Unauthorized communication detection method, unauthorized communication detection device, and program

The unauthorized communication detection method and device enhance network security by using facility and device status to block unauthorized device control commands, addressing the vulnerability of existing systems that rely on administrator input.

JP7725445B2Active Publication Date: 2025-08-19PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022504408
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-03-04
Filing Date
2021-03-02
Publication Date
2025-08-19
Estimated Expiration
2041-03-02

AI Technical Summary

Technical Problem

Existing security measures in networks, such as those in vehicles or buildings, require administrator input for protection criteria, rendering them ineffective when no administrator is present, and are vulnerable to cyberattacks.

Method used

An unauthorized communication detection method and device that utilize first information indicating the facility status and device status to determine whether to execute device control commands, preventing unauthorized communications by detecting and blocking device control commands based on the presence of individuals and device states.

Benefits of technology

Enhances network security by preventing unauthorized device control commands, especially in the absence of administrators, thereby safeguarding connected devices from cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725445000001
    Figure 0007725445000001
  • Figure 0007725445000002
    Figure 0007725445000002
  • Figure 0007725445000003
    Figure 0007725445000003
Patent Text Reader

Abstract

The present invention is an improper communication detection method that detects an improper communication message on a network inside a facility, the network being connected so that two or more instruments, including a first instrument and a second instrument, can communicate with each other, wherein: a communication message transmitted from the first instrument to the second instrument is received from the first instrument (S3001); when the communication message has been received from the first instrument, if first information is acquired that indicates a person in the facility and at least one condition of the two or more instruments, and the communication message received from the first instrument is a communication message including an instrument control command for controlling the second instrument, it is determined whether to execute a process relating to the instrument control command on the basis of the first information (S3006); and if it is determined to execute the process relating to the instrument control command, the process is executed (S3008).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an unauthorized communication detection method, an unauthorized communication detection device, and a program. [Background technology]

[0002] In recent years, devices such as electronic control units in vehicles, home appliances, devices in buildings, devices in stores, and manufacturing equipment in factories have begun to connect to local networks within vehicles or buildings and to the Internet via routers and other devices. Connecting these devices to the Internet enables functions such as remote control, status monitoring, and integration of devices within a building. Meanwhile, cyberattacks targeting these connected devices have also occurred. Current cyberattacks have hijacked routers, personal computers, smartphones, and other devices, forcing them to participate in attacks on other servers on the Internet. Furthermore, hijacking routers, personal computers, smartphones, and other devices means that attackers can also attack devices within vehicles or buildings.

[0003] As a security measure against attacks on devices connected to a network (such as a local area network (LAN)) that is restricted to a certain space, such as inside a vehicle or a building, there is a method disclosed in Patent Document 1, for example. According to the method of Patent Document 1, for communications that are completed within the network inside a vehicle or a building, a countermeasure device determines whether to pass or discard packets, making it possible to restrict communications between devices at any timing. This makes it possible, for example, to restrict specific communication services within the network. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 4082613 Summary of the Invention [Problem to be solved by the invention]

[0005] However, the method disclosed in Patent Document 1 requires an administrator to input data (restriction criteria) that serves as the criteria for determining whether a packet is allowed to pass or discard into a countermeasure device, and in a network where no administrator is present, the network may not be protected because the data that serves as the criteria cannot be input. Also, even if an administrator is present, the network may not be protected until the administrator inputs the data that serves as the criteria. In other words, there is room for improvement in security measures against attacks on devices.

[0006] In order to solve the above-mentioned problems, the present disclosure provides an unauthorized communication detection method, an unauthorized communication detection device, and a program with improved security measures. [Means for solving the problem]

[0007] An unauthorized communication detection method according to one embodiment of the present disclosure is a method for detecting unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are connected to each other so that they can communicate with each other, and includes the following steps: a receiving step for receiving from the first device a communication message transmitted from the first device to the second device; an acquisition step for acquiring, when the communication message is received from the first device, first information indicating a person in the facility in which the in-facility network is installed and the status of at least one of the two or more devices; a first determination step for determining, based on the first information, whether to execute processing related to the device control command if the communication message received from the first device is a communication message including a device control command for controlling the second device; and an execution step for executing the processing if it is determined in the first determination step that the processing related to the device control command should be executed.

[0008] An unauthorized communication detection device according to one embodiment of the present disclosure is an unauthorized communication detection device that detects unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are connected to each other so that they can communicate with each other, and includes: a receiving unit that receives from the first device a communication message transmitted from the first device to the second device; an acquiring unit that acquires first information indicating a person in the facility in which the in-facility network is installed and the status of at least one of the two or more devices when the communication message is received from the first device; a determination unit that, when the communication message received from the first device is a communication message including a device control command for controlling the second device, determines based on the first information whether to execute processing related to the device control command; and an execution unit that executes the processing when the determination unit determines that the processing related to the device control command should be executed.

[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the unauthorized communication detection method described above. [Effects of the Invention]

[0010] According to one aspect of the present disclosure, it is possible to realize an unauthorized communication detection method and the like with improved security measures. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram showing the overall configuration of an unauthorized communication detection system according to the first embodiment. [Figure 2] FIG. 2 is a configuration diagram of a home gateway according to the first embodiment. [Figure 3] FIG. 3 is a diagram showing an example of a status list according to the first embodiment. [Figure 4] FIG. 4 is a diagram showing an example of a determination list according to the first embodiment. [Figure 5] FIG. 5 is a diagram showing an example of a device list according to the first embodiment. [Figure 6]FIG. 6 is a flowchart illustrating an example of a main process of the home gateway according to the first embodiment. [Figure 7] FIG. 7 is a flowchart illustrating an example of the classification process of the classification unit according to the first embodiment. [Figure 8] FIG. 8 is a flowchart illustrating an example of a determination process of the home gateway according to the first embodiment. [Figure 9] FIG. 9 is a configuration diagram of a home gateway according to the second embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a determination list according to the second embodiment. [Figure 11] FIG. 11 is a diagram showing an example of a mode determination list according to the second embodiment. [Figure 12] FIG. 12 is a diagram showing another example of the determination list according to the second embodiment. [Figure 13] FIG. 13 is a diagram showing another example of the mode determination list according to the second embodiment. [Figure 14] FIG. 14 is a flowchart illustrating an example of a determination process of the home gateway according to the second embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of the overall configuration of an unauthorized communication detection system according to the first modification. [Figure 16] FIG. 16 is a diagram showing another example of the overall configuration of the unauthorized communication detection system according to the first modification. [Figure 17] FIG. 17 is a configuration diagram of a home gateway according to the second modification. [Figure 18] FIG. 18 is a flowchart illustrating an example of a main process of the home gateway according to the second modification. [Figure 19] FIG. 19 is a flowchart showing another example of the main process of the home gateway according to the second modification. [Figure 20] FIG. 20 is a configuration diagram of a home gateway according to the third modification. [Figure 21] FIG. 21 is a flowchart showing an example of a determination process of a home gateway according to the third modification. [Figure 22] FIG. 22 is a configuration diagram of a home gateway according to the fourth modification. [Figure 23] FIG. 23 is a flowchart showing an example of a determination process of a home gateway according to the fourth modification. [Figure 24] FIG. 24 is a flowchart showing an example of classification processing according to the fifth modification. [Figure 25] FIG. 25 is a flowchart showing an example of a classification update process according to the sixth modification. [Figure 26] FIG. 26 is a diagram showing an example of a determination list according to the seventh modification. [Figure 27] FIG. 27 is a diagram showing another example of the determination list according to the eighth modification. [Figure 28] FIG. 28 is a diagram showing an example of a mode determination list according to the ninth modification. [Figure 29] FIG. 29 is a diagram showing yet another example of the determination list according to the ninth modification. [Figure 30] FIG. 30 is a diagram showing an example of mode transition according to the tenth modification. [Figure 31] FIG. 31 is a configuration diagram of a home gateway according to the tenth modification. [Figure 32] FIG. 32 is a flowchart showing an example of a determination process of a home gateway according to the eleventh modification. [Figure 33] FIG. 33 is a configuration diagram of a home gateway according to the eleventh modification. [Figure 34] FIG. 34 is a flowchart showing an example of a determination process of a home gateway according to the eleventh modification. [Figure 35] FIG. 35 is a diagram showing an example of the configuration of an electric lock according to the twelfth modification. [Figure 36] FIG. 36 is a flowchart showing an example of a determination process of an electric lock according to the twelfth modification. [Figure 37] FIG. 37 is a diagram showing another example of the configuration of an electric lock according to the twelfth modification. [Figure 38]FIG. 38 is a flowchart showing another example of the determination process of the electric lock according to the twelfth modification. DETAILED DESCRIPTION OF THE INVENTION

[0012] An unauthorized communication detection method according to one embodiment of the present disclosure is a method for detecting unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are connected to each other so that they can communicate with each other, and includes the following steps: a receiving step for receiving from the first device a communication message transmitted from the first device to the second device; an acquisition step for acquiring, when the communication message is received from the first device, first information indicating a person in the facility in which the in-facility network is installed and the status of at least one of the two or more devices; a first determination step for determining, based on the first information, whether to execute processing related to the device control command if the communication message received from the first device is a communication message including a device control command for controlling the second device; and an execution step for executing the processing if it is determined in the first determination step that the processing related to the device control command should be executed.

[0013] This makes it possible to prevent the execution of a process related to a device control command that is unlikely to be sent in a certain state based on the state of at least one of a person in a facility where an intranet is installed and two or more devices. For example, it is possible to detect unauthorized communication messages that cannot be detected when the execution of a process is determined based on a communication message including a device control command. Therefore, according to one aspect of the present disclosure, security measures are improved.

[0014] Also, for example, the in-facility network may further include a relay device that relays the communication messages transmitted and received between the two or more devices, and that executes the unauthorized communication detection method, and the processing related to the device control command may be a processing of sending the communication message including the device control command to the second device, and in the first determination step, the determination of whether to execute the processing related to the device control command may include determining whether to send the communication message including the device control command to the second device, and in the execution step, the execution of the processing may include sending the communication message to the second device.

[0015] This makes it possible to prevent unauthorized communication messages from being sent to the second device, which means that unauthorized control can be prevented from being exercised in the second device.

[0016] Also, for example, the first information may include the status of people in the facility, and in the first determination step, if it can be determined from the first information that there are people in the facility, it may be determined that the communication message including the equipment control command should be sent to the second equipment, and if it can be determined from the first information that there are no people in the facility, it may be determined that the communication message including the equipment control command should not be sent to the second equipment.

[0017] This makes it possible to prevent a communication message including a device control command that would not normally occur in a person's state from being sent to the second device. Also, by simply acquiring the person's state, it is possible to determine whether or not to send a communication message to the second device.

[0018] Also, for example, the second device may be installed at the entrance of the facility, and in the first determination step, if it can be determined from the first information that there are people only near the entrance of the facility, it may be determined that the communication message including the device control command should be sent to the second device.

[0019] This makes it possible to prevent a communication message from being sent to a device other than the entrance when a person is near the entrance. For example, when a person leaves the facility, it is possible to prevent a communication message that is likely to be an unauthorized communication message, such as a message that turns on the lights in the facility, from being sent to the second device.

[0020] Also, for example, the method may further include a second determination step of determining a forwarding determination mode of the relay device based on the first information, and in the first determination step, it may be determined whether or not to send the communication message including the device control command to the second device based on the forwarding determination mode of the relay device determined in the second determination step.

[0021] In this way, by using the transfer determination mode determined in the second determination step in the first determination step, the amount of processing in the first determination step can be reduced, and the first determination step can be performed quickly, which contributes to improving security measures.

[0022] Also, for example, in the second determination step, if it can be determined from the first information that there is someone in the facility, the transfer determination mode can be determined to be active mode, and if it can be determined from the first information that there is no person in the facility, the transfer determination mode can be determined to be absent mode, and in the first determination step, if the transfer determination mode is active mode, it can be determined to send the device control command to the second device, and if the transfer determination mode is absent mode, it can be determined not to send the device control command to the second device.

[0023] As a result, in the first determination step, it is possible to determine whether to transmit the communication message to the second device based on whether the forwarding determination mode is the active mode or the absent mode. In other words, this determination can be easily made.

[0024] Also, for example, the transfer determination mode may further include an inactive mode, and in the second determination step, if the first information indicates that there is a person in the facility and that the person is active, the transfer determination mode may be determined to be the active mode, and if the first information indicates that there is a person in the facility and that the person is not active, the transfer determination mode may be determined to be the inactive mode.

[0025] As a result, since there are three transfer determination modes, the determination in the first determination step can be more detailed than when there are two transfer determination modes, making it possible to more appropriately determine whether to transmit the communication message to the second device depending on the state of the facility at the time the communication message is received.

[0026] Also, for example, the second device may be an electric lock, and the device control command may include either an unlock command for unlocking the electric lock or another command other than the unlock command, and in the first determination step, when the transfer determination mode is the active mode, it may be determined that the unlock command and the other command will each be sent to the second device, when the transfer determination mode is the inactive mode, it may be determined that of the unlock command and the other commands, only the other command will be sent to the second device, and when the transfer determination mode is the absent mode, it may be determined that the unlock command and the other command will not each be sent to the second device.

[0027] This makes it possible to appropriately determine whether or not important commands such as an unlock command can be sent, while preventing unnecessary determinations that other commands should not be sent.

[0028] Furthermore, for example, in the second determination step, if it can be determined from the first information that there are people only near the entrance of the facility, the transfer determination mode may be determined to be entrance mode, and in the first determination step, if the transfer determination mode is entrance mode and the first device is not near the entrance, it may be determined not to send the unlock command.

[0029] This eliminates the inconvenience of not being able to open the front door when the relay device remains in "away mode" and unlocking commands from outside are not permitted because only the unlocking command from the device (e.g., smartphone) carried by the person who returned home while everyone else was out is permitted (sent), which eliminates the inconvenience of not being able to open the front door. In addition, the relay device can prevent attacks such as unauthorized turning on of devices (e.g., air conditioners or lights) installed in rooms that are difficult to see from the front door when the residents are out.

