Communication apparatus, access control method, and program

By using a position acquisition unit to enable login authentication based on location, wireless routers ensure only authorized users can access settings, preventing unauthorized changes and enhancing network security.

JP2026010753APending Publication Date: 2026-01-23NEC PLATFROMS LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024110714
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-10
Publication Date
2026-01-23

AI Technical Summary

Technical Problem

Wireless routers can be easily moved or stolen, leading to potential leaks of configuration information and compromised network security due to lack of effective physical security measures.

Method used

Implement a position acquisition unit to determine the current location of the device, enabling a login authentication function only when the device is within a preset initial range, allowing authenticated users to access setting information.

Benefits of technology

Enhances security by preventing unauthorized access and changes to settings, ensuring only authorized users can modify configuration information, thus improving network security without reducing convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026010753000001_ABST
    Figure 2026010753000001_ABST
Patent Text Reader

Abstract

To improve security of a communication device.SOLUTION: A communication device comprising: a position acquisition unit that acquires a current position of the communication device using a positioning system; a login control unit that enables a login authentication function based on the current position; and a setting information control unit that executes a login authentication sequence and permits an authenticated user to access setting information in the communication device when the login authentication function is enabled, wherein the login control unit enables the login authentication function when the current position is included in an initial range stored in advance.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a communication device, an access control method, and a program. [Background technology]

[0002] There are wireless routers equipped with a GPS function (see, for example, Patent Document 1). According to the technology disclosed in Patent Document 1, the wireless router records location information acquired by receiving a GPS signal, and when an inquiry about location information is received from a wireless LAN terminal, the wireless router notifies the wireless LAN terminal of the location information. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-169807 Summary of the Invention [Problem to be solved by the invention]

[0004] The following analysis has been carried out by the inventors of the present invention.

[0005] Wireless routers are wireless repeaters that can be installed anywhere because they do not require a wired connection. However, this feature also means that the device itself can be moved carelessly and its settings changed, or it can be stolen by malicious individuals, resulting in the leakage of configuration information or the sale of the device with the settings stored. For this reason, careful attention must be paid to physical security measures for wireless repeaters such as wireless routers. In particular, the leakage of configuration information can have a significant impact on the security of the entire network.

[0006] The present disclosure has been made in consideration of the above circumstances, and one of its objects is to provide a technique that contributes to improving the security of communication devices. [Means for solving the problem]

[0007] According to a first aspect of the present disclosure, a position acquisition unit that acquires a current position of the device using a positioning system; a login control unit that enables a login authentication function based on the current location; a setting information control unit that executes a login authentication sequence when the login authentication function is enabled, and allows an authenticated user to access setting information stored in the device itself; The login control unit enables the login authentication function when the current location is within a preset initial range.

[0008] According to a second aspect of the present disclosure, The computer of the communication device If the current location of the communication device is within a pre-registered initial range, the login authentication function is enabled; If the login authentication function is enabled, execute a login authentication sequence; An access control method is provided that allows a user authenticated in the login authentication sequence to access setting information in the communication device.

[0009] According to a third aspect of the present invention, The computer of the communication device a step of activating a login authentication function when the current location of the communication device is within a pre-registered initial range; If the login authentication function is enabled, executing a login authentication sequence; A program is provided to execute a procedure for permitting a user authenticated in the login authentication sequence to access setting information in the communication device.

[0010] These programs can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present invention can also be embodied as a computer program product. [Effects of the Invention]

[0011] According to the present invention, it is possible to improve the security of a communication device. [Brief explanation of the drawings]

[0012] [Figure 1] 1A is an overall configuration diagram of an example of a communication system according to the present disclosure, and FIG. 1B is a functional block diagram of an example of a SOHO (Small Office Home Office) router according to the present disclosure. [Figure 2] 10 is a flowchart of an example of an access control process of the present disclosure. [Figure 3] FIG. 2 is a functional block diagram of an example SOHO router according to the present disclosure. [Figure 4] 10A and 10B are diagrams illustrating an example of a setting information change screen and a login screen, respectively, according to the present disclosure. [Figure 5] 10 is a flowchart illustrating an example of a setting information change process of the present disclosure. [Figure 6] 10 is a flowchart illustrating an example of an initial range setting process of the present disclosure. [Figure 7] 10 is a flowchart illustrating an example of a login authentication control process according to the present disclosure. [Figure 8] 10 is a flowchart illustrating an example of a login authentication control process according to a modified example of the present disclosure. [Figure 9] 1 is a configuration diagram showing an example of a hardware configuration of a SOHO router according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that reference numerals in the drawings are assigned to each element for convenience as an example to facilitate understanding, and are not intended to limit the present invention to the illustrated aspects. Furthermore, connecting lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Furthermore, in the following description, "A and / or B" means A or B, or A and B.

