Network system and processing method
Patent Information
- Application Number
- JP2025080955
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-09-19
AI Technical Summary
Existing technologies face challenges in accurately determining the location of devices using arbitrary IP addresses, which hinders the provision of various services.
A network system utilizing devices with a communication unit, memory unit, and determination unit that employs digital certificates with public keys to authenticate IP addresses, enabling the determination of location information through a hierarchical zone structure.
Enables the provision of authenticated location information, allowing for various services and secure data exchange among devices.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a network system consisting of devices with authenticated IP addresses, and a processing method in the device and network system. [Background technology]
[0002] Recent advances in information and communication technology (ICT) have been remarkable, and devices connected to networks such as the Internet are no longer limited to traditional information processing devices such as personal computers and smartphones, but are now expanding to include a wide variety of things. This technological trend is known as the "Internet of Things" (IoT), and a variety of technologies and services are being proposed and put into practical use. In the future, it is expected that billions of people and tens of billions or even trillions of devices on Earth will be connected simultaneously. To realize such a networked world, it is necessary to provide solutions that enable simpler, safer, and more free connections.
[0003] Information about the location of such devices is important in providing various services. For example, JP2012-504285A (Patent Document 1) discloses geolocation as a technology for identifying the actual geographical location of computers, mobile devices, website visitors, or other devices connected to the Internet. In particular, Patent Document 1 describes the use of geolocation technology to identify the actual geographical location of Internet-connected computers, mobile devices, website visitors, or other devices that are associated with changes in the IP (Internet Protocol) addresses assigned to residential customers. This paper discloses a technology that supports updating location information. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Special Publication No. 2012-504285 Summary of the Invention [Problem to be solved by the invention]
[0005] As disclosed in the above-mentioned Patent Document 1, it has been difficult to correctly determine the location information of a device by relying on a framework in which an arbitrary IP address is assigned to the device.
[0006] This disclosure provides a solution that solves these problems and enables the provision of various services using location information by adopting a framework that uses authenticated IP addresses. [Means for solving the problem]
[0007] According to an embodiment of the present disclosure, there is provided a network system including a plurality of devices. Each of the plurality of devices includes a communication unit for performing data communication with other devices, a memory unit for storing a digital certificate including a public key for determining an IP address of the device itself, and a determination unit for determining the IP address of the other device based on the public key included in the digital certificate received from the other device. The digital certificate includes location information associated with the corresponding device.
[0008] The location information may indicate any of the zones generated by dividing the zones hierarchically.
[0009] The location information may consist of a code that reflects the hierarchical structure of the zone in question. Any one of the multiple devices may request location information to be set on the device from another device associated with a zone at a higher level than the zone indicated by the location information associated with the device.
[0010] The network system may further include a certificate authority that, in response to a request from any one of the plurality of devices, signs a digital certificate to be stored in the requestor.
[0011] Any one of the multiple devices may exchange digital certificates with another device to establish a session, and then transmit information generated or collected by that device to the other device.
[0012] A first device of the plurality of devices may be configured to manage resources associated with the first device and may be configured to allocate at least a portion of the resources it manages in response to a request from a second device of the plurality of devices, and information regarding the allocation of resources may be shared between the first device and the second device.
[0013] Any one of the plurality of devices may respond to a request for the current location from another device by returning specific information for identifying the device associated with the current location.
[0014] Any one of the multiple devices may include a function for managing value that is compensation for goods or services.
[0015] According to another aspect of the present disclosure, there is provided a device constituting a network system. The device includes a communication unit for performing data communication with other devices, a storage unit for storing a digital certificate including a public key for determining an IP address of the device itself, and a determination unit for determining the IP address of the other device based on the public key included in the digital certificate received from the other device. The digital certificate includes location information associated with the corresponding device.
[0016] According to yet another aspect of the present disclosure, there is provided a processing method in a network system including first and second devices. The processing method includes the steps of: a first device transmitting a first digital certificate to a second device, the first digital certificate including a first public key for determining an IP address of the first device; a second device determining an IP address of the first device based on the first public key included in the first digital certificate received from the first device; a second device transmitting a second digital certificate to the first device, the second digital certificate including a second public key for determining an IP address of the second device; and a first device determining an IP address of the second device based on the second public key included in the second digital certificate received from the second device. The digital certificate includes location information associated with the corresponding device. [Effects of the Invention]
[0017] According to the present disclosure, authenticated location information of a device can be obtained, and various services can be provided using the authenticated location information. [Brief explanation of the drawings]
[0018] [Figure 1] 1 is a schematic diagram showing an example of an overall configuration of a network system according to an embodiment of the present invention; [Figure 2] FIG. 2 is a schematic diagram showing an example of a hardware configuration of a device included in a network system according to the present embodiment. [Figure 3] FIG. 10 is a diagram illustrating an example of IP address authentication processing in the network system according to the present embodiment. [Figure 4] FIG. 2 is a diagram showing an example of a digital certificate used in the network system according to the present embodiment. [Figure 5] FIG. 2 is a schematic diagram illustrating a zone ID used in the network system according to the present embodiment. [Figure 6]FIG. 2 is a schematic diagram for illustrating a coding system of a zone ID used in the network system according to the present embodiment. [Figure 7] FIG. 4 is a schematic diagram illustrating processing relating to setting of a zone ID in the network system according to the present embodiment. [Figure 8] FIG. 10 is a schematic diagram showing an example of an application that uses location information provided by the network system according to the present embodiment. [Figure 9] 9 is a sequence diagram showing a processing procedure for realizing the application shown in FIG. 8. [Figure 10] FIG. 10 is a schematic diagram showing another example of an application that uses location information provided by the network system according to the present embodiment. [Figure 11] FIG. 11 is a schematic diagram illustrating an example of a system configuration for realizing the application shown in FIG. [Figure 12] FIG. 11 is a schematic diagram for explaining resource management in the application shown in FIG. [Figure 13] FIG. 11 is a diagram showing an example of ticket information used in the application shown in FIG. [Figure 14] FIG. 11 is a sequence diagram showing a processing procedure for realizing the application shown in FIG. [Figure 15] FIG. 10 is a schematic diagram showing yet another example of an application that uses location information provided by the network system according to the present embodiment. [Figure 16] FIG. 16 is a schematic diagram showing route selection using the application shown in FIG. [Figure 17] FIG. 16 is a sequence diagram showing a processing procedure for realizing the application shown in FIG. DETAILED DESCRIPTION OF THE INVENTION
[0019] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present disclosure will be described in detail with reference to the accompanying drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals and the description thereof will not be repeated.