[0030] Furthermore, for example, in the second determination step, if the first information indicates that there is a person in the facility and that the person is the only person who is not authorized to control the two or more devices via the facility network, the transfer determination mode may be determined to be an away mode, and in the first determination step, if the transfer determination mode is the away mode, it may be determined that of the unlock command and the other command, only the other command should be sent.

[0031] This prevents unauthorized unlocking commands from being sent to the electric lock, and can prevent intruders from breaking into a house when only children are present.

[0032] Also, for example, the unauthorized communication detection method may be executed by the second device, the processing related to the device control command may be processing for executing the device control command included in the communication message, and in the first determination step, the determination of whether or not to execute the processing related to the device control command may be made by determining whether or not the second device executes the device control command, and in the execution step, the execution of the processing may be made by controlling the operation of the second device based on the device control command.

[0033] This allows the second device itself to detect unauthorized communications, thereby further improving security measures in the in-house network.

[0034] Also, for example, the second device may be an electric lock, and the device control command may be an unlock command for unlocking the electric lock.

[0035] This effectively prevents suspicious individuals from entering the facility, thereby enabling effective security measures to be implemented in the facility.

[0036] Furthermore, for example, the method may further include, between the first determination step and the execution step, an update step of updating the first information based on the people in the facility and the status of at least one of the two or more devices after it is determined that the processing related to the device control command is to be executed, if any.

[0037] This allows the first information to be updated before the next first determination step is performed, thereby reducing the amount of processing required for the next first determination step, and thus allowing the first determination step to be performed more quickly.

[0038] Also, for example, in the first determination step, if the communication message is a message including the device control command, it is determined whether or not to execute the processing related to the device control command based on a predetermined condition, and the predetermined condition may include that the first device is a device having a predetermined function.

[0039] This makes it possible to prevent a message containing a device control command from being sent from a device that does not have a predetermined function to a second device on an intra-facility network. For example, if a device that does not have a predetermined function is more susceptible to external cyber-attacks than a device that has the predetermined function, it is possible to prevent a message from being sent from a first device that does not have the predetermined function to a second device. Furthermore, even if a device that does not have the predetermined function is attacked and masquerades as a "device with the predetermined function" midway through, the masquerading device can be identified as a "device that does not have the predetermined function" using the device list. Thus, it is possible to realize an unauthorized communication detection method with further improved security measures.

[0040] Furthermore, for example, the facility may be a residence.

[0041] This allows for improved security measures in home networks.

[0042] In addition, an unauthorized communication detection device according to one embodiment of the present disclosure is an unauthorized communication detection device that detects unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are connected to each other so that they can communicate with each other, and includes: a receiving unit that receives from the first device a communication message transmitted from the first device to the second device; an acquiring unit that, when receiving the communication message from the first device, acquires first information indicating a person in the facility in which the in-facility network is installed and the status of at least one of the two or more devices; a determination unit that, when the communication message received from the first device is a communication message including a device control command for controlling the second device, determines based on the first information whether to execute processing related to the device control command; and an execution unit that executes the processing when the determination unit determines that the processing related to the device control command should be executed.

[0043] This provides the same effect as the unauthorized communication detection method described above.

[0044] A program according to one aspect of the present disclosure is a program for causing a computer to execute the unauthorized communication detection method described above.

[0045] This provides the same effect as the unauthorized communication detection method described above.

[0046] Hereinafter, with reference to the drawings, a description will be given of an unauthorized communication detection system and the like according to embodiments of the present disclosure. Note that each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, component arrangements and connection forms, steps, and step order shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is defined based on the claims. Therefore, among the components in the following embodiments, components that are not recited in the independent claims that represent the superordinate concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.

[0047] In addition, the drawings are not necessarily strict illustrations. In the drawings, substantially the same components are denoted by the same reference numerals, and overlapping descriptions may be omitted or simplified.

[0048] Furthermore, in this specification, terms indicating relationships between elements such as "same," as well as numerical values and numerical ranges, are not expressions that only express a strict meaning, but are expressions that also include a substantially equivalent range, for example, a difference of about a few percent.

[0049] (Embodiment 1) The unauthorized communication detection system according to the first embodiment of the present disclosure determines whether a device control command is unauthorized based on, for example, the operating state of each home appliance, the state of the resident living in the house estimated from information obtained from each sensor and at least one of each home appliance. The configuration of the unauthorized communication detection system according to the first embodiment of the present disclosure will be described below.

[0050] [1. Details of the First Embodiment] Here, as an embodiment of the present disclosure, an unauthorized communication detection system according to the present disclosure will be described with reference to the drawings. Note that in this embodiment, a case where home appliances (home electronic devices) and PCs (personal computers) are connected to a home (in-home) network (home network 11) is shown. That is, in this embodiment, the unauthorized communication detection system is a system that detects unauthorized communication within a home. Note that the application of the unauthorized communication detection system is not limited to homes, but may also be factories, buildings, hospitals, vehicles, etc. A home is an example of a facility to which the unauthorized communication detection system is applied.

[0051] [1.1 Overall configuration of the fraudulent communication detection system] FIG. 1 is a diagram showing the overall configuration of an unauthorized communication detection system according to this embodiment.

[0052] As shown in FIG. 1, the unauthorized communication detection system includes the Internet 10, a home network 11, a home gateway 20, a PC 30, an electric lock 40, an air conditioner 41, a light 42, a controller 43, and a terminal 50. The Internet 10 is a general Internet, and the PC 30 is a general personal computer. The home gateway 20, the PC 30, the electric lock 40, the air conditioner 41, the light 42, and the controller 43 are connected to each other via the home network 11, and when the PC 30, the electric lock 40, the air conditioner 41, the light 42, and the controller 43 communicate with a server or a terminal 50 outside the home, the communication is performed via the home gateway 20. The home network 11 is a communication network that connects two or more devices (e.g., the electric lock 40, the air conditioner 41, the light 42, and the controller 43) so that they can communicate with each other. The home network 11 is an example of an in-facility network.

[0053] The home gateway 20 is connected to the PC 30, electric lock 40, air conditioner 41, lighting 42, and controller 43, and functions as an intermediary for communication between the connected devices and communication between the connected devices and the Internet 10. The home gateway 20 also manages information such as IP (Internet Protocol) addresses required for communication between the PC 30, electric lock 40, air conditioner 41, lighting 42, and controller 43, and assigns IP addresses and notifies the devices of information required for communication in response to requests from the devices. The home gateway 20 also monitors whether unauthorized device control commands are being sent to the electric lock 40, air conditioner 41, and lighting 42, and blocks unauthorized device control commands as necessary. The home gateway 20 is a relay device that relays communication messages sent and received between two or more devices. It is an example of a relay device that executes the unauthorized communication detection method described below, and is also an example of an unauthorized communication detection device.

[0054] The electric lock 40, the air conditioner 41, and the lighting 42 are devices (home appliances) that receive device control commands, interpret the contents of the received device control commands, and operate accordingly. The electric lock 40, the air conditioner 41, and the lighting 42 also notify other devices of their operating status or information (sensor information) detected by sensors installed in each device. For example, when a locking operation is performed, the electric lock 40 transmits a message to other devices notifying them that the device is locked after the operation is completed. When an unlocking operation is performed, the electric lock 40 also transmits a message to other devices notifying them that the device is unlocked, just like when a locking operation is performed. Furthermore, for example, the air conditioner 41 notifies other devices of its operating state, such as whether it is operating (ON) or not (OFF), the operating mode of the air conditioner 41 (automatic / cooling / heating / dehumidifying / humidifying / fan, etc.), the set temperature of the air conditioner 41, information from sensors mounted on the air conditioner 41 (room temperature / humidity / outdoor temperature), and set values of the air conditioner 41, such as wind direction and air volume. Also, for example, the lighting 42 notifies other devices of its operating state, whether it is ON or OFF, and the set value of a dimming function if it has one. These notifications may be made periodically, when the state or value changes, or when an inquiry is made from another device.

[0055] The electric lock 40, the air conditioner 41, and the lighting 42 are examples of devices connected to the home network 11. The electric lock 40 is also an example of a second device. The unauthorized communication detection system may include two or more devices.

[0056] The controller 43 is a device for controlling the electric lock 40, the air conditioner 41, and the lighting 42, and controls these devices by sending device control commands to the electric lock 40, the air conditioner 41, and the lighting 42. The controller 43 may send device control commands in response to input from a user, or may send device control commands automatically in response to pre-set conditions. The controller 43 may be a device dedicated to the home network 11, or may be a mobile terminal such as a smartphone.

[0057] The terminal 50 is a device connected to the Internet 10 via a mobile phone network (wireless), and is used to view the status of the electric lock 40, air conditioner 41, and lights 42 from outside the home, or to receive notifications from the home gateway 20. Note that there may be a server (not shown) connected to the Internet 10, and the home gateway 20 and the terminal 50 may exchange information with each other by communicating with the server via the Internet 10. The terminal 50 may also be a mobile terminal such as a smartphone.

[0058] In this embodiment, the electric lock 40, the air conditioner 41, and the light 42 are used as three components of the device control command monitoring system as devices that receive device control commands, but these three devices are not necessarily required and other devices may be included, and the number of devices does not necessarily have to be three. Furthermore, these devices may not only receive device control commands but also transmit device control commands to other devices or may perform communications other than device control commands. Furthermore, these devices may communicate with a terminal 50 or a server (not shown) on the Internet 10 via the Internet 10.

[0059] Although the terminal 50 is said to be connected to the Internet 10, this is not limited to this, and it may be directly connected to the home gateway 20 to view the status of the electric lock 40, air conditioner 41, and lighting 42, control the equipment, or receive notifications from the home gateway 20.

[0060] In the following description, the air conditioner 41 will be referred to as the first device and the electric lock 40 as the second device, but this is not limiting. The first device may be any device that can transmit a device control command to the second device via the home gateway 20, and may also be referred to as the device that transmits the device control command. The first device may be, for example, a portable terminal such as the terminal 50. The second device may be any device that is located in the home. The second device may also be referred to as the device to which the device control command is transmitted.

[0061] [1.2 Home Gateway 20 Configuration] FIG. 2 is a configuration diagram of the home gateway 20 according to this embodiment.

[0062] As shown in FIG. 2, the home gateway 20 includes a receiving unit 100, an initial device list creation unit 110, an unregistered device detection unit 120, a classification unit 130, a home appliance message determination unit 140, a forwarding determination unit 150, a transmitting unit 160, a device list holding unit 200, and a status holding unit 210.

[0063] These configurations indicate functions, and are realized by reading and executing a program stored in a memory unit in the home gateway 20 using a processing unit, storing specified data in the memory unit, or transmitting and receiving data via an input / output unit, or by a combination of these.

[0064] The receiving unit 100 receives communication messages from the Internet 10 or the home network 11. The receiving unit 100 receives not only communication messages addressed to the home gateway 20 but also all communication messages flowing through the communication line to which the home gateway 20 is connected.

[0065] The initial device list creation unit 110 creates a device list when the home gateway 20 is connected to the home network 11. When the initial device list creation unit 110 is first started up, when the device list storage unit 200 does not contain a device list, such as when the user instructs initialization of the device list stored in the device list storage unit 200, or when the device list has been deleted. The initial device list creation unit 110 searches for devices connected to the home network 11 and registers the found devices in the device list. The initial device list creation unit 110 also requests the classification unit 130 to classify the devices registered by the initial device list creation unit 110. As will be described in detail later, the device list includes information about two or more devices connected to the home network 11. In this embodiment, the device list includes information about the PC 30, the electric lock 40, the air conditioner 41, the lighting 42, and the controller 43. The device list may also include information about a terminal 50 connected to the home gateway 20.

[0066] The unregistered device detection unit 120 compares information relating to at least one of the sender and destination of the communication message received by the receiving unit 100 with information registered in the device list holding unit 200, and checks whether at least one of the sender and destination devices of the communication message is registered in the device list holding unit 200. If at least one of the sender and destination devices of the communication message is not registered in the device list holding unit 200, the unregistered device detection unit 120 requests the classification unit 130 to classify the device and register it in the device list holding unit 200.

[0067] The classification unit 130 classifies each of two or more devices connected to the home network 11 as to whether the device has a predetermined function. An example of the predetermined function is that the device supports a predetermined communication protocol in the home network 11. In this embodiment, the classification unit 130 classifies each of the two or more devices connected to the home network 11 as either a home appliance (including home equipment) or a non-home appliance. For example, the classification unit 130 classifies a device that can communicate using a protocol for controlling home appliances (an example of a predetermined communication protocol) as a home appliance, and classifies a device that cannot communicate using a protocol for controlling home appliances as a non-home appliance. For example, in ECHONET Lite (registered trademark, the same applies hereinafter), the classification unit 130 registers a device that correctly responded to an inquiry message sent by the home gateway 20 as a home appliance, and registers a device that did not respond or a device that did not correctly respond as a non-home appliance.

[0068] The two or more devices may include, for example, at least one home appliance. The predetermined communication protocol is a communication protocol for performing short-range wireless communication between the home gateway 20 and the terminal 50, such as, but not limited to, ECHONET Lite or ZigBEE (registered trademark, the same applies hereinafter).

[0069] Home appliance message determination unit 140 determines whether a message received by receiving unit 100 is a message (home appliance message) related to a protocol for controlling a home appliance, and if it determines that the received communication message is a home appliance message, requests forwarding determination unit 150 to determine whether to transmit (forward) the message to a destination. When determining whether a received message is a home appliance message, home appliance message determination unit 140 may determine that the received message is a home appliance message if the destination port number of the received message is 3610, for example, because the ECHONET Lite standard specifies that communication is performed using port number 3610 of UDP (User Datagram Protocol). Furthermore, the ECHONET Lite standard also specifies that the first two bytes of communication data are set to 0x1081 or 0x1082, so home appliance message determination unit 140 may determine that the received message is a home appliance message if the first two bytes of the data portion of the received message are 0x1081 or 0x1082. Furthermore, the home appliance message determination unit 140 may make a determination by combining the above or by using other information.

