Virtual private network generation system
The virtual private network generation system ensures secure and reliable communication by authenticating users and terminals, monitoring connections, and restricting access, addressing security risks in virtual networks across multiple public clouds and physical networks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- NEC NETWORKS & SYST INTEGRATION CORP
- Filing Date
- 2024-10-15
- Publication Date
- 2026-04-27
AI Technical Summary
Existing virtual network technologies do not guarantee the reliability of user terminals and their connections, leading to security risks such as data leaks and unauthorized access, especially when spanning multiple public clouds and different physical networks.
A virtual private network generation system that includes user terminals, an authentication server, a virtual private network agent, and a terminal status monitoring agent, ensuring only authenticated users and terminals can connect, with secure communication monitored and restricted to prevent unauthorized access.
Enables highly reliable and secure communication by monitoring connections and restricting access, preventing data leakage and unauthorized access, allowing safe use of cloud services across different physical networks.
Smart Images

Figure 2026070387000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a virtual closed network generation system that can be connected only by an authenticated user and their terminal, and can securely connect to various services (SaaS: Software as a Service) publicly available on a public cloud, enabling comfortable communication with high reliability without depending on the configuration of different physical networks between a user's home and an enterprise base, or between enterprises.
Background Art
[0002] Conventionally, a technique for constructing a virtual network that does not depend on the configuration of a physical network is known.
[0003] Patent Document 1 discloses an invention defined as an overlay network spanning multiple public clouds for interconnecting one or more private networks (e.g., networks within a branch office, department, entity department, or related data center), mobile users, SaaS (Software as a Service) provider machines, machines and / or services within a public cloud, and other web applications.
[0004] Patent Document 2 discloses an invention for accessing a server within an enterprise from an external shared facility while ensuring information security.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0006] Patent Document 1 describes how to transfer data messages using Source Network Address Translation (SNAT) over a virtual network defined for a specific tenant that spans multiple public cloud data centers.
[0007] However, while it enables secure and optimized communication, it does not guarantee the reliability of the entire virtual network, including the reliability of the users and their terminals connected to the virtual network, which is the source of data messages and other communications.
[0008] Patent Document 2 associates facility reservation information indicating the usage period of multiple shared facilities that can be used by multiple people belonging to multiple groups, facility identification information, and connection destination information indicating a connection destination that enables communication with the shared facilities via a communication line, and transfers data messages via a virtual network defined for a specific tenant.
[0009] However, managing facility reservation information using facility IDs or connection IDs carries security risks such as data leaks, and naturally, errors in facility reservation information can lead to problems such as being unable to connect to necessary resources.
[0010] Therefore, the present invention aims to provide a virtual private network generation system that enables comfortable communication with high reliability, regardless of the configuration of different physical networks between users' homes, corporate locations, or different companies. This is achieved by generating a virtual private network that can only be connected to by appropriately authenticated users and their terminals, and that can securely connect to various services (SaaS: Software as a Service) exposed on the public cloud. [Means for solving the problem]
[0011] To achieve the above objective, the present invention provides a virtual private network generation system that generates a highly reliable virtual private network, comprising: a user terminal used by a user to connect to the virtual private network; an authentication server that authenticates the user; a virtual private network agent that controls the user terminal's connection to the virtual private network; and a terminal status monitoring agent that monitors the status of the user terminal. The system is characterized in that the user terminal transmits authentication information that identifies the user to the authentication server, the authentication server uses the authentication information to authenticate the user's connection to the virtual private network, and when the user terminal is permitted to connect to the virtual private network by the authentication server, the virtual private network agent establishes private communication to the virtual private network and the terminal status monitoring agent starts monitoring the private communication. If the terminal status monitoring agent detects that the private communication has not been established, it puts the user terminal into a deactivated state.
[0012] Furthermore, the aforementioned "disabled state" of the present invention is characterized by setting the communication settings or restrictions on accessible connection destinations of the user terminal to a state that has been pre-configured based on the user of the user terminal.
[0013] Furthermore, the virtual private network generation system of the present invention further includes a virtual private network connector that establishes a secure connection with the virtual private network agent via the virtual private network. When using SaaS from a user terminal, if the SaaS private connection service is used, the SaaS private connection service is used via the virtual private network connector located within the SaaS private connection service, thereby enabling secure access to the SaaS using the SaaS private connection service.
[0014] Furthermore, the virtual private network generation system of the present invention further includes a secure web gateway for connecting to the Internet, the secure web gateway includes a virtual private network connector that establishes a secure connection with the virtual private network agent via the virtual private network, and all access to the Internet from the user terminal is performed via the secure web gateway through the virtual private network connector located within the secure web gateway.
[0015] Furthermore, the virtual private network generation system of the present invention further includes a user authentication terminal for authenticating the user, and transmits the authentication information that identifies the individual from the user terminal to the authentication server, and when the authentication server uses the authentication information to authenticate the user's connection to the virtual private network, the authentication server requests the user to perform the necessary input operations for authentication to identify the individual via the user authentication terminal.
[0016] Furthermore, the user authentication terminal of the present invention is characterized by being a terminal that can be carried by the user.
