[go: up one dir, main page]

CN101075994A - Household gateway device - Google Patents

Household gateway device Download PDF

Info

Publication number
CN101075994A
CN101075994A CN 200610164520 CN200610164520A CN101075994A CN 101075994 A CN101075994 A CN 101075994A CN 200610164520 CN200610164520 CN 200610164520 CN 200610164520 A CN200610164520 A CN 200610164520A CN 101075994 A CN101075994 A CN 101075994A
Authority
CN
China
Prior art keywords
information
gateway device
outdoor location
mobile phone
home gateway
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 200610164520
Other languages
Chinese (zh)
Other versions
CN101075994B (en
Inventor
冈山祐孝
田中晶
泽村伸一
中本与一
牧元喜宣
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hitachi Building Systems Co Ltd
Original Assignee
Hitachi Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hitachi Ltd filed Critical Hitachi Ltd
Publication of CN101075994A publication Critical patent/CN101075994A/en
Application granted granted Critical
Publication of CN101075994B publication Critical patent/CN101075994B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

In household gateway device for controlling the indoor machine connected with household network using outdoor location, the load to the server is reduced and the safety is increased and the communication is realized to be applicable for more models of outdoor location. The said device comprises storing part for keeping the information related to the preset device; visit control part for controlling the visit between the said outdoor location. The said visit control part sends the information which is related to the preset device and obtained from the storing part to the said exterior gateway device. In the said exterior gateway devic, when the information related to the outdoor location from the outdoor location is judged whether it conforms to the information related to the preset device, the control part performs the control of the communication of the said outdoor location not via exterior gateway device.

Description

家庭网关装置Home Gateway Device

技术领域technical field

本发明涉及家庭网关装置和网络访问控制系统。The invention relates to a home gateway device and a network access control system.

背景技术Background technique

对TV、DVD/HDD录像机、空调机、照明装置等家用电器,和/或电气门锁和各种传感器等住宅设备机器等(以下,将这些称为“室内机器”)所连接的家庭网关装置,由例如便携电话等室外装置从外部访问而控制室内机器是公知的。Home gateway devices connected to home appliances such as TVs, DVD/HDD recorders, air conditioners, and lighting equipment, and/or residential equipment such as electric door locks and various sensors (hereinafter, these are referred to as "indoor equipment") , it is known that an outdoor device such as a mobile phone accesses from the outside to control an indoor unit.

作为用于防止对上述家庭网络的未授权的访问的现有技术,例如已知的有专利文献1中所述的技术。其公开了经由因特网与室外装置连接的访问服务器装置进行室外装置的认证,配置于家庭网络的入口的家庭网关装置仅与上述访问服务器装置通信,由此防止来自室外装置的未授权的访问。As a prior art for preventing unauthorized access to the above-mentioned home network, for example, the technology described in Patent Document 1 is known. It discloses that an access server device connected to an outdoor device via the Internet performs authentication of the outdoor device, and a home gateway device disposed at an entrance of a home network communicates only with the access server device, thereby preventing unauthorized access from the outdoor device.

此外,在专利文献2中,公开了特别考虑服务器的负担,不经由特别的服务器(网闸:Gatekeeper)而进行对等(peer to peer)通信的IP电话装置。In addition, Patent Document 2 discloses an IP telephone device that performs peer-to-peer communication without going through a special server (Gatekeeper) in particular in consideration of the load on the server.

【专利文献1】日本专利特开2002-77274号公报[Patent Document 1] Japanese Patent Laid-Open No. 2002-77274

【专利文献2】日本专利特开2003-158553号公报[Patent Document 2] Japanese Patent Laid-Open No. 2003-158553

发明内容Contents of the invention

但是,在专利文献1所公开的技术中,在授权的室外装置与室内机器进行数据通信的情况下,上述数据必须经由上述访问服务器装置。因此,在通信数据集中的情况下和进行大容量的数据通信的情况下,访问服务器装置的负担增大。由此,在这种情况下,与家庭网络的通信速度降低,或者存在通信被阻断的可能性。However, in the technique disclosed in Patent Document 1, when an authorized outdoor device performs data communication with an indoor unit, the data must pass through the access server device. Therefore, when communication data is concentrated and when large-capacity data communication is performed, the load on the access server device increases. Therefore, in this case, the communication speed with the home network decreases, or there is a possibility that the communication is blocked.

另一方面,在专利文献2所述的技术中,虽然因为不需要特别的服务器(网闸),故对于服务器等的高负担被减轻,但是未对未授权的访问进行考虑。为了防止未授权的访问,有必要通过各室内机器进行室外装置的认证。在此情况下,如果增加与室内机器通信的室外装置,则产生必须逐一更新各室内机器的认证功能的麻烦。On the other hand, in the technology described in Patent Document 2, since a special server (gatekeeper) is not required, the high load on the server and the like is reduced, but unauthorized access is not considered. In order to prevent unauthorized access, it is necessary to perform authentication of the outdoor unit by each indoor unit. In this case, if the number of outdoor devices communicating with the indoor units is increased, it is troublesome that the authentication function of each indoor unit must be updated one by one.

此外,同样,在专利文献2所述的技术中,未公开在从显示画面的规格不同的各种机型的室外装置访问时,将显示画面变更成适于该室外装置的各机型。因此,因室外装置的机型不同,存在着对等通信时的室外装置的显示画面不是最佳的可能性。Also, similarly, the technology described in Patent Document 2 does not disclose changing the display screen to be suitable for each model of the outdoor device when accessing from various models of outdoor devices having different display screen specifications. Therefore, depending on the model of the outdoor device, the display screen of the outdoor device during peer-to-peer communication may not be optimal.

本发明鉴于上述课题而作成,其目的在于提供一种减轻对服务器的负担、安全性高、且可以适应更多的室外装置的机型的对家庭网络的访问技术。The present invention has been made in view of the above-mentioned problems, and an object of the present invention is to provide a home network access technology that reduces the burden on a server, is highly secure, and can be applied to a larger number of outdoor device models.

为了实现上述目的,本发明提供以下的技术。也就是说,本发明的家庭网关装置,是经由网络与室外装置和外部网关装置连接的家庭网关装置,具有:保持涉及规定的装置的信息的存储部;和控制与上述室外装置之间的访问的访问控制部,上述访问控制部将从上述存储部取得的涉及上述规定的装置的信息发送到上述外部网关装置,在上述外部网关装置判断从上述室外装置取得的涉及上述室外装置的信息符合涉及上述规定的装置的信息的情况下,上述访问控制部不经由上述外部网关装置而进行与上述室外装置通信的控制。In order to achieve the above objects, the present invention provides the following techniques. That is, the home gateway device of the present invention is a home gateway device connected to an outdoor device and an external gateway device via a network, and has: a storage unit that holds information related to a predetermined device; and controls access to the outdoor device. an access control unit, the access control unit transmits the information related to the specified device obtained from the storage unit to the external gateway device, and the external gateway device judges that the information related to the outdoor device obtained from the outdoor device conforms to the In the case of the information of the predetermined device, the access control unit controls communication with the outdoor device without passing through the external gateway device.

根据上述构成,例如,经由服务器装置所进行的关于来自室外装置的访问的认证成功后,室外装置可与家庭网关装置进行对等通信。由此,可以减轻对服务器的负担,而且可以确保高的安全性。According to the above configuration, for example, after successful authentication of access from the outdoor device via the server device, the outdoor device can perform peer-to-peer communication with the home gateway device. Thus, the load on the server can be reduced, and high security can be ensured.

为了实现上述目的,本发明还提供以下的技术。也就是说,根据本发明的家庭网关装置,是经由网络与室外装置、外部网关装置和连接管理装置连接的家庭网关装置,具有:保持涉及规定的装置的信息的存储部;和控制与上述室外装置之间的访问的访问控制部;和画面显示信息成生部,上述访问控制部将从上述存储部取得的涉及上述规定的装置的信息发送到上述外部网关装置,在上述外部网关装置判断从上述室外装置取得的涉及上述室外装置的信息符合涉及上述规定的装置的信息的情况下,上述访问控制部不经由上述外部网关装置而进行与上述室外装置之间的通信的控制。前述画面信息生成部,在涉及上述室外装置的信息符合关于上述规定的装置的信息的情况下,使用从上述室外装置取得的涉及上述室外装置的信息,生成对应于上述室外装置的画面显示信息。In order to achieve the above objects, the present invention also provides the following techniques. That is, the home gateway device according to the present invention is a home gateway device connected to an outdoor device, an external gateway device, and a connection management device via a network, and has: a storage unit that holds information related to a predetermined device; an access control unit for access between devices; and a screen display information generation unit, wherein the access control unit transmits the information related to the predetermined device obtained from the storage unit to the external gateway device, When the information related to the outdoor device obtained by the outdoor device matches the information related to the predetermined device, the access control unit controls communication with the outdoor device without going through the external gateway device. The screen information generation unit generates screen display information corresponding to the outdoor device using the information related to the outdoor device acquired from the outdoor device when the information on the outdoor device matches the information on the predetermined device.

根据上述构成,例如,可以提供适于画面显示性能不同的室外装置的各种机型,可营造对用户良好的使用环境。According to the above configuration, for example, it is possible to provide various models of outdoor devices with different screen display performances, and to create a user-friendly usage environment.

根据本发明,既减轻对服务器的负担,又确保高的安全性而与家庭网络进行通信成为可能。According to the present invention, it becomes possible to communicate with a home network while reducing the burden on the server while ensuring high security.

此外根据本发明,可以提供适于画面显示性能不同的室外装置的各种机型,营造对用户良好的使用环境。In addition, according to the present invention, it is possible to provide various types of outdoor devices suitable for different screen display performances, and to create a user-friendly usage environment.

附图说明Description of drawings

图1是本发明的一个实施方式的室内外通信系统的概略构成图。FIG. 1 is a schematic configuration diagram of an indoor-outdoor communication system according to an embodiment of the present invention.

图2是本发明的一个实施方式的信息处理装置的硬件构成图。FIG. 2 is a hardware configuration diagram of an information processing device according to an embodiment of the present invention.

图3是本发明的一个实施方式的连接机器认证信息数据库的数据结构图。FIG. 3 is a data structure diagram of a connected device authentication information database according to an embodiment of the present invention.

图4是本发明的一个实施方式的用户认证信息数据库的数据结构图。FIG. 4 is a data structure diagram of a user authentication information database according to an embodiment of the present invention.

图5是本发明的一个实施方式的连接管理信息数据库的数据结构图。FIG. 5 is a data structure diagram of a connection management information database according to an embodiment of the present invention.

图6是本发明的一个实施方式的家庭网络连接机器管理信息数据库的数据结构图。FIG. 6 is a data structure diagram of a home network connected device management information database according to an embodiment of the present invention.

图7是本发明的一个实施方式的装置信息登录处理的程序框图。FIG. 7 is a flowchart of device information registration processing according to one embodiment of the present invention.

图8是本发明的一个实施方式的装置信息登录处理的程序框图。FIG. 8 is a flowchart of device information registration processing according to one embodiment of the present invention.

图9是本发明的一个实施方式的连接开始处理的程序框图。FIG. 9 is a flowchart of connection start processing according to one embodiment of the present invention.

图10是本发明的一个实施方式的机器控制处理的程序框图。Fig. 10 is a flowchart of machine control processing according to one embodiment of the present invention.

图11是本发明的一个实施方式的便携电话的画面构成图。FIG. 11 is a screen configuration diagram of a mobile phone according to an embodiment of the present invention.

图12是本发明的一个实施方式的便携电话的画面构成图。Fig. 12 is a screen configuration diagram of a mobile phone according to an embodiment of the present invention.

图13是本发明的一个实施方式的连接结束处理的程序框图。Fig. 13 is a flow chart of connection end processing according to one embodiment of the present invention.

图14是本发明的一个实施方式的对应机型信息数据库的数据结构图。Fig. 14 is a data structure diagram of a corresponding model information database according to an embodiment of the present invention.

图15a是本发明的一个实施方式的连接开始处理的程序框图。Fig. 15a is a flowchart of connection start processing according to one embodiment of the present invention.

图15b是本发明的一个实施方式的连接开始处理的程序框图。Fig. 15b is a flow diagram of connection start processing according to one embodiment of the present invention.

图16是本发明的一个实施方式的机器控制处理的程序框图。Fig. 16 is a flowchart of machine control processing according to one embodiment of the present invention.

图17是本发明的一个实施方式的连接结束处理的程序框图。Fig. 17 is a flow diagram of connection end processing according to one embodiment of the present invention.

图18是本发明的一个实施方式的连接机器认证信息数据库的数据结构图。Fig. 18 is a data structure diagram of a connected device authentication information database according to an embodiment of the present invention.

1…便携电话、2…便携电话专用(Career)网网关装置、3…便携电话网关装置、4…访问管理服务器装置、5…路由装置、6…家庭网关装置、7…室内装置、8…通信介质、9…通信介质、10…通信介质、11…通信控制部、12…浏览器部、31…通信控制部、32…访问管理部、33…画面显示信息生成部、34…用户认证部、35…认证信息数据库、41…通信控制部、42…连接认证部、43…连接管理部、44…装置信息数据库、61…通信控制部、62…访问控制部、63…画面显示信息生成部、64…机器管理控制部、65…认证信息数据库、66…装置信息数据库、67…对应机型信息数据库、71…通信控制部、72…控制部、80…室内系统、101…CPU、102…主存储部、103…通信控制部、104…辅助存储部、105…输入部、106…输出部、700…画面显示、701…按钮显示、702…画面显示、703…按钮显示、704…按钮显示1...Mobile phone, 2...Career network gateway device for mobile phone, 3...Career network gateway device, 4...Access management server device, 5...Routing device, 6...Home gateway device, 7...Indoor device, 8...Communication Media, 9...communication medium, 10...communication medium, 11...communication control unit, 12...browser unit, 31...communication control unit, 32...access management unit, 33...screen display information generation unit, 34...user authentication unit, 35...Authentication information database, 41...Communication control unit, 42...Connection authentication unit, 43...Connection management unit, 44...Device information database, 61...Communication control unit, 62...Access control unit, 63...Screen display information generation unit, 64...Machine management control section, 65...Authentication information database, 66...Device information database, 67...Corresponding model information database, 71...Communication control section, 72...Control section, 80...Indoor system, 101...CPU, 102...Main Storage unit, 103…communication control unit, 104…auxiliary storage unit, 105…input unit, 106…output unit, 700…screen display, 701…button display, 702…screen display, 703…button display, 704…button display

具体实施方式Detailed ways

下面,参照附图说明本发明的实施方式的一例。Hereinafter, an example of embodiment of the present invention will be described with reference to the drawings.

首先,说明本实施方式的室内外通信系统的构成。如图1所示,本实施方式的室内外通信系统包括经由通信介质9所连接的便携电话专用网网关装置2、便携电话网关装置3、访问管理服务器装置4、以及室内系统80。室内系统80设置在单家独院住宅和集合住宅的各户中。此外在本例中,便携电话专用网网关装置2为便携电话服务公司(专业:Career)的基站内的设备。此外,便携电话网关装置3和访问管理服务器装置4配置在位于户建住宅和机器的外部的数据中心内。而且在本例中,构成为由数据中心内的便携电话网关装置3和访问管理服务器装置4总括管理多个户建住宅和机器。First, the configuration of the indoor and outdoor communication system of this embodiment will be described. As shown in FIG. 1 , the indoor and outdoor communication system of this embodiment includes a mobile phone private network gateway device 2 , a mobile phone gateway device 3 , an access management server device 4 , and an indoor system 80 connected via a communication medium 9 . The indoor system 80 is installed in each household of a detached house or a condominium. In addition, in this example, the mobile phone private network gateway device 2 is a device in a base station of a mobile phone service company (professional: Career). In addition, the mobile phone gateway device 3 and the access management server device 4 are arranged in a data center located outside the residential buildings and equipment. Furthermore, in this example, the mobile phone gateway device 3 and the access management server device 4 in the data center collectively manage a plurality of residential buildings and devices.

室内系统80包括与通信介质9连接的路由装置5、家庭网关装置6、以及室内装置7。各装置5~7经由室内通信介质8连接。The indoor system 80 includes a routing device 5 connected to a communication medium 9 , a home gateway device 6 , and an indoor device 7 . The respective devices 5 to 7 are connected via an indoor communication medium 8 .

此外,在本室内外通信系统中,包括便携电话装置1,经由便携电话专用网10与室内外通信系统连接。虽然在本例中,作为访问室内系统80的室外装置,以便携电话为例进行说明,但是也可以使用便携电话以外的装置。例如,作为室外装置也可以使用便携信息终端(PDA)或移动PC(Personal Computer:个人计算机),也可以使用具有通信功能的游戏机等便携通信装置。In addition, this indoor and outdoor communication system includes a mobile phone device 1 and is connected to the indoor and outdoor communication system via a mobile phone dedicated network 10 . In this example, a mobile phone is used as an example of an outdoor device that accesses the indoor system 80, but devices other than the mobile phone may also be used. For example, a portable information terminal (PDA) or a mobile PC (Personal Computer: personal computer) can also be used as an outdoor device, and a portable communication device such as a game machine having a communication function can also be used.

图1所示的室内外通信系统中所包含的各装置(便携电话装置1、便携电话专用网网关装置2、便携电话网关装置3、访问管理服务器装置4、路由装置5、家庭网关装置6、室内装置7),全都由具有能够运行规定的软件的通常的硬件构成的信息处理装置实现。Each device (mobile phone device 1, portable phone private network gateway device 2, mobile phone gateway device 3, access management server device 4, routing device 5, home gateway device 6, All the indoor devices 7) are realized by an information processing device having a normal hardware configuration capable of running predetermined software.

具体地说,这些信息处理装置,全都为图2所示的构成。也就是说,信息处理装置包括CPU(运算处理部)101、主存储部102、通信控制部103、辅助存储部104、输入部105、以及输出部106。而且各部经由总线107相互连接,构成为在各部之间能够传送所需的信息。Specifically, all of these information processing devices have the configuration shown in FIG. 2 . That is, the information processing device includes a CPU (calculation processing unit) 101 , a main storage unit 102 , a communication control unit 103 , an auxiliary storage unit 104 , an input unit 105 , and an output unit 106 . Furthermore, each part is connected to each other via the bus 107, and it is comprised so that necessary information can be transmitted between each part.

CPU101由预先储存在主存储部102和辅助存储部104中的程序进行规定的动作。主存储部102或者作为工作区域发挥作用,或者是用于储存所需的程序的要素,例如对前者由RAM,对后者由ROM来实现。通信控制部103是经由各种通信介质,用于与连接在同一通信介质的装置发送接收信息(数据)的要素,可以由例如调制解调器、网络适配器、无线发送接收装置等来实现。辅助存储部104或者保存用于控制信息处理装置的动作的程序,或者保持信息处理装置的动作所需的信息,可以由例如半导体盘、硬盘(HDD)、光盘等来实现。输入部105是装置利用者(用户)用于对信息处理装置输入必要的命令和信息的要素。输入部105可以由例如TV接收机中所使用的遥控器,和PC中所使用的键盘、鼠标器等来实现。输出部106是用于输出显示响应用户的操作的信息的要素。输出部106可以由例如显像管、CRT、液晶显示器、PDP、投影机、扬声器、头戴耳机等来实现。CPU 101 performs predetermined operations by programs stored in advance in main storage unit 102 and auxiliary storage unit 104 . The main storage unit 102 functions as a work area, or is an element for storing necessary programs, for example, the former is realized by a RAM, and the latter is realized by a ROM. The communication control unit 103 is an element for transmitting and receiving information (data) with devices connected to the same communication medium via various communication media, and can be realized by, for example, a modem, a network adapter, a wireless transmitting and receiving device, and the like. The auxiliary storage unit 104 stores programs for controlling the operation of the information processing device, or holds information necessary for the operation of the information processing device, and can be realized by, for example, a semiconductor disk, a hard disk (HDD), or an optical disk. The input unit 105 is an element for a device user (user) to input necessary commands and information to the information processing device. The input section 105 can be realized by, for example, a remote controller used in a TV receiver, and a keyboard, a mouse, or the like used in a PC. The output unit 106 is an element for outputting and displaying information in response to user operations. The output unit 106 can be realized by, for example, a picture tube, a CRT, a liquid crystal display, a PDP, a projector, a speaker, headphones, or the like.

