Security devices and systems
The security device addresses communication failures in cloud-based security systems by storing and re-transmitting report data through alternative networks, ensuring accurate and timely processing of security reports.
Patent Information
- Application Number
- JP2021107479
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-06-29
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-06-29
AI Technical Summary
In security systems that utilize cloud computing, communication failures on the Internet can prevent timely reporting of abnormal events, leading to discrepancies in reporting data and potential double reporting or loss of data.
A security device that forms report data upon detecting an abnormality, transmits it through a first network, and upon determining a failure in that network, stores the data and re-transmits it through a second network. After failure recovery, the device updates the report data with the incoming call time from the second network and re-sends it through the first network.
Ensures that report data is accurately and timely processed, preventing discrepancies and double reporting, and maintaining data integrity even after communication failures are resolved.
Smart Images

Figure 0007675327000001 
Figure 0007675327000002 
Figure 0007675327000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a security device that detects the occurrence of an abnormal event, such as the intrusion of a suspicious person or a fire, and reports the event to a predetermined reporting destination. [Background technology]
[0002] So-called security devices are often installed in offices, schools, commercial facilities, etc., where there are no users at night or on holidays. Security devices are also being used in ordinary homes to ensure safety at night when residents are often out and not at home or are asleep and out of sight. For example, as shown in Fig. 11, security devices 11 installed in various facilities 10 to be guarded are connected to various monitoring sensors (anomaly detection sensors) such as an intrusion sensor SX1 and a fire sensor SX2.
[0003] The intrusion sensor SX1 includes a human presence sensor that uses infrared rays, ultrasonic waves, visible light, etc. to detect the presence of a human, an opening / closing sensor that uses magnetism or acceleration to detect the opening / closing of a door or window, and an impact sensor that detects the impact when a window or door is broken. The fire sensor SX2 includes a smoke sensor that detects smoke and a heat sensor that detects heat. These various monitoring sensors are connected to the sensor input circuit section 12 of the security device 11. The sensor input circuit section 12 of the security device 11 monitors the output signals from each of the monitoring sensors SX1, SX2, ..., and when it detects the occurrence of an abnormality, it reports the occurrence through the wide area network 20 to a predetermined reporting destination, for example, a security destination accommodation device (control device) 31 of a security company 30.
[0004] The wide area network 20 is a communication network such as a general public telephone network, a mobile phone network, or the Internet. In the security company 30, when the guarded accommodation device 31 receives a report from the security device 11 of the security target facility 10, it notifies the monitor 40 by, for example, emitting a sound of a received message. The monitor 40 operates the guarded accommodation device 31 to identify the source of the report and instructs the security guard 50 to be dispatched to the source of the report. This enables the security guard to be quickly dispatched to the security target facility 10 where an abnormality has occurred and to take appropriate action.
[0005] Also, as disclosed in Patent Document 1 described later, an invention has been disclosed relating to a security system that connects security devices to a monitoring center via different networks, the Internet and a public line. In the case of the invention disclosed in Patent Document 1, even if a network failure occurs, an alarm of abnormality detection information is sent to the monitoring center via another communication line, making it possible to quickly respond to abnormalities in the monitored area. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] JP 2006-285645 A Summary of the Invention [Problem to be solved by the invention]
[0007] In recent years, cloud computing, which provides users with the right to use software and hardware as a service over a network, has become widely used. The various data centers and server devices that are provided on the Internet to realize this cloud computing method are called clouds. Clouds provide users with the software and hardware they desire without making them aware of real server devices.
[0008] In security systems, as in the security system disclosed in Patent Document 1, security devices and security company devices are not simply connected via different networks, but a cloud system is used to build the security system. For example, a receiving server device that receives reports from multiple security target facilities and a security server device that notifies the security company of the occurrence of an abnormality based on information from the receiving server device are installed in the cloud. By using a cloud system, a highly reliable large-scale security system can be built without building a large-scale system at the security company.
[0009] In this way, even when a cloud system is used, there is a possibility that a communication failure or the like occurring on the Internet side will prevent the occurrence of an abnormality from being reported at the appropriate time. In this case, the communication failure or the like includes a malfunction of the Internet and a malfunction of the server device as the cloud system. For this reason, in order to take measures for a BCP (Business Continuity Plan), it is necessary to connect the security device and the so-called on-premises server device of the security company through a network other than the Internet. When a communication failure or the like occurs on the Internet side, a report is sent to the on-premises server device of the security company through the other network, and the occurrence of the abnormality is notified to the security destination accommodation device (control device) through the on-premises server device, making it possible to take appropriate measures quickly.
[0010] In this way, in preparation for some kind of failure in a part of the system, to maintain the function of the entire system even after the failure, a standby device is deployed and operated under normal circumstances as a backup. In this way, in a redundant security system that includes a cloud system as a part, let's say that due to a communication failure on the Internet side, the security device reports to the on-premises server device of the security company through a network other than the Internet.
[0011] In this case, after the communication failure on the Internet side is restored, the report data sent to the on-premise server device of the security company via another network must also be resent to the receiving server device of the cloud system. This is because if the receiving server device on the Internet side, which is the main communication system, is not able to manage all report data, discrepancies will occur in the history and appropriate management and operation will be impossible. For this reason, it is possible to resend the report data that could not be sent from the security device to the receiving server device on the Internet side (cloud system), but there is a concern that inconveniences will occur in this case.
[0012] For example, a discrepancy may occur between the arrival time of the report data and the actual handling of the report data. In other words, if the report data is simply resent from the security device to the receiving server device of the cloud system, the actual arrival time at the receiving server device will be the arrival time of the resent report data received by the receiving server device. However, the resent report data has already been sent to the on-premises server device, which is the backup report destination, and the security destination accommodation device (control device) is handling it at the arrival time of the on-premises server device. For this reason, a discrepancy may occur between the report data sent to the receiving server device of the cloud system and the actual handling of the report data sent to the on-premises server device, making it impossible to perform appropriate management.
[0013] In view of the above, the present invention aims to provide a security system that is configured using a cloud system and is redundant, and that prevents inconveniences associated with the re-sending of report data after a communication failure or the like that has occurred on the cloud side is resolved. [Means for solving the problem]
[0014] In order to solve the above problem, the security device of the invention described in claim 1 is: a notification data generating means for generating notification data when an occurrence of an abnormality is detected; a first notification processing means for transmitting the notification data formed by the notification data forming means to a first notification destination through a first network; a fault determination means for determining whether a fault has occurred on the first network side; a first storage means for storing and holding the report data that could not be transmitted to the first report destination as post-failure report data when the fault determination means determines that the fault has occurred; a second notification processing means for transmitting the post-failure notification data stored in the first storage means to a second notification destination through a second network different from the first network; a recovery determination means for determining whether or not the failure occurring on the first network side has been recovered from; a first provision request sending means for sending, when the recovery determination means determines that the failure has been recovered from, a first provision request to the second report destination, the first provision request requesting the second report destination to provide the post-failure report data including an arrival time at the second report destination; a first acquisition means for acquiring the post-failure report data including the arrival time returned from the second report destination in response to the first provision request as post-failure provision data from the second report destination; Among the post-fault report data stored and held in the first storage means, the post-fault report data corresponding to the post-fault provision data acquired by the first acquisition means is Data provided after the failure a first update means for updating the arrival time of the a first retransmission processing means for transmitting the post-failure report data, the arrival time of which has been updated by the first update means, to the first report destination through the first network; The present invention is characterized by comprising:
[0015] According to the security device of the invention described in claim 1, when an abnormality is detected, first, report data is formed by the report data forming means, and this is transmitted to the first report destination through the first network by the first report processing means. Assume that the failure determination means determines that a failure has occurred on the first report destination side. In this case, the report data that could not be transmitted to the first report destination is stored and held in the first storage means as post-failure report data, and the post-failure report data held in the first storage means is transmitted to the second report destination through the second network by the second report processing means.
