TWI491209B - Router and security system using the same - Google Patents

Router and security system using the same Download PDF

Info

Publication number
TWI491209B
TWI491209B TW102106233A TW102106233A TWI491209B TW I491209 B TWI491209 B TW I491209B TW 102106233 A TW102106233 A TW 102106233A TW 102106233 A TW102106233 A TW 102106233A TW I491209 B TWI491209 B TW I491209B
Authority
TW
Taiwan
Prior art keywords
network
router
module
address
allocation table
Prior art date
Application number
TW102106233A
Other languages
Chinese (zh)
Other versions
TW201434295A (en
Inventor
Yung Wei Chen
Tsung Hao Tsai
Original Assignee
Weltec Entpr Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Weltec Entpr Co Ltd filed Critical Weltec Entpr Co Ltd
Priority to TW102106233A priority Critical patent/TWI491209B/en
Publication of TW201434295A publication Critical patent/TW201434295A/en
Application granted granted Critical
Publication of TWI491209B publication Critical patent/TWI491209B/en

Links

Description

路由器及保全系統Router and security system

本發明有關於一種網路裝置及系統,且特別是一種路由器及保全系統。The present invention relates to a network device and system, and more particularly to a router and security system.

近年來,為了保障住家、辦公大樓、商場、工廠、醫院等,私人或公共場的環境安全,大部分住家、企業、或商家通常會裝設保全系統來監控環境安全。隨著科網際網路的發展,保全系統已由傳統透過電話通訊連結用戶端與遠端監控中心,更新為利用網路通訊管道進行資料與信息的傳遞。In recent years, in order to protect the environmental security of homes, office buildings, shopping malls, factories, hospitals, etc., private or public places, most homes, businesses, or businesses usually install security systems to monitor environmental safety. With the development of the Internet, the security system has been traditionally connected to the user terminal and the remote monitoring center through telephone communication, and is updated to use the network communication channel for data and information transmission.

目前,在保全系統的架構下,遠端監控中心的管理伺服器一般係透過多個路由器來與保全系統中多個保全設備進行通訊。具體地說,習知傳統的路由器通常具有與外部網路連接的廣域網路介面與內部子網路連接的區域網路介面,用以作為外部網路與內部網路通訊的橋樑。路由器並可基於其所具有的公有位址進行網路位址轉譯程序(Network Address Translation,NAT),以配置多個與私有位址給與其連接的網路設備形成內部子網路。因此,於保全系統中,路由器一般係將所接收到的資料(例如由遠端監控中心所傳送的資料封包)的位址進行替換,然後再對應傳送給內部子網路中該些保全設備。At present, under the architecture of the security system, the management server of the remote monitoring center generally communicates with multiple security devices in the security system through multiple routers. Specifically, conventional routers usually have a wide area network interface connected to an external network and a local area network interface connected to the internal subnet, and serve as a bridge between the external network and the internal network. The router can perform Network Address Translation (NAT) based on the public address it has to configure multiple internal addresses to form a subnet with the private address of the network device connected to it. Therefore, in the security system, the router generally replaces the address of the received data (for example, the data packet transmitted by the remote monitoring center), and then transmits the corresponding information to the security devices in the internal subnet.

然而在此保全系統的架構中,遠端監控中心只能透過路由器來進行資料與信息的傳遞,而無法與該些保全設備建立直接通訊 的路徑。此外,遠端監控中心對保全系統中路由器進行管理時,路由器的用戶端須個別登錄到路由器,方可修改,配置與獲取其配置連接各該路由器該些保全設備的私有位址,增加安裝與管理保全系統的繁雜度。再者,每一路由器可提供的私有位址有限,而隨著保全系統的監控功能與範圍的擴大,路由器與內部子網路的數量需求亦隨之增加,進而亦會提高保全系統硬體安裝管理或通訊複雜度。However, in the architecture of the security system, the remote monitoring center can only transmit data and information through the router, and cannot establish direct communication with the security devices. path of. In addition, when the remote monitoring center manages the routers in the security system, the user terminals of the routers must be individually logged into the router to modify, configure and obtain the private addresses of the security devices of the routers, and increase the installation and installation. Manage the complexity of the security system. Moreover, each router can provide a limited private address, and as the monitoring function and scope of the security system expands, the number of routers and internal sub-networks increases, which in turn increases security system hardware installation. Management or communication complexity.

有鑑於此,本發明實施例提供一種路由器與保全系統,所述路由器可將保全系統分割成多個子網域,並將子網域中的各個網路設備位址資訊主動透過網路送至遠端伺服系統,以供遠端伺服系統直接監控該些網路設備,提高保全系統的監控效益。藉此,本發明的路由器與本發明路由器所架構的保全系統可以提供逆向控制的功能,讓遠端的管理者可以直接取得區網內部的網路位址以進行管理與設定。另,路由器中的外掛伺服模組更提供了網路電話VoIP(Voice over IP)的伺服功能,可以作為VoIP伺服器使用,讓路由器的使用者自行架構私有的VoIP環境,進而降低使用與架構VoIP的成本。In view of this, an embodiment of the present invention provides a router and a security system, where the router can divide the security system into multiple sub-domains, and actively transmit the address information of each network device in the sub-domain to the remote network. The end servo system is used for the remote servo system to directly monitor the network devices, thereby improving the monitoring efficiency of the security system. Thereby, the router of the present invention and the security system constructed by the router of the present invention can provide reverse control functions, so that the remote administrator can directly obtain the network address inside the network network for management and setting. In addition, the external servo module in the router provides the VoIP (Voice over IP) servo function, which can be used as a VoIP server, allowing the user of the router to construct a private VoIP environment, thereby reducing the use and architecture of VoIP. the cost of.

本發明實施例提供一種路由器,此路由器適用於連接於上層路由器與多個網路設備之間。所述上層路由器進行第一網路位址轉換程序以建立第一子網域並指派第一私有位址給路由器。所述路由器包括路由器模組、網路模組以及外掛伺服模組。路由器模組耦接於上層路由器與該些網路設備。路由器用以將第一私有位址設定為公有位址,並基於公有位址進行第二網路位址轉換程序以建立第二子網域。網路模組耦接於路由器模組。外掛伺服模組經由網路模組耦接於路由器模組。外掛伺服模組用以取得路由器中的位址分配表,並經由路由模組將位址分配表傳送至遠端伺服 系統。路由器位於第一子網域中,而該些網路設備位於第二子網域中,其中該位址分配表記錄對應於該些網路設備的多個網路位址。The embodiment of the invention provides a router, which is suitable for being connected between an upper layer router and a plurality of network devices. The upper router performs a first network address translation procedure to establish a first subdomain and assign a first private address to the router. The router includes a router module, a network module, and an external servo module. The router module is coupled to the upper router and the network devices. The router is configured to set the first private address as a public address, and perform a second network address translation procedure based on the public address to establish a second subdomain. The network module is coupled to the router module. The external servo module is coupled to the router module via the network module. The external servo module is configured to obtain an address allocation table in the router, and transmit the address allocation table to the remote server via the routing module. system. The router is located in the first sub-domain, and the network devices are located in the second sub-domain, wherein the address allocation table records a plurality of network addresses corresponding to the network devices.

本發明實施例提供一種保全系統,此保全系統包括遠端伺服系統、上層路由器以及複數個路由器。上層路由器經由網路連接至遠端伺服系統,且用以進行第一網路位地址轉換(NAT)程序以建立第一子網域。複數個路由器經由網路連接至上層路由器。各路由器另包括路由器模組、網路模組以及外掛伺服模組。路由器模組耦接於上層路由器與複數個網路設備,並將自上層路由器取得的第一私有位址設定為公有位址。路由器模組並基於公有位址進行第二網路位地址轉換(NAT)程序以建立第二子網域。網路模組耦接於路由器模組。外掛伺服模組經由網路模組耦接於路由器模組。外掛伺服模組用以取得路由器中的位址分配表,並經由路由模組將位址分配表傳送至遠端伺服系統。所述路由器位於第一子網域中,而該些網路設備位於第二子網域中。所述位址分配表記錄對應於該些網路設備的多個網路位址。Embodiments of the present invention provide a security system including a remote servo system, an upper layer router, and a plurality of routers. The upper router is connected to the remote servo system via the network and is configured to perform a first network bit address translation (NAT) procedure to establish the first subdomain. A plurality of routers are connected to the upper router via the network. Each router also includes a router module, a network module, and an external servo module. The router module is coupled to the upper router and the plurality of network devices, and sets the first private address obtained from the upper router as the public address. The router module performs a second network bit address translation (NAT) procedure based on the public address to establish a second subdomain. The network module is coupled to the router module. The external servo module is coupled to the router module via the network module. The external servo module is configured to obtain an address allocation table in the router, and transmit the address allocation table to the remote servo system via the routing module. The router is located in a first sub-domain and the network devices are located in a second sub-domain. The address allocation table records a plurality of network addresses corresponding to the network devices.

