 2025173712000001_ABST
Patent Text Reader

Abstract

To enable secure remote maintenance.SOLUTION: An information processing device includes a control unit. The control unit receives an email containing setting information related to security settings of a local area network, and transmits the setting information to a maintenance target device that is an information processing device located in the local area network and to be maintained. The setting information includes information for changing the settings for allowing a gateway of the local area network and a firewall of the maintenance target device to be accessible from outside the local area network.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] An embodiment of the present disclosure relates to an information processing device and a system for performing maintenance work by remote control. [Background technology]

[0002] 2. Description of the Related Art Remote maintenance techniques have been developed to perform maintenance work on information processing devices by remote control. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2009-252067 Summary of the Invention [Problem to be solved by the invention]

[0004] The problem that the present disclosure aims to solve is to realize remote maintenance that ensures security. [Means for solving the problem]

[0005] According to an embodiment, an information processing device includes a control unit. The control unit receives an email containing setting information related to security settings of a local area network (LAN), and transmits the setting information to a maintenance target device, which is an information processing device that is located on the LAN and is to be maintained. The setting information includes information for changing the settings of a gateway of the LAN and a firewall of the maintenance target device to enable access from outside the LAN. [Brief explanation of the drawings]

[0006] [Figure 1] FIG. 1 is a block diagram showing the functional configuration of a maintenance management system according to an embodiment. [Figure 2]FIG. 2 is a block diagram illustrating the functional configuration of the management device. [Figure 3] FIG. 3 is a block diagram showing the functional configuration of the maintenance target device. [Figure 4] FIG. 4 is a sequence diagram showing the flow of processing in the maintenance management system. [Figure 5] FIG. 5 is a block diagram showing the hardware configuration of the information processing device. [Figure 6] FIG. 6 is a block diagram showing the functional configuration of a management device according to the second embodiment. [Figure 7] FIG. 7 is a sequence diagram showing the flow of processing in the maintenance management system according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0007] <1. Embodiment> Hereinafter, each embodiment of the present disclosure will be described with reference to the drawings. In this specification and each drawing, elements similar to those already described are designated by the same reference numerals, and detailed description thereof will not be repeated.

[0008] (1.1. Overall structure) The overall configuration of a maintenance management system 100 according to an embodiment will be described with reference to Fig. 1. As shown in Fig. 1, the maintenance management system 100 includes an external device 12 arranged in a first local area network N1, and a management device 22 and a maintenance target device 23 arranged in a second local area network N2.

[0009] The external device 12, the management device 22, and the maintenance target device 23 are information processing devices that have input means and output means and can be operated by a user. The information processing devices may be general-purpose or dedicated personal computers, smart devices, etc. Smart devices include tablet terminals, smartphones, smart glasses, smart watches, etc. The hardware configuration of the information processing devices will be described later.

[0010] The external device 12 is, for example, an information processing device used by an administrator who operates the maintenance management system 100. The external device 12 transmits an email regarding security settings of the local area network N2 in which the maintenance target device 23 is located to the management device 22 in the local area network N2. Details of the processing of the external device 12 will be described later.

[0011] The management device 22 is an information processing device that is placed within the local area network N2 and that manages the security of the local area network N2. The management device 22 receives emails related to security settings of the local area network N2 from the external device 12. Details of the processing of the management device 22 will be described later.

[0012] The maintenance target device 23 is an information processing device that is the target of maintenance in the maintenance management system 100. As an example, as shown in FIG. 1, a plurality of maintenance target devices 23 are arranged in the local area network N2, but there may be only one maintenance target device 23. The maintenance target device 23 changes the settings of the local area network N2 to make it accessible from the outside, based on a command (a command instructing the information processing device to execute a specific function) output from the management device 22. Details of the processing of the maintenance target device 23 will be described later.

[0013] The first local area network N1 is provided with a gateway 11. The gateway 11 controls the communication connection between the local area network N1 and the external Internet N.

[0014] The second local area network N2 is provided with a gateway 21. The gateway 21 controls the communication connection between the local area network N2 and the external Internet N.

