Control method for improving security of remote control services and computer program for performing the same
The method enhances remote control service security by managing service activation and deactivation through a security policy server, using unique identification and port management to ensure secure connections, effectively blocking unauthorized access.
Patent Information
- Application Number
- JP2023072828
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-11-23
- Filing Date
- 2023-04-27
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2043-04-27
AI Technical Summary
Remote control application programs have security vulnerabilities that pose a risk of cyber attacks on internal company networks, necessitating a method to enhance the security of remote control services while enabling effective teleworking.
A control method involving a security policy server that manages the activation and deactivation of remote control services based on user and terminal identification, using unused port numbers and firewall policies to ensure secure connections, and terminates the service upon request.
Effectively blocks unauthorized connections and secures remote control services by deactivating the service by default and activating it only for authorized users, preventing security threats through unauthorized access.
Smart Images

Figure 0007735642000001 
Figure 0007735642000002 
Figure 0007735642000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a control method for improving the security of a remote control service and a computer program for carrying out the same. [Background technology]
[0002] With the development of communications technologies such as 5G and cloud computing, restrictions on where people work are disappearing. In particular, with the recent changes in the environment, such as the COVID-19 pandemic, work is no longer limited to the office, and the proportion of people working in various locations, i.e., telework (working from remote locations), is rapidly increasing.
[0003] A user (employee) can telework by connecting to another device at their workplace using a desktop computer, laptop computer, smartphone, or other device located in a remote location (e.g., home) and this type of service is defined as a remote control service. Alternatively, a remote control service is a service that enables a device to connect to another device and telework through a remote control protocol provided by the execution of a remote control application program. Such remote control services are provided by a variety of service providers; for example, Microsoft provides a remote control service through the Remote Desktop Protocol (RDP) and a remote desktop application program.
[0004] A remote control protocol is a protocol that provides an interface for a user to have control over another terminal connected to a network. When a remote control application program is executed on a terminal, the user connects to another terminal at the workplace (such as an internal company network) through the remote control protocol, checks the graphic data displayed on the screen of the other terminal, and performs user input operations on the remote computer through the terminal.
[0005] However, such remote control application programs may have security vulnerabilities, and there is a risk that cyber attacks may be attempted on internal company networks through programs with security vulnerabilities.
[0006] In fact, various vulnerabilities (such as CVE-2019-0708) have been found in remote control application programs, and due to these vulnerabilities, security guidelines issued by the Financial Security Agency and other organizations recommend that users not use remote control application programs with weak security (Financial Company Telework Security Guidebook, published by the Financial Security Agency in 2022).
[0007] Therefore, there is a need for a method that enables effective teleworking using remote control services while preventing security threats caused by remote control application programs with weak security. Summary of the Invention [Problem to be solved by the invention]
[0008] The problem to be solved by the present invention is to provide a method capable of strengthening the security of a remote control service whose security is weak. [Means for solving the problem]
[0009] To solve the above problem, a control method for improving security of a remote control service according to one aspect of the present invention includes the steps of: a security policy server connected to a client terminal and a remote terminal, respectively, receiving identification information from the client terminal that has received a request to provide a remote control service; identifying the remote terminal corresponding to the client terminal based on the received identification information (the remote terminal is in a state where the remote control service is deactivated); generating port information for connecting the client terminal to the identified remote terminal; transmitting the generated port information and a remote control service activation command to the identified remote terminal; transmitting remote terminal connection information including the port information to the client terminal; and providing the remote control service based on the connection between the client terminal and the remote terminal.
[0010] According to an embodiment, the identification information includes at least one piece of unique information related to the client terminal or the user.
[0011] According to one embodiment, the step of identifying a remote terminal corresponding to the client terminal includes a step of identifying a remote terminal having information that matches or corresponds to unique information in the identification information received from the client terminal among service authentication information stored in each of a plurality of remote terminals as the remote terminal corresponding to the client terminal.
[0012] In one embodiment, the step of generating the port information includes the steps of randomly selecting one of the port numbers that are not in use in the remote terminal, and generating the port number including the one of the randomly selected port numbers.