此外,图2所示的信息处理装置的硬件构成是一个例子,图1的各装置1~7的硬件构成没有必要一定是这样的。例如,输出部106也可以由与信息处理装置不同的装置(电视机等)来实现。在此情况下,在信息处理装置上另外具备D/A转换器等电视信号生成装置,该装置与输出部106由AV电缆和同轴电缆等连接。此外,在构成信息处理装置的各要素之中,有与数据和程序的输入输出没有直接关系的要素的情况,也可以不包括该要素。例如,在信息处理装置执行时不需要数据输入和输出的情况下,也可以在构成中不包括输入部105和输出部106。In addition, the hardware configuration of the information processing device shown in FIG. 2 is an example, and the hardware configuration of each device 1 to 7 in FIG. 1 does not necessarily have to be like this. For example, the output unit 106 may be realized by a device (television, etc.) different from the information processing device. In this case, a television signal generating device such as a D/A converter is separately provided on the information processing device, and this device and the output unit 106 are connected by an AV cable, a coaxial cable, or the like. In addition, if there is an element not directly related to the input and output of data and programs among the various elements constituting the information processing device, this element may not be included. For example, the input unit 105 and the output unit 106 may not be included in the configuration when the information processing device does not require data input and output during execution.

此外,图1所示的室内外通信系统中所含有的室内系统80是户建住宅、集合住宅内的一户这样的一般家庭住宅中所设置的系统。In addition, the indoor system 80 included in the indoor-outdoor communication system shown in FIG. 1 is a system installed in a general family house such as a single house in a residential house or a complex.

此外,图1所示的室内外通信系统中所含有的通信介质9是由例如光缆线路、CATV、电话线路等所构成的有线介质,或者由无线介质构成的公众通信网络,或者专用通信网络。而且,在连接于通信介质9的装置之间按照规定的通信协议进行数据的交换。In addition, the communication medium 9 contained in the indoor and outdoor communication system shown in FIG. 1 is a wired medium composed of optical cable lines, CATV, telephone lines, etc., or a public communication network composed of wireless media, or a private communication network. Furthermore, data is exchanged between devices connected to the communication medium 9 according to a predetermined communication protocol.

此外,通信介质8是由例如通信电缆、电力线、内线电话线路等构成的有线介质,或者由无线介质构成的室内系统80中的LAN(局域网)。而且,在连接于通信介质8的装置之间按照规定的通信协议进行数据的交换。此外,通过对连接于通信介质8与通信介质9的双方的路由装置5进行中继,可在连接于通信介质8的装置与连接于通信介质9的装置之间按照规定的通信协议进行数据的交换。Further, the communication medium 8 is a wired medium constituted by, for example, a communication cable, a power line, an extension telephone line, etc., or a LAN (Local Area Network) in the indoor system 80 constituted by a wireless medium. Furthermore, data is exchanged between devices connected to the communication medium 8 according to a predetermined communication protocol. In addition, by relaying the routing device 5 connected to both the communication medium 8 and the communication medium 9, data can be exchanged between the device connected to the communication medium 8 and the device connected to the communication medium 9 according to a predetermined communication protocol. exchange.

而且,在通信介质9这样的室外通信网络、和通信介质8这样的室内LAN中,一般作为指定通信装置的信息的地址(IP地址)的体系不同。前者往往是在全世界唯一地分配的地址(全球地址),后者是仅在LAN内有效的地址(专用地址)。作为这种地址体系不同的网络之间的中继方式(地址变换方式),NAT(Network Address Traslation:网络地址转换法)是公知的。Furthermore, in an outdoor communication network such as the communication medium 9, and an indoor LAN such as the communication medium 8, the systems of addresses (IP addresses) generally used as information for specifying a communication device are different. The former is often an address uniquely assigned worldwide (global address), and the latter is an address valid only within a LAN (private address). NAT (Network Address Translation: Network Address Translation) is known as a relay method (address translation method) between networks having different address systems.

此外,通信介质10连接于便携电话专用网网关装置2,是包括由光缆线路、通信电缆等构成的有线介质;便携电话装置1所连接的无线介质;连接上述有线介质与上述无线介质的基站的专用通信网络。而且,在连接于通信介质10的装置之间按照规定的通信协议进行数据的交换。In addition, the communication medium 10 is connected to the gateway device 2 of the private network for mobile phones, and includes a wired medium composed of an optical cable line, a communication cable, etc.; a wireless medium connected to the mobile phone device 1; a base station connecting the above-mentioned wired medium and the above-mentioned wireless medium private communication network. Furthermore, data is exchanged between devices connected to the communication medium 10 according to a predetermined communication protocol.

而且,连接于通信介质9的便携电话专用网网关装置2具有IP地址(全球地址)。Furthermore, the mobile phone private network gateway device 2 connected to the communication medium 9 has an IP address (global address).

此外,在室外装置为便携信息终端或移动PC的情况下,各机器经由通信介质9连接于便携电话网关装置3。此时,便携信息终端或移动PC具有IP地址(全球地址)。Furthermore, when the outdoor device is a portable information terminal or a mobile PC, each device is connected to the mobile phone gateway device 3 via the communication medium 9 . At this time, the portable information terminal or mobile PC has an IP address (global address).

下面,对图1所示的室内外通信系统中所含有的各装置1~7的通过软件的运行实现的功能,和数据库的构成进行说明。Next, the functions realized by the operation of software of each of the devices 1 to 7 included in the indoor and outdoor communication system shown in FIG. 1 and the configuration of the database will be described.

便携电话装置1连接于室内系统80中所含有的家庭网关装置6,具有执行与室内装置7协作的各种服务的功能的信息处理装置。该各种服务包括例如室内装置7为录像机时的远程录像预约服务和录像图像传送服务;室内装置7为空调机时的电源接通断开服务和温度调整服务;室内装置7为防盗摄像机时的摄像机累积图像阅览服务等。如图1所示,便携电话装置1例如包括通信控制部11、浏览器部12而构成。The mobile phone device 1 is connected to the home gateway device 6 included in the indoor system 80 , and is an information processing device having a function of executing various services in cooperation with the indoor device 7 . These various services include, for example, remote recording reservation service and video image transmission service when the indoor device 7 is a video recorder; power on and off service and temperature adjustment service when the indoor device 7 is an air conditioner; Viewing service of accumulated images of cameras, etc. As shown in FIG. 1 , the mobile phone device 1 includes, for example, a communication control unit 11 and a browser unit 12 .

通信控制部11为了与浏览器部12连接于通信介质9的装置(访问管理服务器装置4、室内系统80)进行通信,具有在与便携电话专用网网关装置2之间按照规定的通信协议生成、解释、进行发送接收的功能。The communication control unit 11 has the functions of creating, Interpretation, sending and receiving functions.

浏览器部12具有取得便携电话网关装置3和家庭网关装置6生成的画面显示信息并显示在便携电话装置1的输出部106的功能。进而,浏览器部12具有将从便携电话装置1的输入部105输入的信息发送到便携电话网关装置3和家庭网关装置6的功能。而且,对于便携信息终端或移动PC的情况,也与便携电话装置1是同样的。The browser unit 12 has a function of acquiring screen display information generated by the mobile phone gateway device 3 and the home gateway device 6 and displaying it on the output unit 106 of the mobile phone device 1 . Furthermore, the browser unit 12 has a function of transmitting information input from the input unit 105 of the mobile phone device 1 to the mobile phone gateway device 3 and the home gateway device 6 . Furthermore, the same applies to the mobile phone device 1 in the case of a portable information terminal or a mobile PC.

这里所谓画面显示信息,是例如XML、HTML、小型(Compact)HTML、XHTML、SGML等标示语言和元语言等描述语言或由它们定义的语言所构成的信息等。例如,包括Web画面信息等。Here, the screen display information refers to markup languages such as XML, HTML, Compact HTML, XHTML, and SGML, and description languages such as metalanguages, or information composed of languages defined by them. For example, Web screen information and the like are included.

便携电话专用网网关装置2是具有相互变换通信介质10与通信介质9中的各规定的通信协议的功能的信息处理装置。其中,便携电话专用网网关装置2在室外装置不是便携电话时,是提供该室外装置的通信服务的通信运营商的网关装置。The mobile phone private network gateway device 2 is an information processing device having a function of mutually converting each predetermined communication protocol in the communication medium 10 and the communication medium 9 . Among them, the mobile phone dedicated network gateway device 2 is a gateway device of a communication carrier that provides communication services for the outdoor device when the outdoor device is not a mobile phone.

便携电话网关装置3是具有认证便携电话装置1的用户、和便携电话装置1的功能的信息处理装置。此外便携电话网关装置3还具有根据从家庭网关装置6取得的连接信息,进行便携电话装置1与家庭网关装置6不经由便携电话网关装置3与访问管理服务器装置4而进行通信,或者,便携电话装置1与家庭网关装置6经由便携电话网关装置3进行通信用的通信管理的功能。而且,便携电话网关装置3在室外装置不是便携电话时,是进行室外装置的认证、通信管理的外部网关装置。The mobile phone gateway device 3 is an information processing device having a function of authenticating the user of the mobile phone device 1 and the mobile phone device 1 . In addition, the mobile phone gateway device 3 also has the function of communicating with the mobile phone device 1 and the home gateway device 6 without going through the mobile phone gateway device 3 and the access management server device 4 based on the connection information obtained from the home gateway device 6, or the mobile phone The device 1 and the home gateway device 6 perform a communication management function for communication via the mobile phone gateway device 3 . Furthermore, the mobile phone gateway device 3 is an external gateway device that performs authentication of the outdoor device and communication management when the outdoor device is not a mobile phone.

这里在本实施例中,所谓“认证”是指判断保持在存储部等之中的认证信息所含有的信息与固有信息、识别信息、机型信息、口令等的信息是否一致。所谓认证成功,是指确认为与上述一致。在认证信息作为数据库被保存时,根据与一致的认证信息建立关联关系而保存的信息,便携电话等室外装置的指定等成为可能。以上说明的所谓“一致”并不仅指数据完全一致,还包含特定的建立关联关系的意思。Here, in this embodiment, "authentication" refers to judging whether the information contained in the authentication information held in the storage unit or the like is consistent with information such as unique information, identification information, model information, and a password. The so-called successful authentication means that it is confirmed to be consistent with the above. When the authentication information is stored as a database, it becomes possible to specify an outdoor device such as a mobile phone based on information stored in association with matching authentication information. The so-called "consistent" explained above does not only mean that the data are completely consistent, but also includes a specific meaning of establishing an association relationship.

如图1所示,便携电话网关装置3包括例如通信控制部31、访问管理部32、画面显示信息生成部33、和用户认证部34而构成。As shown in FIG. 1 , the mobile phone gateway device 3 includes, for example, a communication control unit 31 , an access management unit 32 , a screen display information generation unit 33 , and a user authentication unit 34 .

通信控制部31为了与画面显示信息生成部33连接于通信介质9的装置(访问管理服务器装置4、室内系统80)进行通信,具有按照规定的通信协议对消息进行生成、解释、通信的功能。进而便携电话网关装置3将认证信息数据库35保持在辅助存储部104中。The communication control unit 31 has a function of generating, interpreting and communicating messages according to a predetermined communication protocol in order to communicate with devices (access management server device 4 and in-house system 80 ) connected to the communication medium 9 by the screen display information generating unit 33 . Furthermore, the mobile phone gateway device 3 holds the authentication information database 35 in the auxiliary storage unit 104 .

访问管理部32具有经由访问管理服务器装置4发送向家庭网关装置6的连接指示信息,从家庭网关装置6取得便携电话装置1与家庭网关装置6进行数据通信所需的连接信息的功能。进而,具有根据上述连接信息中所含有的对应机型信息,进行便携电话装置1经由便携电话网关装置3与家庭网关装置6连接,还是直接(不经由便携电话网关装置3)连接于家庭网关装置6的判定的功能。在判定为便携电话装置1直接连接于家庭网关装置6的情况下,便携电话装置1根据上述连接信息连接于家庭网关装置6。The access management unit 32 has a function of transmitting connection instruction information to the home gateway device 6 via the access management server device 4 and obtaining connection information necessary for data communication between the mobile phone device 1 and the home gateway device 6 from the home gateway device 6 . Furthermore, according to the corresponding model information contained in the above-mentioned connection information, whether the mobile phone device 1 is connected to the home gateway device 6 via the mobile phone gateway device 3 or directly (not via the mobile phone gateway device 3) is connected to the home gateway device. 6. Judgment function. When it is determined that the mobile phone device 1 is directly connected to the home gateway device 6, the mobile phone device 1 is connected to the home gateway device 6 based on the connection information.

画面显示信息生成部33具有生成应该显示在便携电话装置1的浏览器部12中的画面显示信息的功能;处理从浏览器部12发送的信息的功能,以及将从家庭网关装置6发送的上述连接信息发送到浏览器部12的功能。便携电话装置1的浏览器部12因便携电话装置1的机型而在一个画面上能够显示的分辨率和功能不同。画面显示信息生成部33针对上述机型分别生成适当的画面显示信息。The screen display information generation part 33 has the function of generating the screen display information to be displayed in the browser part 12 of the mobile phone device 1; the function of processing the information sent from the browser part 12; A function to send connection information to the browser section 12 . The browser unit 12 of the mobile phone device 1 has different resolutions and functions that can be displayed on one screen depending on the model of the mobile phone device 1 . The screen display information generating unit 33 generates appropriate screen display information for each of the aforementioned models.

这里,所谓生成适当的画面显示信息,是指针对机型改写构成画面显示信息的描述语言信息,在各机型中可以没有问题地显示生成语言。在该情况下,为了适应不同的机型,不仅在同一描述语言中改写数据内容,而且还包括进行描述语言的种类的变更。Here, generating appropriate screen display information refers to rewriting the description language information constituting the screen display information for each model, so that the generated language can be displayed without problems in each model. In this case, in order to adapt to different models, not only the data content is rewritten in the same description language, but also the type of description language is changed.

特别是,在画面显示信息的生成主要是描述语言的内容的生成的情况下,画面显示信息生成部33还称为描述语言信息生成部。In particular, when the generation of screen display information is mainly the generation of content in a descriptive language, the screen display information generating unit 33 is also referred to as a descriptive language information generating unit.

用户认证部34具有判断从浏览器部12发送的用户口令(由用户输入)与作为便携电话装置1分别固有(唯一)的信息的便携电话信息(例如便携电话的制造编号或机型信息或上述制造编号与上述机型信息两方的信息)是否与预先储存在认证信息数据库35中的信息一致的功能。The user authentication unit 34 has mobile phone information (for example, the serial number or model information of the mobile phone or the above-mentioned information) for judging the user password (input by the user) sent from the browser unit 12 and the information inherent (unique) to the mobile phone device 1 respectively. The function of whether the information of both the manufacturing number and the above-mentioned model information) is consistent with the information stored in the authentication information database 35 in advance.

此外,在便携信息终端或移动PC的情况下,上述便携电话信息也可以不是上述机型信息,而是浏览器部12中固有的信息。In addition, in the case of a portable information terminal or a mobile PC, the above-mentioned mobile phone information may be information inherent in the browser unit 12 instead of the above-mentioned model information.

如图4所示,认证信息数据库35包括用户口令301、便携电话信息302和连接目的地信息303。各项目中,预先通过某种方法设定每个用户的信息。在用户口令301中,由用户自己决定只有自己知道的信息。在便携电话信息302中,设定作为便携电话装置分别固有(唯一)的信息的便携电话信息。但是,在上述机型信息被设定的情况下,该机型信息针对便携电话装置1的每一种机型是固有的。此外,在便携信息终端或移动PC的情况下,上述便携电话信息也可以是浏览器部12中固有的信息。在该情况下,上述便携电话信息针对每个浏览器部12的种类、版本是固有的。登录信息304是便携电话固有的信息保持在便携电话信息302中的例子,登录信息305是便携电话固有的信息与机型信息保持在便携电话信息302中的例子。在连接目的地信息303中,设定用户口令301的用户将要连接的家庭网关装置6的连接目的地信息。As shown in FIG. 4 , the authentication information database 35 includes a user password 301 , mobile phone information 302 and connection destination information 303 . In each item, information for each user is set in advance by a certain method. In the user password 301, the user decides information that only he or she knows. In the mobile phone information 302, mobile phone information is set as information unique to each mobile phone device (unique). However, when the above model information is set, the model information is specific to each model of the mobile phone device 1 . In addition, in the case of a mobile information terminal or a mobile PC, the above-mentioned mobile phone information may be information inherent in the browser unit 12 . In this case, the mobile phone information described above is specific to each type and version of the browser unit 12 . The registration information 304 is an example in which mobile phone-specific information is held in the mobile phone information 302 , and the registration information 305 is an example in which mobile phone-specific information and model information are held in the mobile phone information 302 . In the connection destination information 303, the connection destination information of the home gateway device 6 to which the user of the user password 301 is to connect is set.

由保持在用户口令301中的信息与保持在便携电话信息302中的信息,就可以单一地指定某位用户的某个便携电话装置。上述用户认证部34使用认证信息数据库35的内容,指定(认证)用户与便携电话装置。From the information held in the user password 301 and the information held in the mobile phone information 302, it is possible to uniquely specify a certain mobile phone device of a certain user. The user authentication unit 34 specifies (authenticates) the user and the mobile phone device using the content of the authentication information database 35 .

访问管理服务器装置4是具有接收便携电话网关装置3发送的向家庭网关装置6的连接指示信息(包括设定在图4的连接目的地信息303中的信息),检索符合的家庭网关装置6并对该家庭网关装置6发送上述连接指示信息的中继功能的信息处理装置。The access management server device 4 is capable of receiving connection instruction information (including information set in the connection destination information 303 in FIG. An information processing device with a relay function that transmits the connection instruction information to the home gateway device 6 .

如图1所示,访问管理服务器装置4例如包括通信控制部41、连接认证部42、和连接管理部43而构成。As shown in FIG. 1 , the access management server device 4 includes, for example, a communication control unit 41 , a connection authentication unit 42 , and a connection management unit 43 .

通信控制部41为了与连接于通信介质9的装置(便携电话网关装置3、室内系统80)进行通信,具有按照规定的通信协议对消息进行生成、解释、通信的功能。进而访问管理服务器装置4将装置信息数据库44保持在辅助存储部104中。The communication control unit 41 has functions of generating, interpreting, and communicating messages according to a predetermined communication protocol in order to communicate with devices connected to the communication medium 9 (the mobile phone gateway device 3 and the home system 80 ). Furthermore, the access management server device 4 holds the device information database 44 in the auxiliary storage unit 104 .

连接认证部42具有认证与访问管理服务器装置4连接的连接装置(便携电话网关装置3、家庭网关装置6)的经授权的功能。作为认证方法,可运用使用PKI(Public Key Infrastructure:公钥基础设施)中的证明书的认证方法。The connection authentication unit 42 has a function of authenticating the authorization of the connection devices (the mobile phone gateway device 3 and the home gateway device 6 ) connected to the access management server device 4 . As an authentication method, an authentication method using a certificate in PKI (Public Key Infrastructure: Public Key Infrastructure) can be used.

连接管理部43是在装置信息数据库44中管理上述连接装置的信息的要素。而且连接管理部43具有根据来自便携电话网关装置3的连接指示信息检索符合的家庭网关装置6而将上述连接指示信息通知到该家庭网关装置6的功能。进而连接管理部43还具有将来自该家庭网关装置6的返回信息传送到上述便携电话网关装置3的功能。The connection management unit 43 is an element that manages the above-mentioned connected device information in the device information database 44 . Furthermore, the connection management unit 43 has a function of searching for a suitable home gateway device 6 based on the connection instruction information from the mobile phone gateway device 3 and notifying the above-mentioned connection instruction information to the home gateway device 6 . Furthermore, the connection management unit 43 also has a function of transmitting the return information from the home gateway device 6 to the mobile phone gateway device 3 .

如图5所示,装置信息数据库44包括装置识别信息401、IP地址402、和端口编号403。在装置识别信息401中,设定单一地指定上述连接装置的信息。As shown in FIG. 5 , the device information database 44 includes device identification information 401 , IP address 402 , and port number 403 . In the device identification information 401, information that uniquely specifies the connection device described above is set.

在IP地址402中,设定由装置识别信息401所指定的连接装置的IP地址(全球地址)。其中,在专用地址分配给该连接装置的情况下,该连接装置经由通信介质8连接,而且,设定连接于通信介质9的装置(图1中路由装置5)的IP地址。In the IP address 402, the IP address (global address) of the connected device specified by the device identification information 401 is set. Wherein, when a dedicated address is assigned to the connection device, the connection device is connected via the communication medium 8, and the IP address of the device (routing device 5 in FIG. 1 ) connected to the communication medium 9 is set.

