System for performing remote operation between firewall-equipped networks or devices
Claim Score by NHIP
Abstract
A remote operation system is disclosed which is used with a network environment in which a unit that provides remote operation services through networks and a unit that receives the services are each safeguarded by a firewall (or "each equipped with a firewall for") from an external network. The remote operation service receiving unit sets up a connection A with the firewall installed on the remote operation service providing unit side and transmits security check information to that firewall. The firewall checks this security check information and then sets up a connection B with the remote operation service providing unit via its associated internal network when it is determined that the security check information has been sent from a contract user unit. Thereby, information used for remote operation can be transmitted between the two units over a logical path composed of the connections A and B.

Term
Term ended
Projected expiry passed 8 February 2019, 7.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
32 claims: 18 independent, 14 dependent
- 1A system which is provided with a servicing unit connected to a first internal network in which a first firewall is installed for an external network and a serviced unit connected to a second internal network in which a second firewall is installed for said external network, wherein said servicing unit performs a remote operation on said serviced unit through said external network, said serviced unit comprising:packet communications means for transmitting an identifier specifying the address of said servicing unit connected to said first internal network, setting up a connection with said servicing unit via said second firewall and said first firewall, and transmitting packets to or from said servicing unit over said connection;and remote operation execution means for fetching remote operation directive information from packets received by said packet communications means and performing a remote operation on said serviced unit as indicated by said remote operation directive information.
- 2A system which is provided with a servicing unit connected to a first internal network in which a first firewall is installed for an external network and a serviced unit connected to a second internal network in which a second firewall is installed for said external network, wherein said servicing unit performs a remote operation on said serviced unit through said external network, said serviced unit comprising:packet communications means for setting up a connection with said first firewall via said second firewall and transmitting packets to or from said first firewall over said connection;and security check means for checking remote operation directive information contained in packets received by said packet communications means for validity;remote operation execution means for performing a remote operation on said serviced unit as indicated by said remote operation directive information which has been validated by said security check means;and execution result return means for returning the result of execution of said remote operation by said remote operation execution means to said first firewall through said packet communications means.
- 3A system which is provided with a servicing unit connected to a first internal network in which a first firewall is installed for the Internet and a serviced unit connected to a second internal network in which a second firewall is installed for the Internet, wherein said servicing unit performs a remote operation on said serviced unit through said Internet, said serviced unit comprising:packet communications means for transmitting an identifier specifying the address of said servicing unit connected to said first internal network, setting up a connection with said servicing unit via said second firewall and said first firewall, and transmitting packets to or from said servicing unit over said connection;and remote operation execution means for fetching remote operation directive information from packets received by said packet communications means and performing a remote operation on said serviced unit as indicated by said remote operation directive information.
- 4A system which is provided with a servicing unit connected to a first internal network in which a first firewall is installed for the Internet and a serviced unit connected to a second internal network in which a second firewall is installed for said Internet, wherein said servicing unit performs a remote operation on said serviced unit through said Internet, said serviced unit comprising:packet communications means for setting up a connection with said first firewall via said second firewall and transmitting packets to or from said first firewall over said connection;and security check means for checking remote operation directive information contained in packets received by said packet communications means for validity;remote operation execution means for performing a remote operation on said serviced unit as indicated by said remote operation directive information which has been validated by said security check means;and execution result return means for returning the result of execution of said remote operation by said remote operation execution means to said first firewall through said packet communications means.
- 5A central unit which functions as a second firewall against access to a servicing unit via an external network by a serviced unit connected to a first internal network in which a first firewall is installed for said external network, comprising:first packet communications means for setting up a first connection with said serviced unit via said first firewall and said external network and transmitting packets to or from said serviced unit over said first connection;security check means for determining whether or not packets received by said packet communications means after said first connection has been set up are packets transmitted from a serviced unit of a contract user;and second packet communications means for, when the determination by said security check means is that said packets are packets from said serviced unit of a contract user, setting up a second connection with said servicing unit via a second internal network connected to said central unit and transmitting packets to or from said servicing unit connected to said second internal network over said second connection.
- 8A central unit which functions as a second firewall against access to a servicing unit via the Internet by a serviced unit connected to a first internal network in which a first firewall is installed for said Internet, comprising:first packet communication means for setting up a first connection with said serviced unit via said first firewall and said Internet and transmitting packets to or from said serviced unit over said first connection;security check means for determining whether or not packets received by said packet communications means after said first connection has been set up are packets transmitted from a serviced unit of a contract user;and second packet communications means for, when the determination by said security check means is that said packets are packets from said serviced unit of contract user, setting up a second connection with said servicing unit via a second internal network connected to said central unit and transmitting packets to or from said servicing unit connected to said second internal network over said second connection.
- 11A remote operation system which is provided with a serviced unit connected to a first internal network in which a first firewall is installed for an external network and a servicing unit connected to a second internal network in which a second firewall is installed for said external network for providing remote operation services to said serviced unit, said servicing unit comprising:packet communications means for setting up a connection with said second firewall and transmitting packets to or from said serviced unit over said connection;and remote operation execution means for producing packets containing a command to perform a remote operation on said serviced unit and transmitting said packets to said second firewall via said packet communications means.
- 13A remote operation system which is provided with a serviced unit connected to a first internal network in which a first firewall is installed for the Internet and a servicing unit connected to a second internal network in which a second firewall is installed for said Internet for providing remote operation services to said serviced unit, said servicing unit comprising:packet communications means for setting up a connection with said second firewall and transmitting data containing packets to or from said serviced unit over said connection;and remote operation execution means for fetching remote operation directive information set up by said serviced unit from packets received by said packet communications means, producing packets containing a command to perform a remote operation indicated by said directive information and transmitting said packets to said second firewall.
- 15A remote operation service system in which first and second internal networks are connected to an external network by first and second firewalls which are respectively installed in said first and second networks, and a servicing unit connected to said second internal network provides remote operation services to a serviced unit connected to said first internal network, said serviced unit including:means for setting up a first connection with said second firewall installed for said second internal network via said first internal network and said first firewall installed for said first internal network;and means for transmitting packets containing data for a remote operation to or from said servicing unit over said first connection, said second firewall including: means for, after said first connection has been set up with said serviced unit, setting up a second connection with said servicing unit via said second internal network;and means for relaying packets between said serviced unit and said servicing unit using said first and second connections, and said servicing unit including: means for providing remote operation services to said serviced unit by transmitting packets to or from said serviced unit via said second firewall and said second connection.
- 18A remote operation service system in which first and second internal networks are connected to the Internet by first and second firewalls which are respectively installed in said first and second networks, and a servicing unit connected to said second internal network provides remote operation services to a serviced unit connected to said first internal network, said serviced unit including:means for setting up a first connection with said second firewall installed for said second internal network via said first internal network and said first firewall installed for said first internal network;and means for transmitting packets containing data for a remote operation to or from said servicing unit over said first connection, said second firewall including: means for, after said first connection has been set up with said serviced unit, setting up a second connection with said servicing unit via said second internal network;and means for relaying packets between said serviced unit and said servicing unit using said first and second connections, and said servicing unit including: means for providing remote operation services to said serviced unit by transmitting packets to or from said serviced unit via said second firewall and said second connection.
- 21A remote operation service providing method in a remote operation service system in which first and second internal networks are connected to an external network by first and second firewalls which are respectively installed in said first and second networks and a servicing unit connected to said second internal network provides remote operation services to a serviced unit connected to said first internal network, said remote operation service providing method comprising the steps of:in said serviced unit, setting up a first connection with said second firewall installed for said second internal network via said first internal network and said first firewall for said first internal network;in said serviced unit, transmitting packets containing data for performing a remote operation to or from said servicing unit connected to said second internal network over said first connection;in said second firewall, setting up a second connection with said servicing unit via said second internal network after said first connection has been set up with said serviced unit;in said second firewall, relaying packets between said serviced unit and said servicing unit over said first and second connections;and in said servicing unit, providing a remote operation service to said serviced unit by transmitting packets to or from said serviced unit via said second firewall and said second connection.
- 22A unit to be serviced which is connected to a first internal network in which a first firewall is installed for an external network and receives a remote operation service from a servicing unit connected to a second internal network in which a second firewall is installed for the external network, comprising:packet communications means for transmitting an identifier specifying an address of the servicing unit connected to the second internal network, establishing a connection to the servicing unit through the first and second firewalls, and transmitting a packet to and from the servicing unit through the connection;and remote operation execution means for retrieving remote operation directive information from the packet received by said packet communications means, and performing a remote operation on the unit to be serviced.
- 24A unit to be serviced which is connected to a first internal network in which a first firewall is installed for an external network and receives a remote operation service from a servicing unit connected to a second internal network in which a second firewall is installed for the external network, comprising:packet communications means for establishing a connection to the second firewall through the first firewall, and transmitting a packet to and from the second firewall through the connection;security check means for checking security of remote operation directive information stored in the packet received by said packet communications means;remote operation execution means for performing a remote operation on the unit to be serviced according to the remote operation directive information whose security is checked by said security check means;and execution result return means for returning an execution result of the remote operation performed by said remote operation execution means to the second firewall through said packet communications means.