[0015] (1.2. Functional Configuration of Management Device 22) The functional configuration of the management device 22 will be described with reference to Fig. 2. The control unit of the management device 22 has an OS processing unit 22a and a userland 22b. The OS processing unit 22a performs processing related to the basic functions of the OS (Operating System) implemented in the management device 22. The userland 22b performs processing based on the authority granted to the user of the management device 22.

[0016] The user land 22b includes a mail sending / receiving module 22b1 and a command output module 22b2. The mail sending / receiving module 22b1 receives an e-mail from the external device 12. The e-mail includes setting information related to security settings of the local area network N2.

[0017] The command output module 22b2 generates a setting information update command, which is a command for updating the setting information, based on the setting information included in the email received by the email sending / receiving module 22b1. The command output module 22b2 outputs the generated setting information update command to the maintenance target device 23.

[0018] (1.3. Functional configuration of the maintenance target device 23) The functional configuration of the maintenance target device 23 will be described with reference to Fig. 3. The control unit of the maintenance target device 23 has an OS processing unit 23a and a userland 23b. The OS processing unit 23a performs processing related to the basic functions of the OS (Operating System) implemented in the maintenance target device 23. The userland 23b performs processing based on the authority granted to the user of the maintenance target device 23.

[0019] The OS processing unit 23a includes a firewall 23a1. The firewall 23a1 performs processing to block unauthorized access to the maintenance target device 23.

[0020] Userland 23b includes a setting information file 23b1 and a setting management module 23b2. Setting information file 23b1 is a file that stores the latest setting information. For example, setting information file 23b1 includes information about a maintenance work schedule and information about the port numbers of gateway 21 and firewall 23a1 when the maintenance work is performed.

[0021] Setting management module 23b2 updates setting information file 23b1 based on a setting information update command input from management device 22. Setting management module 23b2 also refers to setting information file 23b1 at predetermined time intervals and sets gateway 21 and firewall 23a1 to be accessible from outside second local area network N2 in accordance with a maintenance work schedule.

[0022] (1.4. Processing flow) The flow of processing in the maintenance management system 100 will be described with reference to Fig. 4. Fig. 4 is a sequence diagram showing the flow of processing in the maintenance management system 100.

[0023] In step S110, the external device 12 determines a schedule for maintenance work on the maintenance target device 23 based on an operation by the administrator of the maintenance management system 100.

[0024] In step S120, the external device 12 generates setting information based on the operation of the administrator of the maintenance management system 100. The setting information may include information about the maintenance work schedule determined in step S110, and information about the port numbers of the gateway 21 and the firewall 23a1 when the maintenance work is performed.

[0025] In step S130, the external device 12 generates an e-mail to be sent to the management device 22. The setting information generated in step S120 may be attached to the e-mail. Alternatively, the setting information may be included in the body of the e-mail.

[0026] In step S140, the external device 12 affixes a digital signature to the email generated in step S130. The digital signature can use a well-known security protocol such as TLS (Transport Layer Security) or OCSP (Online Certificate Status Protocol).

[0027] In step S150, the external device 12 transmits the email to which the digital signature was added in step S140 to the management device 22. In step S210, the management device 22 receives the email sent from the external device 12. The management device 22 authenticates the digital signature added to the received email.

[0028] In step S220, the management device 22 extracts the setting information contained in the email received in step S210.

[0029] In step S230, the management device 22 transmits a receipt notification indicating that the e-mail has been received to the external device 12. In step S160, the external device 12 receives the receipt notification.

[0030] In step S240, the management device 22 generates a setting information update command based on the setting information extracted in S220 and outputs the command to the maintenance target device 23. The output of the setting information update command from the management device 22 to the maintenance target device 23 can be performed using a well-known communication method. As an example, the management device 22 may generate a User Datagram Protocol (UDP) socket including the setting information update command and broadcast the UDP socket to a port number of the maintenance target device 23 that is always available for communication. If there are multiple maintenance target devices 23, each of the multiple maintenance target devices 23 may be identified by its MAC address. Furthermore, the maintenance target device 23 that receives the UDP socket may confirm the sender by comparing the IP address of the sender with a pre-stored IP address. Furthermore, in order to broadcast the UDP socket, the port number of the maintenance target device 23 may be set to be available for communication at a pre-scheduled timing.