在端口编号403中,设定将上述连接指示信息和上述返回信息发送到访问管理服务器装置4由装置识别信息401所指定的连接装置时使用的端口编号。端口编号是IP(Internet Protocol:因特网协议)网络中所使用的端口编号。In the port number 403, a port number used when the connection instruction information and the return information are transmitted to the connection device specified by the device identification information 401 of the access management server device 4 is set. The port number is a port number used in an IP (Internet Protocol: Internet Protocol) network.

装置信息数据库44的各项目的数据通过接收来自上述连接装置的登录信息来设定。其中,作为上述连接指示信息和上述返回信息,上述登录信息的通信协议,例如IP电话服务中所用的SIP(SessionInitiation Protocol:会话初始化协议)是公知的,在访问管理服务器装置4中也可以运用它。此外,在上述通信协议中运用SIP的情况下,在连接目的地信息303和装置识别信息401中设定SIP-URI(UniformResource Identifiers:通用资源标识符)。The data of each item of the device information database 44 is set by receiving the registration information from the above-mentioned connection device. Among them, as the above-mentioned connection instruction information and the above-mentioned return information, the communication protocol of the above-mentioned login information, for example, SIP (Session Initiation Protocol: Session Initiation Protocol) used in the IP telephone service is known, and it can also be used in the access management server device 4. . In addition, when using SIP as the communication protocol described above, SIP-URI (Uniform Resource Identifiers: Universal Resource Identifiers) is set in the connection destination information 303 and the device identification information 401 .

路由装置5是连接通信介质9与通信介质8的信息处理装置。而且路由装置5具有中继或者拒绝像连接于通信介质9的便携电话网关装置3,与连接于通信介质8的家庭网关装置6那样,连接于不同的通信介质的装置之间的通信的功能。The routing device 5 is an information processing device that connects the communication medium 9 and the communication medium 8 . Furthermore, the routing device 5 has a function of relaying or rejecting communication between devices connected to different communication media such as the mobile phone gateway device 3 connected to the communication media 9 and the home gateway device 6 connected to the communication media 8 .

路由装置5可运用一般流通的宽频带路由装置。路由装置5包括以下要素。也就是说,与连接于通信介质9的室外装置(便携电话网关装置3)按照规定的通信协议进行数据传送的外部通信控制部;将来自连接于通信介质9的室外装置的通信信息向连接于通信介质8的室内装置(家庭网关装置6)进行中继(或者进行其相反处理)的端口变换部;根据来自连接于通信介质8的室内装置的请求控制由端口变换部参照的端口变换设定的端口变换控制部;然后与连接于通信介质8的室内装置按照规定的通信协议进行数据传送的内部通信控制部。As the routing device 5, a generally available broadband routing device can be used. The routing device 5 includes the following elements. That is to say, an external communication control unit that performs data transfer with an outdoor device (portable phone gateway device 3) connected to the communication medium 9 according to a predetermined communication protocol; The port conversion unit that the indoor device (home gateway device 6) of the communication medium 8 performs relaying (or performs its reverse processing); according to the request from the indoor device connected to the communication medium 8, the port conversion setting referred to by the port conversion unit is controlled Then, the internal communication control unit that performs data transmission with the indoor device connected to the communication medium 8 according to the prescribed communication protocol.

其中,作为端口变换部中的中继方式可运用上述NAT。此外,作为端口变换控制部中的端口变换设定控制方式,由UPnP IGD(UniversalPlug and Play Internet Gateway Device:通用即插即用因特网网关装置)中所规定的控制方法是公知的,也可运用于路由装置5。However, the above-mentioned NAT can be used as the relay system in the port conversion unit. In addition, as the port conversion setting control method in the port conversion control unit, the control method specified in UPnP IGD (Universal Plug and Play Internet Gateway Device: Universal Plug and Play Internet Gateway Device) is known and can also be applied to Routing device 5.

家庭网关装置6是具有以下功能的信息处理装置。也就是说,对经由访问管理服务器装置4从便携电话网关装置3所发送的连接指示信息返回用于访问该家庭网关装置6的连接信息的功能;保持上述连接指示信息中所含有的便携电话装置1的便携电话信息,进而,根据上述连接信息对来自便携电话装置1的连接请求信息,通过比较上述连接请求信息中所含有的便携电话装置1的便携电话信息与上述保持的便携电话信息,进行上述便携电话装置1的认证的功能;对上述便携电话装置1生成并发送用于控制室内装置7的画面的功能;对便携电话网关装置3发送室内装置7的信息和用于控制室内装置7的信息的功能;此外,根据来自便携电话装置1和便携电话网关装置3的请求控制室内装置7的功能。The home gateway device 6 is an information processing device having the following functions. That is to say, the function of returning the connection information for accessing the home gateway device 6 to the connection instruction information sent from the mobile phone gateway device 3 via the access management server device 4; 1, and further, based on the above-mentioned connection information, for the connection request information from the mobile phone device 1, by comparing the mobile phone information of the mobile phone device 1 contained in the above-mentioned connection request information with the above-mentioned held mobile phone information, The function of authentication of the above-mentioned mobile phone device 1; the function of generating and transmitting the screen for controlling the indoor device 7 to the above-mentioned mobile phone device 1; In addition, the function of the indoor unit 7 is controlled according to the request from the portable telephone device 1 and the portable telephone gateway device 3 .

如图1所示,家庭网关装置6包括通信控制部61、访问控制部62、画面显示信息生成部、和机器管理控制部。进而家庭网关装置6将认证信息数据库65、装置信息数据库66、对应机型信息数据库67保持在主存储部102或辅助存储部104中。As shown in FIG. 1 , the home gateway device 6 includes a communication control unit 61 , an access control unit 62 , a screen display information generation unit, and a device management control unit. Furthermore, the home gateway device 6 holds the authentication information database 65 , the device information database 66 , and the corresponding model information database 67 in the main storage unit 102 or the auxiliary storage unit 104 .

通信控制部61为了访问控制部62、画面显示信息生成部63和机器管理控制部64,经由连接于通信介质8的装置(路由装置5、室内装置7)和路由装置5与连接于通信介质9的装置(便携电话装置1、访问管理服务器装置4)进行通信,具有按照规定的通信协议对消息进行生成、解释、通信的功能。The communication control unit 61 communicates with the access control unit 62, the screen display information generation unit 63, and the device management control unit 64 via devices connected to the communication medium 8 (routing device 5, indoor device 7) and the routing device 5 and connected to the communication medium 9. The device (mobile phone device 1, access management server device 4) communicates with each other, and has the functions of generating, interpreting, and communicating messages according to a predetermined communication protocol.

访问控制部62具有以下功能。也就是说,对经由访问管理服务器装置4从便携电话网关装置3发送的连接指示信息,生成认证信息(权标:Token)的功能;生成并返回包括该权标、保持在对应机型信息数据库67中的对应机型信息、路由装置5中设定的外部端口编号在内的用于访问该家庭网关装置6的连接信息的功能;将上述权标与上述连接指示信息中所含有的便携电话装置1的便携电话信息与上述外部端口编号保持在认证信息数据库65中的功能;根据上述连接信息所执行的对来自便携电话装置1的连接请求信息,通过上述连接请求信息中所含有的便携电话装置1的便携电话信息与上述保持在认证信息数据库65中的便携电话信息的比较,以及上述连接请求信息中所含有的权标与上述保持在认证信息数据库65中的权标的比较,进行上述便携电话装置1的认证的功能;用于进行将来自便携电话装置1的数据通信向家庭网关装置6中继的端口变换设定信息(外部端口编号、内部端口编号、家庭网关装置6的IP地址)发送到路由装置5的端口变换控制部,设定、解除端口变换的功能。The access control unit 62 has the following functions. That is to say, the function of generating authentication information (token) for connection instruction information transmitted from the mobile phone gateway device 3 via the access management server device 4; The corresponding model information in 67, the function of accessing the connection information of the home gateway device 6 including the external port number set in the routing device 5; The function of storing the mobile phone information of the device 1 and the above-mentioned external port number in the authentication information database 65; the connection request information from the mobile phone device 1 executed based on the above-mentioned connection information is passed through the mobile phone information contained in the above-mentioned connection request information. The mobile phone information of the device 1 is compared with the mobile phone information held in the authentication information database 65, and the token contained in the connection request information is compared with the token held in the authentication information database 65 to perform the above-mentioned portability. Function of authentication of the telephone device 1; port conversion setting information (external port number, internal port number, IP address of the home gateway device 6) for relaying data communication from the mobile phone device 1 to the home gateway device 6 It is sent to the port conversion control unit of the router 5 to set and cancel the port conversion function.

这里所说的所谓对应机型,是室外装置的机型当中的家庭网关装置6可以进行与其他机型不同的通信方法的机型,室外装置的机型当中的家庭网关装置6是可以生成与对其他机型的数据不同的数据的机型等。该对应机型的设定或者在家庭网关装置6的生产时设定,或者在家庭网关装置6上设置外部输入部而设定和更新设定,也可以通过经由网络进行更新设定。以下只要未另外特别说明,由上述这样的设定方法来设定,将关于机型的信息保持在对应机型信息数据库67中的机型表达为“对应机型”。The so-called compatible model mentioned here is a model in which the home gateway device 6 among the outdoor device models can perform a communication method different from other models, and the home gateway device 6 among the outdoor device models can generate Models of data different from data of other models, etc. The setting of the compatible model is either set at the time of production of the home gateway device 6 , or the setting and updating of the home gateway device 6 is provided with an external input unit, or the setting can be updated via the network. Hereinafter, unless otherwise specified, a model whose information about the model is set in the above-mentioned setting method and held in the corresponding model information database 67 is expressed as a "corresponding model".

画面显示信息生成部63具有生成将要在便携电话装置1的浏览器部12上显示的画面显示信息的功能,和处理从浏览器部12发送的信息的功能。如上所述,便携电话装置1的浏览器部12在一个画面上能够显示的分辨率或功能因便携电话装置1机型而不同。画面显示信息生成部63针对保持在对应机型信息数据库67中的机型分别生成适当的画面显示信息。The screen display information generation unit 63 has a function of generating screen display information to be displayed on the browser unit 12 of the mobile phone device 1 and a function of processing information transmitted from the browser unit 12 . As described above, the resolution and functions that can be displayed on one screen by the browser unit 12 of the mobile phone device 1 differ depending on the model of the mobile phone device 1 . The screen display information generation unit 63 generates appropriate screen display information for each of the models held in the corresponding model information database 67 .

这里,所谓生成适当的画面显示信息,例如是针对机型改写构成画面显示信息的描述语言信息,生成描述语言信息的内容以便在各机型中可以没有问题地显示。在该情况下,为了对应不同的机型,不仅在同一描述语言中改写数据内容,而且包括进行描述语言的种类的变更。Here, generating appropriate screen display information means, for example, rewriting the description language information constituting the screen display information for each model, and generating the content of the description language information so that it can be displayed without problems in each model. In this case, in order to correspond to different models, not only the data content is rewritten in the same description language, but also the type of description language is changed.

与上述画面显示信息生成部33同样,在画面显示信息的生成主要是描述语言的内容的生成的情况下,画面显示信息生成部63也称为描述语言信息生成部。Like the screen display information generation unit 33 described above, when the generation of the screen display information is mainly the generation of content in a descriptive language, the screen display information generation unit 63 is also referred to as a descriptive language information generation unit.

机器管理控制部64具有由装置信息数据库66一元管理连接于通信介质8的一个以上的室内装置7,根据从便携电话网关装置3的画面显示信息生成部33或画面显示信息生成部63取得的来自便携电话装置1的机器控制请求控制室内装置7的功能。The device management control unit 64 has a unitary management of one or more indoor devices 7 connected to the communication medium 8 by the device information database 66, based on the information from the screen display information generation unit 33 or the screen display information generation unit 63 of the mobile phone gateway device 3. The device control request of the mobile phone device 1 controls the function of the indoor device 7 .

如图3所示,认证信息数据库65包括便携电话信息201、权标202、外部端口编号203、和内部端口编号204。As shown in FIG. 3 , the authentication information database 65 includes mobile phone information 201 , token 202 , external port number 203 , and internal port number 204 .

在便携电话信息201中,设定从便携电话网关发送的连接指示信息所含有的便携电话信息。便携电话信息与图4中的便携电话信息302中所设定的信息同种。In the mobile phone information 201, the mobile phone information included in the connection instruction information transmitted from the mobile phone gateway is set. The mobile phone information is of the same type as the information set in the mobile phone information 302 in FIG. 4 .

在权标202中,设定家庭网关装置6生成的认证数据。该家庭网关装置6发送的上述连接信息中含有上述连接信息而发送到便携电话装置1。Authentication data generated by the home gateway device 6 is set in the token 202 . The connection information transmitted from the home gateway device 6 is transmitted to the mobile phone device 1 including the connection information.

外部端口编号203为了将来自便携电话装置1的数据通信向家庭网关装置6进行中继,对路由装置5设定用于端口变换设定、解除的通信介质9侧的端口编号。The external port number 203 is set in the router 5 as a port number on the communication medium 9 side for port conversion setting and release in order to relay data communication from the mobile phone device 1 to the home gateway device 6 .

内部端口编号204为了将来自便携电话装置1的数据通信向家庭网关装置6进行中继,对路由装置5设定用于端口变换设定、解除的通信介质8侧的端口编号。The internal port number 204 sets a port number on the communication medium 8 side for setting and canceling port conversion in the routing device 5 in order to relay data communication from the mobile phone device 1 to the home gateway device 6 .

有限期限205设定权标202中所设定的认证数据的有限期限(日期与时刻)。The limited period 205 sets the limited period (date and time) of the authentication data set in the token 202 .

便携电话装置1由浏览器部12、便携电话网关装置3由画面显示信息生成部33访问路由装置5的IP地址的上述外部端口编号。路由装置5通过将上述外部端口编号的访问传送到上述家庭网关装置6的IP地址的内部端口编号,来自便携电话装置1或便携电话网关装置3的通信数据到达上述家庭网关装置6。The browser unit 12 of the mobile phone device 1 and the mobile phone gateway device 3 access the above-mentioned external port number of the IP address of the router device 5 through the screen display information generation unit 33 . The routing device 5 transmits the access of the external port number to the internal port number of the IP address of the home gateway device 6, and the communication data from the mobile phone device 1 or the mobile phone gateway device 3 reaches the home gateway device 6.

如图6所示,装置信息数据库66包括装置ID 501、装置名502、设置场所503、IP地址504、和服务URL(Uniform Resource Locator:通用资源地址)505。As shown in FIG. 6, the device information database 66 includes a device ID 501, a device name 502, an installation location 503, an IP address 504, and a service URL (Uniform Resource Locator: universal resource address) 505.

在装置ID501中,设定用于指定室内装置的单一的识别符。在装置名502中,设定用于用户识别机器的机器名称。在设置场所503中,设定表示由装置ID 501所指定的室内装置的设置场所(卧室、玄关、孩子房间、厨房等)的信息。在IP地址504中,设定由装置ID 501所指定的室内装置的IP地址。通常,设定于IP地址504的各室内装置的IP地址是专用地址,一般来说路由装置5将上述专用地址分配给各室内装置。In the device ID 501, a single identifier for specifying an indoor device is set. In the device name 502, a device name for the user to identify the device is set. In the installation place 503, information indicating the installation place (bedroom, entrance, child's room, kitchen, etc.) of the indoor device specified by the device ID 501 is set. In the IP address 504, the IP address of the indoor device specified by the device ID 501 is set. Usually, the IP address of each indoor device set in the IP address 504 is a private address, and generally, the routing device 5 assigns the above-mentioned private address to each indoor device.

在服务URL 505中,设定从该室内装置以外用于控制由装置ID501所指定的室内装置的连接目的地信息。其中,有时在设定于服务URL 505的连接目的地信息中,设定家庭网关装置6的连接目的地信息。此时,家庭网关装置6的画面显示信息生成部63或者便携电话网关装置3的画面显示信息生成部33生成用于控制室内装置7的画面。机器管理控制部64根据用户的控制指示生成室内装置7的控制信息,按照规定的通信协议将上述控制信息发送到室内装置7的控制部72。然后控制部72按照上述控制信息控制室内装置7。In the service URL 505, connection destination information for controlling the indoor device specified by the device ID 501 from other than the indoor device is set. Among them, the connection destination information of the home gateway device 6 may be set in the connection destination information set in the service URL 505. At this time, the screen display information generating unit 63 of the home gateway device 6 or the screen display information generating unit 33 of the mobile phone gateway device 3 generates a screen for controlling the indoor device 7 . The equipment management control unit 64 generates control information of the indoor unit 7 according to the user's control instruction, and transmits the control information to the control unit 72 of the indoor unit 7 according to a predetermined communication protocol. Then the control unit 72 controls the indoor unit 7 according to the above-mentioned control information.

装置信息数据库66的各项目的数据,由用户输入或者自动地从各室内装置收集设定。The data of each item of the device information database 66 is input by the user or automatically collected and set from each indoor device.

如图14所示,对应机型信息数据库67包括对应机型信息601。在对应机型信息601中,设定画面显示信息生成部63能够生成的便携电话装置1的机型信息。图14示出机型信息602和机型信息603等。虽然这些机型信息在说明上为便携电话的机型信息,但是根据情况,除了便携电话,也可以保持便携信息终端(PDA)或移动PC(PersonalComputer:个人计算机),具有通信功能的游戏机、便携通信装置等不同的室外装置的机型信息。在该情况下,也可以对应来自便携电话以外的室外装置的访问。As shown in FIG. 14 , the corresponding model information database 67 includes corresponding model information 601 . In the corresponding model information 601 , the setting screen displays the model information of the mobile phone device 1 that can be generated by the information generation unit 63 . FIG. 14 shows model information 602, model information 603, and the like. Although these model information is described as the model information of the mobile phone, depending on the situation, in addition to the mobile phone, it is also possible to hold a portable information terminal (PDA) or a mobile PC (Personal Computer: personal computer), a game machine with a communication function, Model information of different outdoor devices such as portable communication devices. In this case, it is also possible to cope with accesses from outdoor devices other than mobile phones.

对来自设定在对应机型信息601中的便携电话的访问,画面显示信息生成部63进行画面显示信息的生成,对来自未设定的便携电话装置的访问,便携电话网关装置3的画面显示信息生成部33进行画面显示信息的生成。For an access from a mobile phone set in the corresponding model information 601, the screen display information generating unit 63 generates screen display information, and for an access from a mobile phone device not set, the screen display of the mobile phone gateway device 3 The information generating unit 33 generates screen display information.

室内装置7是具有通过来自家庭网关装置6的指示执行各种服务的功能的信息处理装置。例如,相当于照明、空调机、HDD录像机、Web摄像机等。The indoor device 7 is an information processing device having a function of executing various services by instructions from the home gateway device 6 . For example, it corresponds to lighting, air conditioners, HDD recorders, Web cameras, etc.

如图1所示,室内装置7包括通信控制部71、和控制部72。为了使控制部72经由连接于通信介质8的装置(路由装置5、家庭网关装置6)和路由装置5与连接于通信介质9的装置(便携电话装置1)进行通信,通信控制部71具有按照规定的通信协议对消息进行生成、解释、通信的功能。As shown in FIG. 1 , the indoor unit 7 includes a communication control unit 71 and a control unit 72 . In order for the control unit 72 to communicate with the device (mobile phone device 1) connected to the communication medium 9 via the device (routing device 5, home gateway device 6) connected to the communication medium 8 and the routing device 5, the communication control unit 71 has the following functions: The functions of the specified communication protocol to generate, interpret, and communicate messages.

控制部72具有执行访问家庭网关装置6或者便携电话装置1保持于服务URL 505的连接目的地信息所指示的命令的功能。The control unit 72 has a function of executing an access command indicated by the connection destination information held in the service URL 505 by the home gateway device 6 or the mobile phone device 1 .

这里所说的控制,例如,如果室内装置7是照明,则是该照明的电源接通(ON)、断开(OFF)切换等。如果室内装置7是空调机,则是该空调机的电源接通、断开切换,运行切换、温度设定等。如果室内装置7是HDD录像机,则是节目录像预约指示等。如果室内装置7是Web摄像机,则是Web摄像机图像的取得等。The control referred to here is, for example, if the indoor device 7 is a lighting, it refers to switching the power supply of the lighting on (ON), off (OFF), or the like. If the indoor device 7 is an air conditioner, the power supply of the air conditioner is switched on and off, the operation is switched, the temperature is set, and the like. If the indoor device 7 is an HDD recorder, it is a program recording reservation instruction and the like. If the indoor device 7 is a Web camera, acquisition of a Web camera image and the like are performed.