綜上所述,本發明實施例所提供的路由器與保全系統,此路由器應用於保全系統中,且可於建立相應的保全系統中子網域的同時,將與路由器連接的網路設備的位址分配表主動傳送遠端伺服系統,以供遠端伺服系統的管理者獲取網路設備的網路位址。遠端伺服系統的管理者從而可根據位址分配表中網路設備的網路位址直接連結網路設備,以對網路設備的位址進行配置與監控網路設備。據此,本發明實施例所提供的路由器可增加保全系統的安裝與管控的便利性,提升保全系統的監控效益。In summary, the router and the security system provided by the embodiments of the present invention are used in the security system, and the bits of the network device connected to the router can be established while establishing the corresponding subdomain in the security system. The address allocation table actively transmits the remote servo system for the remote server system administrator to obtain the network address of the network device. The administrator of the remote servo system can directly connect the network device according to the network address of the network device in the address allocation table to configure and monitor the network device address of the network device. Accordingly, the router provided by the embodiment of the present invention can increase the convenience of installation and control of the security system, and improve the monitoring efficiency of the security system.

為使能更進一步瞭解本發明之特徵及技術內容,請參閱以下有關本發明之詳細說明與附圖,但是此等說明與所附圖式僅係用來說明本發明,而非對本發明的權利範圍作任何的限制。The detailed description of the present invention and the accompanying drawings are to be understood by the claims The scope is subject to any restrictions.

1、2‧‧‧保全系統1, 2‧‧‧Security system

10、20‧‧‧遠端伺服系統10, 20‧‧‧ Remote servo system

12、22‧‧‧網路12, 22‧‧‧ Network

14、24‧‧‧上層路由器14, 24‧‧‧ upper router

140、240‧‧‧第一子網域140, 240‧‧‧ first subdomain

16、16’、26a~26c‧‧‧路由器16, 16', 26a~26c‧‧‧ router

160、260a~260c‧‧‧第二子網域160, 260a~260c‧‧‧second subdomain

162‧‧‧路由器模組162‧‧‧ router module

164‧‧‧網路模組164‧‧‧Network Module

166、166’‧‧‧外掛伺服模組166, 166'‧‧‧ external servo module

1662‧‧‧中央處理單元1662‧‧‧Central Processing Unit

1664‧‧‧內部網路模組1664‧‧‧Internal network module

1666‧‧‧記憶單元1666‧‧‧ memory unit

18、18a~18d、28a~28h‧‧‧網路設備18, 18a~18d, 28a~28h‧‧‧ network equipment

圖1是本發明第一實施例提供的保全系統的功能方塊示意圖。1 is a functional block diagram of a security system according to a first embodiment of the present invention.

圖2是本發明第一實施例提供的路由器的功能方塊圖。2 is a functional block diagram of a router according to a first embodiment of the present invention.

圖3是本發明第二實施例提供的路由器的功能方塊示意圖。FIG. 3 is a functional block diagram of a router according to a second embodiment of the present invention.

圖4是本發明第三實施例提供的保全系統的功能方塊示意圖。4 is a functional block diagram of a security system according to a third embodiment of the present invention.

〔第一實施例〕[First Embodiment]

請參照圖1,圖1繪示本發明第一實施例提供的保全系統的功能方塊示意圖。本實施例之保全系統中的對應每一個子網域的路由器可主動將路由器中對應多個網路設備的位址分配表透過網路傳送至遠端伺服系統,以供遠端伺服系統的管理者對該些網路設備進行管理監控。Please refer to FIG. 1. FIG. 1 is a schematic functional block diagram of a security system according to a first embodiment of the present invention. The router corresponding to each sub-domain in the security system of the embodiment can actively transmit the address allocation table of the corresponding multiple network devices in the router to the remote servo system through the network for management of the remote servo system. Manage and monitor these network devices.

所述保全系統1包括遠端伺服系統10、網路12、上層路由器14、複數個路由器16以及複數個網路設備18a~18d。上層路由器14透過網路12連接遠端伺服系統10。複數個路由器16分別連接於上層路由器14與該些網路設備18a~18d之間。上層路由器14可以有線(例如乙太網路)或無線方式連接該些路由器16。該些網路設備18a~18d可以是透過RJ45接頭連接該些路由器16。遠端伺服系統10與網路12之間或是網路12與上層路由器14之間可進一步包括防火牆(firewall)以過濾交換資訊封包,提高保全系統1的安全性。The security system 1 includes a remote server system 10, a network 12, an upper router 14, a plurality of routers 16, and a plurality of network devices 18a-18d. The upper router 14 is connected to the remote servo system 10 via the network 12. A plurality of routers 16 are respectively connected between the upper router 14 and the network devices 18a-18d. The upper router 14 can connect to the routers 16 either by wire (e.g., Ethernet) or wirelessly. The network devices 18a-18d may be connected to the routers 16 via RJ45 connectors. The firewall between the remote server system 10 and the network 12 or between the network 12 and the upper layer router 14 may further include a firewall to filter the exchange of information packets to improve the security of the security system 1.

於本實施例中,該些路由器16會分別主動將對應該些網路設備18a~18d的一位址分配表經上層路由器14、網路12傳送至遠端伺服系統10。遠端伺服系統10進而可以直接與該些網路設備18a~18d進行通訊。遠端伺服系統10可例如為設置於遠端監控中心的一監控伺服器。In this embodiment, the routers 16 actively transmit the address allocation table corresponding to the network devices 18a-18d to the remote server system 10 via the upper router 14 and the network 12. The remote servo system 10, in turn, can communicate directly with the network devices 18a-18d. The remote servo system 10 can be, for example, a monitoring server disposed at a remote monitoring center.

進一步地說,上層路由器14具有廣域網路(Wide Area Network,WAN)介面(未繪示)與區域網路(Local Area Network,LAN)介面(未繪示)。廣域網路(Wide Area Network,WAN)介 面與區域網路介面為實體層(Physical layer)的電路,負責廣域網路與區域網路的埠口(port)以及處理封包傳送。上層路由器14可透過廣域網路介面,例如符合RJ-11規格的電話線連接一數據機以和網路12與遠端伺服系統10連結,而透過區域網路介面連接例如符合RJ-45規格的纜線連接區域網路中的複數個路由器16。Further, the upper layer router 14 has a Wide Area Network (WAN) interface (not shown) and a Local Area Network (LAN) interface (not shown). Wide Area Network (WAN) The face and area network interface is a circuit of the physical layer, which is responsible for the port of the wide area network and the area network and handles the packet transmission. The upper router 14 can connect to a data machine through a wide area network interface, for example, a telephone line conforming to the RJ-11 specification to connect with the network 12 and the remote servo system 10, and connect, for example, a cable conforming to the RJ-45 specification through a regional network interface. The line connects to a plurality of routers 16 in the area network.

保全系統1於本實施例中係採用網際網路協議版本4(Internet Protocol version 4,IPv4)的網路通訊協定進行通訊,亦即每一位址包含四個位元組,且每一位元組包括8位元。習知在IPv4的網路通訊協定,上層路由器14共可在第一子網域140的網段可配置254個網路位址,故可連接254個路由器16。然而保全系統1亦可依實際架構與運作需求採用網際網路協議版本6(Internet Protocol version 6,IPv6)的網路通訊協定進行通訊,本實施例並不限制In this embodiment, the security system 1 uses the Internet Protocol version 4 (IPv4) network communication protocol for communication, that is, each address includes four bytes, and each bit is The group includes 8 bits. It is known that in the IPv4 network communication protocol, the upper router 14 can be configured with 254 network addresses in the network segment of the first sub-domain 140, so that 254 routers 16 can be connected. However, the security system 1 can also communicate according to the network protocol of the Internet Protocol version 6 (IPv6) according to the actual architecture and the operation requirements. This embodiment is not limited.

所述上層路由器14具有外部辨識的位址(例如為電信業者所提供的),並可進行第一網路位址轉換(Network Address Translation,NAT)程序以建立第一子網域140並指派第一私有位址(private IP address)給各該路由器16。換言之,當該些路由器16被連接至上層路由器14時,上層路由器14即可自動進行動態主機配置協定程序(Dynamic Host Configuration Protocol,DHCP),以分配第一私有位址給各該連接的路由器16。The upper router 14 has an externally recognized address (for example, provided by a carrier), and can perform a first Network Address Translation (NAT) procedure to establish the first subdomain 140 and assign the first A private IP address is given to each of the routers 16. In other words, when the routers 16 are connected to the upper router 14, the upper router 14 can automatically perform a Dynamic Host Configuration Protocol (DHCP) to allocate the first private address to each connected router 16 .

簡單來說,路由器16於連接上層路由器14時,可發出一個廣播訊息,向上層路由器14要求一個動態的網路位址,上層路由器14即根據目前已配置的位址,提供一個可供使用的第一私有位址和對應的子網路遮罩給路由器16。據此,上層路由器14可自動為路由器16分配第一私有位址,且只有當路由器16在開機時才向上層路由器14申請第一私有位址,用畢後立即交回,有效地節省第一子網域中140的網路位址使用數量。Briefly, when the router 16 connects to the upper router 14, it can send a broadcast message, and the upper router 14 requests a dynamic network address. The upper router 14 provides an available address according to the currently configured address. The first private address and the corresponding subnet are masked to the router 16. Accordingly, the upper router 14 can automatically allocate the first private address to the router 16, and only apply to the upper private router 14 when the router 16 is powered on, and immediately return it after use, effectively saving the first. The number of network addresses used by 140 in the subnet domain.

