Security device
The security device enables secure and efficient wireless communication during maintenance by using a dongle to control connection status, addressing inefficiencies and procedural risks in cable-based updates.
Patent Information
- Application Number
- JP2023079263
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2026-08-26
AI Technical Summary
Existing security devices require cable connection for software updates, leading to inefficiencies and risks of procedural errors, such as cable tripping and forgetting to reinsert memory cards.
A security device equipped with a first wireless communication unit that enables communication only when a dongle is connected, using a detection unit to manage the connection status and prevent unauthorized access.
Ensures secure and efficient wireless communication during maintenance, preventing accidental connections and ensuring the wireless function is disabled after use, thereby enhancing security and work efficiency.
Smart Images

Figure 2026136424000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a security device.
Background Art
[0002] Devices that require high reliability need to analyze the operation of the device to maintain reliability. The operation analysis is performed by analyzing the operation log recorded by the device. At this time, the log data is stored in a removable memory card and is sequentially updated with the latest data.
[0003] The operation analysis of the device is carried out by the operator inserting the memory card inserted into the device into a maintenance PC (Personal Computer). Or, it is implemented by connecting the maintenance PC to the device by wire and downloading the log data.
[0004] In Patent Document 1, as a software update system, update device, and update method for flexibly updating the software of a vehicle system composed of a plurality of platforms, the following software update system, update device, and update method are disclosed. "In a software update system, a software update device 10 includes a first update control unit 140 that performs software update of a first software unit of a vehicle and a second update control unit 150 that performs software update of a second software unit. The first update control unit has a first sequence control unit 141 that transmits a control command for the first platform. The second update control unit simulates the second software unit as a software unit on the first platform, and has a pseudo-update execution unit 151 that controls the software update of the second software unit based on receiving a control command for the second software unit simulated on the first platform."
Prior Art Documents
Patent Documents
[0005] [Patent Document 1] Japanese Patent Publication No. 2022-144814 [Overview of the project] [Problems that the invention aims to solve]
[0006] However, rewriting the security device's software requires connecting the device to the maintenance PC with a cable, which presents problems in terms of work efficiency, such as the need to protect the cable to prevent tripping during the process. Furthermore, there is a risk of procedural errors, such as forgetting to put the memory card back into the device after removing it.
[0007] Therefore, the present invention provides a security device that can communicate wirelessly only during maintenance work. [Means for solving the problem]
[0008] To solve the above problems, one representative security device of the present invention comprises a first wireless communication unit for wireless communication, a connection unit for connecting a dongle, and a detection unit for detecting when the dongle is connected to the connection unit, wherein the first wireless communication unit can only perform wireless communication when the dongle is connected. [Effects of the Invention]
[0009] According to the present invention, a security device can be made capable of wireless communication only during maintenance work. [Brief explanation of the drawing]
[0010] [Figure 1] Figure 1 shows an example of the configuration of the security system according to the first embodiment. [Figure 2] Figure 2 is a perspective view of a modified security system of the first embodiment. [Figure 3] Figure 3 shows an example of the configuration of the security system according to the second embodiment. [Figure 4]Figure 4 shows an example of the configuration of the security system according to the third embodiment. [Modes for carrying out the invention]
[0011] The present invention will be described below with reference to the drawings, in the form of embodiments. However, the present invention is not limited to these embodiments. Furthermore, in the drawings, identical parts are denoted by the same reference numerals. When there are multiple components with the same or similar function, they may be described using the same symbol but with different subscripts. Furthermore, when it is not necessary to distinguish between these multiple components, the subscripts may be omitted in the description. The positions, sizes, shapes, and ranges of the components shown in the drawings may not represent their actual positions, sizes, shapes, and ranges in order to facilitate understanding of the invention. Therefore, the present invention is not necessarily limited to the positions, sizes, shapes, and ranges disclosed in the drawings.
[0012] [First Embodiment] First, with reference to Figure 1, the security system 100 of the first embodiment will be described. Figure 1 shows an example of the configuration of security system 100. The security system 100 detects when a dongle is connected to the security device and enables wireless communication, and detects when the dongle is removed from the security device and disables wireless communication. The security system 100 mainly consists of a security device 2, a dongle 3, and a maintenance PC 4.
[0013] <Security device> Security device 2 is a device that requires high reliability. To maintain this high reliability, security device 2 stores an operation log that records its actions. The operation logs stored in security device 2 are transferred to the maintenance terminal and analyzed during maintenance work. The security device 2 mainly includes a control unit 21, a first storage unit 22, a first wireless communication unit 23, and a dongle connection connector 24.
