KR101572191B1 - IP camera router, routing method for providing image of IP camera and computer program - Google Patents
IP camera router, routing method for providing image of IP camera and computer program Download PDFInfo
- Publication number
- KR101572191B1 KR101572191B1 KR1020150071728A KR20150071728A KR101572191B1 KR 101572191 B1 KR101572191 B1 KR 101572191B1 KR 1020150071728 A KR1020150071728 A KR 1020150071728A KR 20150071728 A KR20150071728 A KR 20150071728A KR 101572191 B1 KR101572191 B1 KR 101572191B1
- Authority
- KR
- South Korea
- Prior art keywords
- camera
- address
- communication port
- request message
- forwarding
- Prior art date
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0281—Proxies
-
- H04L61/2007—
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/18—Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
Abstract
A routing method for providing an IP camera router and an IP camera image is disclosed. The first network interface unit is connected to the external network and receives an address request message requesting an address of the IP camera from the user apparatus through the external network. The second network interface unit is connected to the internal network. The control unit allocates a communication port for forwarding to the IP address and the communication port of one or more IP cameras connected to the internal network, changes the allocated forwarding communication port according to preset update information, and responds to the address request message The IP address of the first network interface unit, and the address information including the IP address of the requested IP camera and the communication port for forwarding assigned to the communication port are transmitted to the user device through the external network, When receiving a video request message for requesting an IP camera video for the IP address included in the information and the forwarding communication port from the user device, the IP address and the communication port of the forwarding communication port, And controls the request message to be forwarded.
Description
The present invention relates to an IP camera router and a routing method for providing an IP camera image, and more particularly, to an IP camera router and an IP camera image providing an image of an IP camera connected to an internal network to a user device connected to an external network To a routing method.
The IP camera provides images captured by a wired / wireless network connected to the camera, and includes a camera, a camera module, a decoder, an image compression chip, a CPU, and a network transmission chip. The analog video signal output from the camera module is converted into a digital video signal through a decoder, and the digital video signal is compressed and transmitted from the compression chip.
The IP camera is connected to an internal network (private IP network). A user located at a remote location from the internal network accesses an IP camera through an external network (public IP network) such as the Internet, Receive. Port forwarding is used for connection between the external network and the internal network. Port forwarding is a function that sends a packet to a specific port on the external network side by changing the port to the internal network side. Patent document 10-1241736 (published on March 11, 2013) and Korean Patent No. 10-1205690 (published on November 28, 2012) disclose such a patent document that utilizes such port forwarding in an IP camera.
However, Korean Patent No. 10-1241736 and Korean Patent No. 10-1205690 only mention the convenience of connection of an IP camera connected to an internal network through an external network, and are silent about the security problem blocking arbitrary user access have. When an arbitrary user is able to access the IP camera, problems such as invasion of privacy and leakage of personal information occur, and there is a high possibility that an offense is abused.
In order to prevent this, an IP camera having a function of conducting an authentication procedure at the time of connection is being released. However, it is common for the general user to use the IP camera without setting the password of the IP camera because of troubles and difficulties in configuration and inconvenience in management and use.
Korean Patent Laid-Open No. 10-2005-0093071 (published on September 23, 2005) discloses a method of placing a separate server for performing user authentication. However, in the case where an unauthorized user directly obtains access information of the IP camera, Korean Patent Laid-Open No. 10-2005-0093071 (published on September 23, 2005) discloses a method of preventing unauthorized access to an IP camera There is no.
SUMMARY OF THE INVENTION It is an object of the present invention to provide a method and system for preventing an unauthorized user from accessing an IP camera without accessing an IP camera, And to provide an IP camera router and a routing method for providing an IP camera image that can prevent reconnection and reception of images of an IP camera even if an unauthorized user obtains access information to the IP camera have.
It is another object of the present invention to provide an IP camera router capable of preventing an IP camera image from being exposed even when connection information of an IP camera is leaked to an unauthorized user, Method.
It is another object of the present invention to provide an IP camera router and a routing method for providing an IP camera image that can block access to an IP camera at a specific time.