更具體地說,當第一子網域140中的任一路由器16被連結至 上層路由器14時,路由器16會向上層路由器14傳送DHCP發現封包,以接收上層路由器14響應時回傳的DHCP提供封包。從而,路由器16可根據DHCP提供封包解析上層路由器14的指派的第一私有位址,並自動設定公有位址(即WAN埠口的網路位址),使路由器16的公有位址與上層路由器14處於同一網段。同時,路由器16並根據第一私有位址設置路由器16的私有位址(即LAN埠口的網路位址)。More specifically, when any of the routers 16 in the first subdomain 140 are connected to When the upper router 14 is used, the router 16 transmits a DHCP discovery packet to the upper router 14 to receive the DHCP providing packet returned by the upper router 14 in response. Thus, the router 16 can resolve the assigned first private address of the upper router 14 according to the DHCP providing packet, and automatically set the public address (ie, the network address of the WAN port), so that the public address of the router 16 and the upper router 14 is on the same network segment. At the same time, router 16 also sets the private address of router 16 (i.e., the network address of the LAN port) based on the first private address.

值得注意的是,於本實施例中,第一子網域140內包括多個路由器16。然於實務上,第一子網域140內亦可包括路由器16、個人電腦(Personal Computer,PC)與個人數位助理等網路設備。當上層路由器14完成指派第一私有位址(private IP address)給第一子網域140內的各該路由器16後,上層路由器14會自動建立對應第一子網域140的位址分配表,並利用廣域網路介面經網路12傳送至遠端伺服系統10。所述第一子網域140的位址分配表記錄對應第一子網域140內多個路由器16的配置的第一私有位址,並且是儲存於上層路由器14。It should be noted that, in this embodiment, the plurality of routers 16 are included in the first sub-domain 140. In practice, the first sub-domain 140 may also include network devices such as a router 16, a personal computer (PC), and a personal digital assistant. After the upper router 14 finishes assigning the first private address (private IP address) to each of the routers 16 in the first sub-domain 140, the upper-layer router 14 automatically establishes an address allocation table corresponding to the first sub-domain 140. And transmitting to the remote servo system 10 via the network 12 using the wide area network interface. The address allocation table of the first sub-domain 140 records the first private address corresponding to the configuration of the plurality of routers 16 in the first sub-domain 140, and is stored in the upper-layer router 14.

而每一路由器16如前述會將第一私有位址設定為公有位址(public IP address),並基於此公有位址進行第二網路位址轉換程序以建立第二子網域160。每一路由器16分別配置網路位址給該些網路設備18a~18d。所述網路設備18a~18d分別位於第二子網域160內。第二子網域160的網段與第一子網域140的網段可為不相同,例如第一子網域140的網段可為192.168.0.X,而第二子網域160的網段可為192.168.1.X。而因一路由器16建立第二子網域160內的網路設備18a~18d的網段相同,故對應的網路遮罩亦相同。Each router 16 sets the first private address as a public IP address as described above, and performs a second network address translation procedure based on the public address to establish the second sub-domain 160. Each router 16 is configured with a network address for each of the network devices 18a-18d. The network devices 18a-18d are located in the second subdomain 160, respectively. The network segment of the second sub-domain 160 may be different from the network segment of the first sub-domain 140. For example, the network segment of the first sub-domain 140 may be 192.168.0.X, and the second sub-domain 160 The network segment can be 192.168.1.X. Since the network segment 18a-18d of the second sub-domain 160 is established by the same router 16, the corresponding network mask is also the same.

詳細地說,當第二子網域160中的網路設備18a~18d被連接至對應的路由器16時,該路由器16即會自動進行動態主機配置協定程序,以分配網路位址給各該連接的該些網路設備18a~18d。例如,該些網路設備18a~18d會向路由器16傳送DHCP發 現封包,並接收路由器16響應時回傳的DHCP提供封包。從而,網路設備再根據DHCP提供封包解析路由器16的私有位址(即路由器16的埠口的網路位址),使第二子網域160中網路設備的私有位址(即網路設備的LAN埠口的網路位址)與路由器16處於同一網段。此外,當網路設備18a~18d未被開啟或是斷線時,即會將對應的網路位址交回路由器16重新配置。In detail, when the network devices 18a-18d in the second sub-domain 160 are connected to the corresponding router 16, the router 16 automatically performs a dynamic host configuration agreement procedure to allocate network addresses to each of the routers. The network devices 18a-18d are connected. For example, the network devices 18a-18d will transmit DHCP to the router 16. The packet is now encapsulated and receives a DHCP-provided packet that is returned by the router 16 in response. Therefore, the network device further provides a private address of the packet resolution router 16 according to the DHCP (ie, the network address of the router 16), so that the private address of the network device in the second sub-domain 160 (ie, the network) The network address of the LAN port of the device is in the same network segment as the router 16. In addition, when the network devices 18a-18d are not turned on or disconnected, the corresponding network address is returned to the router 16 for reconfiguration.

當每一路由器16完成動態主機配置協定程序,亦即完成指派網路位址給第二子網域160內的該些網路設備18a~18d後,路由器16會自動建立對應第二子網域160的位址分配表,並透過上層路由器14經網路12傳送至遠端伺服系統10。所述第二子網域160的位址分配表記錄對應第二子網域160內的該些網路設備18a~18d的網路位址,並且是儲存各該路由器16。After each router 16 completes the dynamic host configuration protocol procedure, that is, after assigning the network address to the network devices 18a-18d in the second subdomain 160, the router 16 automatically establishes a corresponding second subdomain. The address allocation table of 160 is transmitted to the remote servo system 10 via the upper layer router 14 via the network 12. The address allocation table of the second sub-domain 160 records the network addresses of the network devices 18a-18d corresponding to the second sub-domain 160, and stores each of the routers 16.

此外,於本實施例中,該些網路設備18a~18d係設置於各監控區域,例如辦公大樓的監控區域。該些網路設備18a~18d可例如包括但不限於各式感知器、讀卡機、門禁系統、視訊門鈴(Video Door Phone)、緊急通訊系統(emergency phone)、數位影音記錄器(Digital Video Recorder,DVR)、數位網路紀錄器(Network Video Recorder,NVR)、監控錄影機、封閉式有線電視(Closed Circuit television,CCTV)或數位個人助理等。In addition, in this embodiment, the network devices 18a-18d are disposed in each monitoring area, such as a monitoring area of an office building. The network devices 18a-18d may include, but are not limited to, various types of sensors, card readers, access control systems, video door phones, emergency phones, digital video recorders. , DVR), Network Video Recorder (NVR), surveillance video recorder, Closed Circuit television (CCTV) or digital assistant.

據此,遠端伺服系統10可根據上層路由器14傳送第一子網域160的位址分配表與路由器16傳送第二子網域160的位址分配表獲取與該些網路設備18a~18d通訊的路徑。遠端伺服系統10隨後可根據第一子網域160的位址分配表與路由器16傳送第二子網域160的位址分配表直接透過上層路由器14、對應的路由器16連結該些網路設備18a~18d以進行管控,從而提高資訊傳遞的效率。遠端伺服系統10進而可直接掌握保全系統1內各該些網路設備18a~18d的即時資訊,提高保全系統1的監控效益。此外,在此架構下,若欲對路由器16中該些網路設備18a~18d的網路位 址進行配置、修正或獲取該些網路設備18a~18d的位址資訊,可不再須要由用戶端自行個別登入路由器16才能達成,而是可由遠端伺服系統10自行連結至該些網路設備18a~18d進行配置與修正。According to this, the remote server system 10 can transmit the address allocation table of the first sub-domain 160 and the address allocation table of the second sub-domain 160 of the router 16 according to the upper-layer router 14 to obtain the network devices 18a-18d. The path of communication. The remote server system 10 can then directly connect the network devices through the upper router 14 and the corresponding router 16 according to the address allocation table of the first sub-domain 160 and the address allocation table of the router 16 transmitting the second sub-domain 160. 18a~18d for control, thus improving the efficiency of information transmission. The remote servo system 10 can directly grasp the real-time information of each of the network devices 18a-18d in the security system 1 to improve the monitoring efficiency of the security system 1. In addition, under this architecture, if the network bits of the network devices 18a-18d in the router 16 are to be used, Address configuration, correction or acquisition of the address information of the network devices 18a~18d can be achieved by the user terminal independently logging into the router 16, but can be directly connected to the network devices by the remote server system 10. Configuration and correction from 18a to 18d.

此外,於本實施例中,上層路由器14的系統架構與路由器16相同。因此,上述上層路由器14與各該路由器16均會個別於完成其所建立的子網路時,傳送第一子網域140與第二子網域160的位址分配表給遠端伺服系統10。但於實務上,上層路由器14與路由器16亦可定時地傳送第一子網域140與第二子網域160的位址分配表給遠端伺服系統10。遠端伺服系統10亦可分別傳送第一子網域140與第二子網域160的位址分配表的要求信息至上層路由器14與路由器16,並該上層路由器14與各該路由器16可在接收要求信息後以郵件方式傳送第一子網域140與第二子網域160的位址分配表至遠端伺服系統10。Further, in the present embodiment, the system architecture of the upper router 14 is the same as that of the router 16. Therefore, the upper layer router 14 and each of the routers 16 transmit the address allocation table of the first sub-domain 140 and the second sub-domain 160 to the remote server system 10 when the sub-networks are completed. . However, in practice, the upper router 14 and the router 16 can also periodically transmit the address allocation tables of the first sub-domain 140 and the second sub-domain 160 to the remote servo system 10. The remote server system 10 can also transmit the request information of the address allocation table of the first sub-domain 140 and the second sub-domain 160 to the upper-layer router 14 and the router 16, respectively, and the upper-layer router 14 and each of the routers 16 can After receiving the request information, the address allocation table of the first sub-domain 140 and the second sub-domain 160 is sent to the remote server system 10 by mail.