[0016] When the recovery determination means determines that the failure at the first report destination side has been recovered, first, the first provision request transmission means transmits a request for providing post-failure report data including the arrival time to the second report destination. In response to this, the post-failure report data (post-failure provision data) including the arrival time at the second report destination returned from the second report destination is acquired through the first acquisition means. Thereafter, the first update means updates the arrival time of the post-failure provision data corresponding to the acquired post-failure provision data among the post-failure report data stored and held in the first storage means. The post-failure report data in the first storage means with the updated arrival time is transmitted to the first report destination through the first network by the first retransmission processing means. Effect of the Invention
[0017] According to this invention, report data that could not be sent to the first report destination due to the occurrence of a communication failure or the like is sent to the second report destination, but after the failure is restored, the report data that could not be sent to the first report destination is resent to the first report destination with the arrival time at the second report destination added. This makes it possible for the report data processed at the second report destination to be processed at the first report destination as if it had been processed at the arrival time at the second report destination. [Brief description of the drawings]
[0018] [Figure 1]1 is a block diagram for explaining a configuration example of a security system according to an embodiment; [Diagram 2] 1 is a block diagram for explaining a configuration example of a security device according to an embodiment; [Diagram 3] FIG. 2 is a block diagram for explaining a configuration of a receiving server device according to an embodiment. [Figure 4] 2 is a block diagram for explaining the configuration of a security server device 5 according to an embodiment. FIG. [Diagram 5] FIG. 2 is a block diagram for explaining a configuration example of an on-premises server device according to an embodiment. [Figure 6] FIG. 2 is a block diagram for explaining a configuration example of a control device according to an embodiment. [Figure 7] 1 is a diagram for explaining the processing flow in a security system according to an embodiment. FIG. [Figure 8] 4 is a diagram for explaining an example of report data transmitted and received in the security system of the embodiment. FIG. [Figure 9] 4 is a flowchart for explaining processing performed by a security device of an embodiment. [Figure 10] 10 is a flowchart continuing from FIG. [Figure 11] FIG. 1 is a diagram for explaining an example of a conventional security system. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0019] Hereinafter, an embodiment of an apparatus and a system according to the present invention will be described with reference to the drawings.
[0020] [Security system configuration example] FIG. 1 is a block diagram for explaining a configuration example of a security system according to an embodiment. The security system according to this embodiment is configured by connecting a security device 1 and a control device 6 of a security company through two different paths. The security device 1 is installed, for example, in a company office, and is connected to a plurality of monitoring sensors (anomaly detection sensors). When an abnormality is notified, the security device 1 forms report data and transmits it to a report destination of the security company, and functions as a transmitter of the report data. Note that there may be a plurality of security devices 1 installed in different locations. For example, in a large office, the office may be divided into a plurality of areas, and a security device 1 may be installed in each area. There may also be a case where the security device 1 is installed in the offices of a plurality of different companies.
[0021] The control device 6 of the security company outputs when, where, and what type of abnormality has occurred when notified of the occurrence of an abnormality, and is realized, for example, as a control PC (Personal Computer). Based on the output information from the control device 6, the security company's personnel can perform so-called control tasks, such as reporting to a designated organization such as the police or fire department, and sending security guards to the site where the abnormality has occurred. Note that there may be multiple control devices 6. For example, there may be a case where a control device 6 is provided for each region. Also, different security companies may use the cloud system, in which case there will be multiple control devices 6 of different security companies.
[0022] In the security system of this embodiment, the first route connecting the security device 1 and the control device 6 is a route connected through a cloud system. As shown in FIG. 1, the cloud system is made up of a receiving server device 4 connected to the Internet 3 and a security server device 5. The receiving server device 4 receives and aggregates the report data from the security device 1, and notifies the security server device 5 through the Internet 3. The security server device 5 notifies the control device 6 of the security company of when, where, and what kind of abnormality has occurred based on the report data from the receiving server device 4. In this way, the route in which the report data from the security device 1 is sent to the Internet 3 through the gateway (written as GW in FIG. 1) 2, received by the receiving server device 4, and provided to the control device 6 through the security server device 5 is the first route.
[0023] The second route connecting the security device 1 and the control device 6 is a route connected through another network 7 different from the Internet 3. Examples of other networks different from the Internet include digital communication networks such as public switched telephone networks (PSTN (Public Switched Telephone Networks)) and integrated services digital networks (ISDN). In this embodiment, for the sake of simplicity, the other network 7 is assumed to be a public switched telephone network. As shown in FIG. 1, a so-called on-premises server device 8 is connected to the security company side of the other network 7. The on-premises server device means an on-premises server, and in this example, it means a server device installed on the premises of the security company (not installed on the cloud side). The on-premises server device 8 has both the functions of the receiving server device 4 and the security server device 5 of the cloud system.
[0024] The on-premises server device 8 receives the report data from the security device 1 and notifies the control device 6 of when, where, and what type of abnormality has occurred. In this way, the second route is the route in which the report data from the security device 1 is sent to the other network 7, received by the on-premises server device 8, and a corresponding report is sent to the control device 6. In the case of the security system of this embodiment, the first route via the cloud system is the main route that is normally used.
[0025] If some kind of failure occurs on this main route, i.e., on the cloud system side (receiving server side) including the Internet, and the report data cannot be sent properly, the report is sent using a second route via another network 7. Cases where this report data cannot be sent properly include cases where the receiving server device 4 cannot receive the report data properly. In this way, the second route is a backup sub-route provided for BCP measures. Note that failures that occur on the main route (Internet 3 side) include various cases such as communication failures on the Internet 3 and malfunctions of the receiving server device 4 or security server device 5.
[0026] In the security system configured in this manner, suppose that some kind of failure occurs on the main route (Internet side), and the report data is sent to the on-premises server device 8 using a second route via another network 7 to handle the abnormality that has occurred. After that, when the failure on the main route (Internet side) is resolved, the security device 1 resends the report data sent to the on-premises server device 8 to the receiving server device 4, but this is done in a way that prevents any inconvenience that would occur if the data were simply resent.
[0027] The first problem that may occur in this case is that a discrepancy may occur between the time when the report data arrives and the actual handling of the report data. As described above, if the security device 1 simply resends the report data to the receiving server device 4, the report data will be treated as having arrived at the date and time of arrival at the receiving server device 4. However, the resent report data has already been sent to the on-premises server device 8, and the control device 6 has handled it at the time of arrival at the on-premises server device 8. For this reason, a discrepancy may occur between the report data sent to the receiving server device 4 and the actual handling of the report data sent to the on-premises server device 8, making it difficult to perform appropriate management.
[0028] Secondly, the resent report data may result in a duplicate report. Depending on the timing and content of a failure or the like on the Internet 3 side, it may happen that the report data resent from the security device 1 has actually already been notified to the control device 6 via the cloud system. In this case, the same report data is sent twice, and since the arrival times of the report data are different, it may result in a duplicate report, and an event that has already been dealt with may be dealt with again.
[0029] Thirdly, it is possible that the report data received by the receiving server device 4 of the cloud system may be lost during the transmission process. That is, even if the report data transmitted from the security device 1 is received by the receiving server device 4 of the cloud system and is not normally subject to retransmission, it may be lost within the cloud system depending on the timing and content of the failure. For example, when the report data is transmitted from the receiving server device 4 of the cloud system to the security server device 5, it may be lost due to a failure that occurs in the receiving server device 4 or the security server device 5, even if this is rare.
[0030] In the security system of this embodiment, the above-mentioned problems are prevented by the security device 1 cooperating with the on-premises server device 8 and the receiving server device 4. Below, an example of the configuration of each device constituting the security system of this embodiment is described, and the details of the processing performed in the security system of this embodiment are described.