[0014] <<First Embodiment>> An overview of this embodiment will be described. Fig. 1(a) is a diagram for explaining an overview of the entire communication system 100 used by the communication device of this embodiment. As shown in this figure, the communication system 100 of this embodiment includes a communication device. In this embodiment, a case where a SOHO (Small Office Home Office) router 200 is used as the communication device will be described as an example.

[0015] The SOHO router 200 is a device that does not require a WAN (Wide Area Network) wired line for Internet connection, but instead uses a mobile network while being installed in a fixed location. It can be installed anywhere, depending on the radio wave conditions. On the other hand, there is a risk that the device may be carelessly moved to another location and its settings changed. There is also the risk that a malicious individual may steal the device and leak the settings information. Furthermore, there is a risk that the device may be sold with its settings saved. For these reasons, it is a communications device that requires careful attention to physical security measures.

[0016] The SOHO router 200 connects one or more terminal devices (hereinafter referred to as "child devices"), such as smartphones or laptop computers, to a mobile communication network 110 provided by a mobile communication carrier. The SOHO router 200 of this embodiment connects the child devices to the Internet 120 via the mobile communication network 110, and connects them to other terminal devices. At this time, setting information required for routing the one or more child devices to the terminal devices, setting information related to security, etc., are set from an input / output device 310, which is a management console connected to the SOHO router 200. The input / output device 310 is connected to the SOHO router 200 directly, via a wired or wireless LAN, a WAN, etc.

[0017] Here, the security setting information set from the input / output device 310 includes, for example, the following information: - Encryption keys for encrypted communications such as IPsec (Security Architecture for Internet Protocol) between routers User ID and password for connecting to the mobile network / Internet provider - User ID and password when authenticating devices between a PC (Personal Computer) and the router -Email address information for periodically sending information about the router status via email etc.

[0018] Furthermore, the SOHO router 200 of this embodiment has a function capable of receiving radio waves (signals) from a group of satellites 130 such as GPS satellites and measuring the position of the device itself.

[0019] In the present embodiment, for example, when the SOHO router 200 is installed in a location different from the geographical location information at the time of initial installation, or when location information cannot be obtained, it is possible to control access from the input / output device 310 to the setting information in the SOHO router 200. This makes it possible to prevent the leakage of the setting information of the SOHO router 200 and security incidents caused by the leakage.

[0020] The functions of the SOHO router 200 of this embodiment that achieve this will be described below. Fig. 1(b) is a functional block diagram of the configuration of the SOHO router 200 of this embodiment that is related to this embodiment. The SOHO router 200 includes a router unit 290, a location acquisition unit 210, a login control unit 220, and a setting information control unit 230.

[0021] The router unit 290 performs processing as a router, for example, connecting one or more slave devices to the mobile communication network 110 and routing to the terminal devices in accordance with preset setting information.

[0022] The location acquisition unit 210 acquires the current location of its own device (SOHO router 200). In this embodiment, the current location information of its own device is acquired using, for example, a satellite positioning system such as GPS (Global Positioning System). The location information of its own device is expressed, for example, by latitude, longitude, altitude, etc. Note that the location acquisition method is not limited to satellite positioning as long as the SOHO router 200 can autonomously acquire its location.

[0023] The login control unit 220 enables the login authentication function based on the current location information (current location) of the device itself acquired by the location acquisition unit 210. The login authentication function is a function for authenticating a user through a normal login authentication sequence. The login control unit 220 enables the login authentication function when the current location is included in a pre-stored initial range. In other words, the login control unit 220 enables the login authentication function when the SOHO router 200 has not moved from the location where it was when the setting information was initially set. Note that the login authentication function is disabled as an initial state, for example, when the initial range is stored.

[0024] In this embodiment, login authentication is required when a user accesses the SOHO router 200 from the input / output device 310 and changes the configuration information. Specifically, when a login request is received from the user, the login control unit 220 determines whether the current location of the device at that time is included in a pre-stored initial range. If included, the login authentication function is enabled. The initial range is set, for example, when the SOHO router 200 starts operating. The initial range is determined by taking into account the initial location, which is the location at that time, and a predetermined allowable range. Here, the user refers to a so-called administrator / configurator who configures the SOHO router 200 via the input / output device 310.

[0025] When the login authentication function is enabled, the setting information control unit 230 executes a login authentication sequence and permits a user authenticated in the login authentication sequence to access the setting information in its own device (SOHO router 200).

[0026] [Access control processing] Here, the flow of the access control process by the login control unit 220 and the setting information control unit 230 of this embodiment will be described. Fig. 2 shows the processing flow of the access control process of this embodiment. This process is started when a login request is received from a user. Also, here, the initial state of the login authentication function is disabled.

