Information processing equipment and communication systems
The information processing device allows secure, remote configuration of communication settings by constructing a virtual unit based on network changes, addressing inefficiencies and ensuring system availability.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- KK TOSHIBA
- Filing Date
- 2022-11-21
- Publication Date
- 2026-04-13
AI Technical Summary
Conventional information processing devices require on-site visits for network setting changes and cannot reliably perform remote configuration, leading to inefficiencies and potential communication disruptions.
An information processing device with a communication unit and control unit that receives setting changes via a network, constructs a virtual communication unit, and reflects settings only if communication with a management device is successful, ensuring secure and remote configuration.
Enables secure and efficient remote configuration of communication settings without disrupting existing systems, enhancing security and reducing the need for on-site visits.
Smart Images

Figure 0007844317000001 
Figure 0007844317000002 
Figure 0007844317000003
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to an information processing apparatus and a communication system.
Background Art
[0002] In recent years, systems that connect various devices to a network using IoT technology have been proposed. For example, communication systems have been proposed to realize preventive maintenance that detects signs of failure in advance and efficient operation of equipment by collecting various operation data during operation and inspection in factories, power plants, railways, etc. and analyzing them with AI (artificial intelligence).
[0003] In order to newly construct such a communication system, since it is necessary to collect various data via a network, there may be a need to connect a system that has been operating in an existing proprietary network to an open network. When connecting a system that has been operating in an existing proprietary network to an open network, in order to deal with unauthorized access, it is conceivable to strengthen security by incorporating security measures into the device itself that newly connects to the open network. However, making changes to existing devices that are already in operation often makes it difficult to implement in terms of cost and availability because it may be necessary to replace the device itself.
[0004] Conventionally, in order to ensure the confidentiality and integrity of a communication path without modifying existing devices, an information processing apparatus connected between an existing device and a network has been developed. Such an information processing apparatus has a function of blocking the communication of an attacker when it detects an attack on the device or a virus infection by observing the behavior of communication in the device.
[0005] However, conventional information processing devices cannot change network settings from a communication management device over a network. Therefore, conventional information processing devices require on-site visits every time network settings are changed, which is time-consuming. Furthermore, if the information processing device changes network settings based on configuration information received from the management system via the network, there is a problem in that if there is a problem with the network settings, communication between the information processing device and the management system will become completely impossible. [Prior art documents] [Patent Documents]
[0006] [Patent Document 1] Japanese Patent Publication No. 2019-50485 [Overview of the project] [Problems that the invention aims to solve]
[0007] The problem that this invention aims to solve is to provide an information processing device and a communication system that can reliably perform changes to communication settings remotely. [Means for solving the problem]
[0008] According to the embodiment, the information processing device has a communication unit and a control unit. The communication unit communicates with a communication management device via a network. The control unit receives information from the communication management device via the communication unit regarding changes to the settings of the communication unit. A virtual communication unit is constructed based on the aforementioned change information, and if communication between the virtual communication unit and the communication management device is successful, the settings of the virtual communication unit are reflected in the communication unit. . [Brief explanation of the drawing]
[0009] [Figure 1] Figure 1 shows an example of the configuration of a communication system according to an embodiment. [Figure 2] Figure 2 is a block diagram showing an example configuration of an information processing device in a communication system according to the embodiment. [Figure 3] Figure 3 is a block diagram showing an example of the configuration of an IC card to be installed in an information processing device according to this embodiment. [Figure 4] Figure 4 shows an example of the hardware configuration of an IC card as an example of the functional configuration of an IC card attached to an information processing device according to the embodiment. [Figure 5] Figure 5 is a block diagram showing an example of the functional configuration of a C card as an example of the configuration of the authentication unit in a communication control device according to the embodiment. [Figure 6] Figure 6 is a sequence illustrating the flow of communication control between an IoT device (terminal device) and a server device in a communication system according to this embodiment. [Figure 7] Figure 7 is a flowchart illustrating the first setting change process performed by the information processing device of the communication system according to the embodiment. [Figure 8] Figure 8 is a diagram illustrating the overview of the second setting change process performed by the information processing device of the communication system according to the embodiment. [Figure 9] Figure 9 is a flowchart illustrating the second setting change process performed by the information processing device of the communication system according to the embodiment. [Figure 10] Figure 10 is a diagram illustrating another example of the configuration of the communication system according to the embodiment. [Modes for carrying out the invention]
[0010] The embodiments will be described below with reference to the drawings. Figure 1 shows an example of the configuration of a communication system having an information processing device 13 according to an embodiment. The communication system 1 comprises an IoT device (terminal device) 11 (11), a server device 12, an information processing device 13 (13A, 13B), a communication management device 14, and a gateway 17. In the configuration example shown in Figure 1, the gateway 17 and the network 18 are collectively referred to as the network NW.
[0011] In communication system 1, each information processing device 13 is expected to be connected to an existing communication system. That is, each information processing device 13 is connected to an existing system that includes an IoT device 11, a server device 12, a communication management device 14, and a gateway 17, at the location shown in Figure 1.
[0012] Each information processing device 13 is installed to construct a communication system 1 while maintaining availability without changing the configuration of each device in the existing system. As shown in Figure 1, the information processing device 13 has a first port (e.g., a first LAN port) 21 and a second port (e.g., a second LAN port) 22 for connecting to the communication path in the existing system. For example, the information processing device 13 is connected between the IoT device 11 and the gateway 17 by connecting the first port 21A to the gateway 17 and the second port 22A to the IoT device 11.
[0013] Each IoT device 11 connects to the network NW via the device-side information processing device 13A to which it is connected. The server device 12 connects to the network NW via the server-side information processing device 13B. In other words, each IoT device 11 and the server device 12 are configured to communicate via the information processing device 13 and network NW to which they are connected.
[0014] The IoT device 11 is a device (terminal device, client terminal) that acquires various types of data. For example, the IoT device 11 may be a device that acquires data using sensors, or a device that acquires data input by an operator. The IoT device 11 transmits the acquired data to the server device 12. The IoT device 11 may also have a function to control its operation according to the control information of the server device 12.
[0015] The server device 12 collects the data acquired by the IoT device 11. For example, the server device 12 manages and analyzes the data collected from each IoT device 11. Also, the server device 12 may transmit control information to the IoT device 11.
[0016] The information processing device 13A on the device side is connected between the IoT device 11 and the gateway 17 of the network NW. The information processing device 13A has a first port 21A as an interface connection part on the network NW side and a second port 22A as an interface connection part on the device side, respectively. The first port 21A and the second port 22A are, for example, LAN ports. In the configuration example shown in FIG. 1, the gateway 17 is connected to the first port 21A, and the IoT device 11A is connected to the second port 22A, respectively.
[0017] The information processing device 13A on the device side mediates communication between the IoT device 11 and the server device 12. The information processing device 13A acquires the data transmitted from the IoT device 11 to the server device 12 and outputs the acquired data to the server device 12. Here, when the information processing device 13A transmits data to the server device 12, the data acquired from the IoT device 11 is encrypted, and the encrypted data is transmitted to the server device 12.
[0018] Also, the information processing device 13A acquires the data transmitted from the server device 12 to the IoT device 11 and outputs the acquired data to the IoT device 11. Here, the data acquired by the information processing device 13A is encrypted data. When the information processing device 13A outputs data to the IoT device 11, the data acquired from the server device 12 via the information processing device 13B on the server side is decrypted, and the decrypted data is output to the IoT device 11.
[0019] Furthermore, the device-side information processing device 13A may be configured to communicate with other device-side information processing devices 13A via the gateway 17. In this case, each device-side information processing device 13A may be configured to allow or disallow communication with other device-side information processing devices 13A according to the communication permission settings set for each device.
[0020] The server-side information processing device 13B is connected between the server device 12 and the network NW. The server-side information processing device 13B has a first port 21B as an interface connection part on the network NW side and a second port 22B as an interface connection part on the server side. The network 18 is connected to the first port 21B, and the server device 12 is connected to the second port 22B.
[0021] The server-side information processing device 13B mediates communication between each IoT device 11 and the server device 12. The server-side information processing device 13B acquires the data transmitted from the server device 12 to the IoT devices 11 and transmits the acquired data to the IoT devices 11. Here, when transmitting data to the IoT devices 11, the server-side information processing device 13B encrypts the data acquired from the server device 12 and transmits the encrypted data to the IoT devices 11.
[0022] Furthermore, the server-side information processing unit 13B acquires data transmitted to the server device 12 by the IoT device 11 and outputs the acquired data to the server device 12. Here, the data acquired by the server-side information processing unit 13B is encrypted data. When outputting data to the server device 12, the server-side information processing unit 13B decrypts the data acquired from the IoT device 11 via the device-side information processing unit 13A and outputs the decrypted data to the server device 12.
