[go: up one dir, main page]

CN102378982B - Monitoring system and communication management device - Google Patents

Monitoring system and communication management device Download PDF

Info

Publication number
CN102378982B
CN102378982B CN201080014851.1A CN201080014851A CN102378982B CN 102378982 B CN102378982 B CN 102378982B CN 201080014851 A CN201080014851 A CN 201080014851A CN 102378982 B CN102378982 B CN 102378982B
Authority
CN
China
Prior art keywords
terminal
connection
monitoring
terminals
sip
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201080014851.1A
Other languages
Chinese (zh)
Other versions
CN102378982A (en
Inventor
藤沢正幸
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
CIKOM Co Ltd
Original Assignee
CIKOM Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by CIKOM Co Ltd filed Critical CIKOM Co Ltd
Publication of CN102378982A publication Critical patent/CN102378982A/en
Application granted granted Critical
Publication of CN102378982B publication Critical patent/CN102378982B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/18Closed-circuit television [CCTV] systems, i.e. systems in which the video signal is not broadcast

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Multimedia (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Telephonic Communication Services (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Closed-Circuit Television Systems (AREA)
  • Alarm Systems (AREA)

Abstract

通信管理装置(11)连接到多个终端。多个终端是监视装置(15)和使用者装置(17)。当进行终端间的通信时,连接源终端将SIP的邀请消息发送到通信管理装置(11)。通信管理装置(11)中除了SIP服务器(37)之外还具有:许可信息存储部(101),存储了连接许可信息,该连接许可信息中存储了连接应被许可的终端的组合;和许可处理部(103),参照连接许可信息来许可终端间的连接。当SIP服务器(37)从连接源终端取得邀请消息时,在许可处理部(103)许可了连接源和连接地的终端的连接的情况下,SIP服务器(37)将来自连接源终端的邀请消息提供到连接地终端。由此,提供一种能够提高将SIP适用于监视系统时的安全性的监视系统。

A communication management device (11) is connected to a plurality of terminals. The plurality of terminals are a monitoring device (15) and a user device (17). When performing communication between terminals, the connection source terminal transmits a SIP invite message to the communication management device (11). In addition to the SIP server (37), the communication management device (11) further includes: a permission information storage unit (101) storing connection permission information in which combinations of terminals to which connections should be permitted are stored; A processing unit (103) permits a connection between terminals by referring to the connection permission information. When the SIP server (37) obtains the invitation message from the connection source terminal, if the permission processing unit (103) permits the connection between the connection source and the connection destination terminal, the SIP server (37) transmits the invitation message from the connection source terminal Provided to the connection ground terminal. Thereby, the monitoring system which can improve the security at the time of applying SIP to a monitoring system is provided.

Description

监视系统及通信管理装置Surveillance system and communication management device

技术领域 technical field

本发明涉及一种监视系统,其中监视对象的终端和使用者一侧的终端互相连接并能够通信,上述监视对象的终端取得监视信息,上述使用者一侧的终端获得监视信息并使用。The present invention relates to a monitoring system in which a monitoring target terminal and a user side terminal are connected to each other and can communicate, the monitoring target terminal obtains monitoring information, and the user side terminal obtains and uses the monitoring information.

背景技术 Background technique

现有技术中,对店铺、工厂等监视对象设置监视照相机从而远程监视影像的监视系统已经实用化。监视影像发送到远程的监视中心,并发送到监视对象的所有者(主人)的办公室。监视影像的发送使用ISDN等普通公用线路(例如专利文献1)。Conventionally, a surveillance system has been put into practical use by installing surveillance cameras on surveillance objects such as stores and factories to remotely monitor images. The surveillance video is sent to a remote surveillance center and then to the office of the owner (master) of the surveillance object. The transmission of surveillance images uses general public lines such as ISDN (for example, Patent Document 1).

近年来,因ADSL、FTTH这样的宽带线路的普及,在因特网上实现收发监视系统中的监视影像等的需求增大。通过利用因特网有助于节约成本、提高系统灵活性。In recent years, due to the popularization of broadband lines such as ADSL and FTTH, there has been an increasing demand for realizing transmission and reception of surveillance images in surveillance systems and the like on the Internet. By utilizing the Internet, it helps to save costs and improve system flexibility.

作为在因特网上传送声音、影像的技术,称为SIP(Session InitiationProtocol:会话发起协议)的协议为人所知。SIP适用于IP电话、电视会议等。为了通过SIP连接两个地点,在SIP服务器中注册各地点的地址。这样一来,在注册了地址的地点之间可进行SIP的通信。A protocol called SIP (Session Initiation Protocol: Session Initiation Protocol) is known as a technology for transmitting audio and video on the Internet. SIP is suitable for IP telephony, video conferencing, etc. In order to connect two sites by SIP, the addresses of the respective sites are registered in the SIP server. In this way, SIP communication can be performed between sites with registered addresses.

但是如果将SIP适用于监视系统则要考虑安全性的问题。即,在从外部对监视对象的影像等进行监视的监视系统中要求较高的安全性。与之相对,在SIP中,通过注册地址可连接任意的地点。因此,从安全性的角度出发不希望直接将SIP适用于监视系统。However, if SIP is applied to the monitoring system, security issues should be considered. In other words, high security is required in a monitoring system that monitors images and the like of a monitoring target from the outside. In contrast, in SIP, an arbitrary location can be connected through a registered address. Therefore, it is not desirable to directly apply SIP to a surveillance system from a security point of view.

例如,假设监视对象是店铺,多个店铺的终端连接到监视中心。监视中心也连接到各店铺的店主的终端。此时,可连接到各店铺的终端的应仅限于对应的店主的终端。For example, it is assumed that the monitoring target is a store, and terminals of a plurality of stores are connected to the monitoring center. The monitoring center is also connected to the terminal of the owner of each store. In this case, the terminals that can be connected to the terminals of each store should be limited to the corresponding store owner's terminal.

但是在现有的SIP中,在SIP服务器中注册了地址的任意的终端之间可进行连接。作为基本的认证功能,SIP服务器可进行密码及ID的认证。但这仅限于终端和SIP服务器之间的认证。如果许可了终端和SIP服务器的连接,则无法限制经由SIP服务器的终端之间的组合。所以也无法限制店铺的终端和店主终端间的连接。因此,店主有可能获得自己之外的店铺的监视信息。However, in the conventional SIP, arbitrary terminals whose addresses are registered with the SIP server can be connected. As a basic authentication function, the SIP server can perform password and ID authentication. But this is limited to the authentication between the terminal and the SIP server. If the connection between the terminal and the SIP server is permitted, the combination of terminals via the SIP server cannot be restricted. Therefore, the connection between the terminal of the store and the terminal of the owner cannot be restricted. Therefore, the store owner may obtain monitoring information of stores other than his own.

专利文献1:日本特开2001-54102号公报Patent Document 1: Japanese Patent Laid-Open No. 2001-54102

发明内容 Contents of the invention

本发明在以上背景下产生。本发明的目的在于提供一种可提高将SIP适用于监视系统时的安全性的监视系统。The present invention was made under the above background. An object of the present invention is to provide a monitoring system capable of improving security when SIP is applied to the monitoring system.

本发明的一个方式是一种监视系统,该监视系统具有:对监视信息进行通信的多个终端;管理多个终端的通信的通信管理装置,多个终端分别设置在监视对象一侧,或利用从监视对象接收的监视信息的使用者一侧,其构成是,当多个终端的一个终端向其他终端请求连接时,该连接源终端将包括连接地终端的识别信息在内的SIP的邀请消息发送到通信管理装置,通信管理装置具有:SIP服务器;许可信息存储部,存储连接许可信息,该连接许可信息表示连接应被许可的终端的组合;许可处理部,参照连接许可信息判断是否许可终端间的连接,当SIP服务器从连接源终端取得邀请消息时,将邀请消息中包含的连接地终端的识别信息提供到许可处理部,当许可处理部许可了终端间的连接时,SIP服务器将来自连接源终端的邀请消息提供到连接地终端。One aspect of the present invention is a monitoring system including: a plurality of terminals for communicating monitoring information; a communication management device for managing the communication of the plurality of terminals, wherein the plurality of terminals are respectively installed on the side of the monitoring object, or used On the user side of the monitoring information received from the monitoring target, when one of the terminals requests a connection from another terminal, the connection source terminal sends a SIP invite message including the identification information of the terminal to be connected. Sent to the communication management device, the communication management device has: a SIP server; a permission information storage unit, which stores connection permission information, and the connection permission information represents a combination of terminals that should be allowed to connect; a permission processing unit, with reference to the connection permission information, judges whether to allow the terminal When the SIP server obtains an invitation message from the connection source terminal, it provides the identification information of the connection destination terminal included in the invitation message to the permission processing unit. When the permission processing unit approves the connection between the terminals, the SIP server sends the An INVITE message for the connection source terminal is provided to the connection destination terminal.

本发明的另一方式是一种通信管理装置,该通信管理装置管理对监视信息进行通信的多个终端的通信,通信管理装置具有:SIP服务器;许可信息存储部,存储连接许可信息,该连接许可信息表示连接应被许可的终端的组合;和许可处理部,参照连接许可信息判断是否许可终端间的连接,SIP服务器从多个终端中的一个取得包括对其他终端的识别信息在内的SIP的邀请消息时,许可处理部根据邀请消息中含有的连接地终端的识别信息判断是否许可终端间的连接,当许可处理部许可了连接时,SIP服务器将来自连接源终端的邀请消息提供到连接地终端。Another aspect of the present invention is a communication management device that manages communications of a plurality of terminals that communicate monitoring information. The communication management device includes: a SIP server; a permission information storage unit that stores connection permission information. The permission information indicates a combination of terminals whose connection should be permitted; and the permission processing unit refers to the connection permission information to judge whether to permit the connection between the terminals, and the SIP server obtains the SIP information including the identification information for other terminals from one of the plurality of terminals. When receiving an INVITE message, the permission processing unit judges whether to allow the connection between the terminals based on the identification information of the connected terminal contained in the INVITE message. When the permission processing unit approves the connection, the SIP server provides the INVITE message from the connection source terminal to the connection terminal. ground terminal.

如下所述,本发明存在其他方式。因此,本发明的公开意在提供本发明的部分方式,并不限制在此记述请求的发明范围。As described below, there are other aspects of the present invention. Therefore, the disclosure of the present invention intends to provide some aspects of the present invention, and does not limit the scope of the invention described and claimed here.

附图说明 Description of drawings

图1是表示本发明的监视系统的整体构成的图。FIG. 1 is a diagram showing the overall configuration of the monitoring system of the present invention.

图2是较具体的表示监视系统的构成的框图。FIG. 2 is a more specific block diagram showing the configuration of the monitoring system.

图3是表示本发明的监视系统中的主要构成的框图。Fig. 3 is a block diagram showing main components in the monitoring system of the present invention.

图4是表示许可信息存储部中存储的连接许可信息的表例的图。4 is a diagram showing an example of a table of connection permission information stored in a permission information storage unit.

图5是表示在监视系统中进行终端间的通信时的动作的图。FIG. 5 is a diagram showing operations when communication between terminals is performed in the monitoring system.

图6是表示监视装置作为连接源以进行终端间的通信的动作的图。FIG. 6 is a diagram showing the operation of the monitoring device as a connection source to perform communication between terminals.

图7是表示使用者装置作为连接源以进行终端间的通信的动作的图。FIG. 7 is a diagram showing an operation in which a user device serves as a connection source to perform communication between terminals.