[0014] The control unit 21 controls the enabling or disabling of the wireless communication function of the first wireless communication unit 23 based on the connection state of the dongle 3. Here, the control unit 21 also functions as a detection unit that detects that the dongle 3 is connected to the dongle connection connector 24. When the control unit 21 detects that the dongle 3 is connected to the dongle connection connector 24, for example, it enables the function of the first wireless communication unit 23 by supplying power. When the control unit 21 detects that the dongle 3 is removed from the dongle connection connector 24, for example, it disables the function of the first wireless communication unit 23 by stopping the power supply. The control unit 21 transfers the log information stored in the first storage unit 22 and updates the software of the security device 2 according to the instructions of the wirelessly connected maintenance PC 4.
[0015] The first storage unit 22 stores the operation log of the security device 2. The first storage unit 22 is, for example, a flash memory. The operation log stored in the first storage unit 22 is, for example, a log indicating the normal operation of the security device 2, a log indicating the error content, and a log of the signals input to and output from the security device 2. The operation log stored in the first storage unit 22 is transferred to the maintenance PC 4 via the first wireless communication unit 23.
[0016] The first wireless communication unit 23 performs wireless communication with the maintenance PC 4. In this embodiment, in the security system 100, in order to transmit and receive data between the security device 2 and the maintenance PC 4, Wi-fi, which is a wireless LAN compliant with the IEEE802.11 standard, is used.
[0017] Wireless LANs connect to the internet by having access points or wireless LAN routers, which act as the base stations for wireless devices connected to the internet network, transmit beacons, and then interconnecting PCs, smartphones, and other devices with built-in wireless LAN client devices via wireless lines.
[0018] The first wireless communication unit 23 is, for example, a wireless access point. The first wireless communication unit 23 connects any wireless LAN client devices to each other. The first wireless communication unit 23 has registered an SSID (Service Set ID) for identifying its own access point, and a password used for connection authentication of wireless LAN client devices. The first wireless communication unit 23 transmits the SSID on a beacon so that the second wireless communication unit 41, which will be described later, can identify the connection target.
[0019] The first wireless communication unit 23 may be included in something other than the security device 2. For example, it may be included in the dongle 3. This allows the security device 2 to only be enabled when the dongle 3 is physically connected and its wireless communication function is active.
[0020] The dongle connector 24 is the connection point to which the dongle 3 is connected. When dongle 3 is connected to security device 2, terminals A and B of the dongle connection connector 24 and security device connection connector 31 (described later) are interconnected. The terminal I of the interconnected dongle connector 24 is pulled up by the resistor 25, bringing it to GND potential. This allows the control unit 21 to detect the connection of the dongle 3.
[0021] <Dongle> The dongle 3 is a device connected to the security device 2 and functions as a physical switch to change the state of the wireless communication function of the first wireless communication unit 23.
[0022] In the security system 100, when the maintenance PC 4 attempts to communicate wirelessly with the security device 2, if the SSID corresponding to the access point of the first wireless communication unit 23 does not match the transmitted password, connection authentication will fail and the wireless connection will be rejected. However, there is a risk that connection authentication between unintended devices and the security device 2 may be established due to accidental matching of passwords transmitted to the first wireless communication unit 23 or through brute-force attacks.
[0023] To prevent such situations and improve security strength, it is desirable to disable the wireless communication function except when performing maintenance on security device 2. This eliminates the risk of connection authentication being established even if a password is accidentally matched or a brute-force attack occurs, because the wireless communication function itself is disabled.
[0024] In the security system 100, the wireless communication function can be easily implemented by providing a button switch on the security device 2 for selecting whether to enable or disable the wireless communication function. However, with this procedure, it can be difficult to easily determine from the outside whether the wireless communication function, which is set by the enable / disable selection switch, is enabled or disabled. This could lead to situations where the worker forgets to disable the wireless communication function selection switch after completing maintenance work. Therefore, by using dongle 3 as a switch to control the physical wireless communication function, the operator can easily determine the enabled / disabled state from its appearance after completing maintenance work.
[0025] Dongle 3 mainly includes a security device connection connector 31. When the security device connection connector 31 is connected to the security device 2, it is interconnected with terminals A and B of the dongle connection connector 24. This allows the control unit 21 to detect the connection of the dongle 3 and enable the wireless communication function.