[0020] <Overall Configuration of Network System 1> First, the overall configuration of network system 1 according to this embodiment will be described. Network system 1 has a function of managing and providing the location information of one or more devices.
[0021] FIG. 1 is a schematic diagram showing an example of the overall configuration of network system 1 according to this embodiment. Referring to FIG. 1, network system 1 includes a plurality of devices 10, and each device 10 is associated with a physical location or range. The location or range associated with each device 10 may be the location or range where each device 10 actually exists, or the location or range where each device 10 manages or provides services.
[0022] In the example shown in FIG. 1, devices 10A1, 10B1, and 10C1 exist in association with three zones A, B, and C. In zone A, there are further devices 10A2, 10A3, and 10A4. In zone B, there are further devices 10B2, 10B3, 10B4, and 10B5. In zone C, there are further devices 10C2, 10C3, 10 C4. Note that each device may also be collectively referred to simply as "device 10".
[0023] In network system 1 according to this embodiment, the location information associated with each device 10 can be determined and provided.
[0024] Each device 10 has an authenticated IP address. In this specification, the term "authenticated IP address" refers to a state in which the legitimacy of the IP address held by each device 10 is guaranteed to the communication destination or a third party. More specifically, the term "authenticated IP address" refers to an IP address that is generated by an irreversible cryptographic hash function and is authenticated directly or indirectly by the certificate authority 2 (details will be described later). By using such an "authenticated IP address," it is possible to ensure that the IP address used by each device 10 for data communication is not forged.
[0025] As a result, any device 10 included in the network system 1 is uniquely identified based on the IP address of each device 10. That is, the IP address of each device itself serves as identification information for each device, and therefore, location information and related information can be determined and provided based on the identification information (i.e., IP address) of each device 10.
[0026] The IP address is assumed to be a global IP address that can be used for data communication between devices 10 connected to the Internet, but it may also be a private IP address that is used only within a specific network. The number of bits that make up the IP address varies depending on the version. The currently established IPv4 (Internet Protocol Version 4) specifies a 32-bit address range, and currently In the established IPv6 (Internet Protocol Version 6), a 128-bit In this embodiment, the IP address conforming to IPv6 will be mainly described. However, the present disclosure can also be applied to network addresses defined by a larger number of bits or a smaller number of bits.
[0027] In this specification, the term "device" refers to any device that has the ability to communicate with other devices using its own IP address. The device 10 may be configured as a standalone communication device, or may be configured as part of or incorporated into some other object.
[0028] More specifically, the device 10 may be, for example, a personal computer, a smartphone, a tablet, or a wearable device (for example, a smart watch or AR glasses) attached to a user's body (for example, an arm or a head). The device 10 may also be a control device or a part thereof installed in a smart home appliance, a connected automobile, a factory, or the like.
[0029] The network system 1 may further include one or more certification authorities 2. Each of the certification authorities 2 may be a computer configured with one or more servers. One or more certification authorities 2 may be used to authenticate the IP address of each device 10. However, some or all of the functions provided by the certification authorities 2 may be performed by any of the devices 10.
[0030] In the network system 1 according to this embodiment, the devices 10 are connected to each other and between the device 10 and the certificate authority 2 so as to be able to communicate data via any wired or wireless communication. This communication uses a peer-to-peer connection. Any protocol can be used, including TCP (Transmission Control Protocol) and UDP (User Datagram Protocol). You can hire Col.
[0031] Each of the devices 10 and the certificate authority 2 connected to the network can be considered a "node" of the network, and in the following description, each of the devices 10 and the certificate authority 2 may also be referred to as a "node."
[0032] <Hardware Configuration Example of Device 10> Next, a hardware configuration example of device 10 included in network system 1 according to the present embodiment will be described.
[0033] FIG. 2 is a schematic diagram showing a hardware configuration example of device 10 included in network system 1 according to the present embodiment. Referring to FIG. 2, device 10 includes, as main components, a control unit 110 which is a processing circuitry.
[0034] The control unit 110 is an operation entity for realizing the provision of functions and the execution of processing according to the present embodiment. The control unit 110 may be configured such that a processor executes computer-readable instructions stored in a memory using a processor and a memory as shown in FIG. 2. Alternatively, a hardware circuit such as an ASIC (Application Specific Integrated Circuit) in which a circuit corresponding to the computer-readable instructions is incorporated may be used to realize the control unit 110. Further alternatively, the control unit 110 may be realized by realizing a circuit corresponding to the computer-readable instructions on an FPGA (field-programmable gate array). Also, the control unit 110 may be realized by appropriately combining a processor, a memory, an ASIC, an FPGA, etc.
[0035] In a configuration using a processor and a memory as shown in FIG. 2, the control unit 110 includes a processor 102, a main memory 104, a storage 106, and a ROM (Read Only Memory) 108.
[0036] The processor 102 is an arithmetic circuit that sequentially reads and executes computer-readable instructions. The processor 102 is configured, for example, with a central processing unit (CPU), a micro processing unit (MPU), a graphics processing unit (GPU), etc. The control unit 110 may be realized using a plurality of processors 102 (multiprocessor configuration), or may be realized using a processor having a plurality of cores (multicore configuration).
[0037] The main memory 104 is a volatile storage device such as a dynamic random access memory (DRAM) or a static random access memory (SRAM). Of the various programs stored in the ROM 106 or the ROM 108, a specified program is loaded onto the main memory 104, and by cooperating with the main memory 104, various processes according to this embodiment are realized.
[0038] The storage 106 is a non-volatile storage device such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, etc. The storage 106 stores various programs executed by the processor 102 and various data to be described later.
[0039] The ROM 108 permanently stores various programs executed by the processor 102 and various data to be described later.
[0040] The device 10 further includes a network interface 120 for connecting the device 10 to a network. The network interface 120 corresponds to a communication unit for performing data communication with other devices 10 via the network.
[0041] The network interface 120 includes a wired connection terminal such as an Ethernet (registered trademark) port, a USB (Universal Serial Bus) port, a serial port such as IEEE1394, or a legacy parallel port. Alternatively, the network interface 120 may include a processing circuit and an antenna for wireless communication with a device, a router, a mobile base station, or the like. Wireless communication supported by the network interface 120 includes, for example, Wi-Fi (registered trademark), Bluetooth (registered trademark), ZigBee (registered trademark), LPWA (Low Power Wide Area), GSM (registered trademark), W-CD MA, CDMA200, LTE (Long Term Evolution), 5th generation mobile communication system ( 5G).