[0013] According to one embodiment, the method further includes a step of activating the remote control service of the remote terminal device in response to the port information and a remote control service activation command, the activating step including a step of modifying registry information or port setting information so that the remote terminal device connects to the client terminal through a port number corresponding to the port information, and a step of setting a firewall policy to allow communication related to the remote control service to the port number.
[0014] According to one embodiment, the method further includes a step of the client terminal connecting to the remote terminal based on the remote terminal connection information, and the connecting step includes a step of the client terminal running a remote control application program provided thereon based on the port information included in the remote terminal connection information.
[0015] According to one embodiment, the step of transmitting the generated port information and remote control service activation command to the identified remote terminal includes a step of transmitting the port information, the remote control service activation command, and IP address information of the client terminal to the remote terminal, and the step of the client terminal connecting to the remote terminal includes a step of the client terminal connecting to the remote terminal when it is confirmed by a remote control application program of the remote terminal that the IP address of the client terminal matches the received IP address information.
[0016] According to one embodiment, the method further includes a step of detecting the termination of the remote control service and a step of transmitting connection termination information based on the detection result to a security policy server, and the step of detecting the termination of the remote control service includes a step of detecting the termination of a remote control application program related to the remote control service or a step of detecting the termination of communication of a port corresponding to the port information.
[0017] According to one embodiment, the method further includes a step in which the security policy server transmits a remote control service deactivation command to the remote terminal in response to the received connection termination information, and a step in which the remote terminal deactivates the remote control service in response to the received remote control service deactivation command.
[0018] In one embodiment, the step of deactivating the remote control service includes at least one of the steps of modifying registry information or port setting information to cancel communication permission for the port corresponding to the port information, deleting a firewall policy that has been set to allow communication related to the remote control service to the port number, and blocking execution of an application program process related to the remote control service.
[0019] According to one aspect of the present invention, there is provided a computer program stored on a computer-readable recording medium that can be combined with a computer as hardware to perform a control method for improving the security of a remote control service according to an embodiment of the present invention. [Effects of the Invention]
[0020] According to the present invention, a remote terminal can effectively block unauthorized connections from other terminals and security threats that exploit security vulnerabilities in the remote control application program by basically deactivating the remote control service and deactivating the basic ports used in the remote control protocol, and can activate the remote control service only when an authorized user's client terminal (a terminal that receives a remote control application execution request) attempts to connect. Furthermore, the remote terminal can smoothly use the remote control application program by restricting network communications used by the remote control application program to information (IP, port) confirmed by the authorized user's client terminal. Therefore, unauthorized users or terminals can be effectively prevented from connecting to the remote terminal through the remote control application program, thereby providing a remote control service with improved security.
[0021] The effects obtained by the control method for improving the security of remote control services according to the present invention are not limited to those mentioned above, and further effects not mentioned will be clearly understood by those skilled in the art from the following description. [Brief explanation of the drawings]
[0022] [Figure 1] 1 is a diagram illustrating a remote control service providing system with improved security according to an embodiment of the present invention. [Figure 2] 2 is a block diagram showing a control configuration of a device included in the system shown in FIG. 1. FIG. [Figure 3] FIG. 1 is a ladder diagram illustrating a control method for improving security of remote control services according to an exemplary embodiment of the present invention. [Figure 4] FIG. 1 is a ladder diagram illustrating a control method for improving security of remote control services according to an exemplary embodiment of the present invention. [Figure 5]1 is a diagram illustrating a telework system using a virtual private network as an example of a system in which a control method for improving security of a remote control service according to an embodiment of the present invention is implemented. DETAILED DESCRIPTION OF THE INVENTION
[0023] The exemplary embodiments of the present invention are provided to more completely explain the present invention to those skilled in the art, and the following embodiments may be modified into various other forms, and the scope of the present invention is not limited to the following embodiments. Rather, these embodiments are provided to more fully and completely convey the present invention to those skilled in the art.
[0024] Although terms such as "first" and "second" are used herein to describe various members, regions, layers, sections, and / or components, it is clear that these members, regions, layers, sections, and / or components should not be limited by these terms. These terms do not imply a specific order, hierarchy, or superiority or inferiority, but are used to distinguish one member, region, section, or component from another member, region, section, or component. Therefore, a first member, region, section, or component described below may refer to a second member, region, section, or component without departing from the teachings of the present invention. For example, a first component may be referred to as a second component, and similarly, a second component may be referred to as a first component, without departing from the scope of the present invention.