[0070] In this way, the home appliance message determination unit 140 determines, from the content of the communication message, whether the communication message conforms to a protocol assumed by the home gateway 20. If the home gateway 20 supports multiple protocols, the home appliance message determination unit 140 determines which protocol the communication message conforms to. In this case, when the home appliance message determination unit 140 determines that the communication message does not conform to any protocol, it determines that the message is not related to a protocol for controlling a home appliance.

[0071] When the home appliance message determination unit 140 determines that the received communication message (received message) is a home appliance message, the forwarding determination unit 150 further determines whether to transmit (forward) the received message to a destination described in the received message. The forwarding determination unit 150 is an example of a determination unit. The process of transmitting (forwarding) the received message (communication message including a device control command) is an example of a process related to a device control command.

[0072] The forwarding determination unit 150 acquires information about the sending device from the received message and acquires the device number from the device list held by the device list holding unit 200 (described later). If the received message includes information about the status of the device that sent the message, the forwarding determination unit 150 acquires the information about that status and registers it in a status list held by the status holding unit 210 (described later). If the received message includes sensor information, the forwarding determination unit 150 registers the sensor information in the status list. Furthermore, if the received message includes information about the status of the device that sent the message or if the message includes sensor information, the forwarding determination unit 150 estimates the status of the resident living in the house from that information or from that information and the information registered in the status list, and registers it in the status list. After registering the status, the forwarding determination unit 150 requests the sending unit 160 to forward the received message.

[0073] Furthermore, if the home gateway 20 is equipped with any kind of sensor, it may register the sensor information of that sensor in the status list, or may estimate the status of the resident living in the house from the sensor information or from the sensor information and the information registered in the status list, and register the estimated status in the status list.

[0074] When the received message contains a device control command, the transfer determination unit 150 obtains from the status holding unit 210 a status list that holds the status of each device at that time and a determination list (rules) regarding each control command for the device controlled by the device control command, and determines whether or not the device control command can be transferred.

[0075] Fig. 3 is a diagram showing an example of a status list according to this embodiment. Fig. 4 is a diagram showing an example of a determination list according to this embodiment. Fig. 4 is an example of a determination list related to an unlock command for electric lock 40. The status list shown in Fig. 3 is an example of first information. The first information indicates the status of people present in the home in which home network 11 is installed and at least one of two or more devices. Each of the two or more devices may be fixedly installed in the home in which home network 11 is installed, or may be portable.

[0076] As shown in Fig. 4, the determination list holds, in list form, information (OK / NG) as to whether or not it is OK to transfer the unlock command for the electric lock 40 ("Electric Lock Unlock Determination" shown in Fig. 4), and information on at least one state of each device and resident (an example of a person in a facility where an intra-facility network is provided). The transfer determination unit 150 determines which state in the determination list the current state (the state shown in Fig. 3) matches, and sets the information (OK / NG) as to whether or not it is OK to transfer the unlock command corresponding to the matching state as the determination result for the current state.

[0077] For example, if the status of each device and resident is the status shown in the status list of Fig. 3, the transfer determination unit 150 recognizes that at least one status of each device and resident is the status in the last row in the determination list of Fig. 4, determines that the transfer of the unlock command for the electric lock 40 is "NG," and does not transfer the received message. Furthermore, according to the determination list of Fig. 4, the transfer determination unit 150 determines that the transfer of the unlock command for the electric lock 40 is "NG" even in cases other than those shown in the status list of Fig. 3, such as when all residents are absent and the air conditioner 41 and lights 42 are OFF, and also when the air conditioner 41 and lights 42 are "ON" and all residents are on the second floor. Furthermore, the transfer determination unit 150 determines that the transfer of the unlock command for the electric lock 40 is "OK" when the air conditioner 41 is ON, the lights 42 are OFF, and the resident is on the first floor. In addition, the transfer determination unit 150 may determine that the transfer of the unlock command for the electric lock 40 is "NG" if all residents are absent regardless of the status of the air conditioner 41, lights 42, etc., or may determine that the transfer of the unlock command for the electric lock 40 is "OK" if both the air conditioner 41 and lights 42 are "ON" and at least one resident is on the first floor. Furthermore, if a Wi-Fi access point (Wi-Fi AP) is installed in the home network 11 and the Wi-Fi AP is communicating with a smartphone carried by a resident, the transfer of the unlock command for the electric lock 40 sent from the smartphone may be determined to be "OK."

[0078] 3 may include the status of at least one of the people in the home and the two or more devices. In this embodiment, the status list includes the status of both the people in the home and the two or more devices. The status list may also include the status of at least one of the two or more devices.

[0079] If the message received by the receiving unit 100 is not a home appliance message, or if the forwarding determination unit 150 determines that the message should be forwarded, the transmitting unit 160 transmits (transfers) the message to the destination. In this embodiment, the transmitting unit 160 transmits a communication message from a first device to a second device as the execution of a process related to a device control command. The transmitting unit 160 is an example of an executing unit.

[0080] The device list holding unit 200 holds information about two or more devices connected to the home network 11 in a list format as a device list. Fig. 5 is a diagram showing an example of a device list according to this embodiment.

[0081] As shown in FIG. 5, in the device list, MAC (Media Access Control) addresses, which are an example of identifiers, and device types classified by the classification unit 130 are registered in association with each other.

[0082] The status storage unit 210 stores information about the status of home appliances connected to the home network 11 as a status list (see FIG. 3). The status list shown in FIG. 3 registers the device numbers of home appliances registered in the device list stored by the device list storage unit 200 and the status of residents living in the house. The status storage unit 210 also stores a determination list (see FIG. 4) that serves as a criterion for the transfer determination unit 150 to determine whether to transfer. The determination list shown in FIG. 4 stores information (in the case of FIG. 4, "OK" and "NG") about the device control command to be determined (the unlock determination of the electric lock 40 in the case of FIG. 4), as well as the device numbers and statuses of home appliances registered in the device list stored by the device list storage unit 200 and the status of residents living in the house as conditions for determining the information about the device control command. In this case, the status of at least one of the device and the resident may be any status, in which case a symbol such as "-" may be used to represent the condition.

[0083] The device list storage unit 200 and the status storage unit 210 are realized by, for example, a hard disk drive (HDD) or a semiconductor memory, but are not limited to this.

[0084] In the above description, the classification unit 130 classifies two or more devices connected to the home network 11 into home appliances and non-home appliances. However, this is not limiting and the devices may be classified into devices that can be controlled by the home gateway 20 and devices that cannot be controlled by the home gateway 20. Devices that cannot be controlled by the home gateway 20 include, for example, devices for which a control method is not implemented in the home gateway 20. Devices that can be controlled by the home gateway 20 are devices that have a function that can be controlled by a control method implemented in the home gateway 20, and are an example of devices that have a predetermined function. These devices can also be said to be devices that can be controlled by the home gateway 20. Devices that cannot be controlled by the home gateway 20 are devices that do not have a function that can be controlled by a control method implemented in the home gateway 20, and are an example of devices that do not have a predetermined function.

[0085] Furthermore, the classification unit 130 may classify appliances into three or more categories instead of two categories. For example, when a plurality of appliances compatible with different protocols for controlling the appliances are connected to the home network 11 and the appliances compatible with the same protocol communicate with each other, the classification unit 130 may classify the appliances by the type of protocol. Furthermore, the classification unit 130 may classify appliances into, for example, controlled appliances, controlling appliances, and non-home appliances, or into at least three or more categories among controlled appliances, controlling appliances, controlling / controlled appliances, appliances that only notify information such as sensor information, and non-home appliances, or may classify only some of these categories or a combination of these categories.

[0086] 5 may register information other than MAC addresses and device types, or may use information other than MAC addresses as identifiers. For example, IP addresses may be registered, or if home gateway 20 has multiple communication ports for connecting communication lines, the communication ports to which devices are connected may be registered. It may also be possible to register whether a device only transmits, only receives, or both transmits and receives control messages to control home appliances, or to register detailed types of home appliances, such as whether the appliance is an electric lock, air conditioner, lighting, or controller.

[0087] Note that while Figure 3 only shows ON and OFF as the device states, this is not limited to this. For example, in the case of an electric lock 40, the unlocked / locked state may be registered; in the case of an air conditioner 41, in addition to ON / OFF, the set temperature, operation mode (cooling / heating, etc.) etc. may be registered; in the case of lighting 42, in addition to ON / OFF, the dimming state may be registered; in the case of a human presence sensor (not shown), whether a person is detected / not detected may be registered; in the case of a temperature and humidity sensor (not shown), the temperature or humidity value itself may be registered; in the case of a window or door opening / closing sensor, information such as open / closed, a numerical value indicating how far open it is, and the lock state (locked / unlocked) may be registered.

[0088] Furthermore, as for the resident's status, in addition to present / absent, information on where in the house the resident is located, such as on the first floor only / on the second floor only, in the bedroom only / in the living room only / in the dining room and kitchen, or attributes of the person at home, such as only children present / only grandparents present, or what the resident is doing, such as sleeping, or whether they are active, may also be registered. Also, in Figure 3, one status is registered for each device and resident, but multiple statuses may be registered, each status may be registered in a separate column, parents and children may be registered in separate columns, each resident may be registered in a separate column, or there may be a column for guests.

[0089] The resident's status is registered by analyzing the usage status of each device or information from various sensors. The resident's status may be determined, for example, from information from a motion sensor installed in the home, or from information obtained by analyzing images or videos from a camera installed in the home. The resident's status may also be determined by having each resident carry a transmitter such as an RF tag, and using a receiver such as an RF receiver installed in the home to determine the location of the transmitter in the home, whether the transmitter is operating, and whether the transmitter is operating. The resident's status may also be determined by having each resident carry a receiver, installing the transmitter in the home, and notifying a server or home gateway 20 or other in-home controller of the received signal. Alternatively, the resident's status may be determined from information obtained by tracking the resident's movements using an indoor positioning system, or from other information.

[0090] In addition, the status of residents may be determined from sensor information obtained from each home appliance (for example, information from refrigerator open / close sensors, information from window and door open / close sensors, water usage in the kitchen and bathroom, room temperature, humidity, chemical substance concentrations such as carbon dioxide concentration or changes therein, etc.), which can determine whether a person is actually in the house or whether a person is moving.

[0091] The determination list shown in FIG. 4 is merely an example, and other devices may be included. The device status may not be defined individually, but may be grouped by device type, the room in which the device is installed, or the like. Furthermore, the device and resident status may include not only ON / OFF but also various other states and information, as in the status list. For example, the device's operating mode, dimming status, temperature or humidity value itself, etc., may be registered as a status. Multiple states may be registered, or they may be registered in separate columns. Furthermore, if a determination can be made regardless of the specific state of a certain device, the determination list may include information such as device number, identifier, and device type as information on permitted and prohibited senders. Furthermore, the status list may include information on communication messages other than home appliance messages, such as information on the most recently accessed site on the Internet 10, the communication protocol used, and information exchanged using the protocol used. Although Figure 4 shows only one judgment list, there may be other judgment lists corresponding to each device control command for each device, such as a judgment list for determining whether an electric lock is locked, a judgment list for determining whether an air conditioner is on or off, a judgment list for determining whether an air conditioner is changed in operation mode or set temperature, and a judgment list for determining whether lights are turned on or off or dimming settings, or the list may be divided into a judgment list for determining whether a device control command is OK and a judgment list for determining whether a device control command is NG.

[0092] In the above description, when a received message includes information about the status of the device that sent the message, the forwarding determination unit 150 registers the status in the status list of the status storage unit 210 and forwards the received message. However, this is not limited to this. As with device control commands, the forwarding determination unit 150 may register the status information and forward the received message only when it determines that the device status information included in the received message is correct. Alternatively, the forwarding determination unit 150 may register the status information only when it determines that the status is correct, and forward the received message regardless of the determination result. Furthermore, when it determines that the status is not correct, the forwarding determination unit 150 may notify the user, or may leave the decision of whether to forward the message to the user. For example, the transfer judgment unit 150 may register the temperature and humidity values within a normal range of values or a predetermined amount of change in a judgment list, and if the values fall outside the range of the registered values or if there is a sudden change compared to the registered amount of change, determine that the state is not correct.Furthermore, the transfer judgment unit 150 may register the amount of change that is determined to be the correct state for each state of window and door (open / closed, how open it is), in a judgment list, and determine that the state is not correct if there is a sudden change compared to the registered value.

[0093] Note that the transfer determination unit 150 determines whether or not it is OK to transfer the device control command from the determination list, but the invention is not limited to this. For example, the transfer determination unit 150 may determine whether or not it is OK for the device to be controlled to execute the device control command.

[0094] Registering the status of each device and resident in more detail in the status list and judgment list enables more detailed judgments to be made, improving the detection performance of the home gateway 20. Also, by grouping devices by type or installation location, it is possible to simplify the judgment list and omit reconfiguration when devices are replaced.

[0095] [1.3 Operation of the Equipment Control Command Monitoring System] The operation of the device control command monitoring system includes (1) main processing, (2) classification processing, and (3) judgment processing.

[0096] Each of these will be explained below with reference to the drawings. Note that the operation of the device control command monitoring system only needs to include at least the determination process (3).

[0097] [1.3.1 Main processing behavior] FIG. 6 is a flowchart showing an example of the main process of the home gateway 20 according to this embodiment.

[0098] 6, first, when there is no device registered in the device list holding unit 200 at the time of startup, the home gateway 20 creates a device list (initial device list) using the initial device list creation unit 110 (S1001). In order to extract devices connected to the home network 11, the initial device list creation unit 110 transmits, for example, an Address Resolution Protocol (ARP) message to all IP addresses in the same subnet, and registers devices that respond in the device list holding unit 200.

[0099] Next, the initial device list creation unit 110 requests the classification unit 130 to classify the devices registered in the device list holding unit 200, and the classification unit 130 executes the classification process (S1002).

[0100] Steps S1001 and S1002 are processes for initial setting.

[0101] After the classification process is completed, the home gateway 20 receives the communication message and executes the determination process (S1003). The home gateway 20 repeats the determination process every time it receives one communication message.

[0102] In the above description, an ARP message is sent to create the device list, and devices that respond are registered in the device list storage unit 200. However, this is not limited to this. For example, an ICMP (Internet Control Message Protocol) Echo Message may be sent, and the device list may be created from the response message, or other methods may be used.