[0026] When dongle 3 is disconnected from security device 2, the interconnection between terminals A and B of dongle connection connector 24 is released. This allows control unit 21 to detect the disconnection of dongle 3 and disable the wireless communication function.
[0027] In this embodiment, the dongle 3 is shown to detect the connection by short-circuiting terminals A and B, but other methods may be used to detect the connection. For example, the dongle 3 may use a USB memory stick and the insertion / removal detection method of the USB standard may be used.
[0028] <Maintenance PC> Maintenance PC4 is a maintenance terminal used for maintaining security device 2. The maintenance PC 4 can wirelessly connect to the security device 2, allowing it to download the operation logs of the security device 2 stored in the first storage unit 22 and update the software of the security device 2. Maintenance PC4 mainly includes the second wireless communication unit 41.
[0029] The second wireless communication unit 41 is a wireless communication device that is paired with the first wireless communication unit. The second wireless communication unit 41 attempts to authenticate the wireless communication connection to the access point of the first wireless communication unit 23. This enables wireless communication to be established with the security device 2.
[0030] The second wireless communication unit 41 identifies the first wireless communication unit 23 to connect to, for example, by receiving a beacon transmitted by the first wireless communication unit 23. The second wireless communication unit 41 then transmits the SSID and its connection password to the identified first wireless communication unit 23 to establish connection authentication.
[0031] As described above, according to this embodiment, the enable / disable status of the wireless communication function can be controlled according to the connection status between the security device 2 and the dongle 3. In other words, maintenance workers can visually understand the status of the wireless communication function of security device 2. This improves security by preventing workers from forgetting to disable wireless communication functions after maintenance work.
[0032] [Differentiation] Next, the security system 300 will be described with reference to Figure 2. The security system 300 differs from the first embodiment in that the security device 2 is housed in the outer casing 6. Figure 2 is a perspective view of security system 300. The security system 300 mainly consists of a security device 2, a dongle 3, a maintenance PC 4, and an outer casing 6.
[0033] <Exterior> The outer casing 6 is a packaging section that protects the security device 2 by housing it inside. The exterior 6 mainly includes the housing portion 61 and the lid portion 62. The outer casing 6 is a box-shaped package in which a lid 62 that can be opened and closed is attached to one of the sides of the housing 61. The lid 62 opens in a double-door manner, with the two lids 62 rotating from the center to the left and right, each pivoting on the left and right ends of the housing 61; however, other methods may also be used. The security device 2 is housed in the housing 61 such that the dongle connection connector 24 faces the lid 62. In other words, it is housed in such a way that the dongle connection connector 24 is visible when the lid 62 is opened.
[0034] The lid 62 is locked when the dongle 3 is connected to the security device 2. In other words, when the security device 2 detects the connection of the dongle 3, the lid 62 cannot rotate around its axis and therefore cannot be closed.
[0035] This allows the worker to determine whether the wireless communication function of the security device 2 is enabled or disabled after maintenance work, not only by visual determination through the connection of the dongle 3, but also by tactile determination through the movement of the lid 62.
[0036] Furthermore, the lid portion 62 may be sized so that when the dongle 3 is connected to the dongle connection connector 24, the dongle 3 body protrudes from the outer casing 6. As a result, if the dongle 3 is forgotten to be removed after maintenance work is completed, when attempting to close the lid 62, the dongle 3 will act like a tensioning rod, preventing it from being closed, and this can be determined by both sight and touch.
[0037] [Second Embodiment] Next, with reference to Figure 3, the security system 200 of the second embodiment will be described. The security system 200 of the second embodiment differs from the first embodiment in that the security device 2 is included in the on-board device 5. Figure 3 shows an example of the configuration of security system 200. In the following description, components that are the same as or equivalent to those in the first embodiment described above will be denoted by the same reference numerals, and their descriptions will be simplified or omitted. The security system 200 mainly consists of an on-board device 5, a dongle 3, and a maintenance PC 4.
[0038] <On-vehicle equipment> The on-board device 5 is a device mounted on the transport equipment and operates the transport equipment based on the driver's driving operations. The transportation equipment operated by the on-board device 5 may be, for example, a train, but it may also be other vehicles. For example, it may be an airplane, an automobile, etc. In this embodiment, the on-board device 5 is described as a device for operating the transport equipment, but it is not limited to transport equipment; it may be a vehicle operated by a driver. The onboard equipment 5 mainly includes the driving device 51 and the security device 2.
[0039] The driving device 51 reflects the driver's driving operations to the transport equipment. The operating device 51 mainly includes an operating signal input unit 52 and an operating signal output unit 53.