[0023] Each information processing device 13 (13A, 13B) performs encryption using, for example, the SSL (Secure Socket Layer) / TLS (Transport Layer Security) protocol. The device-side information processing device 13A and the server-side information processing device 13B, for example, combine the SSL / TLS protocol with HTTP (Hypertext Transfer Protocol) to encrypt the data contained in HTTP and replace it with HTTPS (HTTP Secure), which has improved security.
[0024] Furthermore, the data encryption performed by the device-side information processing unit 13A and the server-side information processing unit 13B is not limited to replacing HTTP with HTTPS. The device-side information processing unit 13A and the server-side information processing unit 13B may replace the SSL / TLS protocol with a secure communication protocol that enhances security by combining it with various communication protocols. For example, the device-side information processing unit 13A and the server-side information processing unit 13B may replace FTP (File Transfer Protocol) with FTPS (FTP Secure).
[0025] In communication system 1, encrypted data is output to the network NW by the information processing device 13A on the device side or the information processing device 13B on the server side. In other words, the data flowing through the network NW in communication system 1 is encrypted data. Therefore, the risk of malicious external access to the data transmitted and received on the network NW and the data being intercepted is avoided, thereby improving security. Note that "data interception" here refers to "the act of secretly viewing data" or "the act of extracting data."
[0026] The communication management device 14 is a server device for managing communication between the device-side information processing device 13A and the server-side information processing device 13B. For example, the communication management device 14 also functions as a private certification authority. The communication management device 14 issues client certificates and private keys to each information processing device 13.
[0027] In the configuration example shown in Figure 1, the communication management device 14 issues a client certificate and a private key to be stored on an IC card inserted into the information processing device 13. When an IC card equipped with an authentication unit and a secure storage unit is inserted into the information processing device 13A on the device side, the communication management device 14 transmits the client certificate and private key to be stored on the IC card to the information processing device 13A via the network NW.
[0028] Furthermore, the communication management device 14 issues a server certificate and a private key to the server-side information processing device 13B. When an IC card equipped with an authentication unit and a secure storage unit is installed in the server-side information processing device 13B, the communication management device 14 transmits the server certificate and private key to be stored on the IC card to the server-side information processing device 13B via the network NW. The client certificate, server certificate, and private key are all pieces of information necessary to determine the common key (session key) used when the device-side information processing device 13A and the server-side information processing device 13B perform encrypted communication.
[0029] Here, we will describe examples of IoT devices 11 and server devices 12. The IoT device 11 and the server device 12 are, for example, components that make up a social infrastructure system. Social infrastructure refers to the facilities necessary to maintain social infrastructure such as road networks, power generation facilities, power transmission facilities, water treatment facilities, or gas distribution facilities. A social infrastructure system is, for example, a mechanism that monitors social infrastructure, understands changes in its condition, and responds to those changes to ensure the stable operation of social infrastructure.
[0030] As a specific example, in a monitoring system that uses video to monitor roads and public facilities, the IoT device 11 is a device (network surveillance camera) that transmits image data captured to monitor road conditions, etc., via a network NW, and the server device 12 is a device that receives the image data transmitted by the IoT device 11 via the network NW. Furthermore, the IoT device 11 and server device 12 may be components of a system that monitors power status in power generation facilities or power transmission facilities. Also, the IoT device 11 and server device 12 may be components of a system that acquires delivery status at a logistics center. Finally, the IoT device 11 and server device 12 may be components of a system that acquires the operating status of equipment in factories or research institutions.
[0031] It should be noted that social infrastructure systems such as surveillance systems and monitoring systems are examples of communication systems that use IoT devices 11 and server equipment 12 as components, and the IoT devices 11 and server equipment 12 are not limited to components of social infrastructure systems.
[0032] The IoT device 11 includes a network (NW) communication unit, a device control unit, and a data acquisition unit. The network communication unit is a communication interface for data communication. The network communication unit is a communication interface such as Ethernet® that enables communication with external devices via a network. In other words, the IoT device 11 is a device configured to communicate with devices connected to a network via the network communication unit.
[0033] In the communication system 1 according to this embodiment, the NW communication unit of the IoT device 11 is connected to the information processing device 13, and communicates with the server device 12 which is connected to the network NW via the information processing device 13. In other words, the communication system 1 according to this embodiment is a system that can be constructed by retrofitting an existing system in which the IoT device 11 and the server device 12 are configured to communicate via a network, by connecting the information processing device 13A between the IoT device 11 and the network NW, and connecting the information processing device 13B between the server device 12 and the network NW.
[0034] The device control unit is, for example, a processor including a CPU, and comprehensively controls the IoT device 11. The device control unit, for example, starts or stops data acquisition by the data acquisition unit, and performs operation settings for the data acquisition unit, according to control from the server device 12. The data acquisition unit acquires data by operating according to the instructions of the device control unit and outputs the acquired data to the control unit. The device control unit transmits (outputs) the data acquired by the data acquisition unit via the network communication unit.
[0035] In the communication system 1 according to this embodiment, the NW communication unit of the IoT device 11 is connected to the information processing device 13. Therefore, each IoT device 11 performs data input and output via the information processing device 13. For example, the IoT device 11 communicates with the server device 12 via the device-side information processing device 13A, the network NW, and the server-side information processing device 13B.
[0036] The server device 12 includes a network (NW) communication unit, a server control unit, and a data storage unit. The network communication unit is a communication interface for data communication. The network communication unit is a communication interface such as Ethernet (registered trademark) that enables communication with external devices via a network. In other words, the server device 12 is a device configured to communicate with devices connected to a network via the network communication unit.
[0037] In the communication system 1 according to this embodiment, the NW communication unit of the server device 12 is connected to the information processing device 13B, and is configured to communicate with devices connected to the network NW via the information processing device 13B. In other words, the communication system 1 according to this embodiment is a system that can be constructed by retrofitting an existing system in which the IoT device 11 and the server device 12 are configured to communicate via a network, by connecting the information processing device 13B between the server device 12 and the network.
[0038] The server control unit is, for example, a processor including a CPU, and comprehensively controls the server equipment. The server control unit acquires data from each IoT device 11 via the network communication unit and stores the acquired data in the data storage unit. The data storage unit stores the acquired data from the IoT devices 11 according to the instructions of the server control unit. The server control unit also outputs control commands, such as operation instructions, to each IoT device 11 communicating via the network communication unit.
[0039] Next, we will describe the communication between the IoT device 11 and the server device 12. Generally, when IoT devices with communication capabilities (client terminals, communication devices) and server equipment are connected via their respective network communication sections and networks, the common communication protocol HTTP is often used for communication between the IoT devices and the server equipment. In this case, unencrypted information (so-called plaintext) output to the network by the communication device or server equipment flows through the network. In this situation, if data on the network is obtained maliciously from an external source, there is a risk that the data can be easily intercepted or tampered with. As a countermeasure against such malicious attacks, it is conceivable for communication devices to encrypt the data before outputting it to the network.
[0040] However, existing IoT devices (client terminals) used in existing systems often lack the resources necessary for encryption processing. For example, a surveillance camera, a typical IoT device, has a CPU or other processor for compressing and encoding image data, but often lacks the resources to perform encryption processing. Therefore, in order to encrypt the data that IoT devices output to the network in existing systems, it may be necessary to install an additional processor for data encryption in the IoT device, potentially requiring changes or replacements to the hardware configuration of the IoT device. Existing IoT devices, as components of social infrastructure systems such as surveillance systems, cannot be easily modified or replaced in terms of hardware configuration.
[0041] Considering the circumstances described above, a communication system is desirable that can be configured to encrypt and transmit data from IoT devices to the network NW without making any changes to existing IoT devices. The communication system 1 according to this embodiment can securely transmit data by connecting an information processing device to existing IoT devices and server equipment without changing the hardware configuration of existing IoT devices in existing systems or replacing existing IoT devices with new IoT devices.
[0042] In other words, in the communication system 1, the information processing device 13 connected between the IoT device 11 and the network NW encrypts the data that the IoT device 11 sends to the server device 12 and outputs it to the network NW. Also, in the communication system 1, the server-side information processing device 13B connected between the server device 12 and the network NW encrypts data such as control data from the server device 12 to the IoT device 11 and outputs it to the network NW. As a result, according to the communication system 1 of this embodiment, the security of data flowing through the network NW can be improved without changing the IoT device 11 and the server device 12.
[0043] Next, the configuration of the information processing device 13 (13A, 13B) according to this embodiment will be described. Figure 2 is a block diagram showing an example configuration of the information processing device 13 (13A, 13B) shown in Figure 1. As shown in Figure 2, the information processing device 13 (13A, 13B) comprises a control unit 30, a first communication unit 31, a second communication unit 32, a reader / writer 33, an IC card 34, and a storage unit 35. Here, the reader / writer 33 and the IC card 34 are examples of an "authentication unit". The authentication unit is not limited to being implemented by the reader / writer 33 and the IC card 34. The authentication unit may be implemented by the control unit 30, or by a processing circuit for authentication processing.
