Monitoring system

The monitoring system facilitates secure remote monitoring from various locations through a closed network authenticated by identification information, using mobile communication networks with grouped device collection and dynamic port numbers, addressing the limitations of single-location restrictions.

JP2026061367APending Publication Date: 2026-04-09TAKASAGO THERMAL ENG CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing remote monitoring systems restrict connections to a single location, preventing monitoring from unauthorized persons but also hinder remote access by authorized personnel outside that location.

Method used

A monitoring system utilizing a closed network established via a mobile communication network with authentication using first and second identification information, allowing secure remote monitoring from various locations, with features like grouped device information collection, fixed IP addresses, and dynamic port numbers to enhance security.

Benefits of technology

Enables secure remote monitoring from multiple locations by limiting access to authorized terminals, minimizing impact on data collection servers, and preventing unauthorized access, thus ensuring robust and flexible monitoring capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026061367000001_ABST
    Figure 2026061367000001_ABST
Patent Text Reader

Abstract

We provide a monitoring system that enables secure remote monitoring from various locations. [Solution] This monitoring system comprises: a collection unit that collects information of the monitored equipment; a wireless communication unit including a first identification device that stores first identification information used for authentication to a mobile communication network; and an output unit that, when a closed network is established via the mobile communication network through authentication using the first identification information and the second identification information between the collection unit and an external terminal including a second identification device that stores second identification information used for authentication to the mobile communication network, outputs a viewing screen to the external terminal via the closed network in response to a display request from the external terminal via the closed network, allowing the collected information to be viewed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a monitoring system.

Background Art

[0002] A remote monitoring method for monitoring devices in a remote location by establishing a remote connection has been proposed (see Patent Documents 1-3).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0004] The remote connection used for remote monitoring is preferably secure. Therefore, in order to prohibit connections from unauthorized persons etc., the source of the remote connection may be limited to the building etc. of the operator who conducts the monitoring business. However, if the source of the connection is limited in this way, for example, a monitoring worker who is out on business cannot perform remote monitoring from the location where they are away.

[0005] One aspect of the disclosed technology aims to provide a monitoring system that can securely realize remote monitoring from various locations.

Means for Solving the Problems

[0006] One aspect of the disclosed technology is exemplified by the following monitoring system: This monitoring system comprises a collection unit that collects information of a monitored device, a wireless communication unit including a first identification device that stores first identification information used for authentication to a mobile communication network, and an external terminal including a second identification device that stores second identification information used for authentication to the mobile communication network, wherein when a closed network is established via the mobile communication network through authentication using the first and second identification information, the output unit outputs a viewing screen to the external terminal via the closed network in response to a display request from the external terminal via the closed network, allowing the collected information to be viewed.

[0007] According to this monitoring system, the display request from the external terminal is sent via the closed network through the mobile communication network by authentication using the first and second identification information. Since the external terminals that can establish the closed network are limited to those that include the second identification device in which the second identification information is stored, eavesdropping on communications via the closed network by third-party terminals that do not possess the first or second identification information is suppressed. Furthermore, since the closed network is established via the mobile communication network, the external terminals may be located in various locations as long as they are within the range where the mobile communication network can be used. Therefore, this monitoring system enables secure remote monitoring from various locations.

[0008] The monitoring system may also have the following features: The monitored devices are grouped according to predetermined conditions, and each of these groups has a collection server that collects the information of the monitored devices, and the collection unit collects the information from the collection server. With a monitoring system having such features, the external terminal does not need to access the collection server. Even if errors or other issues occur, the impact on the aforementioned data collection server will be minimized.

[0009] The monitoring system may further have the following features: A mobile router may be connected to the external terminal, and the mobile router may be assigned a fixed IP address by a mobile communications carrier operating the mobile communications network. The output unit may output the browsing screen to the external terminal when the fixed IP address matches a pre-stored IP address. Since the output destination of the browsing screen is restricted to the fixed IP address, even if a third party's terminal infiltrates the closed network, access to the browsing screen by that third party's terminal will be suppressed.

[0010] The monitoring system may also have the following features: The port number that receives the above-mentioned display request is a first port number that has been changed from the initial value of the monitoring system, and the above-mentioned display request is made by specifying the first port number. By changing the port number from the initial value, the possibility of the above-mentioned display request from a third party being mistakenly accepted is suppressed.

[0011] The monitoring system may further have the following features: It has multiple locations where the above-mentioned collection unit, wireless communication unit, and output unit are located, the first identification device is set with different identification information for each location, and the external terminal has a second identification device that stores the second identification information corresponding to the first identification information stored in the first identification device of the wireless communication unit located at each location. With a monitoring system having such features, a single external terminal can establish the above-mentioned closed network between itself and the wireless communication units at multiple locations by switching or using the second identification devices simultaneously.

[0012] The monitoring system may further have the following features: It has multiple locations where the above-mentioned collection unit, wireless communication unit, and output unit are located; the closed network is established using the first identification information, the second identification information, and a third authentication information set for each location; and when the external terminal receives a selection of the location to connect to, it receives a specification of the third authentication information for the selected location and establishes the closed network with the selected location. With a monitoring system having such features, a single external terminal can establish the closed network with the wireless communication units of multiple locations by switching the third authentication information. Furthermore, since it is the third authentication information that is switched, the closed network can be established with the wireless communication units of multiple locations without having multiple second identification devices. [Effects of the Invention]

[0013] According to the disclosed technology, secure remote monitoring from various locations can be achieved. [Brief explanation of the drawing]

