Method and apparatus for enhancing device-to-device communication security
A verification and call processing system for central-branch equipment communication strengthens security by verifying and controlling connections using preset policies, addressing vulnerabilities from stolen or acquired branch equipment.
Patent Information
- Application Number
- PCT/KR2025/008001
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-21
- Filing Date
- 2025-06-11
- Publication Date
- 2025-12-26
AI Technical Summary
Existing communication systems between central and branch equipment are vulnerable to security breaches when branch equipment is stolen or acquired by attackers, as they continue to allow unauthorized access due to lack of timely policy management and authentication.
Implement a verification and call processing system that verifies the trustworthiness of branch equipment attempting communication based on preset policies, using equipment identification information and location data to control and allow or block connections, enhancing security through the IKE protocol.
Resolves security vulnerabilities by ensuring only authorized branch equipment can reconnect securely to central equipment, preventing unauthorized access and enhancing overall communication security.
Smart Images

Figure KR2025008001_26122025_PF_FP_ABST
Abstract
Description
Method and device for enhancing security of communication between devices
[0001] The present invention relates to a technology for strengthening communication security between central equipment and branch equipment.
[0002] This invention claims the benefit of application No. 10-2024-0081135, filed June 21, 2024, the entire contents of which are incorporated herein by reference for all purposes.
[0003] In fields / industries where branches are operated nationwide from a head office, branches can be operated / managed from the head office through a communication network-based connection between the head office's central equipment and each branch's branch equipment.
[0004] If you want a reliable network connection between two locations in terms of security and quality, you can build it with a dedicated line. However, a dedicated line is not only very expensive to build and maintain, but also has the problem of having to build a new line every time the location changes.
[0005] Therefore, when operating / managing branches, it is often the case that networks between branches are connected through public networks such as the Internet, which are much cheaper to use than dedicated lines and do not cause network connection problems even when locations change.
[0006] And when connecting branch networks through public networks, a method to ensure the security and reliability of communication is required, and for this purpose, technologies such as VPN (Virtual Private Network) are used.
[0007] Furthermore, if each branch office has its own network and wants to establish a connection between the branches, a VPN device is installed at the gateway that connects to the Internet in each network, so that users or devices within the network automatically use the VPN when they need to communicate with a remote branch office without having to use the VPN individually.
[0008] To achieve this, when you first install VPN equipment and configure the initial connection, you will go through an authentication process. After authentication is complete, you can communicate via VPN without a separate authentication process.
[0009] Meanwhile, branches (e.g., construction sites, various dealerships, and other business locations) may frequently be closed or cease operation after operating on a small scale for a certain period of time.
[0010] However, small branches often do not have a designated security officer, and it is difficult to manage and set policies for branch equipment when the branch is closed or in use / closed in a timely manner.
[0011] Accordingly, if an attacker acquires or steals branch equipment used at a branch and reuses it, the attacker will be allowed to continue to connect to the central equipment according to the existing connection permission method, which may create a security vulnerability, such as allowing the attacker to access the head office's network.
[0012] Ultimately, when communicating between central and branch equipment using VPN, a solution will be needed to address security vulnerabilities that may arise when branch equipment is acquired or stolen by an attacker and reused.
[0013] The problem to be solved by the present invention is to provide a technique for strengthening security of communication between central and branch equipment, which resolves a security vulnerability that may arise when an attacker acquires or steals branch equipment and reuses it.
[0014] A method for strengthening security of communication between devices according to a first aspect of the present invention comprises: a verification step of verifying whether a communication connection attempt of a branch device attempting a communication connection to a central device is trustworthy according to a preset policy, using a specific call of the branch device; a communication connection step of performing a subsequent call processing procedure according to the specific call, if the communication connection attempt is verified to be trustworthy, so that a communication connection can proceed between the central device and the branch device; and the policy may be a policy set for branch devices that have been previously permitted to be connected to the central device through a previous authentication procedure.
[0015] A device for strengthening security of communication between devices according to a second aspect of the present invention includes: a verification unit that verifies whether a communication connection attempt of a branch device attempting a communication connection to a central device is trustworthy according to a preset policy by using a specific call of the branch device; a call processing unit that, if the communication connection attempt is verified as trustworthy, performs a subsequent call processing procedure according to the specific call to enable a communication connection to proceed between the central device and the branch device; and the policy may be a policy set for a branch device that has been previously permitted to make a communication connection to the central device through a previous authentication procedure.
[0016] According to embodiments of the present invention, a new method of strengthening security of communication between central and branch equipment is realized, which verifies and controls (blocks or allows) communication connection of branch equipment after initial installation / connection to central equipment.
[0017] Accordingly, according to the present invention, by verifying and allowing the communication connection of the branch equipment after the initial installation / connection to the central equipment, it is possible to resolve existing security vulnerabilities that may arise in a situation where the branch equipment is acquired or stolen by an attacker and reused, and to enhance security.