According to an aspect of the present invention, there is provided an IP camera router including a first network interface unit connected to an external network and receiving an address request message requesting an address of an IP camera from a user apparatus through the external network, A second network interface unit connected to the internal network, and a communication port for forwarding to an IP address and a communication port of one or more IP cameras connected to the internal network, wherein the allocated forwarding communication port is set in advance In response to the address request message, an IP address of the first network interface unit and an address information including an IP address of the requested IP camera and a communication port for forwarding assigned to the communication port in response to the address request message To be transmitted to the user apparatus through the external network, When receiving a video request message requesting an IP camera image for an IP address and a forwarding communication port from the user device, And controlling the message to be forwarded.
Wherein the control unit checks whether the current time corresponds to the allowed time for the forwarding communication port when receiving the video request message, and if the current time corresponds to the allowed time, causes the video request message to be forwarded And if it does not correspond to the allowed time, forwarding of the video request message may be blocked.
Wherein the second network interface unit receives the streaming packet from the IP camera that has received the forwarded video request message and the control unit encrypts the received streaming packet and transmits the encrypted streaming packet through the external network To the user device, and in response to the address request message, control the security key for decrypting the streaming packet to be further transmitted to the user device.
Wherein the second network interface unit receives the streaming packet from the IP camera that has received the forwarded video request message and the control unit encrypts the received streaming packet and decrypts the streaming packet in the encrypted streaming packet And transmits the added security key to the user device via the external network.
The update information may include at least one of update interval information indicating a change interval of the forwarding communication port and update rule information indicating a change rule of the forwarding communication port.
According to another aspect of the present invention, there is provided a routing method for providing an IP camera image, the method comprising: assigning a communication port for forwarding to an IP address and a communication port of one or more IP cameras connected to an internal network; Receiving an address request message for requesting an address of an IP camera from a user device via an external network, and receiving, in response to the address request message, Transmitting address information including an IP address of the IP camera router and an IP address of the requested IP camera and a communication port for forwarding assigned to the communication port to the user device via the external network; The IP address included in the transmitted address information and the IP camera address for the forwarding communication port The method comprising: receiving a video request message for requesting a video request message, and, when receiving the video request message, forwarding the video request message to an IP address and a communication port to which a communication port for forwarding included in the address information is allocated .
The method may further include the steps of: checking whether the current time corresponds to the allowed time for the forwarding communication port when the video request message is received; if the current time does not correspond to the allowed time, And forwarding the video request message to the mobile terminal when the mobile terminal is in the allowed time.
The method includes receiving a streaming packet from an IP camera that has received the forwarded video request message, encrypting the received streaming packet, and transmitting the encrypted streaming packet to the user device over the external network Wherein the step of transmitting the address information may include transmitting a secret key for decrypting the streaming packet to the user device.
The method includes receiving a streaming packet from an IP camera that has received the forwarded video request message, encrypting the received streaming packet, and adding a security key for decrypting the streaming packet to the encrypted streaming packet And transmitting the stringing packet added with the secret key to the user device via the external network.
The update information may include at least one of update interval information indicating a change interval of the forwarding communication port and update rule information indicating a change rule of the forwarding communication port.
According to the IP camera router and the routing method for providing the IP camera image according to the present invention, since the IP camera router relays the access of the IP camera, the user of the external network can prevent direct access to the IP camera, It is possible to prevent the unauthorized user from accessing the IP camera even if the authentication process is not performed at the connection of the IP camera router and the IP camera IP address of the IP camera is not directly exposed to the external network due to the IP camera router, It is possible to prevent information about the camera from being acquired directly from the IP camera. Since the IP camera router periodically changes the forwarding port assigned to the IP camera, the user who has obtained the connection information reconnects and receives the image of the IP camera Can be prevented. In addition, since the IP camera router provides the image of the IP camera by encrypting it, it is possible to prevent the image of the IP camera from being exposed even if the unauthorized user obtains the connection information. In addition, the IP camera router can block the connection to the IP camera in a specific time period by forwarding the video request message only during the permission period.
1 is a configuration diagram showing a configuration of a preferred embodiment of an IP camera image providing system according to the present invention.
2 is a block diagram showing a configuration of a preferred embodiment of an IP camera router according to the present invention.
3 is a diagram illustrating an embodiment of a forwarding table.
FIG. 4 is a diagram illustrating an embodiment in which the forwarding table shown in FIG. 3 is updated.