其中,在图1所示的室内外通信系统中,室内装置7连接于通信介质8,为经由通信介质8与家庭网关装置6进行通信的构成。但是,室内装置7也可以是经由与通信介质8不同的另外的通信介质和家庭网关装置6进行通信的构成。在该情况下,与通信控制部61不同的别的通信控制部设置在家庭网关装置6中,机器管理控制部64经由该别的通信控制部与室内装置7的控制部71进行通信。此时,家庭网关装置6的上述别的通信控制部与室内装置7通信控制部71,按照适于上述别的通信介质的通信协议对消息进行生成、解释、通信。这样,作为上述别的通信介质和上述通信协议,ECHONET(Energy Conservationand Homecare Network:节能家用网)是公知的,在上述情况下也可以运用它。此外,在上述室内装置的例子中,照明、空调机也可以运用。Among them, in the indoor and outdoor communication system shown in FIG. 1 , the indoor device 7 is connected to the communication medium 8 and is configured to communicate with the home gateway device 6 via the communication medium 8 . However, the indoor device 7 may be configured to communicate with the home gateway device 6 via a communication medium different from the communication medium 8 . In this case, another communication control unit different from the communication control unit 61 is provided in the home gateway device 6 , and the appliance management control unit 64 communicates with the control unit 71 of the indoor device 7 via the other communication control unit. At this time, the other communication control unit of the home gateway device 6 and the communication control unit 71 of the indoor unit 7 create, interpret, and communicate messages according to a communication protocol suitable for the other communication medium. In this way, ECHONET (Energy Conservation and Homecare Network: Energy Conservation and Homecare Network) is known as the above-mentioned other communication medium and the above-mentioned communication protocol, and it can also be used in the above-mentioned case. In addition, among the above-mentioned examples of indoor devices, lighting and air conditioners can also be used.

接下来,对在图1所示的室内外通信系统中所执行的、由室外装置(便携电话装置1)对室内装置(室内装置7)的访问、控制处理的细节通过附图进行说明。Next, the details of the access and control process performed by the outdoor device (mobile phone device 1) to the indoor device (indoor device 7) executed in the indoor-outdoor communication system shown in FIG. 1 will be described with reference to the drawings.

在本系统中,为了使访问管理服务器4进行便携电话网关装置3与家庭网关装置6的通信的中介成为可能,在访问管理服务器4上对便携电话网关装置3与家庭网关装置6进行登录处理。此时的处理程序框图示于图7和图8。In this system, the mobile phone gateway device 3 and the home gateway device 6 are registered on the access management server 4 so that the access management server 4 can mediate the communication between the mobile phone gateway device 3 and the home gateway device 6 . The flow chart of the processing at this time is shown in Fig. 7 and Fig. 8 .

如图7所示,家庭网关装置6进行向访问管理服务器4的装置登陆请求(步骤S1001)。此时,家庭网关装置6与上述请求一起,还包括发送装置识别信息、客户证明书、端口编号。如果运用上述SIP,则发送上述装置登陆请求的通信协议相当于REFISTER消息。接收到后,访问管理服务器4对该家庭网关装置6进行机器认证处理(步骤S1002)。此时上述机器认证处理如上所述能够运用PKI的机器认证。也就是说,访问管理服务器装置4预先将CA(Certificate Authority:认证机构)证明书保持在辅助存储部104中,家庭网关装置6预先将上述CA署名的上述客户证明书保持在辅助存储部104中。然后在步骤S1001中,发送上述客户证明书,在步骤S1002中验证上述客户证明书。As shown in FIG. 7, the home gateway device 6 makes a device login request to the access management server 4 (step S1001). At this time, the home gateway device 6 includes the sending device identification information, the client certificate, and the port number together with the above-mentioned request. If the above-mentioned SIP is used, the communication protocol for sending the above-mentioned device registration request corresponds to the REFISTER message. After receiving it, the access management server 4 performs device authentication processing on the home gateway device 6 (step S1002). In this case, the device authentication processing described above can utilize PKI device authentication as described above. That is, the access management server device 4 stores the CA (Certificate Authority) certificate in the auxiliary storage unit 104 in advance, and the home gateway device 6 stores the above-mentioned client certificate signed by the above-mentioned CA in the auxiliary storage unit 104 in advance. . Then in step S1001, the above-mentioned client certificate is sent, and in step S1002, the above-mentioned client certificate is verified.

如果在步骤S1002中判定为上述客户证明书经授权,则访问管理服务器装置4登录上述家庭网关装置6(步骤S1002)。此时,如图5所示,访问管理服务器4将装置信息数据库44保持在辅助存储部104中,追加对判定为经授权的装置的信息。也就是说,在装置信息数据库44的装置识别信息401中设定上述装置识别信息,在IP地址402中设定路由装置5的IP地址(全球地址),在端口编号403中设定包括上述装置登录请求在内的端口编号。其中,路由装置5的IP地址包含在从路由装置5发送到访问管理服务器装置4的IP存储桶首部。例如,在图5中,登录信息404是家庭网关装置6的登录信息。If it is determined in step S1002 that the client certificate is authorized, the access management server device 4 logs in the home gateway device 6 (step S1002). At this time, as shown in FIG. 5 , the access management server 4 holds the device information database 44 in the auxiliary storage unit 104 and adds information on the devices determined to be authorized. That is, the above-mentioned device identification information is set in the device identification information 401 of the device information database 44, the IP address (global address) of the routing device 5 is set in the IP address 402, and the port number 403 includes the above-mentioned devices. Port number including login requests. Wherein, the IP address of the routing device 5 is included in the header of the IP bucket sent from the routing device 5 to the access management server device 4 . For example, in FIG. 5 , the login information 404 is the login information of the home gateway device 6 .

而且,访问管理服务器4返回结果(步骤S1004)。此时,在步骤S1002中机器认证失败时发送该情况,在成功时发送登录结束的情况作为结果。家庭网关装置6接收上述结果,转移到连续等待状态(步骤S1005),结束处理。Also, the access management server 4 returns the result (step S1004). At this time, when the device authentication fails in step S1002, it is sent, and when it succeeds, it is sent as a result that the login is completed. The home gateway device 6 receives the above result, shifts to the continuous waiting state (step S1005), and ends the process.

其中,在图7中,步骤S1001和步骤S1005是家庭网关装置6的访问控制部62执行的处理。此外,步骤1002至步骤1004是访问管理服务器装置4的连接认证部42执行的处理。However, in FIG. 7 , step S1001 and step S1005 are processes executed by the access control unit 62 of the home gateway device 6 . In addition, steps 1002 to 1004 are processes performed by the connection authentication unit 42 of the access management server device 4 .

此外,向便携电话网关装置3的访问管理服务器装置4的登录也是同样的。也就是说,如图8所示,便携电话网关装置3进行向访问管理服务器装置4的装置登录请求(步骤S2001)。此时,便携电话网关装置3在发送上述述时,也包含装置识别信息、客户证明书、端口编号而发送。接收到这些信息的访问管理服务器4对便携电话网关装置3进行机器认证处理(步骤S2002)。此时,上述机器认证处理与步骤1002的处理是同样的。在步骤S2002中如果判定为上述客户证明书是经授权的,则访问管理服务器装置4登录上述便携电话网关装置3(步骤S2002)。此时,如上所述,访问管理服务器4将装置信息数据库44保持在辅助存储部104中,追加对判定为经授权的装置的信息。例如,在图5中,登录信息405是便携电话网关装置3的登录信息。In addition, the same applies to the login to the access management server device 4 of the mobile phone gateway device 3 . That is, as shown in FIG. 8, the mobile phone gateway device 3 makes a device registration request to the access management server device 4 (step S2001). At this time, when the mobile phone gateway device 3 transmits the above, it also transmits the device identification information, the client certificate, and the port number. The access management server 4 having received these information performs device authentication processing on the mobile phone gateway device 3 (step S2002). At this time, the above-mentioned device authentication processing is the same as the processing in step 1002 . If it is determined in step S2002 that the client certificate is authorized, the access management server device 4 logs in the mobile phone gateway device 3 (step S2002). At this time, as described above, the access management server 4 holds the device information database 44 in the auxiliary storage unit 104, and adds information on devices determined to be authorized. For example, in FIG. 5 , the login information 405 is the login information of the mobile phone gateway device 3 .

然后,访问管理服务器4返回结果(步骤S2004)。此时,在步骤S2002中机器认证失败时发送该情况,在成功时将登录结束的情况作为结果发送。便携电话网关装置3接收上述结果,转移到连续等待状态(步骤S2005),结束处理。Then, the access management server 4 returns the result (step S2004). At this time, when the device authentication fails in step S2002, it is sent, and when it succeeds, it is sent as a result that the login is completed. The mobile phone gateway device 3 receives the above result, shifts to the continuous waiting state (step S2005), and ends the process.

其中,在图8中,步骤S2001与步骤S2005是便携电话网关装置3的访问管理部32执行的处理。此外,步骤2002至步骤2004是访问管理服务器装置4的连接认证部42执行的处理。However, in FIG. 8 , step S2001 and step S2005 are processes performed by the access management unit 32 of the mobile phone gateway device 3 . In addition, steps 2002 to 2004 are processes performed by the connection authentication unit 42 of the access management server device 4 .

接下来,对便携电话装置1访问家庭网关装置6的处理的细节进行说明。首先不用关于便携电话的对应机型的信息的第一方法中的处理程序框图示于图9。Next, details of a process in which the mobile phone device 1 accesses the home gateway device 6 will be described. Fig. 9 is a flow chart of the processing in the first method that does not firstly use the information on the corresponding model of the cellular phone.

如图9所示,首先用户操作便携电话装置1,连接便携电话网关装置3(步骤S3001)。也就是说,此时的便携电话装置1的处理成为向家庭网关装置6的连接请求信息的发送。便携电话网关装置3生成用户认证画面数据发送到上述便携电话装置1(步骤S3002)。结果,在上述便携电话装置1的输出部106上显示上述画面,促请来自用户的用户口令输入。接着,送出用户使用便携电话装置1的输入部105输入的用户口令,与作为认证信息的上述便携电话装置1固有的便携电话信息(步骤S3003),上述便携电话网关装置3使用上述用户口令与上述便携电话信息认证便携电话装置1(步骤S3004)。此时,上述认证处理使用图4所示的、便携电话网关装置3预先保持在辅助存储部104中的认证信息数据库35来进行。也就是说,分别比较用户口令301的内容与上述用户口令、便携电话信息302的内容与上述便携电话信息,在全都一致的情况下认证成功。例如,在图4中,如果登录信息304是上述用户的信息,则在上述用户口令为“1234”,上述便携电话信息为“tnk16198”时认证成功。As shown in FIG. 9, first, the user operates the mobile phone device 1 to connect to the mobile phone gateway device 3 (step S3001). That is, the processing of the mobile phone device 1 at this time is transmission of connection request information to the home gateway device 6 . The mobile phone gateway device 3 generates user authentication screen data and sends it to the mobile phone device 1 (step S3002). As a result, the above-mentioned screen is displayed on the output unit 106 of the above-mentioned mobile phone device 1, and the input of the user password from the user is urged. Next, send the user password input by the user using the input unit 105 of the mobile phone device 1, and the mobile phone information unique to the mobile phone device 1 as authentication information (step S3003), and the mobile phone gateway device 3 uses the user password and the above-mentioned The mobile phone information authenticates the mobile phone device 1 (step S3004). At this time, the authentication process described above is performed using the authentication information database 35 shown in FIG. 4 that the mobile phone gateway device 3 holds in advance in the auxiliary storage unit 104 . That is, the contents of the user password 301 and the above-mentioned user password, and the contents of the mobile phone information 302 and the above-mentioned mobile phone information are respectively compared, and the authentication succeeds when all match. For example, in FIG. 4, if the login information 304 is the information of the user, the authentication is successful when the user password is "1234" and the mobile phone information is "tnk16198".

在步骤S3004中,在认证失败时(至少一方不一致时)向便携电话装置1发送该情况。然后上述便携电话装置1在输出装置105上显示该情况(认证失败)(步骤S3005),结束处理。In step S3004, when the authentication fails (when at least one of them does not match), the fact is transmitted to the mobile phone device 1 . Then, the mobile phone device 1 displays the fact (authentication failed) on the output device 105 (step S3005), and ends the process.

在步骤S3004中,在认证成功时,便携电话网关装置3对访问管理服务器装置4发送向家庭网关装置6的连接指示信息。在上述连接指示信息中包含应该连接的家庭网关装置6的装置识别信息,和在步骤3004中取得的上述便携电话信息。例如在上述例子中,在图4中,作为登录信息304的连接目的地信息303的内容的“user01@hogehoge.jp”相当于上述装置识别信息,作为便携电话信息302的内容的“tnk16198”相当于上述便携电话信息。此外,如果运用上述SIP,则发送上述连接指示信息的通信协议相当于INVITE消息。In step S3004 , when the authentication is successful, the mobile phone gateway device 3 transmits connection instruction information to the home gateway device 6 to the access management server device 4 . The device identification information of the home gateway device 6 to be connected and the mobile phone information acquired in step 3004 are included in the connection instruction information. For example, in the above example, in FIG. 4 , "user01@hogehoge.jp" as the content of the connection destination information 303 of the login information 304 corresponds to the above-mentioned device identification information, and "tnk16198" as the content of the mobile phone information 302 corresponds to In the mobile phone information above. In addition, if the above-mentioned SIP is used, the communication protocol for transmitting the above-mentioned connection instruction information corresponds to the INVITE message.

接着,访问管理服务器装置4检索上述连接指示信息中所含有的上述连接目的地信息是否登录在装置信息数据库44中(步骤S3006)。在本例中,由于登录信息404在图7中相当于登录的家庭网关装置6的信息,所以在此情况下,再次构成包括上述便携电话网关装置3的装置识别信息(图5的装置识别信息401的内容,在本例中,登录信息405的装置识别信息401的内容)与上述便携电话信息在内的连接指示信息,将上述连接指示信息发送到上述家庭网关装置6(步骤S3007)。实际上,上述家庭网关装置6对所连接的路由装置5的IP地址(图5的IP地址402的内容)所确定的端口编号(图5的端口编号403的内容)发送上述连接指示信息,上述路由装置5(使用上述端口变换控制部)将上述连接指示信息传送到上述家庭网关装置6。此外,在步骤S3006中,上述连接目的地信息如果不登录在上述装置信息数据库44中,则将连接失败的情况返回到上述便携电话网关装置3。Next, the access management server device 4 searches whether or not the connection destination information included in the connection instruction information is registered in the device information database 44 (step S3006). In this example, since the login information 404 corresponds to the information of the registered home gateway device 6 in FIG. 7 , in this case, the device identification information (the device identification information in FIG. The content of 401, in this example, the content of the device identification information 401 of the registration information 405) and the connection instruction information including the mobile phone information, and the connection instruction information is sent to the home gateway device 6 (step S3007). In fact, the above-mentioned home gateway device 6 sends the above-mentioned connection instruction information to the port number (the content of the port number 403 in FIG. 5 ) determined by the IP address of the connected routing device 5 (the content of the IP address 402 in FIG. The routing device 5 (using the port conversion control unit) transmits the connection instruction information to the home gateway device 6 . In addition, in step S3006, if the connection destination information is not registered in the device information database 44, a connection failure is returned to the mobile phone gateway device 3.

接着,家庭网关装置6将路由器外部端口开放请求发送到上述路由装置5(步骤S3008)。上述路由装置5进行上述端口变换部中的外部端口开放设定(步骤S3009)。由此,对来自室外装置(便携电话装置1)的访问,上述路由装置5可将该访问中继到上述家庭网关装置6。其中,在这里使用的路由器外部端口开放请求中,包含路由装置5的外部端口编号、关联于该外部端口的内部端口编号、以及家庭网关装置6的IP地址。此外,外部端口编号与内部端口编号有必要使用与已经设定的端口编号不重复的端口编号。作为确定端口编号的方法,例如,可以举出从有效范围的小的编号中选择不重复的编号的方法,或选择有效范围内的随机的编号的方法。此外,如果路由装置5和家庭网关装置6的制约不存在,则优选外部端口编号与内部端口编号是同一编号。Next, the home gateway device 6 sends a router external port opening request to the above-mentioned routing device 5 (step S3008). The routing device 5 performs external port opening setting in the port conversion unit (step S3009). Thus, the router device 5 can relay the access from the outdoor device (mobile phone device 1 ) to the home gateway device 6 . Wherein, the router external port opening request used here includes the external port number of the routing device 5 , the internal port number associated with the external port, and the IP address of the home gateway device 6 . In addition, it is necessary to use a port number that does not overlap with an already set port number for the external port number and the internal port number. As a method of specifying the port number, for example, a method of selecting a non-overlapping number from small numbers in the valid range, or a method of selecting a random number within the valid range can be mentioned. In addition, if there is no constraint of the routing device 5 and the home gateway device 6, it is preferable that the external port number and the internal port number be the same number.

接着,在家庭网关装置6中,为了上述便携电话1直接访问上述家庭网关装置6,访问控制部62生成例如权标信息等认证信息,生成包括上述权标信息的访问URL(连接信息)(步骤S3010)。上述访问URL,成为例如,https://11.22.33.44:10000/index.cgi?token=kz7t5ob8dtghh,这样的文本数据。在该情况下,“11.22.33.44”是上述路由装置5的IP地址,“10000”是端口编号,“index.cgi”是上述家庭网关装置6的访问页,“kz7t5ob8dtghh”是权标信息。上述权标信息例如在连接指示信息的接收时随机生成。Next, in the home gateway device 6, in order for the above-mentioned mobile phone 1 to directly access the above-mentioned home gateway device 6, the access control unit 62 generates authentication information such as token information, and generates an access URL (connection information) including the token information (step S3010). The above access URL becomes, for example, https://11.22.33.44:10000/index.cgi? token=kz7t5ob8dtghh, such text data. In this case, "11.22.33.44" is the IP address of the routing device 5, "10000" is the port number, "index.cgi" is the access page of the home gateway device 6, and "kz7t5ob8dtghh" is token information. The above-mentioned token information is randomly generated, for example, when the connection instruction information is received.

进而,在家庭网关装置6中,访问控制部62将来自上述便携电话网关装置3的包括连接指示信息的上述便携电话信息、上述权标信息、上述路由装置5中设定的上述外部端口编号、上述建立关联的内部端口编号、以及上述权标的有效期间登录在图3所示的认证信息数据库65中(步骤S3011)。在本例中,登录信息207是在步骤S3011中登录的信息。上述权标的有效期间是在上述权标所生成的日期时间之上加上例如预先确定的5分钟的日期时间。虽然通过缩短所加的时间(在本例中5分钟)安全性强度增加,但是最好考虑到通信介质8、通信介质9、通信介质10的迟延时间来确定。Furthermore, in the home gateway device 6, the access control unit 62 sends the mobile phone information including the connection instruction information from the mobile phone gateway device 3, the token information, the external port number set in the routing device 5, The above-mentioned associated internal port number and the validity period of the above-mentioned token are registered in the authentication information database 65 shown in FIG. 3 (step S3011). In this example, the login information 207 is the information registered in step S3011. The validity period of the token is a date and time of, for example, a predetermined 5 minutes added to the date and time when the token was generated. Although the security strength is increased by shortening the added time (5 minutes in this example), it is best determined taking into account the delay times of the communication medium 8, the communication medium 9, the communication medium 10.

然后,生成包括含有上述权标的访问URL在内的返回信息并发送到上述访问管理服务器装置4(步骤S3012)。上述访问管理服务器装置4再次构成上述返回信息并发送到上述便携电话网关装置3(步骤S3013)。Then, return information including the access URL including the token is generated and sent to the access management server device 4 (step S3012). The access management server device 4 reconstructs the return information and sends it to the mobile phone gateway device 3 (step S3013).