[0018] Figure 1 is a conceptual diagram explaining a communication environment between central equipment and branch equipment to which the present invention is applied.
[0019] FIG. 2 is a schematic diagram specifically explaining a device for enhancing security of inter-equipment communication according to one embodiment of the present invention.
[0020] FIG. 3 and FIG. 4 are flowcharts illustrating the operation of a method for enhancing security of communication between devices according to one embodiment of the present invention.
[0021] The present invention is susceptible to various modifications and embodiments. Specific embodiments are illustrated and described in detail in the drawings. However, this is not intended to limit the present invention to specific embodiments, but rather to encompass all modifications, equivalents, and alternatives falling within the spirit and technical scope of the present invention. Throughout the description of each drawing, similar reference numerals have been used to designate similar components.
[0022] When a component is referred to as being "connected" or "connected" to another component, it should be understood that the connection may be direct or intervening. Conversely, when a component is referred to as being "directly connected" or "connected" to another component, it should be understood that there are no intervening components.
[0023] The terminology used in this application is only used to describe specific embodiments and is not intended to limit the present invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, it should be understood that the terms "comprise" or "have" indicate the presence of a feature, number, step, operation, component, part, or combination thereof described in the specification, but do not preclude the possibility of the presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.
[0024] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and will not be interpreted in an idealized or overly formal sense unless explicitly defined herein.
[0025] Hereinafter, the present invention will be described with reference to the attached drawings.
[0026] The present invention relates to a technology for strengthening communication security between central equipment and branch equipment.
[0027] In fields / industries where branches are operated nationwide from a head office, branches can be operated / managed from the head office through a communication network (e.g., a public network such as the Internet)-based connection between the head office's central equipment and each branch's branch equipment.
[0028] In cases like this, where a connection based on a communication network (e.g., a public network such as the Internet) is supported between central and branch equipment, a secure communication connection is very important, and among the various technologies used for this purpose, a Virtual Private Network (VPN) is used.
[0029] In other words, VPN technology is a representative technology method used to secure the security and reliability of communication between branch equipment (e.g., construction sites, various dealerships, and other business locations) and the corresponding central equipment of the head office.
[0030] In relation to this, the branch equipment that is initially installed can be connected to the central equipment of the head office by entering the address information and basic authentication information of the central equipment of the head office that will manage it, and the central equipment allows the connection of the branch equipment through a set authentication procedure.
[0031] Figure 1 is a conceptual diagram explaining a communication environment between central equipment and branch equipment to which the present invention is applied.
[0032] According to the communication using VPN between the central equipment and branch equipment (A, B, ..., N), the branch equipment that is installed first (hereinafter, branch equipment A) can connect to the central equipment of the head office through the communication network (1) by entering the address information (e.g., IP address) and basic authentication information (e.g., serial number of branch equipment A) of the central equipment of the head office that will manage it. At this time, the central equipment allows the connection of branch equipment A through a set authentication procedure.
[0033] And, the existing method in which the central equipment allows the connection of branch equipment A is to continue to allow the communication connection since branch equipment A is already an authenticated branch equipment after the initial installation / connection (or after the communication connection has already been allowed once).
[0034] Meanwhile, branches (e.g., construction sites, various dealerships, and other business locations) may frequently be closed or cease operation after operating on a small scale for a certain period of time.
[0035] However, small branches often do not have a designated security officer, and it is difficult to manage and set policies for branch equipment when the branch is closed or in use / closed in a timely manner.
[0036] Accordingly, if an attacker acquires or steals branch equipment used at a branch and reuses it, the attacker will be allowed to continue to connect to the central equipment according to the existing connection permission method, which may create a security vulnerability, such as allowing the attacker to access the head office's network.
[0037] Ultimately, in the case of communication using VPN between central and branch equipment (A, B, ..., N), a solution is needed to resolve security vulnerabilities that may arise when an attacker acquires or hijacks branch equipment and reuses it.
[0038] Accordingly, the present invention proposes a new method of strengthening security for communication between central and branch equipment to resolve security vulnerabilities that may arise when branch equipment is acquired or stolen by an attacker and reused.
[0039] Specifically, the present invention seeks to solve existing security vulnerabilities and enhance security that may arise when an attacker acquires or hijacks branch equipment and reuses it by implementing a device-to-device communication security enhancement technique that verifies and controls (blocks or allows) the communication connection of branch equipment after initial installation / connection to central equipment.
[0040] Below, a device-to-device communication security enhancement device that implements the device-to-device communication security enhancement technique of the present invention will be described in detail.
[0041] An inter-device communication security enhancement device (100) according to one embodiment of the present invention may be configured to include a verification unit (100) and a call processing unit (120).