5 is a configuration diagram showing a configuration of another preferred embodiment of the IP camera image providing system according to the present invention.
6 is a diagram showing another embodiment of the forwarding table.
7 is a diagram illustrating an embodiment in which the forwarding table shown in FIG. 6 is updated.
FIG. 8 is a flowchart illustrating a procedure of a preferred embodiment of a routing method for providing an IP camera image according to the present invention.
Hereinafter, an IP camera router according to the present invention and a routing method for providing an IP camera image will be described in detail with reference to the accompanying drawings. The structure and operation of the present invention shown in the drawings and described by the drawings are described as at least one embodiment, and the technical ideas and the core structure and operation of the present invention are not limited thereby.
Although the terms used in the present invention have been selected in consideration of the functions of the present invention, it is possible to use general terms that are currently widely used, but this may vary depending on the intention or custom of a person skilled in the art or the emergence of new technology. Also, in certain cases, there may be a term selected arbitrarily by the applicant, in which case the meaning thereof will be described in detail in the description of the corresponding invention. Therefore, it is to be understood that the term used in the present invention should be defined based on the meaning of the term rather than the name of the term, and on the contents of the present invention throughout.
1 is a configuration diagram showing a configuration of a preferred embodiment of an IP camera image providing system according to the present invention.
Referring to FIG. 1, an IP camera
The
The
The
The
The external network (3) may be composed of a backbone network and a subscriber network. The backbone network may be composed of one or a plurality of integrated networks of X.25 network, Frame Relay network, ATM network, MPLS (Multi Protocol Label Switching) network and GMPLS (Generalized Multi Protocol Label Switching) network. The subscriber network may be a fiber to the home (FTTH), an asymmetric digital subscriber line (ADSL), a cable network, a wireless LAN (IEEE 802.11b, IEEE 802.11a, IEEE 802.11g, IEEE 802.11n), WIBro HSDPA (High Speed Downlink Packet Access). In some embodiments, the
The
Also, the
2 is a block diagram showing a configuration of a preferred embodiment of an IP camera router according to the present invention.
Referring to FIG. 2, the
The first
The first
The second
The
The
The
The
When the first
When the first
In some embodiments, when the first
In addition, when the second
The
3 is a diagram illustrating an embodiment of a forwarding table.
Referring to FIG. 3, the forwarding table 300 may include a camera address and a virtual address (router address) of the
When the video request message includes the virtual address "rtsp: // id: pw@129.209.223.142: 1001 / onvif / viewurl ", the
FIG. 4 is a diagram illustrating an embodiment in which the forwarding table shown in FIG. 3 is updated.
Referring to FIG. 4, the
When the forwarding table 300 is updated with the forwarding table 400, the video request message including the virtual address "rtsp: // id: pw@129.209.223.142: 1001 / onvif / viewurl" is not forwarded. Therefore, in order to receive the image of the
5 is a configuration diagram showing a configuration of another preferred embodiment of the IP camera image providing system according to the present invention.
5, the IP camera image providing system 1 'includes a
The
The first
The
6 is a diagram showing another embodiment of the forwarding table.
Referring to FIG. 6, the forwarding table 600 may include a router address, a camera address and a virtual address (router address) of the
When the
If the video request message includes the virtual address "rtsp: // id: pw@192.168.11.1: 1001 / onvif / viewurl ", the
7 is a diagram illustrating an embodiment in which the forwarding table shown in FIG. 6 is updated.
Referring to FIG. 7, the
When the forwarding table 600 is updated with the forwarding table 700, the video request message including the router address "rtsp: // id: pw@129.209.223.142: 1001 / onvif / viewurl" 223.142 "is forwarded from the
FIG. 8 is a flowchart illustrating a procedure of a preferred embodiment of a routing method for providing an IP camera image according to the present invention.
Referring to FIG. 8, the
In response to receiving the search request message, the
The
The
The
The
The
The
In response to the address request message, the
The
Upon receiving the video request message, the
If so, the
The
The
In some embodiments, the
The
If it does not correspond to the allowable time, the
The
In step S185, the
The
The
The present invention can also be embodied as computer-readable codes on a computer-readable recording medium. A computer-readable recording medium includes all kinds of recording apparatuses in which data that can be read by a computer system is stored. Examples of the computer-readable recording medium include a ROM, a RAM, a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, and the like, and may be implemented in the form of a carrier wave (for example, transmission via the Internet) . The computer-readable recording medium may also be distributed over a networked computer system so that computer readable code can be stored and executed in a distributed manner.