附帶一提的是,第二子網域160內的其中一個網路設備例如網路設備18b可為另一路由器,路由器16可於進行第二網路位址轉換程序時指派第二私有位址給第二子網域160內的路由器。此路由器可將第二私有位址設定為另一公有位址,並基於此一公有位址進行第三網路位址轉換程序以建立第三子網域(未繪示)。路由器可分別利用動態主機配置協定程序分配派網路位址給第三子網域內的該些網路設備。路由器並於完成動態主機配置協定程序時建立對應第三子網域的位址分配表,並經路由器16、上層路由器14與網路12將第三子網域的位址分配表傳送給遠端伺服系統10。Incidentally, one of the network devices in the second sub-domain 160, such as the network device 18b, may be another router, and the router 16 may assign a second private address when performing the second network address translation procedure. The router within the second subdomain 160 is given. The router can set the second private address to another public address, and perform a third network address translation procedure based on the public address to establish a third subdomain (not shown). The router can allocate the network address to the network devices in the third sub-domain by using the dynamic host configuration protocol program, respectively. The router establishes an address allocation table corresponding to the third subdomain when the dynamic host configuration protocol is completed, and transmits the address allocation table of the third subdomain to the remote terminal via the router 16, the upper router 14, and the network 12. Servo system 10.

接著,請參照圖2,圖2繪示本發明第一實施例提供的路由器的功能方塊圖。路由器16更進一步包括路由器模組162、網路模組164以及外掛伺服模組166。路由器模組162耦接於上層路由器14與其建立的第二子網域160中該些網路設備18a~18d。網路模組164耦接於路由器模組162。外掛伺服模組166經由網路模組 164耦接於路由器模組162。於本實施例中,路由器模組162、網路模組164以及外掛伺服模組166係整合於路由器16的殼體之中。路由器16的殼體可是由絕緣材料所製成。Next, please refer to FIG. 2. FIG. 2 is a functional block diagram of a router according to the first embodiment of the present invention. The router 16 further includes a router module 162, a network module 164, and an external servo module 166. The router module 162 is coupled to the network devices 18a-18d in the second subdomain 160 established by the upper router 14 and the router. The network module 164 is coupled to the router module 162. The external servo module 166 is connected to the network module The 164 is coupled to the router module 162. In this embodiment, the router module 162, the network module 164, and the external servo module 166 are integrated into the casing of the router 16. The housing of the router 16 can be made of an insulating material.

路由器模組162可用以執行路由器16的網路通訊處理功能包括執行網路連結、封包處理、網域管理等功能,而路由器模組162可由實現上述網路通訊功能的硬體及軟體架構所組成。路由器模組162可包括廣域網路介面(未繪示)及區域網路介面(未繪示),其中廣域網路介面可用以與上層路由器14進行通訊,而區域網路介面可用以與該些網路設備18a~18d進行通訊。於一實施方式中,廣域網路介面與區域網路介面可包括RJ45接頭或RJ11接頭。路由器模組162可透過廣域網路介面上層路由器14連接,且透過區域網路介面與該些網路設備18a~18d。The router module 162 can be used to perform the network communication processing functions of the router 16 including performing network connection, packet processing, domain management, etc., and the router module 162 can be composed of a hardware and software architecture for implementing the above network communication functions. . The router module 162 can include a wide area network interface (not shown) and a regional network interface (not shown), wherein the wide area network interface can be used to communicate with the upper layer router 14, and the regional network interface can be used with the networks. The devices 18a-18d communicate. In one embodiment, the wide area network interface and the regional network interface may include an RJ45 connector or an RJ11 connector. The router module 162 can be connected through the WAN interface router 14 and through the regional network interface to the network devices 18a-18d.

路由器模組162並將路由器16被指派的第一私有位址設定為公有位址,以基於公有位址進行第二網路位址轉換程序以建立第二子網域(未繪示輿圖2)。路由器模組162並在該些網路設備18a~18d被連接至路由器模組162時,自動進行動態主機配置協定程序,以對應分配網路位址給各該連接的該些網路設備18a~18d。The router module 162 sets the first private address assigned by the router 16 as a public address to perform a second network address translation procedure based on the public address to establish a second sub-domain (not shown in FIG. 2). . When the network devices 18a-18d are connected to the router module 162, the router module 162 automatically performs a dynamic host configuration protocol to allocate network addresses to the network devices 18a of the connections. 18d.

網路模組164具有一網路接口,以連接該路由器模組162與外掛伺服模組166。於本實施例中,網路模組164為一區域網路模組,且可以是藉由具區域網路介面的硬體電路來實現,例如為RJ45連接介面。The network module 164 has a network interface for connecting the router module 162 and the external servo module 166. In this embodiment, the network module 164 is a regional network module, and may be implemented by a hardware circuit with a regional network interface, such as an RJ45 connection interface.

外掛伺服模組166用以透過路由器模組162取得路由器16中的記錄對應該些網路設備18a~18d的網路位址的位址分配表,並將第二子網域內的位址分配表經由路由模組162、上層路由器傳送至遠端伺服系統10。外掛伺服模組166包括中央處理單元1662、內部網路模組1664以及記憶單元1666。中央處理單元1662分別耦接內部網路模組1664以及記憶單元1666。內部網路模組1664並耦接網路模組164。換言之,外掛伺服模組166係透過內部網路 模組1664連接,以與路由器模組162進行通訊。The external servo module 166 is configured to obtain an address allocation table in the router 16 corresponding to the network addresses of the network devices 18a-18d through the router module 162, and allocate the address in the second subdomain. The table is transmitted to the remote servo system 10 via the routing module 162 and the upper router. The plug-in servo module 166 includes a central processing unit 1662, an internal network module 1664, and a memory unit 1666. The central processing unit 1662 is coupled to the internal network module 1664 and the memory unit 1666, respectively. The internal network module 1664 is coupled to the network module 164. In other words, the external servo module 166 is transmitted through the internal network. Module 1664 is coupled to communicate with router module 162.

外掛伺服模組166的中央處理單元1662用以由路由器模組162取得路由器16中記錄該些網路設備18a~18d的網路位址的位址分配表。中央處理單元1662並將記錄網路設備18a~18d的網路位址的位址分配表儲存於記憶單元1666。中央處理單元1662並驅動內部網路模組1664將記錄網路設備18a~18d的網路位址的位址分配表透過路由器模組162傳送至遠端伺服系統10。外掛伺服模組166的中央處理單元1662可以係以郵件方式將第二私有位址的位址分配表傳送至遠端伺服系統10。The central processing unit 1662 of the external servo module 166 is configured by the router module 162 to obtain an address allocation table of the network address of the network devices 18a-18d in the router 16. The central processing unit 1662 stores the address allocation table of the network addresses of the recording network devices 18a-18d in the memory unit 1666. The central processing unit 1662 drives the internal network module 1664 to transmit the address allocation table of the network addresses of the recording network devices 18a-18d to the remote servo system 10 via the router module 162. The central processing unit 1662 of the plug-in servo module 166 can transmit the address allocation table of the second private address to the remote server system 10 by mail.

附帶一提的是,外掛伺服模組166的中央處理單元1662另可透過執行一監控程式,提供對應路由器16的第二子網域中的一監控網頁給遠端伺服系統10。詳細地說,遠端伺服系統10的管理者可在與路由器16建立通訊路徑時,瀏覽監控網頁以對路由器模組162與該些網路設備18a~18d的進行相關設定與配置,例如啟動或關閉或是監控該些網路設備18a~18d的運作狀態等。所述監控程式的程式碼可以是儲存於記憶單元1666。It should be noted that the central processing unit 1662 of the external servo module 166 can further provide a monitoring webpage in the second sub-domain of the corresponding router 16 to the remote servo system 10 by executing a monitoring program. In detail, the administrator of the remote server system 10 can browse the monitoring webpage to establish and configure the router module 162 and the network devices 18a-18d, such as startup or configuration, when establishing a communication path with the router 16. The operation status of the network devices 18a to 18d is turned off or monitored. The code of the monitoring program may be stored in the memory unit 1666.

值得一提的是,中央處理單元1662可以為中央處理器(central process unit,CPU)、微控制器(microcontroller)或嵌入式控制器(embedded controller)等處理晶片設置於外掛伺服模組166。記憶單元1666可利用快閃記憶體晶片、唯讀記憶體晶片或隨機存取記憶體晶片等揮發性或非揮發性記憶晶片來實現,但本實施例並不以此為限。It is worth mentioning that the central processing unit 1662 can be disposed on the external servo module 166 for a processing chip such as a central processing unit (CPU), a microcontroller, or an embedded controller. The memory unit 1666 can be implemented by using a volatile or non-volatile memory chip such as a flash memory chip, a read-only memory chip, or a random access memory chip, but the embodiment is not limited thereto.