[0025] Unless otherwise defined, all terms used herein, including technical and scientific terms, have the same meaning as commonly understood by those skilled in the art to which the concept of the present invention belongs. Furthermore, commonly used and dictionary-defined terms should be interpreted to have the same meaning as they have in the context of the relevant technology, and should not be interpreted as overly formal unless explicitly defined herein.
[0026] When an embodiment is implemented differently, the order of specific steps or processes may be different from the order described. For example, two steps or processes described as successive may be performed substantially simultaneously, or may be performed in the reverse order from that described.
[0027] Furthermore, the terms "unit", "device", "child", "module" and the like used in this specification refer to a unit that processes at least one function or operation, which may be embodied in hardware or software, or a combination of hardware and software, such as a processor, microprocessor, microcontroller, CPU (Central Processing Unit), GPU (Graphics Processing Unit), APU (Accelerate Processor Unit), DSP (Drive Signal Processor), ASIC (Application Specific Integrated Circuit), FPGA (Field Programmable Gate Array), etc., and may be embodied in a form that is combined with a memory that stores data necessary for processing at least one function or operation.
[0028] It should be understood that the division of components in the present invention is merely a division according to the main function of each component. That is, two or more components described below may be combined into one component, or one component may be divided into two or more components according to further subdivided functions. It goes without saying that each component described below may perform some or all of the functions of other components in addition to its own main function, and that some of the main functions of each component may be exclusively performed by other components.
[0029] As used herein, the term "and / or" includes each and every combination of one or more of the listed items.
[0030] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0031] FIG. 1 is a diagram illustrating a system for providing a remote control service with improved security according to an embodiment of the present invention.
[0032] In the present invention, a remote control service refers to a service that enables a terminal to control the operation of another terminal located at a distance through a remote control protocol provided by the execution of a remote control application program. Such remote control services are provided by various businesses (service providers), and representative examples include Microsoft's Remote Desktop application program and Remote Desktop Protocol (RDP), but the application of the embodiments of the present invention is not limited to Microsoft's services.
[0033] 1, a remote control service providing system according to an embodiment of the present invention includes a first terminal 10, a second terminal 20, and a security policy server 30. Although one first terminal 10, one second terminal 20, and one security policy server 30 are shown in FIG. 1, a plurality of the above components may be provided.
[0034] The first terminal 10 is a client terminal that requests a connection for remote control of the second terminal 20, and is a device that remotely controls the operation of the second terminal 20 through a remote control service and receives and outputs screens and sounds to be output to the second terminal 20. The second terminal 20 is a remote terminal that provides remote control authority to the first terminal 10 through the remote control service and provides screens and sounds to be output to the first terminal 10. Each of the first terminal 10 and the second terminal 20 includes various fixed / mobile terminals such as desktop PCs, notebook PCs, smartphones, tablet PCs, and workstations.
[0035] The security policy server 30 is a server that performs a series of operations to improve the security of the remote control service provided between the first terminal 10 and the second terminal 20.
[0036] FIG. 2 is a block diagram showing the control configuration of the devices included in the system shown in FIG.
[0037] The device 200 shown in Fig. 2 corresponds to the first terminal 10, the second terminal 20, or the security policy server 30 in Fig. 1. Fig. 2 shows a communication unit 210, an input unit 220, an output unit 230, a control unit 240, and a memory 250 as an example of the control configuration of the device 200, but each of the first terminal 10, the second terminal 20, or the security policy server 30 may include more or less components than those shown in Fig. 2.
[0038] The communication unit 210 includes one or more communication modules that connect the device 200 to a network to enable communication with other devices, terminals, servers, etc. For example, the communication modules may include modules that support various known types of wired or wireless communication, such as a mobile communication module, a wired or wireless Internet module, or a short-range wireless communication module. The input unit 220 is for inputting information, image information, audio information, data, etc. input by a user, and includes various input means such as various mechanical / electronic input means, a camera, a microphone, etc. The output unit 230 is for generating an output related to vision, hearing, or touch to provide information to a user, etc., and includes a display, a speaker, a haptic module, etc.