[0040] The driving operation signal input unit 52 converts the driving operations performed by the driver into control signals and transmits them to the control unit 21. The driving operation signal input unit 52 is, for example, an interface such as a master controller handle. The driving operation signal input unit 52 does not have to be an interface, as long as it converts the operation performed by the driver into a control signal and transmits it to the control unit 21. For example, it may be a device that converts the operation of an interface different from the driving operation signal input unit 52 operated by the driver into a control signal.
[0041] The operation signal input unit 52 transmits the operation content and the converted control signal to the first storage unit 22 via the control unit 21. The first storage unit 22 stores the received driving operation details and control signals as an operation log. The operation log stored in the first memory unit 22 is transferred to the maintenance PC 4 when the dongle 3 is connected to the dongle connection connector 24.
[0042] The operation signal output unit 53 is a power mechanism that outputs operation signals based on control signals received from the control unit 21. The driving operation signal output unit 53 is, for example, a running gear. The driving operation signal output unit 53 does not have to be a running gear, as long as it can transmit driving force and braking force to the drive unit such as wheels of the transport equipment based on the control signal received from the control unit 21. For example, it may be a device that relays the control signal received from the control unit 21 to the drive unit.
[0043] As described above, according to this embodiment, in addition to the security device 2, the operation logs of devices other than the security device 2 can be transferred. In other words, it can transfer operation logs of signals input from an external source and operation logs of signals output to an external source. This allows for the transfer of not only the operation logs of security device 2, but also the operation logs of devices connected to security device 2.
[0044] [Third Embodiment] Next, with reference to Figure 4, the security system 400 of the third embodiment will be described. The security system 400 of the third embodiment differs from the first embodiment and others in that the dongle has a storage unit, and the security device and the maintenance PC update the connection authentication settings based on the settings stored in the storage unit. Figure 4 shows an example of the configuration of security system 400. In the following description, components that are the same as or equivalent to those in the first embodiment described above will be denoted by the same reference numerals, and their descriptions will be simplified or omitted.
[0045] The security system 400 establishes wireless communication by updating the settings applied to the security device through rewriting the settings stored in the dongle using a maintenance PC. The security system 400 mainly consists of a security device 402, a dongle 403, and a maintenance PC 404.
[0046] The security device 402 establishes wireless connection authentication based on the settings received from the dongle 403. The security device 402 mainly includes a control unit 21, a first storage unit 22, a first wireless communication unit 423, and a dongle connection connector 24.
[0047] The first wireless communication unit 423 establishes wireless communication with the maintenance PC 404 based on the settings received from the dongle 403. The first wireless communication unit 423 mainly includes a wireless control unit 426, an initial setting memory unit 427, and a wireless circuit 428.
[0048] The wireless control unit 426 controls the first wireless communication unit 423. The wireless control unit 426 controls the wireless communication performed by the wireless circuit 428 based on the set value. The wireless control unit 426 transmits the set value received from the dongle 403 to the initial setting storage unit 427. The first wireless communication unit 423 stores the setting values received from the dongle 403 in the initial setting storage unit 427. The settings stored in the initial setting memory unit 427 are, for example, settings necessary for establishing connection authentication, such as the SSID and password.
[0049] The first wireless communication unit 423 updates the wireless communication connection authentication to the new setting value when a new setting value is stored in the initial setting memory unit 427, for example, by restarting. The wireless control unit 426 controls the wireless circuit 428 to authenticate the wireless communication connection using the updated settings. The wireless circuit 428 performs wireless communication to authenticate the connection based on the updated settings.
[0050] The dongle 403 is a device that stores the settings for wireless communication connection authentication. The dongle 403 functions as a medium for transmitting configuration values from the maintenance PC 404 to the security device 402. For example, dongle 403 first connects to maintenance PC 404, where its stored settings are overwritten with new settings. Next, it connects to security device 402 and transmits the new settings. The dongle 403 mainly includes a security device connection connector 31 and a second storage unit 432.
[0051] The second storage unit 432 stores the settings for wireless communication connection authentication. The settings stored in the second memory unit 432 are, for example, the SSID and password. When dongle 403 is connected to maintenance PC 404, the settings can be overwritten with new values by operations performed on maintenance PC 404. When the dongle 403 is connected to the security device 2, it transmits the information to the initial setting storage unit 427.