[0031] In step S310, setting management module 23b2 of maintenance target device 23 updates setting information file 23b1 based on the input setting information update command, thereby storing information on the schedule for the next maintenance work and information on the port numbers of gateway 21 and firewall 23a1 when the maintenance work is performed.

[0032] In step S320, the setting management module 23b2 of the maintenance target device 23 refers to the setting information file 23b1 and sets the settings of the gateway 21 and the firewall 23a1 so that they can be accessed from outside the second local area network N2 at a timing before the start of the maintenance work in the predetermined maintenance work schedule.

[0033] In step S170, the external device 12 performs remote maintenance work on the maintenance target device 23 from outside the local area network N2 based on the operation of the administrator of the maintenance management system 100.

[0034] In step S330, the setting management module 23b2 of the maintenance target device 23 refers to the setting information file 23b1 and sets the settings of the gateway 21 and the firewall 23a1 to be inaccessible from outside the second local area network N2 at a timing after the completion of the maintenance work according to the predetermined schedule.

[0035] (1.5. Hardware configuration of information processing device) 5, a description will be given of the hardware configuration of information processing devices used as the external device 12, the management device 22, and the maintenance target device 23. The external device 12, the management device 22, and the maintenance target device 23 as information processing devices are realized, as an example, by a computer 90 shown in FIG. 5. The computer 90 includes a CPU 91, a ROM 92, a RAM 93, a storage 94, an input interface 95, an output interface 96, and a communication interface 97.

[0036] The CPU 91 functions as a processor that executes processing. Specifically, the CPU 91 uses the RAM 93 as a work memory and executes a program stored in at least one of the ROM 92 and the storage 94. During program execution, the CPU 91 controls each component via a system bus 98 and executes various processes.

[0037] The ROM 92 stores a program that controls the operation of the computer 90. The ROM 92 stores a program necessary for causing the computer 90 to perform each of the above-described processes. The RAM 93 functions as a storage area in which the programs stored in the ROM 92 are expanded.

[0038] The storage 94 stores data necessary for executing the programs and data obtained by executing the programs. The storage 94 includes one or more selected from a hard disk drive (HDD) and a solid state drive (SSD). The storage 94 may also be implemented as an external storage medium such as an SD card or a universal serial bus (USB) memory.

[0039] The input interface (I / F) 95 can connect the computer 90 to an input device 95a. The input interface 95 is, for example, a serial bus interface such as USB. The CPU 91 can read various data from the input device 95a via the input interface 95.

[0040] The output interface (I / F) 96 can connect the computer 90 and an output device 96a. The output interface 96 is, for example, a video output interface such as DVI (Digital Visual Interface) or HDMI (High-Definition Multimedia Interface), a registered trademark. The CPU 91 can transmit data to the output device 96a via the output interface 96 and cause the output device 96a to output the data.

[0041] The input device 95a is an example of an input means and includes one or more selected from a mouse, a keyboard, a microphone (voice input), and a touchpad. The output device 96a is an example of an output means and includes one or more selected from a display, a projector, a printer, and a speaker. A device having the functions of both the input device 95a and the output device 96a, such as a touch panel, may also be used.

[0042] The communication interface (I / F) 97 can connect the computer 90 to an external server 97a located outside the computer 90. The communication interface 97 is, for example, a network card such as a LAN card. The CPU 91 can read various data from the external server 97a via the communication interface 97.

[0043] The processes executed by the external device 12, the management device 22, and the maintenance target device 23 may be realized by one computer 90 or by a plurality of computers 90 working together.

[0044] The various data processing operations described above may be recorded as a computer-executable program on a magnetic disk (such as a flexible disk or hard disk), an optical disk (such as a CD-ROM, CD-R, CD-RW, DVD-ROM, DVD±R, or DVD±RW), a semiconductor memory, or other non-transitory computer-readable storage medium.