[0014] [Figure 1] Figure 1 shows an example of a remote monitoring system according to an embodiment. [Figure 2] Figure 2 shows an example of the hardware configuration of a monitoring terminal according to the embodiment. [Figure 3] Figure 3 shows an example of the hardware configuration of a remote terminal according to this embodiment. [Figure 4] Figure 4 shows an example of the hardware configuration of a wireless router according to this embodiment. [Figure 5] Figure 5 shows an example of the hardware configuration of a mobile router according to the embodiment. [Figure 6] Figure 6 is a schematic diagram illustrating a mobile private network service provided by a mobile network operator in an embodiment. [Figure 7] Figure 7 shows an example of a processing block for a monitoring terminal according to an embodiment. [Figure 8]FIG. 8 is a diagram showing an example of a list screen output by an output unit in an embodiment. [Figure 9] FIG. 9 is a diagram showing an example of a processing block of a remote terminal according to an embodiment. [Figure 10] FIG. 10 is a diagram illustrating a schematic configuration for a remote terminal to monitor different companies in an embodiment. [Figure 11] FIG. 11 is a diagram showing an example of a processing flow of information collection from a central monitoring server by a monitoring terminal according to an embodiment. [Figure 12] FIG. 12 is a diagram showing an example of a processing flow of a remote terminal according to an embodiment. [Figure 13] FIG. 13 is a diagram illustrating a schematic configuration for a remote terminal to monitor different companies in the first modification example. [Figure 14] FIG. 14 is a diagram showing an example of a processing block of a remote terminal according to the first modification example. [Figure 15] FIG. 15 is a diagram showing an example of a management table stored in a management unit in the first modification example. [Figure 16] FIG. 16 is a diagram showing an example of a profile selection screen output by a selection unit to a display in the first modification example. [Figure 17] FIG. 17 is a diagram showing an example of a site list screen output by an RDP connection unit in the first modification example. MODE FOR CARRYING OUT THE INVENTION

[0015] <Embodiment> Hereinafter, an embodiment will be described with reference to the drawings. FIG. 1 is a diagram showing an example of a remote monitoring system 1 according to an embodiment. The remote monitoring system 1 is a system that realizes remote monitoring by workers W1 at sites P1 and P2 existing in a remote location. The sites P1 and P2 are, for example, buildings such as buildings and factories. In addition, in the present embodiment, the objects of remote monitoring are air conditioning equipment, electrical equipment, machine tools, etc. arranged in buildings and factories.

[0016] Site P1 is equipped with wireless routers 12, hubs 13, 22, and 32, a monitoring terminal 11, central monitoring servers 23 and 33, and monitored networks 24 and 34. Worker W1 remotely connects to the wireless router 12 at Site P1 using a mobile router 52 connected to a remote terminal 51, and remotely monitors Site P1. Site P2 is equipped with the same equipment as Site P1, and worker W1 can remotely monitor Site P2 by connecting to the wireless router at Site P2.

[0017] The wireless router 12 is a router that accepts connections from the mobile router 52 using a mobile communication network. By inserting a SIM card C12 provided by the mobile communication carrier 800, the wireless router 12 can perform wireless communication using the mobile communication network of the mobile communication carrier 800. The wireless router 12 is also connected to the monitoring terminal 11 via a hub 13. The wireless router 12 is an example of a "wireless communication unit". The SIM card C12 is an example of a "first identification device".

[0018] The monitored network 24 is a network where a group of monitored devices, monitored by the central monitoring server 23, are located. The central monitoring server 23 is an information processing device that collects information about the group of monitored devices located in the monitored network 24. The central monitoring server 23 and the monitored network 24 are connected to the hub 22.

[0019] The monitored network 34 is a network in which a group of monitored devices, monitored by the central monitoring server 33, are located. The central monitoring server 33 is located in the monitored network 34. This is an information processing device that collects information from a group of monitored devices. The central monitoring server 33 and the monitored network 34 are connected to the hub 32.

[0020] The central monitoring servers 23 and 33 may collect information on the monitored devices located in the monitored networks 24 and 34 by means of, for example, Simple Network Management Protocol (SNMP) information collection, PING status monitoring, etc. In addition, when collecting information on the monitored devices, for example, if the monitored devices located in the monitored networks 24 and 34 are air conditioning equipment, information such as airflow and temperature of each air conditioning unit may be collected. If the monitored devices located in the monitored networks 24 and 34 are electrical equipment, the status of lights such as on and off will be collected. In this embodiment, for example, it is assumed that air conditioning equipment is located in the monitored network 24 and electrical equipment is located in the monitored network 34. The central monitoring servers 23 and 33 store the collected information on the monitored devices in their storage units.

[0021] The monitored networks 24 and 34 are each home to monitored devices manufactured by different companies. The central monitoring server 23 and monitored networks 24 belong to subnet 20. The central monitoring server 33 and monitored networks 34 belong to subnet 30. In other words, the central monitoring server 23 and monitored networks 24 are connected to different subnets than the central monitoring server 33 and monitored networks 34. Subnets 20 and 30 are examples of "groups".

[0022] The monitoring terminal 11 is an information processing device located at site P1. The monitoring terminal 11 is connected to the central monitoring server 23 via the hub 22. The monitoring terminal 11 is also connected to the central monitoring server 33 via the hub 32. The monitoring terminal 11 accesses information collected by the central monitoring servers 23 and 33 and displays a management screen that lists the status of the monitored devices located in the monitored networks 24 and 34. The monitoring terminal 11 is an example of a "collection unit".