另外,外掛伺服模組166可以作為網路電話伺服器使用,例如VoIP伺服器或是SIP(Session Initiation Protocol)伺服器。外掛伺服模組166可以提供一網路電話(VoIP)登錄介面,供廣域網路(例如遠端伺服系統10的管理者)以及區域網域(例如第二子網域內該些網路設備18a~18d的操作者)的使用者註冊以加入一私有網路電話通訊網路。上述網路電話登錄介面如同SKYPE所提供的網路 電話登錄介面一般,可以讓使用者註冊以加入私有網路電話通訊網路。換言之,利用本發明的路由器16,使用者可以建立私有的網路電話通訊環境,而不需加入或透過外部網路電路供應廠商的所提供的網路電話介面。對於企業而言,可以降低設備成本與提高管理效能。In addition, the external servo module 166 can be used as a network phone server, such as a VoIP server or a SIP (Session Initiation Protocol) server. The plug-in servo module 166 can provide a VoIP login interface for the wide area network (such as the administrator of the remote server system 10) and the regional domain (for example, the network devices 18a in the second sub-domain). The user of the 18d operator registers to join a private internet telephony communication network. The above VoIP login interface is like the network provided by SKYPE. The phone login interface is generally used to allow users to register to join the private Internet telephony communication network. In other words, with the router 16 of the present invention, the user can establish a private network telephony communication environment without having to join or access the VoIP interface provided by the external network circuit provider. For enterprises, it can reduce equipment costs and improve management efficiency.

上述外掛伺服模組166與一般網路電話供應廠商的不同點在於,本發明是將外掛伺服模組166整合於路由器16中,因此保全系統的使用者或企業不需額外建立網路電話的伺服系統,也不需租用雲端的伺服器系統,就可進行網路電話通訊。路由器16是建構區域網路必備的設備,因此使用者可以在建構區域網路的同時,便可同時建立私有網路電話通訊環境,可以簡化網路電話的架構方式與降低設置成本The difference between the above-mentioned external servo module 166 and the general network telephone supplier is that the external servo module 166 is integrated into the router 16, so that the user or the enterprise of the security system does not need to establish an additional network telephone servo. The system can also perform VoIP communication without renting a cloud server system. The router 16 is a necessary device for constructing a regional network, so that the user can establish a private network telephone communication environment at the same time while constructing the regional network, which can simplify the architecture of the network telephone and reduce the installation cost.

此外,上述私有網路電話通訊網路可同時提供給廣域網路(例如遠端伺服系統10的管理者)以及區域網域(例如第二子網域內該些網路設備18a~18d的操作者)的使用者使用。更進一步地說,當電信業者所提供的外部網域發生中斷時,區域網路內的使用者(該些網路設備18a~18d的操作者)仍可透過外掛伺服模組166所建立私有網路電話通訊網路架構相互進行電話與數據通訊運作。而且,路由器16具有回自動回傳網路位址分配表的功能,因此遠端監控系統10的管理者可以透過監控伺服器,直接地連接至區域網路內的路由器16以進行私有網路電話網路的管理。In addition, the above private network telephone communication network can be simultaneously provided to the wide area network (for example, the administrator of the remote server system 10) and the regional domain (for example, the operators of the network devices 18a-18d in the second subdomain) User use. Furthermore, when the external domain provided by the carrier is interrupted, the users in the local area network (the operators of the network devices 18a-18d) can still establish a private network through the external servo module 166. The telephone telephone communication network architecture performs telephone and data communication operations with each other. Moreover, the router 16 has the function of returning the automatic backhaul network address allocation table, so that the administrator of the remote monitoring system 10 can directly connect to the router 16 in the regional network through the monitoring server for private network telephone. Network management.

換言之,本發明的路由器16同時具有位址轉換、自動回傳、逆向控制與網路電話伺服的功能,可以簡化使用者建構私有網路環境的複雜度與成本。In other words, the router 16 of the present invention has the functions of address conversion, automatic backhaul, reverse control and network telephone servo, which can simplify the complexity and cost of constructing a private network environment.

要說明的是,圖1僅用以說明保全系統的一實體架構,並非用以限定本發明。圖2僅用以說明路由器16的系統架構,並非用以限定本發明。It should be noted that FIG. 1 is only used to illustrate a physical architecture of the security system, and is not intended to limit the present invention. FIG. 2 is only used to illustrate the system architecture of the router 16, and is not intended to limit the present invention.

〔第二實施例〕[Second embodiment]

前述之路由器16中,路由器模組162、網路模組164以及外掛伺服模組166係整合於路由器16的殼體之中。但外掛伺服模組166亦可與路由器模組162及網路模組164分開設置。也就是,上述實施例中的外掛伺服模組166可以是外接路由器16。請參照圖3,圖3繪示本發明第二實施例提供的路由器的功能方塊示意圖。In the router 16 described above, the router module 162, the network module 164, and the external servo module 166 are integrated into the casing of the router 16. However, the external servo module 166 can also be provided separately from the router module 162 and the network module 164. That is, the plug-in servo module 166 in the above embodiment may be the external router 16. Please refer to FIG. 3, which is a functional block diagram of a router according to a second embodiment of the present invention.

如圖3所示路由器16’包括路由器模組162及網路模組164。外掛伺服模組166’包括中央處理單元1662、內部網路模組1664以及記憶單元1666。圖3之路由器16’與圖2之路由器16之間的差異在於外掛伺服模組166’與路由器16’並不整合於路由器殼體之中路由器16’與外掛伺服模組166’是分別設置。The router 16' shown in FIG. 3 includes a router module 162 and a network module 164. The plug-in servo module 166' includes a central processing unit 1662, an internal network module 1664, and a memory unit 1666. The difference between the router 16' of Figure 3 and the router 16 of Figure 2 is that the external servo module 166' and the router 16' are not integrated into the router housing. The router 16' and the external servo module 166' are separately provided.

更具體地說,路由器16’可為一般的路由器,而路由器模組162如前述用以執行網路通訊處理功能,如網路連結、封包處理、網域管理等功能具網路通訊等。路由器模組162具廣域網路傳輸介面及區域網路傳輸介面。網路模組164為具有一網路接口的區域網路模組。路由器16’透過網路模組164接至外掛伺服模組266的內部網路模組1664。外掛伺服模組166’的中央處理單元1662可藉由執行監控程式,透過內部網路模組1664向路由器16’的路由器模組162獲取對應網路設備18a~18b的位址分配表。外掛伺服模組166’同時可透過相同路徑,經由路由器16’的路由器模組162將對應網路設備18a~18b的位址分配表以郵件方式傳送給遠端伺服系統10。More specifically, the router 16' can be a general router, and the router module 162 is configured to perform network communication processing functions such as network connection, packet processing, and domain management, and the like. The router module 162 has a wide area network transmission interface and a regional network transmission interface. The network module 164 is a regional network module having a network interface. Router 16' is coupled to internal network module 1664 of external servo module 266 via network module 164. The central processing unit 1662 of the plug-in servo module 166' can obtain the address allocation table of the corresponding network devices 18a-18b through the internal network module 1664 to the router module 162 of the router 16' by executing the monitoring program. The external servo module 166' can simultaneously transmit the address allocation table of the corresponding network devices 18a-18b to the remote server system 10 via the router module 162 of the router 16' via the same path.

值得一提的是,外掛伺服模組166’於本實施例中可例如為個人電腦、筆記型電腦或平板電腦等電腦主機載有監控程式的程式碼。所述監控程式的程式碼可以是儲存於外掛伺服模組166’的記憶單元166。外掛伺服模組166’可透過執行監控程式的程式碼提供對應路由器16’建立的第二子網域中的監控網頁給遠端伺服系統10,以供遠端伺服系統10的管理者對網路設備18a~18b的運作進行管控。It is worth mentioning that the external servo module 166' can be a program code of a monitoring program, for example, a computer host such as a personal computer, a notebook computer or a tablet computer. The code of the monitoring program may be the memory unit 166 stored in the external servo module 166'. The plug-in servo module 166' can provide a monitoring webpage in the second sub-domain established by the corresponding router 16' to the remote servo system 10 through the code of the monitoring program for the administrator of the remote servo system 10 to access the network. The operation of the devices 18a-18b is controlled.

另外,於一實施方式中,外掛伺服模組166’的內部網路模組164可以是透過RJ45的電線連接路由器16’的網路模組164,以進行通訊。In addition, in an embodiment, the internal network module 164 of the external servo module 166' may be connected to the network module 164 of the router 16' via the RJ45 wire for communication.

此外,外掛伺服模組166’如前述實施例所述同時可以作為網路電話伺服器(例如VoIP伺服器或SIP(Session Initiation Protocol)伺服器)使用。也就是,外掛伺服模組166’可以過執行網路電話伺服程式的程式碼提供網路電話(VoIP)登錄介面,經由路由器16’供廣域網路(例如遠端伺服系統10的管理者)以及區域網域(例如第二子網域內該些網路設備18a~18d的操作者)的使用者註冊以加入私有網路電話通訊網路,進行網路電話通訊與數據傳遞等運作,簡化保全系統管理架構。In addition, the plug-in servo module 166' can be used as a network telephony server (for example, a VoIP server or a SIP (Session Initiation Protocol) server) as described in the foregoing embodiments. That is, the plug-in servo module 166' can provide a VoIP login interface through the execution of the code of the VoIP server program, via the router 16' for the wide area network (for example, the administrator of the remote servo system 10) and the area. The user of the domain (for example, the operators of the network devices 18a-18d in the second subdomain) registers to join the private network telephone communication network, performs network telephone communication and data transmission, etc., and simplifies the security system management. Architecture.