标号说明Label description

1 监视系统1 Surveillance system

3 监视中心3 Surveillance Center

5 监视对象5 Surveillance objects

7 使用者地点7 User location

11 通信管理装置11 Communication management device

13 中心装置13 center unit

15 监视装置15 Surveillance device

17 使用者装置17 User Devices

21 中心终端间VPN21 Center-to-terminal VPN

23 SIP通信23 SIP communication

25 终端间VPN25 Inter-terminal VPN

33 HTTP服务器33 HTTP server

35 VPN服务器35 VPN servers

37 SIP服务器37 SIP server

41 账户管理服务器41 Account Management Server

43 数据库43 database

61 控制器61 controller

63 IP线路单元63 IP line units

65、83 路由器65, 83 Router

69 多线路适配器69 multi-line adapter

73 监视照相机73 Surveillance cameras

81 VPN终端装置(VTE)81 VPN Termination Equipment (VTE)

85 使用者PC85 User PCs

101 许可信息存储部101 Licensing Information Storage Department

103 许可处理部103 License Processing Department

具体实施方式 Detailed ways

以下详细说明本发明。但以下的详细说明及附图不用于限定本发明。The present invention will be described in detail below. However, the following detailed description and drawings are not intended to limit the present invention.

本发明是一种监视系统,具有:对监视信息进行通信的多个终端;管理多个终端的通信的通信管理装置,多个终端分别设置在监视对象一侧或利用从监视对象接收的监视信息的使用者一侧,其构成是,当多个终端的一个终端向其他终端请求连接时,该连接源终端将包括连接地终端的识别信息在内的SIP的邀请消息发送到通信管理装置,通信管理装置具有:SIP服务器;许可信息存储部,存储连接许可信息,该连接许可信息表示连接应被许可的终端的组合;和许可处理部,参照连接许可信息,判断是否许可终端间的连接,SIP服务器从连接源终端取得邀请消息时,将邀请消息中含有的连接地终端的识别信息提供到许可处理部,当许可处理部许可了终端间的连接时,SIP服务器将来自连接源终端的邀请消息提供到连接地终端。The present invention is a monitoring system comprising: a plurality of terminals for communicating monitoring information; a communication management device for managing the communication of the plurality of terminals, the plurality of terminals are respectively installed on the monitoring object side or utilize monitoring information received from the monitoring object On the user side of the system, when one of the plurality of terminals requests a connection from another terminal, the connection source terminal sends a SIP invitation message including the identification information of the terminal to be connected to the communication management device, and the communication The management device has: a SIP server; a permission information storage unit that stores connection permission information indicating a combination of terminals that should be allowed to connect; and a permission processing unit that refers to the connection permission information to determine whether to allow a connection between the terminals. When the server obtains the invitation message from the connection source terminal, it provides the identification information of the connection destination terminal contained in the invitation message to the permission processing unit. When the permission processing unit permits the connection between the terminals, the SIP server sends the invitation message from the connection source terminal Provided to the connection ground terminal.

如上所述,根据本发明,监视系统的多个终端连接到具有SIP服务器的通信管理装置。通信管理装置除了SIP服务器外还具有:许可信息存储部,存储连接许可信息,该连接许可信息表示连接应被许可的终端的组合;和许可处理部,参照连接许可信息判断是否许可终端间的连接。在SIP的信令中,邀请消息从连接源终端发送到SIP服务器。此时,在本发明中,许可处理部判断是否许可连接。当许可处理部许可了连接时,SIP服务器将来自连接源终端的邀请消息发送到连接地终端,SIP的信令成功。As described above, according to the present invention, a plurality of terminals of a monitoring system are connected to a communication management device having a SIP server. In addition to the SIP server, the communication management device further includes: a permission information storage unit storing connection permission information indicating a combination of terminals whose connection should be permitted; and a permission processing unit referring to the connection permission information to determine whether to permit the connection between the terminals . In SIP signaling, an INVITE message is sent from a connection source terminal to a SIP server. At this time, in the present invention, the permission processing unit judges whether or not to permit the connection. When the permission processing unit permits the connection, the SIP server transmits an INVITE message from the connection source terminal to the connection destination terminal, and the SIP signaling succeeds.

因此,在本发明中,预先存储连接应被许可的终端的组合的信息,在SIP信令时进行终端间的连接的许可。这样一来,并非终端和SIP服务器之间的简单认证,而是可进行介入了SIP服务器的终端间即P2P的许可,可恰当限制监视信息的使用者。这样一来,可提高适用监视系统SIP时的安全性。Therefore, in the present invention, information on combinations of terminals whose connections should be permitted is stored in advance, and connection between terminals is permitted at the time of SIP signaling. In this way, instead of simple authentication between the terminal and the SIP server, P2P permission can be performed between terminals intervening in the SIP server, and users of monitoring information can be appropriately restricted. By doing so, it is possible to improve the security when the monitoring system SIP is applied.

连接地终端从通信管理装置接收到邀请消息时,可将SIP的OK消息发送到通信管理装置,可向邀请消息及OK消息附加连接确立信息,其用于在SIP会话确立后,在连接源及连接地终端间确立不介入通信管理装置的终端间连接。When the connected terminal receives the invitation message from the communication management device, it can send a SIP OK message to the communication management device, and can add connection establishment information to the invitation message and the OK message, which is used to connect the source and the connection after the SIP session is established. An inter-terminal connection is established between connected terminals without intervention of the communication management device.

这样一来,在SIP会话确立后,可不借助通信管理装置而在终端间进行监视信息的通信。在本发明中,进行两个阶段的通信。第1阶段的通信是SIP,借助通信管理装置进行。第2阶段的通信是不借助通信管理装置的终端间连接。在SIP连接时进行信令,在信令中交换邀请消息和OK消息。本发明利用SIP的信令的消息,交换用于终端间连接的确立的连接确立信息。这样一来,可良好地利用SIP进行终端间连接。并且,可降低通信管理装置和终端的通信量,降低通信管理装置的负荷。In this way, after the establishment of the SIP session, the monitoring information can be communicated between the terminals without using the communication management device. In the present invention, two phases of communication are performed. The communication in the first phase is SIP, and it is carried out by means of a communication management device. The communication in the second stage is a connection between terminals without using a communication management device. Signaling is performed during a SIP connection, and INVITE messages and OK messages are exchanged in the signaling. The present invention uses SIP signaling messages to exchange connection establishment information for establishing a connection between terminals. In this way, it is possible to make good use of SIP for connection between terminals. In addition, the communication traffic between the communication management device and the terminal can be reduced, and the load on the communication management device can be reduced.

不介入通信管理装置的终端间连接可以是在终端间构筑VPN进行连接的终端间VPN。这样一来,通过向终端间通信(上述SIP连接后的第2阶段的通信)适用VPN(虚拟专用网络),可提高安全性。SIP的信号通信中的双向消息交换可适用于VPN连接确立所需的信息交换。The inter-terminal connection that does not involve the communication management device may be an inter-terminal VPN in which a VPN is constructed and connected between terminals. In this way, security can be improved by applying a VPN (Virtual Private Network) to communication between terminals (communication in the second stage after the above-mentioned SIP connection). The two-way message exchange in the signaling communication of SIP is applicable to the information exchange necessary for establishing a VPN connection.

邀请消息可含有连接源终端的IP地址和电子证书作为连接确立信息,OK消息可含有连接地终端的IP地址和电子证书作为连接确立信息。这样一来,可适当利用SIP交换VPN连接中使用的信息,在终端间进行安全的通信。The INVITE message may contain the IP address and electronic certificate of the connection source terminal as connection establishment information, and the OK message may contain the IP address and electronic certificate of the connection destination terminal as connection establishment information. In this way, the information used for VPN connection can be exchanged appropriately using SIP, and secure communication can be performed between terminals.

通信管理装置可设置在监视中心上,该监视中心利用与多个终端的通信对监视对象进行监视。这样一来,可利用通信管理装置良好地进行监视中心和终端的通信及终端间的通信。The communication management device may be installed in a monitoring center which monitors a monitoring target by communicating with a plurality of terminals. In this way, the communication between the monitoring center and the terminal and the communication between the terminals can be satisfactorily performed by the communication management device.

通信管理装置和多个终端的连接可在通信管理装置和多个终端间通过构筑了VPN的中心终端间VPN连接,SIP服务器可借助中心终端间VPN使多个终端和SIP消息通信。这样一来,SIP通信在中心终端间VPN上进行。以上论述了SIP会话确立后在终端间进行VPN连接。这里的中心终端间VPN是中心和各终端间的VPN。通过使用中心终端间VPN,可确保监视中心和各终端的通信的安全性,并且也可确保SIP通信的安全性。The connection between the communication management device and the multiple terminals can be through the central terminal-to-terminal VPN connection between the communication management device and the multiple terminals, and the SIP server can communicate the multiple terminals with SIP messages through the central terminal-to-center VPN. In this way, SIP communication is performed on the VPN between the center terminals. The foregoing has discussed the VPN connection between terminals after the SIP session is established. The center-terminal VPN here is a VPN between the center and each terminal. By using the VPN between the center terminals, the security of communication between the monitoring center and each terminal can be secured, and the security of SIP communication can also be secured.

监视信息可包括由监视对象拍摄的图像、由监视对象检测出的监视信号以及通过使用者一侧生成的控制信息中的至少一个。这样一来,可在终端间对监视信息进行通信。The monitoring information may include at least one of images captured by the monitoring target, monitoring signals detected by the monitoring target, and control information generated by the user. In this way, monitoring information can be communicated between terminals.

本发明的另一方式是一种通信管理装置,管理对监视信息进行通信的多个终端的通信,其中,通信管理装置具有:SIP服务器;许可信息存储部,存储连接许可信息,该连接许可信息表示连接应被许可的终端的组合;和许可处理部,参照连接许可信息,判断是否许可终端间的连接,SIP服务器从多个终端中的一个取得包括对其他终端的识别信息在内的SIP的邀请消息时,许可处理部根据邀请消息中含有的连接地终端的识别信息判断是否许可终端间的连接,当许可处理部许可了连接时,SIP服务器将来自连接源终端的邀请消息提供到连接地终端。该方式中也可适用上述各种构成。Another aspect of the present invention is a communication management device that manages communications of a plurality of terminals that communicate monitoring information, wherein the communication management device includes: a SIP server; a permission information storage unit that stores connection permission information, the connection permission information Indicates the combination of terminals whose connection should be permitted; and the permission processing unit refers to the connection permission information to determine whether to permit the connection between the terminals, and the SIP server obtains the SIP information including the identification information for other terminals from one of the plurality of terminals. In the case of an invitation message, the permission processing unit judges whether to allow the connection between the terminals based on the identification information of the connection destination terminal contained in the invitation message, and when the permission processing unit approves the connection, the SIP server provides the invitation message from the connection source terminal to the connection destination. terminal. Also in this form, the various configurations described above can be applied.

本发明不限于上述监视系统及通信管理装置的方式。本发明的其他方式例如是终端装置。并且,本发明可通过方法、程序、或记录了该程序的计算机可读取的记录介质的形式来实现。The present invention is not limited to the aspects of the above-mentioned monitoring system and communication management device. Another aspect of the present invention is, for example, a terminal device. Also, the present invention can be realized in the form of a method, a program, or a computer-readable recording medium in which the program is recorded.

如上所述,本发明可提高将SIP适用于监视系统时的安全性。As described above, the present invention can improve security when SIP is applied to a surveillance system.