[0023] The mobile router 52 is a router that connects to the wireless router 12 using a mobile communication network. By inserting a SIM card C52 provided by the mobile communication carrier 800, the mobile router 52 can perform wireless communication using the mobile communication network of the mobile communication carrier 800. The wireless router 12 and the mobile router 52 are connected, for example, by a mobile closed network (closed IP network) service that uses the wireless communication environment provided by the mobile communication carrier 800. The SIM card C52 is an example of a "second identification device".

[0024] The remote terminal 51 is a portable information processing device operated by worker W1. The remote terminal 51 is used by worker W1, for example, when worker W1 is away from work. The remote terminal 51 is connected to a mobile router 52, for example, by a Universal Serial Bus (USB) cable. The remote terminal 51 is connected to the monitoring terminal 11 via a communication link L1 established between the wireless router 12 and the mobile router 52. The remote terminal 51 is an example of an "external terminal". The communication link L1 is an example of a "closed network". In this embodiment, the remote terminal 51 is a portable information processing device, but the remote terminal 51 may also be a non-portable information processing device, for example, a desktop type.

[0025] <Hardware Configuration> Figure 2 shows an example of the hardware configuration of the monitoring terminal 11 according to the embodiment. The monitoring terminal 11 consists of a Central Processing Unit (CPU) 111, a main memory unit 112, an auxiliary memory unit 113, a display 114, and a Local Area Network. The system includes LAN port 115, LAN port 116, LAN port 117, and connection bus B1. The CPU 111, main memory 112, auxiliary memory 113, display 114, LAN port 115, LAN port 116, and LAN port 117 are interconnected by connection bus B1.

[0026] The CPU 111 is also called a microprocessor unit (MPU) or processor. The CPU 111 is not limited to a single processor and may be in a multiprocessor configuration. Furthermore, a single CPU 111 connected via a single socket may have a multicore configuration. At least a portion of the processing performed by the CPU 111 may be performed by other processors, such as dedicated processors like a Digital Signal Processor (DSP), Graphics Processing Unit (GPU), numerical processor, vector processor, or image processing processor. Also, at least a portion of the processing performed by the CPU 111 may be performed by integrated circuits (ICs) or other digital circuits. Furthermore, at least a portion of the CPU 111 may include analog circuits. Integrated circuits include Large Scale Integrated Circuits (LSIs), Application Specific Integrated Circuits (ASICs), and Programmable Logic Devices (PLDs). PLDs include, for example, Field-Programmable Gate Arrays (FPGAs). The CPU 111 may be a combination of a processor and integrated circuits. The combination is called, for example, a microcontroller unit (MCU), system-on-a-chip (SoC), system LSI, or chipset. In the monitoring terminal 11, the CPU 111 deploys the program stored in the auxiliary storage unit 113 to the work area of ​​the main memory unit 112 and controls peripheral devices through program execution. This allows the monitoring terminal 11 to perform processing that matches a predetermined purpose. The main memory unit 112 and the auxiliary storage unit 113 are recording media that can be read by the CPU 111.

[0027] The main memory unit 112 is exemplified as a memory unit that is directly accessed by the CPU 111. The main memory unit 112 includes Random Access Memory (RAM) and Read Only Memory (ROM).

[0028] The auxiliary storage unit 113 stores various programs and data on a recording medium in a read-write manner. The auxiliary storage unit 113 is also called an external storage device. The auxiliary storage unit 113 stores the operating system (OS), various programs, various tables, etc. The OS includes a communication interface program that exchanges data with external devices connected via the communication unit 104. External devices include, for example, other information processing devices and external storage devices connected by a computer network. The auxiliary storage unit 113 may also be, for example, part of a cloud system, which is a group of computers on a network.

[0029] The auxiliary storage unit 113 is, for example, an Erasable Programmable ROM (EPROM), a Solid State Drive (SSD), a Hard Disk Drive (HDD), etc. Alternatively, the auxiliary storage unit 113 may be a Compact Disc (CD) drive, a Digital Versatile Disc (DVD) drive, a Blu-ray® Disc (BD) drive, etc.

[0030] The display 114 displays data processed by the CPU 111 and data stored in the main memory 112. The display 114 is, for example, a Liquid Crystal Display (LCD), Plasma Display Panel (PDP), or These are electroluminescence (EL) panels and organic EL panels.

[0031] LAN port 115 is the interface to which hub 13 is connected. LAN port 116 is the interface to which hub 22 is connected. LAN port 117 is the interface to which hub 32 is connected. LAN port 116 is configured to be connected to subnet 20. LAN port 117 is configured to be connected to subnet 30. In addition, LAN port 115 is configured to be on a different subnet than both LAN port 116 and LAN port 117. That is, LAN ports 115, 116, and 117 are configured to be on different subnets.

[0032] The monitoring terminal 11 may further include an input unit that receives, for example, operation instructions from a user. Examples of such input units include keyboards, pointing devices, touch panels, accelerometers, or voice input devices.

[0033] Figure 3 shows an example of the hardware configuration of a remote terminal 51 according to an embodiment. The remote terminal 51 includes a CPU 511, a main memory unit 512, an auxiliary memory unit 513, a display 514, a connection terminal 515, and a connection bus B2. The CPU 511, main memory unit 512, auxiliary memory unit 513, display 514, and connection bus B2 are the same as those of the monitoring terminal 11 (CPU 111, main memory unit 112, auxiliary memory unit 113, display 114, and connection bus B1), so their description is omitted.

[0034] The connection terminal 515 is the connection terminal to which the mobile router 52 is connected. The connection terminal 515 is, for example, a connection terminal compliant with the USB standard. The mobile router 52 is connected to the connection terminal 515, for example, via a USB cable.