[0017] Furthermore, the user authentication terminal of the present invention is characterized by being a terminal capable of authenticating the user by biometric authentication.
[0018] Furthermore, the virtual private network generation system of the present invention further includes an authentication linkage platform that integrates or links the authentication information that identifies the user among a plurality of different authentication servers, and when the user terminal transmits the authentication information that has been previously integrated or linked in the authentication linkage platform to the authentication server as the authentication information that identifies the individual, the authentication server transmits the authentication information to the authentication linkage platform, and the authentication linkage platform uses the authentication information to authenticate the user's connection to the virtual private network. [Effects of the Invention]
[0019] According to the virtual private network generation system of the present invention, a virtual private network is provided that can only be accessed by user terminals on which a terminal status monitoring agent is installed. By monitoring the connection not only when connecting to the virtual private network but also at all times, user terminals assigned to users can connect to cloud services and the like only via the virtual private network, thereby preventing data leakage and unauthorized access, and enabling the safe and efficient use of multiple cloud services.
[0020] In this case, if the user terminal is authorized to connect to the virtual private network from the authentication server, the virtual private network agent establishes private communication to the virtual private network, and the terminal status monitoring agent constantly monitors this private communication. If the terminal status monitoring agent detects that private communication has not been established, it puts the user terminal into a disabled state. This ensures that the use of various services is guaranteed only via the virtual private network, enabling highly secure communication.
[0021] Furthermore, this disabled state setting can be configured according to the desired level of security, for example. Since the disabled state can be freely configured according to the desired level of security for virtual private network communication, user attributes, and the type of user terminal or user authentication terminal, it becomes possible to impose restrictions (disabled state) according to individual circumstances.
[0022] Furthermore, by pre-installing virtual private network connectors in data centers (SaaS private network service departments) of companies providing SaaS private network connection services, direct access to various SaaS applications becomes possible from the virtual private network. This enables more secure communication by eliminating the need to go through the internet when accessing SaaS applications.
[0023] Furthermore, by providing a secure web gateway where a virtual private network connector is arranged, all Internet access is routed through the secure web gateway, enabling all traffic to be monitored and all traffic to be analyzed in case of problems, thus making it possible to construct a more secure and reliable virtual private network.
[0024] Furthermore, since connection to the virtual private network requires authentication that identifies the individual user, it is possible to extend the authentication of the virtual private network not only to the connection terminal but also to the credibility of the user, and to expand the security boundary not only to the connection terminal but also to the credibility of the individual user.
[0025] Furthermore, in personal authentication, by using a user authentication terminal, it becomes possible to reliably identify the individual user, and thereby it becomes possible to expand the security boundary with higher strength not only to the connection terminal but also to the credibility of the individual user.
[0026] Furthermore, by having an authentication cooperation infrastructure that integrates or cooperates the authentication information for identifying the individual user among a plurality of different authentication servers, when generating a virtual private network that spans different enterprises with different physical networks, even if the authentication servers of each enterprise are different, it is possible to easily ensure a high level of security with the pre-integrated or cooperative authentication information and authenticate the connection of individual users to the virtual private network.
Brief Description of the Drawings
[0027] [Figure 1] It is a block diagram showing the configuration of a virtual private network generation system. [Figure 2] It is a block diagram showing the configuration of a user terminal. [Figure 3] It is a flowchart showing an overview of the connection process of a user terminal in a virtual private network generation system. [Figure 4] It is a flowchart showing a connection process that performs authentication only with ID and password in the first form. [Figure 5]This flowchart shows the process of connecting to a virtual private network where the user authentication terminal performs the input operations necessary for authentication in the second form. [Figure 6] This flowchart shows the process of connecting to a virtual private network where the input operations required for biometric authentication are performed at the user authentication terminal in the third form. [Figure 7] This flowchart shows the process of connecting to a virtual private network where authentication is performed using an authentication collaboration platform. [Figure 8] This flowchart shows the process by which the SaaS private network connection service unit processes access to SaaS from user terminals. [Figure 9] This flowchart shows the process of suspending the use of user terminals connected to a virtual private network (VIP) based on monitoring of the VIP network. [Figure 10] This diagram shows an overview of the communication sequences for connecting a user terminal to the virtual private network, connecting to the SaaS private network connection service, and connecting to the secure web gateway. [Modes for carrying out the invention]
[0028] The following describes an embodiment for implementing the virtual private network generation system according to the present invention with reference to the drawings. In this invention, the user terminal transmits authentication information that identifies the user to an authentication server, and when the user terminal is permitted to connect to the virtual private network from the authentication server, the virtual private network agent establishes private communication to the virtual private network, and at the same time, the terminal status monitoring agent constantly monitors the private communication. If it detects that private communication has not been established, the terminal status monitoring agent puts the user terminal into a disabled state.
[0029] This ensures that only properly authenticated users and their devices can connect to the virtual private network. By creating a virtual private network that allows secure connections to various services exposed on the public cloud, it enables highly reliable and comfortable communication, regardless of the configuration of different physical networks at the user's home, between corporate locations, or between different companies.
[0030] [Configuration of the virtual private network generation system] First, we will detail the configuration of the virtual private network generation system, which generates a virtual private network that allows secure connections to the virtual private network for user terminals and to various services exposed to the public cloud, with reference to Figure 1.
[0031] Figure 1 is a block diagram showing the configuration of a virtual private network generation system. As shown in Figure 1, the virtual private network generation system 1 includes a virtual private network 3, a user terminal 10, an authentication server 24, an authentication cooperation platform 27, a SaaS private network connection service unit 31, a secure web gateway 40, and a data center (DC) 50 of company A.
[0032] The virtual private network 3 is a virtual network (such as a VPN) configured to be superimposed on the physical network 4 that forms the network, and the virtual private network 3 is connected to various devices via virtual private lines (also called tunnels) shown by thick lines.
[0033] Furthermore, tunneling technology is used to ensure secure communication when utilizing the virtual private network 3. By establishing a tunnel, which is a virtual private line, data transmitted over the network is encapsulated and encrypted, enabling secure communication between the sender and destination.
[0034] In the virtual private network 3, tunnels are established using tunneling protocols, ensuring that data encapsulated and encrypted at the source is securely transmitted without being decrypted by third parties until it reaches the destination. While passing through the tunnel, the content and path of the data are invisible to external parties, ensuring the privacy and security of the communication.
[0035] User terminals 10 are terminals connected to the virtual private network 3 that users use for work (such as accessing various SaaS 32, the internet 41, and DC 50). User terminals 10 are installed, for example, at the head office and branches of company A as shown in Figure 1, or at company B, which is different from company A. However, the installation of user terminals 10 is not limited to these locations; they may also be used by groups or individuals (at home).
[0036] Figure 2 is a block diagram showing the configuration of a user terminal. As shown in Figure 2, the user terminal 10 consists of a computer and includes a CPU, a control unit, an input / output unit, a communication interface unit, and a storage unit 11. The storage unit 11 of the user terminal 10, which is a storage device, has a data unit and a program unit. The program unit stores a program to control the user terminal 10, and processing programs for the virtual private network agent 15 and the terminal status monitoring agent 16. The user terminal 10 performs its functions as the virtual private network agent 15 and the terminal status monitoring agent 16 when the CPU executes the processing programs for the virtual private network agent 15 and the terminal status monitoring agent 16.
[0037] The virtual private network agent 15 on the user terminal 10 resides on the user terminal 10 and communicates with the virtual private network 3. Meanwhile, the terminal status monitoring agent 16 monitors the connection to the private network service by the virtual private network agent 15 and controls the user terminal 10 to a disabled state in the event of a connection failure (for example, a state where the virtual private network tunnel cannot be configured due to an unstable network connection).
[0038] The authentication server 24 shown in Figure 1 is a server that uses authentication information to identify the user on the user terminal 10 to perform authentication necessary for accessing various SaaS 32 and other applications, and permits connection to the virtual private network 3. For each company (Company A, Company B), there is an authentication server A and an authentication server B. As shown in Figure 1, the authentication server 24 is connected to the physical network 4, and when the user terminal 10 requests authentication to connect to the virtual private network 3, it connects to the authentication server 24 via the physical network 4.
[0039] The authentication linkage platform 27 shown in Figure 1 integrates or links authentication information that identifies individual users between multiple different authentication servers, such as authentication server A and authentication server B, which are specific to each company. The user authentication terminal 20 is a terminal equipped with a camera or fingerprint authentication, carried by the user and connected to the virtual private network 3, and is used to perform input operations necessary for the authentication of the individual user. For example, it is used for authentication requests such as reading a QR code (registered trademark) from the authentication server 24 or reading biometric information such as the user's face or fingerprints.
[0040] The SaaS private network connection service unit 31 shown in Figure 1 is a data center (server) of a service provider that provides secure direct access to various SaaS 32 via dedicated lines 33, etc. By using the SaaS private network connection service unit 31, user terminals 10 of companies, etc., can directly access SaaS 32 such as cloud services without going through the internet.
[0041] The secure web gateway 40 is the gateway through which user terminals 10 connected to the virtual private network 3 access the internet 41. The secure web gateway 40 ensures the security of access to the internet 41 and can also restrict access to websites if necessary.
[0042] This allows all internet access 41 from the user terminal 10 to be routed through the secure web gateway 40, making all traffic monitorable and enabling analysis of all traffic in the event of a problem.
[0043] Furthermore, as shown in Figure 1, virtual private network connectors 30 are installed in each of the following components connected to the virtual private network 3: company A, company B, SaaS private network connection service unit 31, secure web gateway 40, and DC50.
[0044] The virtual private network connector 30 is a connector that enables remote access (private network connection) from the virtual private network agent 15 in accordance with SDP (Software Defined Perimeter). By installing it on the SaaS private connection service unit 31, which provides connection services for the company's DC50 and SaaS32, and on the secure web gateway 40, which provides internet connectivity, private network connections are made possible.
[0045] The virtual private network generation system 1 controls access to users and user terminals only to authorized resources via the virtual private network connector 30. This prevents unauthorized access and external attacks. Specifically, the virtual private network connector 30 establishes a secure connection with the virtual private network agent 15 via the virtual private network 3, enabling a private network connection.
[0046] Furthermore, the virtual private network connector 30 is embedded as a processing program in the storage devices of the SaaS private connection service unit 31, the secure web gateway 40, and the DC50 server, and the server executes the processing program to perform the processing as the virtual private network connector 30.
[0047] Furthermore, although a virtual private network connector 30 is provided within companies A and B, it is stored as a processing program in the memory of a server (not shown) connected to a DMZ (not shown) or the like, which is connected to the LAN (not shown) within companies A and B. When the server executes the processing program, the virtual private network connector 30 performs its functions.
[0048] This enables external user terminals 10 to establish a private network connection to the company's servers via the virtual private network 3. Note that the external user terminals must have a built-in virtual private network agent 15 and a terminal status monitoring agent 16.
[0049] As shown in Figure 1, the virtual private network 3, user terminal 10, SaaS private network connection service unit 31, and secure web gateway 40 are connected by a virtual network indicated by a thick line, the SaaS private network connection service unit 31 and SaaS 32 are connected by a dedicated line indicated by a double line, and the secure web gateway 40 and the internet 41 are connected by a physical network indicated by a thin line.
[0050] In the block diagram of the virtual private network generation system 1 shown in Figure 1, the virtual private network 3 and physical network 4 are depicted as being independent of companies A, B, SaaS private connection service unit 31, secure web gateway 40, DC50, etc. However, in reality, physical network 4 spans the physical networks (LANs, etc.) of companies A, B, SaaS private connection service unit 31, secure web gateway 40, and DC50. Since the virtual private network 3 is generated superimposed on the physical network 4, in the virtual private network generation system 1, the networks of each company are connected by the virtual private network 3, regardless of the different physical network configurations between each company. Note that the various devices connected to the virtual private network 3 shown in Figure 1 are examples only and are not limited to these.
[0051] [Overview of connection processing in the virtual private network generation system] Next, we will explain the connection process for user terminals in the virtual private network generation system 1. Figure 3 is a flowchart showing an overview of the connection process for user terminals in the virtual private network generation system 1.
[0052] As shown in Figure 3, the user of user terminal 10 first performs an operation to connect to the virtual private network 3 (step S1). Since authentication is required to identify the individual user in order for user terminal 10 to connect to the virtual private network 3, authentication is performed by the authentication server 24.
[0053] After the user terminal 10 is authenticated by the authentication server 24 to identify the individual user, it is permitted to connect to the virtual private network 3, and the virtual private network agent 15 within the user terminal 10 establishes private communication to the virtual private network 3. At the same time, the terminal status monitoring agent 16 within the user terminal 10 starts monitoring the private communication and accesses, for example, a specific SaaS 32 (step S2).
[0054] The terminal status monitoring agent 16 of the user terminal 10 constantly monitors the connection status between the user terminal 10 and the virtual private network 3 (step S3).
[0055] When the terminal status monitoring agent 16 of the user terminal 10 detects that the connection between the user terminal 10 and the virtual private network 3 has been lost, it puts the user terminal 10 into a disabled state (step S4).
[0056] [Regarding connection to a virtual private network] Below, we will describe the connection process of the virtual private network by the user terminal 10 in the virtual private network generation system 1 shown in Figure 3, as shown in the three forms shown in Figures 4 to 6. First, we will describe in detail the first form in which connection authentication to the virtual private network is performed using an ID and password. Figure 4 is a flowchart of the connection process in the first form in which authentication is performed using only an ID and password.
[0057] Furthermore, the ID and password used as authentication information are registered in advance on the authentication server 24. As shown in Figure 4, the connection process for the virtual private network 3 begins with the user terminal 10 sending its ID and password to the authentication server 24 and requesting a connection to the virtual private network 3 (step S10).
[0058] The authentication server 24 verifies the user ID and password of the user terminal 10 that made the connection request against the user registration information (step S11), performs authentication (step S12), and if authentication is successful (if OK in step S12), allows the user terminal 10 to connect to the virtual private network 3, and the user terminal 10 connects to the virtual private network 3 (step S13).
[0059] If authentication to identify the user is successful and the user connects to the virtual private network 3, the terminal status monitoring agent 16 in the user terminal 10 starts monitoring the private network communication (step S14). If authentication fails (if it is NG in step S12), the user terminal 10 continues the operations from step S10.
[0060] Next, a second form of the connection process between the user terminal 10 and the virtual private network 3 will be explained with reference to Figure 5. In the second form, authentication confirmation information is sent from the authentication server 24 to the user authentication terminal 20, and the user performs the necessary input operations for authentication using the user authentication terminal 20 to perform the connection process to the virtual private network 3. Figure 5 is a flowchart showing the connection process to the virtual private network in the second form, where the user authentication terminal performs the necessary input operations for authentication.
[0061] Furthermore, the ID and password used as authentication information are registered in advance with the authentication server 24. As shown in Figure 5, the connection process for the virtual private network 3 begins with the user terminal 10 sending its ID and password to the authentication server 24 and requesting a connection to the virtual private network 3 (step S20).