[0031] [Security device 1 configuration example] Fig. 2 is a block diagram for explaining a configuration example of the security device 1 according to the embodiment. In Fig. 2, a connection terminal 101T and a first communication I / F 101 realize a function of performing communication via the Internet 3. Also, a connection terminal 107T and a second communication I / F 107 realize a function of performing communication via another network (public switched telephone network) 7.
[0032] The control unit 102, not shown, is a microprocessor configured by connecting a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), and a non-volatile memory via a bus, and realizes the function of controlling each part of the security device 1. The storage device 103 is configured by a recording medium and its driver, and enables writing, reading, changing, and deleting data to the recording medium. The storage device 103 is realized, for example, as a non-volatile memory device or an SSD (Solid State Drive).
[0033] 2, a report data file 1031, a past report data file 1032, and a post-fault report data file 1033 are formed in the storage device 103 of the security device 1. In addition to the above, the storage device 103 also forms, for example, program files and data files that hold data required for processing, and working files that temporarily store intermediate results of processing.
[0034] The report data file 1031 temporarily stores report data that is to be sent (report data to be sent). The past report data file 1032 stores and holds past report data that has already been sent (past report data). In this embodiment, past report data from the start of security guard duty to the end of security guard duty is stored and held. Specifically, in the office in which the security device 1 is installed, the report data sent by the last employee leaving the office during the period from when the security guard duty start operation is performed to when the security guard duty end operation is performed is accumulated as past report data.
[0035] The post-failure report data file 1033 stores and holds, as post-failure report data, report data that could not be properly sent to the receiving server device 4 or that was not properly received due to a failure on the cloud system side. The report data to be sent, past report data, and post-failure report data are all time-series data generated in chronological order. These data are report data of the same format that are generated at different times and are classified according to the situation, such as data before transmission, data that has already been transmitted, and data that could not be properly transmitted to the receiving server device 4 due to a failure.
[0036] Connection ends 104T1, 104T2, ..., 104Tn constitute connection ends with monitoring sensors 105(1), 105(2), ..., 105(n). Sensor detection unit 104 monitors output signals from monitoring sensors 105(1), 105(2), ..., 105(n), and when it detects the occurrence of an abnormality, notifies control unit 102. There are various types of monitoring sensors, such as intrusion sensors, fire sensors, and water intrusion sensors, but in this embodiment, for the sake of simplicity, monitoring sensors 105(1), 105(2), ..., 105(n) will be described as intrusion sensors.
[0037] The sensor detection unit 104 can also determine which of the monitoring sensors 105(1), 105(2), ..., 105(n) detected the occurrence of an abnormality and notify the control unit 102 of the result. Therefore, the occurrence of an abnormality can be grasped according to the detection by the monitoring sensors 105(1), 105(2), ..., 105(n) installed at various locations as the intruder moves. For example, it is possible to grasp the occurrence of an intrusion (the movement of the intruder) such that the intrusion is first detected by the monitoring sensor 105(1), then by the monitoring sensor 105(3), and then by the monitoring sensor 105(4). The clock circuit 106 provides the current date, the current day of the week, and the current time, and also provides the transmission date and time (transmission time) of the report data transmitted from the security device 1, as described later.
[0038] As described above, the control unit 102, which has received a notification of the occurrence of an abnormality from the sensor detection unit 104, forms report data, stores it in the report data file 1031, and controls the first report processing unit 111 to transmit the report data to the first report destination. Under the control of the control unit 102, the first report processing unit 111 transmits the report data stored in the report data file 1031 to the Internet 3 via the first communication I / F 101 and the connection terminal 101T, and performs processing to transmit the report data to the receiving server device 4. When the report data is transmitted to the receiving server device 4 via the first report processing unit 111 and properly received, the control unit 102 functions to transfer the report data in the report data file 1031 to the past report data file 1032. Whether the report data has been properly received by the receiving server device 4 can be determined, for example, by whether a response has been returned from the receiving server device 4.
[0039] The fault determination unit 112 determines that a fault has occurred when no response is received or a fault occurrence notification is received from the Internet 3 side despite the fact that the fault data has been sent to the receiving server device 4 via the first report processing unit 111. The fault determination unit 112 notifies the control unit 102 of the determination result. Upon receiving the fault occurrence notification from the fault determination unit 112, the control unit 102 transfers the report data in the report data file 1031 to the post-fault report data file 1033. Furthermore, the control unit 102 controls the second report processing unit 113 to transmit the report data to the second report destination. Under the control of the control unit 102, the second report processing unit 113 performs a process of transmitting the report data to the on-premises server device 8 of the security company, which is the second report destination.
[0040] Specifically, the second report processing unit 113 connects a communication line between the on-premises server device 8 and the other network 7. After that, the second report processing unit 113 performs processing to send the past report data stored in the past report data file 1032 to the other network (public switched telephone network) 7 through the second communication I / F 107 and the connection terminal 107T, and transmits it to the on-premises server device 8. In addition to the past report data that has already arrived at the control device 6, there is a possibility that the past report data may include data that has not arrived or data that has been abandoned. For this reason, by providing the past report data that has not arrived or data that has been abandoned to the control device 6, it is possible to prevent the occurrence of missed reports.
[0041] Also, the second report processing unit 113 performs processing to send the post-fault report data stored in the post-fault report data file 1033 to another network (public switched telephone network) 7 via the second communication I / F 107 and the connection end 107T, and transmit it to the on-premises server device 8. This allows the occurrence of a new abnormality to be notified to the security company's control device 6 without delay. Note that the second report processing unit 113 has been described as first transmitting past report data to the on-premises server device 8, and then transmitting post-fault report data, but this is not limited to this. The second report processing unit 113 can also be configured to first transmit post-fault report data to the on-premises server device 8 to notify the occurrence of the latest abnormality, and then transmit past report data to prevent missed reports.
[0042] The recovery determination unit 114 transmits the report data to the on-premises server device 8 through the second report processing unit 113, and then performs a retry communication with the receiving server device 4 to determine whether or not the failure that occurred on the Internet 3 side has been restored. The result of the determination by the recovery determination unit 114 is notified to the control unit 102. Upon receiving the notification from the recovery determination unit 114 of the determination result that the failure, etc. that occurred on the Internet 3 side has been restored, the control unit 102 controls the report data acquisition unit 115 to perform processing for acquiring the arrival time of the report data transmitted to the on-premises server device 8.
[0043] Specifically, the report data acquisition unit 115 forms and transmits a provision request to the on-premises server device 8, which requests the provision of post-failure report data transmitted from the security device 1, with the arrival time at the on-premises server device 8 updated. The provision request is sent to the other network (public switched telephone network) 7 via the second communication I / F 107 and the connection terminal 107T, and transmitted to the on-premises server device 8. In response to this, the on-premises server device 8 returns the post-failure report data transmitted from the security device 1, with the arrival time at the on-premises server device 8 updated, as post-failure provision data. The post-failure provision data from the on-premises server device 8 is received via the connection terminal 107T and the second communication I / F 107, and is recorded in a work file of the storage device 103 by the control unit 102.
[0044] Similarly, under the control of the control unit 102, the report data acquisition unit 115 forms and transmits a request for providing past report data transmitted from the security device 1, which has the updated arrival time at the on-premises server device 8, to the on-premises server device 8. The request for providing is sent to another network (public switched telephone network) 7 through the second communication I / F 107 and the connection terminal 107T, and transmitted to the on-premises server device 8. In response to this, the on-premises server device 8 returns the past report data transmitted from the security device 1, which has the updated arrival time at the on-premises server device 8, as past provision data. The past provision data from the on-premises server device 8 is received through the connection terminal 107T and the second communication I / F 107, and is recorded in a work file of the storage device 103 by the control unit 102. After this, the control unit 102 controls the retransmission processing unit 116 to perform a retransmission process of the report data that could not be transmitted to the receiving server device 4 due to the failure.
[0045] Under the control of the control unit 102, the retransmission processing unit 116 identifies the post-failure report data in the post-failure report data file 1033 that corresponds to the post-failure provided data from the on-premises server device 8 in the work file of the storage device 103. Next, the retransmission processing unit 116 updates the arrival time of the corresponding post-failure provided data from the on-premises server device 8 for the identified post-failure report data, sends it to the Internet 3 via the first communication I / F 101 and the connection end 101T, and retransmits it to the receiving server device 4. This makes it possible to retransmit the post-failure report data that could not be transmitted to the receiving server device 4 due to the failure on the Internet 3 side. Since the arrival time at the on-premises server device 8 has been updated for the retransmitted post-failure report data, the receiving server device 4 can process it as report data that has already been notified to the control device 6.
[0046] Also, under the control of the control unit 102, the retransmission processing unit 116 specifies the past report data in the past report data file 1032 that corresponds to the past provided data from the on-premises server device 8 in the work file of the storage device 103. Next, the retransmission processing unit 116 updates the arrival time of the corresponding past report data from the on-premises server device 8 for the specified past report data, sends it to the Internet 3 through the first communication I / F 101 and the connection terminal 101T, and retransmits it to the receiving server device 4. This makes it possible to appropriately manage report data that has already been transmitted but has not yet reached the control device 6 or has been abandoned from being transmitted to the control device 6 and does not exist in the receiving server device 4. In this case, since the arrival time at the on-premises server device 8 has been updated for the retransmitted past report data, the receiving server device 4 can process the data as report data that has already been notified to the control device 6.
[0047] In this way, when the security device of this embodiment detects the occurrence of an abnormality through monitoring sensors 105(1), 105(2), ..., 105(n), it can report this through report data to the receiving server device 4 of the cloud system, which is the first report destination. Also, suppose that some kind of failure occurs on the Internet 3 side, and the report data cannot be properly provided to the receiving server device 4. In this case, the report data can be sent via another network 7 to the on-premises server device 8 of the security company, which is the second report destination, and notified to the control device 6. This allows the report processing to be carried out without delay.
[0048] Furthermore, when a failure or the like on the Internet 3 side is restored, the post-failure report data and past report data can be resent to the receiving server device 4 with the arrival time at the on-premises server device 8 updated. Since the arrival time at the on-premises server device 8 has been updated in the resent report data, the receiving server device 4 can handle it as already processed report data that has been processed at the arrival date and time at the on-premises server device 8.
[0049] [Example of the configuration of the receiving server device 4] Fig. 3 is a block diagram for explaining the configuration of the receiving server device 4 according to the embodiment. In Fig. 3, a connection terminal 401T and a communication I / F 401 realize a function of performing communication via the Internet 3. A control unit 402, which is not shown, is a microprocessor configured by connecting a CPU, a ROM, a RAM, and a non-volatile memory via a bus, and realizes a function of controlling each unit of the receiving server device 4.
[0050] The storage device 403 is composed of a recording medium and its driver, and enables writing, reading, changing, and deleting data to the recording medium. The storage device 403 is realized, for example, as a non-volatile memory device or SSD. In addition to forming a report data file that stores and holds received report data, the storage device 403 also forms, for example, a program file, a data file that stores data required for processing, and a work file that temporarily stores intermediate results of processing.
[0051] The clock circuit 404 provides the current date, current day of the week, and current time, and can obtain the arrival time at the security device 1 of the report data transmitted from the security device 1, as described below. The report data reception unit 405 receives report data from the security device 1 received through the connection terminal 401T and the communication I / F 401. If the received report data has not had its arrival date and time updated, the report data reception unit 405 can determine that it is new report data. In this case, the report data reception unit 405 obtains the arrival date and time at the security device 1 from the clock circuit 404, updates the arrival date and time of the received report data, and provides this to the report data provision unit 406, making it the subject of the report to the control device 6.
[0052] Furthermore, if the received report data has an updated arrival date and time, the report data receiving unit 405 performs a process of recording the report data in the report data file of the storage device 403, since the report data has already been reported to the control device 6 via the on-premises server device 8. In this case, the report data receiving unit 405 discards the received report data if report data with the same serial number assigned to the report data already exists in the report data file, in order to prevent duplicate reports, as will be described in detail later.
[0053] The report data providing unit 406 sends the report data, with the arrival time updated from the report data receiving unit 405, via the communication I / F 401 and the connection terminal 401T to the Internet 3, and transmits it to the security server device 5. In addition, the report data providing unit 406 records the report data transmitted to the security server device 5 in a report data file in the storage device 403.
[0054] In this way, the receiving server device 4 has a function of receiving report data from the security device 1 and handing it over to the security server device 5. Even if multiple security devices 1 exist, the report data can be received in a centralized manner and handed over to the security server device 5 without delay.
[0055] [Example of configuration of security server device 5] Fig. 4 is a block diagram for explaining the configuration of security server device 5 according to an embodiment. In Fig. 4, connection terminal 501T and communication I / F 501 realize a function of performing communication via Internet 3. Although not shown, control unit 502 is a microprocessor configured by connecting a CPU, ROM, RAM, and non-volatile memory via a bus, and realizes a function of controlling each unit of security server device 5.
[0056] The storage device 503 is composed of a recording medium and its driver, and enables writing, reading, changing, and deleting data to the recording medium. The storage device 503 is realized, for example, as a non-volatile memory device or SSD. In the storage device 503, a report data file that stores and holds report data and a notification destination file that associates the report source with the control device 6 of the security company that is the report destination are formed. In addition, in the storage device 503, for example, a program file, a data file that stores data required for processing, a working file that temporarily stores intermediate results of processing, and the like are formed.
[0057] The clock circuit 504 provides the current date, current day of the week, and current time, and can obtain, for example, the processing time in the device itself. The report data receiving unit 505 receives report data from the receiving server device 4 received through the connection terminal 501T and the communication I / F 501, and provides this to the report data providing unit 406, making it the subject of report to the control device 6.
[0058] The report notification unit 506 refers to the notification destination file in the storage device 503 based on the notification source of the report data from the report data receiving unit 505, identifies the control device 6 of the security company that is the notification destination, and provides the report data to the control device 6. This makes it possible to notify the target control device 6 of at least when, where, and what kind of abnormality occurred. Furthermore, the report notification unit 506 records the report data that is to be notified to the control device 6 in the report data file in the storage device 503. Note that the security server device 5 can also add necessary information to the report data and provide it. Examples of necessary information include the address and telephone number of the facility to be guarded where the abnormality has occurred.
[0059] In this way, the security server device 5 has a function of receiving report data from the receiving server device 4 and reporting to the target control device 6. Even if multiple control devices 6 exist, it is possible to identify the appropriate control device 6 and report depending on the installation location of the security device that sent the report data.
[0060] [Example of on-premise server device 8 configuration] Fig. 5 is a block diagram for explaining a configuration example of the on-premises server device 8 according to the embodiment. In Fig. 5, a connection terminal 801T and a communication I / F 801 realize a function of communicating through another network (public switched telephone network) 7. A connection terminal 809T and a LAN I / F 809 realize a function of communicating with a control device 6 connected to a LAN. Although not shown, a control unit 802 is a microprocessor configured by connecting a CPU, a ROM, a RAM, and a non-volatile memory via a bus, and realizes a function of controlling each unit of the on-premises server device 8.
[0061] The storage device 803 is composed of a recording medium and its driver, and enables writing, reading, changing, and deleting data to the recording medium. The storage device 803 is realized, for example, as a non-volatile memory device or SSD. The storage device 803 is formed with a post-fault report data file that stores and holds post-fault report data from the security device, and a past report data file that stores and holds past report data. The storage device 803 is also formed with, for example, program files, data files that store data required for processing, and work files that temporarily store intermediate results of processing. The clock circuit 804 provides the current date, current day of the week, and current time, and can, for example, obtain the processing time in the device itself.
[0062] The report data reception unit 805 receives post-fault report data and past report data from the security device 1 received through the connection terminal 801T and the communication I / F 801, and records them in a post-fault data file and a past report data file in the storage device 803. In this case, the report data reception unit 805 obtains the current date and time from the clock circuit 804 as the reception date and time, updates the reception date and time of the received post-fault report data and past report data, and records them in the storage device 803. In this way, the report data from the security device 1 includes post-fault report data and past report data. The report notification unit 806 functions to immediately send the post-fault report data to the LAN through the LAN I / F 809 and the connection terminal 809T, and transmits it to the control device 6. This makes it possible to respond quickly to the occurrence of an abnormality.
[0063] The control unit 802 also provides past report data to the control device 6 via the connection terminal 809T and the LAN I / F 809. The control device 6 is able to identify past report data from the on-premises server device 8 that does not exist in the report data it holds, and take action against the past report data that does not exist in its own device. Therefore, even for past report data that is not provided properly through the receiving server device 4 and security server device 5, which are the cloud system, and does not exist in the control device 6, the control device 6 can obtain it from the on-premises server device 8 and take appropriate action. In other words, missed reports are prevented.
[0064] The provision request receiving unit 807 receives a request for provision of post-failure report data or past report data from the security device 1 received through the connection terminal 801T and the communication I / F 801, and notifies the control unit 802. The control unit 802, which has received the provision request, controls the provision data providing unit 808 to perform a provision process of the provision data. That is, under the control of the control unit 802, the provision data providing unit 808 returns the post-failure report data and past report data with the updated arrival date and time at its own device stored and held in the storage device 803 to the security device 1 that sent the report as post-failure provision data and past provision data. The post-failure provision data and past provision data from the on-premises server device 8 are sent to the other network 7 through the communication I / F 801 and the connection terminal 801T, and are returned to the security device 1.
[0065] In this way, the on-premises server device 8 realizes the function of receiving and holding the report data from the security device 1 and providing it to the control device 6 of the security company. The on-premises server device 8 also has a function of returning post-failure report data and past report data, with the date and time of arrival at the own device updated, to the security device 1 as post-failure provided data and past provided data from the own device in response to a request for provision from the security device 1.
[0066] [Configuration example of control device 6] Fig. 6 is a block diagram for explaining a configuration example of the control device of the embodiment. In Fig. 6, a connection terminal 601T and a communication I / F 601 realize a function of communicating through the Internet 3. A connection terminal 602T and a LAN I / F 602 realize a function of communicating with an on-premises server device 8 connected through a LAN. Although not shown, the control unit 102 is a microprocessor configured by connecting a CPU, a ROM, a RAM, and a non-volatile memory through a bus, and realizes a function of controlling each part of the control device 6.
[0067] The storage device 604 is composed of a recording medium and its driver, and enables writing, reading, changing, and deleting data to the recording medium. The storage device 604 is realized, for example, as a non-volatile memory device or SSD. The operation unit 605 is composed, for example, of a pointing device such as a keyboard or a mouse, and receives operation input from the user and notifies the control unit 603 of the received information as an electrical signal. In this way, the control unit 603 can control each unit according to instructions from the user and perform processing intended by the user.
[0068] The microphone 606, the audio input unit 607, the display unit 608, the audio output unit 609, and the speaker 610 constitute a user interface. The microphone 606 picks up sound, converts it into an electrical signal, and supplies it to the audio input unit 607. The audio signal from the audio input unit 607 is converted into a digital signal and input into the device. In this way, the microphone 606 and the audio input unit 607 realize the audio input function.
[0069] The audio output unit 609 converts the digital audio signal from the control unit 603 into an analog audio signal and supplies it to the speaker 610. As a result, the speaker 610 emits audio corresponding to the digital audio signal from the control unit 603. In this way, the audio output unit 609 and the speaker 610 realize an audio output function. The display unit 608 is composed of a display element such as an LCD (Liquid Crystal Display) and its driver, and displays information mainly corresponding to received report data and information necessary for air traffic control operations under the control of the control unit 603. The communication I / F 611 and the connection terminal 611T enable connection to an external device such as a communication device.
[0070] As a result, the control device 6 can receive report data from the security server device 5 of the cloud system via the connection terminal 601T and the communication I / F 601, and report data from the on-premises server device 8 via the connection terminal 602T and the LAN I / F 602. When report data is received, necessary information can be displayed on the display unit 608, and an alarm sound can be emitted from the audio output unit 609 and the speaker 610, to notify the person in charge at the security company of the occurrence of an abnormality.
[0071] A security company personnel can operate the operation unit 605 to connect a communication line to, for example, a communication device of a security vehicle through the communication I / F 611 and the connection terminal 611T. This makes it possible to use the microphone 606 and the voice input unit 607 as a transmitter and the voice output unit 609 and the speaker 610 as a receiver to have a voice call with a security guard, to give instructions or receive a report on the situation.
[0072] [Security system processing flow] Fig. 7 is a diagram for explaining the flow of data in the security system of the embodiment. The part enclosed by the dotted line rectangle on the left side of Fig. 7 shows the part related to the transmission of report data of the security device 1. The part enclosed by the dotted line rectangle on the upper right side of Fig. 7 shows the part of the cloud system configured by connecting the receiving server device 4 and the security server device 5 via the Internet 3. The part enclosed by the dotted line rectangle on the lower right side of Fig. 7 shows the part of the LAN system of the security company configured by connecting the on-premises server device 8 and the control device 6 via a LAN.
[0073] As explained with reference to FIG. 2, it is assumed that the occurrence of an abnormality (the occurrence of an intrusion in this embodiment) is detected in the security device 1 through the monitoring sensors 105(1)-105(n) and the sensor detection unit 104. In this case, the control unit 102 forms report data and stores it in the report data file 1031 of the storage device 103. Thereafter, under the control of the control unit 102, the first report processing unit 111 transmits the report data in the report data file 1031 to the Internet 3 through the first communication I / F 101, and transmits it to the receiving server device 4, which is the first report destination (FIGS. 7(1) and (2)). After transmitting the report data, the control unit 102 transfers the report data in the report data file 1031 to the past report data file 1032 (FIG. 7(3)).
[0074] The report data transmitted to the receiving server device 4 is sent to the security server device 5 (FIG. 7(4)), and is then sent from the security server device 5 to the control device 6 of the security company (FIG. 7(5)), whereby the occurrence of an abnormality is reported, and the security company takes appropriate action. Thus, the processes shown in (1) to (5) in FIG. 7 are normal report processes through the cloud system. In this case, as shown by the dotted arrow (FIG. 7(NG)) from the receiving server device 4 to the first communication I / F 101, it is assumed that a communication failure or the like occurs on the Internet side, and the report data cannot be properly transmitted or cannot be properly received by the receiving server device 4. The occurrence of a communication failure on the Internet side can be determined, for example, when no response is returned despite the transmission of the report data, or when the occurrence of a failure is notified from the Internet 3 side. The occurrence of a communication failure or the like is determined by the failure determination unit 112, and is notified to the control unit 102.
[0075] The control unit 102, which has been notified of the occurrence of a communication failure or the like, transfers the report data in the report data file 1031 to the post-failure report data file 1033 in the storage device 103 (FIG. 7(A)). Thereafter, under the control of the control unit 102, the second report processing unit 113 sends the past report data in the past report data file 1032 to the other network 7 via the second communication I / F 107 and transmits it to the on-premises server device 8 of the security company (FIGS. 7(B) and (C)). Furthermore, under the control of the control unit 102, the second report processing unit 113 sends the post-failure report data in the post-failure report data file 1033 to the other network 7 via the second communication I / F 107 and transmits it to the on-premises server device 8 of the security company (FIGS. 7(D) and (E)).
[0076] The on-premises server device 8 updates the arrival date and time of the received past report data and post-fault report data with the current date and time of arrival obtained from its own clock circuit 804. After this, the past report data is recorded in a past report data file in the storage device 803, and the post-fault report data is recorded in a post-fault report data file in the storage device 803. As a result, when a communication failure or the like occurs on the Internet 3 side, the on-premises server device 8 can receive the past report data and post-fault report data from the security device 1 and provide them to the control device 6 (FIG. 7(F)).
[0077] In this case, the control device 6 identifies the report data that has not been provided by the security server device 5, outputs the contents indicated by the newly acquired report data, and notifies the security company's personnel of the occurrence of the abnormality. Based on the report data, the security company's personnel will report the occurrence of the abnormality to a specified report destination, or send a security guard to the location of the abnormality. As shown in FIG. 7, the transmission of past report data itself has been completed, but in addition to the report data that has normally arrived at the control device 6 (reached the control device), there is a possibility that there is also the report data that has not arrived at the control device 6 due to the influence of a failure or the like (not reached the control device). In addition, there is a possibility that the transmission itself has been abandoned for some reason, and there is also the report that has not arrived at the receiving server device 4 (abandoned).
[0078] In this way, past report data that has not yet reached the control device 6 (not reached control device) and data for which transmission has been abandoned and the report has not yet reached the receiving server device 4 (abandoned) can also be provided from the security device 1 to the control device 6 via the on-premises server device 8. This makes it possible to reliably avoid a situation in which no report data is provided to the control device 6 at all, i.e., a "missed report."
[0079] Thereafter, in the security device 1, under the control of the control unit 102, the recovery determination unit 114 functions to perform retry communication with the receiving server device 4, which is the first report destination, via the first communication I / F 101 and the Internet 3 (FIG. 7 (RT)). The recovery determination unit 114 determines whether the retry communication is successful or not, i.e., whether the communication failure or the like has been resolved or not. The recovery determination unit 114 notifies the control unit 102 of the determination result. When the control unit 102 is notified of the fact that the communication failure or the like has been resolved, the control unit 102 controls the report data acquisition unit 115 to perform processing to acquire, from the on-premises server device 8, report data in which the date and time of arrival at the on-premises server device 8 has been updated.
[0080] That is, the report data acquisition unit 115 forms a request to acquire past report data, and sends it to the other network 7 via the second communication I / F 107 to transmit it to the on-premises server device 8 (FIGS. 7(G) and (H)). In response to this, the on-premises server device 8 returns past report data with the arrival date and time at its own device updated as past provision data. The security device 1 receives this via the connection terminal 107T and the second communication I / F 107 (FIGS. 7(I) and (J)). The control unit 102 functions to record the received past provision data in a work file in the storage device 103. Thereafter, the retransmission processing unit 116 functions to update the arrival date and time of the past report data in the past report data file 1032 that corresponds to the past provision data recorded in the work file to the arrival date and time of the past provision data in the work file.
[0081] Similarly, the report data acquisition unit 115 forms a request to acquire post-failure report data, and sends it to the other network 7 via the second communication I / F 107 to transmit it to the on-premises server device 8 (FIG. 7(K) and (L)). In response to this, the on-premises server device 8 returns the post-failure report data with the updated arrival date and time at its own device as post-failure provision data. The security device 1 receives this via the connection terminal 107T and the second communication I / F 107 (FIG. 7(M) and (N)). The control unit 102 functions to record the received post-failure provision data in a work file in the storage device 103. Thereafter, the retransmission processing unit 116 functions to update the arrival date and time of the post-failure report data corresponding to the post-failure provision data recorded in the work file, among the past report data in the post-failure report data file 1033, to the arrival date and time of the post-failure provision data in the work file.
[0082] After that, the control unit 102 controls the retransmission processing unit 116 to perform a retransmission process of the past report data with the updated arrival date and time and the post-failure report data. That is, the retransmission processing unit 116 reads the past report data with the updated arrival date and time from the past report data file 1032 (FIG. 7(O)), sends it to the Internet 3 through the first communication I / F 101, and retransmits it to the receiving server device 4 (FIG. 7(Q)). Similarly, the retransmission processing unit 116 reads the post-failure report data with the updated arrival date and time from the post-failure report data file 1033 (FIG. 7(P)), sends it to the Internet 3 through the first communication I / F 101, and retransmits it to the receiving server device 4 (FIG. 7(Q)).
[0083] FIG. 8 is a diagram for explaining an example of report data transmitted and received in the security system of the embodiment. As shown in FIG. 8(A), the report data includes a serial number, a report destination, a report source, report contents, an occurrence location, a transmission date and time, and an incoming date and time. The serial number is a so-called sequential number that is incremented by one each time a number is assigned in the control unit 102 of the security device 1 so as to prevent duplication. The report destination is a number that specifies a receiving server device that is a report destination of the report data, such as a URL (Uniform Resource Locator) or IP address of the receiving server device 4. When the report data is transmitted to the on-premise server device 8 of the security company through another network (public switched telephone network) 7, the report data is transmitted after a communication line is connected, for example, as if making a phone call. For this reason, the transmission destination may remain a URL or IP address that specifies the receiving server device.
[0084] The report source is information that allows the security facility where the security device 1 is installed to be uniquely identified, such as a security destination ID that allows the security company's control device 6, which is the transmission destination, to distinguish the security facility where the security device 1 is installed. The report content is information that indicates what abnormality has occurred, and in this embodiment, since the monitoring sensors 105(1) to 105(n) are intrusion sensors, the report content indicates the occurrence of an intrusion. The occurrence location is information that identifies the monitoring sensor (intrusion sensor) 105(1) to 105(n) that detected the intrusion, and a sensor ID, for example, is used. The transmission date and time is information that indicates the date and time when the security device 1 transmits the report data. The reception date and time is usually information that indicates the date and time of reception at the receiving server device 4, but in the case of resent past report data or post-failure report data, it is information that indicates the date and time of reception at the security company's on-premises server device 8.
[0085] Therefore, the report data first transmitted from the security device 1 to the receiving server device 4 of the cloud system (the report data transmitted in (2) of FIG. 7) has the transmission date and time cleared to zero or initialized, as shown in FIG. 8(B). In contrast, past report data and post-fault report data that are not transmitted properly due to a communication failure on the cloud system side, and are transmitted to the security company's on-premises server device 8 and then retransmitted to the receiving server device 4 of the cloud system will be as shown in FIG. 8(C). That is, the report data retransmitted in (Q) of FIG. 7 has the arrival date and time at the on-premises server device 8 updated, as shown in FIG. 8(C).
[0086] This makes it possible to prevent the above-mentioned three problems from occurring. That is, the first problem is that when report data is resent, a discrepancy occurs between the arrival time of the report data and the actual situation of how the report data was handled. This problem can be prevented by updating the arrival time and date at the security company's on-premises server device 8 for the past report data and post-fault report data that are resent.
[0087] A second problem is that resent report data may result in duplicate reports. To deal with this problem, the receiving server device 4 discards resent and received past report data or post-fault report data if report data with the same serial number is already held in the receiving server device 4. This prevents duplicate reports from being sent.
[0088] A third problem may occur when report data received by the receiving server device 4 of the cloud system is lost during the transmission process. This problem is dealt with by transmitting past report data to the on-premises server device 8 and also resending it to the receiving server device 4. This makes it possible to restore lost report data, prevents missed reports, and allows the report data to be restored in the receiving server device 4.
[0089] [Summary of the processes performed by Security Device 1] 9 and 10 are flow charts for explaining the processing performed by the security device 1 of the embodiment. The processing of the flow charts shown in Figs. 9 and 10 is processing executed by each unit of the security device 1 functioning under the control of the control unit 102 of the security device 1. When the security device 1 is in an operating state, the control unit 102 monitors the output signal from the sensor detection unit 104 that aggregates the monitoring sensors 105(1)-105(n), and determines whether or not an abnormality (intrusion) has occurred (step S101). When it is determined in the determination process of step S101 that no abnormality has occurred, the control unit 102 repeats the processing from step S101.
[0090] When it is determined in the determination process of step S101 that an abnormality has occurred, the control unit 102 forms the report data in the form shown in Fig. 8(B) in the report data file 1031 (step S102). Next, the control unit 102 controls the first report processing unit 111 to transmit the report data formed in the report data file 1031 to the receiving server device 4 of the cloud system, which is the first report destination, through the first communication I / F and the connection terminal 101T (step S103). After that, the control unit 102 transfers the report data formed in the report data file 1031 to the past report data file 1032 (step S104).
[0091] Next, the control unit 102 determines whether or not a communication failure or the like has occurred on the cloud system side based on the determination result from the failure determination unit 112 (step S105). When it is determined in the determination process of step S105 that a communication failure or the like has not occurred, the control unit 102 repeats the process from step S101. It is assumed that it is determined in the determination process of step S105 that a communication failure or the like has occurred. In this case, the control unit 102 controls the second report processing unit 113 to connect a communication line to the on-premises server device 8 through the second communication I / F 107 and the connection terminal 107T, and transmits past report data of the past report data file 1032 (step S106).
[0092] Furthermore, the control unit 102 transfers the report data in the report data file 1031 to the post-failure report data file 1033 (step S107), and transmits it to the on-premises server device 8 of the security company through the second communication I / F 107 and the connection end 107T (step S108). After that, the control unit 102 proceeds to the process of Fig. 10, controls the recovery determination unit 114 to perform a retry communication with the receiving server device 4, and determines whether or not the communication failure, etc. has been restored based on the determination result from the recovery determination unit 114 (step S109).
[0093] When it is determined in the determination process of step S109 that the communication failure or the like has not been restored, the control unit 102 determines whether or not a new abnormality has been detected, similarly to the process of step S101 (step S110). When it is determined in the determination process of step S110 that the new abnormality has not been detected, the process from step S109 is repeated. When it is determined in the determination process of step S110 that the new abnormality has been detected, report data for reporting the new abnormality is formed in the report data file 1031 (step S111), and the process from step S107 in FIG. 9 is repeated. This allows the report data to be continuously transmitted to the on-premise server device 8 of the security company even if a new abnormality is detected. This is because in this state, the communication failure or the like on the cloud system side has not yet been restored.
[0094] Assume that it is determined in the determination process of step S109 that the communication failure or the like has been restored. In this case, the control unit 102 controls the report data acquisition unit 115 to form a provision request for requesting provision of past report data and post-failure report data including the date and time of arrival at the on-premises server device 8, and transmits the request to the on-premises server device 8 (step S112). The provision request in this case is also sent to the other network 7 via the second communication I / F 107 and the connection terminal 107T, and transmitted to the on-premises server device 8. In response to this, the on-premises server device 8 returns the past report data and post-failure report data with the date and time of arrival at the on-premises server device 8 updated.
[0095] For this reason, the control unit 102 receives the provided data (past report data, post-failure report data) from the on-premises server device 8 through the connection end 107T and the second communication I / F 107, and records it in a work file in the storage device 103 (step S113). In step S113, when the acquisition of the past report data and post-failure report data from the on-premises server device 8 is completed, the communication line connected between the security device 1 and the on-premises server device 8 through the other network (public switched telephone network) 7 is released.
[0096] Thereafter, the control unit 102 controls the report data acquisition unit 115 to update the arrival date and time of the corresponding provided data to the past report data and post-failure report data corresponding to the provided data recorded in the work file (step S114). In this case, the past report data is stored and held in the past report data file 1032, and the post-failure report data is stored and held in the post-failure report data file 1033. Thereafter, the control unit 102 controls the retransmission processing unit 116 to perform retransmission processing of the past report data and post-failure report data with the updated arrival date and time (step S115).
[0097] That is, in step S115, the retransmission processing unit 116 reads out the past report data with the updated arrival date and time from the past report data file 1032, and reads out the post-failure report data with the updated arrival date and time from the post-failure report data file 1033. After this, the retransmission processing unit 116 sends out the read out past report data and post-failure report data to the Internet 3 via the first communication I / F 101, and retransmits them to the receiving server device 4. After the past report data and post-failure report data are retransmitted to the receiving server device 4 on the cloud system side where the communication failure or the like has been restored by the processing of step S115, the control unit 102 repeats the processing from step S101 in Fig. 9. In this way, the security device 1 is capable of cooperating with the receiving server device 4 on the cloud system side and the on-premises server device 8 of the security company.
[0098] [Effects of the embodiment] As described above, when the security device 1 detects the occurrence of an abnormality (an intrusion in this embodiment), it forms report data and transmits it to the receiving server device 4 of the cloud system, which is the first report destination, and a report can be made to the security company's control device 6 via the cloud system. However, if a communication failure or the like occurs on the cloud system side, the report data can be transmitted to the security company's on-premises server device 8 via another network 7 as a BCP measure, and a report can be made to the security company's control device 6 via the on-premises server device 8.
[0099] In this case, as described above, the security device 1 can provide not only post-failure report data that could not be transmitted due to the occurrence of a communication failure or the like, but also past report data to the control device 6 via the on-premises server device 8. As a result, in cases where report data has been received normally by the receiving server device 4 but has not yet reached the control device 6 due to a communication failure or the like occurring on the cloud system side, it becomes possible to provide the report data to the control device 6, thereby reliably preventing missed reports.
[0100] Furthermore, after recovery from a failure or the like on the cloud system side, the past report data and post-failure report data sent to on-premises server device 8 can be updated with the arrival date and time at on-premises server device 8 and resent to receiving server device 4. This makes it possible to prevent discrepancies between the arrival time of the report data and the actual handling of the report data. Also, since a serial number is assigned to the report data, even if already existing report data is resent at receiving server device 4, it can be discarded, thereby preventing the inconvenience of double reporting.
[0101] [Variations] In the above embodiment, when a communication failure or the like occurs on the cloud system side, both the past report data and the post-failure report data are transmitted to the on-premises server device 8 of the security company. However, this is not limited to this. At least, only the post-failure report data that has occurred most recently and could not be provided appropriately to the receiving server device 4 may be transmitted to the on-premises server device 8 of the security company. This allows at least the latest post-failure report data to be provided to the control device 6 through the on-premises server device 8, making it possible for the security company to take a quick response. However, in order to reliably avoid missed reports, it is preferable to transmit the past report data to the on-premises server device 8 of the security company as well.
[0102] In the above embodiment, all the report data transmitted during the period covered by the security device 1 is stored in the past report data file 1032. In this case, when a communication failure or the like occurs on the cloud system side, all the past report data stored in the past report data file 1032 is transmitted to the on-premises server device 8, but this is not limited to this. For example, when past report data is accumulated for a long period in the past report data file 1032, past report data for a predetermined period from the latest past report data may be transmitted to the on-premises server device 8. The predetermined period in the past can be determined, for example, as a period of 30 minutes in the past or a period of 1 hour in the past based on the transmission date and time of the past dispensing report data. Also, the past report data to be transmitted can be determined by the number of cases, such as 100 cases from the latest past report data.
[0103] In addition, the format of the report data is not limited to that explained using Fig. 8, and various modifications are possible, such as adding more information, etc. For example, it is possible to provide a division so that post-fault report data and past report data can be distinguished.
[0104] In the above embodiment, the sending date and time and the receiving date and time are used, but this is not the only option. Usually, the security period of the security device 1 is not very long from start to finish, such as from 10 pm to 7 am the following day. For this reason, it is also possible to use only the sending time (hour, minute, second) and the receiving time (hour, minute, second) instead of the sending date and time and the receiving date and time.
[0105] [others] As can be seen from the above description of the embodiment, the function of the notification data forming means in the claims is realized by the control unit 102 of the security device 1, and the function of the first notification processing means in the claims is realized by the first notification processing unit 111 of the security device. In addition, the function of the fault determination means in the claims is realized by the fault determination unit 112 of the security device 1, and the function of the first storage means in the claims is realized by the post-fault notification data file 1033 of the security device 1. In addition, the function of the second notification processing means in the claims is realized by the second notification processing unit 113 of the security device 1, and the function of the recovery determination means in the claims is realized by the recovery determination unit 114 of the security device 1. In addition, the function of the first provision request transmission means in the claims is realized by the notification data acquisition unit 115 of the security device 1, and the function of the first acquisition means in the claims is mainly realized by the control unit 102. In addition, the function of the first update means in the claims is realized by the retransmission processing unit 116 of the security device 1, and the function of the first retransmission processing means in the claims is realized by the retransmission processing unit 116 of the security device 1.
[0106] Moreover, the function of the second storage means in the claim is realized by past report data file 1032 of the security device 1. Moreover, the function of the third report processing means in the claim is realized by second report processing unit 113, and the function of the second provision request transmission means in the claim is realized by report data acquisition unit 115 of the security device 1. Moreover, the function of the second acquisition means in the claim is mainly realized by control unit 102, the function of the second update means in the claim is realized by retransmission processing unit 116 of the security device 1, and the function of the second retransmission processing means in the claim is realized by retransmission processing unit 116 of the security device 1.
[0107] The second destination device in the claims corresponds to the on-premises server device 8 in the embodiment. The function of the first provision request receiving means of the second destination device in the claims is realized mainly by the provision request accepting unit 807 of the on-premises server device 8, and the function of the provided data transmitting means of the second destination device in the claims is realized mainly by the provided data providing unit 808 of the on-premises server device 8.
[0108] The first destination device in the claims corresponds to the receiving server device 4 in the embodiment. The function of the message data receiving means of the first destination device in the claims is realized mainly by the message data receiving unit 405 of the receiving server device 4. The function of the message data processing means of the first destination device in the claims is realized by the message data receiving unit 405 and the message data providing unit 406 of the receiving server device 4 working together.
[0109] Moreover, by forming a program for executing the processes shown in the flowcharts of Figures 9 and 10 and installing the program in a security device equipped with a control unit including a CPU, it is possible to realize a security device according to the present invention. That is, the functions of first report processing unit 111, fault determination unit 112, second report processing unit 113, recovery determination unit 114, report data acquisition unit 115, and retransmission processing unit 116 of security device 1 can be realized as functions of the control unit of the security device by a program executed in the control unit.
[0110] The report data receiving unit 405 and the report data providing unit 406 of the receiving server device 4 can also be realized as functions of the control unit 402 of the receiving server device 4 by a program executed in the control unit 402 of the receiving server device 4. The report data receiving unit 505 and the report notifying unit 506 of the security server device 5 can also be realized as functions of the control unit 502 of the security server device 5 by a program executed in the control unit 502 of the security server device 5. [Explanation of symbols]
[0111] 1...security device, 101T...connection end, 101...first communication I / F, 102...control unit, 103...storage device, 1031...report data file, 1032...past report data file, 1033...post-failure report data file, 104T1-104Tn...connection end, 104...sensor detection unit, 105(1)-105(n)...monitoring sensor, 106...clock circuit, 107T...connection end, 107...second communication I / F, 111...first report processing unit, 112...failure determination unit, 113...second report processing unit, 114...recovery determination unit, 115...report data acquisition unit, 116...retransmission processing unit, 2...gateway, 3 Internet, 4...receiving server device, 5...security server device, 6...control device, 7...other network, 8...on-premise server device
Claims
1. a notification data generating means for generating notification data when an occurrence of an abnormality is detected; a first notification processing means for transmitting the notification data formed by the notification data forming means to a first notification destination through a first network; a fault determination means for determining whether a fault has occurred on the first network side; a first storage means for storing and holding the report data that could not be transmitted to the first report destination as post-failure report data when the fault determination means determines that the fault has occurred; a second notification processing means for transmitting the post-failure notification data stored in the first storage means to a second notification destination through a second network different from the first network; a recovery determination means for determining whether or not the failure occurring on the first network side has been recovered from; a first provision request sending means for sending, when the recovery determination means determines that the failure has been recovered from, a first provision request to the second report destination, the first provision request requesting the second report destination to provide the post-failure report data including an arrival time at the second report destination; a first acquisition means for acquiring the post-failure report data including the arrival time returned from the second report destination in response to the first provision request as post-failure provision data from the second report destination; a first updating means for updating the arrival time of the post-failure provision data corresponding to the post-failure provision data acquired by the first acquiring means among the post-failure notification data stored and held in the first storage means; a first retransmission processing means for transmitting the post-failure report data, the arrival time of which has been updated by the first update means, to the first report destination through the first network; A security device comprising:
2. 2. The security device of claim 1, a second storage means for storing and holding the past report data generated by the report data generating means and transmitted to the first report destination as past report data; a third notification processing means for transmitting the past notification data stored in the second storage means to a second notification destination through a second network different from the first network when the failure determination means determines that the failure has occurred; a second provision request sending means for sending a second provision request to the second report destination when it is determined by the recovery determination means that the failure has been recovered from, the second provision request requesting the second report destination to provide the past report data including an arrival time; a second acquisition means for acquiring the past report data including the arrival time returned from the second report destination in response to the second provision request as past provision data from the second report destination; a second updating means for updating the arrival time of the past report data corresponding to the past provision data acquired by the second acquisition means among the past report data stored and held in the second storage means; a second retransmission processing means for transmitting the past report data, the arrival time of which has been updated by the second update means, to the first report destination via the first network; A security device comprising:
3. The security device according to claim 1 or 2, The notification data forming means forms the notification data to which a serial number is added. A security device characterized by:
4. A security system in which a security device and a first notification destination device are connected through a first network, and the security device and a second notification destination device are connected through a second network different from the first network, The security device is a notification data generating means for generating notification data when an occurrence of an abnormality is detected; a first notification processing means for transmitting the notification data formed by the notification data forming means to a first notification destination through a first network; a fault determination means for determining whether a fault has occurred on the first network side; a first storage means for storing and holding the report data that could not be transmitted to the first report destination as post-failure report data when the fault determination means determines that the fault has occurred; a second notification processing means for transmitting the post-failure notification data stored in the first storage means to a second notification destination through a second network different from the first network; a recovery determination means for determining whether or not the failure occurring on the first network side has been recovered from; a first provision request sending means for sending, when the recovery determination means determines that the failure has been recovered from, a first provision request to the second report destination, the first provision request requesting the second report destination to provide the post-failure report data including an arrival time at the second report destination; a first acquisition means for acquiring the post-failure report data including the arrival time returned from the second report destination in response to the first provision request as post-failure provision data from the second report destination; a first updating means for updating the arrival time of the post-failure provision data corresponding to the post-failure provision data acquired by the first acquiring means among the post-failure notification data stored and held in the first storage means; a first retransmission processing means for transmitting the post-failure report data, the arrival time of which has been updated by the first update means, to the first report destination through the first network; Equipped with The second destination device is a first provision request receiving means for receiving the first provision request from the security device; a provision data transmission means for transmitting the post-fault report data from the security device, the post-fault report data having an arrival time at the security device added thereto, as the post-fault provision data to the security device in response to the first provision request from the security device; Equipped with The first destination device is a notification data receiving means for receiving the notification data from the security device; a notification data processing means for processing the received notification data as if the data had a time of arrival added thereto, the notification data being the data that had arrived at the device at the time of arrival; A security system comprising:
Citation Information
Patent Citations
Phone system
JP2002176495A
Center device
JP2002329276A
Security system, security device, and security method
JP2006285645A