[0042] The device (100) for enhancing security of communication between devices of the present invention may be a central device of a head office that operates / manages branch devices (A, B,...N) through a connection based on a communication network (1, e.g., the Internet).
[0043] Of course, the device (100) for enhancing security of communication between devices of the present invention may be a separate device located between branch devices (A, B,...N) and central devices.
[0044] However, in the following description with reference to FIG. 2, the device-to-device communication security enhancement device (100) will be described as an embodiment in which the device-to-device communication security enhancement device (100) is a central device. Therefore, in the following description, the device-to-device communication security enhancement device (100) of the present invention will be described as a "central device (100)."
[0045] In addition, in the following description, a communication environment using VPN between the central equipment (100) and branch equipment (A, B,..., N) as shown in Fig. 1 will be explained.
[0046] Before going into a detailed explanation, the core components of the device-to-device communication security enhancement technique of the present invention will be briefly explained.
[0047] The central equipment (100) sets and manages policies based on the information of each branch equipment that has allowed communication connection (e.g., equipment identification information_serial number, connection location identification information_Mac address of terminal equipment, IP address, etc.) during the authentication procedure at the time of initial installation / connection.
[0048] And, the central equipment (100) verifies and controls (blocks or allows) the communication connection according to the policy set / managed by the branch equipment that attempts to establish a communication connection to the central equipment (100) after the initial installation / connection (or after the communication connection has already been permitted once) through a previous authentication procedure (e.g., the authentication procedure at the time of initial installation / connection).
[0049] Accordingly, according to the present invention, in VPN communication between central equipment (100) and branch equipment (A, B,..., N), by verifying and allowing communication connection of branch equipment after initial installation / connection to central equipment (100), it is possible to resolve existing security vulnerabilities that are a concern in the event that branch equipment is acquired or stolen and reused by an attacker.
[0050] Hereinafter, each component of the device-to-device communication security enhancement device of the present invention, i.e., the central device (100), will be described with reference to FIG. 2.
[0051] The verification unit (110) is responsible for verifying whether the communication connection attempt of the branch equipment is trustworthy according to a preset policy by using a specific number of the branch equipment attempting a communication connection to the central equipment (100).
[0052] The call processing unit (120), if the communication connection attempt is verified as reliable based on the verification result of the verification unit (110), performs subsequent call processing procedures according to the specific call, thereby enabling a communication connection to proceed between the central equipment (100) and the branch equipment that attempted the communication connection.
[0053] Here, a specific call refers to a key exchange attempt call transmitted by a branch device to a central device to generate a security key used for communication between the central device and the branch device.
[0054] To be more specific, VPN-based communication supports secure communication by generating a security key through key exchange between devices based on the IKE protocol, which is a key exchange standard, and encrypting packets based on this key.
[0055] In the present invention, a key exchange attempt call (IKE) transmitted from a branch device to a central device (100) in VPN-based communication is used as a “specific call.”
[0056] To explain an example by mentioning branch equipment A among branch equipment (A, B, ..., N), branch equipment A, which desires a communication connection to the central equipment (100) in the present invention, first transmits a key exchange attempt call (IKE) to the central equipment (100) to exchange keys between the equipment.
[0057] At this time, branch equipment A can transmit, in the VID Payload of the key exchange attempt call (IKE), equipment identification information of branch equipment A (e.g., serial number) and connection location identification information (e.g., Mac address, IP address of the end equipment, etc.) that identifies the end equipment of the communication network (1) to which branch equipment A is connected.
[0058] At this time, the terminal equipment of the communication network (1) to which branch equipment A is connected is a terminal equipment on the branch equipment side that can be identified from the perspective of the communication network (1), and may be various types of equipment such as gateway equipment or a router.
[0059] Accordingly, when branch equipment A first transmits a key exchange attempt call (IKE) to the central equipment (100) for communication connection to the central equipment (100), the central equipment (100, particularly the verification unit (110)) can identify equipment identification information (e.g., serial number) and connection location identification information (e.g., Mac address, IP address, etc. of the end equipment) from this key exchange attempt call (IKE).
[0060] Accordingly, the verification unit (110) can use the information obtained from the key exchange attempt (IKE) of branch equipment A to verify whether the communication connection attempt of branch equipment A is trustworthy according to the preset policy (105).
[0061] The policy (105) set here means a policy set based on information (e.g., equipment identification information_serial number, connection location identification information_Mac address of terminal equipment, IP address, etc.) of branch equipment that is permitted to connect to the central equipment (100) through a previous authentication procedure (e.g., authentication procedure at the time of initial installation / connection).
[0062] To explain a specific embodiment, in the present invention, the policy (105) may be set up in a structure including a list of branch equipment (hereinafter, “management list”) that is permitted to have a communication connection to the central equipment (100), a list of branch equipment (hereinafter, “block list”) that blocks a communication connection through verification, and setting information for verification (e.g., non-connection period, response options for each verification result, etc.).