以下参照附图说明本发明的实施方式的监视系统。A monitoring system according to an embodiment of the present invention will be described below with reference to the drawings.

图1表示本发明的监视系统的整体构成。如图所示,监视系统1中,在监视中心3、监视对象5及使用者地点7之间进行通信。其中,使用者是指监视系统1中的监视对象5的监视服务的使用者。在本实施方式的例子中,监视对象5是店铺,使用者地点7是店铺主人的办公室。FIG. 1 shows the overall configuration of the monitoring system of the present invention. As shown in the figure, in the monitoring system 1 , communication is performed among the monitoring center 3 , the monitoring object 5 and the user site 7 . Here, the user refers to the user of the monitoring service of the monitoring object 5 in the monitoring system 1 . In the example of this embodiment, the monitoring object 5 is a shop, and the user location 7 is the office of the shop owner.

监视中心3中具有通信管理装置11及多个中心装置13,它们连接为能够通信。通信管理装置11及多个中心装置13可配置在地理上远离的地点。多个中心装置13可分别配置在多个担当区域。并且,多个中心装置13可分担功能。例如,某中心装置13可作为处理警备相关的信号的管制中心装置发挥作用,其他中心装置13可作为主要处理监视影像的图像中心装置发挥作用。此外,在本发明的范围内,中心装置13也可以是一个。The monitoring center 3 has a communication management device 11 and a plurality of center devices 13, and these are connected so as to be communicable. The communication management device 11 and the plurality of central devices 13 can be arranged in geographically distant places. A plurality of center devices 13 can be respectively arranged in a plurality of responsible areas. Also, a plurality of central devices 13 can share functions. For example, a certain center device 13 may function as a control center device that processes signals related to security, and another center device 13 may function as an image center device that mainly processes surveillance images. In addition, within the scope of the present invention, there may be only one central device 13 .

监视对象5及使用者地点7中分别设置监视装置15及使用者装置17。监视装置15及使用者装置17相当于本发明的终端。监视装置15将监视信息发送到中心装置13及使用者装置17。监视信息例如是监视照相机的图像,并且是由监视对象5检测出的监视信号。监视信号例如是表示发生异常的警备信号,根据来自设置在监视对象5上的传感器的检测信号生成警备信号,或者在操作警报按钮(开关)时生成。并且,使用者装置17向监视装置15发送控制信号或声音信号。这种从使用者装置17到监视装置15的信号也包含在监视信息中。A monitoring device 15 and a user device 17 are installed in the monitoring object 5 and the user site 7, respectively. The monitoring device 15 and the user device 17 correspond to the terminal of the present invention. The monitoring device 15 transmits monitoring information to the center device 13 and the user device 17 . The surveillance information is, for example, an image of a surveillance camera, and is a surveillance signal detected by the surveillance target 5 . The monitoring signal is, for example, a warning signal indicating occurrence of an abnormality, and is generated based on a detection signal from a sensor provided on the monitored object 5 or when an alarm button (switch) is operated. Furthermore, the user device 17 transmits a control signal or an audio signal to the monitoring device 15 . Such a signal from the user device 17 to the monitoring device 15 is also included in the monitoring information.

图1中示出了一个监视对象5及一个使用者地点7。但实际上,监视中心3与多个监视对象5及多个使用者地点7通信。因此,通信管理装置11也与多个监视装置15及多个使用者装置17通信。各监视装置15与建立关联的使用者装置17(店铺主人的终端)通信。FIG. 1 shows a surveillance object 5 and a user location 7 . However, in reality, the monitoring center 3 communicates with a plurality of monitoring objects 5 and a plurality of user sites 7 . Therefore, the communication management device 11 also communicates with a plurality of monitoring devices 15 and a plurality of user devices 17 . Each monitoring device 15 communicates with an associated user device 17 (terminal of a store owner).

根据图1的监视系统1,例如监视装置15通过传感器信号等检测异常。此时,作为监视信息的警备信号与监视对象5的影像一起被发送到监视中心3。在监视中心3,操作者通过中心装置13的监视器确认警备信号和影像,向警备人员发出必要的指示。接受到指示的警备人员快速到达至监视对象5,处理异常。According to the monitoring system 1 of FIG. 1, for example, the monitoring device 15 detects an abnormality by a sensor signal or the like. At this time, a warning signal as monitoring information is transmitted to the monitoring center 3 together with the video of the monitoring object 5 . In the monitoring center 3, the operator confirms the warning signal and video through the monitor of the center device 13, and issues necessary instructions to the guards. The security personnel who received the instructions quickly arrived at the surveillance object 5 to deal with the abnormality.

并且,例如监视装置15定期地或根据其他设定将监视对象5的影像等发送到使用者装置17。例如,通过传感器检测出来客时,影像等被发送到使用者装置17。并且,也存在使用者装置17要求发送影像等的情况。主人可根据影像等掌握店铺的情况。并且,主人能够从使用者装置17向监视装置15发送声音等,将必要事项指示给店员。In addition, for example, the monitoring device 15 sends the video of the monitoring object 5 to the user device 17 periodically or according to other settings. For example, when a sensor detects a visitor, an image or the like is sent to the user device 17 . In addition, there may be a case where the user device 17 requests transmission of a video or the like. The owner can grasp the situation of the store based on images and the like. In addition, the owner can send a voice or the like from the user device 17 to the monitoring device 15 to instruct the clerk about necessary matters.

接着说明监视系统1的通信方式。通信管理装置11、监视装置15及使用者装置17连接到因特网。Next, the communication method of the monitoring system 1 will be described. The communication management device 11, the monitoring device 15, and the user device 17 are connected to the Internet.

进一步,通信管理装置11在因特网上通过中心终端间VPN(虚拟专用网络)21与监视装置15及使用者装置17连接。为了构筑中心终端间VPN21,使通信管理装置11具有VPN服务器功能,使监视装置15及使用者装置17具有VPN客户端功能。在VPN中,构筑VPN隧道,进行密码通信,实现较高的安全性。Furthermore, the communication management device 11 is connected to the monitoring device 15 and the user device 17 through a VPN (Virtual Private Network) 21 between center terminals on the Internet. In order to construct the center-to-terminal VPN 21, the communication management device 11 has a VPN server function, and the monitoring device 15 and the user device 17 have a VPN client function. In VPN, a VPN tunnel is constructed and encrypted communication is performed to achieve high security.

并且,监视装置15和使用者装置17借助通信管理装置11进行SIP通信23。SIP通信23借助上述中心终端间VPN21进行。通信管理装置11具有SIP服务器功能。Furthermore, the monitoring device 15 and the user device 17 perform SIP communication 23 via the communication management device 11 . The SIP communication 23 is performed via the above-mentioned inter-center VPN 21 . The communication management device 11 has a SIP server function.

并且,监视装置15和使用者装置17不借助通信管理装置11而是直接通过终端间VPN25连接。为构筑该终端间VPN25,使用者装置17具有VPN服务器功能,使监视装置15具有VPN客户端功能。Furthermore, the monitoring device 15 and the user device 17 are directly connected through the inter-terminal VPN 25 without passing through the communication management device 11 . In order to construct this inter-terminal VPN 25, the user device 17 has a VPN server function, and the monitoring device 15 has a VPN client function.

其中,中心终端间VPN21总是连接而构筑VPN隧道,用于中心装置13和监视装置15及使用者装置17之间的通信。而终端间VPN25仅在必要时构筑。Among them, the center terminal VPN 21 is always connected to construct a VPN tunnel for communication between the center device 13 , the monitoring device 15 and the user device 17 . On the other hand, the inter-terminal VPN 25 is constructed only when necessary.

说明使用终端间VPN25的理由。在监视系统1中进行影像等大容量的数据的通信。如果中心终端间VPN21用于所有通信,则通信管理装置11的负荷变得过大。因此,由终端间VPN25进行监视装置15和使用者装置17的通信,从而可确保安全性的同时减轻通信管理装置11的负荷。Explain the reasons for using the inter-terminal VPN25. Communication of large-capacity data such as images is performed in the monitoring system 1 . If the VPN 21 between center terminals is used for all communications, the load on the communication management device 11 will become excessive. Therefore, the communication between the monitoring device 15 and the user device 17 is performed by the inter-terminal VPN 25, thereby reducing the load on the communication management device 11 while ensuring security.

并且,本实施方式中的SIP通信23的作用是和普通的IP电话等不同的特别的作用。即,本实施方式中,将SIP的信令作为VPN连接前的准备的处理来定位。具体而言,确立SIP23的会话时,进行信息通知。在该信息通知中进行双向通信,交换邀请消息和OK消息。另一方面,为了确立VPN连接,需要交换信息。在本实施方式中,交换IP地址及电子证书。电子证书用于验证电子签名等的正当性,使用由可靠的第三方机构发行的证书。因此,SIP通信23的信令作为用于确立VPN连接的信息交换单元使用。In addition, the role of the SIP communication 23 in this embodiment is a special role different from that of an ordinary IP telephone or the like. That is, in this embodiment, SIP signaling is positioned as a process of preparation before VPN connection. Specifically, when a SIP23 session is established, information notification is performed. Two-way communication is carried out in this information notification, and INVITE messages and OK messages are exchanged. On the other hand, in order to establish a VPN connection, information needs to be exchanged. In this embodiment, IP addresses and electronic certificates are exchanged. Electronic certificates are used to verify the legitimacy of electronic signatures, etc., and certificates issued by reliable third-party organizations are used. Therefore, the signaling of the SIP communication 23 is used as an information exchange unit for establishing a VPN connection.

以上说明了监视系统1的整体构成。如上所述,在本实施方式中,使用两种VPN。一种连接通信管理装置11和终端(监视装置15或使用者装置17),另一种连接终端之间(监视装置15和使用者装置17)。因此,在图1中,为了区别这两个VPN,使用中心终端间VPN21和终端间VPN25这两个用语。但也可简化使用VPN21、VPN25这两个用语。The overall configuration of the monitoring system 1 has been described above. As described above, in this embodiment, two types of VPNs are used. One connects the communication management device 11 and a terminal (monitoring device 15 or user device 17), and the other connects terminals (monitoring device 15 and user device 17). Therefore, in FIG. 1 , in order to distinguish these two VPNs, two terms, the center inter-terminal VPN 21 and the inter-terminal VPN 25 , are used. However, the terms VPN21 and VPN25 can also be simplified and used.

接着参照图2具体说明监视系统1的构成。通信管理装置11具有:防火墙31、HTTP服务器33、VPN服务器35、SIP服务器37、STUN服务器39、账户管理服务器41、数据库43及日志服务器45。Next, the configuration of the monitoring system 1 will be specifically described with reference to FIG. 2 . The communication management device 11 has a firewall 31 , an HTTP server 33 , a VPN server 35 , a SIP server 37 , a STUN server 39 , an account management server 41 , a database 43 and a log server 45 .

防火墙31用于屏蔽在通信管理装置11和监视装置15及使用者装置17之间使用的通信数据以外的数据。HTTP服务器33用于因特网连接。VPN服务器35是进行构筑VPN隧道的认证及加密的服务器。The firewall 31 blocks data other than the communication data used between the communication management device 11 and the monitoring device 15 and the user device 17 . HTTP server 33 is used for Internet connection. The VPN server 35 is a server that performs authentication and encryption for constructing a VPN tunnel.