接着,便携电话网关装置3从上述返回信息中取得上述连接信息(访问URL),生成使对上述访问URL的连接成为可能的画面显示数据并发送到上述便携电话装置1(步骤S3014)。结果,在上述便携电话装置1的输出部106上显示基于上述画面显示数据的画面(步骤S3015),对用户促请向上述访问URL的连接信息的选择。如果用户选择上述连接信息,则便携电话装置1将连接请求信息发送到上述家庭网关装置6。此时,便携电话装置1将便携电话信息包含在该连接请求信息中而发送。此外,该连接请求信息对上述访问URL进行。上述访问URL中所含有的IP地址是上述路由装置5的IP地址(在本例中,11.22.33.44),上述IP地址中所含有的端口编号是在步骤3009中设定在上述路由装置5中的上述外部端口编号(在本例中,10000)。因而,上述连接请求信息到达上述家庭网关装置6。此外,在步骤S3015中,也可以是用户不进行上述连接信息选择而自动地将连接请求信息发送到上述家庭网关装置6(URL转移:redirection)。无论如何,便携电话装置1一对上述访问URL响应就发送连接请求信息。Next, the mobile phone gateway device 3 acquires the connection information (access URL) from the return information, generates screen display data enabling connection to the access URL, and sends it to the mobile phone device 1 (step S3014). As a result, a screen based on the screen display data is displayed on the output unit 106 of the mobile phone device 1 (step S3015), and selection of connection information to the access URL is prompted to the user. When the user selects the connection information, the mobile phone device 1 transmits connection request information to the home gateway device 6 . At this time, the mobile phone device 1 includes the mobile phone information in the connection request information and transmits it. In addition, this connection request information is carried out to the above-mentioned access URL. The IP address contained in the above-mentioned access URL is the IP address (in this example, 11.22.33.44) of the above-mentioned routing device 5, and the port number contained in the above-mentioned IP address is set in the above-mentioned routing device 5 in step 3009. The above external port number (in this example, 10000). Accordingly, the above-mentioned connection request information reaches the above-mentioned home gateway device 6 . Furthermore, in step S3015, the user may automatically transmit connection request information to the home gateway device 6 without selecting the connection information (URL redirection: redirection). In any case, the mobile phone device 1 transmits connection request information in response to the above-mentioned access URL.

接着,家庭网关装置6根据上述连接请求信息中所含有的信息进行便携电话装置1的认证(步骤S3016)。在上述连接请求信息中,含有便携电话装置1的便携电话信息,和(上述访问URL中所含有的)权标信息,分别比较这些信息与在步骤S3011中保持的登录信息,在全都一致的情况下认证成功。例如,上述连接请求信息中所含有的便携电话信息为“tnk16198”,而且权标信息为“kz7t5ob8dtghh”,而且如果是上述权标信息的有限期限内,则认证成功。Next, the home gateway device 6 authenticates the mobile phone device 1 based on the information included in the connection request information (step S3016). The above-mentioned connection request information includes the mobile phone information of the mobile phone device 1 and token information (included in the above-mentioned access URL), and these information are compared with the login information held in step S3011, and if they all match The next authentication is successful. For example, if the mobile phone information contained in the connection request information is "tnk16198" and the token information is "kz7t5ob8dtghh", and if it is within the time limit of the token information, the authentication is successful.

在步骤S3016中,在认证失败时(至少一方不一致时),将该情况发送到便携电话装置1,上述便携电话装置1在输出装置105上显示该情况(认证失败)(步骤S3017),结束处理。In step S3016, when authentication fails (when at least one of them does not match), the fact is sent to the mobile phone device 1, and the above-mentioned mobile phone device 1 displays the fact (authentication failed) on the output device 105 (step S3017), and the process ends .

另一方面,在步骤S3016中,在认证成功时,家庭网关装置6生成画面显示(Top画面)以便能够进行室内装置7的远程操作或控制,发送到上述便携电话装置1(步骤S3018)。结果,在上述便携电话装置1的输出部106上,例如,显示图11所示的画面700(步骤S3019),结束处理。此外,在步骤S3018中,生成图6所示的装置信息数据库66的内容和画面显示数据。在本例中,作为室内装置7,例如照明(登录信息506)、网络(Web)摄像机(登录信息507)、HDD录像机(登录信息508)连接于通信介质8。因而,在便携电话装置1输出装置105上,作为控制机器一览,显示能够选择照明、网络摄像机、HDD录像机的画面。On the other hand, in step S3016, when the authentication is successful, the home gateway device 6 generates a screen display (Top screen) to enable remote operation or control of the indoor device 7, and sends it to the mobile phone device 1 (step S3018). As a result, for example, a screen 700 shown in FIG. 11 is displayed on the output unit 106 of the mobile phone device 1 (step S3019), and the process ends. In addition, in step S3018, the contents and screen display data of the device information database 66 shown in FIG. 6 are generated. In this example, indoor devices 7 such as lighting (registration information 506 ), network (Web) cameras (registration information 507 ), and HDD recorders (registration information 508 ) are connected to the communication medium 8 . Therefore, on the output device 105 of the mobile phone device 1, a screen from which lighting, a network camera, and an HDD recorder can be selected is displayed as a list of control devices.

此外,在图9中,步骤S3001、步骤S3003、步骤S3005、步骤S3015、步骤3017和步骤S3019是便携电话装置1的浏览器部12执行的处理。步骤S3002、步骤S3014是便携电话网关装置3的画面显示信息生成部33执行的处理。步骤S3004是便携电话网关装置3的用户认证部34执行的处理。步骤S3006、步骤S3007、步骤S3013是访问管理服务器4的连接管理部43执行的处理。步骤S3008、步骤S3010至步骤S3012、步骤S3016是家庭网关装置6的访问控制部62执行的处理。步骤S3018是家庭网关装置6的画面显示信息生成部63执行的处理。而且步骤S3009是路由装置5的端口变换部执行的处理。In addition, in FIG. 9 , step S3001 , step S3003 , step S3005 , step S3015 , step 3017 , and step S3019 are processes executed by the browser unit 12 of the mobile phone device 1 . Step S3002 and step S3014 are processes performed by the screen display information generation unit 33 of the mobile phone gateway device 3 . Step S3004 is a process executed by the user authentication unit 34 of the mobile phone gateway device 3 . Step S3006 , step S3007 , and step S3013 are processes performed by the connection management unit 43 of the access management server 4 . Step S3008 , step S3010 to step S3012 , and step S3016 are processes executed by the access control unit 62 of the home gateway device 6 . Step S3018 is a process executed by the screen display information generator 63 of the home gateway device 6 . Furthermore, step S3009 is a process executed by the port conversion unit of the routing device 5 .

接下来,对便携电话装置1使用上述连接信息访问家庭网关装置6,控制室内装置7的处理的细节进行说明。此时的处理程序框图示于图10。Next, details of a process in which the mobile phone device 1 accesses the home gateway device 6 and controls the indoor device 7 using the above-mentioned connection information will be described. The flow chart of the processing at this time is shown in FIG. 10 .

如图10所示,首先用户操作便携电话装置1选择打算远程控制的机器,将该选择信息发送到家庭网关装置6(步骤S4001)。此时,在便携电话装置1的输出部106上,显示图11所示的画面700(控制机器一览),用户从其中选择打算远程控制的机器而选择执行按钮701(在图11所示的画面700中若选择执行按钮701,则照明被选择)。As shown in FIG. 10, first, the user operates the mobile phone device 1 to select a device to be remotely controlled, and transmits the selection information to the home gateway device 6 (step S4001). At this time, on the output unit 106 of the mobile phone device 1, a screen 700 (a list of control devices) shown in FIG. In 700, if the execution button 701 is selected, lighting is selected).

接着,家庭网关装置6生成用于控制上述所选择的机器的画面显示数据,发送到上述便携电话装置1(步骤S4002)。结果,在上述便携电话装置1的输出部106上,例如显示图12所示的画面702。图12表示上述照明的状态,在本例中,是上述照明接通(进行照明)的状态。在上述画面702中,如果选择返回按钮704,则上述画面700在上述便携电话装置1的输出部106上显示。Next, the home gateway device 6 generates screen display data for controlling the selected device, and transmits it to the mobile phone device 1 (step S4002). As a result, for example, a screen 702 shown in FIG. 12 is displayed on the output unit 106 of the mobile phone device 1 . FIG. 12 shows the state of the above-mentioned lighting, and in this example, it is a state in which the above-mentioned lighting is turned on (illumination is performed). When the return button 704 is selected on the screen 702 , the screen 700 is displayed on the output unit 106 of the mobile phone device 1 .

例如,在上述画面702中,如果用户选择切断而选择执行按钮703,则将该选择信息发送到上述家庭网关装置6(步骤S4003)。然后,上述家庭网关装置6根据上述选择信息生成所选择的机器的控制用通信数据发送到上述所选择的机器(室内装置7)(步骤S4004)。此时,上述所选择的机器是照明,该照明如上所述,如果是对应于ECHONET的机器,则上述控制用通信数据按照根据ECHONET标准的电文格式生成,使用同样根据ECHONET标准的通信协议发送到上述室内装置7。For example, if the user selects disconnection on the above-mentioned screen 702 and selects the execution button 703, the selection information is sent to the above-mentioned home gateway device 6 (step S4003). Then, the home gateway device 6 generates control communication data for the selected appliance based on the selection information and sends it to the selected appliance (indoor device 7) (step S4004). At this time, the above-mentioned selected device is a lighting. As mentioned above, if the lighting is a device corresponding to ECHONET, the above-mentioned control communication data is generated according to the telegram format according to the ECHONET standard, and is sent to The indoor unit 7 mentioned above.

接着,室内装置7按照接收的上述控制用通信数据控制本机器(在本例中,照明的切断)(步骤S4005),将该控制结果发送到上述家庭网关装置6(步骤S4006)。然后,家庭网关装置6生成表示该控制结果的画面显示数据,发送到上述便携电话装置1(步骤S4007)。结果,在上述便携电话装置1的输出部106上显示表示该控制结果的画面(步骤S4008),结束处理。Next, the indoor device 7 controls itself (in this example, lighting off) according to the received control communication data (step S4005), and transmits the control result to the home gateway device 6 (step S4006). Then, the home gateway device 6 generates screen display data showing the control result, and transmits it to the mobile phone device 1 (step S4007). As a result, a screen showing the result of the control is displayed on the output unit 106 of the mobile phone device 1 (step S4008), and the process ends.

此外,在图10中,步骤S4001、步骤S4003、步骤S4008是便携电话装置1浏览器部12执行的处理。步骤S4002、步骤S4007是家庭网关装置6的画面显示信息生成部63执行的处理。步骤S4004是家庭网关装置6的机器管理控制部64执行的处理。而且步骤S4005至步骤S4006是室内装置7的控制部72执行的处理。In addition, in FIG. 10 , step S4001 , step S4003 , and step S4008 are processes executed by the browser unit 12 of the mobile phone device 1 . Step S4002 and step S4007 are processes performed by the screen display information generation unit 63 of the home gateway device 6 . Step S4004 is a process executed by the device management control unit 64 of the home gateway device 6 . Furthermore, steps S4005 to S4006 are processes executed by the control unit 72 of the indoor unit 7 .

接着在步骤S4001中,对在用户作为控制对象机器选择网络摄像机(在画面700中,选择网络摄像机而选择执行按钮701)的情况进行说明。通常,由于网络摄像机具备网络服务器功能,所以在步骤S4004中,家庭网关装置6对上述网络摄像机(室内装置7)进行网络访问。在步骤S4005中,上述网络摄像机作为静止图像数据生成该时刻的摄像机图像,在步骤S4006中,上述网络摄像机将该静止图像数据发送到上述家庭网关装置6。在步骤S4007中,上述家庭网关装置6生成包括该静止图像数据在内的画面显示数据发送到上述便携电话装置1。结果,该静止图像数据在上述便携电话装置1的输出装置106上被显示(步骤S4008)。Next, in step S4001 , a case where the user selects a network camera as a device to be controlled (on the screen 700 , selects the network camera and selects the execution button 701 ) will be described. Usually, since the network camera has a network server function, in step S4004, the home gateway device 6 performs network access to the network camera (indoor device 7). In step S4005, the network camera generates a camera image at that time as still image data, and in step S4006, the network camera transmits the still image data to the home gateway device 6 . In step S4007, the home gateway device 6 generates screen display data including the still image data and sends it to the mobile phone device 1 . As a result, the still image data is displayed on the output device 106 of the mobile phone device 1 (step S4008).

接着在步骤4001中,对在用户作为控制对象机器选择HDD录像机(在画面700中,选择HDD录像机而选择执行按钮701)的情况进行说明。在步骤S4004中,家庭网关装置6将图像取得请求发送到上述HDD录像机(室内装置7)。在步骤S4005中,对上述累积图像施行适当图像压缩格式变换等以便可以在上述便携电话装置1上再现、阅览上述HDD录像机所请求的累积图像。在步骤S4006中,上述HDD录像机将上述变换后的图像数据发送到上述家庭网关装置6。在步骤S4007中,上述家庭网关装置6将该图像数据发送到上述便携电话装置1,保持在上述便携电话装置1的辅助存储部104中。便携电话装置1在输出装置106上显示累积图像的选择画面,如果用户选择上述图像数据,则上述图像数据被再现。然后所再现的图像在上述便携电话装置1的输出装置106上被显示(步骤S4008)。Next, in step 4001, a case where the user selects an HDD recorder as a device to be controlled (on the screen 700, selects the HDD recorder and selects the execution button 701) will be described. In step S4004, the home gateway device 6 transmits an image acquisition request to the HDD recorder (indoor device 7). In step S4005, appropriate image compression format conversion etc. are performed on the accumulated image so that the accumulated image requested by the HDD video recorder can be reproduced and viewed on the mobile phone device 1 . In step S4006, the HDD recorder sends the converted image data to the home gateway device 6 . In step S4007, the home gateway device 6 transmits the image data to the mobile phone device 1 and stores it in the auxiliary storage unit 104 of the mobile phone device 1 . The mobile phone device 1 displays a selection screen of accumulated images on the output device 106, and when the user selects the image data, the image data is reproduced. The reproduced image is then displayed on the output device 106 of the mobile phone device 1 (step S4008).

接下来,对结束从便携电话装置1向家庭网关装置6的访问的处理的细节进行说明。此时的处理程序框图示于图13。Next, details of the process of terminating access from the mobile phone device 1 to the home gateway device 6 will be described. The flow chart of processing at this time is shown in FIG. 13 .

如图13所示,首先用户操作便携电话装置1,将注销信息发送到家庭网关装置6(步骤S5001)。此时,在便携电话装置1的输出部106上,显示图11所示的画面700(控制机器一览),用户从其中选择注销而选择执行按钮701。As shown in FIG. 13, first, the user operates the mobile phone device 1 to transmit logout information to the home gateway device 6 (step S5001). At this time, on the output unit 106 of the mobile phone device 1, a screen 700 (list of control devices) shown in FIG.

接着,家庭网关装置6将用于结束与便携电话网关装置3的连接的连接结束请求发送到访问管理服务器装置4(步骤S5002)。在上述连接结束请求中,含有上述便携电话网关装置3的装置识别信息。然后,访问管理服务器装置4根据上述装置识别信息检索装置信息数据库44(步骤S5003),如果可以找到上述装置识别信息的登录信息,则将上述连接结束请求发送到上述装置识别信息表示的便携电话网关装置3(步骤S5004)。此时,访问管理服务器装置4再次构成上述连接结束请求以便含有家庭网关装置6的装置识别信息,将上述连接结束请求发送到上述便携电话网关装置3。Next, the home gateway device 6 transmits a connection termination request for terminating the connection with the mobile phone gateway device 3 to the access management server device 4 (step S5002). The device identification information of the mobile phone gateway device 3 is included in the connection end request. Then, the access management server device 4 searches the device information database 44 based on the device identification information (step S5003), and if the registration information of the device identification information can be found, the connection termination request is sent to the mobile phone gateway indicated by the device identification information. Device 3 (step S5004). At this time, the access management server device 4 reconfigures the connection termination request so as to include the device identification information of the home gateway device 6 and transmits the connection termination request to the mobile phone gateway device 3 .

接着,收到上述连接结束请求的便携电话网关装置3进行与上述家庭网关装置6的连接结束处理(保持的信息的删除)(步骤S5005)。然后,生成含有针对是否正常地完成结束处理的结果的返回信息,将该返回信息发送到上述访问管理服务器装置4中(步骤S5006)。在该返回信息中含有上述家庭网关装置6的装置识别信息。然后,访问管理服务器装置4将该返回信息发送到该返回信息中所含有的装置识别信息表示的家庭网关装置6(步骤S5007)。Next, the mobile phone gateway device 3 having received the connection termination request performs a connection termination process (deletion of held information) with the home gateway device 6 (step S5005). Then, return information including the result of whether the end process is completed normally is generated, and the return information is sent to the above-mentioned access management server device 4 (step S5006). The device identification information of the above-mentioned home gateway device 6 is included in the returned information. Then, the access management server device 4 transmits the return information to the home gateway device 6 indicated by the device identification information contained in the return information (step S5007).

接着,家庭网关装置6检索数据传送用端口编号(步骤S5008),对路由装置5,送出路由器外部端口闭锁请求(步骤S5009)。此时,数据传送用端口编号的检索,对图3所示的认证信息数据库65来进行。也就是说,是在图9说明的本连接开始处理中,检索路由装置5中设定的开放外部端口编号,在本例的情况下,成为取得登录信息207的外部端口编号203的内容。然后,就将对上述外部端口编号的路由器外部端口闭锁请求发送到上述路由装置5。然后,路由装置5进行外部端口闭锁设定(步骤S5010)。由此,在路由装置5中,可以阻断来自室外装置的未授权的访问。Next, the home gateway device 6 searches for the port number for data transmission (step S5008), and sends a router external port blocking request to the router device 5 (step S5009). At this time, the search for the port number for data transfer is performed on the authentication information database 65 shown in FIG. 3 . That is, in the present connection start process described in FIG. 9 , the open external port number set in the routing device 5 is searched, and in this example, the external port number 203 of the login information 207 is acquired. Then, the router external port blocking request for the above-mentioned external port number is sent to the above-mentioned routing device 5 . Then, the routing device 5 performs external port blocking setting (step S5010). Thus, in the routing device 5, unauthorized access from the outdoor device can be blocked.

接着,家庭网关装置6进行与上述便携电话网关装置3的连接结束处理(步骤S5011)。具体地说,从图3所示的认证信息数据库65删除符合的登录信息。在本例中,由于登录信息207符合,所以删除登录信息207。然后,家庭网关装置6生成表示连接结束的画面显示数据,发送到上述便携电话装置1(步骤S5012)。结果,在上述便携电话装置1的输出部106上显示表示连接结束的画面(步骤S5013),结束处理。Next, the home gateway device 6 performs connection termination processing with the mobile phone gateway device 3 (step S5011). Specifically, the corresponding login information is deleted from the authentication information database 65 shown in FIG. 3 . In this example, since the login information 207 matches, the login information 207 is deleted. Then, the home gateway device 6 generates screen display data indicating the completion of the connection, and transmits it to the mobile phone device 1 (step S5012). As a result, a screen indicating that the connection has been completed is displayed on the output unit 106 of the mobile phone device 1 (step S5013), and the process ends.

其中,在图13中,步骤S5001、步骤S5013是便携电话装置1的浏览器部12执行的处理。步骤S5002、步骤S5008至步骤S5009、步骤S5011是家庭网关装置6的访问控制部62执行的处理。步骤S5012是家庭网关装置6的画面显示信息生成部63执行的处理,步骤S5003至步骤S5004、步骤S5007是访问管理服务器装置4的连接管理部43执行的处理。步骤S5005至步骤S5006是便携电话网关装置3的访问管理部32执行的处理。而且步骤S5010是路由装置5的端口变换部执行的处理。However, in FIG. 13 , step S5001 and step S5013 are processes executed by the browser unit 12 of the mobile phone device 1 . Step S5002 , step S5008 to step S5009 , and step S5011 are processes executed by the access control unit 62 of the home gateway device 6 . Step S5012 is a process executed by the screen display information generation unit 63 of the home gateway device 6 , and steps S5003 to S5004 and step S5007 are processes performed by the connection management unit 43 of the access management server device 4 . Steps S5005 to S5006 are processes executed by the access management unit 32 of the mobile phone gateway device 3 . Furthermore, step S5010 is a process executed by the port conversion unit of the routing device 5 .

如果使用上述第一方法,则在便携电话装置1与家庭网关装置6的通信中,可降低便携电话网关装置3和访问管理服务器4的负载。Using the first method described above reduces the load on the mobile phone gateway device 3 and the access management server 4 in communication between the mobile phone device 1 and the home gateway device 6 .

接下来,在以下说明在便携电话装置1的浏览器部12上所显示的基于画面显示信息的画面与用户的便携电话装置1的机型的可显示的分辨率和功能对应而显示地改良的第二方法。Next, a description will be given below of how the screen displayed on the browser unit 12 of the mobile phone device 1 based on the screen display information is improved in accordance with the displayable resolution and functions of the model of the mobile phone device 1 of the user. Second method.