[0062] The authentication server 24 compares the user ID and password of the user terminal 10 that made the connection request with the user registration information. After verifying the user, the authentication server 24 extracts the information of the user authentication terminal 20 that is registered in association with the verified user, and sends a one-time password (PW) or an authentication URL to the extracted user authentication terminal 20 (step S21).
[0063] The user authentication terminal 20 displays a one-time password (PW) or an authentication URL sent from the authentication server 24, and a message is displayed requesting the user to enter the one-time password or click the authentication URL (step S22).
[0064] The user performs an input action such as entering a one-time password displayed on the user authentication terminal 20 or clicking on an authentication URL (step S23).
[0065] The authentication server 24 verifies the verification of the one-time password or the click operation of the authentication URL (step S24), performs authentication to identify the user (step S25), and if authentication is successful (if OK in step S25), it allows the user terminal 10 to connect to the virtual private network 3, and the user terminal 10 connects to the virtual private network 3 (step S26).
[0066] If authentication to identify the user is successful and the user connects to the virtual private network 3, the terminal status monitoring agent 16 in the user terminal 10 starts monitoring the private network communication (step S27). If authentication fails (NG in step S25), the user terminal 10 proceeds to the operations in step S23 or from step S20.
[0067] Next, a third form of the connection process between the user terminal 10 and the virtual private network 3 will be explained with reference to Figure 6. In the third form, the authentication server sends a biometric authentication request message to the user authentication terminal 20, and the user authentication terminal 20 performs the input operations necessary for authentication, thereby performing the connection process to the virtual private network 3. Figure 6 is a flowchart showing the connection process to the virtual private network in the third form, where the user authentication terminal performs the input operations necessary for biometric authentication.
[0068] FIDO (Fast Identity Online) authentication is known as a more robust and convenient method for verifying user identity. This authentication method uses biometric information such as facial features and fingerprints, along with ownership information of the user authentication terminal 20 (such as a smartphone or hardware token), to verify identity without using a password. The user creates a public and private key pair for signing on the user authentication terminal 20 and provides the public key to the authentication server 24 in advance. The user's biometric information, such as facial features and fingerprints, is stored in the biometric authentication device of the user authentication terminal 20, and the authentication result on the user authentication terminal 20 is sent to the authentication server 24 as a token protected by the private key, thus ensuring high security.
[0069] As shown in Figure 6, the connection process for the virtual private network 3 begins with the user terminal 10 sending an ID to the authentication server 24 and requesting a connection to the virtual private network 3 (step S30). The authentication server 24 compares the user ID of the user terminal 10 that made the connection request with the user registration information, and the authentication server 24 sends a biometric authentication request message to the user authentication terminal 20 that is registered in association with the matched user (step S31).
[0070] As an input operation, the user authentication terminal 20, for example, captures the user's face with its camera, compares it with the user's face information stored in the biometric authentication device on the user authentication terminal 20 to perform biometric authentication (step S32), signs the result of the biometric authentication with a private key, and sends it to the authentication server 24 (step S33).
[0071] The authentication server 24 decrypts the result of biometric authentication from the user authentication terminal 20 using a public key and verifies it (step S34). If authentication is successful (if OK in step S35), it allows the user terminal 10 to connect to the virtual private network 3, and the user terminal 10 connects to the virtual private network 3 (step S36).
[0072] If authentication to identify the user is successful (OK in step S35) and a connection is made to the virtual private network 3, the terminal status monitoring agent 16 in the user terminal 10 starts monitoring the private network communication (step S37). If authentication fails (NG in step S35), the user terminal 10 performs the operations from step S31 or step 30.
[0073] Furthermore, while the authentication information uses an image of the user's face captured by a camera, it is not limited to the user's face. For example, biometric authentication using the person's physical characteristics may also be used, such as fingerprints, iris scans, or vein patterns. Thus, in this third form of connection processing, it becomes possible to authenticate not only the user terminal 10 but also the user of the user terminal 10, extending the security boundary beyond the connected terminal to the certainty of the individual user.
[0074] [About authentication using the authentication integration platform] Next, the process of connecting to a virtual private network that performs authentication using the authentication collaboration platform 27 will be explained with reference to Figure 7. Figure 7 is a flowchart of the process of connecting to a virtual private network that performs authentication using the authentication collaboration platform 27. The authentication collaboration platform 27 integrates or links authentication information that identifies the user among multiple different authentication servers.
[0075] By using the authentication linkage platform 27, which integrates or links authentication information to identify individual users, when generating a virtual private network spanning different companies with different physical networks, even if the authentication servers (authentication server A, authentication server B) of each company (company A, company B) are different, it becomes possible to easily authenticate individual users' connections to the virtual private network while ensuring a high level of security using pre-integrated or linked authentication information (verifiable credentials).
[0076] Furthermore, in the authentication integration platform 27, authentication information (verifiable credentials) that has been previously integrated or linked is registered in the authentication integration platform 27 as authentication information for identifying individual users.
[0077] As shown in Figure 7, the connection process for the virtual private network 3 begins with the user terminal 10 sending an ID to the authentication server 24 and making a connection request (login request) to the virtual private network 3 (step S40).
[0078] The authentication server 24 receives the ID and determines whether the authentication information of the user of the user terminal 10 that made the connection request is an ID that has been previously registered with the authentication server 24 (step S41). If it is an ID that has been previously registered with the authentication server 24, the authentication server 24 sends (transfers) the ID registered with the authentication server 24 to the authentication cooperation platform 27, thereby requesting (delegating) the authentication process for the user to the authentication cooperation platform 27 (step S42).
[0079] Next, the authentication cooperation platform 27, to which the authentication process has been delegated from the authentication server 24, performs the authentication process on behalf of the authentication server 24 using the same method (process) as steps S31 to S34 of the third form of the process of connecting the user terminal 10 to the virtual private network 3 (step S43).
[0080] If the authentication linkage platform 27 finds that the matching is successful (if OK in step S44), it grants permission for the user terminal 10 to connect to the virtual private network 3, and the user terminal 10 connects to the virtual private network 3 (step S45).
[0081] If authentication to identify the user is successful (OK in step S44) and a connection is established to the virtual private network 3, the terminal status monitoring agent 16 in the user terminal 10 starts monitoring the private network communication (step S46). If authentication fails (NG in step S44), the user terminal 10 performs the operations from step S43.
[0082] In this way, by using the authentication linkage platform 27 as authentication information in the connection process of the virtual private network 3, when creating a virtual private network spanning different companies with different physical networks, even if each company has a different authentication server, it becomes possible to easily authenticate individual users' connections to the virtual private network while maintaining a high level of security using pre-integrated or linked authentication information (verifiable credentials).
[0083] [Regarding access to SaaS] Next, we will explain how a user terminal 10 connected to the virtual private network 3 communicates with SaaS 32 using the SaaS private network connection service unit 31. Figure 8 is a flowchart showing the process by which the SaaS private network connection service unit 31 processes the user terminal 10's access to SaaS 32.
[0084] Furthermore, for service providers that offer services to connect directly to SaaS32 via dedicated lines 33 or other means without going through the internet, a virtual private network connector 30 is pre-installed in the SaaS private connection service unit 31, and the SaaS private connection service unit 31 directly accesses SaaS32.
[0085] Furthermore, when a user terminal 10, where the virtual private network agent 15 resides, requests access to a specific SaaS 32, it is pre-configured which virtual private network connector 30 to connect to.
[0086] First, a user inputs an access request to SaaS32 into the user terminal 10, and the virtual private network agent 15 on the user terminal 10, which is connected to the virtual private network 3, detects the access to the specific SaaS32 (step S50).
[0087] The virtual private network agent 15 of the user terminal 10 extracts the virtual private network connector 30, which is the destination of the communication packet, located in the SaaS private connection service unit 31 that controls direct connections to a specific SaaS 32, and initiates communication (step S51).
[0088] The SaaS private network connection service unit 31 connects to SaaS 32 via a dedicated line through a virtual private network connector 30 installed within the SaaS private network connection service unit 31 (step S52).
[0089] As a result, access from the user terminal 10 to the SaaS 32 is made via a dedicated line 33 from the SaaS private network connection service unit 31, allowing for secure communication from the virtual private network 3 via the dedicated line 33 without going through the internet 41 at all.
[0090] [Regarding the suspension of use of user terminal 10] Next, we will explain how to disable the use of user terminals 10 connected to the virtual private network 3 by monitoring private network communications to the virtual private network 3. Figure 9 is a flowchart showing the process of disabling the use of user terminals 10 connected to the virtual private network 3 by monitoring the virtual private network 3.
[0091] The terminal status monitoring agent 16 on the user terminal 10 detects a disconnection from the virtual private network 3 (step S60). A disconnection from the virtual private network 3 occurs, for example, when a signal from the virtual private network 3 cannot be received within a predetermined time. This can occur in the following cases: firstly, when the virtual private network agent goes down; secondly, when the service that implements the virtual private network stops; or thirdly, when the physical network that forms the basis of the virtual private network goes down or experiences a failure.
[0092] After the terminal status monitoring agent 16 detects a disconnection from the virtual private network 3, the terminal status monitoring agent 16 obtains the terminal's deactivation status setting (policy) from the user's information (step S61).
[0093] The disabled state can be set, for example, according to the desired security level. If the security level is low, access to SaaS32 and the Internet 41 is possible via other networks instead of connecting to the virtual private network 3. If the security level is high, the communication settings of the user terminal 10 are changed to prohibit access to SaaS32 and the Internet 41 that does not go through the virtual private network 3.
[0094] Note that setting user terminal 10 to a disabled state is just one example; it is possible to set multiple disabled states, including communication policies (communication settings) and accessible connection destinations.
[0095] Subsequently, the terminal status monitoring agent 16 of the user terminal 10 sets the user terminal 10 to a disabled state based on the acquired user's disabled state setting (step S62).
[0096] In this way, the terminal status monitoring agent 16 of the user terminal 10 can constantly monitor the communication status and control it to a pre-configured disabled state if there is an abnormality in the communication status.