While the present invention has been particularly shown and described with reference to exemplary embodiments thereof, it is clearly understood that the same is by way of illustration and example only and is not to be taken by way of limitation in the embodiment in which said invention is directed. It will be understood by those skilled in the art that various changes in form and detail may be made therein without departing from the scope of the appended claims.
Claims (11)
A second network interface unit connected to the internal network; And
Assigning a communication port for forwarding to an IP address and a communication port of one or more IP cameras connected to the internal network, periodically changing the assigned forwarding communication port according to preset update information,
Address information including an IP address of the first network interface unit and a forwarding communication port allocated to an IP address of a requested IP camera and a communication port in response to the address request message, To be transmitted to the user device,
When receiving an image request message for requesting an IP camera image for an IP address and a communication port for forwarding from the user device, the IP address of the communication port for forwarding included in the address information, And controlling the video request message to be forwarded to the IP address and the communication port of the IP camera router.
Wherein,
When receiving the video request message, checking whether the current time corresponds to the allowed time for the forwarding communication port, controlling the video request message to be forwarded if the current time corresponds to the allowed time, And prohibits the forwarding of the video request message if the IP address is not within the allowed time.
Wherein the second network interface unit comprises:
Receives a streaming packet from an IP camera that has received the forwarded video request message,
Wherein,
Encrypts the received streaming packet, controls the encrypted streaming packet to be transmitted to the user device via the external network, and in response to the address request message, transmits a secret key for decrypting the streaming packet to the user device To the IP camera router.
Wherein the second network interface unit comprises:
Receives a streaming packet from an IP camera that has received the forwarded video request message,
Wherein,
Encrypts the received streaming packet, adds a security key for decrypting the streaming packet to the encrypted streaming packet, and transmits the encrypted streaming packet to the user device via the external network.
The update information includes:
An updating interval information indicating an interval of changing the forwarding communication port, and an updating rule information indicating a changing rule of the forwarding communication port.
Periodically changing the assigned communication port for forwarding according to preset update information;
Receiving an address request message requesting an IP camera address from a user device via an external network;
In response to the address request message, address information including an IP address of the IP camera router for the external network and an IP address of the requested IP camera and a communication port for forwarding assigned to the communication port, To the user device via the network;
Receiving an image request message for requesting an IP camera image for an IP address and a forwarding communication port included in the transmitted address information from the user device through the external network; And
And forwarding the video request message to an IP address and a communication port to which the forwarding communication port included in the address information is allocated when the video request message is received. For routing.
Confirming whether the current time corresponds to the allowed time for the forwarding communication port when the video request message is received; And
And blocking the forwarding of the video request message if it does not correspond to the allowed time,
Wherein the step of forwarding the video request message is performed when the video frame corresponds to the allowed time.
Receiving a streaming packet from an IP camera that has received the forwarded video request message;
Encrypting the received streaming packet; And
Further comprising transmitting the encrypted streaming packet to the user device via the external network,
Wherein the step of transmitting the address information comprises:
And transmitting a security key for decrypting the streaming packet to the user device.
Receiving a streaming packet from an IP camera that has received the forwarded video request message;
Encrypting the received streaming packet and adding a security key for decrypting the streaming packet to the encrypted streaming packet; And
Further comprising the step of transmitting a stringing packet to which the secret key is added to the user equipment through the external network.