圖3的路由器16’及外掛伺服模組166’與圖1中的路由器16及外掛伺服模組166的其他架構相似,故本發明領域具通常知識者應可由上述說明推知路由器16’及外掛伺服模組166’的運作,故不在此贅述。The router 16' and the external servo module 166' of FIG. 3 are similar to the other architectures of the router 16 and the external servo module 166 of FIG. 1. Therefore, those skilled in the art should be able to infer the router 16' and the external servo from the above description. The operation of the module 166' is not described here.

〔第三實施例〕[Third embodiment]

為了更進一步描述具本發明實施例提供的路由器的保全系統的運作,以下對路由器的實際應用方式作說明。請參照圖4,圖4繪示本發明第三實施例提供的保全系統的功能方塊示意圖。In order to further describe the operation of the security system of the router provided by the embodiment of the present invention, the following describes the actual application mode of the router. Please refer to FIG. 4. FIG. 4 is a schematic functional block diagram of a security system according to a third embodiment of the present invention.

保全系統2包括遠端伺服系統20、網路22、上層路由器24、路由器26a~26c以及網路設備(如視訊門鈴28a、監控系統28b、緊急通訊系統28c、門禁系統28d、監控錄影機1號28e、監控錄影機2號28f、監控錄影機3號28g及監控錄影機4號28h等)。遠端伺服系統30透過網路22連結上層路由器24。上層路由器24透過網路連結路由器26a~26c。路由器26a~26c分別連接多個網路設備。於本實施例中,上層路由器24與路由器26皆為具有外掛伺服模組的路由器,並可以圖2之路由器16或圖3所示路由器16’外接外掛伺服模組166’來實現。遠端伺服系統20可為設置於 遠端伺服中心的監控伺服器。遠端伺服系統20可透過此保全架構,直接獲取掌握保全系統2內的網路設備的通訊路徑,並即時對網路設備進行監控。The security system 2 includes a remote servo system 20, a network 22, an upper router 24, routers 26a-26c, and network devices (such as video doorbell 28a, monitoring system 28b, emergency communication system 28c, access control system 28d, and surveillance video recorder 1). 28e, surveillance video recorder 2nd 28f, surveillance video recorder 3rd 28g and surveillance video recorder 4th 28h, etc.). The remote servo system 30 is coupled to the upper router 24 via the network 22. The upper router 24 connects the routers 26a-26c via the network. The routers 26a-26c are respectively connected to a plurality of network devices. In this embodiment, the upper router 24 and the router 26 are both routers with external servo modules, and can be implemented by the router 16 of FIG. 2 or the external router module 166' of the router 16' shown in FIG. The remote servo system 20 can be configured to The monitoring server of the remote servo center. The remote servo system 20 can directly acquire the communication path of the network device in the security system 2 through the security architecture, and immediately monitor the network device.

具體地說,上層路由器24具有一廣域網路介面位址(即WAN埠口的網路位址)與一區域網路介面位址(即LAN埠口的網路位址)。舉例來說,上層路由器24的WAN埠口的網路位址為220.123.1.1,而上層路由器24的LAN埠口的網路位址為192.168.1.251。上層路由器24進行第一網路位址轉換(NAT)程序以建立第一子網域240並指派第一私有位址給該些路由器26a~26c。上層路由器24透過執行自動進行動態主機配置協定程序(DHCP)分派網路位址至各該路由器26a~26c。當第一子網域240中的各該路由器26a~26c被連結至上層路由器24時,各該路由器26a~26c會根據上層路由器24指派的第一私有位址,設定一公有位址(即WAN埠口的網路位址),與一私有位址(即LAN埠口的網路位址)。Specifically, the upper router 24 has a wide area network interface address (ie, the network address of the WAN port) and a regional network interface address (ie, the network address of the LAN port). For example, the network address of the WAN port of the upper router 24 is 220.123.1.1, and the network address of the LAN port of the upper router 24 is 192.168.1.251. The upper router 24 performs a first network address translation (NAT) procedure to establish a first subdomain 240 and assign a first private address to the routers 26a-26c. The upper router 24 dispatches the network address to each of the routers 26a-26c by executing an automatic dynamic host configuration protocol (DHCP). When each of the routers 26a-26c in the first sub-domain 240 is connected to the upper-layer router 24, each of the routers 26a-26c sets a public address (ie, WAN) according to the first private address assigned by the upper-layer router 24. The network address of the port is connected to a private address (that is, the network address of the LAN port).

舉例來說,路由器26a將上層路由器24指派的第一私有位址192.168.1.1設為公有位址(即WAN埠口的網路位址),同時根據第一私有位址192.168.1.1設置私有位址(即LAN埠口的網路位址)為192.168.0.251。所述路由器26a的公有位址(即WAN埠口的網路位址)與而上層路由器24的LAN埠口的網路位址處於同一網段,而私有位址(即LAN埠口的網路位址)則可與上層路由器24的LAN埠口的網路位址處於不同網段。同樣地,路由器26b將上層路由器24指派的第一私有位址192.168.1.2設為公有位址(即WAN埠口的網路位址),同時根據第一私有位址192.168.1.2設置私有位址(即LAN埠口的網路位址)為192.168.0.251。路由器26c將上層路由器24指派的第一私有位址192.168.1.3設為公有位址(即WAN埠口的網路位址),同時根據第一私有位址192.168.1.3設置私有位址(即LAN埠位址)為192.168.0.251。For example, the router 26a sets the first private address 192.168.1.1 assigned by the upper router 24 to the public address (ie, the network address of the WAN port), and sets the private bit according to the first private address 192.168.1.1. The address (that is, the network address of the LAN port) is 192.168.0.251. The public address of the router 26a (ie, the network address of the WAN port) is in the same network segment as the network address of the LAN port of the upper router 24, and the private address (ie, the network of the LAN port) The address can be in a different network segment from the network address of the LAN port of the upper router 24. Similarly, the router 26b sets the first private address 192.168.1.2 assigned by the upper router 24 to the public address (ie, the network address of the WAN port), and sets the private address according to the first private address 192.168.1.2. (ie the network address of the LAN port) is 192.168.0.251. The router 26c sets the first private address 192.168.1.3 assigned by the upper router 24 to the public address (ie, the network address of the WAN port), and sets the private address according to the first private address 192.168.1.3 (ie, the LAN). The address is 192.168.0.251.

當上層路由器24完成路由器26a~26c的位址配置程序時會產生對應第一子網域240的一位址分配表,且上層路由器24會透過網路22,以郵件方式將此對應第一子網域240的位址分配表傳送至遠端伺服系統20,以供遠端伺服系統20的管理者進行管理。所述第一子網域240的位址分配表記錄各該路由器26a~26c的公有位址(即WAN埠口的網路位址)與私有位址(即LAN埠口的網路位址)。When the upper router 24 completes the address configuration procedure of the routers 26a-26c, an address allocation table corresponding to the first subdomain 240 is generated, and the upper router 24 transmits the corresponding first sub-mail through the network 22. The address allocation table of the domain 240 is transmitted to the remote servo system 20 for management by the administrator of the remote servo system 20. The address allocation table of the first sub-domain 240 records the public address of each of the routers 26a-26c (ie, the network address of the WAN port) and the private address (ie, the network address of the LAN port). .

接著,路由器26a~26c各該公有位址進行第二網路位址轉換(NAT)程序以建立第二子網域260a~260c。路由器26透過執行自動進行動態主機配置協定程序(DHCP)分派網路位址(即LAN埠口的網路位址)至各該網路設備28a~28h。當第二子網域260a~260c中的各該網路設備被連結至對應的路由器26時,網路設備會分別根據路由器26指派私有位址設置其網路位址(LAN埠口的網路位址)。Next, each of the public addresses of the routers 26a-26c performs a second network address translation (NAT) procedure to establish the second sub-domains 260a-260c. The router 26 assigns a network address (i.e., the network address of the LAN port) to each of the network devices 28a-28h by executing an automatic Dynamic Host Configuration Protocol (DHCP). When the network devices in the second sub-domains 260a-260c are connected to the corresponding routers 26, the network devices respectively set their network addresses according to the router 26 assigning a private address (the network of the LAN port) Address).

舉例來說,視訊門鈴28a會於連結路由器26a時,透過路由器26a自動執行進行動態主機配置協定程序獲取對應的私有位址192.168.0.1,其中視訊門鈴28a的私有位址192.168.0.1與路由器26a的LAN埠位址192.168.0.251處於相同頻段。監控系統28b於連結路由器26a獲取對應的私有位址192.168.0.2,以此類推。For example, when the gateway door 26a is connected to the router 26a, the dynamic host configuration protocol is automatically executed by the router 26a to obtain the corresponding private address 192.168.0.1, wherein the private address of the video doorbell 28a is 192.168.0.1 and the router 26a. The LAN埠 address 192.168.0.251 is in the same frequency band. Monitoring system 28b obtains the corresponding private address 192.168.0.2 at link router 26a, and so on.