[0027] First, the login control unit 220 causes the location acquisition unit 210 to acquire the current location (step S1101).

[0028] The login control unit 220 determines whether the current location is within a predetermined initial range (step S1102).

[0029] If it is within the initial range (S1102; Yes), the login control unit 220 enables the login authentication function (step S1103).

[0030] When the login authentication function is enabled, the setting information control unit 230 executes a login authentication sequence (step S1104) and ends the access control process. At this point, a user who has successfully passed login authentication is permitted to access the setting information.

[0031] On the other hand, if it is outside the initial range (S1102; No), the login control unit 220 ends the process. In this case, the login authentication function remains disabled.

[0032] As described above, the SOHO router 200 of this embodiment compares the location information when the SOHO router 200 is installed (initial) with the location information when a login request is made by the user, and enables the login authentication function of the SOHO router 200 only if the two match.

[0033] This allows the SOHO router 200 to reject any login request made to it from a location other than the original installation location, thereby preventing settings from being changed in an unexpected installation location or leaking setting information due to the theft of the device.

[0034] In this embodiment, only the login authentication function for the setting information is controlled among the functions of the SOHO router 200. In other words, even while determining the validity of access to the setting information, the router function of the SOHO router 200 is not affected. Therefore, normal routing functions can be continued.

[0035] Therefore, according to this embodiment, security is improved without reducing the convenience of the SOHO router 200.

[0036] <<Second embodiment>> Next, a second embodiment of the present disclosure will be described. This embodiment is an embodiment that embodies the first embodiment in more detail. In this embodiment, components with the same names as those in the first embodiment basically have the same functions as those in the first embodiment. Hereinafter, this embodiment will be described, focusing on the differences from the first embodiment.

[0037] In this embodiment, the communication device is configured to be able to determine whether or not to enable the login authentication function even when, for example, the communication device cannot acquire location information for some reason. In this embodiment, too, an example will be described in which the communication device is a SOHO router 200.

[0038] The SOHO router 200 of this embodiment, like the first embodiment, includes a location acquisition unit 210, a login control unit 220, a setting information control unit 230, and a router unit 290, as shown in FIG.

[0039] Furthermore, the SOHO router 200 of this embodiment further includes an initial range setting unit 240, an authentication key generation and registration unit 250, a reception unit 260, and an external storage control unit 280. The SOHO router 200 of this embodiment also includes a storage unit 270.

[0040] The storage unit 270 stores information necessary for processing by the SOHO router 200 and information generated by the processing. In this embodiment, the storage unit 270 stores the allowable range used when generating the initial range, the generated initial range, an authentication key (described later), the setting information itself, and the like.

[0041] The reception unit 260 receives requests and instructions from a user. In this embodiment, it receives an initial range setting request, a login request, etc. The initial range setting request is a request to set an initial range to be used in processing. The login request is a login request, which is an access to setting information, as in the first embodiment.

[0042] The accepting unit 260 generates a setting information change screen for accepting, for example, either an initial range setting request or a login request, displays it on the display of the input / output device 310 functioning as a management console, and accepts the user's intention. An example of the generated setting information change screen 410 is shown in Fig. 4(a). As shown in this figure, the setting information change screen 410 includes an initial range setting request accepting unit 411 that accepts an initial range setting request, a login request accepting unit 412 that accepts a login request, and an end accepting unit 413 that accepts an instruction to end.

[0043] Furthermore, when the login authentication function is enabled, a login screen is generated and displayed on the display of the input / output device 310, and input from the user is accepted. The login screen is a screen that accepts input of information required to execute a normal login authentication sequence. An example of the login screen 420 is shown in FIG. 4(b). As shown in this figure, the login screen 420 has an input acceptance area 421 that accepts input of information required for login authentication. Here, an example is shown in which an ID (Identification) and a password are entered as the required information.

[0044] The external storage control unit 280 is a drive that controls writing to and reading from the external storage device 350. The SOHO router 200 of this embodiment is provided with an interface for the removable external storage device 350, such as a USB (Universal Serial Bus) memory or an SD card. The external storage control unit 280 controls the exchange of data with the external storage device 350 via this interface.

[0045] When the initial range setting unit 240 receives an initial range setting request from the user via the receiving unit 260, it generates an initial range. The initial range is generated by adding a predetermined allowable range to the acquired initial position. The initial position is obtained by receiving position information from the position acquisition unit 210 at the time the initial range setting request is received. For example, the position acquisition unit 210 may be controlled to acquire the position information. The allowable range is stored in the storage unit 270, for example. The allowable range may be, for example, a radius r centered on the initial position. In this case, the initial range setting unit 240 determines an area of ​​radius r centered on the initial position as the initial range. The initial range may be, for example, an area having a predetermined width or length and centered on the initial position.