[0039] The control unit 240 controls the overall operation of the device 200. The control unit 240 processes signals, data, information, etc. input or output through the above-mentioned components, or runs various applications stored in the memory 250 to provide predetermined information or functions.
[0040] For example, the control unit 240 provides a remote connection between the first terminal 10 and the second terminal 20 through a remote control application program 254. In particular, when a remote desktop is connected, the control unit 240 provides a remote control service with improved security through a security control application 252. The operation for improving the security of a remote control service according to an embodiment of the present invention will be described in detail below with reference to FIGS.
[0041] The control unit 240 includes at least one processor, which may be implemented in hardware such as a CPU, an AP (application processor), an integrated circuit, a microcomputer, an ASIC (application specific integrated circuit), an FPGA (field programmable gate array), and / or an NPU (neural processing unit).
[0042] The memory 250 stores programs and data necessary for the operation of the device 200. The memory 250 also stores data generated or acquired through the control unit 240. For example, the memory 250 stores various applications and data such as a security control application 252 and a remote control application program 254.
[0043] The memory 250 is configured from a recording medium such as a read only memory (ROM), a random access memory (RAM), a flash memory, a solid state drive (SSD), or a hard disk drive (HDD), or a combination of recording media.
[0044] 3 and 4 are ladder diagrams for explaining a control method for improving security of a remote control service according to an exemplary embodiment of the present invention.
[0045] The security control application 252 according to an embodiment of the present invention is an application that is loaded and executed by the control unit 240 of the device 200 to perform a predetermined operation. That is, the security control application 252 is coupled to a computer (terminal or server) that is hardware, and performs a control operation to improve the security of the remote control service of the first terminal 10, the second terminal 20, or the security policy server 30 according to an embodiment of the present invention. The specific operation of the security control application 252 differs for each of the devices 10, 20, and 30. Hereinafter, although it has been described in the specification that the subject of the control operation to improve the security of the remote control service according to an embodiment of the present invention is the first terminal 10, the second terminal 20, or the security policy server 30, these control operations are performed by the security control application 252 of each device.
[0046] Based on this, referring to Figures 3 and 4, the second terminal 20 deactivates the remote control service (step S300), and the user transmits service authentication information to the security policy server 300 through another terminal to activate the remote control service of the second terminal 20 (step S305).
[0047] The remote control application program 254 is a service in which the second terminal 20 provides other terminals with control authority over the second terminal 20 and provides other terminals with the screen and sound output from the second terminal 20, making it very difficult to ensure security. However, if the remote control application program 254 providing the remote control protocol has a security vulnerability, the security of the remote control protocol may be weakened, leading to problems such as the leakage of important information stored in the second terminal 20.
[0048] Therefore, the second terminal 20 basically deactivates the remote control service and blocks unauthorized users from connecting to the second terminal 20 using the remote control service. For example, the second terminal 20 sets a firewall policy to suspend the service for running the remote control protocol or to block the communication port for the remote control protocol. Alternatively, the second terminal 20 may block the execution of the process (e.g., mstsc.exe) of the remote control application program 254.
[0049] However, the user of the second terminal 20 may attempt to use the remote control service of the second terminal 20 through another terminal of the second terminal 20 or another authorized user. Therefore, the second terminal 20 transmits service authentication information that enables the authorized user to activate the deactivated remote control service to the security policy server 30. Although step S305 is shown in FIG. 1 to be performed after step S300, step S305 may be performed at various times and in various situations, such as when the security control application 252 is first executed or in response to a user setting operation.
[0050] The service authentication information is unique information for identifying a user and / or a terminal, and includes the user's ID, employee number and / or name, and the ID of the second terminal 20. The security policy server 30 stores the service authentication information transmitted from the second terminal 20 in the storage unit 250 or a DB.
[0051] Meanwhile, the first terminal 10 receives a request for providing a remote control service (step S310) and transmits identification information for using the remote control service to the security policy server 30 (step S315).
[0052] The user of the first terminal 10 executes the remote control application program 254 and performs user input operations for remote connection to the second terminal 20. The first terminal 10 receives a request for remote control service provision based on the series of user input operations and transmits identification information for use of the remote control service to the security policy server 30. For example, the identification information includes the user's unique information (ID, employee number, name, etc.) and the IP address and ID of the first terminal 10.