[0097] [Overview of communication sequences] Next, Figure 10 will show an overview of the communication sequences for the user terminal 10's connection to the virtual private network 3, the SaaS private network connection service unit 31, and the secure web gateway 40. Figure 10 is a diagram showing an overview of the communication sequences for the user terminal 10's connection to the virtual private network 3, the SaaS private network connection service unit 31, and the secure web gateway 40.
[0098] As shown in Figure 10, first, the user terminal 10 starts the OS (operating system), launches the virtual private network agent 15, operation menu screen, etc. From the operation menu screen, the user selects the connection item to the virtual private network 3, performs the private network connection operation shown in Figure 4 (not shown in Figure 10), and after authentication by the authentication server 24, connects to the virtual private network 3.
[0099] As a result, the user terminal 10 is connected to the virtual private network 3. Furthermore, the terminal status monitoring agent 16 is activated after connecting to the virtual private network 3.
[0100] Next, the user terminal 10 performs an operation to use a specific SaaS. The user terminal 10 sends a connection request to the specific SaaS to the virtual private network connector 30. The virtual private network agent 15 of the user terminal 10 has previously specified the virtual private network connector 30 to be routed through the virtual private network 3 when accessing the specific SaaS. As a result, the user terminal 10 and the virtual private network connector 30 of the SaaS private connection service unit 31 are connected via a virtual private line (tunnel) in the virtual private network 3.
[0101] In the SaaS private network connection service unit 31, servers and other devices that have the virtual private network connector 30 pre-installed connect directly to specific SaaS communication requests received by the virtual private network connector 30 via a dedicated line 33, etc. As a result, the user terminal 10 and the designated SaaS are connected via a virtual private line (tunnel) of the virtual private network 3 and a dedicated line 33 from the SaaS private network connection service unit 31, thus ensuring reliable communication, preventing unauthorized access, and creating a highly secure virtual private network 3.
[0102] Furthermore, the terminal status monitoring agent 16 constantly monitors the connection status of the virtual private network 3. In the event of a connection failure (for example, if the virtual private network tunnel cannot be configured due to an unstable network connection), the user terminal 10 can be disabled to ensure communication security.
[0103] Next, the communication sequence in which the user terminal 10 connects to the Internet 41 will be described. As shown in Figure 10, the user terminal 10 sends a connection request to the Internet 41 to the virtual private network connector 30 of the secure web gateway 40.
[0104] Furthermore, the virtual private network connector 30 that will be routed through the virtual private network 3 when accessing the Internet 41 from the virtual private network agent 15 of the user terminal 10 has been specified in advance.
[0105] Subsequently, the user terminal 10 and the secure web gateway's virtual private network connector 30 are connected via a virtual private line (tunnel) of the virtual private network 3. The secure web gateway 40 connects to the designated internet 41 based on the internet connection request from the user terminal 10 received by the virtual private network connector 30. As a result, the user terminal 10 and the secure web gateway 40 are connected via a virtual private line (tunnel) of the virtual private network 3.
[0106] In this way, since access to the Internet 41 from the user terminal 10 goes through the secure web gateway 40, all traffic can be traced. This allows for a quick response to problems with the Internet 41 connection, ensures reliable communication, prevents unauthorized access, and creates a highly secure virtual private network 3.
[0107] Furthermore, the terminal status monitoring agent 16 constantly monitors the connection status of the virtual private network 3. In the event of a connection failure (for example, if the virtual private network tunnel cannot be configured due to an unstable network connection), the user terminal 10 can be disabled to ensure communication security.
[0108] As described above, the present invention securely identifies individual users when connecting to the virtual private network 3, installs a virtual private network agent on the user terminal 10 to ensure stable connection to the virtual private network 3 and to SaaS, etc., and monitors the connection status to the virtual private network 3 using a terminal status monitoring agent 16, detecting unstable connections to the virtual private network 3, disconnections, etc., and deactivating the user terminal 10.
[0109] Therefore, according to the virtual private network generation system of the present invention, a virtual private network is provided that can only be accessed by user terminals on which a communication monitoring agent is installed. By monitoring the connection not only when connecting to the virtual private network but also at all times, user terminals provided to users can connect to cloud services and the like only via the virtual private network, thereby preventing data leakage and unauthorized access, and enabling the safe and efficient use of multiple cloud services.
[0110] Furthermore, according to the present invention, when a user terminal is authorized to connect to the virtual private network from the authentication server, the virtual private network agent establishes private communication to the virtual private network, and the terminal status monitoring agent constantly monitors the private communication. If the terminal status monitoring agent detects that private communication has not been established, it puts the user terminal into a disabled state. This ensures that the use of various services is guaranteed only via the virtual private network, thereby enabling highly secure communication.
[0111] Furthermore, according to the present invention, the setting of the disabled state can be configured, for example, according to the desired level of security. Since the disabled state can be freely configured according to the desired level of security for virtual private network communication, the attributes of the user, the type of user terminal or user authentication terminal, etc., it becomes possible to impose restrictions (disabled state) according to individual circumstances.