[0103] [1.3.2 Classification process behavior] FIG. 7 is a flowchart showing an example of the classification process of the classification unit 130 according to this embodiment.

[0104] 7, first, upon receiving a request from the initial device list creation unit 110 or the unregistered device detection unit 120, the classification unit 130 transmits a message (determination message) to each of the plurality of devices connected to the home network 11 to determine whether or not communication with the plurality of devices is possible using a protocol for controlling home appliances (S2001). Here, the classification unit 130 may transmit the determination message by broadcast or multicast so that unspecified devices connected to the home network 11 can receive it, or may transmit the determination message individually to the devices registered in the device list holding unit 200.

[0105] Next, the classification unit 130 determines whether the device that received the determination message has returned a response message (S2002). When the classification unit 130 transmits the determination message by broadcast or multicast, it waits for a response message until a certain time has elapsed after transmitting the determination message, and determines that a "response has been received" for a device that has transmitted a response message, and determines that a "response has not been received" for a device that has not transmitted a response message until the certain time has elapsed. Furthermore, when the classification unit 130 transmits a determination message individually to a device, it determines that a "response has been received" if a response message is received, and determines that a "response has not been received" if a response message is not received within the certain time.

[0106] For a device for which it is determined in step S2002 that there is no response (No in S2002), the classification unit 130 determines that the device is not a home appliance and registers the device as "other than home appliance" in the device list holding unit 200 (S2003). For a device for which it is determined in step S2002 that there is a response (Yes in S2002), the classification unit 130 determines that the device is a home appliance and registers the device as "home appliance" in the device list holding unit 200 (S2004). When the classification unit 130 registers "home appliance" or "other than home appliance" as the device type in the device list held by the device list holding unit 200 in step S2003 or S2004, if there is no information other than the device type in the device list, the classification unit 130 also registers the information.

[0107] [1.3.3 Actions during judgment process] Fig. 8 is a flowchart showing an example of a determination process of the home gateway 20 according to this embodiment. The process shown in Fig. 8 shows an unauthorized communication detection method for detecting an unauthorized communication message in the home network 11 in which two or more devices including a first device and a second device are connected to each other so as to be able to communicate with each other. In this embodiment, for example, the process shown in Fig. 8 is executed by the home gateway 20.

[0108] As shown in FIG. 8, first, the receiving unit 100 receives a communication message (S3001). The receiving unit 100 receives a communication message from a source device (an example of a first device) that is sent from the source device to a destination device (an example of a second device) and is addressed to the destination device. For example, the receiving unit 100 receives from the air conditioner 41 a communication message that is sent from the air conditioner 41 to the electric lock 40. Step S3001 is an example of a receiving step. In this case, the second device is the electric lock 40, and the device control command is an unlock command for unlocking the electric lock 40.

[0109] Next, the unregistered device detection unit 120 determines whether the device is registered in the device list of the device list holding unit 200 based on the information (MAC address, IP address, port number, etc.) of the device that sent the received communication message (received message) (S3002).

[0110] If the unregistered device detection unit 120 determines in step S3002 that the device is "not registered" (No in S3002), it requests the classification unit 130 to perform classification processing. Then, the classification unit 130 executes classification processing (S3003).

[0111] If it is determined in step S3002 that the message is "registered" (Yes in S3002), or after determining that the message is "not registered" and then performing the classification process (S3003), the home appliance message determination unit 140 determines whether the received message is a home appliance message (S3004). The home appliance message determination unit 140 makes the determination in step S3004 based on, for example, whether the destination port number in the received message is 3610 or whether the first 2 bytes of the data portion of the communication message are 0x1081 or 0x1082.

[0112] If the home appliance message determination unit 140 determines in step S3004 that the received message is a "home appliance message" (Yes in S3004), it requests the forwarding determination unit 150 to make an additional determination. The received message is a "home appliance message" meaning that the destination device is a home appliance and the message includes a device control command for controlling the home appliance. Furthermore, if the home appliance message determination unit 140 determines in step S3004 that the received message is not a "home appliance message" (No in S3004), it requests the transmitting unit 160 to transmit the message. A received message determined to be "not a home appliance message" is a normal message, such as, but not limited to, a message for communication via a browser.

[0113] The transfer determination unit 150 acquires information on the device type of the device that has transmitted the received message from the device list holding unit 200, and determines whether the model type of the device that has transmitted the message is a home appliance (S3005). If the communication message is a message that includes a device control command (Yes in S3004), the transfer determination unit 150 may further determine whether to execute processing related to the device control command based on predetermined conditions. The predetermined conditions include whether the device that has transmitted the message (e.g., the air conditioner 41) is a device that has a predetermined function.

[0114] Next, if the transfer determination unit 150 determines in step S3005 that the source device is a "home appliance" (Yes in S3005) and the received message contains a device control command, it acquires from the status storage unit 210 a status list that stores the status of each device at that time and a determination list related to each control command for the device controlled by the device control command, and determines whether or not to transfer the device control command (S3006). Step S3006 includes an acquisition step and a first determination step described below. Note that the first determination step may include determining whether or not to execute processing related to the device control command based on the above-mentioned predetermined condition.

[0115] Obtaining a status list is an example of an acquisition step. In the acquisition step, when the forwarding determination unit 150 receives a communication message from the air conditioner 41, the forwarding determination unit 150 acquires a status list indicating the people in the house and the status of at least one of two or more devices. The status list acquired in the acquisition step may include, for example, the status at the time the communication message was received in step S3001.

[0116] Also, determining whether or not it is acceptable to transfer a control command is an example of a first determination step. In the first determination step, when a communication message received from the air conditioner 41 is a communication message including a device control command for controlling the electric lock 40, the transfer determination unit 150 determines whether or not to execute processing related to the device control command based on the status list. In this embodiment, the transfer determination unit 150 determines whether or not to send a communication message including a device control command to the electric lock 40 as the determination of whether or not to execute processing related to the device control command.

[0117] In addition, when the received message includes not only a device control command but also information indicating the device status, the transfer determination unit 150 may determine whether or not to transfer the message after reflecting the information regarding the status in the information registered in the status list. For example, in the acquisition step, the status list is acquired by reading the status list from the status storage unit 210, but the status of people in the house and at least one of two or more devices may be acquired from the information indicating the device status included in the received message. In this case, the information indicating the device status included in the received message is an example of first information. Furthermore, the transfer determination unit 150 functions as an acquisition unit that acquires the first information.

[0118] Furthermore, if it is determined in step S3005 that the source device is a "home appliance" and the received message does not contain a device control command, forwarding determination unit 150 determines in step S3006 that the received message may be forwarded.

[0119] If the determination in step S3006 is Yes, and if the information included in the received message indicates that the information in the status list held by the status holding unit 210 needs to be updated, the forwarding determination unit 150 registers the device status (S3007). It can also be said that the forwarding determination unit 150 updates the device status in the status list. At this time, the forwarding determination unit 150 may update the status of people in the home in the status list. In this way, for example, if the forwarding determination unit 150 determines to execute a process related to a device control command between steps S3006 and S3008, the forwarding determination unit 150 may update the status list based on the status of people in the home and at least one of two or more devices after the process is executed. Step S3007 is an example of an updating step. Note that the status of people in the home and at least one of two or more devices after the process is executed may be estimated based on the device control command. Step S3007 may also be executed after step S3008.

[0120] Thereafter, the forwarding determination unit 150 requests the sending unit 160 to send the message.

[0121] If the determination in step S3005 or S3006 is No, the forwarding determination unit 150 ends the determination process. The determination in step S3006 is equivalent to detecting an unauthorized communication message.

[0122] The status list may include at least the status of people. In the first determination step, the forwarding determination unit 150 may determine to transmit the communication message including the device control command to the second device if it can be determined from the status list that there is a person in the house, and may determine not to transmit the communication message including the device control command to the second device if it can be determined from the status list that there is no person in the house.

[0123] If the transfer determination unit 150 determines in step S3005 that the source device is "other than a home appliance," the transfer determination unit 150 ends the determination process without transmitting the received message.

[0124] Next, the transmitting unit 160 receives a message transmission request from the home appliance message determination unit 140 or the forwarding determination unit 150 and transmits the message (S3008), thereby terminating the determination process. For example, if the forwarding determination unit 150 determines "Yes" in step S3006, the transmitting unit 160 transmits the received message to the destination device. The transmitting unit 160 transmitting the received message to the destination device is an example of an execution step. In the execution step, if it is determined in step S3006 that processing related to the device control command is to be executed, the processing is executed. In this embodiment, the forwarding determination unit 150 determines whether to transmit a communication message including the device control command to the electric lock 40 as the determination of whether to execute processing related to the device control command.

[0125] After executing the classification process (S3003), the home gateway 20 requests the home appliance message determination unit 140 to determine whether the received message is a home appliance or not. However, this is not limited to this. The determination process may be terminated after the classification process and the home gateway 20 may wait for the next message to be received, or an error may be notified to the sender of the received message.

[0126] Note that the unregistered device detection unit 120 determines whether or not a device is registered in the device list from the information on the device that is the sender of the received message, but this is not limited to this. It may also determine whether or not a device is registered in the device list from the device information on the destination of the received message, or it may determine from the device information on both the destination and sender.

[0127] Note that the processes of steps S3002 to S3004 shown in FIG. 8 are not essential.

[0128] [1.4 Effects of the First Embodiment] In this embodiment, when the home gateway 20 receives a home appliance message, it determines whether to permit the transfer of a device control command included in the home appliance message using the status of at least one of the people in the home and two or more devices, rather than the information included in the home appliance message. In other words, in this embodiment, the information in the home appliance message (e.g., control content) is not used to determine whether to permit the transfer of a device control command. For example, the home gateway 20 estimates the status of each device and the status of the resident from the received home appliance message, and permits the transfer of the device control command only if the status is correct.

[0129] This makes it possible to detect a device control command sent when device control is not normally performed, i.e., when device control commands are not normally sent, as an unauthorized device control command based on the status of at least one of the people in the home and two or more devices. This increases the likelihood of detecting an unauthorized device control command even if an attacker falsifies information about the devices included in the message. Note that at least one of the status of each device and the status of the resident may be estimated based on the sensing results of a sensor.

[0130] Furthermore, since the determination in step S3006 can be made simply by comparing the status list with the determination list, the determination can be made quickly. Also, the countermeasure device (for example, the home gateway 20) can automatically detect unauthorized device control commands.

[0131] Furthermore, the home gateway 20 can flexibly determine unauthorized control of the electric lock 40, home appliances, and other devices based on at least one of the status of devices operating in the home and the status of the resident. The home gateway 20 can also detect unauthorized communications with devices connected to local networks outside the home, such as in buildings, stores, factories, and vehicles, which are connected to the Internet via devices such as routers.

[0132] (Embodiment 2) In embodiment 1 of the present disclosure, whether a home appliance message is fraudulent or not was determined based on information (status information) regarding the operating status of each home appliance, each sensor information, or information obtained from each home appliance (including status information), and status information of the residents of the house estimated from each sensor information.

[0133] Here, as a second embodiment of the present disclosure, a configuration will be described in which a detection mode is set in the home gateway 20 based on information regarding the operating status of each home appliance, each sensor information, information obtained from each home appliance (including status information), or the status of the residents living in the house estimated from each sensor information, and whether the home appliance message is fraudulent or not is determined from the detection mode.

[0134] The unauthorized communication detection system according to the second embodiment of the present disclosure will be described below.

[0135] [2. Details of Embodiment 2] Here, an unauthorized communication detection system according to the present disclosure will be described with reference to the drawings as a second embodiment of the present disclosure. Note that components having the same functions as those in the first embodiment of the present disclosure will be designated by the same reference numerals, and detailed descriptions thereof will be omitted.

[0136] The overall configuration of the unauthorized communication detection system is the same as that of the first embodiment of the present disclosure, and therefore a detailed description thereof will be omitted.

[0137] [2.1 Configuration of the home gateway 20a] 9 is a configuration diagram of a home gateway 20 according to the second embodiment of the present disclosure. Components having the same functions as those in the first embodiment are given the same reference numerals, and detailed descriptions thereof will be omitted or simplified.

[0138] 9, home gateway 20a includes a receiving unit 100, an initial device list creating unit 110, an unregistered device detecting unit 120, a classifying unit 130, a home appliance message determining unit 140, a forwarding determining unit 150, a transmitting unit 160, a mode determining unit 170, a device list holding unit 200, a status holding unit 210, and a mode holding unit 220. The unauthorized communication detection system according to this embodiment includes home gateway 20a instead of home gateway 20 of the unauthorized communication detection system according to embodiment 1. Furthermore, home gateway 20a of the unauthorized communication detection system according to this embodiment includes mode determining unit 170 and mode holding unit 220 in addition to home gateway 20 of the unauthorized communication detection system according to embodiment 1.

[0139] When the home appliance message determination unit 140 determines that the received communication message (received message) is a home appliance message, the forwarding determination unit 150 determines whether or not to send (forward) the received message to the destination described in the received message.

[0140] The forwarding determination unit 150 obtains information about the sending device from the received message and obtains the device number from the device list held by the device list holding unit 200, which will be described later. For example, if the received message includes information about the status of the device that sent the message, the forwarding determination unit 150 obtains the information about that status and registers it in the status list held by the status holding unit 210. Furthermore, if the received message includes sensor information, the forwarding determination unit 150 registers the sensor information in the status list. Furthermore, if the received message includes information about the status of the device that sent the message or if the message includes sensor information, the forwarding determination unit 150 estimates the status of the residents living in the house from that information or from that information and the information registered in the status list, and registers it in the status list.

[0141] The transfer determination unit 150 requests the mode determination unit 170 to determine the mode of the home gateway 20a.

[0142] When the received message includes command information related to device control (device control command), the forwarding determination unit 150 acquires mode information of the home gateway 20a from the mode determination unit 170, and further acquires a determination list from the status holding unit 210, and determines from the determination list whether or not it is acceptable to forward the received message including the device control command in the mode acquired from the mode determination unit 170.

[0143] 10 is a diagram showing an example of a decision list according to the present embodiment, which shows a decision list for a device control command instructing the electric lock 40 to be unlocked.

[0144] As shown in FIG. 10, the transfer determination unit 150 determines that unlocking is "OK (transfer is allowed)" when the mode (transfer determination mode) acquired from the mode determination unit 170 is "active mode," and determines that unlocking is "NG (transfer is not allowed)" when the mode is "inactive mode" or "away mode." The determination list only needs to include at least "active mode" and "away mode." In this embodiment, the determination list further includes "inactive mode."

[0145] Upon receiving a request from the transfer determination unit 150, the mode determination unit 170 determines the mode of the home gateway 20a based on the status list held by the status holding unit 210 and the mode determination list held by the mode holding unit 220 (described later). The mode determination unit 170 compares at least one state of each device and person in the house listed in the status list with at least one state of each device and person in the house listed in the mode determination list, and determines the mode of the home gateway 20a.

[0146] Here, a case will be described in which the mode determination list held in the mode holding section 220 is the mode determination list shown in Fig. 11. Fig. 11 is a diagram showing an example of a mode determination list according to the present embodiment.

[0147] For example, if the status list stored in the status storage unit 210 indicates that device No. 1 is "ON," device No. 2 is "OFF," device No. 3 is "locked," and the resident is "bedroom," and the mode storage unit 220 stores the mode determination list shown in FIG. 11, the mode determination unit 170 determines that the home gateway 20a is in the "inactive mode."

[0148] The status holding unit 210 holds the same status list as in the first embodiment, and therefore a description thereof will be omitted here. The status holding unit 210 provides the information of the status list to the mode determination unit 170 in addition to the transfer determination unit 150.

[0149] The mode holding unit 220 holds a mode determination list and past results of determination made by the mode determination unit 170. The mode holding unit 220 is realized by, for example, an HDD (Hard Disk Drive) or a semiconductor memory, but is not limited to this.

[0150] Note that the transfer determination unit 150 determines whether or not it is permissible to transfer a device control command from the determination list, but this is not limiting. For example, the transfer determination unit 150 may determine whether or not it is permissible for a device to be controlled to execute the device control command.

[0151] Although the modes in the determination list and the mode determination list are described as "active mode," "inactive mode," and "away mode," they are not limited to these. For example, they may be named differently, such as "home mode," or simply "mode 1," "mode 2," "No. 1," "No. 2," "1," "2," "A," or "B," as long as the mode can be identified. Furthermore, the number of modes may be two, four, or more, instead of three. The more modes there are, the more appropriate the determination can be made even in complex situations.

[0152] The mode determination unit 170 may determine the mode of the home gateway 20a from the past modes stored in the mode storage unit 220 and the information in the state list. This allows the mode determination unit 170 to correctly determine the mode, for example, when the current mode needs to be changed depending on the immediately previous or past mode even if the state is the same.

[0153] Although the judgment list shown is a judgment list for a device control command that instructs to unlock the electric lock 40, it is not limited to this. For example, there may be a judgment list for a device control command that instructs to lock the electric lock 40, a judgment list for a device control command that instructs to turn the air conditioner on / off, or a judgment list for a device control command that instructs to change the temperature of the air conditioner; the specific devices and instruction contents of the device control commands are not specified.

[0154] Furthermore, each of these device control commands may have its own determination list. Fig. 12 is a diagram showing another example of a determination list according to this embodiment.

[0155] As shown in FIG. 12, the determination list may be a determination list for a specific device control command (in FIG. 12, an unlock command instructing the electric lock 40 to be unlocked) and other device control commands (other than the unlock command).

[0156] For example, the device control command includes either an unlock command for unlocking the electric lock 40 or other commands other than the unlock command. In the active mode, the unlock command and other commands are sent to the electric lock 40. When the mode determination unit 170 determines that the mode is the active mode, the transfer determination unit 150 determines that the unlock command and other commands are sent to the electric lock 40. In the inactive mode, only the unlock command and other commands are sent to the electric lock 40. When the mode determination unit 170 determines that the mode is the inactive mode, the transfer determination unit 150 determines that only the unlock command and other commands are sent to the electric lock 40. In the unattended mode, the unlock command and other commands are not sent to the electric lock 40. When the mode determination unit 170 determines that the mode is the unattended mode, the transfer determination unit 150 determines that the unlock command and other commands are not sent to the electric lock 40.

[0157] There may also be a judgment list for each type of device, or a combination of these.Also, there may be a judgment list organized by device type, such as "air conditioner" or "electric lock," a judgment list organized by room, such as the air conditioner 41 and light 42 in the living room, or a judgment list for each device, such as by device number.

[0158] The mode determination list holds the status of each device in each mode, but is not limited to this. The mode determination list may be organized by device type, such as "air conditioner" or "electric lock," or by room, such as the air conditioner 41 and light 42 in the living room. Modes may also be defined according to the status information for each device or the status of the resident estimated from sensor information.

[0159] FIG. 13 is a diagram showing another example of the mode determination list according to the present embodiment.

[0160] As shown in FIG. 13 , the mode may be defined based on whether or not there is a resident in the home (present / absent) and whether or not the resident in the home is active or inactive (sleeping, etc.) (active / immobile). The mode determination unit 170 may determine the mode of the home gateway 20a to be the active mode when the first information indicates that there is a resident in the home and that the resident is moving, and may determine the mode of the home gateway 20a to be the inactive mode when the first information indicates that there is a resident in the home and that the resident is not moving. Being active is an example of being active, and for example, means moving part or all of the body more than a predetermined amount. Not moving is an example of being inactive, and for example, means moving part or all of the body less than a predetermined amount. Not moving may mean, for example, sleeping.

[0161] The mode determination unit 170 may determine whether a resident is present in the home (present / absent) and whether the resident is active or inactive (sleeping, etc.) (active / immobile) by, for example, determining whether a motion sensor installed in the home detects a person or human movement, or by analyzing images or videos from a camera installed in the home. The mode determination unit 170 may also determine the above by having all residents carry a transmitter such as an RF tag, and using a receiver such as an RF receiver installed in the home to receive information from a sensor mounted on the transmitter and analyze whether the transmitter is present in the home, whether the transmitter is operating, and whether the transmitter is operating. The mode determination unit 170 may also determine the above by having all residents carry a receiver, installing the transmitter in the home, and notifying a server or home controller such as the home gateway 20 of the signal received by the receiver, or by using an indoor positioning system to grasp the movements of the residents, or by other methods.

[0162] In addition, the mode determination unit 170 may determine whether a person is present / absent and whether a person is moving / still from sensor information obtained from each home appliance (for example, information from a refrigerator open / close sensor, information from a window or door open / close sensor, amount of water used in the kitchen or bathroom, room temperature, humidity, chemical substance concentrations such as carbon dioxide concentration, or changes therein, etc.), based on information that can determine whether a person is actually present in the house or whether a person is moving.

[0163] [2.2 Operation of the Equipment Control Command Monitoring System] The operation of the device control command monitoring system includes (1) main processing, (2) classification processing, and (3) judgment processing.

[0164] The processes (1) and (2) are the same as those in the first embodiment, and therefore will not be described here.

[0165] Below, each of the processes in (3) will be explained using the figures.

[0166] [2.2.1 Actions during judgment process] FIG. 14 is a flowchart showing an example of a determination process of the home gateway 20a according to the second embodiment of the present disclosure.

[0167] The processes from step S3001 to step S3008 are the same as those in the first embodiment, and therefore description thereof will be omitted here. When the transfer determination unit 150 determines in step S3005 that the source device is a "home appliance" (Yes in S3005) and the received message includes a device control command, the transfer determination unit 150 acquires, from the mode determination unit 170, the current mode of the home gateway 20a and a determination list (see, for example, FIG. 10) related to each control command for the device controlled by the device control command, and determines whether or not to transfer the device control command (S3006). The mode acquired in step S3006 is the mode determined in step S3009 when the process shown in FIG. 14 was previously executed. In step S3006, the transfer determination unit 150 according to the present embodiment determines whether or not to transmit the device control command to the electric lock 40 based on the mode of the home gateway 20a determined in step S3009.

[0168] The transfer determination unit 150 may determine to send the device control command to the electric lock 40 when the home gateway 20a is in the active mode (Yes in S3006), and may determine not to send the device control command to the electric lock 40 when the home gateway 20a is in the absent mode. The transfer determination unit 150 may also determine not to send the device control command to the electric lock 40 when the home gateway 20a is in the inactive mode.

[0169] 14 was previously executed, the process of step S3009 may be performed between the current steps S3005 and S3006. For example, if the answer is Yes in step S3005, the forwarding determination unit 150 may determine whether to determine the mode of the home gateway 20a before step S3006, based on whether a predetermined period has elapsed since the process of FIG.

[0170] In step S3007, the forwarding determination unit 150 updates the information in the state list held by the state holding unit 210 with the information included in the received message, and then requests the mode determination unit 170 to determine the mode of the home gateway 20a. The mode determination unit 170 compares the state list held by the state holding unit 210 with the mode determination list held by the mode holding unit 220, determines which mode the home gateway 20a is currently in (S3009), and causes the mode holding unit 220 to hold this.

[0171] It can also be said that the mode determination unit 170 determines the mode of the home gateway 20a based on the status list in step S3009. The mode determination unit 170 may determine the mode as the active mode when it can determine from the status list that there is someone in the house, and may determine the mode as the absent mode when it can determine from the status list that there is no person in the house. Furthermore, the mode determination unit 170 may determine the mode of the home gateway 20a as the active mode when it is determined from the status list that there is someone in the house and that person is active, and may determine the mode of the home gateway 20a as the inactive mode when it is determined from the status list that there is someone in the house and that person is not active. Step S3009 is an example of a second determination step.

[0172] The forwarding determination unit 150 requests the sending unit 160 to send the message, and in step S3008, the sending unit 160 sends the message.

[0173] [2.3 Effects of the Second Embodiment] In this embodiment, each time a message containing information that requires updating the status list information is received, the status list is updated and the mode is determined, and when a message containing a device control command is received, the mode information is used to determine whether the device control command can be executed or transferred.

[0174] As a result, when the home gateway 20a receives a message containing a device control command, it does not need to refer to the large amount of information contained in the status list, and can efficiently perform the determination process by referring only to the mode information. Furthermore, even if the information in the status list is the same, the home gateway 20a can change the mode depending on the previous status (mode), so it can efficiently perform the determination process even under complex conditions.

[0175] [3. Other Modifications] The present disclosure is not limited to the above-described embodiments, and various modifications conceivable by those skilled in the art and combinations of components in different embodiments are also included within the scope of the present disclosure, provided they do not deviate from the spirit of the present disclosure. For example, the following modifications are also included in the present disclosure.

[0176] (1) In the above embodiments, the unauthorized communication detection system is described as having the home gateway 20 or home gateway 20a (hereinafter also referred to as home gateway 20, etc.) as the central point, with the Internet and each device in the home connected to it. However, the method of connecting each device is not limited to this. For example, the configuration shown in FIG. 15 or 16 may be used, or another configuration may be used.

[0177] FIG. 15 is a diagram showing an example of the overall configuration of an unauthorized communication detection system according to Modification 1 of each of the above-described embodiments.

[0178] 15, the unauthorized communication detection system may include the Internet 10, a home network 11, an IT device network 12, a home appliance network 13, a home gateway 20, a PC 30, an electric lock 40, an air conditioner 41, lighting 42, a controller 43, a terminal 50, and a router 60. The difference from FIG. 1 is that the Internet 10 and the PC 30 are directly connected to the home gateway 20, or the Internet 10 and the PC 30 are connected to the router 60, and the router 60 is connected to the home gateway 20.

[0179] An electric lock 40, an air conditioner 41, lights 42, a controller 43, and a router 60 are connected to the home gateway 20, which mediates communications between the connected devices. The home gateway 20 has two types of connection ports: a connection port for connecting a communication line for the IT device network 12, and a connection port for connecting a communication line for the home appliance network 13. In FIG. 15 , the home gateway 20 has one connection port for the IT device network 12 (IT device connection port) and four connection ports for the home appliance network 13 (home appliance connection ports). The router 60 is connected to the IT device connection port, and home appliances such as the electric lock 40, air conditioner 41, lights 42, and controller 43 are connected to the home appliance connection ports. Whether each connection port is an IT device connection port or a home appliance connection port may be determined in advance, may be set by the user, or may be determined automatically by the home gateway 20. As a method for automatic determination, for example, the classification unit 130 of the home gateway 20 may determine that a connection port to which a device classified as a "home appliance" is connected is a "home appliance connection port," and the classification unit 130 may determine that a connection port to which a device classified as "non-home appliance" is connected is a "IT device connection port," or, based on the communication messages sent and received by each device, the connection port to which a device sending and receiving a home appliance message is connected may be determined to be a "home appliance connection port," and other connection ports may be determined to be "IT device connection ports," or other methods may be used.

[0180] The router 60 is a device for connecting the Internet 10 and the home network 11. The home gateway 20 and the PC 30 are connected to the router 60, and when the home gateway 20 and the PC 30 want to communicate with a server on the Internet 10, the communication is via the router 60. The terminal 50 may also be connected to the router 60.

[0181] FIG. 16 is a diagram showing another example of the overall configuration of the unauthorized communication detection system according to the first modification of each of the above embodiments.

[0182] 16, the unauthorized communication detection system may include the Internet 10, a home network 11, a home gateway 20, a PC 30, an electric lock 40, an air conditioner 41, lighting 42, a controller 43, a terminal 50, a router 60, and a hub 70. The difference from FIG. 15 is that each home appliance is connected to the home gateway 20 directly or via the hub 70.

[0183] A router 60 and a hub 70 are connected to the home gateway 20. The home gateway 20 has one connection port for IT devices and one connection port for home appliances, with the router 60 connected to the IT device connection port and the hub 70 connected to the home appliance connection port. Whether each connection port is an IT device connection port or a home appliance connection port may be determined in advance, may be set by the user, or may be determined automatically by the home gateway 20.

[0184] The hub 70 is connected to the home gateway 20, the electric lock 40, the air conditioner 41, the lighting 42, and the controller 43, and relays communications.