[0063] Accordingly, the central equipment (100), especially the verification unit (110), checks whether branch equipment A exists in the management list / block list within the policy (105) based on the equipment identification information (e.g., serial number) obtained from the key exchange attempt (IKE) of branch equipment A.
[0064] The verification unit (110) can determine that branch equipment A is installed / connected for the first time if it does not exist in the management list in the policy (105).
[0065] In this case, the verification unit (110) can perform authentication using basic authentication information, i.e., the serial number of branch equipment A, according to the authentication procedure at the time of initial installation / connection, and allow VPN communication connection.
[0066] At this time, the verification unit (110) can update the management list in the policy (105) by reflecting the information (e.g., equipment identification information_serial number, connection location identification information_Mac address of terminal equipment, IP address, etc.) identified from the current key exchange attempt call (IKE) of branch equipment A.
[0067] Meanwhile, if branch equipment A exists in the management list within the policy (105), the verification unit (110) determines that the communication connection attempt is for reuse after the initial installation / connection (or after the communication connection has already been permitted once). Upon such determination, the verification unit (110) can verify whether the communication connection attempt of branch equipment A is trustworthy based on the configuration information within the policy (105).
[0068] To explain a more specific embodiment, in the present invention, the policy (105) can be set to verify the communication connection attempt of the branch equipment according to a first verification condition that determines whether the time for which the communication between the branch equipment and the central equipment has been disconnected is within a preset disconnection period, for branch equipment in the management list, that is, branch equipment for which communication connection to the central equipment (100) has been previously permitted, and a second verification condition that determines whether the terminal equipment of the communication network (1) to which the branch equipment is connected at the time of attempting the communication connection is the same as the terminal equipment at the time of the authentication procedure (e.g., the authentication procedure at the time of initial installation / connection).
[0069] Here, the verification process for the communication connection attempt of branch equipment A will be explained with a more specific example as follows.
[0070] The verification unit (110) can determine that a communication connection attempt is trustworthy if both the first and second verification conditions described above are satisfied based on the information (e.g., equipment identification information_serial number, connection location identification information_end device MAC address, IP address, etc.) identified from the current key exchange attempt (IKE) of branch device A in the management list within the policy (105) and the policy (105).
[0071] In this case, when both the first and second verification conditions are satisfied, branch equipment A is attempting to reuse and establish a communication connection with the central equipment (100) without exceeding the set disconnection period, and at this time, the terminal equipment of the communication network (1) being connected is the same as the terminal equipment connected during the previous authentication procedure (e.g., the authentication procedure at the time of initial installation / connection), which means that there is no change in the previously authenticated network environment.
[0072] Accordingly, if the call processing unit (120) determines / verifies that the communication connection attempt of branch equipment A is reliable as a result of the verification of the verification unit (110), it performs the subsequent call processing procedure (i.e., inter-equipment key exchange call processing -> security key generation) according to the key exchange attempt call (IKE) of branch equipment A to allow the communication connection to proceed between the central equipment (100) and branch equipment A, thereby allowing the VPN communication connection.
[0073] At this time, the verification unit (110) updates the management list within the policy (105) by reflecting information (e.g., verification result, verification time, etc.) about the branch equipment (e.g., branch equipment A) that allowed communication connection, thereby managing the policy (105) to be used in subsequent verification in the latest state.
[0074] Meanwhile, the verification unit (110) may determine that a communication connection attempt is not trustworthy in the case where both the first and second verification conditions described above are not satisfied, based on the information (e.g., equipment identification information_serial number, connection location identification information_end device MAC address, IP address, etc.) identified from the key exchange attempt call (IKE) of branch device A and the policy (105).
[0075] If the call processing unit (120) determines / verifies that the communication connection attempt of branch equipment A is unreliable as a result of the verification of the verification unit (110), the call processing unit (120) can block the VPN communication connection by preventing the communication connection from proceeding between the central equipment (100) and branch equipment A by not performing the subsequent call processing procedure (i.e., inter-equipment key exchange call processing -> security key generation) according to the key exchange attempt call (IKE) of branch equipment A.
[0076] Meanwhile, the verification unit (110) may determine that a communication connection attempt is a suspicious attempt if any one of the first and second verification conditions described above is not satisfied, based on the information (e.g., equipment identification information_serial number, connection location identification information_end device MAC address, IP address, etc.) identified from the key exchange attempt call (IKE) of branch device A and the policy (105).
[0077] For example, if the first verification condition is unsatisfied and the second verification condition is satisfied, it can be judged as a suspicious attempt. In this case, since the terminal equipment of the communication network (1) that branch equipment A is connected to and the terminal equipment connected during the previous authentication procedure (e.g., the authentication procedure at the time of initial installation / connection) are the same, there is no change in the previously authenticated network environment, but it means that branch equipment A has not been used for a long time exceeding the set non-connection period.
[0078] In this case, the call processing unit (120) may perform subsequent call processing procedures (i.e., inter-equipment key exchange call processing -> security key generation) according to the verification result response option in the policy (105) of the branch equipment A this time in accordance with the key exchange attempt call (IKE) and allow the VPN communication connection to proceed between the central equipment (100) and branch equipment A, but may also perform actions such as notifying the administrator that it is a suspicious attempt.
[0079] Meanwhile, if the verification unit (110) determines / verifies that the communication connection attempt of branch equipment A is unreliable as described above, branch equipment A can be included in the blocking list within the policy (105) and managed.
[0080] That is, the verification unit (110) can update the blocking list within the policy (105) by reflecting the information (e.g., equipment identification information_serial number, connection location identification information_end device MAC address, IP address, etc.) identified from the current key exchange attempt call (IKE) of branch device A.
[0081] Accordingly, the verification unit (110) may decide to block the communication connection with the central equipment (100) without going through the process of verifying whether the communication connection attempt is trustworthy for branch equipment (e.g., branch equipment A) that exists in the blocking list in the policy (105).
[0082] For example, if branch equipment A exists in the blocking list in the policy (105), the verification unit (110) may determine that the communication connection attempt of branch equipment A is an attempt for reuse after the initial installation / connection (or after the communication connection has already been allowed once), but is already verified as untrustworthy.
[0083] Accordingly, the verification unit (110) may decide to block the communication connection between the central equipment (100) and branch equipment A without a verification process when receiving a key exchange attempt call (IKE) from a branch equipment (e.g., branch equipment A) existing in the blocking list, and the call processing unit (120) may block the VPN communication connection by preventing the communication connection from proceeding between the central equipment (100) and branch equipment A by not performing the subsequent call processing procedure according to the key exchange attempt call (IKE) (i.e., key exchange call processing between equipment -> security key generation).
[0084] Instead, the central equipment (100) of the present invention can enable a communication connection to the central equipment (100) to proceed through an authentication procedure for the first connection to the central equipment (100) for a branch equipment (e.g., branch equipment A) in the blocking list that attempts a communication connection to the central equipment (100).
[0085] For example, when the central equipment (100, particularly the verification unit (110)) of the present invention receives a key exchange attempt call (IKE) from a branch equipment (e.g., branch equipment A) existing in the blocking list, it blocks the VPN communication connection by first preventing the communication connection between the central equipment (100) and branch equipment A from proceeding as described above, but by deleting the information of branch equipment A (e.g., information according to existing authentication / verification) within the equipment and returning it to the state for the first connection, and then inducing the authentication procedure for the first connection, it is possible to allow the communication connection between the central equipment (100) and branch equipment A to proceed through the authentication procedure for the first connection of branch equipment A to the central equipment (100).
[0086] Meanwhile, the verification result of the verification unit (110) according to the combination of the first and second verification conditions of the tactic and the subsequent operation of the call processing unit (120) corresponding thereto are only one embodiment.
[0087] In the present invention, depending on how the response options for each verification result in the policy (105) are set, the verification result of the verification unit (110) and the subsequent operation of the call processing unit (120) corresponding thereto may be performed in various ways in addition to the above embodiments.
[0088] As described above, according to embodiments of the present invention, in the case of communication between a central device and a branch device (e.g., VPN communication), a policy is set based on information of each branch device that allows a communication connection (e.g., device identification information_serial number, connection location identification information_Mac address of the terminal device, IP address, etc.) in the authentication procedure at the time of initial installation / connection between the central device and the branch device, and thereafter (or, after the communication connection has already been allowed once), a communication connection can be verified and controlled (blocked or allowed) according to the policy that has been set / managed for the branch device attempting a communication connection to the central device, thereby realizing a new method of strengthening security for communication between devices.
[0089] Accordingly, according to the present invention, by verifying and allowing the communication connection of branch equipment after the initial installation / connection to the central equipment, it is possible to resolve existing security vulnerabilities that may arise when an attacker acquires or steals branch equipment that is relatively vulnerable to theft, theft, etc. and reuses it, thereby enhancing security.
[0090] In particular, in the present invention, in realizing the tactical device-to-device communication security enhancement technique, by applying a standard protocol (e.g., IKE protocol) already used in device-to-device communication (VPN communication) without a separate protocol, basic VPN communication / interoperability may not be hindered even with VPN equipment of other vendors to which the present invention is not applied.
[0091] Hereinafter, the operation flow of a technique / method for strengthening security of inter-device communication according to an embodiment of the present invention will be described with reference to FIGS. 3 and 4.