當路由器26a~26c分別完成第二子網域260a~260c中各該網路設備,例如視訊門鈴28a、監控系統28b、緊急通訊系統28c、門禁系統28d、監控錄影機1號28e、監控錄影機2號28f、監控錄影機3號28g及監控錄影機4號28h等的位址配置程序時會產生對應第二子網域260a~360c的位址分配表,且路由器260a~360c會分別經上層路由器24透過網路22,以郵件方式將個別對應第二子網域260a~260c的位址分配表傳送至遠端伺服系統20,以供遠端伺服系統20的管理者進行管理。所述第二子網域260的位址分配表記錄第二子網域260中各網路設備的私有位址(即LAN 埠口的網路位址)。When the routers 26a-26c respectively complete the network devices in the second sub-domains 260a-260c, such as the video doorbell 28a, the monitoring system 28b, the emergency communication system 28c, the access control system 28d, the surveillance video recorder No. 1 28e, the surveillance video recorder The address allocation table corresponding to the second sub-domains 260a-360c is generated when the address configuration program of the No. 2 28f, the monitoring video recorder No. 3 28g, and the monitoring video recorder No. 4 28h, and the routers 260a to 360c pass through the upper layer respectively. The router 24 transmits the address allocation table of the corresponding second sub-domains 260a-260c to the remote server system 20 via the network 22 for management by the administrator of the remote server system 20. The address allocation table of the second sub-domain 260 records the private address of each network device in the second sub-domain 260 (ie, LAN) The network address of the port).

據此,遠端伺服系統20可獲取第二子網域260a~260c中各該網路設備的通訊路徑。遠端伺服系統20另可透過第一子網域240的位址分配表連結至路由器26a~26c,以瀏覽路由器26a~26c提供的監控網頁,監控各該網路設備,例如監控各該網路設備的運作或是遠端操作各該網路設備等。遠端伺服系統20還可直接透過位址分配表連結各該網路設備,以進行網路設備,位址設定或修正。舉例來說,遠端伺服系統20的管理者可直接連結上層路由器24的網路位址220.123.1.1、路由器26a的網路位址192.168.1.1,及視訊門鈴的網路位址192.168.0.1與視訊門鈴連結進行通訊或裝置設定等。從而,可解決習知的保全系統架構因無法登入路由器建立的子網域直接與網路設備連線,而無法有效掌控網路設備的運作。Accordingly, the remote servo system 20 can obtain the communication path of each of the network devices in the second sub-domains 260a-260c. The remote server system 20 can also be connected to the routers 26a-26c through the address allocation table of the first sub-domain 240 to browse the monitoring webpages provided by the routers 26a-26c, and monitor each network device, for example, monitor each network. The operation of the device or the remote operation of each of the network devices. The remote server system 20 can also directly connect the network devices through the address allocation table to perform network device, address setting or correction. For example, the administrator of the remote server system 20 can directly connect the network address 220.123.1.1 of the upper router 24, the network address 192.168.1.1 of the router 26a, and the network address 192.168.0.1 of the video doorbell. The video doorbell is connected for communication or device settings. Therefore, the conventional security system architecture can be directly connected to the network device because the subdomain established by the router cannot be directly connected to the network device, and the operation of the network device cannot be effectively controlled.

上層路由器24與路由器26a~26c還可分別於第一子網域240與第二子網域260a~260c發生變動時,例如更換路由器或網路設備時,自動重新配置位址,更新位址分配表。同時,即時地主動將位址分配表傳送至遠端伺服系統20。藉此,可避免習知的保全系統需透過用戶端個別登入路由器來對相應子網域中的網路設備的網路位址進行修正或配置等繁雜程序,從而亦可降低保全系統的安裝上的複雜度。When the upper router 24 and the routers 26a-26c can also change between the first subdomain 240 and the second subdomains 260a to 260c, for example, when the router or the network device is replaced, the address is automatically reconfigured, and the address allocation is updated. table. At the same time, the address allocation table is actively transmitted to the remote servo system 20 in real time. Therefore, it can be avoided that the conventional security system needs to manually modify the network address of the network device in the corresponding sub-domain through the user to log in to the router, and the complicated program can be modified, thereby reducing the installation of the security system. The complexity.

另外,上層路由器24與路由器26a~26c的至少其中之一可以如前述透過內建或外接的外掛伺服模組,建立並提供網路電話通訊網路。更進一步地說,上層路由器24與路由器26a~26c的至少其中之一可於建構區域網路的同時建立網路電話通訊網路,並提供網路電話登錄介面,以供廣域網路(例如遠端伺服系統20的管理者)以及區域網域(例如第二子網域260a~260c內該些網路設備(如視訊門鈴28a、監控系統28b、緊急通訊系統28c、門禁系統28d、監控錄影機1號28e、監控錄影機2號28f、監控錄影機3 號28g及監控錄影機4號28h等的操作者)的使用者註冊以加入私有網路電話通訊網路,進而可進行網路電話通訊與數據傳遞等功能。換言之,保全系統2可以建立私有的網路電話通訊環境,且不需加入或透過外部網路電路供應廠商的所提供的網路電話介面,簡化使用者建構私有網路環境的複雜度並降低設備成本,同時亦提高管理效能。In addition, at least one of the upper router 24 and the routers 26a-26c can establish and provide a network telephone communication network through the built-in or external plug-in servo module as described above. Furthermore, at least one of the upper router 24 and the routers 26a-26c can establish a network telephone communication network while constructing the regional network, and provide a network telephone login interface for the wide area network (for example, remote servo The administrator of the system 20) and the regional domain (for example, the network devices in the second sub-domains 260a-260c (such as the video doorbell 28a, the monitoring system 28b, the emergency communication system 28c, the access control system 28d, the monitoring video recorder No. 1) 28e, surveillance video recorder 2nd 28f, surveillance video recorder 3 The user of No. 28g and the operator of the monitoring video recorder No. 4, 28h, etc., registers to join the private network telephone communication network, thereby enabling functions such as network telephone communication and data transmission. In other words, the security system 2 can establish a private network telephone communication environment, and does not need to join or through the external network circuit provider's provided network telephone interface, simplifying the complexity of the user to construct the private network environment and reducing the equipment. Cost, while also improving management efficiency.

綜上所述,本發明實施例所提供的路由器與保全系統,此路由器是應用於保全系統中,且可於建立相應的保全系統中子網域的同時,將與路由器連接的網路設備的位址分配表主動傳送遠端伺服器,以供遠端伺服器的管理者獲取網路設備的網路位址。從而,遠端伺服器的管理者可根據位址分配表中網路設備的網路位址直接連結網路設備,以對網路設備的位址進行配置與監控網路設備。遠端伺服器的管理者還可透過與路由器連結,瀏覽路由器所提供的監控網頁,以對網路設備進行運作監控。In summary, the router and the security system provided by the embodiments of the present invention are used in the security system, and can establish a corresponding subnet domain in the security system while the network device connected to the router is The address allocation table actively transmits the remote server for the remote server manager to obtain the network address of the network device. Therefore, the remote server administrator can directly connect the network device according to the network address of the network device in the address allocation table to configure and monitor the network device address of the network device. The remote server administrator can also connect to the router to browse the monitoring webpage provided by the router to monitor the operation of the network device.

此外,本發明實施例所提供的路由器另可作為網路通話伺服器,提供網路通話伺服功能。從而,路由器的使用者,例如個人或企業,可在不需額外建立網路電話的伺服系統,也不需租用雲端的伺服器系統的情況下,自行架構私有網路電話環境,進行網路電話通訊,簡化使用者建構私有網路環境的複雜度與成本,同時提升保全系統管理效益。據此,本發明實施例所提供的路由器可增加保全系統的安裝與管控便利性,並提升保全系統的監控效益。In addition, the router provided by the embodiment of the present invention can also be used as a network call server to provide a network call servo function. Therefore, the user of the router, such as an individual or a company, can construct a private network telephone environment and perform network telephone without requiring an additional network telephone server or a cloud server system. Communication simplifies the complexity and cost of building a private network environment, while improving the security of the system. Accordingly, the router provided by the embodiment of the present invention can increase the installation and control convenience of the security system, and improve the monitoring efficiency of the security system.

以上所述僅為本發明之實施例,其並非用以侷限本發明之專利範圍。The above description is only an embodiment of the present invention, and is not intended to limit the scope of the invention.

10‧‧‧遠端伺服系統10‧‧‧Remote servo system

16‧‧‧路由器16‧‧‧ router

162‧‧‧路由器模組162‧‧‧ router module

164‧‧‧網路模組164‧‧‧Network Module

166‧‧‧外掛伺服模組166‧‧‧External Servo Module

1662‧‧‧中央處理單元1662‧‧‧Central Processing Unit

1664‧‧‧內部網路模組1664‧‧‧Internal network module

1666‧‧‧記憶單元1666‧‧‧ memory unit

18a~18d‧‧‧網路設備18a~18d‧‧‧Network equipment

Claims (14)

一種路由器,適用於連接於一上層路由器與多個網路設備之間,該上層路由器進行一第一網路位址轉換(NAT)程序以建立一第一子網域並指派一第一私有位址給該路由器,該路由器包括:一路由器模組,耦接於該上層路由器與該些網路設備,將該第一私有位址設定為一公有位址,並基於該公有位址進行一第二網路位址轉換(NAT)程序以建立一第二子網域;一網路模組,耦接於該路由器模組;以及一外掛伺服模組,經由該網路模組耦接於該路由器模組,用以取得該路由器中的一位址分配表,並經由該路由模組將該位址分配表傳送至一遠端伺服系統;其中,該路由器位於該第一子網域中,該些網路設備位於該第二子網域中,該位址分配表記錄對應於該些網路設備的多個網路位址。 A router adapted to be connected between an upper layer router and a plurality of network devices, wherein the upper layer router performs a first network address translation (NAT) procedure to establish a first subdomain and assign a first private bit Addressing the router, the router includes: a router module coupled to the upper router and the network devices, the first private address is set to a public address, and the first address is performed based on the public address a network address translation (NAT) program to establish a second subdomain; a network module coupled to the router module; and an external servo module coupled to the network module a router module, configured to obtain an address allocation table in the router, and transmit the address allocation table to a remote server through the routing module; wherein the router is located in the first subdomain The network devices are located in the second subnet domain, and the address allocation table records a plurality of network addresses corresponding to the network devices. 如申請專利範圍第1項所述的路由器,其中該網路模組為一區域網路模組,具有一網路接口以連接至該外掛伺服模組。 The router of claim 1, wherein the network module is a regional network module having a network interface for connecting to the external servo module. 如申請專利範圍第1項所述的路由器,其中該外掛伺服模組、該路由器模組與該網路模組整合於一路由器殼體之中。 The router of claim 1, wherein the external servo module, the router module and the network module are integrated in a router housing. 如申請專利範圍第1項所述的路由器,其中該外掛伺服模組包括:一中央處理單元;一記憶單元,耦接於該中央處理單元;以及一內部網路模組,耦接於該中央處理員與該網路模組。 The router of claim 1, wherein the external servo module comprises: a central processing unit; a memory unit coupled to the central processing unit; and an internal network module coupled to the central unit The handler and the network module. 如申請專利範圍第1項所述的路由器,其中該外掛伺服模組係以郵件方式將該位址分配表傳送至該遠端伺服系統。 The router of claim 1, wherein the external server module transmits the address allocation table to the remote server system by mail. 如申請專利範圍第1項所述的路由器,其中該路由器在該些網路設備被連接至該路由器模組時,自動進行一動態主機配置協 定程序(Dynamic Host Configuration Protocol)以分派網路位址至該些網路設備的每一個。 The router of claim 1, wherein the router automatically performs a dynamic host configuration protocol when the network devices are connected to the router module. The Dynamic Host Configuration Protocol assigns network addresses to each of these network devices. 如申請專利範圍第1項所述的路由器,其中該外掛伺服模組為一網路電話伺服器,可提供一網路電話登錄介面,供一使用者註冊以加入一私有網路電話網路。 The router of claim 1, wherein the plug-in server module is a network phone server, and provides a network phone login interface for a user to register to join a private network phone network. 一種保全系統,包括:一遠端伺服系統;一上層路由器,經由網路連接至該遠端伺服系統,用以進行一第一網路位址轉換(NAT)程序以建立一第一子網域;以及複數個路由器,經由網路連接至該上層路由器,其中各該路由器包括:一路由器模組,耦接於該上層路由器與複數個網路設備,將自該上層路由器取得的一第一私有位址設定為一公有位址,並基於該公有位址進行一第二網路位址轉換(NAT)程序以建立一第二子網域;一網路模組,耦接於該路由器模組;以及一外掛伺服模組,經由該網路模組耦接於該路由器模組,用以取得該路由器中的一位址分配表,並經由該路由模組將該位址分配表傳送至一遠端伺服系統;其中,該路由器位於該第一子網域中,該些網路設備位於該第二子網域中,該位址分配表記錄對應於該些網路設備的多個網路位址。 A security system includes: a remote servo system; an upper router connected to the remote servo system via a network for performing a first network address translation (NAT) procedure to establish a first subdomain And a plurality of routers connected to the upper router via a network, wherein each of the routers includes: a router module coupled to the upper router and the plurality of network devices, and a first private device obtained from the upper router The address is set to a public address, and a second network address translation (NAT) procedure is performed based on the public address to establish a second subdomain; a network module coupled to the router module And an external servo module coupled to the router module via the network module for obtaining an address allocation table in the router, and transmitting the address allocation table to the router through the routing module a remote servo system; wherein the router is located in the first sub-domain, the network devices are located in the second sub-domain, and the address allocation table records a plurality of networks corresponding to the network devices Address. 如申請專利範圍第8項所述的保全系統,其中該網路模組為一區域網路模組,具有一網路接口以連接至該外掛伺服模組。 The security system of claim 8, wherein the network module is a regional network module having a network interface for connecting to the external servo module. 如申請專利範圍第8項所述的保全系統,其中該外掛伺服模組、該路由器模組與該網路模組整合於一路由器殼體之中。 The security system of claim 8, wherein the external servo module, the router module and the network module are integrated in a router housing. 如申請專利範圍第8項所述的保全系統,其中該外掛伺服模組包括: 一中央處理單元;一記憶單元,耦接於該中央處理單元;以及一內部網路模組,耦接於該中央處理員與該網路模組。 The security system of claim 8, wherein the external servo module comprises: A central processing unit; a memory unit coupled to the central processing unit; and an internal network module coupled to the central processing unit and the network module. 如申請專利範圍第8項所述的保全系統,其中該外掛伺服模組係以郵件方式將該位址分配表傳送至該遠端伺服系統。 The security system of claim 8, wherein the external servo module transmits the address allocation table to the remote server system by mail. 如申請專利範圍第8項所述的保全系統,其中該路由器在該些網路設備被連接至該路由器模組時,自動進行一動態主機配置協定程序(Dynamic Host Configuration Protocol)以分派網路位址至該些網路設備的每一個。 The security system of claim 8, wherein the router automatically performs a dynamic host configuration protocol (Dynamic Host Configuration Protocol) to allocate network bits when the network devices are connected to the router module. Address each of these network devices. 如申請專利範圍第8項所述的保全系統,其中該外掛伺服模組為一網路電話伺服器,可提供一網路電話登錄介面,供一使用者註冊以加入一私有網路電話網路。 The security system of claim 8, wherein the external servo module is a network telephone server, and provides a network telephone login interface for a user to register to join a private network telephone network. .
TW102106233A 2013-02-22 2013-02-22 Router and security system using the same TWI491209B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW102106233A TWI491209B (en) 2013-02-22 2013-02-22 Router and security system using the same

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW102106233A TWI491209B (en) 2013-02-22 2013-02-22 Router and security system using the same

Publications (2)

Publication Number Publication Date
TW201434295A TW201434295A (en) 2014-09-01
TWI491209B true TWI491209B (en) 2015-07-01

Family

ID=51943051

Family Applications (1)

Application Number Title Priority Date Filing Date
TW102106233A TWI491209B (en) 2013-02-22 2013-02-22 Router and security system using the same

Country Status (1)

Country Link
TW (1) TWI491209B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI614725B (en) * 2015-05-28 2018-02-11 Cloud access control system

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW574805B (en) * 2002-07-25 2004-02-01 Leadtek Research Inc Network address translation system and method thereof
US20090073987A1 (en) * 2007-09-14 2009-03-19 At&T Knowledge Ventures, Lp Methods and Systems for Network Address Translation Management
TW200924462A (en) * 2007-11-27 2009-06-01 Ind Tech Res Inst System and method for connection of hosts behind NATs

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TW574805B (en) * 2002-07-25 2004-02-01 Leadtek Research Inc Network address translation system and method thereof
US20090073987A1 (en) * 2007-09-14 2009-03-19 At&T Knowledge Ventures, Lp Methods and Systems for Network Address Translation Management
TW200924462A (en) * 2007-11-27 2009-06-01 Ind Tech Res Inst System and method for connection of hosts behind NATs

Also Published As

Publication number Publication date
TW201434295A (en) 2014-09-01

Similar Documents

Publication Publication Date Title
JP3749720B2 (en) Device and method for connecting between network devices in different home networks
KR100942480B1 (en) A communication device and a system for managing the local devies remotely and the method thereof
US9369448B2 (en) Network security parameter generation and distribution
JP2004510358A (en) Method and apparatus for handling network data transmission
US8543674B2 (en) Configuration of routers for DHCP service requests
CN105376299B (en) Network communication method, equipment and network attached storage equipment
US20090049164A1 (en) Peer-to-peer communication method and system enabling call and arrival
CN104468625B (en) Dialing tunnel agent device, the method for utilizing the tunnel pass through NAT that dials
EP3223498A1 (en) Method and apparatus for interconnection between networks
KR20020026745A (en) IP based network system and networking method thereof
CN105635335A (en) Social resource access method, apparatus, and system
JP2009010606A (en) Tunnel connection system, tunnel control server, tunnel connecting device, and tunnel connection method
CN1929601A (en) New pattern visible intercommunication system
TWI491209B (en) Router and security system using the same
CN1561061A (en) Method for two-way access by NAT
US9774468B2 (en) Home communication network
JPH1013471A (en) Inter-network connection system and domain name managing method
US20050044271A1 (en) Method for allocating a non-data device to a voice vlan object of the invention
KR100853587B1 (en) IP share device which can make it possible to use the network system of the communication terminal without any change and the connection method thereby
KR100482300B1 (en) Internet service providing system for many small subscribers through LAN and method for providing internet service, using the system
KR100546023B1 (en) Communication method between network devices
CN104917719A (en) User-side network equipment and remote login method
KR20070061036A (en) Apparatus and method for sharing media inter homenetworks
US20220158976A1 (en) Method And Apparatus For Remote Network Management
KR101807695B1 (en) Mobile communication router apparatus and ip sharing system comprising the same