[0044] The control unit 30 has a processor, such as a CPU. The control unit 30 comprehensively controls the information processing devices 13 (13A, 13B). The control unit 30 sends commands to the IC card 34 via the reader / writer 33 and receives responses from the IC card 34. The control unit 30 also sends information based on the responses received from the IC card 34 to the other information processing devices 13 (13A, 13B) via the first communication unit 31. The control unit 30 also sends commands to the IC card 34 based on information received from the other information processing devices 13 (13A, 13B) via the first communication unit 31.
[0045] The storage unit 35 stores data. The storage unit 35 is composed of a storage device that allows data to be written to and rewritten. The storage unit 35 has a temporary storage unit 35a such as RAM (Random Access Memory). The storage unit 35 may also include a non-volatile storage device that allows data to be rewritten.
[0046] The first communication unit 31 is a network communication unit for communicating with each device connected via the network NW. The first communication unit 31 is equipped with first ports 21 (21A, 21B) connected to the network NW. The first communication unit 31 is configured, for example, by a NIC (Network Interface Card). For example, the information processing device 13A communicates with the communication management device 14 or with the server-side information processing device 13B via the network NW using the first communication unit 31.
[0047] Specifically, the first communication unit 31 of the device-side information processing device 13A acquires data from the gateway 17 connected to the first port 21A, encrypts the data destined for the server device 12, and outputs it to the network 18 via the gateway 17. In addition, the first communication unit 31 of the server-side information processing device 13B acquires encrypted data from the network 18 connected to the first port 21B, decrypts the acquired data, and outputs it to the server device 12.
[0048] The second communication unit 32 is a device communication unit for communicating with an IoT device 11 or a server device 12 acting as a terminal device. The second communication unit 32 includes a second port 22 (22A, 22B) connected to the terminal device (IoT device 11 or server device 12) that performs the communication. For example, the second communication unit 32 is configured as a NIC (Network Interface Card).
[0049] Specifically, the second communication unit 32 of the device-side information processing device 13A acquires imaging data from the camera, which is an IoT device 11 connected to the second port 22A, and outputs the decoded control data to the IoT device 11. In addition, the second communication unit 32 of the server-side information processing device 13B acquires control data from the server device 12 connected to the second port 22B, and outputs the decoded imaging data to the server device 12.
[0050] Furthermore, the information processing device 13 according to this embodiment may enable communication between the IoT device 11 and the second communication unit 32 after it has been confirmed that the communication permission setting by the communication management device 14 has become effective. That is, the first communication unit 31 is linked up to communicate with the communication management device 14 via the network NW. The second communication unit 32 may be linked up to the IoT device 11 via the second port 22A after it has been confirmed that the first communication unit 31 has linked up to the communication management device 14 via the network NW and that the communication permission setting in the information processing device 13A has become effective.
[0051] The reader / writer 33 communicates with the IC card 34. The reader / writer 33 has an interface that corresponds to the communication method of the IC card 34. If the IC card 34 is a contact-type IC card, the reader / writer 33 has an interface that connects to the contact portion of the IC card 34, as shown in Figure 2, and transmits and receives data via the interface.
[0052] The IC card 34 is formed, for example, by mounting an IC module 40 on a plastic card base material. The IC card 34 comprises the IC module 40 and a card base material (body) in which the IC module 40 is embedded. In the configuration example shown in Figure 2, the IC card 34 is configured to be detachably attached to the reader / writer 33 of the information processing device 13 (13A, 13B). The IC card 34 communicates with the information processing device 13 (13A, 13B) via the contact portion 41 while attached to the reader / writer 33.
[0053] The IC card 34 receives, for example, a command (processing request) transmitted by the information processing device 13 (13A, 13B) via the contact unit 41 and executes processing (command processing) according to the received command. The IC card 34 transmits a response (processing response), which is the result of executing the command processing, to the information processing device 13 (13A, 13B) via the contact unit 41.
[0054] The IC module 40 comprises a contact section 41 and an IC chip 42. The contact section 41 has terminals for various signals necessary for the operation of the IC card 34. These terminals include terminals for receiving power supply voltage, clock signal, reset signal, etc., from the information processing device 13 (13A, 13B), and serial data input / output terminals (SIO terminals) for communicating with the information processing device 13 (13A, 13B). The IC chip 42 is, for example, a Large Scale Integration (LSI) such as a single-chip microprocessor.
[0055] Here, we will describe the hardware configuration of an IC card 34 as an example of the configuration of the authentication unit included in the information processing device 13 according to the embodiment. Figure 3 shows an example of the hardware configuration of the IC card 34 shown in Figure 2. The IC card 34 has an IC module 40 comprising a contact section 41 and an IC chip 42. As shown in Figure 3, the IC chip 42 includes a UART (Universal Asynchronous Receipt Transmitter) 43, a CPU 44, a ROM (Read Only Memory) 45, a RAM (Random Access Memory) 46, and an EEPROM (Registered Trademark) (Electrically Erasable Programmable ROM) 47. Furthermore, each component (43 to 47) is connected via an internal bus BS.
[0056] UART43 communicates serial data with the information processing unit 13 (13A, 13B) via the SIO terminal described above. UART43 outputs the serial data signal received via the SIO terminal to the internal bus BS after converting it to parallel data (for example, 1 byte of data). UART43 also converts the data acquired via the internal bus BS to serial data and outputs it to the information processing unit 13 (13A, 13B) via the SIO terminal. For example, UART43 receives commands from the information processing unit 13 (13A, 13B) via the SIO terminal. UART43 also sends responses to the information processing unit 13 (13A, 13B) via the SIO terminal.
[0057] The CPU 44 executes programs stored in the ROM 45 or EEPROM 47 to perform various operations on the IC card 34. For example, the CPU 44 executes command processing in response to commands received by the UART 43 via the contact section 41.
[0058] ROM 45 is a non-volatile memory, such as a mask ROM, and stores data such as programs for executing various processes of the IC card 34 and command tables. RAM 46 is a volatile memory, such as a static RAM (SRAM), and temporarily stores data used when performing various processes of the IC card 34. EEPROM 47 is a non-volatile memory that can be electrically rewritable, such as an EEPROM 47. EEPROM 47 stores various data used by the IC card 34. EEPROM 47 also stores information used by various services (applications) that utilize the IC card 34.
[0059] Next, we will describe the functions of an IC card 34, which is an example of the configuration of the authentication unit in the information processing device 13 according to this embodiment. Figure 4 is a block diagram showing an example of the functional configuration of the IC card 34 shown in Figure 3. The IC card 34 comprises a communication unit 50, a control unit 51, and a storage unit 54. Here, each part of the IC card 34 shown in Figure 4 is implemented using the hardware of the IC card 34 shown in Figure 3.
[0060] The communication unit 50 transmits and receives commands and responses to the information processing devices 13 (13A, 13B) via the contact unit 41. The communication unit 50 is a function that uses the UART 43 to transmit and receive data by having the CPU 44 execute a program stored in the ROM 45. The communication unit 50 receives commands (processing requests) from the information processing devices 13 (13A, 13B) that request predetermined processing, and transmits responses (processing responses) to the commands to the information processing devices 13 (13A, 13B). The communication unit 50 stores the received data received from the information processing devices 13 (13A, 13B) via the UART 43 in the RAM 46. The communication unit 50 also transmits the transmission data stored in the RAM 46 to the information processing devices 13 (13A, 13B) via the UART 43.
[0061] The control unit 51 controls the operation of the IC card 34. The control unit 51 is implemented by a CPU 44, RAM 45, and ROM 46 or EEPROM 47. The control unit 51 includes a command processing unit 52 and an encryption / decryption unit 53. Here, the processing performed by the command processing unit 52 is an example of "authentication processing". Also, the processing performed by the encryption / decryption unit 53 is an example of "encryption / decryption processing".
[0062] The command processing unit 52 executes various command processes. For example, the command processing unit 52 performs an SSL / TLS handshake as a command process to request an HTTPS request, which will be described later. The SSL / TLS handshake involves the exchange of key information and other information necessary for encrypted communication, and mutual authentication with the communication destination device. Here, mutual authentication is the process by which the information processing unit 13A on the device side and the information processing unit 13B on the server side confirm to each other that they are legitimately authenticated devices before they communicate.
[0063] The encryption / decryption unit 53 performs the process of encrypting data and the process of decrypting encrypted data. The encryption / decryption unit 53 encrypts data output by a device (IoT device 11 or server device 12) acquired via the communication unit 50. The encryption / decryption unit 53 also decrypts encrypted data from the network NW acquired via the communication unit 50.