[0035] Figure 4 shows an example of the hardware configuration of the wireless router 12 according to the embodiment. The wireless router 12 includes a CPU 121, a main memory unit 122, an auxiliary memory unit 123, a WAN communication unit 124, a slot 125, a LAN port 126, and a connection bus B3. The CPU 121, main memory unit 122, auxiliary memory unit 123, and connection bus B3 are the same as those of the monitoring terminal 11 (CPU 111, main memory unit 112, auxiliary memory unit 113, and connection bus B1), so their explanation is omitted.

[0036] The WAN communication unit 124 is a communication unit that connects to the Internet via a mobile communication network. The WAN communication unit 124 includes, for example, an antenna, and uses this antenna to wirelessly connect to the mobile communication network.

[0037] Slot 125 is the slot into which the SIM card C12 is inserted. When the SIM card C12 is inserted into slot 125, the wireless router 12 becomes capable of communication using the mobile communication network provided by the mobile communication carrier that provides the SIM card C12. LAN port 126 is the interface to which the hub 13 is connected.

[0038] Figure 5 shows an example of the hardware configuration of a mobile router 52 according to the embodiment. The mobile router 52 includes a CPU 521, a main memory unit 522, an auxiliary memory unit 523, a WAN communication unit 524, a slot 525, a connection terminal 526, and a connection bus B4. The CPU 521, main memory unit 522, auxiliary memory unit 523, and WAN communication unit 524 are the same as the CPU 121, main memory unit 122, auxiliary memory unit 123, WAN communication unit 124, and connection bus B3 of the wireless router 12, so their explanation is omitted.

[0039] Slot 525 is the slot into which SIM card C52 is inserted. When SIM card C52 is inserted into slot 525, the mobile router 52 This enables communication using the mobile communication network provided by the mobile communication carrier that offers the service.

[0040] The connection terminal 526 is a connection terminal to which the remote terminal 51 is connected. The connection terminal 526 is, for example, a connection terminal compliant with the USB standard. The remote terminal 51 is connected to the connection terminal 526, for example, via a USB cable.

[0041] <Mobile private network service> Next, we will describe the mobile private network service provided by the mobile network operator 800. Figure 6 is a schematic diagram illustrating the mobile private network service provided by the mobile network operator 800 in an embodiment. In the mobile private network service, access points AP1 and AP2 for the private network provided by the mobile network operator 800 are used. Access points AP1 and AP2 are connected to the core network CN1 of the mobile network operator 800.

[0042] SIM cards C12 and C52 each contain the following information: International Mobile Identification information, exemplified by Subscriber Identity (IMSI), is stored. The identification information stored in SIM cards C12 and C52, respectively, identifies, for example, subscribers to the mobile network provided by the mobile network operator 800. The identification information stored in SIM cards C12 and C52, respectively, is also used, for example, for authentication and access control within the mobile network provided by the mobile network operator 800. The identification information stored in SIM card C12 is an example of "first identification information." The identification information stored in SIM card C52 is an example of "second identification information."

[0043] A wireless link L11 is established between the wireless router 12, into which SIM card C12 is inserted, and access point AP1, for example, upon successful authentication using the identification information stored in SIM card C12. Similarly, a wireless link L21 is established between the mobile router 52, into which SIM card C52 is inserted, and access point AP2, for example, upon successful authentication using the identification information stored in SIM card C52. As a result, a communication link L1 is established, including wireless links L11, L21, and the core network CN1. Thus, the communication link L1 is established by the access points AP1 and AP2 for the closed network and the core network CN1 of the mobile network operator 800. Therefore, the communication link L1 is established without going through the internet.

[0044] Since authentication is performed using physical devices, SIM cards C12 and C52, when establishing communication link L1, establishing communication link L1 is easy. Furthermore, unless SIM cards C12 and C52 are stolen, it is difficult for a third party to establish communication link L1. In addition, since communication link L1 does not use the internet, it is more difficult for a third party on the internet to eavesdrop on communications over communication link L1 than with a Virtual Private Network (VPN) connection. Therefore, by using the mobile closed network service provided by the mobile network operator 800, the monitoring terminal 11 and the remote terminal 51 can be connected via a communication link L1 that is easy to establish and secure.

[0045] Furthermore, in the mobile closed network service provided by the mobile network operator 800, a fixed IP address may be assigned to each of the wireless router 12 into which SIM card C12 is inserted and the mobile router 52 into which SIM card C52 is inserted. The fixed IP address assigned here may be, for example, a private IP address.

[0046] In the example in Figure 6, the wireless router 12 is assigned the private IP address "172.19.xx.11" as a static IP address. The mobile router 52 is assigned the private IP address "172.19.xx.22" as a static IP address. It will be assigned.

[0047] When communication between the wireless router 12 and the remote terminal 51 via communication link L1 is performed using private IP addresses, it is easy to place the IP address assigned to the remote terminal 51 and the IP address assigned to the monitoring terminal 11 within the same subnet. As a result, there is no need to perform address translation using Network Address Translation (NAT) or the like in communication between the remote terminal 51 and the monitoring terminal 11, making it easier to configure communication control between the remote terminal 51 and the monitoring terminal 11.

[0048] <Settings for Wireless Router 12> In the wireless router 12, filtering services using IP addresses and port numbers are configured. For example, connections to the wireless router 12 from the outside (e.g., communication link L1) are restricted to the mobile router 52. Such restrictions are implemented, for example, using a fixed IP address assigned to the wireless router 12 by the mobile network operator 800. In other words, the wireless router 12 rejects connections from IP addresses different from the fixed IP address assigned to it by the mobile network operator 800.