VPN服务器35用于实现中心终端间VPN21,在通信管理装置11和监视装置15之间构筑VPN,以及在通信管理装置11和使用者装置17之间构筑VPN。来自监视装置15的信号通过VPN服务器35解密,发送到中心装置13。并且,来自中心装置13的信号通过VPN服务器35加密,发送到监视装置15。并且,在通信管理装置11向监视装置15发送信号时,也通过VPN服务器35进行加密。在通信管理装置11和使用者装置17的通信中,VPN服务器35也同样进行加密及解密。The VPN server 35 is used to realize the VPN 21 between the center terminals, to establish a VPN between the communication management device 11 and the monitoring device 15 , and to establish a VPN between the communication management device 11 and the user device 17 . The signal from the monitoring device 15 is decrypted by the VPN server 35 and sent to the center device 13 . And, the signal from the center device 13 is encrypted by the VPN server 35 and sent to the monitoring device 15 . Furthermore, when the communication management device 11 transmits a signal to the monitoring device 15, encryption is also performed by the VPN server 35 . In the communication between the communication management device 11 and the user device 17, the VPN server 35 similarly performs encryption and decryption.

SIP服务器37根据SIP协议进行信令的处理,连接监视装置15和使用者装置17。在使用者装置17要求连接到监视装置15时,或监视装置15要求连接到使用者装置17时,SIP服务器37起到SIP的连接控制的作用。The SIP server 37 performs signaling processing according to the SIP protocol, and connects the monitoring device 15 and the user device 17 . When the user device 17 requests to connect to the monitoring device 15, or when the monitoring device 15 requests to connect to the user device 17, the SIP server 37 plays a role of SIP connection control.

在SIP的信令中,交换消息。具体而言,交换INVITE(邀请)消息和OK消息。利用该消息交换,如上所述,为确立VPN连接而交换IP地址及电子证书。In SIP signaling, messages are exchanged. Specifically, INVITE (invitation) messages and OK messages are exchanged. By this message exchange, IP addresses and electronic certificates are exchanged to establish a VPN connection as described above.

STUN服务器39为对应监视装置15及使用者装置17的路由器的NAT功能而提供STUN功能。The STUN server 39 provides a STUN function corresponding to the NAT function of the router of the monitoring device 15 and the user device 17 .

账户管理服务器41是管理认证等各种信息的服务器。被管理的信息存储到数据库43中。被管理的信息包括IP线路的账户、用于VPN连接(隧道构筑)的电子证书、密钥对的信息。并且在本实施方式中,在SIP的信令过程中,对终端间的连接进行认证及许可。用于该处理的信息也由数据库43保存,用于账户管理服务器41。此外,对终端间的连接的认证及许可可由SIP服务器自身进行,这种情况下,本发明的许可处理部及许可信息存储部设置在SIP服务器上。The account management server 41 is a server that manages various information such as authentication. Managed information is stored in the database 43 . The managed information includes IP line accounts, electronic certificates for VPN connection (tunnel construction), and key pair information. And in this embodiment, in the signaling process of SIP, the connection between terminals is authenticated and permitted. Information for this processing is also held by the database 43 for the account management server 41 . In addition, authentication and permission of connection between terminals may be performed by the SIP server itself. In this case, the permission processing unit and the permission information storage unit of the present invention are provided on the SIP server.

日志服务器45是保存通过监视装置15生成的日志的服务器。The log server 45 is a server that stores logs generated by the monitoring device 15 .

中心装置13具有监视台51和线路连接装置53。监视台51借助线路连接装置53连接到通信管理装置11。例如,当中心装置13是图像中心时,监视影像被提供到监视台51,由监视台51管理。并且,当中心装置13是管制中心时,警备相关的信息被提供到监视台51。监视影像也良好的显示于管制中心的监视器上。监视影像等也可在中心装置之间进行通信。The center device 13 has a monitoring station 51 and a line connection device 53 . The monitoring station 51 is connected to the communication management device 11 via a line connection device 53 . For example, when the center device 13 is an image center, surveillance images are provided to the surveillance station 51 and managed by the surveillance station 51 . And, when the center device 13 is a control center, information related to guarding is provided to the monitoring station 51 . Surveillance images are also well displayed on the monitors of the control center. Surveillance images, etc. can also be communicated between center devices.

接着说明监视装置15。监视装置15包括:控制器61、IP线路单元63、路由器65、外围设备67、多线路适配器69及监视对象PC(个人计算机)71。Next, the monitoring device 15 will be described. The monitoring device 15 includes a controller 61 , an IP line unit 63 , a router 65 , peripheral devices 67 , a multiline adapter 69 , and a PC (personal computer) 71 to be monitored.

控制器61由计算机构成,与外围设备67协作而实现监视功能。控制器61借助IP线路单元63与监视中心3连接。并且,控制器61也借助IP线路单元63与使用者装置17连接。The controller 61 is constituted by a computer, and realizes a monitoring function in cooperation with the peripheral device 67 . The controller 61 is connected to the monitoring center 3 via an IP line unit 63 . Furthermore, the controller 61 is also connected to the user device 17 via the IP line unit 63 .

在图2中,作为外围设备67示例了监视照相机73、传感器75及警报按钮77。控制器61对监视影像实施图像识别处理来检测异常。并且,控制器61通过从传感器75输入的检测信号来检测异常。当警报按钮77被按下时也检测出异常。其他外围设备也可用于检测异常。当发生异常时,控制器61与中心装置13通信,发送警备信号和图像信号。具有监视照相机73的同时还具有麦克风,也发送声音信号。这样一来,控制器61实现监视对象5的警备功能。In FIG. 2 , a surveillance camera 73 , a sensor 75 , and an alarm button 77 are exemplified as peripheral devices 67 . The controller 61 performs image recognition processing on the surveillance video to detect abnormalities. And, the controller 61 detects an abnormality by a detection signal input from the sensor 75 . Abnormalities are also detected when the alarm button 77 is pressed. Other peripherals can also be used to detect anomalies. When an abnormality occurs, the controller 61 communicates with the central device 13 to send a warning signal and an image signal. Along with the monitoring camera 73, it also has a microphone, which also transmits audio signals. In this way, the controller 61 realizes the guard function of the monitored object 5 .

并且,在中心装置13要求时也会发送监视影像及声音。进一步,监视影像及声音也发送到使用者装置17。例如定期进行、或者也可根据其他设定来进行向使用者装置17的发送。例如,通过传感器75检测到来客时,影像等发送到使用者装置17。并且,在使用者装置17要求时,监视装置15也发送影像等。In addition, when the center device 13 requests, surveillance video and audio are also sent. Furthermore, surveillance video and audio are also transmitted to the user device 17 . For example, the transmission to the user device 17 may be performed periodically or according to other settings. For example, when a visitor is detected by the sensor 75 , an image or the like is transmitted to the user device 17 . In addition, the monitoring device 15 also transmits images and the like when requested by the user device 17 .

IP线路单元63构筑用于控制器61与通信管理装置11通信的VPN隧道。并且,构筑用于控制器61与使用者装置17通信的VPN隧道。前者对应于中心终端间VPN21,后者对应于终端间VPN25。在这些连接中,IP线路单元63实现VPN客户端的功能。The IP line unit 63 constructs a VPN tunnel for the controller 61 to communicate with the communication management device 11 . Furthermore, a VPN tunnel for communication between the controller 61 and the user device 17 is constructed. The former corresponds to the center inter-terminal VPN 21 , and the latter corresponds to the inter-terminal VPN 25 . In these connections, the IP line unit 63 implements the function of a VPN client.

在图2中,IP线路单元63作为控制器61的内部构成被示出。这表现了物理配置。作为通信构成,IP线路单元63配置在控制器61和路由器65之间。并且,IP线路单元63与控制器61通过以太网(注册商标)LAN连接。路由器65是宽带线路用的路由器。In FIG. 2 , an IP line unit 63 is shown as an internal configuration of the controller 61 . This represents the physical configuration. As a communication configuration, an IP line unit 63 is arranged between the controller 61 and the router 65 . Furthermore, the IP line unit 63 and the controller 61 are connected via an Ethernet (registered trademark) LAN. The router 65 is a router for broadband lines.

多线路适配器69借助移动电话网与中心装置13连接。多线路适配器69用于在宽带线路不通时发送警备信号。警备信号从控制器61借助IP线路单元63发送到多线路适配器69,从多线路适配器69发送到中心装置13。The multiline adapter 69 is connected to the central device 13 via the mobile telephone network. The multi-line adapter 69 is used to send an alert signal when the broadband line is blocked. An alert signal is sent from the controller 61 to the multi-line adapter 69 via the IP line unit 63 , and from the multi-line adapter 69 to the center device 13 .

监视对象PC71是设置在监视对象5上的PC。在本实施方式的例子中,监视对象5是店铺。因此,监视对象PC71可以是店铺用的PC。The monitoring target PC 71 is a PC installed on the monitoring target 5 . In the example of this embodiment, the monitoring object 5 is a store. Therefore, the PC 71 to be monitored may be a PC for a shop.

接着说明使用者装置17。使用者装置17由VPN终端装置(以下称VTE)81、路由器81及使用者PC(个人计算机)85构成。Next, the user device 17 will be described. The user device 17 is composed of a VPN terminal device (hereinafter referred to as VTE) 81 , a router 81 , and a user PC (personal computer) 85 .

VTE81是用于宽带连接的线路终端装置。并且,VTE81构筑通信管理装置11的VPN服务器35和VPN隧道,并且构筑监视装置15的IP线路单元63和VPN隧道。在前者中,VTE81作为VPN客户端作用,在后者中,VTE81作为VPN服务器作用。路由器83是宽带线路用的路由器。The VTE81 is a line termination device for broadband connections. Furthermore, the VTE 81 constructs the VPN server 35 and the VPN tunnel of the communication management device 11 , and constructs the IP line unit 63 and the VPN tunnel of the monitoring device 15 . In the former, VTE81 acts as a VPN client, and in the latter, VTE81 acts as a VPN server. The router 83 is a router for broadband lines.

VTE81与使用者PC85连接。VTE81将从监视装置15的控制器61接收的影像、声音及控制信号转发到使用者PC85。并且,VTE81将从使用者PC85接收的声音及控制信号转发到控制器61。VTE81 is connected to user PC85. The VTE 81 transfers images, sounds, and control signals received from the controller 61 of the monitoring device 15 to the user PC 85 . And VTE81 transfers the voice and control signal received from the user's PC85 to the controller 61.

在本实施方式中,使用者地点7是店铺主人的办公室等。因此,使用者PC85可以是店铺的主人的PC。使用者PC85用于主人察看监视对象5的监视影像。为提供该功能,使用者PC85中安装应用程序,通过与控制器61进行通信可显示及切换监视对象5的监视影像。In the present embodiment, the user location 7 is an office of a store owner or the like. Therefore, the user PC 85 may be the owner's PC of the store. The user PC 85 is used by the owner to view the surveillance image of the surveillance object 5 . In order to provide this function, an application program is installed in the user's PC 85 , and the monitoring image of the monitoring object 5 can be displayed and switched by communicating with the controller 61 .

在本实施方式中,使用者装置17是固定的。但是使用者装置17的功能也可组装到移动终端等中,从而可以移动。In this embodiment, the user device 17 is stationary. However, the functions of the user device 17 can also be incorporated into a mobile terminal or the like so that it can be moved.

以上说明了监视系统1的整体构成。接着说明本发明的特征性构成。The overall configuration of the monitoring system 1 has been described above. Next, the characteristic configuration of the present invention will be described.