[0064] The storage unit 54 stores data. The storage unit 54 is implemented by an EEPROM 47 under the control of the control unit 51, which performs data reading and writing. The storage unit 54 has a certificate information storage unit 55 and a secret information storage unit 56. The certificate information storage unit 55 stores certificates issued by the communication management device 14 for devices (IoT devices 11 or server devices 12). Specifically, the certificate information storage unit 55 of the IC card 34 attached to the information processing device 13 stores information indicating a client certificate. In addition, the certificate information storage unit 55 of the IC card 34 attached to the server-side information processing device 13B stores information indicating a server certificate.
[0065] The secret information storage unit 56 stores the secret key issued by the communication management device 14 for the device (IoT device 11 or server device 12). Specifically, the secret information storage unit 56 of the IC card 34 attached to the information processing device 13 stores information indicating the secret key issued to the information processing device 13. In addition, the certificate information storage unit 55 of the IC card 34 attached to the server-side information processing device 13B stores information indicating the secret key issued to the server-side information processing device 13B.
[0066] Next, the configuration of the communication management device 14 in the communication system 1 according to this embodiment will be described. Figure 5 is a block diagram showing an example configuration of the communication management device 14 shown in Figure 1. The communication management device 14 comprises a network communication unit 60, a control unit 61, and a storage unit 62. The NW communication unit 60 is connected to the network NW and communicates with the information processing devices 13 (13A, 13B) via the network NW.
[0067] The control unit 61 includes, for example, a processor such as a CPU and system memory such as ROM and RAM. The control unit 61 performs various processes by executing programs stored in the system memory or other storage units by the processor. The control unit 61 comprehensively controls the communication management device 14. The control unit 61 manages security information used for communication between the information processing device 13 and other devices. For example, the control unit 61 mainly operates as a private certification authority that verifies the legitimacy of the information processing devices 13 (13A, 13B). In the example shown in Figure 6, the control unit 61 performs processes to realize the functions of a key generation unit 71, a certificate issuance unit 72, a certificate renewal unit 73, a certificate management unit 74, and a management unit 75 by having the processor execute programs.
[0068] The key generation unit 71, for example, issues a private key corresponding to the public key included in the certificate described later, based on an authentication request from the information processing device 13 (13A, 13B).
[0069] The certificate issuing unit 72 issues a certificate recognizing the legitimacy of the information processing device 13 (13A, 13B) based on an authentication request from the information processing device 13 (13A, 13B). The certificate includes, for example, a public key and information indicating the owner of the information processing device 13 (13A, 13B).
[0070] The certificate renewal unit 73 renews certificates by setting a new expiration date for certificates whose expiration date has passed. For example, based on a renewal request from the information processing device 13 (13A, 13B), the certificate renewal unit 73 issues a certificate with an extended expiration date for the certificate issued to the information processing device 13 (13A, 13B), and transmits the issued certificate to the information processing device 13 (13A, 13B). Information indicating the issued certificate is received by the information processing device 13 (13A, 13B), and stored in the certificate information storage unit 55 of the IC card 34 of the information processing device 13 (13A, 13B), thereby extending the expiration date of the certificate in the information processing device 13 (13A, 13B).
[0071] The certificate management unit 74 manages certificates that have already been issued. For example, if the legitimacy of mutual authentication cannot be proven due to tampering with or theft of the IC card 34 installed in the information processing device 13 (13A, 13B), the certificate management unit 74 invalidates the certificate issued to the information processing device 13 (13A, 13B).
[0072] Furthermore, the certificate management unit 74 may respond to inquiries from the information processing devices 13 (13A, 13B) to determine whether the certificates issued to the information processing devices 13 (13A, 13B) and other communication devices were issued by the certificate issuing unit 72. In addition, the certificate management unit 74 may periodically verify whether the issued certificates are being used by legitimate information processing devices 13 (13A, 13B).
[0073] The management unit 75 manages the information processing devices 13 (13A, 13B). For example, the management unit 75 remotely controls the mutual authentication performed by the information processing devices 13 (13A, 13B) via the network NW. The storage unit 62 is composed of, for example, a non-volatile storage device. The storage unit 62 includes a key information storage unit 81, a certificate information storage unit 82, and a communication setting storage unit 83. The key information storage unit 81 stores information indicating, for example, public keys and private keys that have already been issued. The certificate information storage unit 82 stores information indicating certificates that have already been issued. The key information storage unit 81 and the certificate information storage unit 82 are referenced, for example, when the key generation unit 71 issues a private key, or when the certificate issuing unit 72 issues a certificate. The key information storage unit 81 also stores information indicating a private key issued by the key generation unit 71. The certificate information storage unit 82 also stores information indicating a certificate issued by the certificate issuing unit 72.
[0074] The communication setting storage unit 83 stores communication setting information that indicates the communication settings to be applied (set) to the information processing device 13. The communication setting information of the information processing device 13 stored in the communication setting storage unit 83 may include a communication permission setting that specifies whether or not communication with the IoT device 11 as a terminal device is permitted. The control unit 61 may also supply the communication setting information stored in the communication setting storage unit 83 in response to a request from the information processing device 13. For example, the control unit 61 may supply the communication setting information to the information processing device 13 when the information processing device 13 is started up.
[0075] Next, we will describe the communication process between the IoT device 11 and the server device 12 via the information processing devices 13A and 13B in the communication system 1. Figure 6 is a sequence chart showing an example of the processing performed by communication system 1.
[0076] When the IoT device 11 sends data (such as data detected or captured by the IoT device) to the server device 12, it first sends an HTTP request to the server device 12 (step S1). The HTTP request sent by the IoT device 11 is received by the device-side information processing device 13 (13A) (step S2).
[0077] When the device-side information processing unit 13 receives an HTTP request sent by the IoT device 11, it sends an HTTPS request (ClientHello) to the server-side information processing unit 13B (step S3). This initiates a handshake between the device-side information processing unit 13 and the server-side information processing unit 13B (step S4).
[0078] Specifically, the ClientHello sent by the device-side information processing unit 13 includes information such as the TLS version and a list of encryption methods and algorithms to be used for communication. In response to the ClientHello, the server-side information processing unit 13B sends an HTTPS response (ServerHello) to the device-side information processing unit 13. The ServerHello sent by the server-side information processing unit 13B includes information such as the selection made by the server device 12 from the options presented in the ClientHello. In other words, the specific encryption algorithm used in communication is determined by the selection made by the server-side information processing unit 13B in response to the presentation from the device-side information processing unit 13.
[0079] The server-side information processing device 13B then sends the information necessary for the shared key used for encrypted communication. The information necessary for the shared key includes, for example, information indicating the public key and its certificate issued to the server device 12, and information requesting the public key and its certificate of the IoT device 11 to be sent. The device-side information processing device 13A sends the public key and its certificate issued to its own device, as well as the information necessary for the shared key used for encrypted communication, to the server-side information processing device 13B.
[0080] Mutual authentication between the device-side information processing device 13A and the server-side information processing device 13B is performed, for example, as follows: The device-side information processing device 13A generates a signature from ServerHello etc. received so far and sends it to the server-side information processing device 13B. The server-side information processing device 13B verifies the signature received from the device-side information processing device 13A based on the certificate received from the device-side information processing device 13. If the verification is successful, the server-side information processing device 13B determines that the certificate is indeed that of the device-side information processing device 13A. The server-side information processing device 13B also generates a signature from ClientHello etc. received so far and sends it to the device-side information processing device 13A. The device-side information processing device 13A verifies the signature received from the server-side information processing device 13B based on the certificate received from the server-side information processing device 13B. If the verification is successful, the device-side information processing device 13A determines that the certificate is indeed that of the server-side information processing device 13B.
[0081] When mutual authentication between the device-side information processing device 13A and the server-side information processing device 13B is successfully performed, the device-side information processing device 13A and the server-side information processing device 13B each generate and exchange a common key to be used for encryption.
[0082] If the public key and certificate issued to the server device 12, sent from the server-side information processing device 13B, are acceptable certificates to the device-side information processing device 13A, then the server-side information processing device 13B terminates the handshake.
[0083] Once the server-side information processing device 13B establishes a handshake with the device-side information processing device 13A, it sends an HTTP request to the server device 12 (step S5). The HTTP request is the same HTTP request sent from the IoT device 11 in step S1.
[0084] The HTTP request sent by the server-side information processing device 13B is received by the server device 12 (step S6). At this time, the server device 12 recognizes that an HTTP request has been made from the IoT device 11. Therefore, the server device 12 sends an HTTP response to the IoT device 11 (step S7). The HTTP response sent by the server device 12 is acquired by the server-side information processing device 13B (step S8).
[0085] The server-side information processing device 13B encrypts the HTTP response received from the server device 12 using the shared key determined in the handshake in step S4 (step S9). The HTTP response encrypted by the server-side information processing device 13B is received by the device-side information processing device 13A via the network NW (step S10). The device-side information processing device 13A decrypts the received HTTP response using the shared key (step S11). The HTTP response decrypted by the device-side information processing device 13A is received by the IoT device 11 (step S12). The IoT device 11 receives the decrypted HTTP response (step S13). At this time, the IoT device 11 recognizes that an HTTP response has been sent from the server device 12. Therefore, the IoT device 11 sends data to the server device 12 (step S14).
[0086] The imaging data transmitted by the IoT device 11 is acquired by the device-side information processing device 13A (step S15). The device-side information processing device 13A encrypts the data transmitted by the IoT device 11 using a common key (step S16). The data encrypted by the device-side information processing device 13A is received by the server-side information processing device 13B via the network NW (step S17).
[0087] The server-side information processing device 13B decrypts the received data using a shared key (step S18). The data decrypted by the server-side information processing device 13B is acquired by the server device 12 (step S19). The server device 12 receives the decrypted data (step S20). At this time, the server device 12 recognizes that it has received data from the IoT device 11.
[0088] Furthermore, in step S4 of the flowchart above, if mutual authentication between the device-side information processing device 13A and the server-side information processing device 13B is not performed correctly, the device-side information processing device 13A will not permit communication with the communication destination. Specifically, the device-side information processing device 13A will not output the information sent from the communication destination to the IoT device 11. This is because if mutual authentication is not performed correctly, the communication destination may be a fraudulent communication device disguised as the server-side information processing device 13B. In this case, the device-side information processing device 13A may, for example, send a communication record of the case where mutual authentication was not performed correctly to the communication management device 14. Thus, the communication management device 14 can obtain a communication record of the case where mutual authentication was not performed correctly, and by understanding the patterns and frequency of fraudulent communication to the device-side information processing device 13A under its management, it can monitor network abnormalities.
[0089] Furthermore, the device-side information processing device 13A may determine whether or not to permit communication with a communication destination based on a destination list that shows information about communication devices that are permitted to communicate with the IoT device 11, instead of mutual authentication, during the handshake performed in step S4 of the flowchart described above. The information about communication devices shown in the destination list is, for example, a URL (Uniform Resource Locator). The control unit 30 of the device-side information processing device 13A permits communication with the communication destination if the URL of the communication destination is registered in the destination list, and does not permit communication if it is not registered in the destination list.
[0090] Furthermore, the control unit 30 may update the destination list. The control unit 30 stores, for example, the URLs of communication destinations that are permitted to communicate with the IoT device 11 during a certain period, and the URLs of communication destinations that are not permitted. The control unit 30 then updates the destination list by, for example, re-registering the URLs of communication destinations that have been communicated with during a certain period from among the URLs registered in the destination list. Alternatively, the device-side information processing device 13 may send the URLs of communication destinations that are permitted to communicate with during a certain period, and the URLs of communication destinations that are not permitted, to the communication management device 14. In this case, for example, the communication management device 14 may update the destination list based on the URLs of communication destinations that have communicated with the device-side information processing device 13A. By updating the destination list by the communication management device 14, the communication management device 14 can centrally manage the communication devices that communicate with the device-side information processing device 13A under its management.
[0091] Furthermore, the device-side information processing device 13A may verify whether the information sent to the IoT device 11 (for example, a firmware update program) after the handshake performed in step S4 is established is correct. For example, the control unit 30 of the device-side information processing device 13A verifies the firmware update program for the IoT device 11 using a verification key (verification key) when it is sent via the network NW. In this case, the communication management device 14 may, for example, send the verification key to both the device-side information processing device 13A and the server-side information processing device 13B.
[0092] For example, the server-side information processing device 13B generates a hash value from the information (plaintext) to be sent to the IoT device 11, and encrypts the generated hash value with a verification key. Then, the server-side information processing device 13B further encrypts the plaintext and the encrypted hash value with a secret key and sends them to the IoT device 11. The device-side information processing device 13 decrypts the information using a shared key and obtains the plaintext and the encrypted hash value.
[0093] Furthermore, the device-side information processing unit 13A generates a hash value from the acquired plaintext and decrypts the encrypted hash value using a verification key. If the hash value generated from the plaintext and the decrypted hash value are equal, the device-side information processing unit 13A determines that the information sent to the IoT device 11 is correct. In this case, the device-side information processing unit 13A outputs the decrypted information (plaintext) to the IoT device 11. On the other hand, if the hash value generated from the plaintext and the decrypted hash value are not equal, the device-side information processing unit 13A determines that the information sent to the IoT device 11 may be malicious information sent from a malicious communication device disguised as the server device 12 or the server-side information processing unit 13B. In this case, the device-side information processing unit 13A does not output the decrypted information (plaintext) to the IoT device 11.
[0094] As a result, the IoT device 11 can only receive information that has been verified as correct. Furthermore, while it is usually assumed that the IoT device 11 would determine whether the contents of the update program are correct when updating the firmware, by having the server-side information processing device 13B verify the contents of the information sent to the IoT device 11 on behalf of the IoT device 11, the processing burden on the IoT device 11 can be reduced.
[0095] As described above, the communication system 1 comprises a device-side information processing device 13A connected between the IoT device 11 and the network NW, and a server-side information processing device 13B connected between the server device 12 and the network NW. The device-side information processing device 13A encrypts information from the IoT device 11 and transmits it to the server-side information processing device 13B via the network NW, decrypts the information from the network NW (information from the server device 12 encrypted by the information processing device 13B) and transmits it to the IoT device 11. The server-side information processing device 13B encrypts information from the server device 12 and transmits it to the device-side information processing device 13 via the network NW, decrypts the information from the network NW (information from the IoT device encrypted by the device-side information processing device 13A) and transmits it to the server device 12.
[0096] As a result, communication system 1 can improve the security of the social infrastructure system without changing the social infrastructure system itself. This is because HTTP protocol data (so-called plaintext) transmitted from IoT device 11 to server device 12 is replaced by HTTPS, which is more secure, by the device-side information processing device 13, for example, by combining it with the SSL / TLS protocol. Furthermore, although control data transmitted from server device 12 to IoT devices 11 is encrypted, it is decrypted by the device-side information processing device 13 and received by IoT device 11. Therefore, there is no need to perform decryption processing on IoT device 11, and existing equipment can be used as is without modification.
[0097] Furthermore, in communication system 1, the device-side information processing device 13A and the server-side information processing device 13B perform mutual authentication, thus improving security compared to cases where authentication is performed in only one direction. In typical client terminal and server devices, an unspecified number of client terminals communicate with the server device, making it impractical to continuously issue and manage valid client certificates for such a large number of client terminals. However, in social infrastructure systems to which communication systems are applied, the relationship between the IoT device 11 and the server device 12 is clearly defined. Therefore, it is possible for the device-side information processing device 13A and the server-side information processing device 13B to perform mutual authentication, thereby improving security.
[0098] Generally, client terminals without client certificates may be required to enter an ID and password issued by the server device in order to communicate with the server device. In such password authentication, to maintain security, passwords may be required to be long strings of characters and numbers, or users may be required to change their passwords regularly. However, if the number of passwords to remember increases, management becomes troublesome, and passwords may be leaked in the process, such as by writing them down or saving them in a web browser.
[0099] In contrast, in communication system 1, the information processing device 13A on the device side possesses a client (device) certificate, enabling reliable mutual authentication with the server device 12. Therefore, password authentication becomes unnecessary. This eliminates the need to enter passwords and the hassle of regularly changing and managing them, improving user convenience. In short, security can be maintained without burdening the user.
[0100] Furthermore, in systems where client terminals without client certificates communicate with server devices based on authentication using IDs and passwords, anyone who can correctly enter the ID and password can communicate with the server device. This makes it possible to illegally hijack client terminals and gain unauthorized access to server devices. For example, a client terminal may become infected with ransomware, where its functions are restricted by an illegally hijacked server device, and a ransom is demanded to unlock them.
[0101] In contrast, in the aforementioned communication system 1, mutual authentication is performed between the IoT device 11 and the server device 12 via the device-side information processing device 13A and the server-side information processing device 13B, preventing the IoT device 11 and the server device 12 from being illegally hijacked. In other words, communication system 1 also provides protection against ransomware.
[0102] Furthermore, for example, if there is a terminal without an administrator on the network (also known as a rogue device), that terminal may be illegally taken over and used as a malicious terminal to carry out attacks such as malware. In contrast, the communication system 1 described above performs mutual authentication between the IoT device 11 and the server device 12 via the device-side information processing unit 13A (13B, 13C) and the server-side information processing unit 13B. This prevents malware infection even if a terminal without an administrator on the network is illegally taken over and used for attacks.
[0103] Furthermore, in the communication system 1 described above, the server device 12 is connected to the server-side information processing device 13B, and authentication processing is not performed internally by the server device 12. Therefore, there is no need for the server device 12 to store certificates, etc., and it becomes clear that the server device 12, which is connected to the server-side information processing device 13B, is under the management of the communication management device 14. If the server device 12 already has a functional unit equivalent to the server-side information processing device 13B, it is not necessarily required that the server-side information processing device 13B be physically connected between the server device 12 and the network NW. In this case, authentication processing between the server device 12 and the device-side information processing device 13A is performed by the functional unit equivalent to the server-side information processing device 13B that the server device 12 originally possesses.