[0046] The authentication key generation and registration unit 250 generates an authentication key by encrypting the information about the initial range generated by the initial range setting unit 240. For example, the information specifying the initial range is converted into a single plaintext according to a predetermined rule, and then encrypted using an encryption algorithm. The encryption algorithm used here may be an existing one or may be unique to the SOHO router 200.

[0047] Furthermore, the authentication key generation and registration unit 250 stores the generated authentication key in the storage unit 270 and the removable external storage device 350. When storing the authentication key in the external storage device 350, the authentication key is stored via the external storage control unit 280. Hereinafter, the authentication key stored in the storage unit 270 will be referred to as the internal authentication key, and the authentication key stored in the external storage device 350 will be referred to as the external authentication key. The internal authentication key and the external authentication key are the same thing. Note that, when the authentication key generation and registration unit 250 has completed storing the authentication key in the external storage device 350, it may notify the user of this and prompt the user to remove the external storage device 350. For example, the user may be prompted to remove the external storage device 350 by displaying a message on the display of the input / output device 310.

[0048] The login control unit 220 basically has the same functions as in the first embodiment. However, in this embodiment, if the location of the login control unit 220 itself when receiving a login request is outside the initial range, the login control unit 220 further performs verification using an authentication key. Note that the current location of the SOHO router 200 being outside the initial range includes, for example, a case where the current location is not actually included in the initial range and a case where the current location cannot be obtained.

[0049] When performing verification using an authentication key, the login control unit 220 may first prompt the user to reconnect the external storage device 350. In this case, the login control unit 220 prompts the user to reconnect by, for example, displaying a message on the display of the input / output device 310. After a predetermined time has elapsed, the login control unit 220 obtains the external authentication key from the external storage device 350 via the external storage control unit 280 and compares it with the internal authentication key stored in the storage unit 270. If they match, the login control unit 220 enables the login authentication function. On the other hand, if they do not match, the login control unit 220 maintains the disabled state. The login control unit 220 also maintains the disabled state if the external storage device 350 cannot be recognized even after a predetermined time has elapsed, if the external authentication key is not stored in the external storage device 350, or if the external authentication key cannot be read from the external storage device 350, for example.

[0050] The other functions of the location acquisition unit 210, the setting information control unit 230, and the router unit 290 are the same as those in the first embodiment, and therefore will not be described here.

[0051] [Setting information change process] The flow of the setting information change process in the SOHO router 200 of this embodiment will be described. Fig. 5 shows the processing flow of the setting information change process of this embodiment. This process is started, for example, when a setting information change request is received. The setting information change request can be selected on the initial screen of the SOHO router 200, or the like. The process may also be started when the SOHO router 200 is started.

[0052] The reception unit 260 displays the setting information change screen 410 (step S2101) and monitors at predetermined time intervals whether or not there is a request from the user. Here, when an initial range setting request is received via the initial range setting request reception unit 411 (step S2102; Yes), it notifies the initial range setting unit 240 of this fact and starts the initial range setting process (step S2103). This initial range setting process is a process that is performed when the SOHO router 200 is installed as a fixed unit. After the initial range setting process has started, the display returns to the setting information change screen and waits for the next instruction.

[0053] Furthermore, when the accepting unit 260 accepts a login request via the login request accepting unit 412 (step S2104; Yes), it notifies the login control unit 220 and starts the login authentication control process (step S2105). After the login authentication control process is started, the screen returns to the setting information change screen display state and waits for the next instruction.

[0054] Furthermore, if the receiving unit 260 receives an instruction to end the setting information change process via the end receiving unit 413 (S2106; Yes), the process ends. On the other hand, if neither request is received (step S2106; No), the process returns to step S2101 and continues monitoring.

[0055] [Initial range setting process] Next, the flow of the initial range setting process that starts in step S2103 above will be described. Fig. 6 shows the processing flow of the initial range setting process of this embodiment.

[0056] First, the initial range setting unit 240 acquires the current location (step S2201). In this embodiment, as described above, the current location is acquired, for example, from the location acquisition unit 210. Alternatively, the initial range setting unit 240 instructs the location acquisition unit 210 to acquire location information, which is then set as the current location.

[0057] The initial range setting unit 240 acquires information about the allowable range from the storage unit 270 (step S2202). The allowable range is stored in advance in the storage unit 270. For example, the allowable range is stored as a range within a radius r centered on the current position.

[0058] The initial range setting unit 240 generates an initial range using the information on the current position and the information on the allowable range (step S2203), and then stores the generated initial range in the storage unit 270 (step S2204).

[0059] Next, when the initial range is stored in storage unit 270, authentication key generation and registration unit 250 generates an authentication key from the initial range (step S2205). Here, for example, the authentication key is generated by encrypting the initial range according to a predetermined encryption algorithm.

[0060] Authentication key generation and registration unit 250 stores the generated authentication key in storage unit 270 and external storage device 350 (step S2206), and ends the process. Note that when storing in external storage device 350, it is stored via external storage control unit 280. After storing, a message may be output requesting the user to remove external storage device 350.

[0061] [Login authentication control process] Next, the flow of the login authentication control process by the login control unit 220, which is started in step S2105 above, will be described. Fig. 7 shows the processing flow of the login authentication control process of this embodiment. Note that when the login authentication control process starts, the login authentication function of the SOHO router 200 is disabled.

[0062] The login control unit 220 first acquires the current location (step S2301). The login control unit 220 acquires the current location, for example, from the location acquisition unit 210. Alternatively, the login control unit 220 instructs the location acquisition unit 210 to acquire location information, which is then used as the current location.

[0063] The login control unit 220 determines (step S2302) whether the acquired current location is within the initial range stored in the storage unit 270. If it is within the initial range (S2302; Yes), the login control unit 220 enables the login authentication function (step S2306) and ends the process.

[0064] On the other hand, if the current location is outside the initial range (S2302; No), the login control unit 220 determines whether the external storage device 350 is connected (step S2303). If it is not connected, the login authentication function remains disabled and the process ends. Whether the external storage device 350 is connected is confirmed via the external storage control unit 280. Before determining whether the external storage device 350 is connected, a message prompting the user to connect the external storage device 350 may be output. The determination may be made after a predetermined period of time has elapsed since the message was output.

[0065] On the other hand, if the external storage device 350 is connected (S2302; Yes), the login control unit 220 determines whether the external authentication key can be acquired from the external storage device 350 (step S2304). If the external authentication key cannot be acquired (S2304; No), the process ends. Note that if the external authentication key cannot be acquired, this includes cases where the storage area of ​​the external storage device 350 cannot be accessed and cases where the external authentication key is not stored in the external storage device 350.

[0066] If the external authentication key is acquired (S2304; Yes), the login control unit 220 determines whether the external authentication key matches the internal authentication key stored in the storage unit 270 (step S2305). If they do not match (S2305; No), the process ends.

[0067] On the other hand, if the two match (S2305; Yes), the login control unit 220 proceeds to step S2306 and enables the login authentication function.

[0068] As described above, the SOHO router 200 of this embodiment has the same configuration as the first embodiment, and therefore provides the same effects as the first embodiment.

[0069] Furthermore, according to this embodiment, even if the current location is outside the initial range, the authentication key can be used to determine the validity of access to the SOHO router 200. Therefore, even if location information cannot be obtained in an environment with poor GPS signal strength, for example, as long as the user possesses the external storage device 350 that stores a valid authentication key, the login sequence for changing the setting information of the SOHO router 200 is enabled.

[0070] This makes it possible to prevent unexpected setting changes and leakage of setting information due to theft of the device, regardless of the environment.

[0071] Therefore, according to this embodiment, the security of the SOHO router 200 is improved.

[0072] <Variation 1> In the above-described embodiments, the position acquisition unit 210 is always operating. However, this is not limiting. For example, the position acquisition function of the position acquisition unit 210 may be selectable between enabled and disabled except when the initial range is set.

[0073] The login control unit 220 may be configured to execute the login authentication control process only when the position acquisition function is enabled. The flow of the process by the login control unit 220 when a login request is received in this case is shown in FIG.

[0074] As shown in the figure, when login control unit 220 receives a login request, it first determines whether or not the position acquisition function is enabled (step S3101). If the function is enabled, it executes the login authentication control process of steps S2301 to S2306. On the other hand, if the function is not enabled, login control unit 220 enables the login authentication function and ends the process.

[0075] The state in which the location acquisition function is disabled includes, for example, a state in which the location acquisition unit 210 is not functioning, and a state in which the SOHO router 200 does not have a location acquisition function.

[0076] The above-described function makes it possible to apply the techniques of the above-described embodiments to a SOHO router 200 that does not have a location acquisition function or a SOHO router 200 that is placed in an environment with poor satellite radio wave conditions, thereby improving convenience. However, conversely, to further improve security, the login authentication function may be configured not to be enabled when the location acquisition function is not enabled.

[0077] <Variation 2> The SOHO router 200 may also have an alarm output function. The alarm is output in response to an instruction from the login control unit 220, for example.