图3表示图1及图2所示的监视系统1的一部分,是本发明的主要部分。在图3中,对在图1及图2中说明的要素标以同样的标号。Fig. 3 shows a part of the monitoring system 1 shown in Figs. 1 and 2, and is a main part of the present invention. In FIG. 3 , the elements described in FIG. 1 and FIG. 2 are denoted by the same reference numerals.

如图3所示,通信管理装置11中除了VPN服务器35和SIP服务器37外,具有许可信息存储部101及许可处理部103。许可信息存储部101存储连接许可信息,该连接许可信息表示连接待被许可的终端(监视装置15及使用者装置17)的组合。并且,许可处理部103参照连接许可信息,判断是否许可终端间的连接。许可信息存储部101及许可处理部103分别通过图2的数据库43及账户管理服务器41实现。As shown in FIG. 3 , the communication management device 11 includes a license information storage unit 101 and a license processing unit 103 in addition to the VPN server 35 and the SIP server 37 . The permission information storage unit 101 stores connection permission information indicating a combination of terminals (monitoring device 15 and user device 17 ) to be allowed to connect. Then, the permission processing unit 103 refers to the connection permission information, and judges whether or not to permit the connection between the terminals. The license information storage unit 101 and the license processing unit 103 are respectively realized by the database 43 and the account management server 41 in FIG. 2 .

图4表示许可信息存储部101中应存储的连接许可信息的例子。在该例中,连接许可信息是表示终端ID的组合的表。该表使各使用者(店铺的主人)、监视装置ID(监视装置15的ID)以及使用者装置ID(使用者装置17的ID)建立对应。监视装置ID及使用者装置ID是能够确定监视装置15及使用者装置17的任意的信息。在后述例子中,监视装置ID是IP线路单元63的ID,使用者装置ID是VTE81的ID。FIG. 4 shows an example of connection permission information to be stored in the permission information storage unit 101 . In this example, the connection permission information is a table showing combinations of terminal IDs. This table associates each user (store owner), monitoring device ID (ID of monitoring device 15 ), and user device ID (ID of user device 17 ) with each other. The monitoring device ID and the user device ID are arbitrary information that can identify the monitoring device 15 and the user device 17 . In the example described later, the monitoring device ID is the ID of the IP line unit 63, and the user device ID is the ID of the VTE81.

存在一个主人拥有多个店铺的情况。此时,一个监视装置15与多个使用者装置17组合。在图4的例子中,使用者C具有两个店铺,两个监视装置15(C01、C02)与使用者装置17(C11)建立对应。此外,一个主人使用多个使用者装置17时,一个监视装置15与多个使用者装置17对应即可。There are cases where one owner owns a plurality of stores. In this case, one monitoring device 15 is combined with a plurality of user devices 17 . In the example of FIG. 4, the user C has two stores, and two monitoring devices 15 (C01, C02) are associated with the user device 17 (C11). In addition, when one owner uses a plurality of user devices 17 , one monitoring device 15 may correspond to a plurality of user devices 17 .

返回到图3,在监视装置15中,IP线路单元63具有SIP处理部111、VPN处理部113及存储部115。SIP处理部111及VPN处理部113分别进行和SIP及VPN相关的处理。存储部115存储通过IP线路单元63处理的各种信息。特别是在本发明中,存储部115存储IP线路单元63的IP地址和电子证书。这些信息相当于本发明的连接确立信息,为了VPN连接而提供到连接对象。并且,存储部115存储IP线路单元ID(IP线路单元63的ID),该IP线路单元ID作为监视对象5的ID使用。Returning to FIG. 3 , in the monitoring device 15 , the IP line unit 63 has a SIP processing unit 111 , a VPN processing unit 113 , and a storage unit 115 . The SIP processing unit 111 and the VPN processing unit 113 perform processing related to SIP and VPN, respectively. The storage unit 115 stores various information processed by the IP line unit 63 . Particularly in the present invention, the storage section 115 stores the IP address and the electronic certificate of the IP line unit 63 . These pieces of information correspond to the connection establishment information of the present invention, and are provided to a connection partner for a VPN connection. Furthermore, the storage unit 115 stores the IP line unit ID (ID of the IP line unit 63 ) used as the ID of the monitoring object 5 .

如图3所示,使用者装置17的VTE81也具有SIP处理部121、VPN处理部123及存储部125。存储部125存储VTE81的IP地址和电子证书。并且,存储部125存储VTE-ID(VTE81的ID)。As shown in FIG. 3 , the VTE 81 of the user device 17 also has a SIP processing unit 121 , a VPN processing unit 123 , and a storage unit 125 . Storage unit 125 stores the IP address and electronic certificate of VTE 81 . Furthermore, the storage unit 125 stores VTE-ID (ID of the VTE 81 ).

接着说明本实施方式的动作。在此说明构筑终端间VPN25时的动作、即进行监视装置15和使用者装置17之间的VPN连接时的动作。Next, the operation of this embodiment will be described. Here, the operation at the time of constructing the inter-terminal VPN 25 , that is, the operation at the time of performing the VPN connection between the monitoring device 15 and the user device 17 will be described.

首先说明动作概要。如上所述,在通信管理装置11和监视装置15之间总是构筑中心终端间VPN21。通信管理装置11和使用者装置17之间也总是构筑中心终端间VPN21。与这些中心终端间VPN21不同,通过以下动作在监视装置15和使用者装置17之间直接构筑终端间VPN25。First, an outline of the operation will be described. As mentioned above, between the communication management apparatus 11 and the monitoring apparatus 15, VPN21 between center terminals is always constructed. Between the communication management device 11 and the user device 17, a center-to-terminal VPN 21 is always established. Unlike these center-to-terminal VPNs 21, an inter-terminal VPN 25 is directly constructed between the monitoring device 15 and the user device 17 by the following operations.

连接终端间VPN25时进行信息的交换。在本实施方式中,在监视装置15和使用者装置17之间交换IP地址和电子证书。作为该信息交换的单元,本实施方式着眼于SIP。在SIP的信息通知中,在终端间交换消息。在该SIP消息中加入上述IP地址及电子证书。这样一来,通过SIP的信息通知可进行用于准备构筑终端间VPN25的信息交换。Information is exchanged when connecting to the VPN25 between terminals. In this embodiment, IP addresses and electronic certificates are exchanged between the monitoring device 15 and the user device 17 . This embodiment focuses on SIP as the means for this information exchange. In the information notification of SIP, messages are exchanged between terminals. Add the aforementioned IP address and electronic certificate to the SIP message. In this way, information exchange for preparing to construct the inter-terminal VPN 25 can be performed by the information notification of the SIP.

在SIP的基本功能中,在SIP服务器37中所注册的任意的地址之间确立SIP的连接。在这种情况下,存在监视装置15与无关的使用者装置17连接的可能性,在安全性上不佳。考虑到这一点,在本实施方式中,如下所述进行信令。以下将监视装置15及使用者装置17中的一个作为SIP的连接源终端,将另一个作为SIP的连接地终端。并且,SIP的消息在中心终端间VPN21上发送。In the basic function of SIP, a SIP connection is established between arbitrary addresses registered in the SIP server 37 . In this case, there is a possibility that the monitoring device 15 is connected to an unrelated user device 17, which is not good in terms of safety. In consideration of this point, in this embodiment, signaling is performed as follows. Hereinafter, one of the monitoring device 15 and the user device 17 will be referred to as a SIP connection source terminal, and the other will be referred to as a SIP connection destination terminal. And, the message of SIP is transmitted through VPN21 between center terminals.

参照图5,首先,连接源终端将INVITE消息(具体而言是SIPINVITE消息,以下相同)发送到SIP服务器37(S1)。INVITE消息中附加有连接源终端的ID及连接地终端的ID、连接源终端的IP地址及电子证书。Referring to FIG. 5 , first, the connection source terminal transmits an INVITE message (specifically, a SIP INVITE message, the same applies hereinafter) to the SIP server 37 ( S1 ). The ID of the connection source terminal, the ID of the connection destination terminal, the IP address of the connection source terminal, and the electronic certificate are attached to the INVITE message.

SIP服务器37接收到INVITE消息后,将连接源终端的ID和连接地终端的ID提供到许可处理部103,询问许可处理部103是否可连接该连接源终端和连接地终端(S3)。许可处理部103参照许可信息存储部101的连接许可信息,判断是否许可连接的(S5)。如果连接源终端和连接地终端的组合注册在许可信息存储部101中,则许可连接。After receiving the INVITE message, the SIP server 37 provides the ID of the connection source terminal and the ID of the connection destination terminal to the license processing unit 103, and asks the permission processing unit 103 whether the connection source terminal and the connection destination terminal can be connected (S3). The permission processing unit 103 refers to the connection permission information of the permission information storage unit 101, and judges whether or not the connection is permitted (S5). If the combination of the connection source terminal and the connection destination terminal is registered in the permission information storage unit 101, the connection is permitted.

SIP服务器37从许可处理部103接收许可结果(S7)。如果由许可处理部103许可了连接,则SIP服务器37将INVITE消息发送到连接地终端(S9)。该INVITE消息包括连接源终端的IP地址及电子证书。The SIP server 37 receives the license result from the license processing unit 103 (S7). When the connection is permitted by the permission processing unit 103, the SIP server 37 transmits an INVITE message to the connection destination terminal (S9). The INVITE message includes the IP address of the connection source terminal and the electronic certificate.

连接地终端接收到INVITE消息后,向SIP服务器37发送OK消息(具体而言是SIP 2000K消息,以下相同)(S11)。OK消息附加有连接地终端的IP地址和电子证书。该OK消息经由SIP服务器37发送到连接源终端(S13)。由此,通过SIP的信息通知交换了IP地址及电子证书。并且,在终端间构筑VPN时,通过连接请求中含有的电子证书和之前交换的电子证书进行认证,构筑终端间VPN25(S15)。After receiving the INVITE message, the connected terminal sends an OK message (specifically, a SIP 2000K message, the same below) to the SIP server 37 (S11). The OK message is attached with the IP address and electronic certificate of the connecting terminal. This OK message is sent to the connection source terminal via the SIP server 37 (S13). Thereby, the IP address and the electronic certificate are exchanged by the information notification of the SIP. Then, when establishing a VPN between terminals, authentication is performed by the electronic certificate included in the connection request and the previously exchanged electronic certificate, and the inter-terminal VPN 25 is established (S15).

如上所述,在本实施方式中,由SIP服务器37接收INVITE消息后进行许可终端的组合的处理。如果连接未被许可,则INVITE消息不会被发送到连接地终端,也不会进行之后的SIP处理和VPN处理。仅在监视装置15和使用者装置17的组合适当时,连接被许可,INVITE消息被发送到连接地终端,进行之后的SIP处理,最终能够进行VPN连接。As described above, in the present embodiment, the SIP server 37 receives the INVITE message and performs the process of permitting the combination of terminals. If the connection is not permitted, the INVITE message will not be sent to the connected terminal, nor will the subsequent SIP processing and VPN processing be performed. Only when the combination of the monitoring device 15 and the user device 17 is appropriate, the connection is permitted, an INVITE message is sent to the connection destination terminal, the subsequent SIP processing is performed, and finally the VPN connection can be performed.

接着参照图6及图7详细说明监视系统1的动作。其中,首先说明监视装置15是连接源终端的情况,接着说明使用者装置17是连接源的情况。Next, the operation of the monitoring system 1 will be described in detail with reference to FIGS. 6 and 7 . Among them, first, the case where the monitoring device 15 is the connection source terminal will be described, and then the case where the user device 17 is the connection source will be described.