[0104] Furthermore, in the communication system 1, the IC card 34 is made to perform at least one of either mutual authentication or encryption / decryption processing. This makes it possible to reduce the equipment cost of the information processing device 13 (13A, 13B).
[0105] Furthermore, while the example described for communication system 1 shows that the IC card 34 attached to the information processing device 13 (13A, 13B) performs at least one of mutual authentication and encryption / decryption processing, the configuration of communication system 1 that performs mutual authentication and encryption / decryption processing is not limited to an IC card. Moreover, the IC card 34 described above can be any functional unit having a storage function for storing a private key and a client certificate (or server certificate), and a processing function for performing at least one of mutual authentication and encryption / decryption processing. For example, it could be a SIM card with an IC chip, or it may not even be in the form of a card.
[0106] Furthermore, in communication system 1, the IC card 34 of the information processing device 13 is detachably attached to the information processing device 13. As a result, in communication system 1, the IC card 34 and the information processing device 13 are separable, so if either one needs to be replaced, only that device needs to be replaced. For example, if the IC card 34 and the information processing device 13 were integrated, replacing the part corresponding to the IC card 34 would require replacing the entire information processing device 13. Compared to this case, communication system 1 can reduce maintenance costs when replacing specific parts of the information processing device 13, such as the IC card 34.
[0107] Furthermore, the communication system 1 is further equipped with a communication management device 14. The communication management device 14 transmits a private key and a client certificate to be stored on an IC card 34 attached to the information processing device 13, and transmits a private key and a server certificate to be stored on an IC card 34 attached to the server-side information processing device 13B. As a result, the communication system 1 can perform a handshake using the legitimate private key and certificate issued by the communication management device 14 to determine a common key, thereby achieving the effects described above and further improving the security of the social infrastructure system.
[0108] The configuration of the communication system 1 is not limited to the examples described above. For example, the information processing device 13 may use a Hardware Security Module (HSM) that implements the functions of the information processing device 13 in hardware, based on the processing load. In other words, the information processing device 13 is not necessarily limited to a configuration that uses an IC card, as long as secure processing is possible, and may also be configured using an IC chip or IC module that can implement the functions of the information processing device 13.
[0109] Furthermore, in communication system 1, secure communication using the SSL / TLS protocol may be performed at all times, or it may be possible to select whether or not to perform communication using the SSL / TLS protocol. Also, in bidirectional communication between IoT device 11 and server device 12, only one direction of communication may be performed using the SSL / TLS protocol. Furthermore, secure communication using the SSL / TLS protocol may be performed at all times, or it may be possible to select whether or not to perform communication using the SSL / TLS protocol.
[0110] By always using the SSL / TLS protocol for communication, it is possible to block communication from devices other than the legitimate information processing device 13 authenticated by the information processing device 13. This prevents unauthorized access to the IoT device 11 and the server device 12, and prevents the IoT device 11 and the server device 12 from being infected with malware.
[0111] Furthermore, the communication system 1 may continuously use the SSL / TLS protocol for communication and record unauthorized access to the IoT device 11 and the server device 12. In this case, records of unauthorized access may be sent to the communication management device 14. The communication management device 14 can recognize whether or not there has been unauthorized access, and can detect and take countermeasures at the preliminary stage before a large-scale attack on the entire system begins.
[0112] Furthermore, in the communication system 1, the information processing device 13 may periodically check whether the connection to the IoT device 11 or server device 12 to which it is connected is maintained. In this case, information indicating the connection status may be transmitted to the communication management device 14. If the communication management device 14 cannot receive information indicating the connection status from the information processing device 13, it will determine that the information processing device 13 has been disconnected from the IoT device 11 or server device 12 and will disable the disconnected information processing device 13. By doing so, the communication management device 14 will prevent the disconnected information processing device 13 from being connected to an unauthorized device and misused for impersonation.
[0113] Furthermore, in the communication system 1, the IC card 34 attached to the information processing device 13 may be equipped with a highly tamper-resistant chip called a secure element that has obtained CC (Common Criteria / ISO15408) certification. By using this chip to store certificates including private keys and public keys, a very high level of security can be maintained.
[0114] Furthermore, in the communication system 1, the server device 12, the communication management device 14, etc., may be configured to update the program of the IoT device 11 via the information processing device 13. By updating the program (firmware update) via the information processing device 13, the functions of the IoT device 11 can be updated securely. When firmware is transmitted from the server device 12 to the IoT device 11 in this manner, the firmware transmitted from the server device 12 is accompanied by a signature of the server device 12, which is encrypted by, for example, the server-side information processing device 13B. In this case, the IoT device 11 can determine that the transmitted firmware is indeed firmware transmitted from the server device 12 by decrypting the signature using the information processing device 13. This prevents the IoT device 11 from being incorrectly updated based on malicious firmware, even if malicious firmware is transmitted to the IoT device 11 from an unauthorized terminal that is pretending to be the server device 12.
[0115] Furthermore, since communication is performed via the information processing device 13 in this manner, the firmware of the IoT device 11 can be safely updated from the server device 12, the communication management device 14, etc. This reduces the work cost compared to when workers have to physically travel to the location where each IoT device 11 is installed to perform firmware updates.
[0116] Furthermore, in the communication system 1, the IoT device 11 may be started or stopped via the information processing device 13 from the server device 12, the communication management device 14, etc. By starting or stopping (remote activation) via the information processing device 13, the functions of the IoT device 11 can be safely updated, and secure remote control can be realized.
[0117] Furthermore, while the communication system 1 was described using the example of IoT device 11 and server device 12 communicating via wired connections, it is not limited to this. At least one of IoT device 11 and server device 12 may be a device that performs wireless communication via Wi-Fi or the like. For example, when IoT device 11 communicates with server device 12 via wireless communication, information processing device 13 has a wireless communication function, encrypts the data transmitted by IoT device 11, and transmits the encrypted data to server device 12 via wireless communication.
[0118] In the example described above, the information processing device 13 communicates with the server-side information processing device 13B in the communication system 1, but the communication destination of the information processing device 13 is not limited to this. For example, the information processing device 13A may communicate with the information processing device 13B. When the information processing device 13A receives a signal to start communication from the information processing device 13B, it first performs mutual authentication with the information processing device 13B to confirm that the information processing device 13B is a legitimate communication terminal. If mutual authentication is performed correctly, the information processing device 13A outputs the information received from the information processing device 13B to the IoT device 11. By attaching an authenticator to the transmitted data using encryption, it becomes possible to detect tampering with the communication information and identify the sender.
[0119] As described above, in the communication system 1, it is possible to ensure that "data is received from the correct party" and "without tampering" in communication between the device-side information processing device 13 and the server-side information processing device 13B, and in communication between the device-side information processing devices 13 themselves.
[0120] Next, the process for changing the communication settings of the information processing device 13 in the communication system 1 according to the embodiment will be described. In the communication system 1 according to the embodiment, the information processing device 13 configures the first communication unit 31 according to network setting (communication setting) information instructed by the communication management device 14. When the communication management device 14 changes the network setting (setting of the first communication unit) of the information processing device 13, it supplies network setting change information to the information processing device 13. The information processing device 13 attempts network communication with the communication unit configured based on the network setting change information from the communication management device 14. If communication with the communication unit to which the network setting change information has been applied is successful, the information processing device 13 applies the settings based on the network setting change information to the first communication unit 31. If communication with the communication unit to which the network setting change information has been applied fails, the information processing device 13 returns the first communication unit 31 to the settings it had before receiving the network setting change information.
[0121] As a result, the information processing device 13 can change the settings of the first communication unit 31 according to the change information from the communication management device 14 if there are no problems with the network setting change information supplied from the communication management device 14, and if there are problems with the network setting change information supplied from the communication management device 14, it can maintain the settings of the first communication unit 31 without applying the settings based on the change information from the communication management device. As a result, the information processing device 13 can maintain normal network communication even if the network setting change information supplied from the communication management device 14 contains factors that cause problems.
[0122] The following describes examples of configuration change processing (first configuration change processing and second configuration change processing) performed by the information processing device 13 in response to network configuration change information supplied from the communication management device 14. First, a first setting change process will be described in which the information processing device 13 performs communication settings in accordance with the specifications from the communication management device 14 in the communication system 1 according to the embodiment. Figure 7 is a flowchart illustrating the first setting change process performed by the information processing device 13 in the communication system 1 according to this embodiment. For example, in communication system 1, the communication management device 14 obtains network setting change information to be applied to the information processing device 13 through operations by an administrator or other means. When the communication management device 14 obtains network setting change information to be applied to the information processing device 13, it sends a network setting change request to the target information processing device 13 requesting the network setting to be changed.