[0042] Device 10 may also include optional components, such as an internal interface 130, an input 140, and an output 150.
[0043] The internal interface 130 performs data communication with a target object when the device 10 is configured as a part of the target object or is incorporated into the target object. The internal interface 130 includes, for example, a wired connection terminal such as a Universal Serial Bus (USB) port, a serial port such as IEEE 1394, or a legacy parallel port. Alternatively, the internal interface 130 may include a circuit for receiving an electrical signal, such as an analog-to-digital conversion circuit.
[0044] The input unit 140 is a component for receiving input operations from a user who operates the device 10. The input unit 140 may be, for example, a keyboard, a mouse, a touch panel disposed on a display device, or operation buttons disposed on the housing of the device 10.
[0045] The output unit 150 is a component for externally presenting the processing results of the processor 102. The output unit 150 may be, for example, an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display. Output unit 150 may be a head-mounted display worn on the user's head, a projector that projects an image onto a screen, or an indicator disposed on the housing of device 10.
[0046] The input section 140 and the output section 150 are optional components, and may be connected from outside the device 10 via any interface such as a USB.
[0047] Device 10 may further include a component for reading various programs (computer-readable instructions) and / or various data from non-transitory media storing the various programs and / or data. The media may be, for example, optical media such as a DVD (Digital Versatile Disc) or semiconductor media such as a USB memory.
[0048] Instead of installing various programs and / or various data in device 10 via media, necessary programs and data may be installed in device 10 from a distribution server on a network. In this case, the necessary programs and data are obtained via network interface 120.
[0049] It is the control unit 110 that realizes the provision of functions and the execution of processes according to this embodiment, and the technical scope of the present application includes at least the hardware and / or software for realizing the control unit 110. As described above, the hardware may include not only a configuration composed of a processor and a memory, but also a hard-wired circuit using an ASIC or the like and a configuration using an FPGA. That is, the control unit 110 can be realized by installing a program in a general-purpose computer, or can also be realized as a dedicated chip.
[0050] In addition, the software executed by the processor may include not only those distributed via a medium, but also those appropriately downloaded via a distribution server.
[0051] Note that the configuration for realizing the provision of functions and the execution of processes according to this embodiment is not limited to the control unit 110 shown in FIG. 2, and can be implemented using any technology according to the era in which it is realized.
[0052] <C. Authenticated IP Address> Next, an example of a method for realizing an authenticated IP address in the network system 1 according to this embodiment will be described.
[0053] In the network system 1 according to this embodiment, as an example, the IP address of each device 10 is authenticated using a public key infrastructure (PKI). Authenticated.
[0054] FIG. 3 is a diagram for explaining an example of IP address authentication processing in the network system 1 according to this embodiment. Referring to FIG. 3, the device 10 has a key pair composed of a private key 160 and a public key 162. By inputting the public key 162 into a predetermined hash function 164, a hash value 166 is calculated, and all or part of the calculated hash value 166 is used as the IP address 168 of the device 10.
[0055] By sharing a predetermined hash function 164 between the devices 10, it is possible to uniquely determine the IP address 168 of the device 10 that is the sender of the public key 162, based on the public key 162 acquired from the other device 10. The public key 162 is transmitted together with the digital certificate 170 or incorporated into the digital certificate 170, and the validity of the public key 162 (i.e., the determined IP address 168) can be ensured based on the digital certificate 170. In other words, by sharing the predetermined hash function 164 between the devices 10, each device 10 has logic for determining the IP address of the other device 10, based on the public key 162 included in the digital certificate 170 received from the other device 10.
[0056] In this way, in the network system 1 according to this embodiment, the IP address 168 itself can be authenticated, and the device itself holds such an authenticated IP address 168, so that an autonomous network can be constructed without using an IP address statically or dynamically assigned to each device.
[0057] The key pair, private key 160 and public key 162, may be generated by device 10 itself, or may be provided from an external source and pre-stored in device 10. If provided from an external source, device 10 may acquire only private key 160 and generate public key 162 by itself.
[0058] As an example of a method for generating the public key 162 of the key pair, a bit string of a predetermined length (for example, 512 bits) generated by a random number generator is used as the private key 160, and a public key 162 is generated by a known cryptographic A public key 162 consisting of a bit string of a predetermined length (e.g., 256 bits) may be generated from the private key 160 in accordance with an algorithm (e.g., an elliptic curve cryptography algorithm). If the device 10 itself generates the key pair, the random number generator may be realized using a function provided by the OS or may be realized using a hardwired circuit such as an ASIC.
[0059] A known irreversible cryptographic hash function (for example, BLAKE) can be used as the hash function 164. The hash function 164 calculates a hash value 166 made up of a bit string of a predetermined length (for example, 256 bits).
[0060] In addition to public key 162, any keyword may be input to hash function 164. A message associated with a predetermined organization may be used as the arbitrary keyword. A message including the name of a trademark owned by the predetermined organization may be used as the message associated with the predetermined organization. For example, the name of a registered trademark owned by the predetermined organization (e.g., "connectFree") may be used as the keyword to be input to hash function 164. By adopting such an implementation method, it is possible to prevent a third party other than the predetermined organization from implementing network system 1 according to this embodiment and related methods and programs without the permission of the predetermined organization.
[0061] All or part of hash value 166 calculated by hash function 164 is used as IP address 168. For example, when a 256-bit (64 hexadecimal digits) hash value 166 is calculated, any 32 digits (e.g., the first 32 digits) of the 64-digit hash value 166 may be determined as IP address 168 (128 bits) corresponding to IPv6. Alternatively, the first 8 digits of the 64-digit hash value 166 may be determined as IP address 168 (32 bits) corresponding to IPv4.
[0062] Alternatively, the 128-bit hash value 166 may be calculated from the hash function 164, taking into consideration the IP address 168 (128 bits) corresponding to IPv6. In this case, the entire calculated hash value 166 can be determined as the IP address 168 (128 bits) corresponding to IPv6.
[0063] The determined IP address may include a predetermined unique value (unique character string) for identification.
[0064] As one example, the first two digits (the first and second digits from the beginning) of the hexadecimal IP address 168 may be fixed to a predetermined unique character string (e.g., "FC"). As another example, a value indicating the type of device 10 (type-specific information) may be embedded in the third and fourth digits from the beginning of the hexadecimal IP address 168.
[0065] Since hash function 164 is usually a one-way function, it is not possible to reverse-calculate public key 162 from IP address 168. Therefore, a random number generator may be used to repeatedly generate private key 160 and public key 162 until the determined IP address 168 satisfies a predetermined condition (in this case, all or part of the first four digits are a predetermined value).
[0066] In this way, by including a predetermined unique value for identification (for example, the first two digits are "FC") in the IP address 168, a third party can determine whether the IP address 168 of the device 10 was determined by the device 10 itself. Also, by including a value indicating the type of the device 10 in the IP address 168, a third party can identify the type of the device 10 from the determined IP address 168.
[0067] FIG. 4 shows the digital certificate 1 used in the network system 1 according to the present embodiment. 4 is a diagram showing an example of a digital certificate 170. Each device 10 holds a digital certificate 170 as shown in FIG. 4 and transmits it to other devices 10 as needed. The digital certificate 170 is typically stored in the storage 106 or ROM 108 (see FIG. 2) of the device 10. In other words, the storage 106 or ROM 108 of the device 10 corresponds to a storage unit that stores the digital certificate 170.
[0068] 4 may be created in advance by the certificate authority 2 and provided to each device 10, or each device 10 may create it itself (however, the certificate authority signature is the signature of the device 10 itself). When the certificate authority 2 issues the digital certificate 170, the device 10 sends a request for issuing a digital certificate (hereinafter also referred to as a "certificate signature request") to the certificate authority 2 along with the public key 162 that the device 10 possesses. In response to the certificate signature request received from the device 10, the certificate authority 2 registers the public key 162 and issues the digital certificate 170 including a certificate authority signature 178 generated according to a predetermined algorithm. In other words, in response to a certificate signature request from any device, the certificate authority 2 signs the digital certificate 170 to be stored in the requesting device.
[0069] 4 shows, as an example, a digital certificate 170 conforming to the X.509v3 certificate format. More specifically, referring to FIG. 4, the digital certificate 170 held by each device 10 includes version information 171, a serial number 172, a signature algorithm 173, an issuer identifier 174, a validity period 175, a subject identifier 176, a public key 162, a certificate authority signature 178, and extension information 180.
[0070] Version information 171 indicates version information of the certificate format. Serial number 172 indicates a serial number for the issuer of digital certificate 170 (certificate authority 2 or device 10). Signature algorithm 173 indicates the algorithm used to generate the certificate authority signature 178 included in digital certificate 170. Issuer identifier 174 indicates information for identifying the issuer of digital certificate 170 (certificate authority 2 or device 10). Validity period 175 indicates the validity period of digital certificate 170. Subject identifier 176 indicates information for identifying the person to whom digital certificate 170 is issued (usually device 10 holding digital certificate 170). Public key 162 is the public key 162 held by device 10 holding digital certificate 170, and is used to determine the IP address of the device itself.
[0071] The certificate authority signature 178 is a signature (hash value) generated by the certificate authority 2 . Extended information 180 can include any information. In network system 1 according to the present embodiment, extended information 180 includes zone ID 182 (details of which will be described later) indicating location information associated with each device 10. Zone ID 182 includes location information associated with the device in which digital certificate 170 is stored (i.e., the device corresponding to zone ID 182). By referencing zone ID 182 included in digital certificate 170, the location or range in which each device 10 exists can be easily identified.
[0072] <D.ゾーンID> Next, details of zone IDs used in network system 1 according to the present embodiment will be described.
[0073] (d1: Decision and system of zone ID) Fig. 5 is a schematic diagram for explaining zone IDs used in network system 1 according to the present embodiment. With reference to Fig. 5, in this embodiment, the range is divided hierarchically according to the request. Fig. 5 shows an example using quadtree space division, but the invention is not limited to this and any division method can be used.
[0074] More specifically, the zones for which zone IDs can be set are divided into four zones, A to D. That is, the highest-level zone IDs in Fig. 5 are "A", "B", "C", and "D".
[0075] Each divided zone can be further divided into four. In the example shown in Figure 5, the zone with zone ID "A" is further divided into four. The zone IDs of the divided zones are "AA", "AB", "AC", and "AD".
[0076] A zone with a zone ID of "AA" is further divided into four. The zone IDs of each divided zone are "AAA", "AAB", "AAC", and "AAD". Zones with zone IDs of "AB" and "AC" are also divided into four zones in the same way. That is, the zone IDs of the zones obtained by dividing a zone with a zone ID of "AB" into four are "ABA", "ABB", "ABC", and "ABD", and the zone IDs of the zones obtained by dividing a zone with a zone ID of "AC" into four are "ACA", "ACB", "ACC", and "ACD".
[0077] Zones with the zone ID "D" are also divided into four zones, and some of these zones are further divided into four zones.
[0078] In this way, by repeating the operation of dividing all or part of the target zone into four, up to the required granularity, the location information can be determined. In other words, the determined location information will indicate one of the zones generated by dividing the zone hierarchically.
[0079] Fig. 6 is a schematic diagram for explaining a code system of zone IDs used in network system 1 according to the present embodiment. The example of the code system shown in Fig. 6 corresponds to the zone division shown in Fig. 5.
[0080] Referring to Figure 6, four zone IDs, "A," "B," "C," and "D," are assigned to the first layer. Zone IDs used in the second layer are the entirety of the corresponding first layer zone ID, with an additional identifying character added. For example, the four zones obtained by dividing the zone ID "A" are assigned "AA," "AB," "AC," and "AD," with the identifying characters "A," "B," "C," and "D" added after "A," respectively.
[0081] Similarly, the third tier uses zone IDs that are the entire equivalent of the second tier zone ID, with additional identifying characters added to the whole. For example, the four zones obtained by dividing the zone ID "AA" use "AAA", "AAB", "AAC", and "AAD", with "A", "B", "C", and "D" added after "AA" for identification purposes, respectively.
[0082] Even for subsequent deeper hierarchies, the zone ID is determined according to the same rules. In this way, a zone ID, which is location information, is composed of a code that reflects the hierarchical structure of the target zone. In network system 1 according to this embodiment, a zone ID that includes all zone IDs in higher hierarchies is used, so that for any zone ID, the zone ID that exists above it can be uniquely identified. For example, a zone with the zone ID "AAA" can be determined to be a partial area of a zone with the zone ID "AA," and can also be determined to be a partial area of a zone with the zone ID "A."
[0083] 5 and 6, for the sake of convenience, an example is shown in which one alphabetical character is added for each deeper layer, but this is not limiting, and any length of identification information ( It is sufficient to configure it so that characters (letters, numbers, etc.) are added sequentially.
[0084] 5 and 6, for the sake of convenience, the highest level (first level) is divided into four zones, but the highest level may have any number of zones. Furthermore, the number of divisions for the second level and below does not need to be limited to four, and they can be sequentially divided into any number of zones.
[0085] For convenience of explanation, FIG. 5 shows an example in which a rectangular zone is sequentially divided. However, this is merely a logical representation, and any unit can be set for each hierarchical zone depending on the application. In other words, the "zones" shown in FIG. 5 are not necessarily limited to physical areas, but may include zone divisions defined according to artificially determined rules. For example, the "zone" hierarchies may be associated with artificially determined address notations (e.g., "prefecture," "city / town / village," "town," "number," "room number," etc.). Furthermore, there are no restrictions on the number of divisions and the divided hierarchical levels of the "zones" shown in FIG. 5. For example, the zone ID corresponding to the address of a fast food restaurant may be further divided, and a zone ID may be assigned to each seat.
[0086] By acquiring a zone ID from each device 10 that can communicate and mapping it on a map, the location of each device 10 can be realized.
[0087] (d2: Setting and updating zone ID) Next, a process example relating to setting and updating a zone ID for each device 10 will be described. A predetermined zone ID may be set for each device 10, and a digital certificate 170 including the set zone ID may be issued by the certificate authority 2. Alternatively, after a device 10 is connected to the network system 1, a zone ID may be set for the connected device 10 based on the connection relationship on the network. Below, a process example for setting a zone ID based on the connection relationship on the network and issuing a digital certificate 170 will be described.
[0088] 7 is a schematic diagram for explaining processing relating to setting of a zone ID in network system 1 according to the present embodiment. FIG. 7 shows an example of processing when device 10A2 (see FIG. 1) is connected to the network of device 10A1 associated with zone A.
[0089] 7A shows an example in which device 10A2 requests device 10A1, which is connected to the same network, to assign a zone ID. In the example shown in FIG. 7A, device 10A2 requests a zone ID from device 10A1 ((1) Zone ID Request). In response to the zone ID request, device 10A1 determines a zone ID by adding further identification information to the zone ID assigned to itself, and sends the zone ID to device 10A2 ((2) Zone ID). Device 10A2 then transmits a certificate signing request to certificate authority 2 that includes the zone ID assigned by device 10A1 and its own device's public key 162 ((3) Certificate Signing Request). In response to the certificate signing request, certificate authority 2 generates digital certificate 170 for device 10A2 and transmits it to device 10A2 ((4) Digital Certificate). Device 10A2 stores digital certificate 170 from certificate authority 2 and uses it for data communication with other devices.
[0090] In this way, a device 10 at a lower level requests the location information to be set in the device from another device associated with a zone at a higher level than the zone indicated by the zone ID (location information) associated with the device.
[0091] In FIG. 7B, a request from device 10A2 is sent to a device connected to the same network. An example of requesting the issuance of an electronic certificate 170 to the vice 10A2 is shown. In the example shown in FIG. 7(B), the device 10A2 requests the device 10A1 to issue an electronic certificate 170 ((1) Certificate issuance request). This request for the issuance of the electronic certificate 170 includes the public key 162 of the device 10A2. In response to the request for the issuance of the electronic certificate 170, the device 10A1 adds additional identification information to the zone ID assigned to its own device to determine the zone ID of the device 10A2 ((2) Zone ID determination). Then, the device 10A2 transmits a certificate signature request including the determined zone ID and the public key 162 of the device 10A2 to the certification authority 2 ((3) Certificate signature request). In response to the certificate signature request, the certification authority 2 generates an electronic certificate 170 for the device 10A2 and transmits it to the device 10A1, and it is relayed by the device 10A1 and delivered to the device 10A2 ((4) Electronic certificate). The device 10A2 stores the electronic certificate 170 from the certification authority 2 and uses it for data communication with other devices.
[0092] The process related to the setting of the zone ID shown in FIG. 7 is an example, and any setting method may be adopted. When the device 10 is connected to another network, the process related to the setting of the zone ID shown in FIG. 7 may be re-executed. By such re-execution, the zone ID can be updated.
[0093] Hereinafter, examples of several applications using the position information according to the present embodiment will be described. In the applications described below, each device may implement a function of managing a value (including ordinary currency and virtual currency) that serves as a price for money, goods, or services. For example, by giving a budget to each device, a settlement process without the intervention of a person can be realized.
[0094] <E. First application example> As a first application example, a configuration used for a fire alarm or the like arranged in a building will be described.
[0095] 8 is a schematic diagram showing an example of an application that uses location information provided by network system 1 according to the present embodiment. Referring to FIG. 8, it is assumed that devices 10DT1 to 10DT6, which are fire alarms, are installed on each floor of a building. Device 10HST, which is a host that aggregates various information including fire detection in the building, is also installed, and device 10HST is capable of data communication with each of devices 10DT1 to 10DT6. Furthermore, device 10HST is capable of data communication with device 10MST, which is a host installed in a fire department or a host that aggregates notifications to the fire department.
[0096] 8, one building is the management unit for zone IDs, and "AKPRMM" is assigned as the zone ID. Furthermore, each floor of the building is assigned a zone ID ("AKPRMM1" to "AKPRMM6").
[0097] For example, when a fire alarm (device 10DT5) located on the fifth floor detects a fire, it notifies the host (device 10HST) of the fire detection information. A session for data communication is established between device 10DT5 and device 10HST by exchanging electronic certificate 170 including a zone ID. The exchanged electronic certificate 170 also includes the zone ID of device 10DT5. Device 10DT5 identifies the zone ID of the device 10 at a higher level from its own zone ID "AKPRMM5". In this example, it is identified that "AKPRMM", which is the zone ID of device 10DT5 with the last character removed, is the notification destination. It can be determined.
[0098] When device 10HST receives fire detection information from device 10DT5, it identifies the zone ID of device 10DT5 by referencing electronic certificate 170 previously acquired from device 10DT5, and notifies device 10MST of the fire detection information together with the identified zone ID. Based on the notification information from device 10HST, device 10MST can identify the location of the fire alarm (device 10DT2) that detected the fire. Then, it takes the necessary action depending on the identified location.
[0099] In this way, by applying network system 1 according to the present embodiment, it is possible to immediately obtain information on which floor of the building an abnormality such as a fire has occurred.
[0100] Fig. 9 is a sequence diagram showing a processing procedure for realizing the application shown in Fig. 8. Referring to Fig. 9, processing for establishing a session is first executed between devices. Device 10HST, which is the host, transmits its own device's digital certificate 170 to device 10MST, which is the fire department (sequence SQ10), and device 10MST also transmits its own device's digital certificate 170 to device 10HST (sequence SQ11). Device 10HST and device 10MST exchange digital certificates 170 to establish a session (sequence SQ12).
[0101] Furthermore, device 10DT5, which is a fire alarm, transmits its own device's digital certificate 170 to device 10HST (sequence SQ13), and device 10HST also transmits its own device's digital certificate 170 to device 10DT5 (sequence SQ14). Device 10DT5 and device 10HST exchange digital certificates 170 to establish a session (sequence SQ15). For ease of explanation, FIG. 9 only shows the process of establishing a session between device 10DT5 and device 10HST, but similar sessions are also established between the other devices 10DT1 to 10DT4 and 10DT6 and device 10HST.
[0102] Thereafter, when device 10DT5 detects a fire (sequence SQ16), device 10DT5 transmits information about the fire detection to device 10HST (sequence SQ17). When device 10HST receives the fire detection information from device 10DT5, it references digital certificate 170 received from device 10DT5 and determines the zone ID of device 10DT5 (sequence SQ18). Then, device 10DT5 transmits the fire detection information from device 10DT5 and the determined zone ID of device 10DT5 to device 10MST (sequence SQ19).
[0103] In this way, device 10DT5, which constitutes network system 1, exchanges digital certificate 170 with device 10HST to establish a session, and then transmits information generated or collected by itself to device 10HST. Device 10DT5 can be reliably identified based on the contents of digital certificate 170 used to establish the session.
[0104] By the above-described processing procedure, the information detected by the fire alarm is transmitted to a fire department or the like along with the location of the detected fire alarm, so that the location information necessary for firefighting activities can be provided to the fire department.
[0105] In Figures 8 and 9, a typical example of notification by a fire alarm is shown, but the present invention is not limited to this and can be applied to any monitoring and detection device (for example, an intrusion detection device using an infrared sensor or camera, etc.).
[0106] Furthermore, devices such as fire alarms and sprinklers may be configured to hold or manage in advance a deposit that can be used to pay for water needed in the event of a fire. By implementing such budget and payment functions, devices such as fire alarms and sprinklers can autonomously provide information to fire departments and manage expenses when they detect a fire, without the intervention of a human such as an administrator.
[0107] <F. Second Application Example> As a second application example, a configuration for managing the right to use services such as hotel room reservations and usage will be described.
[0108] FIG. 10 is a schematic diagram showing another example of an application using the location information provided by the network system 1 according to the present embodiment. In the application shown in FIG. 10, the device 10TRM, which is a mobile terminal held by the user, can be used as an electronic key (usage certificate). In front of each room in the accommodation facility 40, a device 10KEY, which is a locking device, is arranged. When the user operates their mobile terminal, the device 10TRM, to make a usage reservation on a reservation site or the like, ticket information as described below is provided to the mobile terminal and the target locking device. The same ticket information is shared between the mobile terminal and the target locking device. When the user approaches the room they reserved, communication is performed between the user's mobile terminal and the target locking device, and the room is unlocked. Note that the communication between the mobile terminal and the locking device may be automatically started or may be started after the user explicitly performs an operation.
[0109] FIG. 11 is a schematic diagram showing an example of a system configuration for realizing the application shown in FIG. 10. Referring to FIG. 11, devices 10KEY1, 10KEY2, 10KEY3, ···, which are one or more locking devices associated with each room in the hotel, are arranged. The devices 10KEY1, 10KEY2, 10KEY3, ··· are capable of data communication with a device 10SRV, which is a server for managing hotel reservations and the like.
[0110] The device 10SRV, which is a server, is also capable of data communication with the device 10TRM, which is a mobile terminal.
[0111] The device 10SRV, which is a server, manages reservations for each room managed by the devices 10KEY1, 10KEY2, 10KEY3, ..., which are locking devices. If the rooms managed by each locking device are considered to be "resources," the device 10SRV can also be considered to manage the resources to be provided in accordance with requested services. Information for providing the service determined in accordance with resource management, as described below, is transmitted as ticket information 50 to the device 10TRM, which is a mobile terminal, and the device 10KEY that provides the resources.
[0112] Fig. 12 is a schematic diagram for explaining resource management in the application shown in Fig. 10. Referring to Fig. 12, a device 10SRV, which is a server, manages time as a resource for each room associated with devices 10KEY1, 10KEY2, 10KEY3, etc. Since each hotel room accepts only one reservation for use (i.e., service) at a given time, services are assigned on the time axis so as not to overlap.
[0113] In network system 1 according to the present embodiment, each device 10 has an authenticated IP address, so that the authenticated IP address of device 10 that has requested a service can be used in resource management as well.
[0114] As shown in Figure 12, if resources can be secured for the requested service (reservation), the service Ticket information 50 is sent to the device 10 that requested the service and the device 10 that provides the reserved resource.
[0115] Fig. 13 is a diagram showing an example of ticket information 50 used in the application shown in Fig. 10. Referring to Fig. 13, ticket information 50 includes resource allocation period 51, resource IP address 52, resource zone ID 53, and service destination IP address 54.
[0116] The resource allocation period 51 indicates the time during which the room is available. The resource IP address 52 indicates the IP address of the device 10KEY, which is the locking device associated with the reserved room. The resource zone ID 53 indicates the zone ID of the device 10KEY, which is the locking device associated with the reserved room. The service destination IP address 54 indicates the device 10TRM that reserved the room.
[0117] Such ticket information 50 is shared between the device 10TRM and the target device 10KEY. As described above, the devices 10KEY1, 10KEY2, 10KEY3, etc., which are locking devices, are configured to manage resources associated with each device. Then, in response to a request from the device 10TRM, at least a portion of the resources managed by the devices 10KEY1, 10KEY2, 10KEY3, etc. are allocated. Furthermore, information related to the resource allocation is shared between the device 10KEY that provided the resource and the device 10TRM that requested the resource.
[0118] FIG. 14 is a sequence diagram showing a processing procedure for realizing the application shown in FIG. 10. Referring to FIG. 14, a process for establishing a session is first executed between devices. Device 10SRV, which is a server, transmits its own device's electronic certificate 170 to device 10KEY, which is a locking device (sequence SQ20), and device 10KEY also transmits its own device's electronic certificate 170 to device 10SRV (sequence SQ21). Device 10SRV and device 10KEY establish a session by exchanging electronic certificates 170 (sequence SQ22). For ease of explanation, FIG. 14 shows only the process for establishing a session between device 10SRV and one device 10KEY, but a similar session is also established between device 10SRV and each of one or more devices 10KEY1, 10KEY2, 10KEY3, . . .
[0119] Furthermore, device 10TRM, which is a mobile terminal, transmits its own digital certificate 170 to device 10SRV (sequence SQ23), and device 10SRV also transmits its own digital certificate 170 to device 10KEY (sequence SQ24). Device 10DT5 and device 10HST exchange digital certificates 170 to establish a session (sequence SQ25).
[0120] Thereafter, in response to a user operation on the device 10TRM (sequence SQ26), the device 10TRM transmits a reservation request to the device 10SRV (sequence SQ27). The device 10SRV receives the reservation request from the device 10TRM and reserves resources capable of providing the requested service (sequence SQ28). The device 10TRM then generates ticket information 50 according to the reserved resources (sequence SQ29). The device 10SRV transmits the generated ticket information 50 to the device 10TRM that transmitted the reservation request and to the device 10KEY that provides the reserved resources (sequences SQ30 and SQ31).
[0121] When the user approaches the reserved room, the device 10TRM transmits its own digital certificate 170 to the device 10KEY (sequence SQ32), and the device 10KEY also transmits its own digital certificate 170 to the device 10KEY (sequence SQ33). The device 10KEY then sends the device's digital certificate 170 to the device 10TRM (sequence SQ33). The device 10TRM and device 10KEY exchange digital certificates 170 to establish a session (sequence SQ34). Then, the device 10TRM and device 10KEY execute a process to mutually query the ticket information 50 (sequence SQ35). When the query process for the ticket information 50 ends successfully, the device 10KEY unlocks the room it manages (sequence SQ36).
[0122] The above-described processing procedure provides a system that allows users to reserve hotel rooms and use the mobile terminal itself as a room key.
[0123] In the description of the above application, as a typical example, a configuration in which a mobile terminal is used as a key for each room in an accommodation facility such as a hotel has been illustrated. However, it is not limited to this, and it can be used as any usage certificate. For example, the mobile terminal itself can be used as an admission ticket for various facilities such as amusement facilities and various events such as concerts. Furthermore, the mobile terminal itself can also be used as a ticket for railways and airplanes.
[0124] Furthermore, authentication terminals (for example, gates, ticket vending machines, etc.) such as keys and tickets for each room in an accommodation facility as devices can be budgeted for themselves. The budget may be held in cooperation with a deposit or a settlement company, etc. Alternatively, the mobile terminal itself can also be budgeted for. In this way, seamless money transactions can be made between the authentication terminal and the mobile terminal, and a system can be constructed without the intervention of a person such as an administrator.
[0125] <G. Third Application Example> As a third application example, a configuration for managing traffic resources will be described.
[0126] In this specification, "traffic resources" means physical or human resources used by moving bodies such as automobiles, railways, airplanes, and ships. Basically, "traffic resources" are limited and are appropriately mediated and used according to requests. Hereinafter, a system configured by a device 10 that manages such traffic resources is assumed.
[0127] FIG. 15 is a schematic diagram showing yet another example of an application using the location information provided by the network system 1 according to the present embodiment. FIG. 15 shows a system assuming a road on which vehicles pass as traffic resources. More specifically, four roads are assumed, traffic resources are defined for each section where the roads 61, 62, 63, and 64 intersect, and a device 10 that manages each traffic resource is arranged. It is assumed that a zone ID indicating the traffic resource to be managed is set in each device 10.
[0128] The device 10 (zone: Avenue 001) associated with road 61 has a resource table 71 for managing transportation resources. Similarly, the device 10 (zone: Avenue 002) associated with road 62 has a resource table 72 for managing transportation resources. Similarly, the device 10 (zone: Street 001) associated with road 63 has a resource table 73 for managing transportation resources. Similarly, the device 10 (zone: Street 002) associated with road 64 has a resource table 74 for managing transportation resources.
[0129] Vehicles that exist in the associated transportation resources are registered in the resource tables 71 to 74. Each vehicle has an IP address and is capable of data communication with the device 10 associated with each transportation resource. When a vehicle uses (or is scheduled to use) the associated transportation resource, each device 10 that manages the resource tables 71 to 74 registers the IP address of the vehicle in the corresponding resource table. Furthermore, each device 10 that manages the resource tables 71 to 74 deletes the IP address of the vehicle from the corresponding resource table when the vehicle has finished using the associated transportation resource. Furthermore, additional information such as the traveling direction of each vehicle may also be registered.
[0130] By managing transportation resources in this way, it is possible to avoid congestion caused by traffic congestion and provide optimal route selection for each vehicle.
[0131] Fig. 16 is a schematic diagram showing route selection using the application shown in Fig. 15. Referring to Fig. 16, for example, by allocating transportation resources of roads 61 and 63 to a vehicle (IP address xx) in advance, smooth travel is possible.
[0132] More specifically, by registering the IP addresses of vehicles that plan to use the transportation resources in resource table 71 associated with road 61 and resource table 73 associated with road 63, a kind of ``right'' for the vehicles to pass through can be secured.
[0133] In this way, by providing a zone ID associated with each transportation resource, and configuring the device 10 to which each zone ID is assigned to manage the corresponding transportation resource, as well as manage the services that use each transportation resource, optimal use of transportation resources can be achieved.
[0134] A mobile vehicle can use the zone ID coding system to identify the device 10 that manages the available transportation resources.
[0135] Fig. 17 is a sequence diagram showing the processing procedure for realizing the application shown in Fig. 15. Fig. 17 shows an example of a network system including a device 10SRV which is a zone management server existing in a higher hierarchy than the devices 10RM1, 10RM2, 10RM3, and 10RM4, in addition to the device 10M mounted on a vehicle and devices 10RM1, 10RM2, 10RM3, and 10RM4 which are resource managers that manage roads 61, 62, 63, and 64.
[0136] 17, the device 10M mounted on the vehicle acquires its current location by any method (sequence SQ40). Typically, the current location is acquired based on information from a GPS or a mobile base station.
[0137] Then, device 10M transmits its own digital certificate 170 to device 10SRV, which is the zone management server (sequence SQ41), and device 10SRV also transmits its own digital certificate 170 to device 10M (sequence SQ42). Device 10M and device 10SRV exchange digital certificates 170 to establish a session (sequence SQ43).