一般来说便携电话装置1的浏览器部12在一个画面上能够显示的分辨率和功能因便携电话装置1的机型而不同。因此,家庭网关装置6的画面显示信息生成部63不得不对应具有访问家庭网关装置6的可能性的便携电话的所有机型。在第一方法中,在便携电话装置1的浏览器部12上所显示的画面显示信息,家庭网关装置的画面显示信息生成部63必定生成。但是,一般来说,因为成本方面等制约,搭载在家庭网关装置6上的辅助存储部104的容量是有限的,无法确保可以进行对应于所有的便携电话的机型的画面显示信息生成的程度的容量。因此,在家庭网关装置6中,难以生成分别对应于所有的便携电话的机型的画面显示信息。此外,在第一方法中,在搭载在家庭网关装置6上的辅助存储部104中便携电话的新机型登场的情况下,也产生无法生成对应于新机型的画面显示信息这样的课题。In general, the resolution and functions that can be displayed on one screen by the browser unit 12 of the mobile phone device 1 differ depending on the model of the mobile phone device 1 . Therefore, the screen display information generator 63 of the home gateway device 6 has to support all models of mobile phones that may access the home gateway device 6 . In the first method, the screen display information generation part 63 of the home gateway device always generates the screen display information displayed on the browser part 12 of the mobile phone device 1 . However, generally speaking, due to constraints such as cost, the capacity of the auxiliary storage unit 104 mounted on the home gateway device 6 is limited, and it cannot be ensured that the generation of screen display information corresponding to all mobile phone models can be performed. capacity. Therefore, in the home gateway device 6, it is difficult to generate screen display information corresponding to all mobile phone models. Also, in the first method, when a new model of the mobile phone comes out in the auxiliary storage unit 104 mounted on the home gateway device 6, there is a problem that screen display information corresponding to the new model cannot be generated.

以下,参照附图对用于解决上述课题的第二方法的详细的室外装置(便携电话装置1)进行的室内装置(室内装置7)的访问、控制处理的细节进行说明。Hereinafter, the details of the access and control processing of the indoor device (indoor device 7 ) by the outdoor device (mobile phone device 1 ) for the second method for solving the above-mentioned problems will be described with reference to the drawings.

为了解决上述课题,首先,将在第一方法中图9所示的处理程序框图变更成图15所示的处理程序框图即可。In order to solve the above-mentioned problems, first, in the first method, the processing flowchart shown in FIG. 9 may be changed to the processing flowchart shown in FIG. 15 .

此外,虽然图15在图15a和图15b两个附图上分别描述了处理程序框图,但是这两个程序框图由附图中所描述的(A)标示表示连接起来。由此在以下的说明中,将这两个程序框图作为一个程序框图来处理,仅表达为图15。In addition, although FIG. 15 depicts the process block diagrams on the two drawings of FIG. 15a and FIG. 15b respectively, these two flow diagrams are connected by the symbol (A) described in the drawings. Therefore, in the following description, these two program block diagrams are treated as one program block diagram, which is only expressed as FIG. 15 .

在图15中,对在第二方法中便携电话装置1访问家庭网关装置6的处理的细节进行说明。此外,在说明时,也使用第一方法的说明中使用的示意图,补充说明第二方法中不同之处。In FIG. 15 , the details of the process in which the mobile phone device 1 accesses the home gateway device 6 in the second method will be described. In addition, in the description, the schematic diagram used in the description of the first method is also used to supplement the description of the differences in the second method.

如图15所示,首先用户操作便携电话装置1,连接于便携电话网关装置3(步骤S6001)。也就是说,此时的便携电话装置1的处理成为向家庭网关装置6的连接请求信息的发送。便携电话网关装置3生成用户认证画面数据并发送到上述便携电话装置1(步骤S6002)。结果,在上述便携电话装置1的输出部106上显示上述画面,促请来自用户的用户口令输入。接着,发送用户使用便携电话装置1的输入部105输入的用户口令,和作为认证信息的上述便携电话装置1固有的便携电话信息(含有机型信息)(步骤S6003),上述便携电话网关装置3使用上述用户口令与上述便携电话信息认证便携电话装置1(步骤S6004)。此时,上述认证处理由图4所示的、便携电话网关装置3预先保持在辅助存储部104中的认证信息数据库35进行。也就是说,分别比较用户口令301的内容与上述用户口令,便携电话信息302的内容与上述便携电话信息,在全都一致时为认证成功。例如,在图4中,如果登录信息305是上述用户的信息,则在上述用户口令为“4567”,上述便携电话信息为“hmn61618aa公司制bb机型”时认证成功。As shown in FIG. 15, first, the user operates the mobile phone device 1 to connect to the mobile phone gateway device 3 (step S6001). That is, the processing of the mobile phone device 1 at this time is transmission of connection request information to the home gateway device 6 . The mobile phone gateway device 3 generates user authentication screen data and sends it to the mobile phone device 1 (step S6002). As a result, the above-mentioned screen is displayed on the output unit 106 of the above-mentioned mobile phone device 1, and the input of the user password from the user is urged. Next, the user password input by the user using the input unit 105 of the mobile phone device 1, and the mobile phone information (including model information) specific to the mobile phone device 1 as authentication information are sent (step S6003), and the mobile phone gateway device 3 The mobile phone device 1 is authenticated using the user password and the mobile phone information (step S6004). At this time, the authentication process described above is performed by the authentication information database 35 previously held by the mobile phone gateway device 3 in the auxiliary storage unit 104 shown in FIG. 4 . That is, the contents of the user password 301 and the above-mentioned user password are compared, and the contents of the mobile phone information 302 and the above-mentioned mobile phone information are compared, and when all match, the authentication is successful. For example, in FIG. 4, if the login information 305 is the user's information, the authentication is successful when the user's password is "4567" and the mobile phone information is "bb model made by hmn61618aa company".

在步骤S6004中,在认证失败时(至少一方不一致时),将该情况发送到便携电话装置1。然后上述便携电话装置1在输出装置105上显示该情况(认证失败)(步骤S6005),结束处理。In step S6004, when the authentication fails (when at least one of them does not match), the fact is sent to the mobile phone device 1 . Then, the above-mentioned mobile phone device 1 displays the fact (authentication failed) on the output device 105 (step S6005), and ends the process.

在步骤S6004中,在认证成功时,便携电话网关装置3对访问管理服务器装置4发送向家庭网关装置6的连接指示信息。在上述连接指示信息中,含有将要连接的家庭网关装置6的装置识别信息,和在步骤S6004中取得的上述便携电话信息。例如在上述例中,在图4中,作为登录信息305的连接目的地信息303的内容“user02@hogehoge.jp”相当于上述装置识别信息,作为便携电话信息302的内容的“hmn61618aa公司制bb机型”相当于上述便携电话信息。In step S6004, when the authentication is successful, the mobile phone gateway device 3 transmits connection instruction information to the home gateway device 6 to the access management server device 4 . The above-mentioned connection instruction information includes device identification information of the home gateway device 6 to be connected and the above-mentioned mobile phone information acquired in step S6004. For example, in the above-mentioned example, in FIG. 4 , the content "user02@hogehoge.jp" of the connection destination information 303 as the login information 305 corresponds to the above-mentioned device identification information, and the content of the mobile phone information 302 "hmn61618aa made by the company bb "Model" corresponds to the above-mentioned mobile phone information.

接着,访问管理服务器装置4检索上述连接指示信息中所含有的上述连接目的地信息是否登录在装置信息数据库44中(步骤S6006)。在本例中,由于登录信息404在图7中相当于登录的家庭网关装置6的信息,所以在该情况下,再次构成含有上述便携电话网关装置3的装置识别信息(图5的装置识别信息401的内容,在本例中,登录信息405的装置识别信息401的内容)与上述便携电话信息在内的连接指示信息,将上述连接指示信息发送到上述家庭网关装置6(步骤S6007)。实际上,对上述家庭网关装置6所连接的路由装置5的IP地址(图5的IP地址402的内容)所确定的端口编号(图5的端口编号403的内容)发送上述连接指示信息,上述路由装置5(使用上述端口变换控制部)将上述连接指示信息传送到上述家庭网关装置6。此外,在步骤S6006中,上述连接目的地信息如果未登录在上述装置信息数据库44中,则将连接失败的情况返回到上述便携电话网关装置3。Next, the access management server device 4 searches whether or not the connection destination information included in the connection instruction information is registered in the device information database 44 (step S6006). In this example, since the login information 404 corresponds to the information of the registered home gateway device 6 in FIG. 7 , in this case, the device identification information (device identification information in FIG. The content of 401, in this example, the content of the device identification information 401 of the registration information 405) and the connection instruction information including the mobile phone information, and the connection instruction information is sent to the home gateway device 6 (step S6007). Actually, the above-mentioned connection instruction information is sent to the port number (the content of the port number 403 in FIG. 5 ) determined by the IP address (the content of the IP address 402 in FIG. 5 ) of the routing device 5 connected to the above-mentioned home gateway device 6, and the above-mentioned The routing device 5 (using the port conversion control unit) transmits the connection instruction information to the home gateway device 6 . In addition, in step S6006, if the connection destination information is not registered in the device information database 44, a connection failure is returned to the mobile phone gateway device 3.

接着,家庭网关装置6将路由器外部端口开放请求发送到上述路由装置5(步骤S6008)。上述路由装置5进行上述端口变换部中的外部端口开放设定(步骤S6009)。由此,对来自室外装置(便携电话装置1)的访问,上述路由装置5可将该访问中继到家庭网关装置6。Next, the home gateway device 6 sends a router external port opening request to the above-mentioned routing device 5 (step S6008). The routing device 5 performs external port opening setting in the port conversion unit (step S6009). Thus, the routing device 5 can relay the access from the outdoor device (mobile phone device 1 ) to the home gateway device 6 .

接着,在家庭网关装置6中,访问控制部62作为上述便携电话1用于直接访问上述家庭网关装置6的认证信息生成权标信息,生成含有上述权标信息的访问URL(连接信息),和用于在家庭网关装置6与便携电话网关装置3之间进行密码通信用的密钥(步骤S6010)。Next, in the home gateway device 6, the access control unit 62 generates token information as the authentication information for the mobile phone 1 to directly access the home gateway device 6, generates access URL (connection information) including the token information, and A key for encrypted communication between the home gateway device 6 and the mobile phone gateway device 3 (step S6010).

进而,家庭网关装置6将来自上述便携电话网关装置3的含有连接指示信息的上述便携电话信息、上述权标信息、上述路由装置5中设定的上述外部端口编号、上述建立关联的内部端口编号、上述权标的有效期间、以及上述密钥,登录在图18所示的认证信息数据库65中(步骤S6011)。Furthermore, the home gateway device 6 transmits the above-mentioned mobile phone information including the connection instruction information from the above-mentioned mobile phone gateway device 3, the above-mentioned token information, the above-mentioned external port number set in the above-mentioned routing device 5, and the above-mentioned associated internal port number , the validity period of the token, and the key are registered in the authentication information database 65 shown in FIG. 18 (step S6011).

这里,对图18所示的认证信息数据库65进行说明。图18所示的认证信息数据库65是在图3所示的认证信息数据库65中加入密钥206的条目。密钥206设定家庭网关装置6与便携电话网关装置3用于进行密码通信用的密码信息(密码算法等)与密钥。Here, the authentication information database 65 shown in FIG. 18 will be described. The authentication information database 65 shown in FIG. 18 is an entry in which the key 206 is added to the authentication information database 65 shown in FIG. 3 . The encryption key 206 sets encryption information (encryption algorithm, etc.) and a encryption key for encrypted communication between the home gateway device 6 and the mobile phone gateway device 3 .

在本例中,登录信息208是在步骤S6011中登录的信息。上述所生成的密钥保持于密钥206。In this example, the login information 208 is the information registered in step S6011. The key generated above is held in the key 206 .

回到图15,生成含有上述含有权标信息的访问URL、上述密钥、以及含有图14所示的对应机型信息数据库67中所保存的对应机型信息(对应机型信息601中所保存的所有的信息)的返回信息并发送到上述访问管理服务器装置4(步骤S6012)。上述访问管理服务器装置4再次构成上述返回信息并发送到上述便携电话网关装置3(S6013)。Returning to Fig. 15, generate the above-mentioned access URL containing token information, the above-mentioned key, and the corresponding model information (saved in the corresponding model information 601) stored in the corresponding model information database 67 shown in Fig. 14 . All the information) and send the return information to the above-mentioned access management server device 4 (step S6012). The access management server device 4 reconstructs the return information and sends it to the mobile phone gateway device 3 (S6013).

接着,便携电话网关装置3从上述返回信息中取得上述密钥保持在主存储部102或辅助存储部104中,并且从上述返回信息中取得上述对应机型信息,与图4所示的认证信息数据库35中所保存的便携电话信息302的内容进行比较(步骤S6014)。在本例中,保持在登录信息305中的便携电话信息302中的信息为“hmn61618aa公司制bb机型”,由于在上述对应机型信息中含有“aa公司制bb机型”,所以可以判定为不符合。也就是说,可以判定成上述家庭网关装置6的画面显示信息生成部63无法生成适于上述便携电话装置1的画面显示信息。Next, the mobile phone gateway device 3 obtains the above-mentioned key from the above-mentioned return information and stores it in the main storage unit 102 or the auxiliary storage unit 104, and obtains the above-mentioned corresponding model information from the above-mentioned return information, and the authentication information shown in FIG. 4 The contents of the mobile phone information 302 stored in the database 35 are compared (step S6014). In this example, the information in the mobile phone information 302 held in the registration information 305 is "hmn61618 bb model manufactured by aa company", and since the above-mentioned corresponding model information includes "bb model manufactured by aa company", it can be determined for non-compliance. That is, it can be determined that the screen display information generator 63 of the home gateway device 6 cannot generate screen display information suitable for the mobile phone device 1 .

如果在步骤S6014中判定为不符合,则家庭网关装置6因为在便携电话网关装置3中生成适于便携电话装置1的画面显示信息,将室内装置的信息取得请求发送到上述家庭网关装置3(步骤S6015)。家庭网关装置6根据装置信息数据库66的内容检索室内装置(步骤S6016),将其结果(室内装置信息)返回到便携电话网关装置3(步骤S6017)。在本例中,作为室内装置7,例如照明(登录信息506)、网络摄像机(登录信息507)、HDD录像机(登录信息508)连接于通信介质8。因而,在上述室内装置信息中,含有照明、网络摄像机、HDD录像机的信息。If it is determined in step S6014 that it does not match, the home gateway device 6 sends the information acquisition request of the indoor device to the above-mentioned home gateway device 3 ( Step S6015). The home gateway device 6 searches for indoor devices based on the contents of the device information database 66 (step S6016), and returns the result (indoor device information) to the mobile phone gateway device 3 (step S6017). In this example, indoor devices 7 such as lighting (registration information 506 ), network cameras (registration information 507 ), and HDD recorders (registration information 508 ) are connected to the communication medium 8 . Therefore, the indoor device information includes information on lighting, network cameras, and HDD recorders.

此外,步骤S6015和步骤S6017中的便携电话网关装置3与家庭网关装置6的通信使用在步骤S6010中所生成的密钥进行密码通信。在步骤S6010中所生成的密钥经由步骤S6012和步骤S6013,在步骤S6014中保持在便携电话网关装置3中,在便携电话网关装置3与家庭网关装置6之间共用上述密钥。由此,可以在便携电话网关装置3与家庭网关装置6之间进行安全的通信。In addition, the communication between the mobile phone gateway device 3 and the home gateway device 6 in steps S6015 and S6017 is encrypted using the encryption key generated in step S6010. The key generated in step S6010 is held in the mobile phone gateway device 3 in step S6014 via steps S6012 and S6013, and the key is shared between the mobile phone gateway device 3 and the home gateway device 6 . Thereby, secure communication can be performed between the mobile phone gateway device 3 and the home gateway device 6 .

接着,便携电话网关装置3与上述室内装置信息一起,生成画面显示(Top画面)数据以便能够进行室内装置7的远程操作和控制,发送到上述便携电话装置1(步骤S6018)。结果,在上述便携电话装置1的输出部106上,例如,显示图11所示的画面(步骤S6019),结束处理。在本例中,在上述室内装置信息中,例如,含有照明(登录信息506)、网络摄像机(登录信息507)、HDD录像机(登录信息508)。因而,在本例中,在便携电话装置1输出装置105上,作为控制机器一览,显示能够选择照明、网络摄像机、HDD录像机的画面。Next, the mobile phone gateway device 3 generates screen display (Top screen) data for enabling remote operation and control of the indoor device 7 together with the indoor device information, and sends it to the mobile phone device 1 (step S6018). As a result, for example, the screen shown in FIG. 11 is displayed on the output unit 106 of the mobile phone device 1 (step S6019), and the process ends. In this example, the indoor device information includes, for example, lighting (registration information 506 ), network camera (registration information 507 ), and HDD video recorder (registration information 508 ). Therefore, in this example, on the output device 105 of the mobile phone device 1, a screen from which lighting, a network camera, and an HDD recorder can be selected is displayed as a list of control devices.

此外,在步骤S6014中判定为符合时,也就是,在判定为家庭网关装置3可以生成适于上述便携电话装置1的画面显示信息时,进行与图9所示的步骤S3014至步骤S3019的处理同样的处理。In addition, when it is determined to be consistent in step S6014, that is, when it is determined that the home gateway device 3 can generate the screen display information suitable for the above-mentioned mobile phone device 1, the processing from step S3014 to step S3019 shown in FIG. 9 is performed. Same deal.

也就是说,便携电话网关装置3从在步骤S6013中取得的返回信息中取得上述连接信息(访问URL),生成使向上述访问URL的连接成为可能的画面显示数据并发送到上述便携电话装置1(步骤S6020)。结果,在上述便携电话装置1的输出部106上显示基于上述画面显示数据的画面(步骤S6021),对用户促请上述访问URL的连接信息的选择。如果用户选择上述连接信息,则便携电话装置1将连接请求信息发送到上述家庭网关装置6。此时,便携电话装置1将便携电话信息包含在该连接请求信息中而发送。此外,该连接请求信息对上述访问URL进行。上述访问URL中所含有的IP地址是上述路由装置5的IP地址(在本例中,11.22.33.44),上述访问URL中所含有的端口编号是在步骤6009中上述路由装置5中所设定的上述外部端口编号(在本例中,10001)。因而,上述连接请求信息到达上述家庭网关装置6。That is, the mobile phone gateway device 3 acquires the above-mentioned connection information (access URL) from the return information obtained in step S6013, generates screen display data enabling connection to the above-mentioned access URL, and sends it to the above-mentioned mobile phone device 1. (step S6020). As a result, a screen based on the screen display data is displayed on the output unit 106 of the mobile phone device 1 (step S6021), and the user is prompted to select connection information of the access URL. When the user selects the connection information, the mobile phone device 1 transmits connection request information to the home gateway device 6 . At this time, the mobile phone device 1 includes the mobile phone information in the connection request information and transmits it. In addition, this connection request information is carried out to the above-mentioned access URL. The IP address contained in the above-mentioned access URL is the IP address (in this example, 11.22.33.44) of the above-mentioned routing device 5, and the port number contained in the above-mentioned access URL is set in the above-mentioned routing device 5 in step 6009. The above external port number (in this example, 10001). Accordingly, the above-mentioned connection request information reaches the above-mentioned home gateway device 6 .

接着,家庭网关装置6根据上述连接请求信息中所含有的信息进行便携电话装置1的认证(步骤S6022)。在上述连接请求信息中,含有便携电话装置1的便携电话信息,和(上述访问URL中所含有的)权标信息,分别比较这些信息,与在步骤S6011中保持的登录信息,在全都一致的情况下为认证成功。例如,如果上述连接请求信息中所含有的便携电话信息为“hmn61618aa公司制bb机型”,而且权标信息为“D89bae95hze8”,而且是上述权标信息的有限期限内,则认证成功。Next, the home gateway device 6 performs authentication of the mobile phone device 1 based on the information included in the connection request information (step S6022). The above-mentioned connection request information includes the mobile phone information of the mobile phone device 1 and the token information (included in the above-mentioned access URL), and these information are compared with each other, and it is found that all of them match the registration information held in step S6011. If the authentication is successful. For example, if the mobile phone information contained in the connection request information is "bb model made by hmn61618aa company", and the token information is "D89bae95hze8", and the time limit of the token information is within the time limit, the authentication is successful.