[0049] Furthermore, the wireless router 12 restricts the port numbers allowed for connections from the remote terminal 51 to those used by the service that the monitoring terminal 11 accepts connections from the remote terminal 51. For example, if the monitoring terminal 11 accepts connections to the remote terminal 51 via a remote desktop service, only the port numbers used by that remote desktop service are permitted. As a result of these restrictions on IP addresses and port numbers, connections to the wireless router 12 that do not meet the IP address and port number combinations that the monitoring terminal 11 allows connections to from the remote terminal 51 are prohibited.

[0050] <Processing block> Figure 7 shows an example of a processing block of a monitoring terminal 11 according to an embodiment. The monitoring terminal 11 includes a data collection unit 1101, an output unit 1102, a firewall unit 1103, and an RDP unit 1104. The monitoring terminal 11 performs processing as each of its respective units, such as the data collection unit 1101, output unit 1102, firewall unit 1103, and RDP unit 1104, by having the CPU 111 execute a computer program that has been loaded into the main memory unit 112.

[0051] The collection unit 1101 accesses the central monitoring servers 23 and 33 to collect information on the monitored networks 24 and 34 that has been collected and stored by the central monitoring servers 23 and 33. The collection unit 1101 stores the collected information, for example, in the auxiliary storage unit 113. The collection unit 1101 is an example of a "collection unit".

[0052] The output unit 1102 outputs the information collected by the collection unit 1101 to the display 114. Figure 8 shows an example of a list screen G1102 output by the output unit 1102 in this embodiment. On the list screen G1102, the air conditioning equipment information I1 collected from the central monitoring server 23 and the electrical equipment information I2 collected from the central monitoring server 33 are displayed in a list. Since the information is collected from the central monitoring servers 23 and 33 by the collection unit 1101, the list screen G1102 displays a list of information on monitored equipment groups connected to different networks of monitored networks 24 and 34.

[0053] The FW unit 1103 is a firewall that restricts network connections to the monitoring terminal 11. For example, the FW unit 1103 restricts the source of connections to the monitoring terminal 11 to fixed IP addresses assigned to the mobile router 52 by the mobile communication carrier 800, and restricts the port numbers allowed for network connections to port numbers used by the RDP unit 1104. In other words, the FW unit 1103 is assigned to the mobile router 52. The firewall unit 1103 rejects connections to the monitoring terminal 11 from IP addresses other than the assigned fixed IP address. In addition, the firewall unit 1103 rejects connections to port numbers other than those used by the RDP unit 1104.

[0054] The RDP unit 1104 accepts remote desktop connections from the remote terminal 51 via the mobile router 52. When the RDP unit 1104 accepts a remote desktop connection from the remote terminal 51, it forwards the screen output to the display 114 to the remote terminal 51. Here, the RDP unit 1104 may change the port number for accepting remote desktop connections from its initial value. If the port number for accepting remote desktop connections is changed from its initial value, the port number permitted by the FW unit 1103 should also be the changed port number.

[0055] Figure 9 shows an example of a processing block of a remote terminal 51 according to an embodiment. The remote terminal 51 includes an RDP connection unit 5101 and an operation unit 5102. The remote terminal 51 performs processing as each part of the remote terminal 51, such as the RDP connection unit 5101 and the operation unit 5102, by having the CPU 511 execute a computer program that has been loaded into the main memory unit 512 in an executable format.

[0056] The RDP connection unit 5101 requests a remote desktop connection to the monitoring terminal 11 via the communication link L1. The RDP connection unit 5101 requests a remote desktop connection to the monitoring terminal 11 by specifying the IP address of the monitoring terminal 11 and the port number of the remote desktop service that the monitoring terminal 11 has exposed. If the port number that the monitoring terminal 11 accepts remote desktop connections on has been changed from its initial value, the RDP connection unit 5101 requests a remote desktop connection by specifying the changed port number. The port number used for the remote desktop connection to the monitoring terminal 11 may, for example, be stored in the auxiliary storage unit 513 in advance. Alternatively, the port number used for the remote desktop connection to the monitoring terminal 11 may be specified, for example, by worker W1. Once the remote desktop connection from the remote terminal 51 to the monitoring terminal 11 is established by the RDP connection unit 5101, for example, the list screen G1102 output to the display 114 of the monitoring terminal 11 is displayed on the display 514 of the remote terminal 51.

[0057] The operation unit 5102 accepts input from a keyboard or other means to the list screen G1102 displayed on the display 514 via the remote desktop connection established by the RDP connection unit 5101. The operation unit 5102 switches the information displayed on the list screen G1102 by accepting an operation from, for example, worker W1.

[0058] Note that sites P1 and P2 are not limited to locations of the same company, but may belong to different companies. In other words, the remote terminal 51 may monitor the information systems of different companies collectively. Figure 10 is a diagram illustrating a schematic configuration in which different companies are monitored by the remote terminal 51 in an embodiment. In the example in Figure 10, the information systems of companies A, B, C, and D are remotely monitored by the remote terminal 51.

[0059] The information systems of companies A, B, C, and D are each equipped with the same equipment as site P1. Specifically, each of the information systems of companies A, B, C, and D is equipped with wireless routers 12, hubs 13, 22, and 32, monitoring terminals 11, central monitoring servers 23 and 33, and monitored networks 24 and 34. Furthermore, each of the wireless routers 12 of companies A, B, C, and D is assigned a different IP address by, for example, a mobile communications carrier 800.

[0060] The mobile router 52 has a SIM card C52 that connects to the wireless router 12 of company A. Four SIM cards C52 are provided: one SIM card C52 connected to company B's wireless router 12, one SIM card C52 connected to company C's wireless router 12, and one SIM card C52 connected to company D's wireless router 12. In other words, the mobile router 52 is equipped with SIM cards C52 that store identification information corresponding to the identification information stored in each company's SIM card C12 for authentication on the mobile communication network provided by the mobile communication carrier 800.