[0052] Maintenance PC 404 rewrites the settings of dongle 403 to the new settings. Based on the new settings, maintenance PC 404 establishes wireless communication with security device 402. The maintenance PC 404 mainly includes a second wireless communication unit 41, a dongle connection connector 42 for connecting to a dongle 403, and a control unit 43 for controlling the maintenance PC 404.
[0053] As described above, according to this embodiment, the security device 402 and the maintenance PC 404 can attempt to authenticate the wireless communication connection based on the new configuration information via the dongle 3. In other words, the information used for wireless connection authentication can be updated with each authentication. This improves security by preventing attackers from using the authentication information to communicate wirelessly, even if they decipher it.
[0054] Furthermore, the present invention can also take the following forms. (Aspect 1) The first radio communication unit conducts radio communications, The connector for connecting the dongle, The system includes a detection unit that detects when the dongle is connected to the connection portion, The first wireless communication unit can perform wireless communication only when the dongle is connected. Security device. (Aspect 2) A security device according to Embodiment 1, The control unit includes a control unit that enables or disables the wireless communication of the first wireless communication unit based on the connection status of the dongle detected by the detection unit. Security device. (Aspect 3) A security device according to embodiment 1 or 2, The first wireless communication unit communicates wirelessly with the second wireless communication unit included in the maintenance terminal. Characterized by Security device. (Aspect 4) The security device described in embodiment 3, It is equipped with a first storage unit that stores operation logs, The first wireless communication unit transfers the operation log to the maintenance terminal. Characterized by Security device. (Appendix 5) A security device according to embodiment 3 or 4, The first wireless communication unit communicates wirelessly with a plurality of maintenance terminals. Characterized by Security device. (Aspect 6) A security device according to any one of embodiments 3 to 5, The dongle includes a second storage unit that stores the wireless communication connection authentication information, The first wireless communication unit performs the wireless communication that performs connection authentication based on the connection authentication information. Characterized by Security device. (Aspect 7) A security device according to any one of embodiments 1 to 6, An input unit that converts the operation content into a control signal, It comprises an output unit that outputs based on the aforementioned control signal, The first wireless communication unit transmits the operation log of the input unit or the output unit via wireless communication. Characterized by Security device. (Pattern 8) A security device according to any one of embodiments 1 to 7, The connection part is provided with a cover that protects the connection part, The lid is characterized in that it locks open and closed when the dongle is connected to the connection portion. Security device. [Explanation of Symbols]
[0055] 100, 200, 300, 400 security systems 2,402 Security Devices 21 Control Unit 22 1st memory section 23. 1st Radio Communication Section 24 Dongle connection connectors 25 resistor 426 Wireless Control Unit 427 Initial setting storage section 428 Radio circuit 3,403 dongles 31 Security device connection connector 432 2nd memory section 4, 404 Maintenance PC 41. Second Radio Communication Section 42 Dongle connection connectors 43 Control Unit 5 Onboard equipment 51 Operating device 52 Operation signal input section 53 Operation signal output section 6. Exterior 61. Enclosure 62 Lid
Claims
1. The first radio communication unit conducts radio communications, The connector for connecting the dongle, The system includes a detection unit that detects when the dongle is connected to the connection portion, The first wireless communication unit can perform wireless communication only when the dongle is connected. Security device.
2. A security device according to claim 1, The control unit includes a control unit that enables or disables the wireless communication of the first wireless communication unit based on the connection status of the dongle detected by the detection unit. Security device.
3. A security device according to claim 1, The first wireless communication unit communicates wirelessly with the second wireless communication unit included in the maintenance terminal. Characterized by Security device.
4. The security device according to claim 3, It is equipped with a first storage unit that stores operation logs, The first wireless communication unit transfers the operation log to the maintenance terminal. Characterized by Security device.
5. The security device according to claim 3, The first wireless communication unit communicates wirelessly with a plurality of maintenance terminals. Characterized by Security device.
6. The security device according to claim 3, The dongle includes a second storage unit that stores the wireless communication connection authentication information, The first wireless communication unit performs the wireless communication that performs connection authentication based on the connection authentication information. Characterized by Security device.
7. A security device according to claim 1, An input unit that converts the operation content into a control signal, It comprises an output unit that outputs based on the aforementioned control signal, The first wireless communication unit transmits the operation log of the input unit or the output unit via wireless communication. Characterized by Security device.
8. A security device according to claim 1, The connection part is provided with a cover that protects the connection part, The lid is characterized in that it locks open and closed when the dongle is connected to the connection portion. Security device.
Citation Information
Patent Citations
Software update device, software update system, and software update method
JP2022144814A