在图6的时间图中,控制器61及IP线路单元63是监视装置15的构成,SIP服务器37及许可信息存储部101(账户管理服务器41)是通信管理装置11的构成,VTE81及使用者PC85是使用者装置17的构成。In the time chart of FIG. 6 , the controller 61 and the IP line unit 63 constitute the monitoring device 15, the SIP server 37 and the license information storage unit 101 (account management server 41) constitute the communication management device 11, and the VTE 81 and the user The PC 85 is a configuration of the user device 17 .

控制器61将包括VTE-ID(VTE81的ID)的连接指示(P2P连接指示)发送到IP线路单元63(S101)。这里,VTE-ID用作连接地终端ID。The controller 61 transmits a connection instruction (P2P connection instruction) including the VTE-ID (ID of the VTE 81 ) to the IP line unit 63 ( S101 ). Here, VTE-ID is used as the terminal ID of the connection.

IP线路单元63从存储部115读出IP线路单元IP地址(IP线路单元63的IP地址)及IP线路单元个别证书。IP线路单元个别证书是分配给各IP线路的电子证书。并且,IP线路单元63从存储部115读出作为连接源终端ID的IP线路单元ID(IP线路单元63的ID)。并且,IP线路单元63将该信息附加到INVITE消息,然后将INVITE消息发送到SIP服务器37(S103)。具体而言,INVITE消息包括IP线路单元IP地址、IP线路单元ID、VTE-ID及IP线路单元个别证书。The IP line unit 63 reads the IP line unit IP address (the IP address of the IP line unit 63 ) and the IP line unit individual certificate from the storage unit 115 . The IP line unit individual certificate is an electronic certificate assigned to each IP line. Then, the IP line unit 63 reads out the IP line unit ID (ID of the IP line unit 63 ) which is the connection source terminal ID from the storage unit 115 . And, the IP line unit 63 attaches this information to the INVITE message, and then transmits the INVITE message to the SIP server 37 (S103). Specifically, the INVITE message includes the IP address of the IP line unit, the ID of the IP line unit, the VTE-ID, and the individual certificate of the IP line unit.

SIP服务器37接收INVITE消息,将IP线路单元ID及VTE-ID发送到许可处理部103,询问是否许可连接(S105)。许可处理部103参照许可信息存储部101的连接许可信息来判断是否许可连接(S107)。这里,读出图4的表。然后许可处理部103判断询问的终端ID的组合是否注册到了表中。如果对应的组合已被注册,则许可处理部103许可连接。许可结果从许可处理部103发送到SIP服务器37(S109)。在许可处理部103许可了连接时,SIP服务器37将INVITE消息发送到VTE81(S111)。该INVITE消息附加有IP线路单元IP地址及IP线路单元个别证书。The SIP server 37 receives the INVITE message, transmits the IP line unit ID and VTE-ID to the permission processing unit 103, and inquires whether the connection is permitted (S105). The permission processing unit 103 refers to the connection permission information of the permission information storage unit 101 to determine whether to permit the connection (S107). Here, the table of FIG. 4 is read out. The permission processing unit 103 then judges whether or not the inquired combination of terminal IDs is registered in the table. If the corresponding combination is already registered, the permission processing section 103 permits the connection. The license result is sent from the license processing unit 103 to the SIP server 37 (S109). When the permission processing unit 103 permits the connection, the SIP server 37 transmits an INVITE message to the VTE 81 (S111). The INVITE message is attached with the IP line unit IP address and the IP line unit individual certificate.

在上述处理中,在步骤S107中如果未许可连接,则SIP服务器37不会将INVITE消息发送到VTE81。因此,不会进行之后的SIP处理,也不进行之后的VPN连接。In the above processing, if the connection is not permitted in step S107, the SIP server 37 does not send the INVITE message to the VTE 81. Therefore, subsequent SIP processing is not performed, nor is subsequent VPN connection performed.

VTE81接收到INVITE消息后,由存储部125保存IP线路单元IP地址及IP线路单元个别证书,向使用者PC85进行连接请求(P2P连接请求)的询问(S113)。该连接请求附加有IP线路单元IP地址。之后使用者PC85向VTE81发送连接响应(S115)。After receiving the INVITE message, the VTE 81 stores the IP address of the IP line unit and the individual certificate of the IP line unit in the storage unit 125, and inquires about a connection request (P2P connection request) to the user PC 85 (S113). This connection request is attached with the IP line unit IP address. Thereafter, the user PC 85 sends a connection response to the VTE 81 (S115).

VTE81从存储部125读出VTE-IP地址(VTE81的IP地址)及VTE个别证书(分配给VTE81的电子证书)。然后,VTE81将OK消息发送到SIP服务器37(S117)。该OK消息附加有VTE-IP地址和VTE个别证书。The VTE 81 reads a VTE-IP address (IP address of the VTE 81 ) and a VTE individual certificate (an electronic certificate assigned to the VTE 81 ) from the storage unit 125 . Then, VTE 81 transmits an OK message to SIP server 37 (S117). The OK message is appended with the VTE-IP address and the VTE individual certificate.

SIP服务器37将OK消息与VTE-IP地址及VTE个别证书一起发送到IP线路单元63(S 119)。IP线路单元63接收到OK消息后,由存储部115保存VTE-IP地址及VTE个别证书,将ACK消息发送到SIP服务器37(S121),进一步,SIP服务器37将ACK消息发送到VTE81(S123)。The SIP server 37 sends the OK message to the IP line unit 63 together with the VTE-IP address and the VTE individual certificate (S119). After the IP line unit 63 receives the OK message, the VTE-IP address and the VTE individual certificate are saved by the storage unit 115, and the ACK message is sent to the SIP server 37 (S121), and further, the SIP server 37 sends the ACK message to the VTE81 (S123) .

在上述过程中,IP线路单元63取得VTE81的IP地址及电子证书。并且,VTE81取得IP线路单元63的IP地址及电子证书。因此,能够使用这些信息识别对方从而在IP线路单元63和VTE81之间确立VPN连接。这是终端间VPN25。In the above process, the IP line unit 63 obtains the IP address and the electronic certificate of the VTE81. And, the VTE 81 acquires the IP address and electronic certificate of the IP line unit 63 . Therefore, it is possible to establish a VPN connection between the IP line unit 63 and the VTE 81 by using these pieces of information to identify the other party. This is the VPN25 between terminals.

如图所示,IP线路单元63向VTE81进行VPN连接请求(S125)。这里,不借助SIP服务器37而是直接请求VPN连接。VTE81通过VPN连接请求所包含的IP线路单元个别证书和存储部125中保存的IP线路单元的个别证书进行认证,将包括对象的IP线路单元IP地址在内的到达信息发送到使用者PC85(S127)。IP线路单元IP地址由使用者PC85在VPN通信时使用。并且,VTE81作为VPN服务器,将进行了VPN连接处理的情况通知IP线路单元63(S129)。IP线路单元63将连接结果是OK的情况通知控制器61,并且将对象的VTE-IP地址通知控制器61(S131)。VTE-IP地址由控制器61在VPN通信时使用。由此,确立了VPN连接,通过终端间VPN25进行通信。监视影像及声音等从监视装置15提供到使用者装置17。As shown in the figure, the IP line unit 63 makes a VPN connection request to the VTE 81 (S125). Here, the VPN connection is requested directly without resorting to the SIP server 37 . The VTE 81 authenticates with the individual certificate of the IP line unit included in the VPN connection request and the individual certificate of the IP line unit stored in the storage unit 125, and sends the arrival information including the IP address of the target IP line unit to the user PC 85 (S127 ). The IP line unit IP address is used by the user PC 85 during VPN communication. Then, the VTE 81 as a VPN server notifies the IP line unit 63 that the VPN connection process has been performed (S129). The IP line unit 63 notifies the controller 61 that the connection result is OK, and notifies the controller 61 of the VTE-IP address of the object (S131). The VTE-IP address is used by the controller 61 during VPN communication. Thereby, a VPN connection is established, and communication is performed through the inter-terminal VPN 25 . Surveillance video, audio, and the like are supplied from the monitoring device 15 to the user device 17 .

接着参照图7说明使用者装置17是连接源的情况。使用者(主人)例如将显示影像的指示输入到使用者PC85。使用者PC85将包括IP线路单元ID在内的连接指示(P2P连接指示)发送到VTE81(S201)。这里,IP线路单元ID用作连接地终端的ID。Next, a case where the user device 17 is the connection source will be described with reference to FIG. 7 . The user (host) inputs, for example, an instruction to display a video to the user PC 85 . The user PC 85 transmits a connection instruction (P2P connection instruction) including the IP line unit ID to the VTE 81 (S201). Here, the IP line unit ID is used as the ID of the connected terminal.

VTE81从存储部125读出VTE-IP地址及VTE个别证书。并且,VTE81从存储部125读出作为连接源终端ID的VTE-ID。并且,VTE81将这些信息附加于INVITE消息,将INVITE消息发送到SIP服务器37(S203)。具体而言,INVITE消息包括VTE-IP地址、VTE-ID、IP线路单元ID及VTE个别证书。The VTE 81 reads out the VTE-IP address and the VTE individual certificate from the storage unit 125 . Then, the VTE 81 reads the VTE-ID which is the connection source terminal ID from the storage unit 125 . And, VTE81 attaches these pieces of information to the INVITE message, and transmits the INVITE message to the SIP server 37 (S203). Specifically, the INVITE message includes VTE-IP address, VTE-ID, IP line unit ID and VTE individual certificate.

SIP服务器37接收INVITE消息,将VTE-ID和IP线路单元ID发送到许可处理部103,询问是否许可连接(S205)。许可处理部103和上述同样参照许可信息存储部101的连接许可信息,判断是否许可连接(S207),将许可结果发送到SIP服务器37(S209)。即,如果VTE-ID和IP线路单元ID的组合已经被注册,则许可连接。在许可处理部103许可了连接后,SIP服务器37将INVITE消息发送到IP线路单元63(S211)。该INVITE消息附加有VTE-IP地址及VTE个别证书。The SIP server 37 receives the INVITE message, transmits the VTE-ID and the IP line unit ID to the permission processing unit 103, and inquires whether the connection is permitted (S205). The permission processing unit 103 refers to the connection permission information of the permission information storage unit 101 in the same manner as above, judges whether to allow the connection (S207), and sends the permission result to the SIP server 37 (S209). That is, if the combination of VTE-ID and IP line unit ID is already registered, connection is permitted. After the permission processing unit 103 permits the connection, the SIP server 37 transmits an INVITE message to the IP line unit 63 (S211). The INVITE message is attached with the VTE-IP address and the VTE individual certificate.

在上述处理中,在步骤S207中如果未许可连接,则SIP服务器37不会将INVITE消息发送到IP线路单元63。因此,不进行之后的SIP的处理,也不进行之后的VPN连接。In the above processing, if the connection is not permitted in step S207, the SIP server 37 does not transmit the INVITE message to the IP line unit 63. Therefore, the subsequent SIP processing is not performed, and the subsequent VPN connection is also not performed.

IP线路单元63接收到INVITE消息后,在存储部115中保存VTE-IP地址及VTE个别证书。并且,IP线路单元63对控制器61进行连接请求(P2P连接请求)的询问(S213)。该连接请求附加有VTE-IP地址。然后控制器61向IP线路单元63发送连接响应(S215)。After receiving the INVITE message, IP line unit 63 stores the VTE-IP address and VTE individual certificate in storage unit 115 . Then, the IP line unit 63 makes an inquiry of a connection request (P2P connection request) to the controller 61 (S213). This connection request is attached with a VTE-IP address. The controller 61 then sends a connection response to the IP line unit 63 (S215).