[0061] The remote terminal 51 can switch the connection destination using the mobile private network service between the wireless routers 12 of company A, company B, company C, and company D by changing the SIM card C52 inserted into the mobile router 52. For example, when connecting to company A's wireless router 12, SIM card C52A is inserted into the mobile router 52; when connecting to company B's wireless router 12, SIM card C52B is inserted into the mobile router 52; when connecting to company C's wireless router 12, SIM card C52C is inserted into the mobile router 52; and when connecting to company D's wireless router 12, SIM card C52D is inserted into the mobile router 52. Therefore, a single remote terminal 51 can monitor the information systems of multiple companies.

[0062] If the mobile router 52 has four slots 525, then four SIM cards C52 may be inserted into the slots 525 of the mobile router 52: SIM card C52A connected to company A's wireless router 12, SIM card C52B connected to company B's wireless router 12, SIM card C52C connected to company C's wireless router 12, and SIM card C52D connected to company D's wireless router 12. With this configuration, the remote terminal 51 can monitor the information systems of companies A, B, C, and D without the hassle of changing the SIM cards C52 inserted into the mobile router 52.

[0063] Here, companies A, B, C, and D are all different companies. Therefore, it is undesirable for the information systems of companies A, B, C, and D to be interconnected. In such cases, the mobile router 52 is configured to prohibit access from one company's information system to another company's information system. For example, packets originating from the IP address of company A's wireless router 12 are prohibited from being sent to the wireless routers 12 of companies B, C, and D.

[0064] With this configuration, access from one company's information system to another company's information system is prohibited, while the remote terminal 51 can access the information systems of companies A, B, C, and D. In other words, it is possible to monitor the information systems of multiple companies using a single remote terminal 51 while ensuring the security of information systems between companies. Furthermore, since it is not necessary to prepare a separate remote terminal for each of companies A, B, C, and D, it is possible to monitor the information systems of multiple companies with a simple configuration.

[0065] <Processing Flow> Figure 11 shows an example of the processing flow for information collection from central monitoring servers 23 and 33 by the monitoring terminal 11 according to this embodiment. The following description will refer to Figure 11 to explain an example of the processing flow for information collection from central monitoring servers 23 and 33 by the monitoring terminal 11.

[0066] In step S1, the collection unit 1101 collects information on the monitored devices located in the monitored networks 24 and 34 from the central monitoring servers 23 and 33. In step S2, the collection unit 1101 stores the information collected in step S1 in the auxiliary storage unit 113. The process from step S1 to step S2 is repeated at predetermined intervals.

[0067] Figure 12 shows an example of the processing flow of the remote terminal 51 according to this embodiment. Referring to Figure 12, an example of the processing flow of the remote terminal 51 will be explained.

[0068] In step S11, the mobile router 52 is connected to the remote terminal 51. Then, a communication link L1 is established between the mobile router 52 and the wireless router 12.

[0069] In step S12, the RDP connection unit 5101 requests a remote desktop connection to the remote monitoring system 1 via the communication link L1 established in step S11, and a remote desktop connection is established between the remote terminal 51 and the monitoring terminal 11. The RDP connection unit 5101 may perform authentication using, for example, a username and password, and the remote desktop connection may only be established if the authentication is successful.

[0070] In step S13, the display 514 of the remote terminal 51 displays the list screen G1102 from the display 114 of the monitoring terminal 11 via the remote desktop connection established in step S12. The operation unit 5102 changes or updates the information output to the list screen G1102 displayed on the display 514 in response to the operation of worker W1.

[0071] <Effects of the Embodiment> In this embodiment, communication between the monitoring terminal 11 and the remote terminal 51 is performed via a communication link L1. The communication link L1 is restricted by identification information stored in the SIM cards C12 and C52, respectively. That is, the communication link L1 is established only between the wireless router 12 and the mobile router 52, which have SIM cards C12 and C52 provided by the mobile network operator 800. Therefore, access to the monitoring terminal 11 by a third party via the communication link L1 is suppressed. Furthermore, since the communication link L1 is established by the mobile network operator 800, even when worker W1 is away from the premises, the communication link L1 can be established and a remote desktop connection can be made from the remote terminal 51 to the monitoring terminal 11. In other words, according to this embodiment, remote monitoring from various locations can be securely realized.

[0072] In this embodiment, the remote terminal 51 collects information gathered by the central monitoring servers 23 and 33, and the monitoring terminal 11 collects this information. The remote terminal 51 then establishes a remote desktop connection to the monitoring terminal 11. Therefore, even if worker W1 makes an error on the remote terminal 51, the impact on the central monitoring servers 23 and 33 is minimized.

[0073] In this embodiment, the communication link L1 between the monitoring terminal 11 and the remote terminal 51 is realized by a mobile private network service provided by the mobile communications carrier 800. Since the communication link L1 is established by the mobile private network service using access points AP1 and AP2 for the private network and the core network CN1 of the mobile communications carrier 800, it is more robust against intrusion by third parties than a VPN connection. Therefore, according to this embodiment, remote monitoring of the monitored devices can be achieved in a more secure environment than a VPN connection.

[0074] In this embodiment, subnets are divided according to the manufacturer of the monitored equipment, such as subnets 20 and 30. Therefore, the influence of subnets where equipment from other manufacturers is located on the operation of each subnet where equipment from a particular manufacturer is located is suppressed.

[0075] In this embodiment, the source of connections to the monitoring terminal 11 is restricted to fixed IP addresses assigned to the mobile router 52 by the mobile communications carrier 800. Therefore, even if a third-party terminal infiltrates the communication link L1, it is prevented from establishing a remote desktop connection to the monitoring terminal 11 or viewing the list screen G1102.

[0076] In this embodiment, the port number on which the monitoring terminal 11 accepts remote desktop connections is changed from its initial value. Therefore, even if a third party requests a remote desktop connection to the monitoring terminal 11 via communication link L1, they cannot easily establish a remote desktop connection because the port number has been changed.

[0077] <First variation> In the embodiments described above, SIM cards C52A, C52B, C52C, and C52D were individually prepared for connection to each of the wireless routers 12 of companies A, B, C, and D. In the first modified example, a configuration in which a single SIM card C52 is used to connect to the wireless routers 12 of multiple companies will be described. Components identical to those in the embodiments will be denoted by the same reference numerals, and their descriptions will be omitted. The first modified example will be described below with reference to the drawings.

[0078] Figure 13 illustrates a schematic configuration in the first modified example in which a remote terminal 51 monitors different companies. In the example in Figure 13, the information systems of companies A, B, C, and D are remotely monitored by the remote terminal 51. Here, the wireless routers 12 and mobile routers 52 of companies A, B, C, and D are each assigned IP addresses within the same subnet by the mobile communications carrier 800.

[0079] The first modification differs from the embodiment in that it connects to the wireless routers 12 of companies A, B, C, and D using a single SIM card C52E. In the first modification, in order to enable connection to the wireless routers 12 of companies A, B, C, and D using a single SIM card C52E, the remote terminal 51 stores the profiles used to connect to the wireless routers 12 of companies A, B, C, and D.

[0080] Figure 14 shows an example of the processing block of a remote terminal 51A according to the first modified example. The remote terminal 51A differs from the remote terminal 51 according to the embodiment in that it includes an RDP connection unit 5101A instead of an RDP connection unit 5101, and further includes a selection unit 5103 and a management unit 5104.

[0081] The management unit 5104 manages the profiles used to connect to the wireless routers 12 of companies A, B, C, and D, respectively. The management unit 5104 is built in, for example, the auxiliary storage unit 513. Figure 15 shows an example of a management table 5105 stored in the management unit 5104 in the first modified example. The management table 5105 has the following items: "Connection Name", "IP Address", "Username", and "Password". The "Connection Name" stores a name that uniquely distinguishes the profile. The connection name can be any name assigned by the user, for example. In the example in Figure 15, the names of companies A, B, C, and D are stored in the "Connection Name" of the management table 5105. The "IP Address" stores the IP addresses assigned to the wireless routers 12 of companies A, B, C, and D by the mobile closed network service provided by the mobile communications carrier 800. The "Username" and "Password" stores the username and password used for authentication when establishing a connection with the wireless router 12, respectively.

[0082] In the management table 5105, each record associated with the "connection name" becomes a profile used to connect to the wireless router 12 of companies A, B, C, and D, respectively. Furthermore, since each profile stores the IP address assigned to the wireless router 12, the profiles are associated with the wireless router 12.

[0083] Returning to Figure 14, the selection unit 5103 accepts the specification of the profile to be used for connection. If one profile is selected, the selection unit 5103 will select the wireless router 12 from among the wireless routers 12 of companies A, B, C, and D that corresponds to the selected profile. A connection may be established between them. Alternatively, the selection unit 5103 may accept the designation of multiple profiles and establish a connection with the wireless router 12 corresponding to each selected profile among the wireless routers 12 of companies A, B, C, and D.

[0084] Figure 16 shows an example of a profile selection screen 5106 output by the selection unit 5103 to the display 514 in the first modified example. The profile selection screen 5106 has a profile frame 5106A that displays information for each profile.

[0085] The profile frame 5106A includes a connection name field 5106B, a connection status field 5106C, and a connect button 5106D. The connection name field 5106B displays the connection name stored in the "Connection Name" field of the management table 5105. The connection status field 5106C displays the connection status with the wireless router 12 corresponding to the profile indicated by the connection name displayed in the connection name field 5106B. For example, the connection status field 5106C displays "Connected" if a connection with the wireless router 12 has been established, and "Not Connected" if a connection with the wireless router 12 has not been established. The connect button 5106D is a button that accepts connection instructions from worker W1. When the connect button 5106D is pressed, a connection is made with the wireless router 12 corresponding to the profile indicated by the connection name displayed in the connection name field 5106B.

[0086] Returning to Figure 14, the RDP connection unit 5101A outputs a site list screen to the display 514, which lists the sites to be monitored by the remote terminal 51A. Figure 17 shows an example of the site list screen G5101 output by the RDP connection unit 5101A in the first modified example. The site list screen G5101 includes a list area R1 and an information display area R2.

[0087] The list area R1 displays a list for selecting the sites to be displayed in the information display area R2. In the example in Figure 17, "All," "Company A," "Company B," "Company C," and "Company D" are displayed as list items. On the site list screen G5101, when any of "All," "Company A," "Company B," "Company C," or "Company D" is selected, the information of the selected site is displayed in the information display area R2. Figure 17 illustrates the state when "All" is selected in the list area R1.

[0088] The information display area R2 displays information about the site selected in the list area R1. In the example in Figure 17, because "All" was selected in the list area R1, the site information display area J1 displaying information about company A, the site information display area J2 displaying information about company B, the site information display area J3 displaying information about company C, and the site information display area J4 displaying information about company D are displayed in the information display area R2. Each of the site information display areas J1, J2, J3, and J4 may, for example, display a reduced version of the list screen G1102 for each respective site. In addition, for sites among company A, company B, company C, and company D that are not connected, "Not Connected" may be displayed in the site information display areas J1, J2, J3, and J4. In the example in Figure 17, "Company C" is in an unconnected state.