[0078] Specifically, for example, in the above-described access control process or login authentication control process, if the current location is not within the initial range, the login control unit 220 issues an alarm output instruction. Also, if the external authentication key and the internal authentication key do not match, an alarm output instruction may be issued. Furthermore, after the SOHO router 200 is relocated, the current location may be acquired when the power is turned back on, and if the current location is not within the initial range, an alarm output instruction may be issued.

[0079] The alarm may be, for example, a lamp, a speaker, or the like provided on the SOHO router 200, and the lamp may be lit, or a sound or voice message may be output from the speaker. Alternatively, the alarm may be configured to be notified by email or SMS (Short Message Service) via the mobile communication network 110 (and the Internet 120). In this case, information such as the address of the notification destination is registered in advance in the storage unit 270 or the like.

[0080] The alarm may be configured to be output if the external storage device 350 is not removed from the SOHO router 200 within a predetermined time after the authentication key is stored in the external storage device 350. In this case, the authentication key generation and registration unit 250 receives a signal from the external storage control unit 280 and instructs it to output an alarm.

[0081] This makes it possible to prompt the user to remove the external storage device 350 from the main body of the SOHO router 200 after the authentication key has been stored in the external storage device 350 .

[0082] <Variation 3> In the above embodiment, the initial position is acquired, and the initial range is an area of ​​radius r centered on the initial position, or an area of ​​a predetermined width or length centered on the initial position (center of gravity). However, this is not limiting. For example, if the SOHO router 200 has information on the layout of each room in a building, the initial range may be the range of a room that includes the initial position. In this case, in addition to satellite positioning, other sensors such as a barometric sensor may be provided to acquire more detailed location information including altitude.

[0083] The initial range may be set by the user. The user may set it by, for example, inputting an address or inputting the range numerically. The allowable range may also be set by the user. For example, it may be linked to map information.

[0084] <Variation 4> Note that when an initial range setting request is received, login authentication may be performed. For example, when an initial range setting request is received via setting information change screen 410, login screen 420 may be displayed to perform login authentication.

[0085] <Variation 5> In addition, in the above-described embodiments and modifications, the login authentication function of the SOHO router 200 is disabled by default, but this is not limiting. For example, the login authentication function may be configured to be enabled or disabled depending on the result of the login authentication control process.

[0086] <Variation 6> In the above embodiments and modifications, the communication device is described as an example of the SOHO router 200, but the communication device is not limited to this. Any device that can be installed in any location and that holds setting information that can be changed on-site may be used, such as a general router or a relay device such as a switching hub.

[0087] [Hardware configuration] The SOHO router 200 of each of the above embodiments may be realized, for example, by a general-purpose information processing device. The general-purpose information processing device may include, for example, a CPU (Central Processing Unit) 191, a main storage device (memory) 192, an auxiliary storage device 193, a communication I / F 194, an expansion I / F 195, and a positioning signal receiver 196, all of which are interconnected by an internal bus, as shown in FIG. 9 . The general-purpose information processing device may also include a speaker 197 and a lamp 198.

[0088] The CPU 191 realizes the above functions and controls the entire device by, for example, loading a program stored in the auxiliary storage device 193 into the main storage device 192 and executing it. Note that the CPU 191 may be replaced by one or more processors such as an MPU (Micro Processing Unit).

[0089] The main storage device 192 is a memory such as a RAM (Random Access Memory), and is a work area used by the CPU 191 when processing programs executed by the SOHO router 200.

[0090] The auxiliary storage device 193 is, for example, a read-only memory (ROM), a hard disk drive (HDD), or a solid state drive (SSD). The auxiliary storage device 193 stores various programs executed by the SOHO router 200. In each of the above embodiments and / or modifications, the storage unit 270 may be constructed on the auxiliary storage device 193. The auxiliary storage device 193 may include a storage medium such as a flexible disk, a hard disk, an optical disk, a CD-ROM, a CD-R, a magnetic tape, a nonvolatile memory card, or a DVD.

[0091] The programs stored in the auxiliary storage device 193 can be provided as program products recorded on a non-transitory computer-readable recording medium. The auxiliary storage device 193 can be used to store various programs recorded on a non-transitory computer-readable recording medium for the medium to long term.

[0092] The communication I / F 194 is an interface for inputting and outputting signals and data via wired or wireless communication. In this embodiment, the communication I / F 194 includes a communication network interface for connecting to the mobile communication network 110 and a LAN interface such as Ethernet or wireless LAN.

[0093] The communication network interface is an interface that connects to a WAN (Wide Area Network). The SOHO router 200 connects to a nearby base station from the communication network interface via the mobile communication network 110, and then connects to the Internet 120. If the input / output device 310 that functions as a management console is located remotely, it may connect to the SOHO router 200 via the communication network interface using a communication protocol such as telnet, SSH (Secure Shell), or http. The user updates setting information via this input / output device 310. The input / output device 310 also transmits initial range setting requests and login requests.