[0053] The security policy server 30 identifies the second terminal 20 corresponding to the first terminal 10 based on the received identification information (S320).
[0054] The security policy server 30 identifies the second terminal 20 corresponding to the first terminal 10 for remote connection based on the received identification information. Specifically, the security policy server 30 identifies the remote terminal (second terminal 20) having information that matches or corresponds to the identification information received from the first terminal 10 among the remote terminal-specific service authentication information (received and stored in step S315) stored in the memory 250 or DB as the corresponding terminal. For example, the security policy server 30 identifies the second terminal 20 having an ID that matches the user ID included in the identification information received from the first terminal 10 among the remote terminal-specific user IDs stored in the memory 250 or DB as the corresponding terminal.
[0055] On the other hand, if the corresponding terminal is not identified, the security policy server 30 requests the first terminal 10 to retransmit the identification information or does not permit the first terminal 10 to use the remote control service.
[0056] The security policy server 30 generates port information for connecting the first terminal 10 to the identified second terminal 20 (step S325), and transmits the generated port information and a remote control service activation command to the second terminal 20 (step S330).
[0057] In TCP / UDP communication, port numbers are used to identify which program in the terminal to send data to. Some of the port numbers in the second terminal 20 are used by other programs, but the remaining part is unused.
[0058] The security policy server 30 generates port information corresponding to one of the port numbers that are not currently in use in the second terminal 20. To this end, the second terminal 20 may provide information about the port numbers that are not currently in use to the security policy server 30. For example, the one port number may be selected randomly, but is not limited to this and may be selected in various ways. The security policy server 30 transmits the generated port information and a remote control service activation command to the second terminal 20.
[0059] According to an embodiment, the security policy server 30 further transmits the IP address information of the first terminal 10 to the second terminal 20 in addition to the port information and the remote control service activation command, so that the second terminal 20 can connect only the first terminal 10 to the port number corresponding to the port information.
[0060] The second terminal 20 activates the deactivated remote control service based on the received port information and the remote control service activation command (step S335).
[0061] For example, the second terminal 20 modifies registry information or port setting information so that a remote control protocol connection is made to the port number corresponding to the received port information. The second terminal 20 also sets a remote control service-related policy in the firewall to allow communication related to the remote control service to the IP address and port number of the first terminal 10. Then, the remote control service (e.g., remote desktop service) of the second terminal 20 is executed, thereby activating the remote control service of the second terminal 20.
[0062] Meanwhile, the security policy server 30 transmits the second terminal connection information including the generated port information to the first terminal 10 (step S340).
[0063] The first terminal 10 connects to the second terminal 20 based on the received second terminal connection information (step S345), and if the connection is successful, a remote control service between the first terminal 10 and the second terminal 20 is provided (step S350).
[0064] For example, the second terminal connection information includes the generated port information and IP address information of the second terminal 20.
[0065] Based on the received second terminal connection information, the first terminal 10 transmits a connection request to the second terminal 20 to a port number corresponding to the port information. When the second terminal 20 receives the connection request from the first terminal 10 through the port number, the second terminal 20 permits the connection. According to an embodiment, when the connection request is received, the second terminal 20 may permit the connection after checking the IP address of the first terminal 10.
[0066] As the first terminal 10 connects to the second terminal 20, a remote control service is provided, and the first terminal 10 receives and outputs data corresponding to the screen and / or sound to be output through the output unit 230 of the second terminal 20, and transmits user input received through the input unit 220 of the first terminal 10 to the second terminal 20.
[0067] Meanwhile, referring to FIG. 4, the first terminal 10 receives a request to terminate the remote control service (step S400), and terminates the connection to the second terminal 20 in response to the received request (step S410).
[0068] After finishing using the remote control service, the user of the first terminal 10 inputs a request to terminate the execution of the remote control application program 254 or a request to terminate the connection with the second terminal 20 through the input unit 220. That is, the first terminal 10 receives a remote control service termination request corresponding to the execution termination request or the connection termination request through the input unit 220.
[0069] In response to the received remote control service termination request, the first terminal 10 terminates the connection to the second terminal 20. For example, the security control application 252 of the first terminal 10 detects the termination of the remote control service by detecting the termination of the remote control application program 254 or by monitoring communication on a port used during the provision of the remote control service and detecting the termination of communication. After detecting the termination of the remote control service, the first terminal 10 transmits connection termination information to the security policy server 30. The connection termination information includes information about the second terminal 20, which is a remote terminal.