IP线路单元63从存储部115读出IP线路单元IP地址及IP线路单元个别证书。并且,IP线路单元63将OK消息发送到SIP服务器37(S217)。该OK消息附加有IP线路单元IP地址和IP线路单元个别证书。The IP line unit 63 reads out the IP line unit IP address and the IP line unit individual certificate from the storage unit 115 . And, the IP line unit 63 transmits an OK message to the SIP server 37 (S217). The OK message is attached with the IP line unit IP address and the IP line unit individual certificate.

SIP服务器37将OK消息和IP线路单元IP地址及IP线路单元个别证书一起发送到VTE81(S219)。VTE81接收到OK消息后,将IP线路单元IP地址及IP线路单元个别证书保存到存储部125中,向SIP服务器37返回ACK消息(S221),并且,向使用者PC85通知SIP连接确立(S223)。SIP服务器37将ACK消息发送到IP线路单元63(S225)。The SIP server 37 transmits the OK message to the VTE 81 together with the IP line unit IP address and the IP line unit individual certificate (S219). After receiving the OK message, the VTE 81 saves the IP line unit IP address and the IP line unit individual certificate in the storage unit 125, returns an ACK message to the SIP server 37 (S221), and notifies the user PC 85 that the SIP connection is established (S223) . The SIP server 37 sends the ACK message to the IP line unit 63 (S225).

在上述过程中,在IP线路单元63和VTE81之间交换IP地址及电子证书。IP线路单元63接收到ACK消息后,对VTE81进行VPN连接请求(S227)。VPN连接不通过SIP服务器37而进行。VTE81将包括对象的VTE-IP地址的到达信息发送到使用者PC85(S229)。并且,VTE81作为VPN服务器将进行了VPN连接的处理的情况通知IP线路单元63(S231)。IP线路单元63将包括对象的VTE-IP地址的到达信息发送到控制器61(S233)。由此,VPN连接确立,通过终端间VPN25进行通信。During the above process, IP addresses and electronic certificates are exchanged between the IP line unit 63 and the VTE 81 . After receiving the ACK message, the IP line unit 63 makes a VPN connection request to the VTE 81 (S227). The VPN connection is performed without passing through the SIP server 37 . The VTE 81 transmits arrival information including the target VTE-IP address to the user PC 85 (S229). Then, the VTE 81 as a VPN server notifies the IP line unit 63 that the process of VPN connection has been performed (S231). The IP line unit 63 transmits the arrival information including the VTE-IP address of the object to the controller 61 (S233). Thereby, a VPN connection is established, and communication is performed through the inter-terminal VPN 25 .

如图6、图7所示,在两图的处理中,从IP线路单元63向VTE81发送VPN连接请求。其理由如下。在VPN中,需要从客户端向服务器发送连接请求。在本实施方式中,VPN服务器的功能仅设置在VTE81中。因此,在图6及图7双方中,VPN连接请求都是从IP线路单元63发送到VTE81。As shown in FIG. 6 and FIG. 7 , in the processing in both figures, a VPN connection request is sent from the IP line unit 63 to the VTE 81 . The reason for this is as follows. In a VPN, a connection request needs to be sent from the client to the server. In this embodiment, the function of the VPN server is only set in VTE81. Therefore, in both FIG. 6 and FIG. 7 , the VPN connection request is sent from the IP line unit 63 to the VTE 81 .

以上说明了本发明的优选实施方式。根据本实施方式,多个终端(监视装置15、使用者装置17)连接到具有SIP服务器37的通信管理装置11。如图3所示,通信管理装置11除了SIP服务器37之外还具有许可信息存储部101和许可处理部103。在SIP的信息通知中,从连接源终端向SIP服务器发送INVITE(邀请)消息。此时,许可处理部103判断是否许可连接。仅在许可处理部103许可连接时,SIP服务器37将来自连接源终端的INVITE消息发送到连接地终端,SIP的信息通知成功。Preferred embodiments of the present invention have been described above. According to this embodiment, a plurality of terminals (monitoring device 15 , user device 17 ) are connected to communication management device 11 having SIP server 37 . As shown in FIG. 3 , the communication management device 11 has a license information storage unit 101 and a license processing unit 103 in addition to the SIP server 37 . In the information notification of SIP, an INVITE (invite) message is sent from the connection source terminal to the SIP server. At this time, the permission processing unit 103 judges whether or not to permit the connection. Only when the permission processing unit 103 permits the connection, the SIP server 37 transmits the INVITE message from the connection source terminal to the connection destination terminal, and the SIP information notification is successful.

因此,在本发明中,预先存储连接应被许可的终端的组合的信息,在SIP信息通知时进行终端间的连接的许可。由此,并非终端和SIP服务器37之间的简单认证,而是能够进行介入了SIP服务器37的终端间即P2P的许可,可恰当限制监视信息的使用者。由此可提高监视系统1中适用SIP时的安全性。Therefore, in the present invention, information on combinations of terminals whose connection is to be permitted is stored in advance, and connection between terminals is permitted at the time of notification of SIP information. Thereby, instead of simple authentication between the terminal and the SIP server 37, P2P permission can be performed between the terminals intervening in the SIP server 37, and users of monitoring information can be restricted appropriately. Thereby, the security at the time of applying SIP to the monitoring system 1 can be improved.

并且,在本发明中,SIP的信息通知中的INVITE消息和OK消息的交换中可附加连接确立信息,该连接确立信息是不借助通信管理装置11的终端间连接的确立所使用的信息。由此,能够在终端间交换连接确立信息,从而确立终端间连接。因此,可良好地利用SIP进行终端间连接。并且,可降低通信管理装置11和终端的通信量,降低通信管理装置11的负荷。Furthermore, in the present invention, connection establishment information used to establish a connection between terminals without using the communication management device 11 may be added to the exchange of the INVITE message and the OK message in the SIP information notification. As a result, connection establishment information can be exchanged between the terminals to establish a connection between the terminals. Therefore, connections between terminals can be performed favorably using SIP. In addition, the amount of communication between the communication management device 11 and the terminal can be reduced, and the load on the communication management device 11 can be reduced.

并且,在本实施方式中,以IP地址和电子证书作为连接确立信息为例进行了说明,也可代替电子证书而使用其他信息进行对象的认证。例如,也可将电子证书中含有的通用名等用作连接确立信息。Furthermore, in this embodiment, an IP address and an electronic certificate are used as connection establishment information as an example for description, but instead of the electronic certificate, other information may be used for object authentication. For example, a common name or the like included in the electronic certificate may be used as connection establishment information.

并且,根据本发明,不介入通信管理装置11的终端间连接,可以是在终端间构筑VPN并连接的终端间VPN25。可将SIP的信息通知中的双向的信息交换适用于VPN连接确立所需的信息的交换,并且,通过使用VPN可提高安全性。Furthermore, according to the present invention, the inter-terminal VPN 25 that does not intervene in the inter-terminal connection of the communication management device 11 and establishes a VPN between the terminals and connects them may be used. The two-way information exchange in the information notification of SIP can be applied to the exchange of information required to establish a VPN connection, and security can be improved by using a VPN.

并且,根据本发明,邀请消息包括连接源终端的IP地址和电子证书作为连接确立信息,OK消息包括连接地终端的IP地址和电子证书作为连接确立信息。由此,可良好地利用SIP交换VPN连接中使用的信息,在终端间可进行安全的通信。Also, according to the present invention, the INVITE message includes the IP address of the connection source terminal and the electronic certificate as connection establishment information, and the OK message includes the IP address of the connection destination terminal and the electronic certificate as connection establishment information. Thereby, information used for VPN connection can be exchanged favorably by using SIP, and secure communication can be performed between terminals.

并且,根据本发明,通信管理装置11可设置于监视中心3。由此,利用通信管理装置11可良好地进行监视中心3和终端的通信及终端间的通信。Also, according to the present invention, the communication management device 11 may be installed in the monitoring center 3 . Thereby, the communication between the monitoring center 3 and the terminal and the communication between the terminals can be satisfactorily performed by the communication management device 11 .

并且,根据本发明,通信管理装置11和多个终端的连接可通过在通信管理装置11和多个终端之间构筑了VPN的中心终端间VPN21来连接,SIP服务器37可借助中心终端间VPN21与多个终端进行SIP消息通信。由此,SIP通信在中心终端间VPN21上进行。SIP通话后确立的终端间VPN25是终端间的VPN,而中心终端间VPN21是通信管理装置11和终端间的VPN。通过使用中心终端间VPN21,可确保监视中心3和各终端的通信的安全性,并且可确保SIP通信的安全性。And, according to the present invention, the connection between the communication management device 11 and a plurality of terminals can be connected through the center terminal VPN 21 that has constructed a VPN between the communication management device 11 and a plurality of terminals, and the SIP server 37 can communicate with each other through the center terminal VPN 21. Multiple terminals perform SIP message communication. Thereby, SIP communication is performed on VPN21 between center terminals. The inter-terminal VPN 25 established after the SIP call is a VPN between terminals, and the center inter-terminal VPN 21 is a VPN between the communication management device 11 and terminals. By using VPN21 between center terminals, the security of the communication of the monitoring center 3 and each terminal can be ensured, and the security of SIP communication can be ensured.

并且,根据本发明,监视信息可包括由监视对象5拍摄的图像、由监视对象5检测出的监视信号、由使用者一侧生成的控制信息中的至少一个。由此,可在终端间对监视信息进行通信。Furthermore, according to the present invention, the surveillance information may include at least one of images captured by the surveillance object 5, surveillance signals detected by the surveillance object 5, and control information generated by the user. Thereby, monitoring information can be communicated between terminals.

以上说明了本发明的优选实施方式。但本发明不限于上述实施方式,本领域技术人员在本发明的范围内当然可对上述实施方式进行变形。Preferred embodiments of the present invention have been described above. However, the present invention is not limited to the above-mentioned embodiments, and those skilled in the art can certainly modify the above-mentioned embodiments within the scope of the present invention.

以上说明了目前考虑到的本发明的优选实施方式,但对本实施方式能够作多种变形,并且处于本发明的真实精神和范围内的所有变形均包含在权利要求的范围内。The presently considered preferred embodiment of the present invention has been described above, but various modifications can be made to this embodiment, and all modifications within the true spirit and scope of the present invention are included in the scope of claims.

产业上利用的可能性Possibility of industrial use

如上所述,本发明涉及的监视系统适用于通过通信来远程监视店铺等。As described above, the monitoring system according to the present invention is suitable for remote monitoring of shops and the like through communication.