- 26Broadest claimClaim Score 74, broad(NHIP)A servicing unit which is connected to the second internal network in which the second firewall is installed for the external network and provides a remote operation service for a unit to be serviced connected to a first internal network in which a first firewall is installed for an external network, comprising:packet communications means for establishing a connection to the second firewall, and transmitting a packet storing data to be transmitted to and from the unit to be serviced through the connection;and remote operation execution means for generating the packet for which a command to perform a remote operation is set for the unit to be serviced, and transmitting the packet to the second firewall through said packet communications means.
- 29A remote operation method for use with a unit to be serviced which is connected to a second internal network in which a second firewall is installed for an external network and receives a remote operation service from a servicing unit connected to a first internal network in which a first firewall is installed for the external network, comprising the steps of:establishing a connection to the servicing unit through the second and first firewalls after transmitting an identifier specifying an address of the servicing unit connected to the first internal network;transmitting a packet to and from the servicing unit through the connection;and retrieving remote operation directive information from the received packet and performing a remote operation on the unit to be serviced.
- 30A remote operation method for use with a servicing unit, connected to a second internal network in which a second firewall is installed for an external network, for providing a remote operation service for a unit to be serviced which is connected to a first internal network in which a first firewall is installed for the external network, comprising the steps of:establishing a connection to the second firewall;transmitting a packet storing data to be transmitted to and from the unit to be serviced through the connection;generating a packet in which a command to perform a remote operation on the unit to be serviced is set;and transmitting the packet to the second firewall through the connection.
- 31A remote operation method for use with a unit to be serviced which is connected to a second internal network in which a second firewall is installed for an external network and receives a remote operation service from a servicing unit connected to a first internal network in which a first firewall is installed for the external network, comprising the steps of:establishing a connection to the first firewall through the second firewall;transmitting a packet to and from the first firewall through the connection;checking security of remote operation directive information stored in a received packet;performing a remote operation on the unit to be serviced according to the remote operation directive information whose security is checked;and transmitting an execution result of the remote operation to the first firewall through the connection.
- 32A security check method for use with a center device functioning as a second firewall in response to access through an external network to a servicing unit by a unit to be serviced which is connected to a first internal network in which a first firewall is installed for the external network, comprising the steps of:establishing a first connection to the unit to be serviced through the first firewall and external network;transmitting a packet to and from the unit to be serviced through the first connection;checking after establishing the first connection whether or not a received packet is transmitted from the unit to be serviced of a subscriber;establishing a second connection to the servicing unit through an internal network when it is determined as a result of the checking that the received packet is transmitted from the unit to be serviced of the subscriber;and transmitting the packet to and from the servicing unit connected to the internal network through the second connection.
Independent claims18
177 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
[0001] 1. Field of the Invention
[0002] This invention relates to a remote maintenance and remote operation system in which a servicing device connected to an intracompany network of a service providing company performs maintenance and management on a device connected to a user-side network over an open external network, such as the Internet, through remote operation, and more specifically to a remote maintenance and remote operation system for use with network systems each of which is equipped with a firewall for the other.
[0003] 2. Description of the Related Art
[0004] Nowadays a system is being practiced actively which performs maintenance and management on users' devices through remote operation over networks in order to save expenses and time for business trips.
[0005] Also, an attempt is being made to adopt a system which employs the Internet as a network for remote operation. The Internet is the worldwide network which permits free communications with unspecified persons around the world. Thus, the employment of the Internet will permit global remote maintenance service.
[0006] Incidentally, the Internet has a problem of security because it is an open network. In particular, if an intracompany network of a company is connected to the Internet and so all of host computers connected to that network are made accessible by outsiders over the Internet, then the company will be exposed to dangers that important internal information which must be kept confidential may be stolen, the system may be crashed, data may be altered, and the like.
[0007] For this reason, a “firewall” has come to be provided between the Internet and an intracompany network recently. The firewall is a facility for protecting the intracompany network from hackers. In general, firewalls are roughly classified into packet filtering gateways, circuit gateways, and application gateways.
[0008]FIG. 1 is a schematic illustration of a firewall that is equipped with the above-described packet filtering gateway feature and installed between an external network (Internet) <b>1</b> and an internal network (intracompany network) <b>2</b>. In this figure there are illustrated IP address filtering and TCP port filtering by way of example.
[0009] Communications are made over the Internet on the basis on the TCP/IP protocol and IP datagram (IP packet) routing within the Internet is controlled on a bucket brigade basis. The IP datagram contains an IP header and a TCP header in its header.
[0010] The IP header contains an IP destination address (receiving IP address in the figure) and an IP source address (transmitting IP address in the figure). The IP address comprises a network address and a host address.
[0011] The TCP header contains a receiving port number and a transmitting port number. The port numbers have a one-to-one correspondence with processes and are utilized for interprocess communications over the Internet. A firewall <b>3</b> is provided with an IP address table <b>32</b> and a port number table <b>34</b>. Into the IP address table <b>32</b> is entered a set of IP addresses that is acceptable to the internal network <b>2</b>. Also, into the port number table <b>34</b> is entered a set of port numbers that is acceptable to the internal network <b>2</b>.
[0012] In the IP address filtering, when a packet is received, a reference is made to the IP address table <b>32</b>. If a transmitting IP address that has not been entered into that table is placed in the IP header of that packet (IP datagram), the IP datagram is rejected. Also, in the TCP port filtering, a reference is made to the port number table <b>34</b> when an IP datagram (packet) is received. If a port number that has not been stored into the port number table <b>34</b> is placed in the TCP header of that IP datagram, it is rejected. In this way, specific applications, such as Telenet, FTP and the like, can be filtered.
[0013]FIG. 2 is a diagram for use in explanation of a second feature of the firewall <b>3</b>.
[0014] The firewall <b>3</b> is provided with a feature of making access to hosts within the internal network <b>2</b> for hosts on the external network <b>1</b> (e.g., the Internet) in order not to allow the external hosts to make direct access to the hosts within the internal network <b>2</b>. In other words, access by hosts within the internal network <b>2</b> to the external network is to be made through the firewall <b>3</b> all the time.
[0015] In the example shown in FIG. 2, an IP address of “E” is set up on the firewall <b>3</b>. Also, “A”, “B”, “C” and “D” are set up on hosts A, B, C and D in the internal network <b>2</b> as their respective IP addresses. In such a system, for example, when the host B wants to transmit an IP datagram <b>12</b> to some host (external host) on the external network <b>1</b>, the host B transmits the datagram <b>12</b> to the firewall <b>3</b> not to the external host directly. Since the IP address set up on the host B is “B” as described above, the transmitting IP address of the IP datagram <b>12</b> is “B”. Upon receipt of the IP datagram <b>12</b>, the firewall <b>3</b> translates the original transmitting IP address B to its IP address “E” for subsequent transmission over the external network <b>1</b>.
[0016] Thus, if only the IP address of the firewall <b>3</b> is made open to the external network <b>1</b>, the existence of the internal network will be kept from the external network. The feature is also called the IP relay feature.
[0017] By installing the firewall <b>3</b> equipped with such a packet filtering gateway feature as described above between the internal network <b>2</b> and the external network <b>1</b>, improper IP datagrams that are going to enter the internal network <b>2</b> directly from the external network <b>1</b> can be blocked almost completely.
[0018]FIG. 3 shows a system in which internal networks <b>2</b>A, <b>2</b>B, <b>2</b>C and <b>2</b>D of respective A, B, C and D companies are connected with a commercial network <b>5</b>. In this system, each of the A, B, C and D companies installs a respective one of firewalls <b>3</b>A, <b>3</b>B, <b>3</b>C and <b>3</b>D between its own internal network <b>2</b>A, <b>2</b>B, <b>2</b>C, and <b>2</b>D and the commercial internet <b>5</b> in order to protect their respective internal networks from unauthorized access via the commercial network <b>5</b>.
[0019] Next, problems with such a system as shown in FIG. 3 will be described with reference to FIG. 4.
[0020] In FIG. 4, the A company is a company which provides maintenance and management services for pieces of software and hardware within a network that its client manages. Suppose that the client is the D company and the A company considers performing maintenance and management services for a serviced device <b>7</b> connected to the D company's network <b>2</b>D using a servicing device <b>6</b> connected to its own network by means of remote operation over the commercial internet <b>5</b>.
[0021] In this case, when the IP address of the A company's firewall <b>3</b>A has not been entered into the IP address table <b>32</b> in the D company's firewall <b>3</b>D, even if the servicing device <b>6</b> transmits a packet for remote operation to the serviced device <b>7</b> of the D company, that packet is rejected by the firewall <b>3</b>D and cannot enter the D company's internal network <b>2</b>D. Thus, the A company cannot provides maintenance and management services for the serviced device of the D company.
[0022] If, on the other hand, the IP address of the A company's firewall <b>3</b>A is entered into the IP address table <b>32</b> of the D company's firewall <b>3</b>D, then the A company's servicing device <b>6</b> will be able to perform maintenance and management on the D company's serviced device <b>7</b> by remote operation. However, this will result in a problem of security. That is, in this case, since any host connected to the A company's internal network <b>2</b>A, even it be a host other than the servicing device <b>6</b>, can enter the D company's internal network, the possibility exists that the internal network <b>2</b>D system of the D company may be destroyed and important information may be stolen. The reason is that the D company's firewall <b>3</b>D cannot identify the source of packets sent from the A company's firewall <b>3</b>A over the commercial internet <b>5</b>.
[0023] In the prior art, therefore, as shown schematically in FIG. 5, direct point-to-point connection is made by a public line <b>8</b> or private line between the A company's servicing device <b>6</b> and the D company's serviced device <b>7</b> for maintenance and management service for the latter. With such an approach, however, it is required that both the A and D companies prepare communications devices <b>9</b>A and <b>9</b>B dedicated to the direct point-to-point connection therebetween and a servicing environment. Undesirably this involves double investment by both the companies, resulting in an increase in cost. In addition, in order to protect intracompany network security, it is necessary to carry out troublesome work of disconnecting each of the servicing device <b>6</b> and the serviced device <b>7</b> from its associated intracompany network <b>2</b>A, <b>2</b>B at the start of service and connecting them again at the termination of service.
SUMMARY OF THE INVENTION
[0024] It is an object of the invention to enable remote operation between devices each of which is connected to its associated internal network equipped with a firewall.
[0025] The present invention is directed to a system which is provided with a servicing unit connected to a first internal network in which a first firewall is installed for an external network and a serviced unit connected to a second internal network in which a second firewall is installed for the external network and wherein the servicing unit performs a remote operation on the serviced unit through the external network. In such a system, the serviced unit comprises: packet communications means for transmitting an identifier specifying the address of the servicing unit connected to the first internal network, setting up a connection with the servicing unit via the second firewall and the first firewall, and transmitting packets to or from the servicing unit over the connection; and remote operation execution means for fetching remote operation directive information from packets received by the packet communications means and performing a remote operation on the serviced unit as indicated by the remote operation directive information.
[0026] The serviced unit becomes able to transmit and receive packets used for remote operation to or from the servicing unit by first sending the identifier to the firewall on the servicing unit side and then setting up the connection with the servicing unit. Thus, the serviced unit can receive packets containing remote operation directive information from the servicing unit and perform an operation on itself as indicated by that directive information, thereby performing a remote operation.
BRIEF DESCRIPTION OF THE DRAWINGS
[0027]FIG. 1 is a diagram for use in explanation of the packet filtering gateway feature of a firewall;
[0028]FIG. 2 is a diagram for use in explanation of the IP address translation/relay feature which is a second feature of the firewall;
[0029]FIG. 3 shows a system in which each of internal networks of A, B, C and D companies is connected by a firewall to a commercial internet;
[0030]FIG. 4 is a diagram for use in explanation of the reason why, in the system of FIG. 3, a servicing unit connected to the internal network of the A company cannot perform remote maintenance/operation on a serviced unit connected to the internal network of the D company;
[0031]FIG. 5 is a diagram for use in explanation of a prior art method by which, in the system of FIG. 3, the servicing unit connected to the internal network of the A company performs remote maintenance/operation on a serviced unit connected to the internal network of the D company;
[0032]FIG. 6 is a first diagram for use in explanation of the principles of the present invention;.
[0033]FIG. 7 is a second diagram for use in explanation of the principles of the present invention;
[0034]FIG. 8 is a third diagram for use in explanation of the principles of the present invention;
[0035]FIG. 9 is a fourth diagram for use in explanation of the principles of the present invention;
[0036]FIG. 10 shows the entire configuration of a remote maintenance and operation system according to an embodiment of the present invention;
[0037]FIG. 11 is a diagram for use in explanation of the overall operation of the system of FIG. 10;
[0038]FIG. 12 shows an exemplary system configuration of the embodiment of FIG. 10;
[0039]FIG. 13 shows a configuration of the header of an IP datagram in a packet communicated between the service company network and the client company network in the system of FIG. 12;
[0040]FIG. 14 is a first diagram illustrating the contents of a packet communicated between the servicing unit and the client's serviced device when the servicing device performs remote maintenance/operation on the serviced unit in the system of FIG. 12;
[0041]FIG. 15 is a second diagram illustrating the contents of a packet communicated between the servicing unit and the client's serviced device when the servicing unit performs remote maintenance/operation on the serviced unit in the system of FIG. 12;
[0042]FIG. 16 is a third diagram illustrating the contents of a packet communicated between the servicing unit and the client's serviced device when the servicing unit performs remote maintenance/operation on the serviced unit in the system of FIG. 12;
[0043]FIG. 17 shows the format of a packet transferred between the servicing unit and the serviced unit during the operation shown in FIGS. 14, 15 and <b>16</b>;
[0044]FIGS. 18A and 18B are diagrams for use in explanation of the formats of the respective packets shown in FIGS. 14 and 16;
[0045]FIG. 19 is an operating flowchart illustrating a process of relaying a packet (IP datagram) between the serviced unit and the servicing unit by the remote maintenance/operation central unit; and
[0046]FIG. 20 is an operating flowchart illustrating the IP relay feature of the remote maintenance/operation central unit illustrated in the operating flowchart of FIG. 19 from a different point of view.
DESCRIPTION OF THE PREFERRED EMBODIMENT
[0047] Referring now to FIG. 6, which is a first diagram illustrating the principles of the present invention, a client's internal network <b>82</b> is connected by an external network <b>84</b> with a remote operation service providing company's internal network <b>86</b>. Firewalls <b>83</b> and <b>85</b> are respectively installed in the internal networks <b>82</b> and <b>86</b> for the external network <b>84</b>. An embodiment of the present invention supposes a remote operation service system in which a remote operation service is provided to a serviced unit <b>81</b> connected to the client internal network <b>82</b> by a servicing unit <b>87</b> connected to the remote operation providing company's internal network <b>86</b>.
[0048] The serviced unit <b>81</b> sets up a first connection with the second firewall <b>85</b> associated with the remote operation service providing company's internal network <b>86</b> via the client network <b>82</b> and the first firewall <b>83</b> associated with the network <b>82</b> and then communicates packets containing data for remote operation with the servicing unit <b>87</b> connected to the service company's internal network <b>86</b>.
[0049] The second firewall <b>85</b> sets up a second connection with the servicing unit <b>87</b> via its associated internal network <b>86</b> after the first connection with the serviced unit <b>81</b> has been set up and then relays packets to be transmitted between the serviced unit <b>81</b> and the servicing unit <b>87</b> using the fist and second connections.
[0050] The servicing unit <b>87</b> transmits packets to be transmitted to or from the serviced unit <b>81</b> to or from the second firewall <b>85</b> over the second connection to thereby provide a remote operation service for the serviced unit <b>81</b>.
[0051] It should be noted here that the above-described first and second connections indicate logical paths, not private lines.
[0052] The second firewall <b>85</b> is equipped with a validation section for validating whether or not the serviced unit <b>81</b> belongs to a user under contract on the basis of the contents of data in packets transmitted from the serviced unit <b>81</b> over the first connection.
[0053] The serviced unit <b>81</b> is equipped with a validation section which, at the time of receipt of a packet produced by the servicing unit <b>87</b> and transferred from the second firewall <b>85</b> over the first connection, validates whether a remote operation executing command stored in that packet is valid or not.
[0054] The above-described external network is the Internet by way of example.
[0055]FIG. 7 is a second diagram illustrating the principles of the present invention.
[0056] In the figure, the serviced unit <b>81</b> is illustrated equipped with a packet communications section <b>51</b>, a remote operation execution section <b>52</b>, an execution result return section <b>53</b>, and a security check section <b>54</b>.
[0057] The packet communications section <b>51</b> transmits an identifier specifying the address of the servicing unit <b>87</b> connected to the internal network <b>86</b> to the second firewall <b>85</b>, sets up a connection with the servicing unit <b>87</b> via the first and second firewalls <b>83</b> and <b>85</b>, and transmits packets to or from the servicing unit <b>87</b> over that connection.
[0058] The execution result return unit <b>53</b> returns the results of execution of remote operation by the remote operation execution section <b>52</b> to the second firewall <b>85</b> via the packet communications section.
[0059] The security check section <b>54</b> checks the validity of a remote operation command contained in a packet received by the packet communications section <b>51</b>.
[0060] In this case, the remote operation execution section <b>52</b> carries out remote operation on the serviced unit in accordance with the remote operation command after its validity has been confirmed by the security check section <b>54</b>.
[0061]FIG. 8 is a third diagram for use in explanation of the principles of the invention.
[0062] In this figure, a central unit <b>88</b> functions as the second firewall <b>85</b> for the external network <b>84</b> of the internal network <b>86</b> of the company which provides remote operation service via the external network <b>84</b> for the serviced unit <b>81</b> connected to the contract user's internal network <b>82</b> in which the first firewall <b>83</b> is installed against the external network <b>84</b>.
[0063] The central unit <b>88</b> is equipped with a first packet communications section <b>61</b>, a security check unit <b>62</b>, and a second packet communications section <b>63</b>.
[0064] The first packet communications unit <b>61</b> sets up a first connection with the serviced unit <b>81</b> via the first firewall <b>83</b> and the external network <b>84</b> and transmits packets to or from the serviced unit <b>81</b> over the first connection.
[0065] The security check unit <b>62</b> checks packets received by the first communications unit <b>61</b> after the first connection has been set up to ensure that they have been sent from the serviced unit <b>81</b> of the user under contract.
[0066] The second communications section <b>63</b> sets up a second connection with the servicing unit <b>87</b> via its associated internal network <b>86</b> when the security check section <b>62</b> determined that the packets had been sent from the serviced unit <b>81</b> of the user under contract and then transmits packets to or from the servicing unit <b>87</b> over the second connection.
[0067] Moreover, the central unit <b>88</b> is equipped with a first database <b>64</b> into which validation information for the user under contract has been entered. The security check section <b>62</b> checks received packets for the presence of the validation information entered into the database <b>64</b>, thereby determining whether they are from the user under contract.
[0068] Furthermore, the central unit <b>88</b> is equipped with a second database <b>65</b> into which servicing unit identification information used to set up the second connection has been entered. The second packet communications section <b>63</b> may be configured to retrieve servicing unit identification information corresponding to service identification information stored in packets received by the first packet communications section <b>61</b> from the second database <b>65</b> and set up the second -connection using the servicing unit identification information.
[0069]FIG. 9 is a fourth diagram illustrating the principles of the invention.
[0070] As shown in this figure, the servicing unit <b>87</b> is equipped with a packet communications section <b>71</b> and a remote operation execution section <b>72</b>.
[0071] The packet communications section <b>71</b> sets up a connection with the second firewall <b>85</b> and then transmits packets to or from the serviced unit <b>81</b> over that connection.
[0072] The remote operation execution section <b>72</b> produces a packet in which a command is set up to perform a remote operation, which is specified by remote operation instructing information stored in packets received by the packet communications section <b>71</b>, on the serviced unit and transmits it to the second firewall <b>85</b> via the packet communications section.
[0073] The remote operation execution section <b>72</b> obtains the result of execution of an remote operation that the serviced unit <b>81</b> placed from packets received by the packet communications section and outputs it to the outside.
[0074] Hereinafter, the operation of the system shown in FIGS. <b>6</b> to <b>9</b> will be described.
[0075] The serviced unit <b>81</b> sets up a first connection with the second firewall <b>85</b> installed for the remote operation servicing company's internal network <b>86</b> via the client network <b>82</b>, the first firewall <b>83</b> and the external network <b>84</b> and then transmits packets containing data for remote operation to or from the servicing unit <b>87</b> connected to the servicing company's internal network <b>86</b> over the first connection.
[0076] The second firewall <b>85</b> sets up a second connection with the servicing unit <b>87</b> via its associated internal network <b>86</b> after the first connection has been set up and relays packets to be transmitted between the serviced unit <b>81</b> and the servicing unit <b>87</b> by the use of the first and second connections.
[0077] The servicing unit <b>87</b> performs remote operation service on the serviced unit <b>81</b> by transmitting packets that are to be transmitted to or from the serviced unit <b>81</b> to or from the second firewall <b>85</b> over the second connection.
[0078] For example, in this case, after the first connection has been set up, the second firewall <b>85</b> determines, through its validation section, whether the serviced unit <b>81</b> belongs to the user under contract or not on the basis of the contents of data placed in packets transmitted from the serviced unit <b>81</b> over the first connection.
[0079] Also, when receiving a packet from the servicing unit <b>87</b> through the second firewall <b>85</b> and the first connection, the serviced unit <b>81</b> determines whether a remote operation executing command stored in that packet is a valid command or not through its validation section.
[0080] Thus, in a system in which first and second firewalls are respectively installed in a client internal network <b>82</b> and a remote operation servicing company's internal network <b>86</b> for an external network <b>84</b> to which each of the internal networks is connected, a servicing unit <b>87</b> on the servicing company internal network can perform remote operation service on a serviced unit <b>81</b> on the client internal network through the external network with security for the customer and servicing company internal networks being kept.
[0081] The packet communications section <b>51</b> transmits an identifier which allows the second firewall <b>85</b> to specify the address of the servicing unit <b>87</b> connected to the internal network <b>86</b>, sets up a connection with the servicing unit <b>87</b> through the first and second firewalls <b>83</b> and <b>85</b>, and transmits packets to or from the servicing unit <b>87</b> over that connection. The remote operation execution section <b>52</b> fetches remote operation command information from a packet received by the packet communications section <b>51</b> and then performs remote operation as specified by the remote operation command information.
[0082] Thus, in a system in which firewalls are respectively installed in a remote operation service providing company's internal network <b>86</b> and a client internal network <b>82</b> for an external network <b>84</b> to which each of the internal networks is connected, a serviced unit <b>81</b> on the client network can transmit packets to the service providing company's internal network <b>86</b> and receive packets from a servicing unit <b>87</b> on the service providing company's internal network <b>86</b>.
[0083] The security check section <b>54</b> checks the remote operation instruction information placed in packets received by the packet communications section <b>51</b> for validity. The remote operation execution section <b>52</b> then performs a remote operation according to the contents of the remote operation directive information the validity of which has been confirmed by the security check section <b>54</b>. The execution result return section <b>53</b> then sends the results of the remote operation executed by the remote operation execution section <b>52</b> to the second firewall <b>85</b> through the packet communications section.
[0084] Therefore, the serviced unit <b>81</b> can receive remote operation service while keeping its security and the servicing unit <b>87</b> can acquire the results of a remote operation performed on the serviced unit <b>81</b> through the second firewall <b>85</b>.
[0085] The first packet communications section <b>61</b> sets up a first connection with the serviced unit <b>81</b> through the first firewall <b>83</b> and the external network <b>84</b> and then transmits packets to or from the serviced unit <b>81</b> over the first connection. The security check section <b>62</b> checks whether or not the packets received by the first packet communications section <b>61</b> after the first connection has been set up are packets transmitted from the serviced unit <b>81</b> of the user under contract. When it is determined by the securing check section <b>62</b> that the packets received by the first packet communications section <b>61</b> are packets transmitted from the serviced unit <b>81</b> of the user under contract, then the second packet communications section <b>63</b> sets up a second connection with the servicing unit <b>87</b> through its associated internal network <b>86</b> and then transmits packets to or from the servicing unit <b>87</b> over the second connection.
[0086] Therefore, packets can be transmitted to or from the serviced unit <b>81</b> connected to the client internal network <b>82</b> in which the first firewall <b>83</b> is installed. In addition, a security check can be performed on received packets to reject improper packets. Only packets sent from the serviced unit <b>81</b> of a user under contract can be transmitted to the servicing unit <b>87</b>. Furthermore, packets can be transmitted from the servicing unit <b>87</b> to the serviced unit <b>81</b>.
[0087] The packet communications section <b>71</b> sets up a connection with the second firewall <b>85</b> and then transmits packets to or from the serviced unit <b>81</b> over that connection. The remote operation execution section <b>72</b> produces a packet in which a command is placed to perform on the serviced unit <b>81</b> a remote operation specified by remote operation request information stored in packets received by the packet communications section <b>71</b> and then transmits it to the second firewall <b>85</b> through the packet communications section <b>71</b>. Moreover, the remote operation execution section <b>72</b> fetches the result of execution of the remote operation set by the serviced unit <b>81</b> from packets received by the packet communications section <b>71</b> and provides it to the outside.
[0088] Therefore, the servicing unit <b>87</b> on the service providing company's internal network <b>86</b> can transmit packets to or from the second firewall <b>85</b> installed for the external network <b>84</b>. This allows the servicing unit <b>87</b> to transmit packets for remote operation service to or from the serviced unit <b>81</b> when the second firewall <b>85</b> sets up a connection with the serviced unit <b>81</b> on the user internal network <b>82</b>.
[0089]FIG. 10 shows the entire configuration of a remote maintenance and remote operation system according to an embodiment of the present invention.
[0090] In this figure, a network <b>110</b> is an intracompany network of the A company which provides remote maintenance and remote operation service, while a network <b>210</b> is an intracompany network of the D company which is a client or user of that service.
[0091] The A company's network <b>110</b> and the D company's client network <b>210</b> are connected by a line <b>250</b> such as a public line, a commercial internet, or the like. Between the network <b>110</b> and the line <b>250</b> is installed a remote maintenance/operation central unit <b>120</b> which serves as a firewall. Also, a firewall <b>220</b> is installed between the client network <b>210</b> and the line <b>250</b>.
[0092] To the service company's network <b>110</b> is connected a servicing unit <b>130</b> which provides remote maintenance and remote operation service. To the client network <b>210</b> is connected a serviced unit <b>230</b> which receives the remote maintenance and remote operation service provided by the servicing unit <b>130</b>.
[0093] The remote maintenance/operation central unit <b>120</b> has a function of relaying packets (IP datagrams) from the servicing unit <b>130</b> on the service company's network <b>110</b> to the serviced unit <b>230</b> on the client network <b>210</b>. The central unit <b>120</b> has a user validation feature to provide security for its associated network <b>110</b>. The user validation feature is implemented by the provision of a user validation database <b>121</b>.
[0094] The user validation database <b>121</b> stores four pieces of information items, i.e., serviced unit ID, user ID, password, and service ID, for each serviced unit <b>230</b>.
[0095] The remote maintenance/operation central unit <b>120</b> is also equipped with a servicing unit database <b>122</b>, which stores IP addresses of servicing unit <b>130</b> having service IDs which have been entered into the user validation database <b>121</b>.
[0096] The remote maintenance/operation central unit <b>120</b> is further equipped with a serviced unit connected section <b>124</b>, a servicing unit connecting section <b>125</b>, and a service company network security section <b>126</b>.
[0097] The serviced unit connected unit <b>124</b> sets up a connection A, which is a logical path, with the serviced unit <b>230</b> connected to the client network <b>210</b> via the firewall <b>220</b> by means of the TCP protocol. In this case, a setup request for the connection A is made by the serviced unit <b>230</b> on the client network <b>210</b>. The serviced unit connected section <b>124</b> uses the pass A corresponding to the connection A to deliver packets bound for the serviced unit <b>230</b> produced by the servicing unit <b>130</b> to the serviced unit <b>230</b> through the firewall <b>220</b> and the client network <b>210</b>.
[0098] The servicing unit connecting section <b>125</b> is responsive to a request by the serviced unit connecting section <b>124</b> to set up a connection B, which is a logical path, between the remote maintenance/operation central unit <b>120</b> and the servicing unit <b>130</b> through the service company network security section <b>126</b> by means of the TCP protocol. Note that the setup request for the connection B is made after the connection path A has been set up and the serviced unit <b>230</b> has been identified as a contract user's unit on the basis of the service ID, user ID, serviced unit ID and password contained in the data part of a packet sent from the serviced unit over the path A.
[0099] The service company network security section <b>126</b> carries out the above-mentioned user validation process of determining whether the serviced unit <b>230</b> is a contract user's unit by making a reference to the user validation database <b>121</b> as requested by the serviced unit connected section <b>124</b> and then returns the result to the serviced unit connecting section <b>124</b>.
[0100] The servicing unit <b>130</b> is equipped with a central unit connecting section <b>132</b> and a remote maintenance/operation execution section <b>134</b>.
[0101] The central unit connecting section <b>132</b> sets up the connection B with the servicing unit connecting section <b>125</b> in the remote maintenance/operation central unit <b>120</b> through the associated network <b>110</b> and receives a remote maintenance/operation requesting packet transmitted by the serviced unit <b>230</b> from the servicing unit connecting section <b>125</b> over the path B corresponding to the connection B. This request is delivered to the remote maintenance/operation execution section <b>134</b>. A packet which stores a command to execute remote maintenance/operation requested by the remote maintenance/operation execution section <b>134</b> is sent to the servicing unit connecting section <b>125</b> in the central unit <b>120</b> over the path B.
[0102] Upon receipt of a packet containing a message requesting the start of remote maintenance/operation transmitted by the serviced unit <b>230</b> via the servicing unit connecting section <b>125</b>, the remote maintenance/operation execution section <b>134</b> produces a packet bound for the serviced unit <b>230</b> which contains, in its data part, a command to perform remote maintenance/operation on the serviced unit <b>230</b> and then requests the central unit connected section <b>132</b> to send that packet to the servicing unit <b>130</b> in the remote maintenance/operation central unit <b>120</b>. This packet is sent by the central unit connected section <b>132</b> to the servicing unit connected section <b>125</b> in the remote maintenance/operation central unit <b>120</b> over the connection B, then sent by the serviced unit connecting section <b>124</b> to the serviced unit <b>230</b> over the connection A. For example, the remote maintenance/operation execution section <b>134</b> performs a remote operation of locating and correcting faults in hardware and software that the service company sold to the user (client).
[0103] The serviced unit <b>230</b> is composed of a central unit connecting section <b>232</b>, a remote maintenance/operation executed section <b>234</b>, and a serviced unit security section <b>235</b>.
[0104] The central unit connecting section <b>232</b> sets up the connection A with the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> through its associated firewall <b>220</b> in making a request to the servicing unit <b>130</b> under contract for remote maintenance/operation of its associated unit <b>230</b>. After that, commands for remote maintenance/operation and packets containing the results of the remote maintenance/operation are transmitted between the central unit connecting section <b>232</b> and the servicing unit <b>130</b> over the secondary path comprised of the connection A and the connection B.
[0105] The remote maintenance/operation executed section <b>234</b> receives packets transmitted by the servicing unit <b>130</b> from the central unit connecting section <b>232</b>, fetches a command for remote maintenance/operation from the packets, and analyzes and executes that command. The section <b>234</b> then produces a packet which contains the result of the execution of that command, i.e., the result of the execution of the remote maintenance/operation and requests the central unit connecting section <b>232</b> to transmit that packet to the servicing unit <b>130</b>. The central unit connecting section <b>232</b> then sends that packet to the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> over the connection A.
[0106] When receiving a request by the remote maintenance/operation executed section <b>234</b>, the serviced unit security protection section <b>235</b> performs a security check on a packet that the remote maintenance/operation executed section <b>234</b> receives from the servicing unit <b>130</b>. That is, a check is made as to whether the command stored in that packet is a proper command specified in the contract and the like. The result of that check is returned to the remote maintenance/operation executed section <b>234</b>. For example, the security check is made to protect files that the client does not want for the service provider to make access to.
[0107] The serviced unit <b>230</b> is equipped with a non-reference file name database <b>236</b> as a database which allows the serviced unit security protection section <b>235</b> to make a security check as described above.
[0108] The names of files that the client forbids the servicing unit <b>130</b> to make access to are entered into the non-reference file name database <b>236</b>. When a command placed in a packet sent from the servicing unit <b>130</b> is directed at any one of the files to be protected from unauthorized access, the security protection section <b>235</b> instructs the remote maintenance/operation execution section <b>134</b> to prohibit the execution of that command.
[0109] As a result, the remote maintenance/operation executed section <b>234</b> will execute only commands which, of commands from the servicing unit <b>130</b>, ensure the user security protection.
[0110] The operation of the above-described embodiment will be described hereinafter with reference to FIG. 11 .
[0111] In the embodiment, the execution of remote maintenance/operation is started as requested by the client. For example, this request is made through a GUI (Graphical User Interface) displayed on a display section of the serviced unit <b>230</b> (S<b>11</b>).
[0112] When this request is made, the central unit connecting section <b>232</b> sets up the connection A with the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> through the client network <b>210</b> and the firewall <b>220</b>. Thereby, a session is established between the central unit connecting section <b>232</b> and the serviced unit connected section <b>124</b>, permitting packets to be transmitted between the sections <b>232</b> and <b>124</b> over the connection A.
[0113] After that, the central unit connecting section <b>232</b> produces a packet containing the service ID, user ID, serviced unit ID and password which were assigned to the serviced unit <b>230</b> at the time of contract and then sends it to the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> over the connection A (S<b>12</b>).
[0114] Upon receipt of the packet, the serviced unit connected section <b>124</b> sends the service ID, user ID, serviced unit ID, and password placed in the packet to the service company network security protection section <b>126</b> for a request for determination of whether the packet was sent from the serviced unit connected section <b>124</b> of a contract user. The security protection section <b>125</b> checks the four pieces of information with information entered into the user validation database <b>121</b> (S<b>13</b>) and determines whether or not that packet was sent from the contract user (S<b>14</b>). If the determination is that the packet was sent from the contract user (S<b>14</b>, YES), then the security protection section <b>125</b> searches the servicing unit database <b>122</b> for a servicing unit <b>130</b> corresponding to the service ID using the service ID as a key and acquires the IP address of the servicing unit <b>130</b>. The security protection section returns the result of the check and the IP address of the servicing unit <b>130</b> to the serviced unit connected section <b>124</b> (S<b>15</b>).
[0115] If, on the other hand, the determination in step S<b>14</b> is that the packet is not from a contract user (NO), then the packet is rejected. In addition, the connection A is disconnected.
[0116] When the serviced unit connecting section <b>124</b> receives the result of the determination from the associated network security protection section <b>126</b> and hence knows that the packet received by itself was sent from the serviced unit <b>230</b> of a contract user, it sends the IP address of the servicing unit <b>130</b> connected to the service company network security protection section <b>126</b> to the servicing unit connecting section <b>125</b> to make a request for setting up the connection B with the servicing unit <b>130</b>. In response to this request, the servicing unit connecting section <b>125</b> sets up the connection B with the central unit connected section <b>132</b> in the servicing unit <b>130</b> via the service company network <b>110</b> (S<b>16</b>).
[0117] Thereby, a session is established between the servicing unit connecting section <b>125</b> and the central unit connected section <b>132</b>, permitting the sections <b>125</b> and <b>132</b> to transmit packets therebetween. The service company network security protection section <b>126</b> may directly request the servicing unit connecting section <b>125</b> to set up the connection B.
[0118] The servicing unit connecting section <b>125</b> notifies the central unit connected section <b>132</b> in the servicing unit <b>130</b> via the connection B that packet communications with the serviced unit <b>230</b> was made possible (S<b>17</b>).
[0119] The central unit connecting section <b>232</b> then requests the remote maintenance/operation execution section <b>134</b> to start the execution of remote maintenance/operation on the serviced unit <b>230</b>. In response to this request, the execution section <b>134</b> starts providing remote maintenance/operation services specified at the time of a contract. The remote operation is performed by transmitting a packet containing a command for remote maintenance/operation to the contract serviced unit <b>230</b>. That is, the remote maintenance/operation execution section <b>134</b> produces that packet and requests the central unit connected section <b>132</b> to transmit it to the serviced unit <b>230</b> (S<b>18</b>).
[0120] The central unit connected section <b>132</b> then transmits that packet for remote maintenance/operation execution to the servicing unit connecting section <b>125</b> in the remote maintenance/operation central unit <b>120</b> over the connection B (Sl<b>9</b>).
[0121] Upon receipt of that packet, the servicing unit connecting section <b>125</b> sends it to the central unit connecting section <b>232</b> in the serviced unit <b>230</b> over the connection A (S<b>20</b>).
[0122] Upon receipt of that packet, the central unit connecting section <b>232</b> requests the serviced unit security protection section <b>235</b> to check it for validity. Upon receipt of the result that the command contained in that packet is valid from the security protection section <b>235</b>, the central unit connecting section <b>232</b> requests the remote maintenance/operation executed section <b>234</b> to execute that command. Then, the section <b>234</b> executes the command, produces a packet which contains the result of the execution, and requests the central unit connecting section <b>232</b> to send that packet to the servicing unit <b>130</b>. The connecting section <b>232</b> sends the packet received to the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> over the connection A (S<b>21</b>).
[0123] If, in this case, it is determined by the serviced unit security protection section <b>235</b> that the command specified by the servicing unit <b>130</b> is a command to make access to a file entered into the non-reference file name database <b>236</b>, then the remote maintenance/operation execution section <b>234</b> will not execute that command (S<b>22</b>).
[0124] The serviced unit connected section <b>124</b> receives a packet containing the results of the remote maintenance/operation execution and then sends it to the central unit connected section <b>132</b> in the servicing unit <b>130</b> over the connection B (S<b>23</b>).
[0125] Upon receipt of that packet, the connected section <b>132</b> fetches the results of the remote maintenance/operation execution from it and then sends them to the remote maintenance/operation execution section <b>134</b>, which displays the execution results on the display section of the servicing unit <b>130</b> (S<b>24</b>).
[0126] The processes in steps <b>18</b> through <b>24</b> are repeated while the execution of remote maintenance/operation is directed in the serviced unit <b>230</b>. Note that the remote maintenance/operation execution is directed through a GUI (Graphical User Interface) displayed on the display section of the servicing unit <b>130</b>.
[0127] When the execution of all remote maintenance/operation services for the serviced unit <b>230</b> terminates, it is notified to the central unit connected section <b>132</b> by the remote maintenance/operation execution section <b>134</b> (S<b>25</b>).
[0128] The central unit connected section <b>132</b> then disconnects the connection B (S<b>26</b>).
[0129] After the connection B has been disconnected, the servicing unit connecting section <b>125</b> in the remote maintenance/operation central unit <b>120</b> produces a packet to assign a new password to the serviced unit <b>230</b> and then sends it to the central unit connecting section <b>232</b> in the serviced unit <b>230</b> over the connection A. When the serviced unit <b>230</b> acknowledges receipt of the new password, the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> disconnects the connection A (S<b>27</b>).
[0130] After the disconnection of the connection A, the serviced unit <b>230</b> stores that new password in a predetermined memory for use with the next remote maintenance/operation (S<b>28</b>).
[0131] Next, the flow of packets at the time of remote maintenance/operation execution will be described in detail.
[0132] Suppose here that, as shown in FIG. 12, the service company network <b>110</b> and the client network <b>210</b> are connected by the Internet <b>250</b>, and the remote maintenance/operation central unit <b>120</b> and the servicing unit <b>130</b> in the service company network <b>110</b> and the firewall <b>220</b> and the serviced unit <b>230</b> in the client network <b>210</b> are assigned IP addresses and port numbers as shown.
[0133] That is, in the service company network <b>110</b>, the remote maintenance/operation central unit <b>120</b> has its IP address set to “C”, the serviced unit connected section <b>124</b> in the central unit has its port number set to “P<b>1</b>”, and the servicing unit <b>130</b> has its IP address set to “D”.
[0134] In the client network <b>210</b>, on the other hand, the serviced unit <b>230</b> has its IP address set to “A”, the central unit connecting section <b>232</b> in the serviced unit has its port number set to “P<b>2</b>”, and the firewall <b>220</b> has its IP address set to “B”.
[0135]FIG. 13 shows the configuration of a header <b>300</b> set up on an IP datagram in a packet transmitted between the service company network <b>110</b> and the client network <b>210</b>.
[0136] The header <b>300</b> is composed of an IP header <b>301</b>, a TCP header <b>302</b>, and a remote maintenance/operation header <b>303</b>. The IP header <b>301</b> contains various pieces of information determined by the IP protocol, such as a transmitting IP address (source address), a receiving IP address (destination address), etc. The TCP header <b>302</b> contains various pieces of information determined by the TCP protocol, such as a transmitting port number (source port number), a receiving port number (destination port number), an SEQ (sequence number), etc.
[0137] The remote maintenance/operation header <b>303</b>, which constitutes a feature of the present embodiment, contains a service ID (SVID), user ID (UID), password (PWD), and serviced unit ID (WID) which, as described previously, are used for security check to determine whether or not packets received by the serviced unit connected section <b>124</b> over the connection A have been sent from a contract user. The remote maintenance/operation header <b>303</b> is placed in the data part of the TCP header <b>302</b>.
[0138]FIGS. 14, 15 and <b>16</b> are diagrams for use in explanation of the flow of packets described in conjunction with the flowchart of FIG. 11 and the packet contents.
[0139] Before describing the flow of packets and the packet contents, reference will first be made to FIG. 17 to describe the format of a packet <b>400</b> transmitted between the serviced unit <b>230</b> and the servicing unit <b>130</b>. This packet begins with a TCP/IP header <b>400</b><i>a </i>as in a usual IP datagram, followed by a remote maintenance/operation header <b>400</b><i>b </i>used for remote maintenance/operation between the serviced unit <b>230</b> and the servicing unit <b>130</b> and communications data <b>400</b><i>c</i>. The TCP/IP header <b>400</b><i>a </i>consists of the IP header <b>301</b> and the TCP header <b>302</b> shown in FIG. 13. The contents of the remote maintenance/operation header <b>400</b><i>b </i>are the same as those of the header <b>303</b> of FIG. 13.
[0140] Of packets <b>401</b> to <b>406</b> shown in FIGS. 14, 15 and <b>16</b>, packets <b>401</b>, <b>402</b> and <b>403</b> sent from the serviced unit <b>230</b> to the servicing unit <b>130</b> each have a TCP/IP header formatted as shown in FIG. 18A. Packets <b>404</b>, <b>405</b> and <b>406</b> sent from the servicing unit <b>130</b> to the serviced unit <b>230</b> each have a TCP/IP header formatted as shown in FIG. 18B.
[0141] With packet (IP datagram) communications between the serviced unit <b>230</b> and the servicing unit <b>130</b> shown in FIGS. 14, 15 and <b>16</b>, the connection (session) A set up between the serviced unit <b>230</b> and the remote maintenance/operation central unit <b>120</b> and the connection (session) B set up between the remote maintenance/operation central unit <b>120</b> and the servicing unit <b>130</b> are employed.
[0142] After the connection A has been set up, the central unit connecting section <b>232</b> in the serviced unit <b>230</b> associated with the client network <b>210</b> transmits to the firewall <b>220</b> a packet (IP datagram) <b>401</b> containing a remote maintenance/operation header in the data part of the TCP header shown in FIG. 18. The firewall <b>220</b> receives that packet over the client network <b>210</b> and then changes the transmitting IP address in the IP header from the IP address, “A”, of the serviced unit <b>230</b> to its IP address “B”. The resulting packet (IP datagram) <b>404</b> is then transmitted to the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b> associated with the service company network <b>110</b> over line <b>250</b>.
[0143] The above packet communications are made by using the connection (session) A. In this case, the service company network <b>110</b> will not know the IP address A of the serviced unit <b>230</b> because the transmitting IP address of the packet <b>402</b> that the remote maintenance/operation central unit <b>120</b> associated with the service company network <b>110</b> receives is set to the IP address B of the firewall <b>220</b> associated with the client network <b>210</b>.
[0144] Upon receipt of the packet <b>402</b>, the remote maintenance/operation central unit <b>120</b> examines the remote maintenance/operation header of the packet <b>402</b> while maintaining the session A with the firewall <b>220</b> on the client network <b>210</b> side. That is, the service company network security protection section <b>126</b> examines whether or not the service ID, user ID, password, and serviced unit ID which are placed in the remote maintenance/operation header have been entered into the user validation database <b>121</b>. If the entry is confirmed, then the IP address (“D” in this case) of the servicing unit <b>130</b> having that service ID is fetched from the servicing unit database <b>122</b>. The servicing unit connecting section <b>125</b> receives this IP address D from the security protection section <b>126</b> and then sets up the connection (session) B with the central unit connected section <b>132</b> in the servicing unit <b>130</b>.
[0145] After that, the central unit connected section <b>132</b> produces a packet (IP datagram) <b>403</b> shown in FIG. 15. That is, the receiving IP address in the packet <b>403</b> is set to “D” and the transmitting IP address is set to its IP address “C”. The receiving port number in the packet <b>403</b> is set to a port number (P<b>3</b> in this case) assigned to the central unit connected section <b>132</b> in the servicing unit <b>130</b>. Notification information from the user for a session request is placed in the data part of the TCP header. The servicing unit connecting section <b>125</b> then sends the packet <b>403</b> to the central unit connected section <b>132</b> in the servicing unit <b>130</b> via the associated network <b>110</b>.
[0146] In the servicing unit <b>130</b>, when the central unit connected section <b>132</b> receives the packet <b>403</b>, the remote maintenance/operation execution section <b>134</b> interprets directive data from the user (service provider) placed in the data part of the packet <b>403</b>. The execution section <b>134</b> then produces a command (directive information to the service provider) to execute the maintenance/operation indicated by the directive data and a packet (IP datagram) <b>404</b> in which that command is placed in the data part. In this case, the receiving IP address of the packet <b>404</b> is set to the IP address “C” of the remote maintenance/operation central unit <b>120</b> and the transmitting IP address is set to the IP address “C” of the servicing unit <b>130</b>. Further, the receiving port number is set to the port number P<b>1</b> of the servicing unit connecting section <b>125</b> in the central unit <b>120</b> and the transmitting port number is set to the port number P<b>3</b> of the central unit connected section <b>132</b>. The central unit connected section <b>132</b> sends the packet <b>404</b> to the servicing unit connecting section <b>125</b> in the central unit <b>120</b> over the connection B.
[0147] Upon receipt of the packet <b>404</b> from the servicing unit connecting section <b>125</b>, the serviced unit connected section <b>124</b> in the central unit <b>120</b> produces a packet (IP datagram) <b>405</b> shown in FIG. 15. The servicing unit connecting section <b>125</b> converts the receiving IP address, transmitting IP address, and receiving port number in the packet <b>404</b>. That is, the receiving IP address in the packet <b>405</b> is set to the IP address B of the firewall <b>220</b> associated with the client network <b>210</b> and the transmitting IP address is set to the IP address C of the central unit <b>120</b>. Further, the receiving port number is set to the port number P<b>2</b> of the central unit connecting section <b>232</b> in the serviced unit <b>230</b> on the client network <b>210</b>. The serviced unit connecting section <b>124</b> transmits the packet <b>405</b> to the firewall <b>220</b> on the client network <b>210</b> over the connection A. Upon receipt of the packet <b>405</b>, the firewall <b>220</b> first performs an IP address translation process and then produces a packet (IP datagram) <b>406</b> shown in FIG. 16. That is, the receiving IP address is translated from B to A, the IP address of the serviced unit <b>230</b>, and the transmitting IP address is translated from C to B, the IP address of the firewall itself. The firewall <b>220</b> transmits the packet <b>406</b> to the central unit connecting section <b>232</b> in the serviced unit <b>230</b> using the session with the serviced unit <b>230</b>.
[0148] In this way, the serviced unit <b>230</b> receives only packets in which the transmitting IP address is the IP address of the firewall. Therefore, the serviced unit will not know the IP address of the servicing unit <b>130</b>.
[0149] The central unit connecting section <b>232</b> receives the packet <b>406</b> and then sends it to the remote maintenance/operation executed section <b>234</b>. The executed section <b>234</b> fetches directive information of the service provider from the packet <b>406</b>, analyzes it, and carries out maintenance/operation indicated by it. The directive information is checked for validity by the serviced unit security protection section <b>235</b> before the maintenance/operation is carried out. The remote maintenance/operation execution section <b>234</b> carries out only directive information that has been validated.
[0150] After the termination of the execution of the remote maintenance/operation, the remote maintenance/operation execution section <b>234</b> produces a packet (IP datagram) which contains the result of the execution in the data part of the TCP header. This packet is sent to the servicing unit <b>130</b> connected to the service company network <b>110</b> over the secondary path (refer to FIG. 10) connected by the connection A and the connection B described previously.
[0151] Next, the operation of the remote maintenance/operation central unit <b>120</b> to set up the connection (session) A with the serviced unit <b>230</b> connected to the client network <b>210</b> via the firewall <b>220</b> installed in the client network <b>210</b> will be described in more detail.
[0152]FIG. 19 is an operating flowchart illustrating the process of relaying packets (IP datagrams) between the serviced unit <b>230</b> and the servicing unit <b>130</b> by the remote maintenance/operation central unit <b>120</b>.
[0153] Note here that the firewall <b>220</b> on the client network <b>210</b> is equipped with, for example, the TCP port filtering feature. When a contract for remote maintenance/operation service is concluded, the service providing company informs the contract user of the port number assigned to the serviced unit connected section <b>124</b> in the remote maintenance/operation central unit <b>120</b>. Then, a firewall <b>220</b> administrator of the service receiving company sets the TCP port filtering of the firewall <b>220</b> so that packets can be transmitted between the serviced unit <b>230</b> on the service receiving company network <b>210</b> and the serviced unit connected section <b>124</b> through that firewall <b>220</b>. The port number of the serviced unit connected section <b>124</b> may be fixed or may vary with the serviced units.
[0154] When the firewall <b>220</b> on the client network is equipped with the IP address filtering feature, the service provider informs the contract user of the IP address of the remote maintenance/operation central unit <b>120</b> and then requests the user to set the IP address filtering so that packets transmitted from the remote maintenance/operation central unit <b>120</b> toward the serviced unit <b>230</b> can pass through the firewall <b>220</b>.
[0155] The serviced unit connected section <b>124</b> is always placed in the wait state for a request for session (connection) setup by the serviced unit <b>230</b> (S<b>41</b>).
[0156] Upon receipt of a packet containing a session setup requesting message from the serviced unit <b>230</b> via the firewall <b>220</b>, the serviced unit connected section <b>124</b> requests the service company network security protection section <b>126</b> to make a check as to whether or not the service ID, user ID, password and serviced unit ID which are placed in the remote maintenance/operation header of that packet have been entered into the user validation database <b>121</b> (S<b>42</b>).
[0157] After that, the serviced unit connected section <b>124</b> receives the result from the security protection section <b>126</b> to determine whether or not the serviced unit <b>230</b> belongs to a contract user (S<b>43</b>).
[0158] Next, if the determination is that the session setup requesting message is not from a contract user (S<b>43</b>, NG), then the serviced unit connected section <b>124</b> rejects the request for session setup (S<b>44</b>).
[0159] If, on the other hand, the determination is that the session setup requesting packet is from a contract user (S<b>43</b>, OK), then the serviced unit connected section <b>124</b> sends the service ID contained in that packet to the servicing unit connecting section <b>125</b>. Upon receipt of that service ID, the servicing unit connecting section <b>125</b> retrieves the IP address of the servicing unit <b>130</b> corresponding to the service ID from the servicing unit database <b>122</b> (S<b>45</b>).
[0160] And, the servicing unit connecting section <b>125</b> sets up the session (connection) B with the servicing unit <b>130</b> having the IP address via the service company network <b>110</b> using this IP address.
[0161] Then, the servicing unit connecting section <b>125</b> generates a child process for the serviced unit <b>230</b> while maintaining the sessions (connections) with the serviced unit <b>230</b> and the servicing unit <b>130</b> (S<b>47</b>).
[0162] Next, the servicing unit connecting section <b>125</b> makes a system call to wait for a session request by another serviced unit <b>230</b> (S<b>48</b>). The procedure then returns to step S<b>41</b>.
[0163] The above-described steps S<b>41</b> to S<b>48</b> allows the remote maintenance/operation central unit <b>120</b> to set up multiple sessions between the serviced unit <b>230</b> and the servicing unit <b>130</b>. That is, the servicing unit <b>130</b> can provide remote maintenance/operation service to multiple serviced units <b>230</b>.
[0164] In FIG. 19, there are illustrated child processes generated by sessions set up between the servicing unit <b>130</b> and a serviced unit A, between the servicing unit <b>130</b> and a serviced unit B, and between the servicing unit <b>130</b> and a serviced unit C. Each child process is equipped with a buffer <b>127</b> (<b>127</b>A, <b>127</b>B, <b>127</b>C) for the corresponding serviced unit <b>230</b> and a buffer <b>128</b> (<b>128</b>A, <b>128</b>B, <b>128</b>C) for the servicing unit <b>130</b>. When a packet is transmitted from a serviced unit <b>230</b> to the servicing unit <b>130</b>, it is stored temporarily in the corresponding buffer <b>127</b> and then copied into the buffer <b>128</b> for the servicing unit <b>130</b>. The packet stored in the buffer <b>128</b> is taken out by the servicing unit connecting section <b>125</b>, then output to the servicing unit <b>130</b>.
[0165] Though not shown in FIG. 19, where a packet is sent from the servicing unit <b>130</b> to a serviced unit <b>230</b>, it is temporarily stored in the buffer <b>128</b> for the servicing unit <b>130</b>, then copied into the corresponding buffer <b>127</b> for the serviced unit <b>230</b>. The packet is taken out from the buffer <b>127</b> by the serviced unit connected section <b>124</b>, then output to the serviced unit <b>230</b>.