[0123] The information processing device 13 communicates with the communication management device 14 via the network NW (network 18 and gateway 17) using the first communication unit 31. The control unit 30 of the information processing device 13 receives the network setting change request transmitted by the communication management device 14 via the first communication unit 31 (step S31). Here, the network setting change request is assumed to be a request for a change in the communication settings of the first communication unit 31 of the information processing device 13.
[0124] When the control unit 30 of the information processing device 13 receives a network setting change request from the communication management device 14, it stores information indicating the current network settings applied to the first communication unit 31 (the current settings of the first communication unit 31) in the temporary storage unit 35a as current setting information (step S32).
[0125] When the control unit 30 of the information processing device 13 stores the current setting information, which indicates the settings of the first communication unit 31, in the temporary storage unit 35a, it notifies the communication management device 14 that it is ready to change the network settings (step S33).
[0126] When the communication management device 14 receives notification that it is ready to change the network settings, it transmits network setting information (communication setting change information) as communication setting information to be applied to the first communication unit 31 of the information processing device 13. Here, the network setting change information includes, for example, information specifying that the IP address, default gateway, subnet, DNS server, NTP server, etc., will be changed.
[0127] The control unit 30 of the information processing device 13 receives network setting change information transmitted from the communication management device 14 via the first communication unit 31 (step S34). Upon receiving the network setting change information from the communication management device 14, the control unit 30 changes (updates) the setting of the first communication unit 31 to the setting based on the network setting change information from the communication management device 14, while retaining the current setting information in the temporary storage unit 35a (step S35).
[0128] When the control unit 30 of the information processing device 13 performs a change in the settings of the first communication unit 31, it attempts network communication by the updated first communication unit 31 to determine whether or not normal network communication by the updated first communication unit 31 was successful (step S36). For example, the control unit 30 attempts to communicate with the communication management device 14 by the updated first communication unit 31 within a predetermined time and checks whether or not normal communication with the communication management device 14 was successful within the predetermined time.
[0129] However, the method for determining whether successful network communication was achieved by the updated first communication unit 31, which has been configured based on the network configuration change information, is not limited to a specific method. For example, the control unit 30 of the information processing device 13 may determine whether successful communication was achieved by attempting to communicate with the communication management device 14 using HTTP or HTTPS with the updated first communication unit 31. Alternatively, the control unit 30 may determine whether successful communication was achieved by attempting to communicate using ICMP (Internet Control Message Protocol) with the updated first communication unit 31.
[0130] If the control unit 30 of the information processing device 13 successfully communicates with the communication management device 14 via the first communication unit 31 (step S36, YES), it sends a notification to the communication management device 14 indicating that the network settings change in the first communication unit 31 has been successful (step S37).
[0131] Furthermore, if the first communication unit 31 fails to communicate with the communication management device 14 (step S36, NO), the control unit 30 restores the settings of the first communication unit 31 to their previous state based on the current setting information stored in the temporary storage unit 35a (step S38). Once the control unit 30 restores the settings of the first communication unit 31 to their previous state, it sends a notification to the communication management device 14 indicating that the network setting change failed (step S39).
[0132] After the network settings have been successfully changed, or after the network settings have been reverted to their previous state due to a failure in the network settings change, the control unit 30 of the information processing device 13 deletes the communication settings information stored in the temporary storage unit 35a (step S40) and terminates the series of processes. Furthermore, the communication management device 14 may specify whether or not communication between the information processing device 13 and the IoT device 11 (or server device 12) as a terminal device is permitted depending on the success or failure of the network setting change. For example, the communication management device 14 may permit communication between the IoT device 11 and the second communication unit 32A of the information processing device 13A if the setting change (network setting) in the first communication unit 31A of the information processing device 13A is successful, and disallow communication between the IoT device 11 and the second communication unit 32A of the information processing device 13A if the setting change (network setting) in the first communication unit 31A of the information processing device 13A fails.
[0133] As described above, when the information processing device of the communication system 1 to which the first setting change process has been applied receives network setting change information from the communication management device, it stores the current setting information, which indicates the current setting of the first communication unit, in the temporary storage unit. With the current setting information stored in the temporary storage unit, the information processing device changes (updates) the settings of the first communication unit based on the network setting change information. The information processing device attempts network communication by the first communication unit after the update and determines whether the network communication is successful or not. If the network communication by the first communication unit after the update is successful, the information processing device notifies the communication management device that the network setting change was successful. If the network communication by the first communication unit after the update fails, the information processing device reverts the settings of the first communication unit to the state before the update based on the current setting information stored in the temporary storage unit and notifies the communication management device that the network setting change failed.
[0134] As a result, the information processing device according to the embodiment can change the settings of the first communication unit in response to a request for a change in network settings from a communication management device communicating via the network. Furthermore, if the change in the settings of the first communication unit fails, the information processing device 13 can revert the settings of the first communication unit to their previous settings. As a result, even if there are deficiencies in the setting change information instructed remotely by the communication management device, the network communication by the first communication unit will not be interrupted, and the setting change can be safely implemented.
[0135] Next, the second setting change process of the information processing device 13 in the communication system 1 according to the embodiment will be described. Figure 8 is a diagram illustrating the second configuration change process performed by the information processing device 13 in the communication system 1 according to the embodiment. In the second configuration change process, the information processing device 13 provides a virtual NIC 31v (31Av) in addition to the first communication unit 31 (31A), as shown in Figure 8. The virtual NIC 31Av is a virtual communication unit that performs communication between the information processing device 13 and the network NW (devices connected to the network 18) in place of the first communication unit 31A.
[0136] When the information processing device 13A receives network configuration change information for the first communication unit 31A from the communication management device 14, it constructs a virtual NIC 31Av with the settings based on the received network configuration change information. The information processing device 13A attempts to communicate with the communication management device 14 via the network NW using the virtual NIC 31v while retaining the communication settings of the first communication unit 31A (without changing the settings of the first communication unit 31A).
[0137] When network communication via the virtual NIC 31Av is successful, the information processing device 13A applies the communication settings applied to the virtual NIC 31Av to the first communication unit 31A. This allows the information processing device 13A to apply the communication settings that have been confirmed to enable normal network communication using the virtual NIC 31Av to the first communication unit 31A, thereby ensuring that normal network communication is maintained even after the communication settings are changed.
[0138] Figure 9 is a flowchart illustrating the second setting change process performed by the information processing device 13 in the communication system 1 according to this embodiment. First, in the communication system 1, the communication management device 14 sends a network setting change request to the information processing device 13 requesting a change in network settings. The control unit 30 of the information processing device 13 receives the network setting change request sent from the communication management device 14 via the network NW (network 18 and gateway 17) by the first communication unit 31 (step S51). The network setting change request requests a change (update) of the settings of the first communication unit 31.
[0139] When the control unit 30 of the information processing device 13 receives a network configuration change request from the communication management device 14, it prepares to construct a virtual NIC 31v that will operate as the first communication unit 31, which is the communication unit whose change is requested in the request (step S52).
[0140] When the control unit 30 of the information processing device 13 has finished preparing the virtual NIC 31v which will operate as the first communication unit 31, it notifies the communication management device 14 that it has finished preparing to change the network settings (step S53).
[0141] When the communication management device 14 receives a notification that it is ready to change the network settings, it transmits network setting change information as communication setting information to be applied to the information processing device 13. The control unit 30 of the information processing device 13 receives network setting change information transmitted from the communication management device 14 via the first communication unit 31 (step S54). Upon receiving the network setting change information from the communication management device 14, the control unit 30 applies the settings based on the network setting change information from the communication management device 14 to the prepared virtual NIC 31v (step S55).
[0142] When the control unit 30 of the information processing device 13 has completed the virtual NIC 31v to which the settings based on the network setting change information have been applied, it attempts network communication using the virtual NIC 31v to determine whether or not normal network communication by the communication unit to which the settings based on the network setting change information have been applied has been successful (step S56). For example, the control unit 30 attempts to communicate with the communication management device 14 using the virtual NIC 31v within a predetermined time and checks whether or not normal communication with the communication management device 14 has been successful within the predetermined time. Furthermore, the method for determining whether or not the virtual NIC to which the settings based on the network setting change information has been applied has been successful in normal network communication is not limited to a specific method.
[0143] If network communication using the virtual NIC 31v is successfully completed (step S56, YES), the control unit 30 of the information processing device 13 sends a notification to the communication management device 14 indicating that the network setting change was successful (step S57), and reflects the settings of the virtual NIC 31v to the first communication unit 31 (step S58).
[0144] Once the application of the virtual NIC settings to the first communication unit 31 is complete, the control unit 30 of the information processing device 13 deletes the network settings in the virtual NIC 31v (step S60) and configures the first communication unit 31, which has been changed to the settings based on the network setting change information, to communicate with the network NW. This allows the information processing device to apply the settings whose validity has been verified by the virtual NIC to the communication unit that is subject to the change (update) of communication settings specified by the communication management device.