[0045] For example, information recorded on a recording medium can be read by a computer (or an embedded system). The recording medium may have any recording format (storage format). For example, the computer reads a program from the recording medium and causes a processor to execute instructions written in the program based on the program. The computer may acquire (or read) the program via a network.

[0046] (1.6.Summary) As described above, the maintenance management system 100 according to this embodiment includes the management device 22, which is an information processing device for management, and the maintenance target device 23, which is an information processing device to be maintained and is located on the local area network N2. The control unit (first control unit) of the management device 22 receives an email containing setting information related to the settings of the second local area network N2, and outputs a command based on the setting information to the maintenance target device 23. Based on the input command, the second control unit of the maintenance target device 23 changes the settings of the gateway 21 and the firewall 23a1 to enable access from outside the local area network N2. With this configuration, remote maintenance of the maintenance target device 23 can be performed while ensuring security, without using any special equipment for ensuring security.

[0047] The setting information may also include information for changing the settings of the gateway 21 of the local area network N2 and the firewall 23a1 of the maintenance target device 23 to enable access from outside the local area network, and the control unit (second control unit) of the maintenance target device 23 may set the port numbers of the gateway 21 and the firewall 23a1 to enable access from outside the local area network N2 based on the setting information. By adopting such specifications, the technical idea of ​​the present disclosure can be specifically realized, and remote maintenance of the maintenance target device 23 can be performed while ensuring security.

[0048] Furthermore, the email may include a digital signature of the sender, and the first control unit of the management device 22 may authenticate the validity of the digital signature in the received email. By adopting such specifications, it is possible to prevent tampering or spoofing of email, thereby improving the security of remote maintenance work.

[0049] 2. Second Embodiment A maintenance management system 200 according to a second embodiment of the present disclosure will be described with reference to Figures 6 and 7. The maintenance management system 200 differs from the first embodiment in that the firewall 23a1 of the maintenance target device 23 is set to always allow external access, and the management device 22 changes the settings of the gateway 21. The following description will focus on the differences from the first embodiment.

[0050] (2.1.Management device 22) 6, in the management device 22 according to the second embodiment, the user land 22b included in the control unit of the management device 22 includes a setting management module 22b3 and a setting information file 22b4. The setting management module 22b3 updates the setting information file 22b4 based on emails received by the email sending / receiving module 22b1. The setting management module 22b3 refers to the setting information file 22b4 and configures the gateway 21 so that it can be accessed from outside the local area network N2.

[0051] (2.2. Processing flow) The flow of processing in the maintenance management system 200 will be described with reference to Fig. 7. Note that the description of processing similar to that in the first embodiment will not be repeated.

[0052] After the processing of steps S110 to S160, in step S240, setting management module 22b3 of management device 22 updates setting information file 22b4, thereby storing information on the schedule for the next maintenance work and information on the port number of gateway 21 when the maintenance work is to be performed.

[0053] In step S250, the setting management module 22b3 of the management device 22 refers to the setting information file 22b4 and sets the port number of the gateway 21 to be accessible from outside the second local area network N2 at a timing before the start of the maintenance work in the predetermined schedule.

[0054] In step S170, the external device 12 performs remote maintenance work on the maintenance target device 23 from outside the local area network N2 based on the operation of the administrator of the maintenance management system 200.

[0055] In step S260, the setting management module 22b3 of the management device 22 refers to the setting information file 22b4 and sets the port number of the gateway 21 to be inaccessible from outside the second local area network N2 at a timing after the completion of the maintenance work according to the predetermined schedule.

[0056] In this way, as a second embodiment of the present disclosure, the control unit of the management device 22 included in the maintenance management system 200 receives an email containing setting information regarding the settings of the local area network N2 in which the maintenance target device 23 is located. Based on the setting information, the control unit of the management device 22 changes the setting of the gateway 21 of the local area network N2 to enable access from outside the local area network N2. With this configuration, remote maintenance can be achieved with a simpler configuration while ensuring security.