[0094] The LAN interface is connected to an input / output device 310 that functions as a management console, etc. For example, the LAN interface may be connected to the SOHO router 200 via a wireless LAN such as Wi-Fi (registered trademark).

[0095] The expansion I / F 195 is an interface for connecting an input device, an external storage device 350, etc. For example, an input / output device 310 that functions as a management console may be connected. In this embodiment, for example, a USB (Universal Serial Bus) interface may be used. A USB memory may be connected as the external storage device 350 via this expansion I / F 195.

[0096] The positioning signal receiver 196 receives positioning signals. For example, it is configured with a GPS receiver or the like. The GPS receiver receives signals from GPS satellites and detects the position. Note that the positioning signals are not limited to signals from GPS satellites. Radio waves from a GNSS (Global Navigation Satellite System), which is a positioning satellite system including GPS, may also be received and processed. Signals from various other positioning satellites and radio signals for positioning may also be used.

[0097] The speaker 197 outputs signals such as audio data from the SOHO router 200. In this embodiment, for example, an alarm sound, an alarm message, etc. The original data is stored in the storage unit 270 in advance.

[0098] The lamp 198 outputs light. For example, it is made up of an LED or the like. In this embodiment, it emits light as an alarm.

[0099] Each function of the SOHO router 200 is realized by the CPU 191 loading a program stored in the auxiliary storage device 193 into the main storage device 192 and executing the program.

[0100] Note that the hardware configuration of SOHO router 200 is not limited to this. Furthermore, each function (server) of each device may be implemented, for example, by an integrated circuit (IC) dedicated to each process, an application specific integrated circuit (ASIC), a system on chip (SOC), a field programmable gate array (FPGA), or the like.

[0101] In addition, a program for realizing each of the above functions of each device can be recorded on a computer-readable storage medium. The storage medium can be a non-transitory medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present invention can also be embodied as a computer program product.

[0102] In the process flow used in the above explanation, multiple steps (processes) are described in order, but the order in which each step is performed is not limited to the order described. For example, the order of the steps shown in the figure can be changed to the extent that the content is not affected, such as performing each process in parallel.

[0103] Although the embodiments and modifications of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments and can be modified in various ways that would be understandable to a person skilled in the art. Each embodiment and modification can be combined with other embodiments as appropriate. Furthermore, for example, the network configurations and element configurations shown in the drawings are examples intended to aid in understanding the present invention, and the present disclosure is not limited to the configurations shown in these drawings.

[0104] Finally, preferred embodiments of the present disclosure will be summarized. Some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes. (Appendix 1) The communication device a position acquisition unit that acquires a current position of the device using a positioning system; a login control unit that enables a login authentication function based on the current location; a setting information control unit that executes a login authentication sequence when the login authentication function is enabled, and allows an authenticated user to access setting information stored in the device itself; The login control unit enables the login authentication function when the current location is within a preset initial range. (Appendix 2) 2. The communication device according to claim 1, further comprising an initial range setting unit that generates and sets the initial range; When the initial range setting unit receives an initial range setting request from a user, it preferably acquires the current position at the time of acceptance as the initial position, and generates the initial range by adding a predetermined allowable range to the acquired initial position. (Appendix 3) 3. The communication device according to claim 1, an authentication key generation unit that encrypts the initial range to generate an authentication key; an authentication key registration unit that stores the authentication key in a storage unit included in the communication device and in an external storage device that is a detachable external storage device, When the current location is outside the initial range, it is desirable that the login control unit compares the authentication key stored in the memory unit with the authentication key stored in the external storage device, and if they match, activates the login authentication function. (Appendix 4) 4. The communication device according to claim 3, It is desirable that the login control unit does not enable the login authentication function if the current location is outside the initial range, if the external storage device is not connected, or if the authentication key cannot be obtained from the external storage device. (Appendix 5) 5. The communication device according to claim 1, the location acquisition unit is set to either enabled or disabled, It is preferable that the login control unit enables the login authentication function when the position acquisition unit is set to be disabled. (Appendix 6) 6. The communication device according to any one of Supplementary Note 1 to 5, It is preferable that the login control unit disables the login authentication function after the initial range is set. (Appendix 7) 7. The communication device according to claim 1, It is desirable that the login control unit executes a process of enabling the login authentication function in response to a login request from a user. (Appendix 8) 8. The communication device according to claim 1, The positioning system is preferably a satellite positioning system using an artificial satellite. (Appendix 9) The access control method is The computer of the communication device If the current location of the communication device is within a pre-registered initial range, the login authentication function is enabled; If the login authentication function is enabled, execute a login authentication sequence; A user who is authenticated in the login authentication sequence is permitted to access the setting information in the communication device. (Appendix 10) The program is The computer of the communication device a step of activating a login authentication function when the current location of the communication device is within a pre-registered initial range; If the login authentication function is enabled, executing a login authentication sequence; A procedure is executed to permit a user authenticated in the login authentication sequence to access setting information in the communication device. (Appendix 11) 4. The communication device according to claim 3, It is desirable that the login control unit prompts the user to remove the external storage device after storing the authentication key in the external storage device. (Appendix 12) 12. The communication device according to claim 3, The login control unit may prompt the user to reconnect the external storage device when the current location is outside the initial range. (Appendix 13) 3. The communication device according to claim 2, It is preferable that the initial range setting unit executes a login authentication sequence when it receives an initial range setting request from a user, and generates the initial range if the user is authenticated. In addition, the forms of Supplements 9 and 10 can be expanded into the forms of Supplements 2-8 and 11-13, just like Supplement 1.

[0105] The disclosures of the above-mentioned patent documents, etc. are incorporated herein by reference. Modifications and adjustments of the embodiments and variations are possible within the scope of this disclosure (including the claims), and further based on its basic technical concept. Furthermore, various combinations and selections of the various disclosed elements (including each element of each claim, each element of each embodiment or variation, each element of each drawing, etc.) are possible within the scope of this disclosure. In other words, this disclosure naturally includes various modifications and alterations that would be possible by a person skilled in the art in accordance with the entire disclosure, including the claims, and the technical concept. In particular, with regard to the numerical ranges described herein, any numerical value or subrange included within the range should be construed as being specifically described, even if not otherwise specified. [Explanation of symbols]

[0106] 100: communication system, 110: mobile communication network, 120: Internet, 130: satellite group, 191: CPU, 192: main memory device, 193: auxiliary memory device, 194: communication I / F, 195: expansion I / F, 196: positioning signal receiver, 197: speaker, 198: lamp, 200: SOHO router, 210: location acquisition unit, 220: login control unit, 230: setting information control unit, 240: initial range setting unit, 250: authentication key generation and registration unit, 260: reception unit, 270: storage unit, 280: external storage control unit, 290: router unit, 310: Input / output device, 350: External storage device, 410: setting information change screen, 411: initial range setting request acceptance section, 412: login request acceptance section, 413: termination acceptance section, 420: login screen, 421: input acceptance area

Claims

1. a position acquisition unit that acquires a current position of the device using a positioning system; a login control unit that enables a login authentication function based on the current location; a setting information control unit that executes a login authentication sequence when the login authentication function is enabled, and allows an authenticated user to access setting information stored in the device itself; The login control unit enables the login authentication function when the current location is within a preset initial range.

2. 2. The communication device according to claim 1, further comprising an initial range setting unit that generates and sets the initial range; When the initial range setting unit receives an initial range setting request from a user, it acquires the current position at the time of acceptance as an initial position, and generates the initial range by adding a predetermined allowable range to the acquired initial position.

3. 2. The communication device according to claim 1, an authentication key generation unit that encrypts the initial range to generate an authentication key; an authentication key registration unit that stores the authentication key in a storage unit included in the communication device and in an external storage device that is a detachable external storage device, When the current location is outside the initial range, the login control unit compares the authentication key stored in the memory unit with the authentication key stored in the external storage device, and when they match, enables the login authentication function.

4. 4. The communication device according to claim 3, The login control unit does not enable the login authentication function when the current location is outside the initial range, when the external storage device is not connected, and when the authentication key cannot be obtained from the external storage device.

5. 2. The communication device according to claim 1, the location acquisition unit is set to either enabled or disabled, The login control unit enables the login authentication function when the location acquisition unit is set to be disabled.

6. 3. The communication device according to claim 2, The login control unit disables the login authentication function after the initial range is set.

7. 2. The communication device according to claim 1, The login control unit executes a process of enabling the login authentication function in response to a login request from a user.

8. 2. The communication device according to claim 1, A communication device, wherein the positioning system is a satellite positioning system using an artificial satellite.

9. The computer of the communication device If the current location of the communication device is within a pre-registered initial range, the login authentication function is enabled; If the login authentication function is enabled, execute a login authentication sequence; The access control method permits a user authenticated in the login authentication sequence to access setting information in the communication device.

10. The computer of the communication device a step of activating a login authentication function when the current location of the communication device is within a pre-registered initial range; If the login authentication function is enabled, executing a login authentication sequence; A program that executes a procedure for permitting a user authenticated in the login authentication sequence to access setting information in the communication device.

Citation Information

Patent Citations

  • Wireless router and location information notifying method

    JP2012169807A