[0185] 15 and 16, connection port information may be included in the device list, status list, determination list, mode determination list, etc. For example, by including information about the connection port that receives a device control command in the determination list, it becomes possible to determine whether or not to permit the transfer of the device control command for each connection port. Also, by including connection port information for each device in the status list, determination list, mode determination list, etc., when a device is connected to a different connection port, it is possible to determine the state or mode as a different state or a different mode.

[0186] This allows for more flexible determination based on the connection port to which the device is connected. Furthermore, the home gateway 20 and the like can detect that a home appliance has been connected to the IT device network 12 or that a device other than a home appliance, such as a PC 30, has been connected to the home appliance network 13, and notify the user of this. The user can connect the device to the appropriate network by receiving the notification and performing an operation to connect the device to the appropriate network. Even if a device other than a home appliance connected to the IT device network 12 transmits a device control command for unauthorized control of the home appliance, if the connection port that received the received message is an IT device connection port, the device control command can be determined to be unauthorized. Even if a device is installed in a location where it would be better to connect it to the IT device network 12, or if the device is a home appliance, the transmission of the device control command to the home appliance on the home appliance network 13 can be permitted at the user's discretion, enabling flexible network configuration.

[0187] (2) In the above embodiment, all devices connected to the home network 11 are registered in the initial device list during the main processing, but this is not limiting. For example, the initial device list creation process (S1001) may not be performed, and only the classification process (S1002) and the determination process (S1003) may be performed, or the initial device list creation process (S1001) and the classification process (S1002) may not be performed, and only the determination process (S1003) may be performed.

[0188] Fig. 17 is a configuration diagram of a home gateway 20b according to Modification 2 of each of the above-mentioned embodiments. Fig. 18 is a flowchart showing an example of main processing of the home gateway 20b according to Modification 2 of each of the above-mentioned embodiments. Fig. 19 is a flowchart showing another example of main processing of the home gateway 20b according to Modification 2 of each of the above-mentioned embodiments.

[0189] As shown in FIG. 17, the configuration of the home gateway 20b is the same as the configuration of the home gateway 20 according to the first embodiment of the present disclosure (see FIG. 2), except that the initial device list creating unit 110 is not included.

[0190] According to such a home gateway 20b, the main processing is performed as shown in a flowchart in Fig. 18 or 19. In other embodiments and modifications, similar configuration changes and processing changes can be made.

[0191] This reduces the processing time and bus load at the time of initial startup, and therefore makes it possible to protect home appliances connected to the home network 11 immediately after the home gateway 20b is started up.

[0192] (3) In each of the above embodiments, the home gateway 20 or the like determines whether a received message is a home appliance message, and the forwarding determination unit 150 performs the determination only when the message is a home appliance message. However, this is not limited to this, and the forwarding determination unit 150 may perform the determination for all communications. Fig. 20 is a configuration diagram of a home gateway 20c according to a third modification of each of the above embodiments. Fig. 21 is a flowchart showing an example of the determination process of the home gateway 20c according to the third modification of each of the above embodiments.

[0193] As shown in FIG. 20, the configuration of the home gateway 20c differs from the configuration of the home gateway 20 according to the first embodiment of the present disclosure (see FIG. 2) in that the home appliance message determination unit 140 is not included.

[0194] 21, the determination process does not include the step (S3004) of determining whether a received message is a home appliance message from the determination process of the first embodiment of the present disclosure (see FIG. 6). Instead, for example, the forwarding determination unit 150 may determine whether to transmit a message based on information about the source and destination of the received message. Similar configuration changes and process changes can be made in other embodiments and modifications. For example, the forwarding determination unit 150 may determine whether to transmit a communication message from a connection port (receiving port) that received the communication message or a connection port (destination port) to which the communication message is to be transmitted, or the like. Alternatively, the forwarding determination unit 150 may determine whether to transmit a communication message based on information about the receiving port and the destination. Alternatively, the forwarding determination unit 150 may determine whether to transmit a communication message based on whether the receiving port, the destination, and the source device are permitted.

[0195] As a result, the home gateway 20c can prevent the transmission of unauthorized device control commands even when it is difficult to determine whether a received message is a home appliance message. Furthermore, the home gateway 20c can effectively prevent attacks on home appliances from devices other than home appliances by restricting only messages from devices other than home appliances to home appliances, which are likely to be the subject of attacks, and not restricting other communications. Furthermore, the home gateway 20c can create status lists and update status information that include messages other than home appliance messages, which allows for more complex conditions to be set when determining device control commands, enabling more flexible responses. The home gateway 20c also achieves a similar effect when determining modes.

[0196] (4) In each of the above embodiments, the unregistered device detection unit 120 determines whether the sender of a received communication message is registered in the device list, and if not, registers it additionally, but this is not limited to this. Fig. 22 is a configuration diagram of a home gateway 20d according to a fourth modification of each of the above embodiments. Fig. 23 is a flowchart showing an example of a determination process of the home gateway 20d according to the fourth modification of each of the above embodiments.

[0197] As shown in Fig. 22, the home gateway 20d does not need to include the unregistered device detection unit 120. As shown in Fig. 23, according to such a home gateway 20d, the processes of steps S3002 and S3003 can be eliminated from the determination process.

[0198] As a result, the home gateway 20d cannot communicate with a new unauthorized home appliance even if it is added to the home network 11, making the home network 11 safer.

[0199] (5) In the above-described embodiments, devices are classified by transmitting a determination message during classification processing, but this is not limiting. Fig. 24 is a flowchart showing an example of classification processing according to Variation 5 of each of the above-described embodiments.

[0200] As shown in FIG. 24, the classification unit 130 may determine whether the received message is a home appliance message (S2005), and if it is a home appliance message (Yes in S2005), may register the device that is the sender as a home appliance (S2004).

[0201] This allows the home gateway 20 and the like to classify devices without transmitting a determination message, thereby reducing the network load.

[0202] (6) In the above-described embodiment, classification processing is performed when the sender of a received communication message is not registered in the device list at the time of initial startup of the home gateway 20, etc., but this is not limited to this. Fig. 25 is a flowchart showing an example of classification update processing according to Variation 6 of each of the above-described embodiments.

[0203] 25, the home gateway 20 or the like may further perform a classification update process to update the classification. In the classification update process, the classification unit 130 first transmits a determination message to the network (S4001). Next, the classification unit 130 determines whether or not a response message to the determination message has been received (S4002). If the classification unit 130 receives a response message in step S4002 (Yes in S4002), it extracts a sender from the response message (S4003). Then, the classification unit 130 determines whether or not the extracted sender is registered in the device list (S4004).

[0204] If the classification unit 130 determines in step S4004 that the device has not been registered in the device list (No in S4004), this means that a new device has been connected, and so the classification unit 130 registers the device as a home appliance in the device list (S4005). Furthermore, if the classification unit 130 does not receive a response message until a certain period of time has elapsed in step S4002 (No in S4002), or if the sender has been registered in the device list in step S4004 (Yes in S4004), the classification unit 130 determines whether there is a difference with the registration information in the device list (S4006).

[0205] If the information differs from the registration information in the device list in step S4006 (Yes in S4006), the classification unit 130 updates the information in the device list (S4007). If the information is the same as the registration information in the device list in step S4006 (No in S4006), the classification unit 130 ends the classification update process. Here, before updating the device list in step S4007, the classification unit 130 may inquire of the user and update only the registration information of devices that the user has authorized.

[0206] This allows the home gateway 20 etc. to flexibly respond to the addition or deletion of devices. Also, by inquiring of the user, the home gateway 20 etc. can register only devices that the user has authorized, creating a safer environment.

[0207] (7) In the above-described embodiments, the state storage unit 210 stores a state list and a determination list, but this is not limitative. Fig. 26 is a diagram showing an example of a determination list according to Modification 7 of each of the above-described embodiments.

[0208] As shown in Fig. 26, the status list and the determination list may be held as a single list. In this case, at least one of the statuses of the device and the person corresponding to the status number "now" shown in Fig. 26 may be updated.

[0209] This eliminates the need for the home gateway 20 etc. to manage multiple lists, and allows the current status and the judgment list to be managed in a unified manner, thereby simplifying the judgment process in the home gateway 20 etc.

[0210] (8) In each of the above embodiments, there are a determination list and a mode determination list, and the modes are "active mode," "inactive mode," and "away mode." However, this is not limited to this. Figure 27 is a diagram showing another example of a determination list according to Modification 8 of each of the above embodiments.

[0211] As shown in FIG. 27, the determination list and the mode determination list may be combined into one list, and there may be only two modes: "active mode" and "absent mode."

[0212] This simplifies the judgment process because the home gateway 20 and the like do not need to manage multiple lists and can centrally manage the current status and the judgment list. Also, by simplifying the number of modes to two, the home gateway 20 and the like can speed up the judgment.

[0213] (9) In the above-described embodiments, the modes in the determination list and the mode determination list include "active mode," "inactive mode," and "away mode," but are not limited to these. FIG. 28 is a diagram showing an example of a mode determination list according to Modification 9 of the above-described embodiments. FIG. 29 is a diagram showing another example of a determination list according to Modification 9 of the above-described embodiments. For example, as shown in FIGS. 28 and 29, the modes of the home gateway 20, etc., may further include "entrance mode" and "home-sitting mode."

[0214] Here, "entrance mode" refers to a state in which there is someone near the entrance of the house, and may be, for example, a state in which there is only someone near the entrance of the house. "Entrance mode" may refer to a state in which all residents who were in the house are near the entrance to go out, or a state in which one resident has returned home and is outside the entrance while everyone else is out. In either case, there is no one in the house except for the area around the entrance. In this case, the forwarding determination unit 150 permits only unlocking commands from a terminal (e.g., terminal 50) located near the entrance, and does not permit control commands other than unlocking commands from terminals located near the entrance, or control commands including unlocking commands from terminals not located near the entrance. "Near the entrance" may be, for example, a space where the entrance door is installed, or may be within a range within visual range of the entrance door. Furthermore, "near the entrance" may be within a predetermined distance (e.g., several meters) from the entrance door.

[0215] For example, the entrance mode may be determined when there is no one inside the house and there is only one person outside the entrance, or the entrance mode may be determined when there is only one person inside the house.

[0216] For example, in step S3009 shown in FIG. 14, if it can be determined from the state list that there is a person only near the entrance of the house, the mode determination unit 170 may determine that the mode of the home gateway 20, etc. is the entrance mode.

[0217] Then, in step S3006 shown in FIG. 14, the forwarding determination unit 150 may determine not to send an unlock command if the mode of the home gateway 20 or the like is the entrance mode and the first device is not near the entrance.

[0218] In addition, the second device is installed at the entrance of the house, and in step S3006, the forwarding determination unit 150 may further determine that a communication message including a device control command should be sent to the electric lock 40 if it can be determined from the status list that there are people only near the entrance of the house.

[0219] As a result, when a resident returns home while everyone else is out, the home gateway 20 etc. only allows unlocking commands from a device (such as a smartphone) carried by the resident who has returned home, eliminating the inconvenience of the home gateway 20 remaining in "away mode" and not allowing unlocking commands from outside, making it impossible to open the front door.In addition, the home gateway 20 etc. can prevent attacks such as unauthorized turning on of the air conditioner 41 or lights 42 in a room that is difficult to check from the front door, even when the resident is out.

[0220] The mode determination unit 170 may determine whether all residents in the house are near the entrance to go out, for example, when motion sensors installed in rooms other than the entrance do not detect any people, and only the motion sensor installed in the entrance detects a person, thereby determining that the system is in "entrance mode." The mode determination unit 170 may also analyze video from a camera installed in the entrance to constantly keep track of who has gone out or returned home, and determine that the system is in "entrance mode" when a person captured on camera leaves the house, indicating that everyone has left the house. The mode determination unit 170 may also have all residents carry transmitters such as RF tags, constantly keep track of who has gone out or returned home using receivers such as RF receivers installed inside and outside the entrance and inside the house, and determine that the system is in "entrance mode" when a person carrying a transmitter receiving a signal from the receiver leaves the house, indicating that everyone has left the house. The mode determination unit 170 may also have all residents carry receivers, and have transmitters installed inside and outside the entrance and inside the house, and have the receivers notify a controller in the house such as a server or home gateway 20 of received signals, thereby constantly keeping track of who has gone out or returned home, and determine that the system is in "entrance mode" when a person carrying a receiver receiving a signal from the transmitter installed at the entrance goes out, meaning that everyone has gone out. The mode determination unit 170 may also keep track of the locations of the residents using an indoor positioning system, and determine that the system is in "entrance mode" when no one is present except near the entrance, or may use other methods to determine whether all residents who were in the house are near the entrance to go out.

[0221] Furthermore, the mode determination unit 170 can determine whether one of the residents has returned home and is outside the front door while everyone else is out, by determining whether no one is inside the house and is outside the front door in the same manner as the method for determining whether all of the residents who were in the house are near the front door to leave, i.e., whether no one is inside the house and is outside the front door. However, since a method using a motion sensor cannot determine who is outside the front door, it is difficult to make this determination using only a motion sensor. Another method for determining whether one of the residents has returned home and is outside the front door while everyone else is out is to use Wi-Fi (registered trademark). For example, if a Wi-Fi access point (Wi-Fi AP) is installed in the home network 11 and the Wi-Fi AP can communicate with a smartphone carried by a resident, when one of the residents approaches the front door, the Wi-Fi AP and the smartphone carried by the resident can communicate with each other. In this way, the mode determination unit 170 may determine that the mode is in "entrance mode" when the Wi-Fi AP and the smartphone carried by the resident are able to communicate with each other, or may determine that the mode is in "entrance mode" when the resident is near the house in cooperation with an outdoor positioning system (e.g., a Global Positioning System (GPS)). Another method for determining whether all residents who were in the house are near the entrance to go out is for the mode determination unit 170 to attach sensors to the shoes of the residents and determine that the mode is in "entrance mode" when all residents put on their shoes. In this case, if one person owns multiple pairs of shoes, the mode determination unit 170 determines that the resident has put on shoes when a sensor attached to one of the shoes reacts to the resident putting on shoes. Furthermore, the determination may be made by combining several of the above methods.