[0092] In the following description, as an example in which the device-to-device communication security enhancement device (100) of the present invention is implemented as a central device of the head office, the device-to-device communication security enhancement device (100) of the present invention will be described by referring to it as a “central device (100).”
[0093] In addition, in the following description, a communication environment using VPN between the central equipment (100) and branch equipment (A, B,..., N) as shown in Fig. 1 will be explained.
[0094] First, referring to FIG. 3, according to the method for strengthening security of communication between devices of the present invention, the central device (100) basically sets and manages a policy (105) for application of the present invention.
[0095] Here, the policy (105) can be set up in a structure that includes a list of branch equipment (hereinafter, management list) that is allowed to have a communication connection to the central equipment (100), a list of branch equipment (hereinafter, block list) that is to have a communication connection blocked through verification, and setting information for verification (e.g., non-connection period, response options for each verification result, etc.).
[0096] The branch equipment (10) initially installed at the branch can be connected to the central equipment (100) by entering the address information and basic authentication information (e.g., serial number) of the head office central equipment (100) that will manage it, and the central equipment (100) allows the communication connection of the branch equipment (10) through a set authentication procedure (S10).
[0097] At this time, the branch equipment (10) first transmits a key exchange attempt call (IKE) to the central equipment (100) for communication using VPN. According to the present invention, the branch equipment (10) transmits the VID payload of this key exchange attempt call (IKE) including equipment identification information (e.g., serial number) and connection location identification information (e.g., Mac address, IP address of the end equipment, etc.).
[0098] Accordingly, according to the method for strengthening security of communication between devices of the present invention, the central device (100) can update the information of the branch device (10) (e.g., device identification information_serial number, connection location identification information_Mac address of terminal device, IP address, etc.) identified from the key exchange attempt call (IKE) in the authentication procedure at the time of initial installation / connection by reflecting it in the policy (105, particularly the management list) settings (S20).
[0099] When the branch device (10) attempts to reconnect communication to the central device (100) after the initial installation / connection of the tactic (or after the communication connection has already been permitted once), the branch device (10) first transmits a key exchange attempt call (IKE) to the central device (100) for communication using VPN, and at this time, the VID payload of the key exchange attempt call (IKE) includes equipment identification information (e.g., serial number) and connection location identification information (e.g., Mac address, IP address, etc. of the end device) and transmits them (S30).
[0100] According to the method for strengthening security of communication between devices of the present invention, the central device (100) can obtain device identification information (e.g., serial number) and connection location identification information (e.g., MAC address, IP address, etc. of the end device) from the key exchange attempt call (IKE).
[0101] Accordingly, the central equipment (100) uses the information obtained from the key exchange attempt (IKE) of the branch equipment (10) to verify whether the current communication connection attempt of the branch equipment (10) is trustworthy according to the preset policy (105) (S40).
[0102] According to the method for strengthening security of communication between devices of the present invention, if the communication connection attempt of the branch device (10) is verified as reliable in the verification at step S40, the central device (100) performs the subsequent call processing procedure (i.e., inter-device key exchange call processing -> security key generation) according to the key exchange attempt call (IKE) of the branch device (10) to allow the communication connection to proceed between the central device (100) and the branch device (10) (S50, S60), thereby allowing the VPN communication connection.
[0103] Hereinafter, with reference to FIG. 4, the process of verifying a communication connection attempt of a branch device (10) in the method for strengthening communication security between devices of the present invention will be described in detail.
[0104] According to the method for strengthening security of communication between devices of the present invention, the central device (100) can identify device identification information (e.g., serial number) and connection location identification information (e.g., Mac address, IP address, etc. of the terminal device) from a key exchange attempt call (IKE) received from a branch device (10).
[0105] Accordingly, the central equipment (100) can use the information obtained from the key exchange attempt (IKE) of the branch equipment (10) to verify whether the communication connection attempt of the branch equipment (10) is trustworthy according to the preset policy (105).
[0106] Specifically, the central equipment (100) checks whether the branch equipment (10) exists in the management list / block list within the policy (105) based on the equipment identification information (e.g., serial number) obtained from the key exchange attempt (IKE) of the branch equipment (10) (S42, S43).
[0107] The central equipment (100) can block the VPN communication connection of the branch equipment (10) first by preventing the communication connection between the central equipment (100) and the branch equipment (10) from proceeding (S46) by not performing the subsequent call processing procedure (i.e., key exchange call processing between equipment -> security key generation) according to the current key exchange attempt call (IKE) (S42 Yes).
[0108] The central equipment (100) blocks the VPN communication connection by preventing the communication connection between the central equipment (100) and the branch equipment (10) from proceeding as described above (S46), but returns the state for the first connection by deleting the information of the branch equipment (10) (e.g., information according to existing authentication / verification) inside the equipment and inducing the authentication procedure for the first connection, thereby allowing the communication connection between the central equipment (100) and the branch equipment (10) to proceed through the authentication procedure for the first connection of the branch equipment (10) to the central equipment (100) (S48).
[0109] Meanwhile, if the branch equipment (10) exists in the management list (S42 No, S43 Yes), the central equipment (100) can verify the communication connection attempt of the branch equipment (10) by combining the first and second verification conditions described above (S44) based on the information (e.g., equipment identification information_serial number, connection location identification information_Mac address of the terminal equipment, IP address, etc.) identified from the current key exchange attempt call (IKE) of the branch equipment (10) and the policy (105).
[0110] Specifically, the central equipment (100) can determine / verify that a communication connection attempt is trustworthy when both the first and second verification conditions described above are satisfied, based on the information (e.g., equipment identification information_serial number, connection location identification information_end device MAC address, IP address, etc.) identified from the current key exchange attempt (IKE) of the branch equipment (10) and the policy (105) (S44 Yes).
[0111] Accordingly, if the communication connection attempt of the branch equipment (10) is verified as reliable, the central equipment (100) performs the subsequent call processing procedure (i.e., inter-equipment key exchange call processing -> security key generation) according to the key exchange attempt call (IKE) of the branch equipment (10) to allow the communication connection to proceed between the central equipment (100) and the branch equipment (10) (S45), thereby allowing the VPN communication connection.
[0112] At this time, the central equipment (100) updates the management list within the policy (105) by reflecting information (e.g., verification result, verification time, etc.) about the branch equipment (10) that allowed communication connection, thereby managing the policy (105) to be used in subsequent verification in the latest state.
[0113] Meanwhile, the central equipment (100) can determine / verify that the communication connection attempt is unreliable in the case where both the first and second verification conditions described above are not satisfied, based on the information (e.g., equipment identification information_serial number, connection location identification information_end device MAC address, IP address, etc.) identified from the key exchange attempt call (IKE) of the branch equipment (10) and the policy (105) (S44 No).
[0114] Accordingly, if the communication connection attempt of the branch equipment (10) is verified as unreliable, the central equipment (100) can block the VPN communication connection by not performing the subsequent call processing procedure (i.e., inter-equipment key exchange call processing -> security key generation) according to the key exchange attempt call (IKE) of the branch equipment (10) this time, thereby preventing the communication connection from proceeding between the central equipment (100) and the branch equipment (10) (S46).
[0115] At this time, if the central equipment (100) verifies that the communication connection attempt of the branch equipment (10) is unreliable as described above, the information of the branch equipment (10) (e.g., equipment identification information_serial number, connection location identification information_Mac address of the terminal equipment, IP address, etc.) can be reflected by adding or updating it to the blocking list in the policy (105).
[0116] Meanwhile, the central equipment (100) can determine that the branch equipment (10) is installed / connected for the first time if the branch equipment (10) also exists in the management list (S43 No).
[0117] In this case, the central equipment (100) can perform authentication using the basic authentication information, i.e., the serial number of the branch equipment (10), according to the authentication procedure at the time of initial installation / connection, and allow VPN communication connection (S47, same as S20 of FIG. 3).
[0118] At this time, the central equipment (100) can update the management list in the policy (105) by reflecting information (e.g., equipment identification information_serial number, connection location identification information_Mac address of terminal equipment, IP address, etc.) identified from the current key exchange attempt call (IKE) of the branch equipment (10).
[0119] According to embodiments of the present invention as described above, in communication between a central device and a branch device (e.g., VPN communication), a policy is set based on information of each branch device that allows a communication connection (e.g., device identification information_serial number, connection location identification information_Mac address of terminal device, IP address, etc.) at the time of initial installation / connection between the central device and the branch device, and thereafter (or, after a communication connection has already been allowed once), the communication connection can be verified and controlled (blocked or allowed) according to the policy that has been set / managed for the branch device that attempts a communication connection to the central device.
[0120] Accordingly, according to the present invention, by verifying and allowing the communication connection of the branch equipment after the initial installation / connection to the central equipment, it is possible to resolve existing security vulnerabilities that may arise in a situation where the branch equipment is acquired or stolen by an attacker and reused, and to enhance security.
[0121] The technique / method for strengthening security of communication between devices according to an embodiment of the present invention may be implemented in the form of program commands that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program commands, data files, data structures, etc., alone or in combination. The program commands recorded on the medium may be those specially designed and configured for the present invention or may be those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program commands such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. The above hardware device may be configured to operate as one or more software modules to perform the operations of the present invention, and vice versa.
[0122] As described above, the present invention has been described with specific details such as specific components and limited embodiments and drawings, but these are provided only to help understanding of the present invention, and the present invention is not limited to the above embodiments, and those with ordinary knowledge in the field to which the present invention pertains can make various modifications and variations from this description.
[0123] Therefore, the spirit of the present invention should not be limited to the described embodiments, and all things that are equivalent or equivalent to the scope of the following claims as well as the claims are considered to fall within the scope of the spirit of the present invention.
Claims
1. A verification step that verifies whether the communication connection attempt of the branch equipment is trustworthy according to a preset policy by using a specific number of the branch equipment attempting a communication connection to the central equipment; If the above communication connection attempt is verified as reliable, a communication connection step is included to perform subsequent call processing procedures according to the specific call so that a communication connection can proceed between the central equipment and the branch equipment; The above policy is, A method for strengthening security of communication between devices, characterized in that the policy is set based on information of branch devices that have been previously permitted to connect to the central device through a previous authentication procedure.
2. In paragraph 1, The above specific number is, A method for enhancing security of communication between central and branch equipment, characterized in that the key exchange attempt signal is transmitted from the branch equipment to the central equipment to generate a security key used for communication between the central equipment and the branch equipment.
3. In paragraph 1, The above branch equipment is, In the above-mentioned specific number transmitted to the above-mentioned central equipment, the connection location identification information that identifies the terminal equipment of the communication network to which the above-mentioned branch equipment is connected is included and transmitted, The above verification step is, A method for strengthening security of communication between devices, characterized in that the connection connection attempt of the branch device is verified according to the policy using the connection location identification information identified from the specific number.
4. In paragraph 1, The above policy is, For branch equipment that has already been permitted to connect to the above central equipment, A method for strengthening security of communication between devices, characterized in that the communication connection attempt of the branch device is verified according to a first verification condition for determining whether the time for which communication between the branch device and the central device remains disconnected is within a preset disconnection period, and a second verification condition for determining whether the terminal device of the communication network to which the branch device is connected at the time of attempting the communication connection is the same as the terminal device at the time of the authentication procedure.
5. In paragraph 4, The above verification step is, Information obtained from a specific number of branch equipment attempting to establish a communication connection with the above central equipment and according to the above policy, A method for enhancing security of communication between devices, characterized in that a communication connection attempt is judged as trustworthy when the first and second verification conditions are satisfied, a communication connection attempt is judged as unreliable when the first and second verification conditions are not satisfied, and a communication connection attempt is judged as a suspicious attempt when either of the first and second verification conditions is not satisfied.
6. In paragraph 1, Step of including the branch equipment in a blocking list if the above communication connection attempt is verified as unreliable; A method for strengthening security of communication between devices, characterized in that it further includes a step of allowing a communication connection to proceed to the central device through an authentication procedure for the first connection to the central device for a branch device in the blocking list attempting to establish a communication connection to the central device.
7. In the device for strengthening security of communication between devices, A verification unit that verifies whether the communication connection attempt of the branch equipment is trustworthy according to a preset policy by using a specific number of the branch equipment attempting a communication connection to the central equipment; If the above communication connection attempt is verified as reliable, a call processing unit is included that performs subsequent call processing procedures according to the specific call to enable a communication connection to proceed between the central equipment and the branch equipment; The above policy is, A device for strengthening security of communication between devices, characterized in that the policy is set based on information of branch devices that have been previously permitted to connect to the central device through a previous authentication procedure.
8. In paragraph 7, The above specific number is, A device for enhancing security of communication between central and branch equipment, characterized in that it is a key exchange attempt signal transmitted from branch equipment to central equipment for generating a security key used for communication between central equipment and branch equipment.
9. In paragraph 7, The above policy is, For branch equipment that has already been permitted to connect to the above central equipment, A device for enhancing security of communication between devices, characterized in that it is set to verify a communication connection attempt of a branch device according to a first verification condition for determining whether the time for which communication between the branch device and the central device remains disconnected is within a preset disconnection period, and a second verification condition for determining whether the terminal device of the communication network to which the branch device is connected at the time of attempting the communication connection is the same as the terminal device at the time of the authentication procedure.
10. A step of verifying whether the communication connection attempt of the branch equipment is trustworthy according to a preset policy by using a specific number of the branch equipment that is combined with hardware and attempts to establish a communication connection with the central equipment. If the above communication connection attempt is verified as reliable, the step of executing subsequent call processing procedures according to the specific call is stored in the medium to enable a communication connection to proceed between the central equipment and the branch equipment. The above policy is, A computer program characterized in that the policy is set based on information of branch equipment that has been previously permitted to connect to the central equipment through a previous authentication procedure.
Citation Information
Patent Citations
Authentication system and method for device attempting connection
KR1020140043071A
Sleeping mattress cleaning and disinfection device
KR1020230151193A
System and method for hybrid security
KR102206847B1
Device access authorization via connected user equipment
US20220399996A1
Access Control Method and Related Device
US20240048528A1