在步骤S6022中,在认证失败时(至少某一方不一致时),将该情况发送到便携电话装置1,上述便携电话装置1在输出装置105上显示该情况(步骤S6023),结束处理。In step S6022, when the authentication fails (at least one of the parties does not agree), the fact is sent to the mobile phone device 1, and the mobile phone device 1 displays the fact on the output device 105 (step S6023), and the process ends.

另一方面,在步骤S6022中,在认证成功时,家庭网关装置6生成画面显示(Top画面)数据以便能够进行室内装置7的远程操作和控制,发送到上述便携电话装置1(步骤S6024)。On the other hand, in step S6022, when the authentication is successful, the home gateway device 6 generates screen display (Top screen) data to enable remote operation and control of the indoor device 7, and sends it to the mobile phone device 1 (step S6024).

结果,在上述便携电话装置1的输出部106上,例如,显示图11所示的画面700(步骤S6025),结束处理。此外,在步骤S6024中,根据图6所示的装置信息数据库66的内容,生成画面显示数据。在本例中,作为室内装置7,例如照明(登录信息506)、网络摄像机(登录信息507)、HDD录像机(登录信息508)连接于通信介质8。因而,在便携电话装置1输出装置105上,作为控制机器一览,显示能够选择照明、网络摄像机、HDD录像机的画面。As a result, for example, a screen 700 shown in FIG. 11 is displayed on the output unit 106 of the mobile phone device 1 (step S6025), and the process ends. In addition, in step S6024, screen display data is generated based on the contents of the device information database 66 shown in FIG. 6 . In this example, indoor devices 7 such as lighting (registration information 506 ), network cameras (registration information 507 ), and HDD recorders (registration information 508 ) are connected to the communication medium 8 . Therefore, on the output device 105 of the mobile phone device 1, a screen from which lighting, a network camera, and an HDD recorder can be selected is displayed as a list of control devices.

此外,此时生成的画面显示数据,根据在步骤S6022中取得的便携电话装置1的便携电话信息中所含有的便携电话机型信息,如前所述对应于标示语言的描述的内容而生成。也就是说,根据取得的便携电话装置1的便携电话信息中所含有的便携电话机型信息指定便携电话的机型,按照该机型的显示画面的规格,生成画面显示数据。具体地说,例如,即使显示字符数,或显示画面尺寸、显示行数、显示位数等因便携电话机型而不同,为了防止字符或按钮等显示对象显示在用户使用不方便的位置,也可以在标示语言中变更字符和显示对象等的显示位置的特征的描述。此外,例如也可以在标示语言中变更字符或显示对象等的显示的尺寸的特征的描述,以便字符和显示对象的大小不因便携电话的机型而成为用户使用不方便的尺寸。In addition, the screen display data generated at this time is generated based on the mobile phone model information included in the mobile phone information of the mobile phone device 1 acquired in step S6022 and corresponding to the content of the description in the markup language as described above. That is, the model of the mobile phone is specified based on the mobile phone model information included in the acquired mobile phone information of the mobile phone device 1, and screen display data is generated according to the specification of the display screen of the model. Specifically, for example, even if the number of displayed characters, or the size of the display screen, the number of display lines, and the number of display digits differ depending on the model of the mobile phone, in order to prevent display objects such as characters or buttons from being displayed at places that are inconvenient for the user, the Characteristic descriptions of display positions such as characters and display objects can be changed in the markup language. In addition, for example, in the markup language, the characteristic description of the display size of characters and display objects may be changed so that the size of characters and display objects does not become inconvenient for the user depending on the model of the mobile phone.

此外,在图15中,步骤S6001、步骤S6003、步骤S6005、步骤S6019、步骤S6021、步骤S6023和步骤S6025是便携电话装置1的浏览器部执行的处理。步骤S6002、步骤S6018和步骤S6020是便携电话网关装置3的画面显示信息生成部33执行的处理。步骤S6004、步骤S6014和步骤S6015是便携电话网关装置3的用户认证部34执行的处理。步骤S6006、步骤S6007、步骤S6013是访问管理服务器4的连接管理部43执行的处理。步骤S6008、步骤S6010至步骤S6012、步骤S6022是家庭网关装置6的访问控制部62执行的处理。步骤S6024是家庭网关装置6的画面显示信息生成部63执行的处理。而且步骤S6009是路由装置5的端口变换部执行的处理。In addition, in FIG. 15 , step S6001 , step S6003 , step S6005 , step S6019 , step S6021 , step S6023 , and step S6025 are processes executed by the browser unit of the mobile phone device 1 . Step S6002 , step S6018 , and step S6020 are processes executed by the screen display information generation unit 33 of the mobile phone gateway device 3 . Step S6004 , step S6014 and step S6015 are processes performed by the user authentication unit 34 of the mobile phone gateway device 3 . Step S6006 , step S6007 , and step S6013 are processes performed by the connection management unit 43 of the access management server 4 . Step S6008 , step S6010 to step S6012 , and step S6022 are processes executed by the access control unit 62 of the home gateway device 6 . Step S6024 is a process executed by the screen display information generator 63 of the home gateway device 6 . Furthermore, step S6009 is a process executed by the port conversion unit of the routing device 5 .

其次,在第二方法中,在图15的步骤S6014中判定为符合时,室内装置的控制以与图10的程序框图的说明同样的方法,便携电话装置1与家庭网关装置6不经由便携电话网关装置3和访问管理服务器4而访问。Next, in the second method, when it is judged to be consistent in step S6014 of FIG. 15 , the control of the indoor device is performed in the same way as described in the flowchart of FIG. Gateway device 3 and access management server 4 to access.

此外,其次,在图15的步骤S6014中判定为不符合时,便携电话装置1、家庭网关装置6、便携电话网关装置3、访问管理服务器4如下地进行处理。Furthermore, next, when it is determined that it does not match in step S6014 of FIG. 15 , the mobile phone device 1 , the home gateway device 6 , the mobile phone gateway device 3 , and the access management server 4 perform processing as follows.

也就是说,以下在判定成家庭网关装置6的画面显示信息生成部63无法生成适于上述便携电话装置1的画面显示信息时,便携电话装置1使用上述连接信息访问家庭网关装置6,对控制室内装置7的处理的细节进行说明。此时的处理程序框图示于图16。That is to say, when it is determined that the screen display information generator 63 of the home gateway device 6 cannot generate screen display information suitable for the mobile phone device 1, the mobile phone device 1 accesses the home gateway device 6 using the connection information, and controls the home gateway device 6. The details of the processing of the indoor unit 7 will be described. The flow chart of processing at this time is shown in FIG. 16 .

如图16所示,首先用户操作便携电话装置1选择打算遥控控制的机器,将该选择信息发送到便携电话网关装置3(步骤S7001)。此时,在便携电话装置1的输出部106上,显示图11所示的画面700(控制机器一览),用户从其中选择打算远程控制的机器而选择执行按钮701(如果在图11中所示的画面700中选择按钮701,则照明被选择)。As shown in FIG. 16, first, the user operates the mobile phone device 1 to select a device to be remotely controlled, and transmits the selection information to the mobile phone gateway device 3 (step S7001). At this time, on the output unit 106 of the mobile phone device 1, a screen 700 (list of control devices) shown in FIG. If the button 701 is selected in the screen 700 of the screen 700, the lighting is selected).

接着,上述便携电话网关装置3,为了生成控制上述所选择的机器用的画面显示数据,将在步骤S7001中所选择的机器(室内装置)的信息的取得请求发送到家庭网关装置6(步骤S7002)。然后,上述家庭网关装置6参照装置信息数据库66访问该室内装置,取得当前的状态,将含有该状态的上述室内装置的信息发送到上述便携电话网关装置3(步骤S7003)。Next, the mobile phone gateway device 3 transmits a request for obtaining information on the device (indoor device) selected in step S7001 to the home gateway device 6 in order to generate screen display data for controlling the selected device (step S7002 ). Then, the home gateway device 6 accesses the indoor device by referring to the device information database 66, acquires the current state, and transmits the information of the indoor device including the state to the mobile phone gateway device 3 (step S7003).

便携电话网关装置3根据上述室内装置的信息生成用于控制该室内装置的画面显示数据,发送到上述便携电话装置1(步骤S7004)。结果,在上述便携电话装置1的输出部106上,显示例如图12所示的画面702。在图12中,显示上述照明的状态,在本例中,上述照明为接通(进行照明)的状态。在上述画面702中,如果选择返回按钮704,则上述画面700在上述便携电话装置1的输出部106上被显示。The mobile phone gateway device 3 generates screen display data for controlling the indoor device based on the information on the indoor device, and sends it to the mobile phone device 1 (step S7004). As a result, a screen 702 such as that shown in FIG. 12 is displayed on the output unit 106 of the mobile phone device 1 . In FIG. 12 , the state of the above-mentioned lighting is shown, and in this example, the above-mentioned lighting is in a state of being turned on (illumination is performed). When the return button 704 is selected on the screen 702 , the screen 700 is displayed on the output unit 106 of the mobile phone device 1 .

例如在上述画面702中,如果用户选择切断而选择执行按钮703,则将该选择信息(机器控制指示)发送到上述便携电话网关装置3(步骤S7005)。然后,上述便携电话网关装置3再次构成上述机器控制指示并发送到家庭网关装置6(步骤S7006)。For example, if the user selects disconnection on the screen 702 and selects the execution button 703, the selection information (device control instruction) is sent to the mobile phone gateway device 3 (step S7005). Then, the mobile phone gateway device 3 reconfigures the device control instruction and sends it to the home gateway device 6 (step S7006).

上述家庭网关装置6根据上述机器控制指示生成所选择的机器的控制用通信数据并发送到上述所选择的机器(室内装置7)(步骤S7007)。此时,如果上述所选择的机器为照明,该照明如上所述是对应于ECHONET的机器,则上述控制用通信数据以根据ECHONET标准的电文格式来生成,使用同样根据ECHONET标准的通信协议发送到上述室内装置7。The home gateway device 6 generates control communication data for the selected appliance based on the appliance control instruction, and transmits it to the selected appliance (indoor device 7) (step S7007). At this time, if the above-mentioned selected device is lighting, and the lighting is a device corresponding to ECHONET as described above, the above-mentioned control communication data is generated in a message format according to the ECHONET standard, and is sent to The indoor unit 7 mentioned above.

接着,室内装置7按照接收的上述控制用通信数据控制本机器(在本例中,照明的切断)(步骤S7008),将该控制结果发送到上述家庭网关装置6(步骤S7009)。然后,家庭网关装置6将该控制结果发送到上述便携电话网关装置3(步骤S7010),上述便携电话网关装置3生成表示该控制结果的画面显示数据,发送到上述便携电话装置1(步骤S7011)。结果,在上述便携电话装置1的输出部106上显示表示该控制结果的画面(步骤S7012),结束处理。Next, the indoor device 7 controls itself (in this example, lighting off) according to the received control communication data (step S7008), and transmits the control result to the home gateway device 6 (step S7009). Then, the home gateway device 6 transmits the control result to the above-mentioned mobile phone gateway device 3 (step S7010), and the above-mentioned mobile phone gateway device 3 generates screen display data representing the control result and sends it to the above-mentioned mobile phone device 1 (step S7011) . As a result, a screen showing the result of the control is displayed on the output unit 106 of the mobile phone device 1 (step S7012), and the process ends.

上述便携电话网关装置3与上述家庭网关装置6之间的通信(步骤S7002、步骤S7003、步骤S7006和步骤S7010)在图15中由共通密钥加密进行通信。由此,上述便携电话网关装置3与上述家庭网关装置6之间的安全的通信成为可能。The communication between the mobile phone gateway device 3 and the home gateway device 6 (step S7002, step S7003, step S7006, and step S7010) is encrypted by a common key in FIG. 15 . Thus, secure communication between the mobile phone gateway device 3 and the home gateway device 6 becomes possible.

此外,在图16中,步骤S7001、步骤S7005和步骤S7012是便携电话装置1的浏览器部12执行的处理。步骤S7002、步骤S7004、步骤S7006和步骤S7011是便携电话网关装置3的画面显示信息生成部33执行的处理。步骤S7003、步骤S7007和步骤S7010是家庭网关装置6的机器管理控制部64执行的处理。而且步骤S7008至步骤S7009是室内装置7的控制部72执行的处理。In addition, in FIG. 16 , step S7001 , step S7005 , and step S7012 are processes executed by the browser unit 12 of the mobile phone device 1 . Step S7002 , step S7004 , step S7006 , and step S7011 are processes performed by the screen display information generation unit 33 of the mobile phone gateway device 3 . Step S7003 , step S7007 , and step S7010 are processes performed by the device management control unit 64 of the home gateway device 6 . Furthermore, steps S7008 to S7009 are processes executed by the control unit 72 of the indoor unit 7 .

接下来对在步骤S7001中,用户作为控制对象机器选择网络摄像机(在画面700中,选择网络摄像机而选择执行按钮701)的情况进行说明。通常,由于网络摄像机具备网络服务器功能,所以在步骤S7007中,家庭网关装置6对上述网络摄像机(室内装置7)进行网络访问。在步骤S7008中,上述网络摄像机作为静止图像数据生成该时刻的摄像机图像,在步骤S7009中,上述网络摄像机将该静止图像数据发送到上述家庭网关装置6。在步骤S7010中,上述家庭网关装置6将该静止图像数据发送到上述便携电话网关装置3,在步骤S7011中,上述便携电话网关装置3生成含有上述静止图像数据的画面显示数据并发送到上述便携电话装置1。结果,该静止图像数据在上述便携电话装置1的输出装置106上被显示(步骤S7012)。Next, in step S7001, a case where the user selects a network camera as a device to be controlled (in the screen 700, selects the network camera and selects the execution button 701) will be described. Usually, since the network camera has a network server function, in step S7007, the home gateway device 6 performs network access to the network camera (indoor device 7). In step S7008, the network camera generates a camera image at that time as still image data, and in step S7009, the network camera transmits the still image data to the home gateway device 6 . In step S7010, the home gateway device 6 transmits the still image data to the mobile phone gateway device 3, and in step S7011, the mobile phone gateway device 3 generates screen display data including the still image data and sends it to the mobile phone gateway device 3. Telephone device 1 . As a result, the still image data is displayed on the output device 106 of the above-mentioned mobile phone device 1 (step S7012).

接下来对在步骤S7001中,用户作为控制对象机器选择HDD录像机(在画面700中,选择HDD录像机而选择执行按钮701)的情况进行说明。在步骤S7007中,家庭网关装置6将图像取得请求发送到上述HDD录像机(室内装置7)。在步骤S7008中,上述HDD录像机在上述便携电话装置1中再现所请求的累积图像,对上述累积图像施行适当图像压缩格式变换等,以便可以阅览。在步骤S7009中,上述HDD录像机将上述变换后的图像数据发送到上述家庭网关装置6。在步骤S7010中,上述家庭网关装置6将该图像数据发送到上述便携电话网关装置3,要步骤S7011中上述便携电话网关装置3将上述图像数据发送到上述便携电话装置1,保持在上述便携电话装置1的辅助存储部104中。便携电话装置1在输出装置106上显示累积图像的选择画面,如果用户选择上述图像数据,则上述图像数据被再现。然后所再现的图像在上述便携电话装置1的输出装置106上被显示(步骤S7012)。Next, in step S7001, a case where the user selects an HDD recorder as a device to be controlled (in the screen 700, selects the HDD recorder and selects the execution button 701) will be described. In step S7007, the home gateway device 6 transmits an image acquisition request to the HDD recorder (indoor device 7). In step S7008, the HDD video recorder reproduces the requested accumulated image on the mobile phone device 1, and performs appropriate image compression format conversion on the accumulated image so that it can be browsed. In step S7009, the HDD video recorder sends the converted image data to the home gateway device 6 . In step S7010, the above-mentioned home gateway device 6 transmits the image data to the above-mentioned mobile phone gateway device 3, and in step S7011, the above-mentioned mobile phone gateway device 3 transmits the above-mentioned image data to the above-mentioned mobile phone device 1, and keeps it in the above-mentioned mobile phone in the auxiliary storage unit 104 of the device 1. The mobile phone device 1 displays a selection screen of accumulated images on the output device 106, and when the user selects the image data, the image data is reproduced. The reproduced image is then displayed on the output device 106 of the mobile phone device 1 (step S7012).

接下来,对在第二方法中,结束从便携电话装置1经由便携电话网关装置3向家庭网关装置6的访问时的处理的细节进行说明。此时的处理程序框图示于图17。Next, in the second method, the details of the processing when the access from the mobile phone device 1 to the home gateway device 6 via the mobile phone gateway device 3 is terminated will be described. The flow chart of the processing at this time is shown in Fig. 17 .

如图17所示,首先用户操作便携电话装置1,将注销信息发送到便携电话网关装置3(步骤S8001)。此时,在便携电话装置1的输出部106上,显示图11所示的画面700(控制机器一览),用户从其中选择注销而选择执行按钮701。As shown in FIG. 17, first, the user operates the mobile phone device 1 to transmit logout information to the mobile phone gateway device 3 (step S8001). At this time, on the output unit 106 of the mobile phone device 1, a screen 700 (list of control devices) shown in FIG.

接着,上述便携电话网关装置3将用于结束与家庭网关装置6的连接的连接结束请求发送到访问管理服务器装置4(步骤S8002)。在上述连接结束请求中含有上述家庭网关装置6的装置识别信息。然后,访问管理服务器装置4根据上述装置识别信息检索装置信息数据库44(步骤S8003),如果找到上述装置识别信息的登录信息,则将上述连接结束请求发送到上述装置识别信息表示的家庭网关装置6(步骤S8004)。此时访问管理服务器装置4再次构成上述连接结束请求以便含有上述便携电话网关装置3的装置识别信息,将上述连接结束请求发送到上述家庭网关装置6。Next, the mobile phone gateway device 3 transmits a connection termination request for terminating the connection with the home gateway device 6 to the access management server device 4 (step S8002). The device identification information of the home gateway device 6 is included in the connection end request. Then, the access management server device 4 searches the device information database 44 according to the device identification information (step S8003), and if the registration information of the device identification information is found, the connection end request is sent to the home gateway device 6 indicated by the device identification information. (step S8004). At this time, the access management server device 4 reconfigures the connection termination request so as to include the device identification information of the mobile phone gateway device 3 , and transmits the connection termination request to the home gateway device 6 .

接着,收到上述连接结束请求的家庭网关装置6检索数据传送用端口编号(步骤S8005),对路由装置5发送路由器外部端口闭锁请求(步骤S8006)。此时,数据传送用端口编号的检索,对图18所示的认证信息数据库65来进行。也就是说,是在图5说明的本连接开始处理中,检索路由装置5中设定的开放外部端口编号,在本例的情况下,取得登录信息208的外部端口编号203的内容。然后,成为将对上述外部端口编号的路由器外部端口闭锁请求发送到上述路由装置5。然后,路由装置5进行外部端口闭锁设定(步骤S8007)。由此,可以阻断来自室外装置的未授权的访问。Next, the home gateway device 6 having received the above-mentioned connection termination request searches for the port number for data transfer (step S8005), and sends a router external port blocking request to the router device 5 (step S8006). At this time, the search for the port number for data transfer is performed on the authentication information database 65 shown in FIG. 18 . That is, in the present connection start process described in FIG. 5 , the open external port number set in the router 5 is searched, and in this example, the content of the external port number 203 of the login information 208 is acquired. Then, a router external port blocking request for the external port number is transmitted to the routing device 5 . Then, the routing device 5 performs external port block setting (step S8007). Thereby, unauthorized access from the outdoor device can be blocked.

接着,家庭网关装置6进行与上述便携电话网关装置3的连接结束处理(步骤S8008)。具体地说,从图18所示的认证信息数据库65中删除符合的登录信息。在本例中,由于登录信息208符合,所以就删除登录信息208。然后,家庭网关装置6生成含有关于是否正常地结束处理的结果的返回信息,将该返回信息发送到访问管理服务器装置4(步骤S8009)。在该返回信息中含有上述便携电话网关装置3的装置识别信息。然后,访问管理服务器装置4将该返回信息发送到该返回信息中所含有的装置识别信息表示的便携电话网关装置3(步骤S8010)。Next, the home gateway device 6 performs connection termination processing with the mobile phone gateway device 3 (step S8008). Specifically, the matching login information is deleted from the authentication information database 65 shown in FIG. 18 . In this example, since the login information 208 matches, the login information 208 is deleted. Then, the home gateway device 6 generates return information including the result of whether or not the processing was completed normally, and transmits the return information to the access management server device 4 (step S8009). The device identification information of the mobile phone gateway device 3 is included in the return information. Then, the access management server device 4 transmits the return information to the mobile phone gateway device 3 indicated by the device identification information contained in the return information (step S8010).