[0222] It should be noted that "entrance mode" is defined as a state in which all residents in the house are near the entrance to go out, or a state in which one resident has returned home and is outside the entrance while everyone is out; however, it is not limited to this. A state in which all residents in the house are near the entrance to go out can be defined as "active mode" or "inactive mode," and "entrance mode" can be used only when one resident has returned home and is outside the entrance while everyone is out. Alternatively, "entrance mode" can be defined as a state in which all residents in the house are near the entrance to go out, and "away mode" can be defined as a state in which one resident has returned home and is outside the entrance while everyone is out, and when the residents return home, the door can be unlocked using a physical key rather than unlocked via the home network 11, or the system can be configured to switch between these modes.

[0223] This allows the home gateway 20 and the like to be flexibly configured in accordance with the resident's schedule, belongings, and in-home facilities.

[0224] Furthermore, "home-sitting mode" refers to a state in which only children (one example of a person who is not permitted to control two or more devices via the home network 11) are present in the home and do not unlock the electric lock 40 via the home network 11. In this state, only control commands other than the unlock command are permitted.

[0225] 14, the mode determination unit 170 may further determine that the mode of the home gateway 20, etc. is the away mode when, from the status list, it is determined that there is a person in the house and that the person is the only person in the house who is not permitted to control two or more devices via the home network 11 (for example, a child). Note that information about people who are not permitted to control two or more devices via the home network 11 is set in advance and stored, for example, in the status storage unit 210, etc.

[0226] Then, in step S3006 shown in FIG. 14, if the mode of the home gateway 20 or the like is the answering machine mode, the forwarding determination unit 150 may determine to send only the unlock command and the other command other than the unlock command.

[0227] This allows the home gateway 20 etc. to prevent the transmission of an unauthorized unlock command when the electric lock 40 is unlocked unauthorizedly and a suspicious person gains unauthorized entry. For example, it can prevent a suspicious person from breaking into a house when only a child who cannot resist is present inside.

[0228] The mode determination unit 170 may determine whether only children or other individuals who have not unlocked the electric lock via the home network 11 are in the home by, for example, analyzing video from a camera installed at the home entrance, similar to the determination of "entrance mode," by constantly keeping track of who has left or returned home, and determining that the home is in "home-sitting mode" when only children have returned home and their parents have not. The mode determination unit 170 may also have all residents carry transmitters such as RF tags, register each transmitter as being a child or not, and determine that the home is in "home-sitting mode" when only transmitters registered as children have returned home. The mode determination unit 170 may also have all residents carry receivers, install transmitters inside and outside the home entrance, and register each receiver as being a child or not, and determine that the home is in "home-sitting mode" when only receivers registered as children have returned home. The mode determination unit 170 may also determine that the home is in "home sitting mode" when a Wi-Fi access point (Wi-Fi AP) is installed in the home network 11, the Wi-Fi AP can communicate with a smartphone carried by the resident, and only a smartphone registered as a child can communicate with the Wi-Fi AP. The mode determination unit 170 may also determine that the home is in "home sitting mode" when a child does not carry a transmitter, receiver, or smartphone, or when the transmitter, receiver, or smartphone is outside the home and a motion sensor in the home reacts or the electronic lock on the front door is opened using a physical key. The determination may also be made by combining several of the above methods.

[0229] This allows the home gateway 20 and the like to make flexible decisions based on the belongings that children and the like have with them or the equipment in the home.

[0230] Although the people who are not permitted to control the equipment are described as children, this is not limited to children, and can include anyone who would be unable to resist if a suspicious person illegally enters the equipment, such as the elderly, sick, or injured.

[0231] (10) In the above embodiments, the mode of the home gateway 20 is determined based on the state list stored in the state storage unit 210 and the mode determination list stored in the mode storage unit 220, but this is not limited to this.

[0232] FIG. 30 is a diagram showing an example of mode transition according to the tenth modification of each of the above embodiments.

[0233] 30, the mode determination unit 170 may define conditions for transitioning from one mode to another, and determine the mode of the home gateway 20, etc., according to the conditions. At this time, if the information about the device state, the information about the device control command, etc., does not meet the conditions for mode transition, the home gateway 20, etc. may determine that the message is an invalid message and not forward it. Furthermore, the conditions for mode transition may include not only the information about the device state or the information about the device control command, but also the time elapsed since transition to the mode, the time elapsed since the device state changed, the time elapsed since the previous device control command was received, etc.

[0234] This allows the home gateway 20 and the like to set detailed conditions for mode transition, making it possible to improve the detection rate of fraudulent messages and reduce false detections.

[0235] Note that Fig. 30 is an example, and the modes, the number of modes, the mode transition method, etc. are not limited to this. There may be modes other than those shown in Fig. 30, some modes may be missing, or different mode transitions may be performed.

[0236] In addition, since a transition from one of the inactive mode and the absent mode to the other is unlikely to occur in reality, it may be prohibited. When a transition from one of the inactive mode and the absent mode to the other occurs, the forwarding determination unit 150 may determine not to forward the received message to the second device.

[0237] (11) In the above embodiment, the transfer determination unit 150 and the mode determination unit 170 determine whether to transfer a received message based on a status list that stores the status of each device and a determination list related to each control command for a device controlled by the device control command. Furthermore, the transfer determination unit 150 and the mode determination unit 170 determine the mode of each device based on the state of each device and determine whether to transfer a received message based on the mode. However, this is not limited to this. The mode determination unit 170 may determine whether to transfer a received message, determine the mode, and determine a mode transition based on not only the state of each device but also the elapsed time since the device entered a certain state. For example, if the device is rarely turned on / off or the electric lock is locked / unlocked within a short period of time, the transfer determination unit 150 and the mode determination unit 170 may determine not to transfer a received message if the time elapsed since the device entered the ON state is shorter than a certain time when an OFF device control command is received, or if the time elapsed since the device entered the OFF state is shorter than a certain time when an ON device control command is received. Alternatively, in a case where the entrance light 42 normally turns on immediately after the electric lock 40 of the front door is unlocked, the transfer determination unit 150 and the mode determination unit 170 may determine that an abnormal state has occurred if the entrance light 42 does not turn on even after a certain time has passed since the electric lock 40 of the front door was unlocked.

[0238] (12) In the above embodiments, the mode determination unit 170 determines the mode according to the mode determination list, but this is not limiting. For example, if there is a security system for detecting the opening and closing of windows and doors when going out, and there is an "away setting" that detects the opening and closing of windows and doors, and an "at home setting" that does not detect the opening and closing of windows and doors, the mode of the home gateway 20 may be changed in conjunction with the "away setting" and "at home setting" of the security system. Alternatively, if there is a controller for home automation and there is a command to operate devices collectively when going out, returning home, going to bed, etc., the mode of the home gateway 20 may be changed in conjunction with the command, for example, to transition to "away mode" when a collective operation is performed when going out, to "active mode" when a collective operation is performed when returning home, or to "inactive mode" when a collective operation is performed when going to bed.

[0239] This allows the home gateway 20, etc. to more accurately transition modes by linking with other systems, functions of other devices, etc., even when the mode cannot be determined solely from the communication messages exchanged over the home network 11.

[0240] The home gateway 20 etc. is not limited to being a security system or home automation controller, but may be linked to other systems or other devices, or may be provided with an input unit that allows residents to input modes directly.

[0241] (13) In the above-described embodiments, the home gateway 20 or the like includes the receiving unit 100, the initial device list creating unit 110, the unregistered device detecting unit 120, the classification unit 130, the home appliance message determining unit 140, the forwarding determining unit 150, the transmitting unit 160, the device list holding unit 200, and the status holding unit 210. Alternatively, the home gateway 20 includes the receiving unit 100, the initial device list creating unit 110, the unregistered device detecting unit 120, the classification unit 130, the home appliance message determining unit 140, the forwarding determining unit 150, the transmitting unit 160, the mode determining unit 170, the device list holding unit 200, the status holding unit 210, and the mode holding unit 220. However, this is not limiting. FIG. 31 illustrates an example of the configuration of a home gateway 20e according to an eleventh modification of the above-described embodiments. FIG. 32 is a flowchart illustrating an example of a determination process of the home gateway 20e according to the eleventh modification of the above-described embodiments. Fig. 33 is a diagram showing another example of the configuration of the home gateway 20f according to Modification 11 of each of the above-mentioned embodiments. Fig. 34 is a flowchart showing an example of the determination process of the home gateway 20f according to Modification 11 of each of the above-mentioned embodiments.

[0242] As shown in FIG. 31, the home gateway 20e may include at least a receiving unit 100, a forwarding determining unit 150, a transmitting unit 160, and a status holding unit 210.

[0243] In this case, as shown in FIG. 32, the main processing must include at least a judgment process (S1003), which at least receives a message (S3001), and determines whether or not the received message can be forwarded based on the status of at least one of the devices connected to the home network 11 and the people in the home (S3006).If forwarding is permitted (Yes in S3006), the processing of registering the device status (S3007) and sending the message (S3008) can be performed as necessary.

[0244] 33, the home gateway 20f may include at least a receiving unit 100, a forwarding determination unit 150, a transmitting unit 160, a mode determination unit 170, a status holding unit 210, and a mode holding unit 220.

[0245] In this case, as shown in FIG. 34, the judgment process involves at least receiving a message (S3001), and judging whether or not it is OK to forward the received message based on the status of at least one of the devices connected to the home network 11 and the people in the home (S3006). If it is OK to forward the message (Yes in S3006), the process of registering the device status (S3007), determining the mode (S3009), and sending the message (S3008) can be performed as necessary.

[0246] (14) In the above embodiment, unauthorized communication is detected by the home gateway 20 or the like, but this is not limiting. Unauthorized communication may be detected in a home appliance (including residential equipment) such as the electric lock 40, and a decision may be made as to whether or not to process (execute) the received message. For example, when the electric lock 40 receives a device control command from another device instructing it to unlock the electric lock 40, the electric lock 40 may execute the device control command and decide whether or not to perform the unlocking process for the electric lock 40.

[0247] Fig. 35 is a diagram showing an example of the configuration of the electric lock 40a according to Modification 12 of each of the above-mentioned embodiments. Fig. 36 is a flowchart showing an example of the determination process of the electric lock 40a according to Modification 12 of each of the above-mentioned embodiments. Note that, although an example in which the electric lock 40a has the configuration shown in Fig. 35 will be described below, other devices (e.g., air conditioner 41, lighting 42, etc.) may also have the configuration shown in Fig. 35. For example, each of two or more devices may have the configuration shown in Fig. 35.

[0248] The configuration of a home appliance (e.g., electric lock 40a) that detects unauthorized communication is, for example, as shown in FIG. 35. As shown in FIG. 35, electric lock 40 has a receiving unit 100, a determining unit 180, a processing execution unit 190, and a status holding unit 210. Here, the determining unit 180 performs the same processing as the forwarding determining unit 150 used to determine whether to forward a message, and determines whether to process the received message based on a status list (an example of first information). The determining unit 180 determines whether to execute processing related to a device control command by determining whether the device control command is to be executed by its own device (e.g., electric lock 40a). Furthermore, the processing execution unit 190 actually processes the received message. For example, the processing execution unit 190 in electric lock 40a actually performs unlocking and locking processing.

[0249] The electric lock 40a according to this modification functions as an unauthorized communication detection device that detects unauthorized communication messages in the home network 11. The process execution unit 190 is an example of an execution unit.

[0250] The determination process in this configuration is as shown in FIG. 36. Here, while the home gateway 20 or the like determines whether or not the control command can be transferred in step S3006, in this configuration, it determines whether or not the electric lock 40a can process the received control command (S3006a). The specific determination content is the same as in the above embodiment and other modified examples, so a detailed explanation will be omitted. In the determination in step S3006a, a determination as to whether or not to execute is made based on the status list stored in the status storage unit 210. Step S3006a is an example of a first determination step. If the result in step S3006a is Yes, processing for the received message is executed (S3011). Step S3011 is an example of an execution step. In the execution step, the operation of the electric lock 40a may be controlled based on the device control command as the execution of the processing. In this case, the processing of executing the device control command included in the communication message is an example of processing related to the device control command.

[0251] Alternatively, the electric lock may have the configuration shown in Fig. 37. Fig. 37 is a diagram showing another example of the configuration of the electric lock 40b according to the twelfth modification of each of the above-mentioned embodiments. Fig. 38 is a flowchart showing another example of the determination process of the electric lock 40b according to the twelfth modification of each of the above-mentioned embodiments.

[0252] As shown in Figure 37, the configuration of electric lock 40b is the same as the configuration of electric lock 40a shown in Figure 35, with the addition of a mode determination unit 170 and a mode retention unit 220. The determination process in this configuration is as shown in Figure 38. The process of determining the mode (step S3009) is the same as in the above embodiment, so a description thereof will be omitted.

[0253] This allows unauthorized communications to be detected in the home appliance or housing equipment itself.

[0254] Note that the configurations of Figures 35 and 37 and the determination processes of Figures 36 and 38 are merely examples, and may be combined with the components or processes included in embodiment 1, embodiment 2, and other modified examples.

[0255] (15) In the above embodiment, home appliances and non-home appliances are registered as device types, but this is not limited to this. If there are multiple communication protocols controlling home appliances within the home network 11, for example, the device types may be set as protocol 1 devices, protocol 2 devices, and other devices, and the forwarding determination unit 150 may determine to forward when the source device type and the destination device type are the same, and may determine not to transmit when the source device type and the destination device type are different.

[0256] (16) In the above embodiment, a configuration in which home appliances and a PC are connected to the home network 11 has been described, but the present invention is not limited to this. A configuration in which a control device and a PC are connected to a factory network, a configuration in which a building equipment management device and a PC are connected to a building network, or a configuration in which various electronic control units are connected to an in-vehicle network may also be used. Any configuration may be used as long as multiple devices are connected to a network limited to a certain space and communication is performed to control those devices.

[0257] (17) In the above embodiment, the home network 11 is simply described. However, the home network 11 may be connected via wired communication such as Ethernet (registered trademark), CAN (Controller Area Network) (registered trademark), or via wireless communication such as Bluetooth (registered trademark), Wi-Fi (registered trademark), ZigBee (registered trademark), Z-Wave (registered trademark), or a combination of these, and is not dependent on the communication method. Furthermore, the communication method itself may include a protocol for controlling home appliances (including residential equipment), or any combination of a communication method and a protocol may be used, such as Ethernet as the communication method and ECHONET Lite as the protocol. Furthermore, a unique communication method or protocol may be combined with an existing communication method or protocol.