The update information includes:
Wherein the forwarding communication port includes at least one of update interval information indicating a changing interval of the forwarding communication port and updating rule information indicating a changing rule of the forwarding communication port.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020150071728A KR101572191B1 (en) | 2015-05-22 | 2015-05-22 | IP camera router, routing method for providing image of IP camera and computer program |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020150071728A KR101572191B1 (en) | 2015-05-22 | 2015-05-22 | IP camera router, routing method for providing image of IP camera and computer program |
Publications (1)
Publication Number | Publication Date |
---|---|
KR101572191B1 true KR101572191B1 (en) | 2015-11-27 |
Family
ID=54847750
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
KR1020150071728A KR101572191B1 (en) | 2015-05-22 | 2015-05-22 | IP camera router, routing method for providing image of IP camera and computer program |
Country Status (1)
Country | Link |
---|---|
KR (1) | KR101572191B1 (en) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR20180069462A (en) * | 2016-12-15 | 2018-06-25 | 한화에어로스페이스 주식회사 | Apparatus and method for registering camera |
CN115065856A (en) * | 2022-06-13 | 2022-09-16 | 深圳绿米联创科技有限公司 | Data display method and data display system |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2005033250A (en) | 2003-07-07 | 2005-02-03 | Matsushita Electric Ind Co Ltd | Relaying apparatus and port forward setting method |
JP2008048050A (en) | 2006-08-11 | 2008-02-28 | Hitachi Kokusai Electric Inc | Encrypted data communication system |
-
2015
- 2015-05-22 KR KR1020150071728A patent/KR101572191B1/en active IP Right Grant
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2005033250A (en) | 2003-07-07 | 2005-02-03 | Matsushita Electric Ind Co Ltd | Relaying apparatus and port forward setting method |
JP2008048050A (en) | 2006-08-11 | 2008-02-28 | Hitachi Kokusai Electric Inc | Encrypted data communication system |
Cited By (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
KR20180069462A (en) * | 2016-12-15 | 2018-06-25 | 한화에어로스페이스 주식회사 | Apparatus and method for registering camera |
KR102596485B1 (en) | 2016-12-15 | 2023-11-01 | 한화비전 주식회사 | Apparatus and method for registering camera |
CN115065856A (en) * | 2022-06-13 | 2022-09-16 | 深圳绿米联创科技有限公司 | Data display method and data display system |
CN115065856B (en) * | 2022-06-13 | 2024-05-03 | 深圳绿米联创科技有限公司 | Data display method and data display system |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108989848B (en) | Video resource file acquisition method and management system | |
CN103299313B (en) | Transfer management equipment, program, transmission and management system and transfer management method | |
EP3075096B1 (en) | Method and system for encrypted communications | |
CN110912880B (en) | Network distribution method and device, electronic equipment and storage medium | |
EP3748928A1 (en) | Method and system for apparatus awaiting network configuration to access hot spot network apparatus | |
EP4164175B1 (en) | Method for securely controlling smart home appliance and terminal device | |
KR101575222B1 (en) | System, service provider device, service user device and method for providing image of IP camera and computer program | |
JP2007323553A (en) | Adapter device performing encrypted communication on network and ic card | |
US20150141061A1 (en) | Method for tracking a mobile device onto a remote displaying unit | |
EP2713547A1 (en) | Media resource access control method and device | |
US20160277369A1 (en) | Electronic device and communication method thereof | |
KR20090111256A (en) | Home network control apparatus and method to obtain encrypted control information | |
KR101847636B1 (en) | Method and apprapatus for watching encrypted traffic | |
KR101572191B1 (en) | IP camera router, routing method for providing image of IP camera and computer program | |
US20160105407A1 (en) | Information processing apparatus, terminal, information processing system, and information processing method | |
KR20150060050A (en) | Network device and method of forming tunnel of network device | |
KR20150018024A (en) | Data sharing method and data sharing system | |
KR101584986B1 (en) | A method for network access authentication | |
CN114390520A (en) | Key updating method, device, equipment and storage medium | |
CA2849174C (en) | System and method for the safe spontaneous transmission of confidential data over unsecure connections and switching computers | |
KR101837064B1 (en) | Apparatus and method for secure communication | |
CN114268492B (en) | Distribution method, distribution device, robot, equipment, medium and distribution system | |
JP2008123021A (en) | Digital information sharing system, digital information sharing server, terminal equipment, and digital information sharing method | |
CN108076456A (en) | A kind of WiFi communication data security protection method and system based on more passwords | |
JP2005242547A (en) | Remote service execution method, remote client, and remote service server |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
E701 | Decision to grant or registration of patent right | ||
GRNT | Written decision to grant | ||
FPAY | Annual fee payment |
Payment date: 20181002 Year of fee payment: 4 |
|
FPAY | Annual fee payment |
Payment date: 20191120 Year of fee payment: 5 |