[0057] <3. Other embodiments> The maintenance management system 100 according to this embodiment has been described above, but the application of the technical concept of the present disclosure is not limited to the above embodiment. For example, in the above embodiment, the management device 22 and the maintenance target device 23 are arranged on the same local area network N2, but the present invention is not limited to this. For example, the management device 22 may be arranged outside the local area network N2.

[0058] The disclosure may include the following features. (Appendix 1) An information processing device including a control unit, The control unit receiving an email containing setting information regarding security settings of a local area network in which the information processing device to be maintained is located; transmitting the setting information to a maintenance target device that is the information processing device to be maintained; The information processing device, wherein the setting information includes information for changing the settings of a gateway of the local area network and a firewall of the maintenance target device to enable access from outside the local area network. (Appendix 2) The email includes a digital signature from the sender; 2. The information processing device according to claim 1, wherein the control unit verifies the validity of the electronic signature. (Appendix 3) An information processing device including a control unit, The control unit receiving an email containing setting information regarding security settings of a local area network in which the information processing device to be maintained is located; The information processing device changes the setting of the gateway of the local area network to a setting that allows access from outside the local area network based on the setting information. (Appendix 4) a management device that includes a first control unit and is an information processing device for management; a maintenance target device that includes a second control unit, is placed on a local area network, and is an information processing device that is a maintenance target; The first control unit receiving an email containing configuration information regarding security settings for the local area network; outputting a command based on the setting information to the maintenance target device; The second control unit changes the settings of a gateway of the local area network and a firewall of the device to be maintained based on the command to enable access from outside the local area network. (Appendix 5) The system described in Appendix 4, wherein the second control unit sets port numbers of the gateway and the firewall to be accessible from outside the local area network based on the setting information.

[0059] Although several embodiments of the present disclosure have been illustrated above, these embodiments are presented by way of example only and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, substitutions, modifications, etc. can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, as well as within the scope of the invention and its equivalents as set forth in the claims. Furthermore, the above-described embodiments can be implemented in combination with each other. [Explanation of symbols]

[0060] 11: Gateway, 12: External device, 21: Gateway, 22: Management device, 22a: OS processing unit, 22b: Userland, 22b1: Mail sending / receiving module, 22b2: Command output module, 22b3: Setting management module, 22b4: Setting information file, 23: Maintenance target device, 23a: OS processing unit, 23a1: Firewall, 23b: Userland, 23b1: Setting information file, 23b2: Setting management module, 90: Computer, 91: CPU, 92: ROM, 93: RAM, 94: Storage, 95: Input interface, 95a: Input device, 96: Output interface, 96a: Output device, 97: Communication interface, 97a: External server, 98: System bus, 100: Maintenance management system, 200: Maintenance management system

Claims

1. An information processing device including a control unit, The control unit receiving an email containing setting information regarding security settings of a local area network in which the information processing device to be maintained is located; transmitting the setting information to a maintenance target device that is the information processing device to be maintained; The information processing device, wherein the setting information includes information for changing the settings of a gateway of the local area network and a firewall of the maintenance target device to enable access from outside the local area network.

2. The email includes a digital signature from the sender; The information processing device according to claim 1 , wherein the control unit authenticates the authenticity of the digital signature.

3. An information processing device including a control unit, The control unit receiving an email containing setting information regarding security settings of a local area network in which the information processing device to be maintained is located; The information processing device changes the setting of the gateway of the local area network to a setting that allows access from outside the local area network based on the setting information.

4. a management device that includes a first control unit and is an information processing device for management; a maintenance target device that includes a second control unit, is placed on a local area network, and is an information processing device that is a maintenance target; The first control unit receiving an email containing configuration information regarding security settings for the local area network; outputting a command based on the setting information to the maintenance target device; The second control unit changes the settings of a gateway of the local area network and a firewall of the maintenance target device based on the command to enable access from outside the local area network.

5. 5. The system according to claim 4, wherein the second control unit sets port numbers of the gateway and the firewall based on the setting information so as to enable access from outside the local area network.

Citation Information

Patent Citations

  • Management device, management method and computer program

    JP2009252067A