[0145] Furthermore, if network communication using the virtual NIC 31v fails (step S56, NO), the control unit 30 of the information processing device 13 sends a notification to the communication management device 14 indicating that the network setting change failed (step S59). If communication using the virtual NIC 31v fails, the control unit 30 deletes the settings for the virtual NIC 31v (step S60) and configures the first communication unit 31, which has not had its settings changed, to communicate with the network NW. As a result, the information processing device 13 can operate the first communication unit 31 in the state it was in before receiving the network setting change information from the communication management device 14, without applying the settings that could not be verified as valid on the virtual NIC 31v to the first communication unit 31.
[0146] As described above, the information processing device of the communication system to which the second configuration change process has been applied constructs a virtual communication unit that applies the settings based on the change information when it receives network configuration change information from the communication management device, and operates as the first communication unit. The information processing device attempts network communication by the virtual communication unit and determines whether the network communication is successful or not. If the network communication by the virtual communication unit is successful, the information processing device reflects the settings of the virtual communication unit in the first communication unit and notifies the communication management device that the network configuration change was successful. If the network communication by the virtual communication unit fails, the information processing device notifies the communication management device that the network configuration change failed and deletes the virtual communication unit.
[0147] As a result, the information processing device that has applied the second configuration change process can use a virtual communication unit that applies settings based on network configuration change information from a communication management device communicating via the network to verify whether the settings based on the network configuration change information are valid. Furthermore, if the network configuration by the virtual communication unit fails, the information processing device can notify the communication management device of the network configuration failure without changing the settings of the first communication unit. Consequently, even if there are deficiencies in the configuration change information instructed remotely from the communication management device, the network communication by the first communication unit will not be interrupted, and the configuration change can be safely implemented.
[0148] In the embodiments described above, the configuration change process was explained based on the example configuration of the communication system 1 shown in Figure 1. However, the configuration of the communication system 1 is not limited to the example configuration shown in Figure 1 and can be changed in various ways. For example, there may be multiple information processing devices on the device side connected to the gateway 17. Also, the IoT devices connected to the second communication unit may be changed or added to the information processing device on the device side.
[0149] The following describes examples of applying the first and second setting change processes according to various configurations in the communication system 1 according to the embodiment. Figure 10 shows an example configuration of a communication system 1 in which multiple information processing devices 13 (13A1, 13A2) exist on the device side in relation to the communication management device 14. In the configuration example shown in Figure 10, the communication system 1 has multiple information processing devices 13A1 and 13A2 connected to the gateway 17. In this configuration, the communication management device 14 can request changes to the network settings from each of the multiple information processing devices 13A1 and 13A2.
[0150] However, in the configuration example shown in Figure 10, multiple information processing devices 13A1 and 13A2 connected to a single gateway 17 may have similar communication settings. The communication management device 14 may simultaneously request a change in communication settings from multiple information processing devices 13A1 and 13A2 that have similar communication settings.
[0151] If the communication management device 14 requests a change in communication settings from multiple information processing devices 13A1 and 13A2 simultaneously, it may cancel the network setting change to the other information processing devices if it receives notification from any one of the information processing devices that the network setting change has failed. Alternatively, the communication management device 14 may, after successfully changing the network settings to one information processing device 13A1, then simultaneously execute the network setting change on the other information processing devices 13A2.
[0152] Furthermore, while the examples of the first and second configuration change processes described above describe the process of changing (updating) the settings of the first communication unit 31 connected to the network NW, the settings of the second communication unit 32 connected to the IoT device 11 may also be changed using the first or second configuration change process described above. For example, in the communication system 1, the information processing device 13 may change the device connected to the second communication unit 32. In the example shown in Figure 10, the information processing device 13 indicates that IoT device 11C has been connected to the second communication unit 32, which was previously connected to IoT device 11A. When the device 11, which is a terminal device connected to the second communication unit 32, is changed, the information processing device 13 may need to change the settings of the second communication unit 32.
[0153] The communication management device 14 also manages the communication setting information of the second communication unit 32 in the information processing device 13. When the information processing device 13 receives a request from the communication management device 14 to change the communication settings of the second communication unit 32, it may change the settings of the second communication unit 32 using a procedure similar to the first or second setting change process. For example, as an example of applying the first setting change process, when the control unit 30 of the information processing device 13 receives setting change information for the second communication unit 32 from the communication management device 14, it stores information indicating the current (pre-change) settings of the second communication unit 32 (current setting information) in the temporary storage unit 35a.
[0154] The control unit 30 of the information processing device 13 updates the settings of the second communication unit 32 with change information from the communication management device 14 while retaining the original setting information in the temporary storage unit 35a. If the updated second communication unit 32 successfully communicates with the IoT device 11, the control unit 30 deletes the current setting information from the temporary storage unit 35a. If the updated second communication unit 32 fails to communicate with the IoT device 11, the control unit 30 reverts the settings of the second communication unit 32 to their previous state based on the current setting information stored in the temporary storage unit 35a. This ensures that the information processing device 13 reliably implements setting changes in the second communication unit 32 connected to the IoT device in accordance with the setting changes instructed by the communication management device 14.
[0155] Furthermore, as an example of applying the second setting change process, when the control unit 30 of the information processing device 13 receives setting change information for the second communication unit 32 from the communication management device 14, it constructs a virtual NIC that operates as the second communication unit 32 with the settings based on the received change information applied. If communication with the IoT device 11 via the virtual NIC is successful, the control unit 30 reflects the settings of the virtual NIC in the second communication unit 32, and if communication with the IoT device 11 via the virtual NIC fails, it deletes the virtual NIC. In this way, the information processing device 13 can reliably implement setting changes in the second communication unit 32 connected to the IoT device 11 as a terminal device in response to change requests from the communication management device 14.
[0156] While several embodiments of the present invention have been described, these embodiments are presented as examples only and are not intended to limit the scope of the invention. These novel embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents. [Explanation of symbols]
[0157] 1...Communication system, 11...IoT device (terminal device), 12...Server device, 13 (13A, 13B)...Information processing device, 14...Communication management device, 17...Gateway, 18...Network, NW...Network, 21 (21A, 21B)...First port, 22 (22A, 22B)...Second port, 30...Control unit (first control unit), 31 (31A (31A1, 31A2), 31B)...First communication unit, 32 (32A, 32B)...Second communication unit, 31v...Virtual NIC (virtual communication unit), 33...Reader / writer, 34...IC card, 40...IC module, 41...Contact unit, 42...IC chip, 43...UART, 44...CPU, 45...ROM, 46...RAM, 47...EEPROM, 60...NW communication unit, 61...Control unit (second control unit), 62...Storage unit.
Claims
1. In an information processing device that performs network communication, A communication unit that communicates with a communication management device via the aforementioned network, A control unit which, when the communication unit receives information about changes to the settings of the communication unit from the communication management device, constructs a virtual communication unit configured based on the change information, and when the virtual communication unit successfully communicates with the communication management device, reflects the settings of the virtual communication unit in the communication unit, An information processing device having
2. After constructing the virtual communication unit, the control unit attempts to communicate with the communication management device via the virtual communication unit within a predetermined time. If communication with the communication management device is unsuccessful within the predetermined time, the control unit is configured based on the current configuration information. The information processing apparatus according to claim 1.
3. If the virtual communication unit fails to communicate with the communication management device, the control unit notifies the communication management device that the change in settings based on the change information has failed. The information processing apparatus according to claim 1.
4. The control unit deletes the virtual communication unit if it reflects the settings of the virtual communication unit to the communication unit, or if communication with the communication management device by the virtual communication unit is unsuccessful. The information processing apparatus according to claim 1.
5. In a communication system including an information processing device and a communication management device, The aforementioned information processing device is A communication unit that connects to the network, The system includes a first control unit which, when the communication unit receives information about changes to the settings of the communication unit from the communication management device, constructs a virtual communication unit based on the change information, and when communication between the virtual communication unit and the communication management device is successful, reflects the settings of the virtual communication unit in the communication unit. The aforementioned communication management device is A network communication unit that communicates with the information processing device via the aforementioned network, The system includes a second control unit which transmits information about changes to the settings of the communication unit to the information processing device that communicates via the NW communication unit. Communication system.
6. The communication management device further includes a storage unit that stores communication setting information indicating the settings of the communication unit in the information processing device. The second control unit of the communication management device updates the communication setting information of the communication unit of the information processing device stored in the storage unit based on the change information when the information processing device changes the setting of the communication unit based on the change information. The communication system according to claim 5.
Citation Information
Patent Citations
Method for altering setting of transmitter
JP2004235791A
Information processor, communication system, management device and program
JP2008010018A
Communication system
JP2019029777A
Communication control system and communication controller
JP2019050485A