[0070] According to an embodiment, the remote control service termination request is received by the second terminal 20, and the second terminal 20 transmits connection termination information to the security policy server 30, similar to the operation of the first terminal 10 described above.
[0071] When the first terminal 10 (or the second terminal 20) terminates the connection in response to the remote control service termination request, it transmits information notifying the termination of the connection (connection termination information) to the security policy server 30 (step S420). In response to the received connection termination information, the security policy server 30 transmits a remote control service deactivation command to the second terminal 20 (step S430), and the second terminal 20 deactivates the remote control service in response to the received command (step S440).
[0072] In response to the received command, the second terminal 20 suspends the service for operating the remote control protocol by modifying registry information or port setting information to cancel communication permission for the port used to provide the remote control service in the embodiment of FIG. 3. Alternatively, the second terminal 20 deletes the firewall policy set to permit communication related to the remote control service. Alternatively, the second terminal 20 again blocks execution of the remote control application program process (e.g., mstsc.exe). By performing at least one of the above operations, the second terminal 20 deactivates the remote control service.
[0073] 3 and 4, the second terminal 20 (remote terminal) can effectively block connections of other terminals by basically deactivating the remote control service, and can provide a smooth remote control service by activating the remote control service when the first terminal 10 (client terminal) of an authorized user attempts to connect. Thus, unauthorized users or terminals can be effectively prevented from connecting to the remote terminal through the remote control application program and remote control protocol, thereby providing a remote control service with improved security.
[0074] FIG. 5 is a diagram illustrating a telework system using a virtual private network as an example of a system in which a method for improving security of a remote control service according to an embodiment of the present invention is implemented.
[0075] Recently, with the development of communication and cloud computing technology, and the COVID-19 pandemic creating a non-face-to-face society, the proportion of people working in various locations, not just in the office, i.e., teleworking (working from a remote location) is increasing. This teleworking system refers to a system in which, when workers are not in the office, they cannot use the terminal device 630 on the company network 600, so they use a terminal device 500 such as a desktop computer or laptop computer in a remote location (such as at home) to connect to a data management system 620 on the company network 600 and work.
[0076] Only authorized users' terminals 500 should be able to connect to the company network 600. To this end, external terminals connect to the company network 600 via a virtual private network (VPN) 800 or a dedicated private network. Because a dedicated private network is inefficient in terms of cost, most telework systems adopt a VPN connection method by providing the company network 600 with VPN equipment (e.g., a VPN gateway 610). The authorized user's terminal 500 corresponds to a VPN client that is equipped with a VPN application for connecting to the VPN gateway 610 of the company network 600. The terminal 500 requests connection to the company network 600 using an IP address assigned by executing the VPN application, and the VPN gateway 610 of the company network 600 permits or denies the connection based on the IP address included in the connection request.
[0077] Meanwhile, the internal company network 600 is generally equipped with high-level security management solutions (such as data loss prevention (DLP) and digital rights management (DRM)) to prevent various security threats, such as data leakage and hacking. However, the security management level for external terminals 500, such as home PCs, is relatively low compared to the internal company network 600. Therefore, an attacker may exploit security vulnerabilities in the terminals 500 to launch cyber attacks on the internal company network 600 through the terminals 500 and VPN 800. Furthermore, when the terminal 500 connects to the terminal 630 of the internal company network 600 through a remote control service, a security vulnerability in the remote control application program may cause a security problem in the internal company network 600.
