Network management device, network management system, IoT device, and network management method

The network management device and system ensure secure IoT device connections by comparing network information to prevent unintentional connections to insecure networks, thereby safeguarding data and communication integrity.

WO2025173727A1PCT designated stage Publication Date: 2025-08-21PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/004710
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-15
Filing Date
2025-02-13
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

IoT devices can unintentionally connect to insecure networks, leading to issues such as loss of log information and personal data leakage.

Method used

A network management device and system that acquires and compares network information from both the IoT device and the control device to determine if they match, preventing connection if the networks are not secure.

Benefits of technology

Prevents IoT devices from connecting to insecure networks, ensuring secure communication and protecting against data loss and unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025004710_21082025_PF_FP_ABST
    Figure JP2025004710_21082025_PF_FP_ABST
Patent Text Reader

Abstract

A network management device (1) comprises: a first information acquisition unit (11) that acquires a first network information (i1) pertaining to a network specified by an IoT device (70); a first information output unit (21) that outputs the first network information (i1) acquired by the first information acquisition unit (11); a second information acquisition unit (12) that acquires second network information (i2) pertaining to a network specified by a control device (90) which requests connection to the IoT device (70); an information processing unit (50) that obtains a determination result (R) indicating whether or not to connect the control device (90) to the IoT device (70), on the basis of the first network information (i1) and the second network information (i2); and a second information output unit (22) that outputs the determination result (R) to the IoT device (70).
Need to check novelty before this filing date? Find Prior Art

Description

Network management device, network management system, IoT device, and network management method

[0001] The present disclosure relates to a network management device, a network management system, an IoT (Internet of Things) device, and a network management method.

[0002] Conventionally, IoT devices connected to a communication network have been known. The Matter standard has been proposed as a communication standard for communication between these IoT devices. The Matter standard is a standard for smart homes established by the Connectivity Standards Alliance (CSA). By using the Matter standard, multiple IoT devices manufactured by different manufacturers can be easily connected to each other for communication. Patent Document 1 discloses a method for building a network between a UPnP (Universal Plug and Play) device and a UPnP endpoint.

[0003] Special Publication No. 2010-507285

[0004] In conventional technology, IoT devices may be connected to insecure networks, which can cause security issues.

[0005] The present disclosure provides a network management device and the like that can prevent IoT devices from being connected to an insecure network.

[0006] A network management device according to one aspect of the present disclosure includes a first information acquisition unit that acquires first network information of a network specified by an IoT device, a first information output unit that outputs the first network information acquired by the first information acquisition unit, a second information acquisition unit that acquires second network information of a network specified by a control device that requests connection to the IoT device, an information processing unit that obtains a judgment result indicating whether or not to connect the control device to the IoT device based on the first network information and the second network information, and a second information output unit that outputs the judgment result to the IoT device.

[0007] A network management system according to one aspect of the present disclosure is a network management system comprising the above-mentioned network management device and the IoT device, wherein the IoT device pairs with the control device when the determination result indicates that the control device should be connected to the IoT device.

[0008] An IoT device according to one aspect of the present disclosure includes a first information output unit that outputs first network information of a network specified by the IoT device, an information acquisition unit that acquires second network information of a network specified by a control device that requests connection to the IoT device, an information processing unit that obtains a judgment result indicating whether or not to connect the control device to the IoT device based on the first network information and the second network information, and a second information output unit that outputs the judgment result to the control device.

[0009] A network management method according to one aspect of the present disclosure includes the steps of outputting first network information of a network specified by an IoT device, acquiring second network information of a network specified by a control device requesting connection to the IoT device, obtaining a judgment result indicating whether or not to connect the control device to the IoT device based on the first network information and the second network information, and outputting the judgment result to the IoT device.

[0010] According to the network management device and the like of the present disclosure, it is possible to prevent IoT devices from being connected to an unsecure network.

[0011] FIG. 1 is a diagram showing a schematic configuration of a network management system according to an embodiment. FIG. 2 is a block diagram of a network management device, IoT devices, and control devices included in the network management system according to an embodiment. FIG. 3 is a diagram showing the flow of information in the network management device, IoT devices, and control devices. FIG. 4 is a sequence diagram showing the operation of the network management device, IoT devices, and control devices according to an embodiment. FIG. 5 is a flowchart showing the operation of the network management device according to an embodiment. FIG. 6 is a flowchart showing the operation of the control device according to an embodiment. FIG. 7 is a diagram showing an example of an IoT device according to a first modification of the embodiment. FIG. 8 is a block diagram of an IoT device and a control device according to the first modification of the embodiment. FIG. 9 is a diagram showing the flow of information in the IoT device and a control device according to the first modification of the embodiment. FIG. 10 is a sequence diagram showing the operation of the network management device, IoT devices, and control devices according to a second modification of the embodiment.

[0012] (Background to the present disclosure) In recent years, log information of IoT devices connected to a network has been collected, and services suited to the usage style of users of the IoT devices have been provided.

[0013] Furthermore, with regard to networks to which IoT devices are connected, communication standards (e.g., the Matter standard) have been proposed that enable the interconnection of multiple IoT devices from different manufacturers. This communication standard allows IoT devices to be connected to a network using a control device such as a smartphone. However, when connecting an IoT device to a network, the IoT device may be connected to an insecure network unintentionally by the user of the IoT device. When an IoT device is connected to an insecure network, a problem occurs in which log information from the IoT device cannot be collected. Furthermore, a problem of personal information being leaked via the insecure network may also occur.

[0014] In response to this, the network management device and network management system of the present disclosure have the following configuration to prevent IoT devices from being connected to an unsecure network.

[0015] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. Note that each of the embodiments described below represents a preferred specific example of the present disclosure. The shapes, components, component placement positions, and connection configurations shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not described in the independent claims that represent the highest concept of the present disclosure will be described as optional components that constitute a more preferred embodiment. Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration.

[0016] (Embodiment) [General Configuration of Network Management System] A general configuration of a network management system according to an embodiment will be described with reference to FIG.