然后,上述便携电话网关装置3进行与上述家庭网关装置6的连接结束处理(保持的信息的删除),生成表示连接结束的画面显示数据,将上述画面显示数据发送到上述便携电话装置1(步骤S8011)。结果,在上述便携电话装置1的输出部106上显示表示连接结束的画面(步骤S8012),结束处理。Then, the above-mentioned mobile phone gateway device 3 performs connection termination processing (deletion of held information) with the above-mentioned home gateway device 6, generates screen display data indicating that the connection is completed, and transmits the above-mentioned screen display data to the above-mentioned mobile phone device 1 (step S8011). As a result, a screen indicating that the connection has been completed is displayed on the output unit 106 of the mobile phone device 1 (step S8012), and the process ends.

上述便携电话网关装置3与上述家庭网关装置6之间的通信(步骤S8002、步骤S8004、步骤S8009和步骤S8010)以在图15中共用的共同密钥进行加密并通信。由此,上述便携电话网关装置3与上述家庭网关装置6之间可安全通信。The communication between the mobile phone gateway device 3 and the home gateway device 6 (step S8002, step S8004, step S8009, and step S8010) is encrypted and communicated using the common key shared in FIG. 15 . Thus, secure communication between the mobile phone gateway device 3 and the home gateway device 6 is possible.

此外,在图17中,步骤S8001和步骤S8012是便携电话装置1的浏览器部执行的处理。步骤S8002和步骤S8011是便携电话网关装置3的访问管理部32执行的处理。步骤S8005至步骤S8006和步骤S8008至步骤S8009是家庭网关装置6的访问控制部62执行的处理。步骤S8003至步骤S8004、步骤S8010是访问管理服务器装置4的连接管理部43执行的处理。而且步骤S8007是路由装置5的端口变换部执行的处理。In addition, in FIG. 17 , step S8001 and step S8012 are processes executed by the browser unit of the mobile phone device 1 . Step S8002 and step S8011 are processes performed by the access management unit 32 of the mobile phone gateway device 3 . Steps S8005 to S8006 and steps S8008 to S8009 are processes executed by the access control unit 62 of the home gateway device 6 . Step S8003 to step S8004 and step S8010 are processes performed by the connection management unit 43 of the access management server device 4 . Furthermore, step S8007 is a process executed by the port conversion unit of the routing device 5 .

以上,像说明的那样,根据本实施方式,通过经由便携电话网关装置与访问管理服务器装置进行与便携电话和家庭网关装置的连接管理,可以提高安全性。在从便携电话装置控制室内机器时,使便携电话与家庭网关装置的对等通信成为可能。进而,可以由家庭网关装置认证来自便携电话的访问经授权。因此,即使在网络数据、静止图像、图像之类大容量数据通信中,也可以既确保高的安全性,而且进行能够降低访问管理服务器装置的负荷的对等通信。As described above, according to the present embodiment, the security can be improved by performing connection management with the mobile phone and the home gateway device via the mobile phone gateway device and the access management server device. When the indoor equipment is controlled from the mobile phone device, peer-to-peer communication between the mobile phone and the home gateway device is enabled. Furthermore, the access from the mobile phone can be authenticated by the home gateway device as authorized. Therefore, even in large-capacity data communication such as network data, still images, and images, it is possible to perform peer-to-peer communication capable of reducing the load on the access management server device while ensuring high security.

进而,在本实施例中,由家庭网关装置通过从便携电话网关装置所发送的认证信息,与从便携电话装置所发送的认证信息的比较来进行经授权证明。因此,即使用户所有的便携电话的变更和室外装置的种类增加,家庭网关装置中的认证信息更新也没有必要。也就是说,如上所述,便携电话网关装置因为服务器运营者运营的数据中心中备有,故不用将便携电话装置的变更通知服务器运营者就可以在服务器运营者侧进行认证信息的更新。因而,利用家庭网络的终端的用户,没有必要更新例如登录于家庭网关装置内的认证信息。Furthermore, in this embodiment, the authentication information transmitted from the mobile phone gateway device is compared with the authentication information transmitted from the mobile phone device by the home gateway device to verify authorization. Therefore, even if the mobile phone owned by the user is changed or the types of outdoor devices increase, it is not necessary to update the authentication information in the home gateway device. That is, as described above, since the mobile phone gateway device is provided in the data center operated by the server operator, the authentication information can be updated on the server operator side without notifying the server operator of a change in the mobile phone device. Therefore, the user of the terminal using the home network does not need to update the authentication information registered in the home gateway device, for example.

进而,通过由家庭网关装置进行室内机器的连接管理,在用户使用便携电话访问室内机器时,即使连接于家庭网络(室内系统)的室内机器增加也可以提高使用方便性。Furthermore, by performing connection management of indoor devices by the home gateway device, when a user accesses the indoor devices using a mobile phone, usability can be improved even if the number of indoor devices connected to the home network (indoor system) increases.

进而,在家庭网关装置无法生成对应于访问的便携电话等室外装置的机型的画面显示信息的情况也是,通过使从便携电话等室外装置经由便携电话网关装置等外部网关装置与家庭网关装置进行通信成为可能,可以提供柔性地适应用户所有的室外装置的变更或新机型的良好的使用环境。Furthermore, even when the home gateway device cannot generate screen display information corresponding to the model of the outdoor device such as the mobile phone to access, by making the outdoor device such as the mobile phone communicate with the home gateway device via the external gateway device such as the mobile phone gateway device, Communication becomes possible, and it is possible to provide a good use environment that flexibly adapts to changes or new models of outdoor equipment owned by the user.

工业实用性Industrial Applicability

本发明可以运用于从室外,使用例如便携电话等室外装置,控制连接于家庭网络的家用电器和/或住宅设备机器的系统。本发明例如可以利用于从室外控制室内的DVD/HDD录像机,将其中所累积的内容下载到室外装置等,大容量的数据通信服务。而且本发明为了实现这种服务等,防止未授权的访问而提高安全性,进而对于适应更多种类的室外装置是合适的。The present invention can be applied to a system for controlling home appliances and/or house equipment connected to a home network from the outside using an outdoor device such as a mobile phone. For example, the present invention can be used for large-capacity data communication services such as controlling a DVD/HDD recorder indoors from the outdoors, and downloading contents accumulated therein to an outdoor device. Furthermore, in order to realize such services and the like, the present invention improves security by preventing unauthorized access, and is suitable for adapting to a wider variety of outdoor devices.

Claims (20)

1. one kind via network and outdoor location and the home gateway device that the exterior gateway device is connected, and it is characterized in that having:
Keep relating to the storage part of information of the device of regulation; With
The access control portion of the visit between control and the described outdoor location,
The information of the device that relates to described regulation that described access control portion will obtain from described storage part sends to described exterior gateway device,
Judge that at described exterior gateway device the information conforms that relates to described outdoor location that obtains from described outdoor location relates under the situation of information of device of described regulation, described access control portion does not carry out and described outdoor location control of communication via described exterior gateway device.
2. home gateway device according to claim 1 is characterized in that:
Also have picture display message generating unit,
Described image information generating unit relates in the information conforms that relates to described outdoor location under the situation of information of device of described regulation, the information that relates to described outdoor location that use obtains from described outdoor location generates the picture display message corresponding with described outdoor location.
3. home gateway device according to claim 2 is characterized in that:
Described picture display message generating unit relates in the information conforms that relates to described outdoor location under the situation of information of device of described regulation, the information that relates to described outdoor location that use sends from described outdoor location generates to show the data that corresponding descriptive language is described with the picture of described outdoor location.
4. home gateway device according to claim 3 is characterized in that:
Described descriptive language is an indicating language.
5. home gateway device according to claim 3 is characterized in that:
Described descriptive language is the descriptive language by the metalanguage definition.
6. home gateway device according to claim 2 is characterized in that:
Described picture display message generating unit relates in the information conforms that relates to described outdoor location under the situation of information of device of described regulation, the information that relates to described outdoor location that use obtains from described outdoor location generates the data of the description content of description of change language.
7. home gateway device according to claim 1 is characterized in that:
Described access control portion does not meet in the information that relates to described outdoor location under the situation of information of the device that relates to described regulation, via described exterior gateway device carry out with described outdoor location between communicate by letter.
8. home gateway device according to claim 2 is characterized in that:
The information that relates to the device of described regulation comprises the model information of outdoor location or the information of the browser that outdoor location has.
9. home gateway device according to claim 2 is characterized in that:
Also have the machine handing control part that is used to control via the indoor machine of described home gateway device and home-network linkups,
The described indoor machine of Control on Communication between described machine handing control part basis and the described outdoor location.
10. one kind via network and outdoor location, exterior gateway device and the home gateway device that the connection management device is connected, and it is characterized in that having:
Keep relating to the storage part of information of the device of regulation; With
The access control portion of the visit between control and the described outdoor location,
Described access control portion
In described exterior gateway device,, receive from described exterior gateway device via described connection management device and to connect indication information under the situation from first authentication success of the visit of described outdoor location,
Under the situation that receives described connection indication information, generate first authentication information,
Described first authentication information is sent to described outdoor location,
Relate under the situation of information of device of described regulation carrying out described first when authentication send to described exterior gateway device from described outdoor location the information conforms that relates to described outdoor location, use second authentication information that sends from described outdoor location to carry out second authentication.
11. home gateway device according to claim 10 is characterized in that:
Also have picture display message generating unit,
Described second authentication information sends with the information that relates to described outdoor location,
Described image information generating unit is used the information that relates to described outdoor location under the situation of described second authentication success, generate the picture display message corresponding with described outdoor location,
Described access control portion sends to described outdoor location with described picture display message.
12. home gateway device according to claim 11 is characterized in that:
The information that relates to the device of described regulation comprises the model information of outdoor location or the information of the browser that outdoor location has.
13. home gateway device according to claim 11 is characterized in that:
Also have under the situation of described second authentication success, according to the machine handing control part of the signal controlling that sends from described outdoor location via the indoor machine of described home gateway device and home-network linkups.
14. home gateway device according to claim 11 is characterized in that:
The token that described first authentication information that described access control portion generates generates when comprising the described connection indication information of each reception at random.
15. home gateway device according to claim 11 is characterized in that:
Send to described first authentication information of described outdoor location, the URL information of the described home gateway device that generates with described access control portion is sent to described outdoor location,
Described second authentication information generates under the selecteed situation of the link information of the URL of the described home gateway device of the display frame that is shown in described outdoor location.
16. home gateway device according to claim 11 is characterized in that:
Described outdoor location is a portable phone,
Described second authentication information comprises the identifying information of described portable phone,
Described identifying information relates to the information of the manufacturing numbering of described portable phone.
17. one kind via network and outdoor location and the home gateway device that the exterior gateway device is connected, and it is characterized in that having:
Keep relating to the storage part of information of the device of regulation; With
The access control portion of the visit between control and the described outdoor location,
The information of the device that relates to described regulation that described access control portion will obtain from described storage part sends to described exterior gateway device,
Judge that at described exterior gateway device the information conforms that relates to described outdoor location that obtains from described outdoor location relates under the situation of information of device of described regulation, described access control portion carry out and described outdoor location between the control of peer-to-peer communications.
18. home gateway device according to claim 17 is characterized in that:
Also have descriptive language information generating unit,
Described descriptive language information generating unit relates in the information conforms that relates to described outdoor location under the situation of information of device of described regulation, the information that relates to described outdoor location that use obtains from described outdoor location generates the corresponding descriptive language information of picture demonstration with described outdoor location.
19. home gateway device according to claim 18 is characterized in that:
Described outdoor location is a portable terminal device,
Described descriptive language information generating unit relates in the information conforms that relates to described outdoor location under the situation of information of device of described regulation, according to the information that relates to described outdoor location that obtains from described outdoor location, change also generates the description that relates to the label of CSD in the descriptive language information.
20. home gateway device according to claim 18 is characterized in that:
Described outdoor location is a portable terminal device,
Described descriptive language information generating unit relates in the information conforms that relates to described outdoor location under the situation of information of device of described regulation, according to the information that relates to described outdoor location that obtains from described outdoor location, change also generates the description that relates to the label of the display position of display object in the descriptive language information.
CN2006101645201A 2006-05-19 2006-12-05 Household gateway device Active CN101075994B (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
JP2006-139686 2006-05-19
JP2006139686 2006-05-19
JP2006139686A JP4742981B2 (en) 2006-05-19 2006-05-19 Home gateway device

Publications (2)

Publication Number Publication Date
CN101075994A true CN101075994A (en) 2007-11-21
CN101075994B CN101075994B (en) 2010-09-01

Family

ID=38844584

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2006101645201A Active CN101075994B (en) 2006-05-19 2006-12-05 Household gateway device

Country Status (2)

Country Link
JP (1) JP4742981B2 (en)
CN (1) CN101075994B (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101820344A (en) * 2010-03-23 2010-09-01 中国电信股份有限公司 AAA server, home network access method and system
WO2014187307A1 (en) * 2013-12-12 2014-11-27 中兴通讯股份有限公司 Remote home gateway controller, home gateway, terminal and terminal control method
WO2015161494A1 (en) * 2014-04-25 2015-10-29 Abb Technology Ltd A household system of a door entry system, the door entry system and an integrated indoor station
CN105230039A (en) * 2013-05-23 2016-01-06 三菱电机株式会社 Indoor equipment, tele-control system and program

Families Citing this family (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2009146306A (en) * 2007-12-17 2009-07-02 Sharp Corp Server device, communication terminal device, access system, access method, and access program
JP5038956B2 (en) * 2008-03-27 2012-10-03 パナソニック株式会社 Network system
JP5025694B2 (en) * 2008-07-28 2012-09-12 株式会社デジックス Network camera system
JP5238565B2 (en) * 2009-03-18 2013-07-17 東日本電信電話株式会社 Information communication system
US8681761B2 (en) 2009-06-04 2014-03-25 Nec Corporation Gateway apparatus, method, and system
JP4785952B2 (en) * 2009-06-16 2011-10-05 日本電信電話株式会社 ACCESS CONTROL SYSTEM, ACCESS CONTROL METHOD, ACCESS CONTROL PROGRAM, AND ACCESS CONTROL PROGRAM RECORDING MEDIUM
JP5561278B2 (en) * 2009-07-08 2014-07-30 日本電気株式会社 Gateway apparatus and method and communication system
US20120110203A1 (en) 2009-07-10 2012-05-03 Kazunori Ozawa Delivery system and method, gateway device, and program
JP2011186571A (en) * 2010-03-05 2011-09-22 Hitachi Ltd Server and client system
JP5874486B2 (en) * 2012-03-26 2016-03-02 富士通株式会社 COMMUNICATION SYSTEM, PORTABLE TERMINAL, RELAY DEVICE, AND COMMUNICATION CONTROL METHOD
CN102594638A (en) * 2012-03-29 2012-07-18 中山大学 Digital home network system and method
CN103401742B (en) * 2013-08-15 2017-05-24 上海斐讯数据通信技术有限公司 Effective method and system for home gateway SIP (Session Initiation Protocol) configuration
US20150373304A1 (en) 2014-06-18 2015-12-24 Opentv, Inc. User/interaction association via a media gateway
JP6882314B2 (en) * 2015-11-24 2021-06-02 サムスン エレクトロニクス カンパニー リミテッド Smart home service server and its control method

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001331389A (en) * 2000-05-24 2001-11-30 Nec Mobiling Ltd Information processing system
JP2004078280A (en) * 2002-08-09 2004-03-11 Fujitsu Ltd Remote access mediation system and method
JP4042641B2 (en) * 2003-07-07 2008-02-06 株式会社日立製作所 Method and system for accessing network-compatible device
JP4377786B2 (en) * 2004-09-22 2009-12-02 パナソニック株式会社 ELECTRIC DEVICE, SERVER DEVICE, PORTABLE TERMINAL, COMMUNICATION SYSTEM, COMMUNICATION METHOD, AND PROGRAM

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101820344A (en) * 2010-03-23 2010-09-01 中国电信股份有限公司 AAA server, home network access method and system
CN105230039A (en) * 2013-05-23 2016-01-06 三菱电机株式会社 Indoor equipment, tele-control system and program
CN105230039B (en) * 2013-05-23 2018-11-16 三菱电机株式会社 Indoor controller and tele-control system
WO2014187307A1 (en) * 2013-12-12 2014-11-27 中兴通讯股份有限公司 Remote home gateway controller, home gateway, terminal and terminal control method
WO2015161494A1 (en) * 2014-04-25 2015-10-29 Abb Technology Ltd A household system of a door entry system, the door entry system and an integrated indoor station
CN105517654A (en) * 2014-04-25 2016-04-20 Abb技术有限公司 A household system of a door entry system, the door entry system and an integrated indoor station
CN105517654B (en) * 2014-04-25 2020-03-31 Abb瑞士股份有限公司 Household indoor system of building intercom system, building intercom system and main indoor unit

Also Published As

Publication number Publication date
CN101075994B (en) 2010-09-01
JP4742981B2 (en) 2011-08-10
JP2007312148A (en) 2007-11-29

Similar Documents

Publication Publication Date Title
CN101075994A (en) Household gateway device
CN1881964A (en) Home gateway device, access control system for home network
CN1278557C (en) Information delivery system, method, information processing apparatus, and method
CN101438256B (en) Information processing device, information communication system, information processing method
CN1282934C (en) Information processing device and method, content distribution device and method and computer program
CN1790987A (en) System for and method of authenticating device and user in home network
CN1682491A (en) Local terminal device and communication system
CN1748207A (en) Information processing device, information processing method, and computer program
CN1780219A (en) Information terminal remote operation system and method, gateway server, information terminal, information terminal control apparatus, information terminal apparatus
CN101064628A (en) Household network appliance safe management system and method
CN1759564A (en) Access control processing method
US20100180312A1 (en) Content delivery apparatus, program, and storage medium
CN1685689A (en) Device, method and computer software product for controlling home terminal
CN1615632A (en) Mechanism for supporting wired and wireless methods for client and server side authentication
CN1842782A (en) Server architecture for network resource information routing
CN1684423A (en) Information-provision control method and information reproduction system
CN1852418A (en) Mobile television television broadcasting control system and broadcasting network and method
CN100343835C (en) Program, information processing method and device
CN1893356A (en) Method and system for accessing computer resource through mobile terminal
CN101076976A (en) Authentication system, authentication method, and authentication information generation program
CN1820473A (en) Method, terminal device and server for transmission operation message in fixed and/or mobile network
CN1694452A (en) Method and system for communicating between a terminal and at least one communication device
CN1698047A (en) Terminal device, provision server, electronic information utilization method, electronic information provision method, terminal device program, provision server program, intermediate program and recor
CN1578277A (en) Television portal services system and method using message-based protocol
CN1738248A (en) Information-processing method, information-processing apparatus and computer program

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
ASS Succession or assignment of patent right

Owner name: HITACHI?INDUSTRIAL?CONTROL INFORMATION SYSTEM CO.,

Free format text: FORMER OWNER: HITACHI,LTD.

Effective date: 20141231

C41 Transfer of patent application or patent right or utility model
TR01 Transfer of patent right

Effective date of registration: 20141231

Address after: Ibaraki

Patentee after: Hitachi industrial control information system

Address before: Tokyo, Japan

Patentee before: Hitachi, Ltd.

C56 Change in the name or address of the patentee

Owner name: HITACHI INDUSTRIAL CONTROL SOLUTIONS LTD.

Free format text: FORMER NAME: HITACHI?INDUSTRIAL?CONTROL INFORMATION SYSTEM CO., LTD.

CP01 Change in the name or title of a patent holder

Address after: Ibaraki

Patentee after: HITACHI INDUSTRY & CONTROL SOLUTIONS, LTD.

Address before: Ibaraki

Patentee before: Hitachi industrial control information system

CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: Japan

Patentee after: HITACHI INDUSTRY & CONTROL SOLUTIONS, LTD.

Country or region after: Japan

Address before: Ibaraki

Patentee before: HITACHI INDUSTRY & CONTROL SOLUTIONS, LTD.

Country or region before: Japan

TR01 Transfer of patent right
TR01 Transfer of patent right

Effective date of registration: 20250307

Address after: Japan

Patentee after: HITACHI BUILDING SYSTEMS Co.,Ltd.

Country or region after: Japan

Address before: Japan

Patentee before: HITACHI INDUSTRY & CONTROL SOLUTIONS, LTD.

Country or region before: Japan