[0078] Therefore, the terminal 500, the terminal 630 of the internal network 600, and the security policy server 700 can effectively improve the security of the internal network 600 by providing the remote control service with improved security as described above in Figures 3 and 4. The present invention can be embodied as computer-readable code on a recording medium having a program recorded thereon. Computer-readable recording media include all recording devices that store data readable by a computer system. Examples of computer-readable media include HDDs, SSDs, SDDs (Silicon Disk Drives), ROMs, RAMs, CD-ROMs, magnetic tapes, floppy disks, and optical data storage devices. Therefore, the above detailed description should not be construed as limiting, but should be considered as illustrative. The scope of the present invention should be determined by reasonable interpretation of the appended claims, and all modifications within the scope of the present invention are encompassed within the scope of the present invention. [Explanation of symbols]
[0079] 10, 20, 500, 630 Terminal 1 30,300,700 Security Policy Servers 200 equipment 210 Communications Department 220 Input section 230 Output section 240 Control Unit 250 storage unit (memory) 252 Security Control Applications 254 Remote Control Application Program 600 Internal network 610 VPN Gateway 620 Data Management System
Claims
1. a security policy server connected to the client terminal and the remote terminal, respectively, receiving identification information from the client terminal that has received a request for providing a remote control service; a step of the security policy server identifying the remote terminal corresponding to the client terminal based on the received identification information, the remote terminal being in a state where a remote control service is deactivated, the deactivation of the remote control service being performed by interrupting a service for driving a remote control protocol or by interrupting execution of a remote control application program process; the security policy server receiving information about a currently unused port number from the identified remote terminal, and generating port information for connecting the client terminal to the identified remote terminal based on the received information; the security policy server transmitting the generated port information and a remote control service activation command to the identified remote terminal; the security policy server transmitting remote terminal connection information including the port information to the client terminal; providing a remote control service based on the connection between the client terminal and the remote terminal; A control method for improving security of a remote control service, comprising:
2. The identification information includes at least one unique information related to the client terminal or the user. The control method for improving security of a remote control service according to claim 1.
3. The step of identifying a remote terminal corresponding to the client terminal comprises: identifying a remote terminal having information that matches or corresponds to unique information in the identification information received from the client terminal among service authentication information stored in each of a plurality of remote terminals as a remote terminal corresponding to the client terminal; The control method for improving security of a remote control service according to claim 2.
4. The step of generating port information includes: randomly selecting one of the port numbers that are not in use by the remote terminal; generating the port number including any one of the randomly selected port numbers; The control method for improving security of a remote control service according to claim 1.
5. further comprising activating a remote control service of the remote terminal in response to the port information and a remote control service activation command; The activating step includes: modifying registry information or port setting information so that the remote terminal can connect to the client terminal through a port number corresponding to the port information; and setting a firewall policy to allow communication related to the remote control service to the port number. The control method for improving security of a remote control service according to claim 1.
6. The method further includes connecting the client terminal to the remote terminal based on the remote terminal connection information; The connecting step includes: the client terminal drives a remote control application program based on the port information included in the remote terminal connection information; The control method for improving security of a remote control service according to claim 5.
7. transmitting the generated port information and the remote control service activation command to the identified remote terminal; transmitting the port information, a remote control service activation command, and IP address information of the client terminal to the remote terminal; The step of the client terminal connecting to the remote terminal comprises: and when it is confirmed by a remote control application program of the remote terminal that the IP address of the client terminal matches the received IP address information in response to the connection request, the client terminal connects to the remote terminal. The control method for improving security of a remote control service according to claim 6.
8. detecting the termination of the remote control service; transmitting connection termination information based on the detection result to a security policy server; The step of detecting the end of the remote control service includes: detecting the termination of a remote control application program related to the remote control service; or detecting the end of communication at a port corresponding to the port information; The control method for improving security of a remote control service according to claim 1.
9. the security policy server transmitting a remote control service deactivation command to the remote terminal in response to the received connection termination information; and the remote terminal deactivating the remote control service in response to the received remote control service deactivation command. The control method for improving security of a remote control service according to claim 8.
10. The step of deactivating the remote control service includes: modifying registry information or port setting information so as to cancel communication permission for the port corresponding to the port information; deleting a firewall policy that is set to allow communication related to the remote control service to the port number corresponding to the port information; and blocking the execution of a process of the application program related to the remote control service. The control method for improving security of a remote control service according to claim 9.
11. A computer program stored on a computer-readable recording medium for causing a computer that is hardware to perform the method of claim 1.
Citation Information
Patent Citations
Communication method and communication system using internet protocol
JP2005080255A
Remote service execution method, remote client, and remote service server
JP2005242547A
Operation history accumulation system, method, and program
JP2006350854A
Access control system and access control server
JP2008015786A
Connection control method, communication system and terminal
JP2009277024A