[0017] FIG. 1 is a diagram showing a schematic configuration of a network management system 5 according to an embodiment.

[0018] FIG. 1 shows a network management device 1, an IoT device 70, and a control device 90 included in a network management system 5.

[0019] The network management device 1 is a device that constructs a network between IoT devices 70 and control devices 90 that control the operation of the IoT devices 70 .

[0020] The IoT device 70 is a device that can be controlled by the control device 90 and is also called a controlled device. The IoT device 70 is, for example, an electrical device such as a refrigerator, a television, a projector, a printer, or a copier. The IoT device 70 is placed in a predetermined space within a building. The predetermined space is, for example, a space that is temporarily used by different users, such as a common space in an office, a conference room, a guest room, or a rental room in a building.

[0021] The control device 90 is a mobile terminal owned by a user who uses a predetermined space, such as a smartphone or a tablet terminal. Software compatible with the Matter standard is installed on the control device 90.

[0022] The following describes an example in which a user uses an IoT device 70 in a common space in an office.

[0023] 1A shows a state in which a network management device 1 and an IoT device 70 are arranged in a shared space. The IoT device 70 has network information of the network to which the IoT device 70 is connected, i.e., network information of the IoT device 70. The network in this example is a LAN (Local Area Network) using, for example, Wi-Fi (registered trademark) or Zigbee (registered trademark).

[0024] 1(b) shows a state in which a user carrying a control device 90 has entered a shared space. The user attempts to establish a network between IoT device 70 and control device 90 in order to use IoT device 70 placed in the shared space.

[0025] 1(c), the network management system 5 performs a process of determining whether to connect the control device 90 to the IoT device 70. The network management device 1 acquires network information of the IoT device 70 and stores it in a storage unit (c1). The network management device 1 also outputs integrated authentication information including the network information of the IoT device 70 (c2).

[0026] The user acquires the network information of the IoT device 70 using the control device 90 (c3). For example, the user acquires the network information of the IoT device 70 by reading the integrated authentication information displayed in the shared space with a camera.

[0027] The control device 90 accesses the network of the IoT device 70 based on the acquired network information and outputs this network information to the IoT device 70 (c4). The IoT device 70 receives the network information output from the control device 90 and outputs it to the network management device 1 (c5).

[0028] The network management device 1 determines whether or not to connect the control device 90 to the IoT device 70 based on the network information output from the control device 90 and the network information stored in the storage unit. For example, if the above two pieces of network information match, the network management device 1 determines that the control device 90 may be connected to the IoT device 70 in the above network.

[0029] According to the network management system 5 of the present disclosure, it is possible to prevent the IoT device 70 from being connected to an insecure network.

[0030] [Configurations of Network Management Device, IoT Device, and Control Device] The configurations of the network management device 1, IoT device 70, and control device 90 included in the network management system 5 will be described with reference to FIGS. 2 and 3. FIG.

[0031] 2 is a block diagram of the network management device 1, IoT devices 70, and control devices 90 included in the network management system 5. FIG. 3 is a diagram showing the flow of information in the network management device 1, IoT devices 70, and control devices 90.

[0032] 2 and 3, the network management system 5 includes a network management device 1, an IoT device 70, and a control device 90. Although one IoT device 70 is shown in these figures, the network management system 5 may include multiple IoT devices.

[0033] The IoT device 70 has a user interface such as a touch panel and button switches. When a user connects the control device 90 to the IoT device 70, the user performs a predetermined operation input via the user interface. Upon receiving the predetermined operation input, the IoT device 70 outputs identification information d1 of the IoT device 70 and first network information i1, which is network information of the IoT device 70, to the network management device 1 (see (a) in FIG. 3 ).

[0034] The identification information d1 of the IoT device 70 is, for example, a logical address or a physical address of the IoT device 70. The first network information i1 is information about the network to which the IoT device 70 is connected, that is, network information about the first network specified by the IoT device 70. The first network information i1 includes an SSID (Service Set IDentifier) ​​and a password for connecting to the first network specified by the IoT device 70.

[0035] 2, the network management device 1 includes a first information acquisition unit 11, a second information acquisition unit 12, a first information output unit 21, a second information output unit 22, an information generation unit 30, an information processing unit 50, and a storage unit 60. The network management device 1 also includes a display unit 24 such as a display. Also shown in FIG. 2 is an information acquisition unit 10 including the first information acquisition unit 11 and the second information acquisition unit 12.

[0036] The first information acquisition unit 11 is configured with an arithmetic circuit and a communication circuit. The first information acquisition unit 11 acquires information output from the IoT device 70 via the first network. Specifically, the first information acquisition unit 11 acquires identification information d1 and first network information i1 of the IoT device 70.

[0037] The identification information d1 and the first network information i1 of the IoT device 70 acquired by the first information acquisition unit 11 are output to the storage unit 60 (see (b) of FIG. 3 ). The identification information d1 and the first network information i1 are also output to the information generation unit 30 (see (c) of FIG. 3 ).

[0038] The storage unit 60 is a storage medium that temporarily or non-temporarily stores data. The storage medium is, for example, a flash memory, a RAM (Random Access Memory), a hard disk, etc. The storage unit 60 stores a program that describes the operation of the network management device 1. The storage unit 60 also stores identification information d1 and first network information i1 of the IoT device 70 output from the first information acquisition unit 11.

[0039] The information generation unit 30 is configured with an arithmetic circuit. The information generation unit 30 generates integrated authentication information ui based on the identification information d1 of the IoT device 70 and the first network information i1 output from the first information acquisition unit 11. The integrated authentication information ui includes the identification information d1 of the IoT device 70 and the first network information i1. The integrated authentication information ui generated by the information generation unit 30 is output to the first information output unit 21.

[0040] The first information output unit 21 is configured with an arithmetic circuit and a communication circuit. The first information output unit 21 outputs the integrated authentication information ui generated by the information generation unit 30 by broadcast communication (see (d) in FIG. 3). For example, the first information output unit 21 outputs the integrated authentication information ui using a communication method such as BLE (Bluetooth (registered trademark) Low Energy). If the first information output unit 21 has an LED (Light Emitting Diode), the first information output unit 21 may output the integrated authentication information ui using an infrared communication method or an optical communication method.

[0041] The information generating unit 30 may generate a two-dimensional barcode such as a QR code (registered trademark) as the integrated authentication information ui (see (e) in FIG. 3). When the integrated authentication information ui using a two-dimensional barcode is generated, the first information output unit 21 may output the two-dimensional barcode to the display unit 24 of the network management device 1. The first information output unit 21 may display the two-dimensional barcode on the screen of the IoT device 70, or may print and display it on paper output from the IoT device 70 (not shown).

[0042] The control device 90 is a device that requests a connection to the IoT device 70. The control device 90 includes an acquisition unit 91, a transmission / reception unit 92, a calculation unit 95, and a storage unit 96. The calculation unit 95 includes a network access unit 95a.

[0043] The storage unit 96 stores identification information d2 and second network information i2 of the control device 90. The identification information d2 of the control device 90 is, for example, the logical address or physical address of the control device 90. The second network information i2 is network information of the second network specified by the control device 90.

[0044] The acquisition unit 91 acquires the integrated authentication information ui output from the first information output unit 21. The acquisition unit 91 may acquire the integrated authentication information ui by reading the integrated authentication information ui displayed on a screen or paper using a camera of the control device 90. The acquisition unit 91 outputs the acquired integrated authentication information ui to the calculation unit 95 (see (f) in FIG. 3 ).

[0045] The calculation unit 95 extracts the first network information i1 from the integrated authentication information ui and acquires the first network information i1.

[0046] The network access unit 95a of the calculation unit 95 accesses the first network based on this first network information i1. Specifically, the network access unit 95a accesses the first network using the SSID and password included in the first network information i1.

[0047] Furthermore, the calculation unit 95 replaces the contents of the second network information i2 stored in the storage unit 96 with the same contents as the first network information i1 and outputs it. In other words, the calculation unit 95 outputs the information included in the first network information i1 as the second network information i2 (see (g) in FIG. 3).

[0048] The transmitter / receiver 92 uses the first network that has become accessible to transmit the second network information i2 and the identification information d2 of the control device 90 to the IoT device 70 (see (h) in FIG. 3). In this way, the second network information i2 of the control device 90 is transmitted to the IoT device 70 at the time when the control device 90 becomes able to access the first network.

[0049] The IoT device 70 stores the second network information i2 transmitted from the control device 90 and the identification information d2 of the control device 90 in a storage unit of the IoT device 70. The IoT device 70 also transfers the second network information i2 transmitted from the control device 90 to the network management device 1 (see (i) in FIG. 3).

[0050] 2 is configured with an arithmetic circuit and a communication circuit. The second information acquisition unit 12 acquires second network information i2 output from the control device 90 via the IoT device 70. The second information acquisition unit 12 outputs the acquired second network information i2 to the information processing unit 50 (see (j) in FIG. 3).

[0051] The information processing unit 50 is configured with an arithmetic circuit. The information processing unit 50 obtains a determination result R indicating whether or not to connect the control device 90 to the IoT device 70, based on the first network information i1 and the second network information i2. For example, the information processing unit 50 obtains the determination result R by comparing the first network information i1 with the second network information i2.

[0052] Specifically, when the first network information i1 stored in the storage unit 60 matches the second network information i2 output from the control device 90, the information processing unit 50 outputs a G determination to connect the control device 90 to the IoT device 70. When the first network information i1 stored in the storage unit 60 does not match the second network information i2 output from the control device 90, the information processing unit 50 outputs an NG determination to not connect the control device 90 to the IoT device 70. The information processing unit 50 outputs the obtained determination result R to the second information output unit 22 (see (k) in FIG. 3 ).

[0053] The second information output unit 22 is composed of an arithmetic circuit and a communication circuit. The second information output unit 22 outputs the determination result R obtained by the information processing unit 50 to the IoT device 70 (see (l) in FIG. 3). The IoT device 70 transfers the determination result R output from the second information output unit 22 to the control device 90 (see (m) in FIG. 3). In other words, the second information output unit 22 outputs the determination result R to the control device 90 via the IoT device 70. The transmitter / receiver unit 92 of the control device 90 receives this determination result R and outputs it to the arithmetic unit 95 (see (n) in FIG. 3).

[0054] For example, when the judgment result R output from the second information output unit 22 is a G judgment, the IoT device 70 and the control device 90 perform commissioning with each other. Commissioning is a process for setting up the control device and the controlled device so that they can communicate via a predetermined network. Commissioning is performed using a communication method such as BLE. This commissioning establishes pairing between the IoT device 70 and the control device 90, and the IoT device 70 and the control device 90 communicate with each other using a secure network based on the first network information i1.

[0055] On the other hand, if the judgment result R is an NG judgment, the IoT device 70 and the control device 90 do not perform commissioning. In this case, pairing between the IoT device 70 and the control device 90 is not established, and communication via the network is not realized. In this way, if the judgment result R is an NG judgment, it is possible to prevent, for example, the control device 90 from being unintentionally connected to the IoT device 70 and the network of the IoT device 70 from being rewritten.

[0056] The network management device 1 of this embodiment includes a first information acquisition unit 11 that acquires first network information i1 of a network specified by an IoT device 70, a first information output unit 21 that outputs the first network information i1 acquired by the first information acquisition unit 11, a second information acquisition unit 12 that acquires second network information i2 of a network specified by a control device 90 that requests connection to the IoT device 70, an information processing unit 50 that obtains a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 and the second network information i2, and a second information output unit 22 that outputs the judgment result R to the IoT device 70.

[0057] In this way, by obtaining the determination result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 and the second network information i2, it is possible to prevent, for example, the network of the IoT device 70 from being unintentionally rewritten. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0058] [Operations of Network Management Device, IoT Device, and Control Device] The operations of the network management device, IoT device, and control device will be described with reference to FIG.

[0059] FIG. 4 is a sequence diagram showing the operations of the network management device 1, the IoT device 70, and the control device 90.

[0060] As shown in FIG. 4, the IoT device 70 outputs the identification information d1 of the IoT device 70 and the first network information i1 to the network management device 1 (step S10).

[0061] The network management device 1 acquires identification information d1 of the IoT device 70 and first network information i1 from the IoT device 70 (step S11). The identification information d1 of the IoT device 70 is, for example, the logical address or physical address of the IoT device 70. The first network information i1 is network information of the first network specified by the IoT device 70. The first network information i1 includes an SSID and a password for connecting to the first network.

[0062] The network management device 1 stores the identification information d1 and the first network information i1 of the IoT device 70 acquired in step S11 in the storage unit 60 (step S12).

[0063] The network management device 1 generates integrated authentication information ui including the identification information d1 and the first network information i1 of the IoT device 70 (step S13). Then, the network management device 1 outputs the integrated authentication information ui generated in step S13 to the outside (step S14). The network management device 1 may output the integrated authentication information ui as binary data or as a two-dimensional barcode.

[0064] The control device 90 acquires the integrated authentication information ui output from the network management device 1 (step S15).

[0065] The control device 90 acquires the first network information i1 from the integrated authentication information ui (step S16), and accesses the first network based on the first network information i1 (step S17).

[0066] Furthermore, the control device 90 replaces the content of its own second network information i2 with the same content as the first network information i1 and outputs it. That is, the control device 90 outputs the information included in the first network information i1 as the second network information i2 (step S18). At this time, the control device 90 transmits the second network information i2 to the IoT device 70 via the first network that has become accessible.

[0067] The IoT device 70 transfers the second network information i2 transmitted from the control device 90 to the network management device 1 (step S19). The network management device 1 acquires the second network information i2 output from the IoT device 70 (step S20).

[0068] The network management device 1 obtains a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 saved in step S12 and the second network information i2 acquired in step S20 (step S21). For example, the network management device 1 obtains the judgment result R by comparing the first network information i1 with the second network information i2. In this example, if the first network information i1 and the second network information i2 match, the judgment result R is a G judgment, and if they do not match, the judgment result R is an NG judgment.

[0069] The network management device 1 outputs the above-mentioned determination result R to the IoT device 70 (step S22). The IoT device 70 transfers the determination result R output from the network management device 1 to the control device 90 (step S23). The control device 90 acquires the determination result R output from the IoT device 70 (step S24).

[0070] For example, when the judgment result R is a G judgment, the IoT device 70 and the control device 90 perform commissioning with each other. This commissioning establishes pairing between the IoT device 70 and the control device 90, and the IoT device 70 and the control device 90 communicate with each other using a secure network based on the first network information i1.

[0071] On the other hand, if the judgment result R is an NG judgment, the IoT device 70 and the control device 90 do not perform commissioning. In this case, pairing between the IoT device 70 and the control device 90 is not established, and communication via the network is not realized. In this way, if the judgment result R is an NG judgment, it is possible to prevent, for example, the network of the IoT device 70 from being unintentionally rewritten.

[0072] By performing these steps, the IoT device 70 can be prevented from connecting to an insecure network.

[0073] [Operation Flow of the Network Management Device] The operation flow of the network management device will be described with reference to FIG.

[0074] FIG. 5 is a flowchart showing the operation of the network management device 1.

[0075] As shown in FIG. 5, the network management device 1 acquires the identification information d1 of the IoT device 70 and the first network information i1 from the IoT device 70 (step S111).

[0076] The network management device 1 stores the identification information d1 and the first network information i1 of the IoT device 70 acquired in step S111 in the storage unit 60 (step S112).

[0077] The network management device 1 generates integrated authentication information ui including the identification information d1 of the IoT device 70 and the first network information i1 (step S113).

[0078] Then, the network management device 1 outputs the integrated authentication information ui generated in step S113 to the outside (step S114).

[0079] The network management device 1 acquires the second network information i2 transmitted from the control device 90 via the IoT device 70 (step S120).

[0080] The network management device 1 obtains a determination result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 saved in step S112 and the second network information i2 acquired in step S120 (step S121). For example, the network management device 1 obtains the determination result R by comparing the first network information i1 with the second network information i2.

[0081] The network management device 1 outputs the above-mentioned determination result R to the IoT device 70 (step S122). The determination result R is transferred to the control device 90 via the IoT device 70.

[0082] For example, when the judgment result R is a G judgment, the IoT device 70 and the control device 90 communicate with each other using a secure network based on the first network information i1. On the other hand, when the judgment result R is an NG judgment, the IoT device 70 and the control device 90 do not communicate with each other via the network.

[0083] By performing these steps, the IoT device 70 can be prevented from connecting to an insecure network.

[0084] [Operation Flow of Control Device] The operation flow of the control device will be described with reference to FIG.

[0085] FIG. 6 is a flowchart showing the operation of the control device 90.

[0086] As shown in FIG. 6, the control device 90 acquires the integrated authentication information ui generated by the network management device 1 (step S115).

[0087] The control device 90 acquires the first network information i1 from the integrated authentication information ui (step S116).

[0088] The control device 90 accesses the first network based on the first network information i1 (step S117).

[0089] Control device 90 replaces the content of its own second network information i2 with the same content as first network information i1 and outputs it. In other words, control device 90 outputs the information included in first network information i1 as second network information i2 (step S118).

[0090] The control device 90 transmits the second network information i2 to the IoT device 70 via the first network that has become accessible (step S118A).

[0091] The second network information i2 transmitted from the IoT device 70 is output to the network management device 1 via the IoT device 70. The network management device 1 obtains a determination result R indicating whether or not to connect the control device 90 to the IoT device 70, based on the first network information i1 included in the integrated authentication information ui and the second network information i2 output by the control device 90.

[0092] The control device 90 acquires the determination result R output from the network management device 1 via the IoT device 70 (step S124).

[0093] If the judgment result R is a G judgment, the control device 90 performs commissioning with the IoT device 70. This commissioning establishes pairing between the IoT device 70 and the control device 90, and the IoT device 70 and the control device 90 communicate with each other using a secure network based on the first network information i1.

[0094] On the other hand, if the judgment result R is an NG judgment, the control device 90 does not perform commissioning with the IoT device 70. The control device 90 is not paired with the IoT device 70 and is unable to communicate with the IoT device 70 via the network. In this case, the control device 90 may display information indicating that pairing has not been established on the screen of the control device 90.

[0095] By performing these steps, the IoT device 70 can be prevented from connecting to an insecure network.

[0096] [Modification 1] A network management system 5A according to Modification 1 of the embodiment will be described with reference to Fig. 8 and Fig. 9. In Modification 1, an example will be described in which the network management device 1 is provided in an IoT device 70A.

[0097] FIG. 7 is a diagram illustrating an example of an IoT device 70A according to the first modification of the embodiment.

[0098] 7 is, for example, a refrigerator. The IoT device 70A includes the network management device 1 and a display input unit 74. The display input unit 74 is, for example, a touch panel and functions as a user interface.

[0099] Fig. 8 is a block configuration diagram of IoT device 70A and control device 90 according to Modification 1. Fig. 9 is a diagram showing the flow of information in IoT device 70A and control device 90 according to Modification 1.

[0100] As shown in FIGS. 8 and 9, a network management system 5A of the first modification includes an IoT device 70A and a control device 90.

[0101] As shown in FIG. 8, the network management device 1 includes a first information output unit 21, a second information output unit 22, an information generation unit 30, an information acquisition unit 10, an information processing unit 50, and a storage unit 60.

[0102] A program describing the operation of the IoT device 70A is stored in the storage unit 60. The storage unit 60 also stores identification information d1 and first network information i1 of the IoT device 70A.

[0103] By accepting a predetermined operation input via the display input unit 74, the IoT device 70A outputs the identification information d1 and first network information i1 of the IoT device 70A stored in the memory unit 60 to the information generation unit 30 (see (c) of Figure 9).

[0104] The information generating unit 30 generates the integrated authentication information ui based on the identification information d1 and the first network information i1. The integrated authentication information ui generated by the information generating unit 30 is output to the first information output unit 21.

[0105] The first information output unit 21 outputs the integrated authentication information ui generated by the information generation unit 30 (see (d) of FIG. 9 ). Specifically, the first information output unit 21 outputs the integrated authentication information ui including the identification information d1 and the first network information i1 by broadcast communication.

[0106] The information generating unit 30 may generate a two-dimensional barcode such as a QR code (registered trademark) as the integrated authentication information ui (see (e) of FIG. 9). When the integrated authentication information ui using a two-dimensional barcode is generated, the first information output unit 21 may output the two-dimensional barcode to the display input unit 74 of the IoT device 70A. The first information output unit 21 may print and display the two-dimensional barcode on paper output from the IoT device 70A (not shown).

[0107] The control device 90 is a device that requests a connection to the IoT device 70A. The control device 90 includes an acquisition unit 91, a transmission / reception unit 92, a calculation unit 95, and a storage unit 96. The calculation unit 95 includes a network access unit 95a.

[0108] The acquisition unit 91 acquires the integrated authentication information ui output from the first information output unit 21. The acquisition unit 91 outputs the acquired integrated authentication information ui to the calculation unit 95 (see (f) in FIG. 9).

[0109] The calculation unit 95 extracts the first network information i1 from the integrated authentication information ui and acquires the first network information i1.

[0110] The calculation unit 95 also replaces the contents of the second network information i2 stored in the storage unit 96 with the same contents as the first network information i1 and outputs the replaced information. In other words, the calculation unit 95 outputs the information included in the first network information i1 as the second network information i2 (see (g) in FIG. 9). The network access unit 95a of the calculation unit 95 accesses the first network based on this first network information i1.

[0111] The transmitter / receiver 92 uses the now accessible first network to transmit the second network information i2 and the identification information d2 of the control device 90 to the IoT device 70A (see (h) of FIG. 9).

[0112] The information acquisition unit 10 of the IoT device 70A acquires the second network information i2 output from the control device 90. The information acquisition unit 10 outputs the acquired second network information i2 to the information processing unit 50 (see (j) in FIG. 9).

[0113] The information processing unit 50 obtains a determination result R indicating whether or not to connect the control device 90 to the IoT device 70A based on the first network information i1 and the second network information i2. For example, the information processing unit 50 obtains the determination result R by comparing the first network information i1 with the second network information i2.

[0114] Specifically, when the first network information i1 stored in the storage unit 60 matches the second network information i2 output from the control device 90, the information processing unit 50 outputs a G determination to connect the control device 90 to the IoT device 70A. When the first network information i1 stored in the storage unit 60 does not match the second network information i2 output from the control device 90, the information processing unit 50 outputs an NG determination to not connect the control device 90 to the IoT device 70A. The information processing unit 50 outputs the obtained determination result R to the second information output unit 22 (see (k) in FIG. 9 ).

[0115] The second information output unit 22 transmits the determination result R obtained by the information processing unit 50 to the control device 90 (see (m) in FIG. 9). The transmitter / receiver unit 92 of the control device 90 receives this determination result R and outputs it to the calculation unit 95 (see (n) in FIG. 9).

[0116] For example, when the judgment result R output from second information output unit 22 is a G judgment, IoT device 70A and control device 90 perform commissioning with each other. This commissioning establishes pairing between IoT device 70A and control device 90, and IoT device 70A and control device 90 communicate with each other using a secure network based on first network information i1.

[0117] On the other hand, if the judgment result R is an NG judgment, the IoT device 70A and the control device 90 do not perform commissioning. In this case, pairing between the IoT device 70A and the control device 90 is not established, and communication via the network is not realized. In this way, if the judgment result R is an NG judgment, it is possible to prevent, for example, the network of the IoT device 70A from being unintentionally rewritten.

[0118] The IoT device 70A of variant example 1 includes a first information output unit 21 that outputs first network information i1 of a network specified by the IoT device 70A, an information acquisition unit 10 that acquires second network information i2 of a network specified by a control device 90 that requests connection to the IoT device 70A, an information processing unit 50 that obtains a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70A based on the first network information i1 and the second network information i2, and a second information output unit 22 that outputs the judgment result R.

[0119] In this way, by obtaining the determination result R indicating whether or not to connect the control device 90 to the IoT device 70A based on the first network information i1 and the second network information i2, it is possible to prevent, for example, the network of the IoT device 70A from being unintentionally rewritten, thereby preventing the IoT device 70A from being connected to an unsafe network.

[0120] [Modification 2] A network management system 5 according to Modification 2 of the embodiment will be described. Modification 2 describes an example in which a determination result R indicating whether or not to connect control device 90 to IoT device 70 is obtained based on the security strength of the second network.

[0121] The network management system 5 of the second modification includes the network management device 1, the IoT device 70, and the control device 90, as in the embodiment (see FIG. 2).

[0122] Similar to the embodiment, the network management device 1 of the second modification includes a first information acquisition unit 11, a second information acquisition unit 12, a first information output unit 21, a second information output unit 22, an information generation unit 30, an information processing unit 50, and a storage unit 60. The network management device 1 also includes a display unit 24 such as a display.

[0123] The control device 90 comprises an acquisition unit 91, a transmission / reception unit 92, a calculation unit 95, and a storage unit 96. Identification information d2 and second network information i2 of the control device 90 are stored in the storage unit 96. The second network information i2 is network information that was stored in the control device 90 before the control device 90 received the first network information i1 from the network management device 1.

[0124] FIG. 10 is a sequence diagram showing the operations of the network management device 1, the IoT device 70, and the control device 90 according to the second modification of the embodiment.

[0125] As shown in FIG. 10, the IoT device 70 outputs the identification information d1 of the IoT device 70 and the first network information i1 to the network management device 1 (step S10).

[0126] The network management device 1 acquires the identification information d1 of the IoT device 70 and the first network information i1 from the IoT device 70 (step S11). The first network information i1 of the second modification example includes an SSID and a password for connecting to the first network, and further includes information regarding the security strength of the first network.

[0127] The network management device 1 stores the identification information d1 and the first network information i1 of the IoT device 70 acquired in step S11 in the storage unit 60 (step S12).

[0128] The network management device 1 generates integrated authentication information ui including the identification information d1 and the first network information i1 of the IoT device 70 (step S13), and then outputs the integrated authentication information ui generated in step S13 to the outside (step S14).

[0129] The control device 90 acquires the integrated authentication information ui output from the network management device 1 (step S15).

[0130] The control device 90 acquires the first network information i1 from the integrated authentication information ui (step S16), and accesses the first network based on the first network information i1 (step S17).

[0131] Control device 90 of Modification 2 does not replace the contents of its own second network information i2 with first network information i1, but outputs the second network information i2 stored in storage unit 96 (step S18B). Control device 90 transmits second network information i2 to IoT device 70 via the first network that has become accessible. Second network information i2 of Modification 2 includes an SSID and password for connecting to the second network, as well as information regarding the security strength of the second network.

[0132] The IoT device 70 transfers the second network information i2 transmitted from the control device 90 to the network management device 1 (step S19). The network management device 1 acquires the second network information i2 output from the IoT device 70 (step S20).

[0133] The network management device 1 obtains a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 saved in step S12 and the second network information i2 acquired in step S20 (step S21).

[0134] For example, the network management device 1 obtains the above-mentioned judgment result R by comparing the security strength of the first network information i1 with the security strength of the second network information i2. The strength of security strength is determined based on whether the network encryption method is based on a highly secure standard such as WPA (Wi-Fi Protected Access). In this example, if the security strength of the second network information i2 is equivalent to the security strength of the first network information i1, the judgment result R is a G judgment. On the other hand, if the security strength of the second network information i2 is lower than the security strength of the first network information i1, the judgment result R is an NG judgment.

[0135] The network management device 1 outputs the above-mentioned determination result R to the IoT device 70 (step S22).

[0136] The IoT device 70 transfers the determination result R output from the network management device 1 to the control device 90 (step S23).

[0137] The control device 90 acquires the determination result R output from the IoT device 70 (step S24).

[0138] For example, when the judgment result R is a G judgment, the IoT device 70 and the control device 90 perform commissioning with each other. This commissioning establishes pairing between the IoT device 70 and the control device 90, and the IoT device 70 and the control device 90 communicate with each other using a secure second network based on the second network information i2.

[0139] On the other hand, if the judgment result R is an NG judgment, the IoT device 70 and the control device 90 do not perform commissioning. In this case, pairing between the IoT device 70 and the control device 90 is not established, and communication via the network is not realized. In this way, if the judgment result R is an NG judgment, it is possible to prevent the network of the IoT device 70 from being rewritten into a network with low security.

[0140] By performing these steps, the IoT device 70 can be prevented from connecting to an insecure network.

[0141] (Summary) A network management device according to one aspect of the present disclosure will be illustrated.

[0142] The network management device 1 of Example 1 comprises a first information acquisition unit 11 that acquires first network information i1 of a network specified by an IoT device 70, a first information output unit 21 that outputs the first network information i1 acquired by the first information acquisition unit 11, a second information acquisition unit 12 that acquires second network information i2 of a network specified by a control device 90 that requests connection to the IoT device 70, an information processing unit 50 that obtains a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 and the second network information i2, and a second information output unit 22 that outputs the judgment result R to the IoT device 70.

[0143] In this way, by obtaining the determination result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 and the second network information i2, it is possible to prevent, for example, the network of the IoT device 70 from being unintentionally rewritten. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0144] The network management device 1 of Example 2 is the network management device described in Example 1, in which the control device 90 acquires the first network information i1 output from the first information output unit 21 and outputs the first network information i1 as second network information i2, and the second information acquisition unit 12 acquires the second network information i2 output from the control device 90.

[0145] In this way, by outputting the first network information i1 as the second network information i2, it is possible to prevent the network of the IoT device 70 from being rewritten, thereby preventing the IoT device 70 from being connected to an unsafe network.

[0146] The network management device 1 of Example 3 is the network management device described in Example 1 or 2, and the information processing unit 50 may obtain the judgment result R by comparing the first network information i1 with the second network information i2.

[0147] In this way, by comparing the first network information i1 with the second network information i2, it is possible to obtain an appropriate determination result R. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0148] The network management device 1 of Example 4 is the network management device described in Example 3, and further includes a storage unit 60 in which first network information i1 is stored. The information processing unit 50 may obtain a determination result R in which it is determined that the control device 90 should be connected to the IoT device 70 when the first network information i1 stored in the storage unit 60 matches the second network information i2 output from the control device 90.

[0149] In this way, when the first network information i1 stored in the storage unit 60 matches the second network information i2 output from the control device 90, it is determined that the control device 90 should be connected to the IoT device 70, thereby preventing the network of the IoT device 70 from being rewritten. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0150] The network management device 1 of Example 5 is a network management device described in any of Examples 1 to 4, in which the second information acquisition unit 12 acquires second network information i2 output from the control device 90 via the IoT device 70, and the second information output unit 22 may output the judgment result R to the control device 90 via the IoT device 70.

[0151] In this way, by outputting the second network information i2 and the information related to the determination result R via the IoT device 70, it is possible to notify the IoT device 70 of the information necessary for constructing the network. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0152] The network management device 1 of Example 6 is the network management device according to any one of Examples 1 to 5, and further includes an information generation unit 30 that generates integrated authentication information ui that includes first network information i1 and identification information d1 of the IoT device 70. The first information output unit 21 outputs the integrated authentication information ui generated by the information generation unit 30 to the control device 90, and the control device 90 may acquire the first network information i1 from the integrated authentication information ui.

[0153] By generating and outputting the integrated authentication information ui in this manner, it is possible to reduce the number of times data is read in the control device 90, for example.

[0154] A network management system 5 of Example 7 includes the network management device 1 according to any one of Examples 1 to 6, and an IoT device 70. The IoT device 70 pairs with the control device 90 when a determination result R indicating that the control device 90 should be connected to the IoT device 70 is obtained.

[0155] This network management system 5 can prevent the IoT device 70 from being connected to an unsafe network.

[0156] The network management system 5 of Example 8 is the network management system described in Example 7, and the IoT device 70 may receive the second network information i2 output from the control device 90 and transfer it to the second information acquisition unit 12, and may also receive the judgment result R output from the second information output unit 22 and transfer it to the control device 90.

[0157] In this way, by transferring the second network information i2 and the information related to the determination result R via the IoT device 70, it is possible to notify the IoT device 70 of the information necessary for constructing the network. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0158] The network management system 5 of Example 9 is the network management system described in Example 7 or 8, and the IoT device 70 may output the first network information i1 to the first information acquisition unit 11 by accepting a specified operation input.

[0159] This makes it possible to connect the control device 90 to the IoT device 70 when a predetermined operation input is received via a user interface, for example.

[0160] A network management system 5 of Example 10 is the network management system according to any one of Examples 7 to 9, further comprising a control device 90 that requests a connection to an IoT device 70. The control device 90 may access the IoT device 70 based on the first network information i1, thereby outputting second network information i2 to the IoT device 70, and the IoT device 70 may output the second network information i2 output from the control device 90 to the network management device 1.

[0161] This allows the control device 90 to transmit the second network information i2 to the IoT device 70 at the timing when the control device 90 becomes able to access the first network. This makes it possible to output the second network information i2 to the network management device 1. This allows the network management device 1 to determine whether or not to connect the control device 90 to the IoT device 70.

[0162] The network management system 5 of Example 11 is the network management system described in Example 10, and when the information processing unit 50 obtains a judgment result R indicating that the control device 90 should be connected to the IoT device 70, the IoT device 70 and the control device 90 may communicate using a network based on the first network information i1.

[0163] This allows the IoT device 70 and the control device 90 to communicate with each other using a secure network.

[0164] The network management system 5 of Example 12 is the network management system described in Example 10, and when the information processing unit 50 obtains a judgment result R indicating that the control device 90 should be connected to the IoT device 70, the IoT device 70 and the control device 90 may communicate based on network information stored in the control device 90 before the control device 90 received the first network information i1.

[0165] According to this, for example, if the network based on the network information stored in the control device 90 is a secure network, the IoT device 70 and the control device 90 can communicate with each other using this secure network.

[0166] The network management system 5 of Example 13 is the network management system according to any one of Examples 7 to 9, and further includes a control device 90 that requests a connection to the IoT device 70. The control device 90 may output information included in the first network information i1 output from the first information output unit 21 as the second network information i2.

[0167] In this way, by outputting the information included in the first network information i1 as the second network information i2, it is possible to prevent the network of the IoT device 70 from being rewritten, thereby preventing the IoT device 70 from being connected to an unsafe network.

[0168] The IoT device 70A of Example 14 includes a first information output unit 21 that outputs first network information i1 of a network specified by the IoT device 70A, an information acquisition unit 10 that acquires second network information i2 of a network specified by a control device 90 that requests connection to the IoT device 70A, an information processing unit 50 that obtains a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70A based on the first network information i1 and the second network information i2, and a second information output unit 22 that outputs the judgment result R to the control device 90.

[0169] In this way, by obtaining the determination result R indicating whether or not to connect the control device 90 to the IoT device 70A based on the first network information i1 and the second network information i2, it is possible to prevent, for example, the network of the IoT device 70A from being unintentionally rewritten, thereby preventing the IoT device 70A from being connected to an unsafe network.

[0170] The network management method of Example 15 includes the steps of outputting first network information i1 of a network specified by the IoT device 70, acquiring second network information i2 of a network specified by a control device 90 requesting connection to the IoT device 70, obtaining a judgment result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 and the second network information i2, and outputting the judgment result R to the IoT device 70.

[0171] In this way, by obtaining the determination result R indicating whether or not to connect the control device 90 to the IoT device 70 based on the first network information i1 and the second network information i2, it is possible to prevent, for example, the network of the IoT device 70 from being unintentionally rewritten. This makes it possible to prevent the IoT device 70 from being connected to an unsafe network.

[0172] (Other Embodiments) Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.

[0173] In the above, examples have been given in which the IoT device 70 is an electrical device such as a refrigerator, a television, a projector, a printer, or a copier, but the IoT device 70 is not limited thereto. For example, the IoT device 70 may be an electrical device such as a lighting device, an air conditioner, an air purifier, a hair dryer, a refrigerator, a microwave oven, or an electric kettle.

[0174] In the above, examples have been given in which the spaces in which the IoT devices 70 are placed are common spaces in an office, conference rooms, guest rooms, and rental rooms in a building, but the spaces are not limited thereto. For example, the spaces in which the IoT devices 70 are placed may be floors of a house, an apartment building, or a facility.

[0175] Although the above example shows software that complies with the Matter standard being pre-installed in control device 90, this is not limiting. For example, control device 90 may install software that complies with the Matter standard by downloading application software that complies with the Matter standard.

[0176] Although the example in which the information generating unit 30 generates a two-dimensional barcode as the integrated authentication information ui has been described above, the present invention is not limited to this. For example, the information generating unit 30 may input the integrated authentication information ui into a near field communication (NFC) tag, and the first information output unit 21 may output the integrated authentication information ui via the NFC tag.

[0177] In the above example, the first network information i1 includes an SSID and a password, but the first network information i1 may include only the SSID and not the password. In this case, the integrated authentication information ui does not include a password, but the user may obtain the password through a route other than the network management device 1. If the integrated authentication information ui acquired by the control device 90 does not include a password, the control device 90 may display a screen requesting the user to enter a password. The control device 90 may be able to access the first network when the user enters a password.

[0178] In addition, this disclosure also includes forms obtained by making various modifications to the embodiments that a person skilled in the art would think of, and forms realized by arbitrarily combining the components and functions of each embodiment within the scope of the present disclosure.

[0179] 1 Network management device 5, 5A Network management system 10 Information acquisition unit 11 First information acquisition unit 12 Second information acquisition unit 21 First information output unit 22 Second information output unit 24 Display unit 30 Information generation unit 50 Information processing unit 60 Storage unit 70, 70A IoT device 74 Display input unit 90 Control device 91 Acquisition unit 92 Transmitting / receiving unit 95 Calculation unit 95a Network access unit 96 Storage unit d1, d2 Identification information i1 First network information i2 Second network information R Determination result ui Integrated authentication information

Claims

1. A network management device comprising: a first information acquisition unit that acquires first network information of a network specified by an IoT (Internet of Things) device; a first information output unit that outputs the first network information acquired by the first information acquisition unit; a second information acquisition unit that acquires second network information of a network specified by a control device that requests connection to the IoT device; an information processing unit that obtains a judgment result indicating whether or not to connect the control device to the IoT device based on the first network information and the second network information; and a second information output unit that outputs the judgment result to the IoT device.

2. The network management device according to claim 1, wherein the control device acquires the first network information output from the first information output unit and outputs the first network information as the second network information, and the second information acquisition unit acquires the second network information output from the control device.

3. The network management device according to claim 1, wherein the information processing unit obtains the determination result by comparing the first network information with the second network information.

4. The network management device of claim 3, further comprising a memory unit in which the first network information is stored, wherein the information processing unit obtains the judgment result of determining to connect the control device to the IoT device when the first network information stored in the memory unit matches the second network information output from the control device.

5. A network management device as described in claim 1, wherein the second information acquisition unit acquires the second network information output from the control device via the IoT device, and the second information output unit outputs the judgment result to the control device via the IoT device.

6. A network management device as described in claim 1, further comprising an information generation unit that generates integrated authentication information including the first network information and identification information of the IoT device, wherein the first information output unit outputs the integrated authentication information generated by the information generation unit to the control device, and the control device obtains the first network information from the integrated authentication information.

7. A network management system comprising: a network management device according to any one of claims 1 to 6; and an IoT device, wherein the IoT device pairs with the control device when the determination result indicates that the control device should be connected to the IoT device.

8. The network management system described in claim 7, wherein the IoT device receives the second network information output from the control device and transfers it to the second information acquisition unit, and receives the judgment result output from the second information output unit and transfers it to the control device.

9. The network management system according to claim 7, wherein the IoT device outputs the first network information to the first information acquisition unit by receiving a predetermined operation input.

10. The network management system of claim 7, further comprising a control device that requests a connection to the IoT device, wherein the control device accesses the IoT device based on the first network information, thereby outputting the second network information to the IoT device, and the IoT device outputs the second network information output from the control device to the network management device.

11. A network management system as described in claim 10, wherein when the information processing unit obtains a judgment result that the control device should be connected to the IoT device, the IoT device and the control device communicate using a network based on the first network information.

12. A network management system as described in claim 10, wherein when the information processing unit obtains a judgment result that the control device should be connected to the IoT device, the IoT device and the control device communicate based on network information that was stored in the control device before the control device received the first network information.

13. The network management system according to claim 7, further comprising a control device that requests a connection to the IoT device, wherein the control device outputs information contained in the first network information output from the first information output unit as the second network information.

14. An IoT (Internet of Things) device comprising: a first information output unit that outputs first network information of a network specified by the IoT device; an information acquisition unit that acquires second network information of a network specified by a control device that requests connection to the IoT device; an information processing unit that obtains a determination result indicating whether or not to connect the control device to the IoT device based on the first network information and the second network information; and a second information output unit that outputs the determination result to the control device.

15. A network management method including the steps of: outputting first network information of a network specified by an IoT (Internet of Things) device; acquiring second network information of a network specified by a control device requesting connection to the IoT device; obtaining a judgment result indicating whether or not to connect the control device to the IoT device based on the first network information and the second network information; and outputting the judgment result to the IoT device.

Citation Information

Patent Citations

  • Network system, information processing method, server, communication terminal, and program

    JP2019040510A