[0089] If any of "Company A," "Company B," "Company C," or "Company D" is selected in the list area R1 of the site list screen G5101, the list screen G1102 of the selected site should be displayed in the information display area R2.

[0090] According to the first modification, a single SIM card C52E can be used to connect to the wireless routers 12 of multiple companies, thus reducing the burden of changing SIM cards C52 when monitoring multiple companies. Furthermore, even if the mobile router 52 does not have multiple slots 525, it can connect to multiple sites exemplified by companies A, B, C, and D. The connection between the wireless routers 12 of multiple companies and the mobile router 52 in this manner... This can be easily achieved because each of the wireless routers 12 and mobile routers 52 of multiple companies is assigned an IP address within the same subnet by the mobile communications carrier 800.

[0091] In the first modified example, the authentication information exemplified by the username and password was stored in the management table 5105, but the authentication information does not necessarily have to be stored in the management table 5105. In such a case, the remote terminal 51A only needs to accept the authentication information exemplified by the username and password when the connect button 5106D is pressed on the profile selection screen 5106. The authentication information exemplified by the username and password is an example of the "third authentication information". Selecting a company to connect to on the profile selection screen 5106 and using the username and password stored in the management table 5105, or accepting the input of a username and password, is an example of "accepting the specification of the third authentication information".

[0092] <Other variations> In the embodiments described above, the monitoring terminal 11 and the wireless router 12 were separate devices, but the monitoring terminal 11 may also incorporate the functions of the wireless router 12. That is, the monitoring terminal 11 may be assigned a fixed IP address by the mobile communications carrier 800 by inserting a SIM card C12. By adopting such a configuration, the remote monitoring system 1 can be made simpler. Similarly, the remote terminal 51 may also incorporate the functions of the mobile router 52.

[0093] In the embodiments described above, air conditioning equipment and electrical equipment were mentioned as the group of monitored devices placed in the monitored networks 24 and 34. However, the group of monitored devices placed in the monitored networks 24 and 34 may be other devices. Examples of the group of monitored devices placed in the monitored networks 24 and 34 include various devices such as audio equipment, medical equipment, and machine tools.

[0094] The embodiments and variations disclosed above can be combined in any way. [Explanation of Symbols]

[0095] 1. Remote monitoring system 11. Surveillance terminal 12. Wireless Router 20, 30 subnets 23, 33... Central monitoring server 24, 34 · · Surveillance Network 51, 51A... Remote terminals 52. Mobile Router 111, 121, 511, 521...CPU 112, 122, 512, 522...Main memory 113, 123, 513, 523... Auxiliary storage section 114, 514... Display 115, 116, 117, 126... LAN ports 124, 524 ··WAN Communications Department 125, 525 slots 515, 526... Connection terminals 800 Mobile carriers 1101 ··Collection Department 1102 Output section 1103...FW section 1104...RDP section 5101··RDP connection section 5102...Operation unit 5103...Selection section 5104·Management Department 5105 ··Management Table 5106 ··Profile Selection Screen 5106A ··Profile frame 5106B ··Connection Name Field 5106C ··Connection Status Section 5106D ··Connect button C12, C52 SIM card G1102 ··List screen G5101 ·· Site List Screen I1...Air conditioning equipment information I2. Electrical Equipment Information L1 ··Communication Link P1, P2... Site R1··List area R2...Information display area J1, J2, J3, J4... Site information display area W1 ··Worker

Claims

1. A collection unit that collects information on monitored devices, A wireless communication unit including a first identification device that stores first identification information used for authentication to a mobile communication network, The device includes an output unit that, when a closed network is established via the mobile communication network between the device and an external terminal including a second identification device which stores second identification information used for authentication to the mobile communication network, and the external terminal via the closed network, outputs a viewing screen to the external terminal via the closed network in response to a display request from the external terminal via the closed network, allowing the collected information to be viewed. Monitoring system.

2. The monitored devices are grouped according to predetermined conditions, Each of the aforementioned groups is equipped with a collection server that collects the information of the monitored devices within that group. The collection unit collects the information from the collection server. The monitoring system according to claim 1.

3. A mobile router is connected to the aforementioned external terminal. The aforementioned mobile router is assigned a fixed IP address by the mobile communications carrier operating the aforementioned mobile communications network. The output unit outputs the browsing screen to the external terminal when the fixed IP address matches a pre-stored IP address. The monitoring system according to claim 1.

4. The port number receiving the aforementioned display request is a first port number that has been changed from the initial value of the monitoring system. The aforementioned display request is made by specifying the first port number. The monitoring system according to claim 1.

5. The collection unit, the wireless communication unit, and the output unit are located at multiple locations, The first identification device is configured with different identification information for each location. The external terminal has a second identification device that stores the second identification information corresponding to the first identification information stored in the first identification device, which is located in the wireless communication unit at each of the bases. The monitoring system according to any one of claims 1 to 4.

6. The collection unit, the wireless communication unit, and the output unit are located at multiple locations, The closed network is established using the first identification information, the second identification information, and the third authentication information set for each location. When the external terminal receives the selection of the location to be connected to, it receives the specification of the third authentication information of the selected location and establishes the closed network with the selected location. The monitoring system according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Monitoring / controlling system

    JP2009004987A

  • Remote monitoring system

    JP2024061340A

  • Information processing device, communication device, information processing method, communication method, and communication system

    WO2023002682A1