Claims (4)

1.一种监视系统,具有:设置于监视对象的监视对象侧终端;设置于使用者一侧的使用者侧终端,使用从上述监视对象侧终端接收的上述监视信息;和管理上述监视对象侧终端和上述使用者侧终端的通信的通信管理装置,上述监视系统的特征在于,1. A kind of monitoring system, has: be arranged on the monitoring object side terminal of monitoring object; Be arranged on the user side terminal of user side, use the above-mentioned monitoring information that receives from above-mentioned monitoring object side terminal; And manage above-mentioned monitoring object side A communication management device for communication between a terminal and the above-mentioned user-side terminal, and the above-mentioned monitoring system are characterized in that 上述监视对象侧终端具有取得上述监视对象的上述监视信息并发送到上述使用者侧终端的功能,The monitoring object side terminal has a function of acquiring the monitoring information of the monitoring object and sending it to the user side terminal, 上述使用者侧终端具有使用从上述监视对象侧终端接收的上述监视信息进行上述监视对象的监视的功能,The user side terminal has a function of monitoring the monitoring target using the monitoring information received from the monitoring target side terminal, 上述监视系统构成为:当上述监视对象侧终端或上述使用者侧终端的一方向另一方请求连接时,该连接源终端将包括自身的IP地址和电子证书以及连接地终端的识别信息在内的SIP的邀请消息发送到上述通信管理装置,上述监视对象侧终端和上述使用者侧终端作为相互具有不同功能的终端的组;The monitoring system is configured such that, when one of the monitoring target terminal or the user terminal requests a connection from the other, the connection source terminal sends the information including its own IP address, electronic certificate, and identification information of the terminal to which it is connected. The invitation message of SIP is sent to the above-mentioned communication management device, and the above-mentioned monitoring object side terminal and the above-mentioned user side terminal are as a group of terminals having different functions from each other; 上述通信管理装置具有:SIP服务器;The communication management device above has: a SIP server; 许可信息存储部,存储用于表示连接应被许可的作为相互具有不同功能的终端的组的监视对象侧终端和使用者侧终端的对应组合的连接许可信息;和a permission information storage unit storing connection permission information indicating a corresponding combination of a monitoring target terminal and a user terminal which are a group of terminals having different functions from each other to which the connection should be permitted; and 许可处理部,参照上述连接许可信息来判断是否许可监视对象侧终端和使用者侧终端间的连接,The permission processing unit refers to the connection permission information to determine whether to permit the connection between the monitoring object side terminal and the user side terminal, 上述SIP服务器,从上述连接源终端取得上述邀请消息时,将上述邀请消息中包含的上述连接地终端的识别信息提供到上述许可处理部,当上述许可处理部许可了监视对象侧终端和使用者侧终端间的连接时,上述SIP服务器将来自上述连接源终端的邀请消息提供到上述连接地终端,The SIP server, when obtaining the invitation message from the connection source terminal, provides the identification information of the connection destination terminal included in the invitation message to the permission processing unit, and when the permission processing unit permits the monitoring target terminal and the user When connecting between terminals on the side, the SIP server provides an invitation message from the connection source terminal to the connection destination terminal, 上述连接地终端从上述通信管理装置接收到上述邀请消息时,将包含自身的IP地址和电子证书的SIP的OK消息发送到上述通信管理装置,When the connected terminal receives the invitation message from the communication management device, it sends a SIP OK message including its own IP address and electronic certificate to the communication management device, 上述连接源和连接地的终端使用在上述邀请消息和上述OK消息中交换的各终端的IP地址和电子证书,在SIP会话确立后在上述连接源和连接地的终端间确立不介入上述通信管理装置的终端间连接。The terminals at the connection source and the connection destination use the IP addresses and electronic certificates of the terminals exchanged in the INVITE message and the OK message to establish non-intervention in the communication management between the terminals at the connection source and the connection destination after the SIP session is established. Device-to-terminal connections. 2.根据权利要求1所述的监视系统,其特征在于,2. The monitoring system according to claim 1, characterized in that, 不介入上述通信管理装置的终端间连接是在终端间构筑VPN而进行连接的终端间VPN。The inter-terminal connection without intervening the above-mentioned communication management device is an inter-terminal VPN in which a VPN is constructed and connected between terminals. 3.根据权利要求1所述的监视系统,其特征在于,3. The monitoring system according to claim 1, characterized in that, 上述通信管理装置和上述监视对象侧终端或使用者侧终端之间的连接,通过在上述通信管理装置和上述监视对象侧终端或使用者侧终端间构筑了VPN的中心终端间VPN进行连接,The connection between the above-mentioned communication management device and the above-mentioned monitoring object side terminal or user-side terminal is connected through a center-terminal VPN in which a VPN is constructed between the above-mentioned communication management device and the above-mentioned monitoring object-side terminal or user-side terminal, 上述SIP服务器通过上述中心终端间VPN与上述监视对象侧终端或使用者侧终端进行SIP消息的通信。The said SIP server communicates a SIP message with the said monitoring target side terminal or a user side terminal through the said center inter-terminal VPN. 4.根据权利要求1~3的任意一项所述的监视系统,其特征在于,4. The monitoring system according to any one of claims 1 to 3, characterized in that, 上述监视信息包括由上述监视对象拍摄的图像、由上述监视对象检测出的监视信号和由上述使用者一侧生成的控制信息中的至少一个。The monitoring information includes at least one of an image captured by the monitoring target, a monitoring signal detected by the monitoring target, and control information generated by the user.
CN201080014851.1A 2009-03-30 2010-03-25 Monitoring system and communication management device Active CN102378982B (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
JP2009081307A JP4781447B2 (en) 2009-03-30 2009-03-30 Monitoring system
JP2009-081307 2009-03-30
PCT/JP2010/002119 WO2010116642A1 (en) 2009-03-30 2010-03-25 Monitoring system and communication management device

Publications (2)

Publication Number Publication Date
CN102378982A CN102378982A (en) 2012-03-14
CN102378982B true CN102378982B (en) 2015-05-27

Family

ID=42935943

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201080014851.1A Active CN102378982B (en) 2009-03-30 2010-03-25 Monitoring system and communication management device

Country Status (4)

Country Link
JP (1) JP4781447B2 (en)
KR (1) KR101516708B1 (en)
CN (1) CN102378982B (en)
WO (1) WO2010116642A1 (en)

Families Citing this family (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5779882B2 (en) * 2011-01-05 2015-09-16 株式会社リコー Device management system, device, device management method and program
JP2013038684A (en) * 2011-08-10 2013-02-21 Refiner Inc Vpn connection management system
US9467297B2 (en) 2013-08-06 2016-10-11 Bedrock Automation Platforms Inc. Industrial control system redundant communications/control modules authentication
US9727511B2 (en) 2011-12-30 2017-08-08 Bedrock Automation Platforms Inc. Input/output module with multi-channel switching capability
US11967839B2 (en) 2011-12-30 2024-04-23 Analog Devices, Inc. Electromagnetic connector for an industrial control system
US8862802B2 (en) 2011-12-30 2014-10-14 Bedrock Automation Platforms Inc. Switch fabric having a serial communications interface and a parallel communications interface
US9600434B1 (en) 2011-12-30 2017-03-21 Bedrock Automation Platforms, Inc. Switch fabric having a serial communications interface and a parallel communications interface
US9191203B2 (en) 2013-08-06 2015-11-17 Bedrock Automation Platforms Inc. Secure industrial control system
US12061685B2 (en) 2011-12-30 2024-08-13 Analog Devices, Inc. Image capture devices for a secure industrial control system
US11314854B2 (en) 2011-12-30 2022-04-26 Bedrock Automation Platforms Inc. Image capture devices for a secure industrial control system
US8971072B2 (en) 2011-12-30 2015-03-03 Bedrock Automation Platforms Inc. Electromagnetic connector for an industrial control system
US9437967B2 (en) 2011-12-30 2016-09-06 Bedrock Automation Platforms, Inc. Electromagnetic connector for an industrial control system
US10834094B2 (en) 2013-08-06 2020-11-10 Bedrock Automation Platforms Inc. Operator action authentication in an industrial control system
US10834820B2 (en) 2013-08-06 2020-11-10 Bedrock Automation Platforms Inc. Industrial control system cable
US10613567B2 (en) 2013-08-06 2020-04-07 Bedrock Automation Platforms Inc. Secure power supply for an industrial control system
CN111293495B (en) 2014-07-07 2022-05-24 基岩自动化平台公司 Industrial control system cable
CN105635078A (en) * 2014-11-07 2016-06-01 中兴通讯股份有限公司 Method and system of realizing session initiation protocol (SIP) session transmission
CN105933198B (en) * 2016-04-21 2020-01-14 浙江宇视科技有限公司 Device for establishing direct connection VPN tunnel
JP7085826B2 (en) * 2016-12-16 2022-06-17 ベドロック・オートメーション・プラットフォームズ・インコーポレーテッド Image capture device for secure industrial control systems
CN110087034B (en) * 2019-04-25 2020-11-10 山西潞安金源煤层气开发有限责任公司 Coal bed gas remote monitoring system
JP7312359B2 (en) * 2019-09-30 2023-07-21 ブラザー工業株式会社 printer

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1717913A (en) * 2003-08-06 2006-01-04 松下电器产业株式会社 Relay server, relay server service control method, service providing system and program

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3779101B2 (en) * 1999-08-13 2006-05-24 セコム株式会社 Image sending device
JP4415311B2 (en) * 2003-12-25 2010-02-17 日本ビクター株式会社 Monitoring system and output control device
JP4410070B2 (en) * 2004-09-17 2010-02-03 富士通株式会社 Wireless network system and communication method, communication apparatus, wireless terminal, communication control program, and terminal control program
JP4551866B2 (en) * 2005-12-07 2010-09-29 株式会社リコー COMMUNICATION SYSTEM, CALL CONTROL SERVER DEVICE, AND PROGRAM
JP2008219239A (en) * 2007-03-01 2008-09-18 Yamaha Corp Vpn dynamic setting system
JP4750761B2 (en) * 2007-07-23 2011-08-17 日本電信電話株式会社 Connection control system, connection control method, connection control program, and relay device

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1717913A (en) * 2003-08-06 2006-01-04 松下电器产业株式会社 Relay server, relay server service control method, service providing system and program

Also Published As

Publication number Publication date
JP4781447B2 (en) 2011-09-28
CN102378982A (en) 2012-03-14
KR101516708B1 (en) 2015-05-04
KR20120028298A (en) 2012-03-22
WO2010116642A1 (en) 2010-10-14
JP2010233167A (en) 2010-10-14

Similar Documents

Publication Publication Date Title
CN102378982B (en) Monitoring system and communication management device
CN107306214B (en) Method, system and related equipment for connecting terminal with virtual private network
CN102340650B (en) Method and system for terminal video monitoring
KR100924692B1 (en) Data transmission system, apparatus and method for processing information, apparatus and method for relaying data, and storage medium
JP5148540B2 (en) Monitoring system
KR101981812B1 (en) Network communication systems and methods
CA2419853A1 (en) Location-independent packet routing and secure access in a short-range wireless networking environment
JP2010233167A5 (en)
EP2765564B1 (en) System and method for controlling security systems
JP4750869B2 (en) Communication control device and monitoring device
JP5357619B2 (en) Communication failure detection system
WO2012122914A2 (en) Method and system for implementing ip-based vvm
CN104363235A (en) Communication method, device and system and communication channel establishing method and device
CN107454178B (en) Data transmission method and device
JP2007286821A (en) Information sharing system and information sharing method
JP2016035621A (en) Work support system and work support method
JP2006108768A (en) Communication connection method and communication system for concealing identification information of user terminal
JP5302076B2 (en) Communication failure detection system
JP4472566B2 (en) Communication system and call control method
JP4061239B2 (en) Communication apparatus and communication establishment method
JP2010251945A (en) Electronic certificate management system for communication authentication and terminal device
US20250023987A1 (en) System for establishing communication
KR100911364B1 (en) Method for providing real-time participant monitoring service in SIP based multi-party conference, conference management server and conference system for him
JP2007286820A (en) Information sharing system and information sharing method
JP2007281811A (en) Gateway apparatus, information sharing system, and information sharing method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant