Program, virtual network allocation method, and virtual network allocation system
The described system addresses the lack of location-based network allocation in wireless communication by using location information to assign virtual networks through 5G slicing, ensuring secure and efficient network allocation and communication in shared environments.
Patent Information
- Application Number
- JP2025095735
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2041-08-30
AI Technical Summary
Existing wireless communication systems fail to consider location information of information terminals when establishing connections to access networks, leading to inefficiencies in network allocation.
A program and system that utilize location information to allocate virtual networks by acquiring first and second location information, such as reader IDs and base station IDs, to assign virtual networks based on the terminal's location, enabling precise network control and security through 5G network slicing.
Enables secure, efficient allocation of virtual networks tailored to specific locations, ensuring appropriate network resources and communication security for each user or device, even in shared facilities, by using 5G network slicing to generate logical networks based on location data.
Smart Images

Figure 2025128273000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a program, a virtual network allocation method, and a virtual network allocation system. [Background technology]
[0002] A wireless communication system is known that uses at least two types of communication networks, including a wireless communication network, and can simultaneously establish a connection between a basic access network that is capable of signaling communication related to continuous communication switching control and an access network that performs data communication other than the signaling communication (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 4811606 Summary of the Invention [Problem to be solved by the invention]
[0004] However, the wireless communication system described in Patent Document 1 has a problem in that it does not take into consideration the point of establishing a connection to an access network based on the location information of an information terminal that serves as a communication node of the wireless communication system.
[0005] The present invention has been made in view of the above circumstances, and has as its object to provide a program or the like that can allocate a virtual network to an information terminal based on the location information of the information terminal. [Means for solving the problem]
[0006] In one proposal, the program causes a computer to execute a process of acquiring first location information regarding the location where an information terminal is located, acquiring second location information that identifies a base station of a local network with which the information terminal can communicate, and assigning a virtual network to be connected to the information terminal based on the acquired first location information and second location information.
[0007] In one proposal, a virtual network allocation method causes a computer to acquire first location information regarding the location where an information terminal is located, acquire second location information that identifies a base station of a local network with which the information terminal can communicate, and execute a process of allocating a virtual network to be connected to the information terminal based on the acquired first location information and second location information.
[0008] In one proposal, the virtual network allocation system includes an information terminal and a control device that allocates a virtual network to the information terminal, wherein the information terminal acquires first location information regarding the location where the terminal is located, acquires second location information that identifies a base station that makes the location where the terminal is located a local network with which the terminal can communicate, and outputs the acquired first location information and second location information to the control device, and the control device acquires the first location information and second location information from the information terminal and allocates a virtual network to be connected to the information terminal according to the acquired first location information and second location information. [Effects of the Invention]
[0009] According to the present invention, it is possible to provide a program or the like that allocates a virtual network to an information terminal based on the location information of the information terminal. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a system overview diagram illustrating a virtual network allocation system according to a first embodiment. [Figure 2]1 is a block diagram showing an example of the configuration of a mobile terminal, a control device, and the like included in a virtual network allocation system. [Figure 3] FIG. 10 is an explanatory diagram illustrating an example of an authentication table. [Figure 4] 1 is an explanatory diagram (sequence diagram) illustrating an example of each process performed by a mobile terminal, a control device, etc.; [Figure 5] 10 is a flowchart illustrating an example of a virtual network allocation process. [Figure 6] 10 is a flowchart showing an example of a virtual network allocation process according to the second embodiment (multiple mobile terminals). DETAILED DESCRIPTION OF THE INVENTION
[0011] (Embodiment 1) FIG. 1 is a system overview diagram illustrating a virtual network allocation system S according to a first embodiment. FIG. 2 is a block diagram showing an example configuration of an information terminal 2, a control device 1, and the like included in the virtual network allocation system S. The virtual network allocation system S includes, for example, a plurality of base stations KK (RAN: Radio Access Network) and a control device 1 (5G core network: 5th Generation Core network / EPC (Evolved Packet Core)) constituting a 5G (5th Generation) communication network, and an information terminal 2 connected to a virtual network KN generated and allocated by the control device 1 (5G core network). The information terminal 2 is communicably connected to a reader 41 that transmits information (first location information) indicating the physical location of the information terminal 2. A SIM card 3 compatible with 5G is inserted into the information terminal 2.
[0012] The reader 41 may be provided at the entrance (gate) of a room 4, such as an office or a conference room, in a shared office or a rental conference room building, and may be configured as part of a so-called door gate (entrance / exit management device). As illustrated in the present embodiment, the shared office has three offices (rooms 4), and a reader 41 (door gate) is installed at the entrance (gate) of each room 4. When a user of the office (room 4) enters the room 4, the user holds their own information terminal 2, such as a smartphone, over the reader 41, and the reader 41 performs entrance / exit control (entrance / exit management). Each reader 41 installed in each room 4 is assigned an identification number (reader ID) for identifying the individual reader 41, and the reader ID is transmitted from the reader 41 to the information terminal 2. The information terminal 2 acquires the reader ID transmitted from the reader 41 as first location information.
[0013] The information terminal 2 further acquires the base station ID transmitted from the base station KK as second location information. The information terminal 2 stores the acquired reader ID (first location information) and base station ID (second location information) in the SIM card 3 installed in the terminal, and then combines (associates) the first location information and the second location information and transmits them to the control device 1 (5G core network) via the base station KK.
[0014] The control device 1 (5G core network) performs mutual authentication based on the first location information and second location information transmitted from the information terminal 2, and if the result of the mutual authentication is positive, assigns a virtual network KN to the information terminal 2.
[0015] The virtual network KN is a logical network generated by network slicing, a 5G function. By using network slicing, a single network infrastructure (base station KK and 5G core network) can be virtually divided (sliced) and provided and operated as multiple logical networks to provide services according to various needs and applications. An information terminal 2 to which a virtual network KN is assigned can then use the virtual network KN to communicate with a management server KS or an application server connected to a wide area network BN such as the Internet.
[0016] As described above, a different reader 41 (door gate) is installed in each office (room 4) in a shared office or the like, and therefore the reader ID (first location information) transmitted from each reader 41 is different. Therefore, a different virtual network KN can be assigned to each office (room 4) in accordance with the reader ID (first location information), enabling precise control for each room 4, such as ensuring security and bandwidth for each room 4. Therefore, even in a facility used by an unspecified number of users, such as a shared office, a virtual network KN (logical network using 5G network slicing) can be generated and assigned for each room 4 used by each user, thereby providing each user of the room 4 with a secure network environment for each room 4. In this embodiment, the reader 41 (door gate) is installed in each office (room 4) in a shared office or the like. However, this is not limited thereto, and the reader 41 (door gate) may be installed in, for example, each facility. That is, the room 4 in this embodiment includes, for example, each office in a shared office, each conference room in a rental conference room building, each retail store in a shopping mall, and facilities in a complex building.
[0017] In the present embodiment, the virtual network KN is assigned to the information terminal 2, but the present invention is not limited to this, and the virtual network KN may be assigned to various devices equipped with a SIM card 3 based on the first location information and the second location information. That is, if, for example, a plurality of readers 41 that output the first location information are provided in each of a plurality of areas of a factory, and a SIM card 3 is equipped in a transport vehicle traveling within the factory, the virtual network KN may be assigned to each transport vehicle based on the first location information transmitted from the corresponding reader 41 in each area where the transport vehicle is located, and the second location information transmitted from the base station KK.
[0018] The information terminal 2 is configured as a terminal device (mobile terminal) equipped with the functions of a mobile phone, such as a smartphone, tablet PC, or personal computer. The information terminal 2 includes a control unit 21, a storage unit 22, a communication unit 23, and a display unit 24, and a 5G-compatible SIM card 3 is inserted inside the terminal.
[0019] The control unit 21 has one or more central processing units (CPUs), micro-processing units (MPUs), graphics processing units (GPUs), and other processing devices with timekeeping and GPS functions, and performs various information processing, control processing, etc. related to the information terminal 2 by reading and executing programs (program products) stored in the memory unit 22.
[0020] The storage unit 22 includes a volatile storage area such as a static random access memory (SRAM), a dynamic random access memory (DRAM), or a flash memory, and a non-volatile storage area such as an EEPROM or a hard disk. The storage unit 22 pre-stores a program (program product) and data to be referenced during processing. The program stored in the storage unit 22 may be a program read from a recording medium 221 that can be read by a terminal device. Alternatively, the program may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 22.
[0021] The communication unit 23 is, for example, a communication IF compatible with 5G, and functions as a wide-area communication unit. The communication unit may further include a short-range communication unit having a Wi-Fi (registered trademark) or NFC (Near Field Communication) function for communicating information from an IC chip compatible with the NFC standard by short-range wireless communication.
[0022] The display unit 24 is, for example, a liquid crystal display, and is provided integrally with the main body (housing) of the information terminal 2. The display unit 24 may function as an input unit such as a touch panel. The display unit 24 may display a QR code (registered trademark) or the like that is to be read (read target) by the reader 41.
[0023] The SIM card 3 complies with the 5G standard, includes a microcomputer 31, an input / output unit 32, and a non-volatile memory 33, and is inserted into a slot provided inside the information terminal 2. The microcomputer 31 has a CPU and a memory. The microcomputer 31 of the SIM card 3 may be responsible for accepting the virtual network KN allocated by the control device 1 (5G core network).
[0024] The input / output unit 32 is a connection interface for connecting to the information terminal 2, and by connecting to a slot (connection unit) provided in the information terminal 2, it becomes possible to exchange information between the control unit 21 of the information terminal 2 and the SIM card 3. The microcomputer 31 and the nonvolatile memory 33 may be formed on a single semiconductor circuit, or may be configured as separate semiconductor circuits.
[0025] The nonvolatile memory 33 is configured of, for example, an EEPROM, similar to the storage unit 22 of the information terminal 2, and stores (memorizes) the first location information and the second location information acquired (received) by the information terminal 2 in a combined (associated) manner. In the present embodiment, the first location information and the second location information are stored (memorized) in the nonvolatile memory 33 of the SIM card 3, but this is not limitative, and the first location information and the second location information may be stored (memorized) in the storage unit 22 of the information terminal 2.
[0026] The control device 1 is a device that configures and controls the 5G core network, and performs processes such as generation, allocation, and deletion of the virtual network KN. The 5G core network is configured by multiple devices, such as an MME (Mobility Management Entity), an SGW (Serving Gateway), and a PGW (Packet data network Gateway), working together, and the control device 1 is a collective term for these multiple devices, and the control unit 11, storage unit 12, communication unit 13, etc. that the control device 1 is provided with are intended to indicate the control units, etc., that these multiple devices are provided with.
[0027] The control unit 11 of the control device 1 is configured with multiple CPUs, etc., and performs overall control processing as a 5G core network, such as relay control in 5G communication, and generation, allocation, and deletion of a virtual network KN by network slicing, by reading and executing a control program (program product) stored in the storage unit 12. The communication unit 13 of the control device 1 includes a 5G-side communication IF that communicates with the base station KK, and a communication IF on the wide area network BN side, such as the Internet.
[0028] The storage unit 12 of the control device 1 is configured with volatile and nonvolatile storage areas, and stores a control program for performing overall control processing as a 5G core network. The control program may be a control program read from a recording medium 121 readable by the control device 1. Alternatively, the program may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 12.
[0029] The storage unit 12 of the control device 1 stores an authentication table used when allocating a virtual network KN to the information terminal 2. The control device 1 determines the validity of the combination of the first location information and the second location information transmitted from the information terminal 2 by referring to the authentication table stored in the storage unit, i.e., performs mutual authentication based on the first location information and the second location information.
[0030] 3 is an explanatory diagram showing an example of an authentication table. The authentication table includes, as management items (fields), for example, first location information indicating the physical location of the information terminal 2 and second location information specifying the base station KK. The field for the first location information stores the reader ID of a reader 41 provided in each of multiple rooms 4 in a shared office or the like. The field for the second location information stores the base station ID of the base station KK to be controlled by the control device 1.
[0031] Each record in the authentication table is configured with fields for the first location information and the second location information, thereby managing combinations of the first location information and the second location information. That is, a combination of the first location information and the second location information stored (defined) in any record is determined to be a valid combination of the first location information and the second location information, and the mutual authentication by the control device 1 results in a positive outcome. If the combination of the first location information and the second location information transmitted by the information terminal 2 does not correspond to the combination of the first location information and the second location information in any record, the mutual authentication by the control device 1 results in a negative outcome.
[0032] The second location information field is said to store the reader ID of the reader 41 installed in each of multiple rooms 4, such as a shared office, but is not limited to this and may also store GPS data (latitude, longitude) indicating the location information of the room 4.
[0033] 4 is an explanatory diagram (sequence diagram) illustrating one mode of each process by the information terminal 2, the control device 1, etc. The reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2 as entrance / exit control when the user of the information terminal 2 enters a room (S11). The reader 41 may perform entrance / exit control when the user of the information terminal 2 enters a room, for example, by reading a QR code displayed on the display unit 24 of the information terminal 2. Alternatively, the reader 41 and the information terminal 2 may have an NFC (Near Field Communication) function, and the reader 41 may obtain information associated with the information terminal 2 by reading information on an NFC-compliant IC chip inserted into the information terminal 2 using short-range communication according to the NFC standard.
[0034] The reader 41 transmits (outputs) a reader ID (first location information) to the information terminal 2 (S12). The reader 41 and the information terminal 2 communicate using a short-range communication function such as WiFi, NFC, or infrared communication, and the information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as the first location information. The first location information is not limited to the reader ID transmitted from the reader 41, and may be, for example, GPS data indicating the current location of the information terminal 2. The information terminal 2 may use GPS data acquired by a GPS module included in the information terminal 2 as the first location information when triggered by a signal or the like transmitted from a door gate such as the reader 41 that is used for entrance / exit control when the user of the information terminal 2 enters a room.
[0035] The base station KK transmits (outputs) the base station ID (second location information) to the information terminal 2 (S13). The base station KK broadcasts its own base station ID using a 5G carrier, for example, and the information terminal 2 receives (acquires) the base station ID from the base station KK as the second location information.
[0036] The information terminal 2 stores (memorizes) the reader ID (first location information) and the base station ID (second location information) in the SIM card 3 (S14). The information terminal 2 associates (combines) the acquired first location information and second location information and stores them in the non-volatile memory 33 of the SIM card 3, thereby storing them in the SIM card 3.
[0037] The information terminal 2 transmits (outputs) the reader ID (first location information) and base station ID (second location information) stored in the SIM card 3 to the control device 1 via the base station KK (S15). The information terminal 2 and the control device 1 communicate using, for example, a 5G carrier, and the control device 1 receives (acquires) the reader ID (first location information) and base station ID (second location information) transmitted from the information terminal 2.
[0038] The control device 1 performs mutual authentication using a combination of the received reader ID (first location information) and base station ID (second location information) (S16). The control device 1 may perform authentication processing (determination processing) to determine whether the combination of the first location information and the base station ID transmitted from the information terminal 2 is appropriate (positive) or not (negative) by, for example, referring to an authentication table stored in a storage unit.
[0039] If the mutual authentication is positive, the control device 1 assigns the virtual network KN to the information terminal 2 (S17). The information terminal 2 connects to the virtual network KN assigned by the control device 1. As described above, the control device 1 is, for example, a 5G core network (a group of devices that control a 5G core network), and generates individually independent logical networks (virtual networks KN) using the same physical infrastructure while using network slicing, which is a function of 5G. By assigning the virtual network KN thus generated to the information terminal 2, the control device 1 provides the information terminal 2 with access permission to the virtual network KN and communication resources such as bandwidth. The information terminal 2 to which the virtual network KN is assigned can connect to, for example, a management server KS connected to a wide area network BN such as the Internet, or various application servers, using a secure network environment using the virtual network KN.
[0040] The information terminal 2 transmits (outputs) the encrypted log data to the management server KS via the allocated virtual network KN (S18). When communicating data with the management server KS that manages log data such as the operation log and communication log of the information terminal 2 via the allocated virtual network KN, the information terminal 2 may generate encrypted log data to which the first location information and the second location information are added, and transmit the encrypted log data to the management server KS.
[0041] The reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2 as entry / exit control when the user of the information terminal 2 leaves the room (S19). When the user of the information terminal 2 leaves the room, the reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2, in the same way as when the user enters the room.
[0042] The reader 41 transmits (outputs) the reader ID (first location information) to the information terminal 2 (S20). The information terminal 2 receives (acquires) the reader ID (first location information) from the reader 41. When the user of the information terminal 2 leaves the room, the information terminal 2 also receives (acquires) the reader ID (first location information) from the reader 41, in the same way as when the user enters the room.
[0043] The information terminal 2 generates exit information based on the received reader ID (first location information) and transmits (outputs) it to the control device 1 via the base station KK (S21). The information terminal 2 generates exit information based on the received reader ID (first location information) when the user of the information terminal 2 leaves the room, and transmits (outputs) the generated exit information to the control device 1. The exit information is, for example, data in which a predetermined flag (exit flag) is added to the reader ID (first location information).
[0044] The control device 1 receives (acquires) the exit information from the information terminal 2. This allows the control device 1 to recognize that the information terminal 2 to which the virtual network KN has been assigned has left the room 4 identified by the first location information. In other words, by receiving the exit information from the information terminal 2, the control device 1 can recognize that the information terminal 2 to which the virtual network KN has been assigned based on the positive result of mutual authentication is currently in a state that does not correspond to the positive result.
[0045] The control device 1 halts the allocation of the virtual network KN to the information terminal 2 (S22). By halting the allocation of the virtual network KN to the information terminal 2, access to the virtual network KN by the information terminal 2 is blocked. When halting the allocation of the virtual network KN to the information terminal 2, the control device 1 may eliminate the virtual network KN. Alternatively, the control device 1 may maintain the virtual network KN whose allocation is to be halted, but transition the state of the virtual network KN to an inactive state and block access (connection) from the information terminal 2, thereby halting the allocation of the virtual network KN to the information terminal 2.
[0046] When canceling the allocation of the virtual network KN to the information terminal 2, the control device 1 may transmit alert information indicating that the allocation of the virtual network KN has been canceled to the information terminal 2. The alert information is displayed, for example, on the display unit 24 of the information terminal 2, thereby efficiently notifying the user of the information terminal 2 that the allocation of the virtual network KN has been canceled.
[0047] When the control device 1 receives (acquires) exit information from the information terminal 2, it may stop allocating the virtual network KN to the information terminal 2 after a predetermined grace period, such as five minutes, has elapsed. In this case, it goes without saying that if the reader ID (first location information) and the base station ID (second location information) are transmitted (retransmitted) from the information terminal 2 within the grace period (before the grace period has elapsed), the control device 1 continues allocating the virtual network KN to the information terminal 2.
[0048] 5 is a flowchart showing an example of allocation processing of the virtual network KN. The flow of processing by the control unit 21 of the information terminal 2 and the control unit 11 of the control device 1, and the relationship between these processes will be described.
[0049] When the user of information terminal 2 enters the room, control unit 21 of information terminal 2 receives (acquires) the reader ID transmitted from reader 41 as first location information (T101). When the user of information terminal 2 enters the room, reader 41 (the door gate of room 4) reads information associated with information terminal 2 from information terminal 2, for example, by using a QR code or an NFC function, and transmits its own reader ID to information terminal 2. Control unit 21 of information terminal 2 receives (acquires) the reader ID transmitted from reader 41 as first location information.
[0050] The control unit 21 of the information terminal 2 receives (acquires) the base station ID as second location information from the base station KK (T102). The control unit 21 of the information terminal 2 receives (acquires) the base station ID as second location information from the base station KK whose communication area is the location where the reader 41 is placed, i.e., the room 4 that the user has entered.
[0051] The control unit 21 of the information terminal 2 stores (memorizes) the reader ID (first location information) and the base station ID (second location information) in the SIM card 3 (T103). The microcomputer 31 of the SIM card 3 associates (combines) the reader ID (first location information) and the base station ID (second location information) acquired from the control unit 21 of the information terminal 2, and stores them in the non-volatile memory 33.
[0052] The control unit 21 of the information terminal 2 transmits (outputs) the reader ID (first location information) and base station ID (second location information) stored in the SIM card 3 to the control device 1 via the base station KK (T104). The control unit 21 of the information terminal 2 transmits (outputs) the reader ID (first location information) and base station ID (second location information) stored in the SIM card 3 to the control device 1 (5G core network) using the 5G carrier (bandwidth) provided by the base station KK.
[0053] The control unit 21 of the information terminal 2 transmits (outputs) the encrypted log data with the first location information and the second location information added thereto to the management server KS via the allocated virtual network KN (T105). When the virtual network KN is allocated by the control device 1 (5G core network), the control unit 21 of the information terminal 2 accepts the allocation, connects to the virtual network KN as a communication node, and thereafter transmits (outputs) the encrypted log data with the first location information and the second location information added thereto to the management server KS. In addition, the control unit 21 of the information terminal 2 may access (perform data communication) an application server or the like connected to a wide area network BN such as the Internet via the virtual network KN.
[0054] When the user of the information terminal 2 leaves the room, the control unit 21 of the information terminal 2 transmits (outputs) exit information generated based on the reader ID transmitted from the reader 41 to the control device 1 via the base station KK (T106). When the user of the information terminal 2 leaves the room, the control unit 21 of the information terminal 2 transmits (outputs) exit information generated by, for example, adding a predetermined flag (exit flag) to the reader ID (first location information) to the control device 1 via the base station KK. As a result, allocation of the virtual network KN to the information terminal 2 is discontinued, and access from the information terminal 2 to the virtual network KN is blocked.
[0055] The control unit 11 of the control device 1 receives (acquires) the reader ID (first location information) and base station ID (second location information) transmitted from the information terminal 2 (S101). The control unit 11 of the control device 1 performs mutual authentication using a combination of the received reader ID (first location information) and base station ID (second location information) (S102). The control device 1 performs mutual authentication based on the combination of the first location information and second location information transmitted from the information terminal 2 by referring to an authentication table stored in the storage unit.
[0056] The control unit 11 of the control device 1 determines whether the result of the mutual authentication is positive or negative. (S103). The control unit 11 of the control device 1 may determine whether the result of the mutual authentication is positive or negative depending on whether the combination of the first location information and the second location information transmitted from the information terminal 2 is defined (stored in any record) in the authentication table. If the result of the mutual authentication is negative (S103: NO), the control unit 11 of the control device 1 ends the processing in this flowchart. Alternatively, if the result of the mutual authentication is negative, the control unit 11 of the control device 1 may perform loop processing to execute the processing of S101 again.
[0057] If the result of the mutual authentication is positive (S103: YES), the control unit 11 of the control device 1 assigns the virtual network KN to the information terminal 2 (S104). The control unit 11 of the control device 1, which functions as a 5G core network, generates the virtual network KN using network slicing, which is a function of 5G, and assigns it to the information terminal 2. As a result, the information terminal 2 is connected to the virtual network KN, and becomes able to communicate with the management server KS via the virtual network KN.
[0058] The control unit 11 of the control device 1 determines whether or not exit information has been received from the information terminal 2 (S105). If exit information has not been received from the information terminal 2 (S105: NO), the control unit 11 of the control device 1 performs loop processing to execute the processing of S105 again.
[0059] When the control unit 11 of the control device 1 receives the exit information from the information terminal 2 (S105: YES), the control unit 11 of the control device 1 cancels the allocation of the virtual network KN to the information terminal 2 (S106). When the control unit 11 of the control device 1 receives the exit information from the information terminal 2, the control unit 11 recognizes that the information terminal 2 to which the virtual network KN was assigned based on the positive result of mutual authentication is currently in a state that does not correspond to the positive result, and cancels the allocation of the virtual network KN to the information terminal 2. When canceling the allocation of the virtual network KN to the information terminal 2, the control device 1 may eliminate the virtual network KN, or may maintain the virtual network KN whose allocation is canceled, and transition the state of the virtual network KN to an inactive state (connection-disabled state).
[0060] According to an embodiment of the present disclosure, the control device 1 assigns a virtual network KN to the information terminal 2 based on first location information and second location information acquired from the information terminal 2, and connects the information terminal 2 to the virtual network KN. The first location information indicates the physical location information of the information terminal 2, and may be, for example, identification information of a gate through which the information terminal 2 has passed or GPS data indicating the location of the information terminal 2. The second location information is information specifying a base station KK of the local network with which the information terminal 2 can communicate at the time the information terminal 2 is located at the location specified by the first location information, and may be, for example, a base station KK number (base station ID).
[0061] The control device 1 allocates the virtual network KN to the information terminal 2 according to the combination of the first location information and the second location information, thereby ensuring the appropriateness (security) of the information terminal 2 to which the virtual network KN is allocated, i.e., which becomes a communication node in the virtual network KN. The control device 1 may allocate a virtual network KN that has been generated in advance to the information terminal 2, or may newly generate a virtual network KN and allocate it when allocation of a virtual network KN becomes necessary.
[0062] According to an embodiment of the present disclosure, the control device 1 performs mutual authentication using the combination of the acquired first location information and second location information, for example, by referring to a predetermined authentication table, and if the result of the mutual authentication is positive, performs a process of assigning a virtual network KN to the information terminal 2. By referring to the authentication table in this way, it is possible to efficiently determine the appropriateness of the combination of the first location information and the second location information. If the result of the mutual authentication is negative, the control device 1 may output, for example, error information indicating that the mutual authentication has failed to the information terminal 2, without performing the process of assigning the virtual network KN to the information terminal 2.
[0063] According to an embodiment of the present disclosure, the information terminal 2 is assigned a virtual network KN generated (constructed) by network slicing (5G network slicing) in 5G (fifth generation mobile communication system), thereby enabling virtual independent logical networks to be multiplexed on the same physical network architecture.
[0064] According to an embodiment of the present disclosure, the first location information indicating the physical location of the information terminal 2 is, for example, information about a reader 41 provided in each of a plurality of rooms 4 in a shared office or the like, and is, for example, a reader 41 number (reader ID) for individually identifying each reader 41. When a user carrying an information terminal 2 enters the room 4, the reader 41 reads information associated with the information terminal 2, for example, by using a QR code or a near field communication (NFC) function, thereby controlling entry and exit (entry and exit management) of the user to the room 4. If the reader 41 successfully reads the information (QR code, etc.) of the information terminal 2, the reader 41 transmits (outputs) the reader 41 number (reader ID) to the information terminal 2, and the reader 41 number (reader ID) is combined with the second location information (base station ID) as the first location information and transmitted to the control device 1.
[0065] The control device 1 allocates the virtual network KN based on the first location information and the second location information that identify the room 4 in which the information terminal 2 is located, so even if there are multiple rooms 4 within the communication area of a single base station KK, it is possible to allocate a virtual network KN corresponding to each room 4 in which each information terminal 2 is located. This makes it possible to allocate a different virtual network KN to each room 4 in a facility with multiple rooms 4, such as a shared office, and efficiently ensure security on a room-by-room 4 basis.
[0066] According to an embodiment of the present disclosure, when a user of the information terminal 2 leaves the room 4 corresponding to the first location information, information attached to the information terminal 2, such as a QR code, is read by a reader 41 that controls entry and exit to the room 4. At this time, the information terminal 2 transmits exit information indicating that the information terminal 2 (its own terminal) is located outside the room 4 corresponding to the first location information to the control device 1. When the control device 1 acquires the exit information from the information terminal 2, it cancels the allocation of the virtual network KN to the information terminal 2, thereby efficiently prohibiting the information terminal 2 from connecting to (accessing) the virtual network KN when the information terminal 2 is outside the room 4 corresponding to the first location information, and efficiently ensuring security in the virtual network KN.
[0067] According to an embodiment of the present disclosure, an information terminal 2 to which a virtual network KN is assigned transmits data (log data) such as operation log data or communication log data to a management server KS connected to the Internet, for example, via the virtual network KN. The data is encrypted with the first location information and second location information added when mutual authentication is performed by the control device 1, and therefore, the security of the transmitted data based on the first location information and second location information can be ensured not only when the virtual network KN is assigned, but also in a communication state using the virtual network KN after the assignment.
[0068] In the embodiment of the present disclosure, the virtual network KN is assumed to be generated by network slicing, which is a function of 5G, but is not limited to this. The virtual network KN may be generated by network slicing based on next-generation communications, such as 6G or 7G, that are applied after 5G.
[0069] (Embodiment 2) 6 is a flowchart showing an example of allocation processing of a virtual network KN according to the second embodiment (multiple information terminals 2). The second embodiment relates to a state in which multiple information terminals 2 exist in a single room 4 (users of multiple information terminals 2 have entered the room). Since the processing in each information terminal 2 is the same as in the first embodiment, the processing related to the control device 1 will be explained.
[0070] The control unit 11 of the control device 1 determines whether or not the first location information and the second location information have been received from the information terminal 2 (S201). If the first location information and the second location information have not been received (S201: NO), the control unit 11 of the control device 1 performs a loop process to execute the process of S201 again.
[0071] If the first location information and the second location information are received (S201: YES), the control unit 11 of the control device 1 assigns a virtual network KN to the information terminal 2 that transmitted the first location information and the second location information (S202).
[0072] The control unit 11 of the control device 1 increments the number of information terminals 2 to which the virtual network KN is assigned by one (S203). The control unit 11 of the control device 1 stores the current number of information terminals 2 to which the virtual network KN is assigned in a storage unit or the like by storing the number in, for example, a predetermined variable. The variable for storing the number of information terminals 2 is defined for each generated virtual network KN, and the number of information terminals 2 to which the virtual network KN is assigned is stored in each variable corresponding to each virtual network KN. The control unit 11 of the control device 1 increments the number of information terminals 2 to which the virtual network KN is assigned by one, and performs loop processing to execute the processing of S201 again.
[0073] The control unit 11 of the control device 1 determines whether or not exit information has been received from the information terminal 2 (S204). If exit information has not been received (S204: NO), the control unit 11 of the control device 1 performs loop processing to execute the processing of S204 again.
[0074] When the exit information is received (S204: YES), the control unit 11 of the control device 1 suspends the allocation of the virtual network KN to the information terminal 2 that transmitted the exit information (S205). The control unit 11 of the control device 1 suspends the allocation of the virtual network KN to the information terminal 2 that transmitted the exit information, but maintains the virtual network KN itself without eliminating it. As a result, the allocation of the virtual network KN to the information terminal 2 that did not transmit the exit information, i.e., the information terminal 2 that is present in the room 4 corresponding to the first location information, continues. When the information terminal 2 that transmitted the exit information is once again present in the room 4 corresponding to the first location information, i.e., when the user of the information terminal 2 re-enters the room 4, the control unit 11 of the control device 1 resumes (reassigns) the allocation of the virtual network KN to the information terminal 2 that has re-entered the room. By performing the reallocation process in this manner, the allocation process of the virtual network KN to the information terminal 2 that has re-entered the room can be efficiently performed.
[0075] The control unit 11 of the control device 1 decreases the number of information terminals 2 to which the virtual network KN is assigned by one (S206). The control unit 11 of the control device 1 decreases the number of information terminals 2 to which the virtual network KN is assigned by one, and performs loop processing to execute the processing of S206 again.
[0076] The control unit 11 of the control device 1 determines whether the number of information terminals 2 to which the virtual network KN is assigned is 0 (S207). If the number of information terminals 2 to which the virtual network KN is assigned is not 0 (S207: NO), the control unit 11 of the control device 1 performs loop processing to execute the processing of S207 again.
[0077] If the number of information terminals 2 to which the virtual network KN is assigned is 0 (S207: YES), the control unit 11 of the control device 1 eliminates (S208) the virtual network KN that has been assigned to these multiple information terminals 2. If the number of information terminals 2 to which the virtual network KN is assigned is 0, the control unit 11 of the control device 1 eliminates the virtual network KN that has been assigned to these multiple information terminals 2 and prevents reallocation by these information terminals 2, thereby halting the allocation of the virtual network KN to all of the multiple information terminals 2.
[0078] According to an embodiment of the present disclosure, when allocating a different virtual network KN to each room 4, if multiple information terminals 2 exist in the same room 4 (rooms 4 corresponding to the same first location information), the control device 1 allocates the same virtual network KN to these multiple information terminals 2. As a result, the multiple information terminals 2 existing (located) in the same room 4 share the same virtual network KN, and while ensuring security by the virtual network KN, communication between these multiple information terminals 2 can be performed with a low number of hops, thereby improving communication efficiency.
[0079] According to an embodiment of the present disclosure, when multiple information terminals 2 are present in the same room 4 (rooms 4 corresponding to the same first location information), if all of these multiple information terminals 2 are located outside the room 4, the control device 1 will, for example, terminate the virtual network KN, thereby ceasing the allocation of the virtual network KN to all of the multiple information terminals 2, thereby efficiently ensuring security in the virtual network KN.
[0080] The embodiments disclosed herein are to be considered as illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0081] S Virtual Network Allocation System BN Wide Area Network KS Management Server KN Virtual Network KK base station 1. Control device 11 Control section 12 Storage section 121 Recording Media 13 Communications Department P1 control program 2. Information terminal 21 Control section 22 Memory section 221 Recording Media P2 Program 23 Communications Department 24 Display section 3 SIM cards 31 Microcomputer 32 Input / output section 33 Non-volatile memory 4 rooms 41 Reading device (door gate, entry / exit control device)
Claims
1. acquiring first location information relating to a location where the information terminal is located; acquiring second location information that identifies a base station of a local network with which the information terminal can communicate; assigning a virtual network to be connected to the information terminal in accordance with the acquired first location information and the acquired second location information; The communication protocol of the local network is 5G, The virtual network is generated by network slicing in 5G, The generation by the network slicing is performed after selecting a base station of the local network and confirming location information between the base station of the local network and the location where the information terminal is located. A program that causes a computer to perform a process.
2. performing mutual authentication using a combination of the acquired first location information and the acquired second location information; If the result of the mutual authentication is positive, the virtual network to be connected to the information terminal is assigned. The program according to claim 1.
3. the first location information is information about a reader provided in each of a plurality of rooms and configured to read information associated with the information terminal; The virtual network is assigned to each of the information terminals corresponding to each of the plurality of rooms. The program according to claim 1 or 2.
4. When the information terminal acquires exit information indicating that the information terminal is located outside the room corresponding to the first location information, Stopping allocation of the virtual network to the information terminal The program according to any one of claims 1 to 3.
5. When a plurality of information terminals are present in a room corresponding to the same first location information, the same virtual network is assigned to the plurality of information terminals. The program according to any one of claims 1 to 4.
6. After the plurality of information terminals are present in a room corresponding to the same first location information and the same virtual network is allocated to the plurality of information terminals, when exit information indicating that the information terminal is located outside the room is acquired from all of the plurality of information terminals, allocation of the virtual network to all of the plurality of information terminals is stopped. The program according to claim 5.
7. The data transmitted from the information terminal via the virtual network is encrypted with the first location information and the second location information added thereto. The program according to any one of claims 1 to 6.
8. On the computer, acquiring first location information relating to a location where the information terminal is located; acquiring second location information that identifies a base station of a local network with which the information terminal can communicate; assigning a virtual network to be connected to the information terminal in accordance with the acquired first location information and the acquired second location information; The communication protocol of the local network is 5G, The virtual network is generated by network slicing in 5G, The generation by the network slicing is performed after selecting a base station of the local network and confirming location information between the base station of the local network and the location where the information terminal is located. A virtual network allocation method for executing processing.
9. A virtual network allocation system including an information terminal and a control device that allocates a virtual network to the information terminal, The information terminal acquiring first location information relating to a location where the terminal is located; acquire second location information that identifies a base station that defines the location of the terminal as a local network that can communicate with the terminal, outputting the acquired first position information and second position information to the control device; The control device acquiring the first location information and the second location information from the information terminal; assigning a virtual network to be connected to the information terminal in accordance with the acquired first location information and the acquired second location information; The communication protocol of the local network is 5G, The virtual network is generated by network slicing in 5G, The generation by the network slicing is performed after selecting a base station of the local network and confirming location information between the base station of the local network and the location where the information terminal is located. Virtual network allocation system.
10. acquiring first location information relating to a location where the information terminal is located; acquiring second location information that identifies a base station of a local network with which the information terminal can communicate; assigning a virtual network to be connected to the information terminal in accordance with the acquired first location information and the acquired second location information; When the information terminal acquires exit information indicating that the information terminal is located outside the room corresponding to the first location information, the allocation of the virtual network to the information terminal is stopped; The second location information acquired by the information terminal at the time of acquiring the exit information is the second location information at the time of allocation of the virtual network. A program that causes a computer to perform a process.
Citation Information
Patent Citations
Conference room reservation system, conference room reservation method, and conference room reservation program
JP2016184241A
Communication control method and connection target change method
JP2021016014A
Network connection method and apparatus
US20200205205A1
Controlling an operation mode of a communications network
WO2020120647A1
JP1973011606B1