[0138] After the session is established, the device 10M transmits a destination node inquiry including the current location acquired in sequence SQ40 to the device 10SRV (sequence SQ44). The device 10SRV responds to the device 10M with the destination node based on the current location included in the destination node inquiry (sequence SQ45). The destination node is information for identifying the device 10 that manages the transportation resources that the device 10M will use. Note that the destination node may include multiple devices 10. In this example, it is assumed that the device 10RM1, which is a resource manager, is notified as the destination node.
[0139] In this way, device 10SRV responds to a request for its current location from device 10M by , and responds with a connection destination node (specific information) for identifying the devices 10RM1, 10RM2, 10RM3, and 10RM4 associated with the current location.
[0140] Next, device 10M transmits its own digital certificate 170 to device 10RM1, which is the resource manager (sequence SQ46), and device 10RM1 also transmits its own digital certificate 170 to device 10M (sequence SQ47). Device 10M and device 10RM1 exchange digital certificates 170 to establish a session (sequence SQ48).
[0141] After the session is established, device 10M transmits a resource request to device 10RM1 (sequence SQ49). Device 10RM1 receives the resource request from device 10M and reserves the resources according to the request (sequence SQ50). Device 10RM1 then transmits a resource request response to device 10M indicating that the resources have been reserved (sequence SQ51). Furthermore, device 10RM1 identifies a transportation resource subsequent to the transportation resource managed by device 10RM1, and responds to device 10M with a destination node indicating the device manager that manages the identified transportation resource (sequence SQ52). In this example, it is assumed that device 10RM2, which is a resource manager, has been notified as the destination node.
[0142] Next, device 10M transmits its own digital certificate 170 to device 10RM2, which is the resource manager (sequence SQ53), and device 10RM2 also transmits its own digital certificate 170 to device 10M (sequence SQ54). Device 10M and device 10RM2 exchange digital certificates 170 to establish a session (sequence SQ55).
[0143] After the session is established, device 10M transmits a resource request to device 10RM2 (sequence SQ56). Device 10RM2 receives the resource request from device 10M and reserves the resources according to the request (sequence SQ57). Device 10RM2 then transmits a resource request response to device 10M indicating that the resources have been reserved (sequence SQ58). Furthermore, device 10RM2 identifies a transportation resource subsequent to the transportation resource managed by device 10RM2, and responds to device 10M with a destination node indicating the device manager that manages the identified transportation resource (sequence SQ59). Thereafter, similar processes to sequences SQ46 to SQ52 and sequences SQ53 to SQ59 are repeated.
[0144] Through such a processing procedure, the allocation of traffic resources as shown in FIG. 16 is completed. Thereby, efficient utilization of traffic resources can be realized.
[0145] As described above, the devices 10RM1, 10RM2, 10RM3, and 10RM4 are configured to manage traffic resources associated with each device. And in response to a request from the device 10M, at least a part of the traffic resources managed by the devices 10RM1, 10RM2, 10RM3, and 10RM4 is allocated.
[0146] In the above description of the application, the case where a road is adopted as a typical example of traffic resources is illustrated. However, it is not limited to this, and it is applicable to any traffic resources. For example, each seat of each train, aircraft, ship, etc. can also be treated as a traffic resource.
[0147] A budget can also be allocated to the above-mentioned traffic resources. In this case, if it is desired to guarantee arriving at the destination in the shortest time, a mechanism can be proposed such that road users charge for the traffic resources. On the other hand, even for an efficient route, in a non-congested road, the traffic resources can also pay the user or the like a consideration for use from the budget.
[0148] <H. Other Forms> In the above example of the application, the process of exchanging data with the device 10 is illustrated. However, it is not limited to this, and commands may be exchanged with the device 10. By exchanging such commands, the role of the device 10 and the like can be dynamically changed.
[0149] By dynamically changing such roles, for example, it becomes possible to delegate or proxy the processing of a certain device 10 to another device 10. For example, when some malfunction occurs in the device 10 responsible for managing traffic resources as shown in FIG. 15, or when the processing related to the management of traffic resources has increased, it is possible to change the device 10 that was in charge of the processing to another device 10, or to add another device 10 in addition to the device 10 that was in charge of the processing, and perform a role change such as this. Any method for optimally using the device 10 as a whole for such a network system can be adopted.
[0150] <I. Advantages> According to the network system 1 according to the present embodiment, it is possible to obtain the authenticated location information of the device and provide various services using the authenticated location information.
[0151] The disclosed embodiments should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is shown not by the above description but by the claims, and it is intended that all modifications within the meaning and scope equivalent to the claims be included.
Explanation of Reference Numerals
[0152] 1 Network system, 2 Certificate authority, 10, 10A1 to 10A4, 10B1 to 10B5, 10C1 to 10C4, 10DT1 to 10DT6, 10HST, 10KEY, 10KEY1 to 10KEY3, 10M, 10MST, 10RM1 to 10RM4, 10SRV, 10TRM Device, 40 Accommodation, 50 Ticket information, 51 Resource allocation period, 52, 54, 168 IP address, 53, 182 Zone ID, 61, 62, 63, 64 Road, 71, 72, 73, 74 Resource table, 102 Processor, 104 Main memory, 106 Storage, 108 ROM, 110 Control unit, 120 Network interface, 130 Internal interface, 140 Input unit, 150 Output unit, 160 Private key, 162 Public key, 164 Hash function, 166 Hash value, 170 Digital certificate, 171 Version information, 172 Serial number, 173 Signature algorithm, 174 Issuer distinguished name, 175 Validity period, 176 Subject distinguished name, 178 Certificate Authority Signature, 180 Extended Information.
Claims
1. A network system comprising at least one first device, The first device means for managing resources associated with the first device; means for allocating at least a portion of the resources associated with the first device in response to a resource allocation request from a second device; A network system, wherein information regarding the allocated resources is shared between the first device and the second device.
2. 2. The network system according to claim 1, wherein the first device comprises means for generating a ticket including information indicating the content of the allocated resource and the network address of the second device to which the resource has been allocated.
3. 3. The network system according to claim 1, wherein the network address of the second device is determined based on a public key that is a key pair of a private key of the second device.
4. 4. The network system according to claim 1, wherein the resources include available space and available time.
5. the network system includes a plurality of the first devices and a third device capable of communicating with the plurality of first devices; A network system according to any one of claims 1 to 4, wherein the third device, in response to a resource allocation request from the second device, identifies a corresponding first device and responds to the second device with the identified first device.
6. A processing method executed in a network system, a step by a first device for managing resources associated with said first device; and allocating, by the first device, at least a portion of the resources associated with the first device in response to a resource allocation request from a second device; The method of claim 1, wherein information regarding the allocated resources is shared between the first device and the second device.