[0166] In the manner described above, packets are transmitted between the serviced unit <b>230</b> and the servicing unit <b>130</b> via the remote maintenance/operation central unit <b>120</b> by the use of the two connections—the connection A and the connection B—and remote maintenance/operation is performed on the serviced unit <b>230</b> by the servicing unit <b>130</b>.
[0167]FIG. 20 is an operating flowchart illustrating the IP relay feature of the remote maintenance/operation central unit <b>120</b> from a different point of view.
[0168] In this figure, based on steps S<b>41</b> to S<b>46</b>, which are identical to the corresponding steps in FIG. 19, the servicing unit connecting section <b>125</b> sets up a session (connection B) with the servicing unit <b>130</b> through the service company network <b>110</b> in accordance with a session setup request by the serviced unit <b>230</b>.
[0169] The servicing unit connecting section <b>125</b> then creates a session management table (S<b>51</b>). This table contains three types of information items—session number, serviced unit session ID, and servicing unit session ID. The serviced unit session ID is related to a session that is set up by the connection A established between the serviced unit <b>230</b> and the serviced unit connected section <b>124</b>. The servicing unit session ID is related to a session that is set up by the connection B established between the servicing unit connecting section <b>125</b> and the servicing unit <b>130</b>. By the serviced unit session ID and the servicing unit session ID, information about a logical path established between the serviced unit <b>230</b> and the servicing unit <b>130</b> is obtained, which allows the remote maintenance/operation central unit <b>120</b> to carry out a process of relaying packets (IP datagrams) between the serviced unit <b>230</b> and the servicing unit <b>130</b>. The session ID, which is managed on the TCP protocol layer by the servicing unit connecting section <b>125</b>, is used to identify each session (connection) distinguished by information such as transmitting IP address, receiving IP address, transmitting port number, receiving port number and the like. In the session management table, each session between the serviced unit <b>230</b> and the servicing unit <b>130</b> that is determined by a set of serviced unit and servicing unit session IDs is assigned a unique session number.
[0170] The remote maintenance/operation central unit <b>120</b> (the serviced unit connected section <b>124</b> or servicing unit connecting section <b>125</b>) waits for entry of packets from each unit (the serviced unit <b>230</b> or the servicing unit <b>130</b>) (S<b>52</b>).
[0171] Upon receipt of a packet from a unit, the remote maintenance/operation central unit <b>120</b> (serviced unit <b>124</b> or servicing unit connecting section <b>125</b>) searches the session management table by the ID (session ID) of a session over which that packet has been transmitted and fetches the session ID of a unit (serviced unit <b>230</b> or servicing unit <b>130</b>) corresponding to that session ID from the session management table (S<b>54</b>). That is, when the serviced unit connected section <b>124</b> receives a packet from the serviced unit <b>230</b>, it fetches the servicing unit session ID corresponding to the session (serviced unit session ID) over which that packet has been transmitted. On the other hand, when the servicing unit connecting section <b>125</b> receives a packet from the servicing unit <b>130</b>, it fetches the serviced unit session ID corresponding to the session (servicing unit session ID) over which that packet has been transmitted.
[0172] The servicing unit connecting section <b>125</b> sends the packet from the serviced unit <b>230</b> to the servicing unit <b>130</b> according to the session ID fetched. Also, the serviced unit connected section <b>124</b> sends the packet from the servicing unit <b>130</b> to the serviced unit <b>230</b> according to the session ID fetched (S<b>55</b>).
[0173] According to the present embodiment, as described above, in a system in which an internal network of a remote maintenance/operation service providing company and an internal network of a client company having a service receiving unit are interconnected by an external network such as an internet, public line or the like and each of the companies is equipped with a firewall for the external network, the service providing company can use a servicing unit connected to its internal network to perform remote maintenance/operation on the serviced unit connected to the client internal network. And moreover, both the companies are equipped with a security protection feature and hence can provide security for their respective internal networks.
[0174] In the present embodiment, a commercial internet can be used as the external network. In this case, dialup IP connection users can become clients. In addition, users who use dialup IP connection terminals each assigned an IP address at the time of line connection to the commercial internet can also become clients. The reason is that, in the present embodiment, whether received packets have been sent from a contract user or not is determined on the basis of the service ID, user ID, serviced unit ID and password which are entered at the time a contract is concluded and thus contract user validation can be made possible without depending on only IP addresses.
[0175] Although, in the above embodiment, the TCP/IP protocol is used to, transmit packets for remote maintenance/operation, this is not restrictive and any other protocol may be used. Moreover, the intracompany networks of a contract user company and a service providing company need not necessarily be interconnected by the Internet and may be interconnected by any network that is provided by a common carrier. Furthermore, the present invention is applicable not only to remote maintenance/operation but also to remote operation in general.
[0176] According to the present invention, a remote operation service receiving client and a remote operation service providing company can perform remote operation by the use of units connected to their respective intracompany networks with their respective firewalls installed in an external network. Therefore, existing intracompany networks can be used as they are to implement a safe, inexpensive remote operation service system.
[0177] A serviced unit is equipped with a security check feature which prevents the execution of remote operations other than those specified in a contract, thus ensuring security. Also, a service providing company is equipped with a security check feature which, after a connection has been set up with the serviced unit of a contract user, checks packets sent over the connection for the presence of user validation information indicating a contract user, thus protecting the servicing unit from unfair access.
Contents4
26 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10706168B2 | Cited by | United States of America | Applicant |
| US11599657B2 | Cited by | United States of America | Applicant |
| US7591001B2 | Cited by | United States of America | Applicant |
| US2008107068A1 | Cited by | United States of America | Pre-grant |
| US2007286076A1 | Cited by | United States of America | Pre-grant |
| US2005262570A1 | Cited by | United States of America | Pre-grant |
| US10467606B2 | Cited by | United States of America | Applicant |
| CN103117993A | Cited by | China | Search report |
| US2013081130A1 | Cited by | United States of America | Pre-grant |
| US7549159B2 | Cited by | United States of America | Applicant |
| US7823194B2 | Cited by | United States of America | Applicant |
| US2003097479A1 | Cited by | United States of America | Pre-grant |
| US2004151135A1 | Cited by | United States of America | Pre-grant |
| US7660980B2 | Cited by | United States of America | Applicant |
| US10198719B2 | Cited by | United States of America | Applicant |
| US9509704B2 | Cited by | United States of America | Applicant |
| US2004098619A1 | Cited by | United States of America | Pre-grant |
| US7506358B1 | Cited by | United States of America | Search report |
| US2007162300A1 | Cited by | United States of America | Pre-grant |
| US7386889B2 | Cited by | United States of America | Search report |
| US2002095599A1 | Cited by | United States of America | Pre-grant |
| US9177338B2 | Cited by | United States of America | Applicant |
| US2007286393A1 | Cited by | United States of America | Pre-grant |
| US2007248105A1 | Cited by | United States of America | Pre-grant |
| US10380621B2 | Cited by | United States of America | Applicant |
| US2005160289A1 | Cited by | United States of America | Pre-grant |
| US7543070B1 | Cited by | United States of America | Search report |
| US10999094B2 | Cited by | United States of America | Applicant |
| US8745719B2 | Cited by | United States of America | Applicant |
| US10192234B2 | Cited by | United States of America | Applicant |
| US6654802B1 | Cited by | United States of America | Search report |
| US2005180326A1 | Cited by | United States of America | Pre-grant |
| US2008016000A1 | Cited by | United States of America | Pre-grant |
| US11494801B2 | Cited by | United States of America | Applicant |
| US9621372B2 | Cited by | United States of America | Search report |
| US2004098620A1 | Cited by | United States of America | Pre-grant |
| US10073984B2 | Cited by | United States of America | Applicant |
| US9100437B2 | Cited by | United States of America | Search report |
| US2010074256A1 | Cited by | United States of America | Pre-grant |
5 members in 2 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 12197595 | Japan | A | |
| 12197595 | Japan | A | |
| 61406096 | United States of America | A | |
| 61406096 | United States of America | A | |
| 24592199 | United States of America | A | |
| 07121975 | – | – | – |
| 08614060 | – | – | – |
| JP19950121975 | – | – | – |
| US19960614060 | – | – | – |
| US19990245921 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| JPH08314835A | Japan | A | |
| US5960177A | United States of America | A | |
| US2002004847A1 | United States of America | A1 | |
| JP3262689B2 | Japan | B2 | |
| US6374298B2 | United States of America | B2 |
6 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAYER NUMBER DE-ASSIGNED (ORIGINAL EVENT CODE: RMPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2002004847
- Publication, EPODOC
- US2002004847
- Application
- 9245921
- Application, DOCDB
- 24592199
- Application, EPODOC
- US19990245921
Titles
- English
- SYSTEM FOR PERFORMING REMOTE OPERATION BETWEEN FIREWALL-EQUIPPED NETWORKS OR DEVICES
Classification
- CPC, 3
- H04L63/02
- H04L63/029
- H04L67/125
- IPC, 6
- G06F11 30
- G06F13 00
- H04L12 66
- H04L29 06
- H04L29 08
- H04Q9 00
- USPC, 4
- 709249000
- 709208000
- 709227000
- 726011000