[0258] Furthermore, the home network 11 is not limited to being within a home. For example, it may be a network within a building, factory, vehicle, or other building, in which multiple devices are connected via a network and status notifications and device control are performed via the network, and any communication method or protocol adopted in each network may be used.

[0259] This makes it possible to detect fraudulent messages sent and received not only in homes, but also in buildings, factories, vehicles, and any other building.

[0260] (18) Each device in the above embodiments is specifically a computer system consisting of a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), a hard disk unit, a display unit, a keyboard, a mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device achieves its function when the microprocessor operates in accordance with the computer program. Here, a computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.

[0261] (19) In each of the above embodiments, some or all of the constituent elements may be configured from a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0262] Furthermore, each of the components constituting each of the above devices may be individually integrated into a single chip, or some or all of them may be integrated into a single chip.

[0263] Although we refer to it as a system LSI here, it may also be called an IC (Integrated Circuit), LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the method of integration is not limited to LSI, but may be realized using dedicated circuits or general-purpose processors. It is also possible to use FPGAs (Field Programmable Gate Arrays), which can be programmed after LSI manufacturing, or reconfigurable processors, which allow the connections and settings of circuit cells within LSI to be reconfigured.

[0264] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.

[0265] (20) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or the module achieves its functions when the microprocessor operates according to a computer program. This IC card or the module may be tamper-resistant.

[0266] (21) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.

[0267] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.

[0268] The present disclosure may also be applied to transmitting a computer program or digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0269] The present disclosure may also be a computer system including a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.

[0270] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal may be implemented by another independent computer system.

[0271] (22) The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block. Furthermore, the functions of multiple functional blocks with similar functions may be processed in parallel or time-shared by a single piece of hardware or software.

[0272] (23) The order of processes described in the flowcharts of the above embodiments is merely an example. The order of multiple processes may be changed, or multiple processes may be executed in parallel.

[0273] (24) The above-described embodiments and modifications may be combined with each other.

[0274] Furthermore, this technology can be realized as a method including some or all of the processing steps performed by each component in each of the above embodiments or their variations, or as a program that is executed by a processor of the unauthorized communication detection system to cause the unauthorized communication detection system to implement this method. Furthermore, in the above embodiments or their variations, the processing performed by a specific component may be performed by another component instead of the specific component. Furthermore, the order of multiple processes may be changed, or multiple processes may be performed in parallel. [Industrial Applicability]

[0275] The present disclosure is useful, for example, in a communication network in which home appliances and other devices are connected. [Explanation of symbols]

[0276] 10. Internet 11 Home Network 12 IT equipment networks 13 Home appliance networks 20, 20a, 20b, 20c, 20d, 20e, 20f Home Gateway 30 PC 40, 40a, 40b electric lock 41 Air Conditioner 42 Lighting 43 Controller 50 devices 60 Router 70 Hub 100 Receiver 110 Initial Equipment List Creation Department 120 Unregistered device detection unit 130 Classification Department 140 Home appliance message determination unit 150 Forwarding decision unit 160 Transmitter 170 Mode determination unit 180 Judgment section 190 Processing execution unit 200 Device list holder 210 State holding unit 220 Mode holding unit

Claims

1. 1. A method for detecting unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are communicatively connected to each other, the method comprising: a receiving step of receiving, from the first device, a communication message transmitted from the first device to the second device; an acquisition step of acquiring, when the communication message is received from the first device, first information indicating at least one of a state indicating whether or not there is a person in the facility in which the intra-facility network is installed and a state of at least one of the two or more devices; a first determination step of determining, when the communication message received from the first device is a communication message including a device control command for controlling the second device, whether or not to execute a process related to the device control command based on the first information; an execution step of executing the process related to the device control command when it is determined in the first determination step that the process is to be executed; the intra-facility network further includes a relay device that relays the communication messages transmitted and received between the two or more devices, the relay device executing the unauthorized communication detection method; the process related to the device control command is a process of transmitting the communication message including the device control command to the second device; In the first determination step, as the determination of whether to execute the process related to the device control command, it is determined whether to transmit the communication message including the device control command to the second device; In the execution step, the communication message is transmitted to the second device as the execution of the process; The method further includes a second determination step of determining a forwarding determination mode of the relay device based on the first information, In the first determination step, it is determined whether or not to transmit the communication message including the device control command to the second device based on the transfer determination mode of the relay device determined in the second determination step; In the second determination step, when it is determined from the first information that there is a person in the facility, the transfer determination mode is determined to be an active mode, and when it is determined from the first information that there is no person in the facility, the transfer determination mode is determined to be an absent mode; In the first determination step, when the transfer determination mode is an active mode, it is determined that the device control command is to be sent to the second device, and when the transfer determination mode is an absent mode, it is determined that the device control command is not to be sent to the second device; The forwarding determination mode further includes an inactive mode; In the second determination step, when it is determined from the first information that there is a person in the facility and that the person is active, it is determined that the transfer determination mode is the active mode, and when it is determined from the first information that there is a person in the facility and that the person is not active, it is determined that the transfer determination mode is the inactive mode; the second device is an electric lock, The device control command includes either an unlock command for unlocking the electric lock or a command other than the unlock command, In the first determination step, when the transfer determination mode is the active mode, it is determined that each of the unlock command and the other command will be sent to the second device; when the transfer determination mode is the inactive mode, it is determined that only the other command out of the unlock command and the other command will be sent to the second device; and when the transfer determination mode is the absent mode, it is determined that each of the unlock command and the other command will not be sent to the second device. Method for detecting unauthorized communications.

2. A method for detecting unauthorized communication, which detects unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are communicably connected to each other, comprising: a receiving step of receiving, from the first device, a communication message transmitted from the first device to the second device; an acquisition step of acquiring, when the communication message is received from the first device, first information indicating at least one of a state indicating whether or not there is a person in the facility in which the intra-facility network is installed and a state of at least one of the two or more devices; a first determination step of determining, when the communication message received from the first device is a communication message including a device control command for controlling the second device, whether or not to execute a process related to the device control command based on the first information; an execution step of executing the process related to the device control command when it is determined in the first determination step that the process is to be executed; the intra-facility network further includes a relay device that relays the communication messages transmitted and received between the two or more devices, the relay device executing the unauthorized communication detection method; the process related to the device control command is a process of transmitting the communication message including the device control command to the second device; In the first determination step, as the determination of whether to execute the process related to the device control command, it is determined whether to transmit the communication message including the device control command to the second device; In the execution step, the communication message is transmitted to the second device as the execution of the process; The method further includes a second determination step of determining a forwarding determination mode of the relay device based on the first information, In the first determination step, it is determined whether or not to transmit the communication message including the device control command to the second device based on the transfer determination mode of the relay device determined in the second determination step; In the second determination step, when it is determined from the first information that there is a person in the facility, the transfer determination mode is determined to be an active mode, and when it is determined from the first information that there is no person in the facility, the transfer determination mode is determined to be an absent mode; In the first determination step, when the transfer determination mode is an active mode, it is determined that the device control command is to be sent to the second device, and when the transfer determination mode is an absent mode, it is determined that the device control command is not to be sent to the second device; The forwarding determination mode further includes an inactive mode; In the second determination step, when it is determined from the first information that there is a person in the facility and that the person is active, it is determined that the transfer determination mode is the active mode, and when it is determined from the first information that there is a person in the facility and that the person is not active, it is determined that the transfer determination mode is the inactive mode; the device control command includes either a specific device control command or a command other than the specific device control command, In the first determination step, when the transfer determination mode is the active mode, it is determined that each of the specific device control command and the other command will be sent to the second device; when the transfer determination mode is the inactive mode, it is determined that only the other command out of the specific device control command and the other commands will be sent to the second device; and when the transfer determination mode is the absent mode, it is determined that each of the specific device control command and the other command will not be sent to the second device. Method for detecting unauthorized communications.

3. the first information includes a status indicating whether or not there is a person in the facility, In the first determination step, when it can be determined from the first information that there is a person in the facility, it is determined that the communication message including the device control command is to be transmitted to the second device, and when it can be determined from the first information that there is no person in the facility, it is determined that the communication message including the device control command is not to be transmitted to the second device. The method for detecting unauthorized communications according to claim 1 or 2.

4. In the second determination step, when it is determined from the first information that a person is present only near an entrance of the facility, the transfer determination mode is determined to be an entrance mode; In the first determination step, if the transfer determination mode is the entrance mode and the first device is not located near the entrance, it is determined that the unlock command should not be transmitted. The method for detecting unauthorized communications according to claim 1 .

5. In the second determination step, when it is determined from the first information that there is a person in the facility and that the person is the only person who is not authorized to control the two or more devices via the facility network, the transfer determination mode is determined to be an answering machine mode; In the first determination step, if the transfer determination mode is the answering machine mode, it is determined that only the other command out of the unlock command and the other command is to be transmitted. The unauthorized communication detection method according to claim 1 or 4.

6. and an updating step, between the first determination step and the execution step, of updating the first information based on at least one of a state indicating whether or not there is a person in the facility after the execution of the process when it is determined that the process related to the device control command is to be executed, and a state of at least one of the two or more devices. The unauthorized communication detection method according to any one of claims 1 to 5.

7. In the first determination step, if the communication message is a message including the device control command, it is determined whether or not to execute the process related to the device control command based on a predetermined condition; the predetermined condition includes that the first device is a device having a predetermined function; The unauthorized communication detection method according to any one of claims 1 to 6.

8. The facility is a residence. The unauthorized communication detection method according to any one of claims 1 to 7.

9. An unauthorized communication detection device that detects unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are communicably connected to each other, a receiving unit that receives, from the first device, a communication message transmitted from the first device to the second device; an acquisition unit that acquires, when the communication message is received from the first device, first information indicating at least one of a state indicating whether or not a person is present in the facility in which the intra-facility network is installed and a state of at least one of the two or more devices; a first determination unit that, when the communication message received from the first device is a communication message including a device control command for controlling the second device, determines whether or not to execute a process related to the device control command based on the first information; an execution unit that executes the process when the first determination unit determines that the process related to the device control command is to be executed; the process related to the device control command is a process of transmitting the communication message including the device control command to the second device; the first determination unit determines whether to transmit the communication message including the device control command to the second device as the determination of whether to execute the process related to the device control command; the execution unit transmits the communication message to the second device as the execution of the process; a second determination unit that determines a transfer determination mode based on the first information; the first determination unit determines whether to transmit the communication message including the device control command to the second device based on the transfer determination mode determined by the second determination unit; the second determination unit determines the transfer determination mode to be an active mode when it can be determined from the first information that there is a person in the facility, and determines the transfer determination mode to be an absent mode when it can be determined from the first information that there is no person in the facility; the first determination unit determines to transmit the device control command to the second device when the transfer determination mode is an active mode, and determines not to transmit the device control command to the second device when the transfer determination mode is an absent mode; The forwarding determination mode further includes an inactive mode; the second determination unit determines, from the first information, when there is a person in the facility and the person is active, that the transfer determination mode is the active mode; and, from the first information, when there is a person in the facility and the person is not active, that the transfer determination mode is the inactive mode; the second device is an electric lock, The device control command includes either an unlock command for unlocking the electric lock or a command other than the unlock command, the first determination unit determines, when the transfer determination mode is the active mode, to transmit each of the unlock command and the other command to the second device; when the transfer determination mode is the inactive mode, to transmit only the other command out of the unlock command and the other command to the second device; and when the transfer determination mode is the absent mode, to determine not to transmit each of the unlock command and the other command to the second device. Unauthorized communications detection device.

10. An unauthorized communication detection device that detects unauthorized communication messages in an in-facility network in which two or more devices, including a first device and a second device, are communicably connected to each other, comprising: a receiving unit that receives, from the first device, a communication message transmitted from the first device to the second device; an acquisition unit that acquires, when the communication message is received from the first device, first information indicating at least one of a state indicating whether or not a person is present in the facility in which the intra-facility network is installed and a state of at least one of the two or more devices; a first determination unit that, when the communication message received from the first device is a communication message including a device control command for controlling the second device, determines whether or not to execute a process related to the device control command based on the first information; an execution unit that executes the process when the first determination unit determines that the process related to the device control command is to be executed; the process related to the device control command is a process of transmitting the communication message including the device control command to the second device; the first determination unit determines whether to transmit the communication message including the device control command to the second device as the determination of whether to execute the process related to the device control command; the execution unit transmits the communication message to the second device as the execution of the process; a second determination unit that determines a transfer determination mode based on the first information; the first determination unit determines whether to transmit the communication message including the device control command to the second device based on the transfer determination mode determined by the second determination unit; the second determination unit determines the transfer determination mode to be an active mode when it can be determined from the first information that there is a person in the facility, and determines the transfer determination mode to be an absent mode when it can be determined from the first information that there is no person in the facility; the first determination unit determines to transmit the device control command to the second device when the transfer determination mode is an active mode, and determines not to transmit the device control command to the second device when the transfer determination mode is an absent mode; The forwarding determination mode further includes an inactive mode; the second determination unit determines, from the first information, when there is a person in the facility and the person is active, that the transfer determination mode is the active mode; and, from the first information, when there is a person in the facility and the person is not active, that the transfer determination mode is the inactive mode; the device control command includes either a specific device control command or a command other than the specific device control command, the first determination unit determines, when the transfer determination mode is the active mode, to transmit each of the specific device control command and the other command to the second device; when the transfer determination mode is the inactive mode, to transmit only the other command out of the specific device control command and the other commands to the second device; and when the transfer determination mode is the absent mode, to determine not to transmit each of the specific device control command and the other command to the second device. Unauthorized communications detection device.

11. A program for causing a computer to execute the unauthorized communication detection method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Domestic appliance control system

    JP2006203516A

  • Device for restricting telecommunications services

    JP4082613B2

  • Device control method, device control system, and server device

    WO2014024428A1