[0112] Furthermore, according to the present invention, by pre-installing the virtual private network connector in the data center (SaaS private network service department) of a business operator that provides SaaS private network connection services, direct access to various SaaS applications becomes possible from the virtual private network. This enables more secure communication by eliminating the need to go through the internet when accessing SaaS applications.
[0113] Furthermore, according to the present invention, by providing a secure web gateway on which a virtual private network connector is located, all internet access is routed through the secure web gateway, making all traffic monitorable and allowing all traffic to be analyzed in the event of a problem, thus enabling the construction of a more secure and reliable virtual private network.
[0114] Furthermore, according to the present invention, since connection to the virtual private network requires authentication that identifies the individual user, it becomes possible to extend the authentication of the virtual private network not only to the connecting terminal but also to the certainty of the user, thereby extending the security boundary not only to the connecting terminal but also to the certainty of the individual user.
[0115] Furthermore, according to the present invention, by using a user authentication terminal in personal authentication, it becomes possible to reliably identify the user, thereby extending the boundary of stronger security not only to the connected terminal, but also to the certainty of the individual user.
[0116] Furthermore, according to the present invention, by having an authentication linkage platform that integrates or links authentication information that identifies an individual user among multiple different authentication servers, when generating a virtual private network spanning different companies with different physical networks, even if the authentication servers of each company are different, it becomes possible to easily authenticate the connection of an individual user to the virtual private network while ensuring a high level of security with pre-integrated or linked authentication information.
[0117] This invention can be embodied in numerous forms without departing from its essential characteristics. Therefore, it goes without saying that the embodiments described above are purely illustrative and do not limit the present invention.
[0118] Furthermore, the functional block diagrams shown in Figures 1 and 2 illustrate the functional configuration of the virtual private network generation system 1 of the present invention and do not limit the specific implementation form. That is, it is not necessary to implement hardware corresponding to the functional blocks in the figures, and it is certainly possible to have a configuration in which a single processor executes a program to realize the functions of multiple functional units. In addition, some of the functions realized by software in the embodiment may be realized by hardware, and furthermore, some of the functions realized by hardware may be realized by software. [Explanation of symbols]
[0119] 1. Virtual Private Network Generation System 3. Virtual Private Network 4 Physical network 10. User terminals 11 Storage section 15 Virtual Private Network Agent 16 Terminal Status Monitoring Agent 20 User Authentication Terminal 24 Authentication Server 27 Authentication Integration Platform 30 Virtual Private Network Connectors 31 SaaS Private Network Connection Service Department 32 SaaS 33 Private Line 40 Secure Web Gateway 41 Internet 50 Data Centers (DCs)
Claims
1. A virtual private network generation system that generates a highly reliable virtual private network, A user terminal used by a user to connect to the aforementioned virtual private network, The authentication server that authenticates the aforementioned user, A virtual private network agent that controls the connection of the user terminal to the virtual private network, The system includes a terminal status monitoring agent that monitors the status of the user terminal, The user terminal transmits authentication information that identifies the individual user to the authentication server, and the authentication server uses the authentication information to authenticate the user's connection to the virtual private network. When the user terminal is authorized by the authentication server to connect to the virtual private network, the virtual private network agent establishes private communication to the virtual private network, and the terminal status monitoring agent starts monitoring the private communication. A virtual private network generation system characterized in that, when the terminal status monitoring agent detects that the private network communication has not been established, it puts the user terminal into a disabled state.
2. The virtual private network generation system according to claim 1, characterized in that the aforementioned "disabled state" means setting the communication settings or restrictions on accessible connection destinations of the user terminal to a state that has been set in advance based on the user of the user terminal.
3. The virtual private network generation system further includes a virtual private network connector that establishes a secure connection with the virtual private network agent via the virtual private network. The virtual private network generation system according to claim 1, characterized in that when a user terminal uses SaaS, if the SaaS private network connection service is used, the SaaS private network connection service is used via the virtual private network connector located within the SaaS private network connection service, thereby enabling secure access using the SaaS private network connection service when using SaaS.
4. The aforementioned virtual private network generation system further includes a secure web gateway for connecting to the Internet. The secure web gateway includes a virtual private network connector that establishes a secure connection with the virtual private network agent via the virtual private network. The virtual private network generation system according to claim 1, characterized in that all access to the Internet from the user terminal is performed via the secure web gateway through the virtual private network connector located within the secure web gateway.
5. The virtual private network generation system further includes a user authentication terminal for authenticating the user. The user terminal transmits the authentication information that identifies the individual to the authentication server. The virtual private network generation system according to claim 1, characterized in that when the authentication server authenticates the user's connection to the virtual private network using the authentication information, the authentication server requests the user to perform the necessary input operations for authentication to the user authentication terminal via the user authentication terminal in order to identify the individual.
6. The virtual private network generation system according to claim 5, characterized in that the user authentication terminal is a terminal that the user can carry with them.
7. The virtual private network generation system according to claim 6, characterized in that the user authentication terminal is a terminal capable of authenticating the user by biometric authentication.
8. The virtual private network generation system further includes an authentication linkage platform that integrates or links the authentication information that identifies the user among multiple different authentication servers. The virtual private network generation system according to claim 1, characterized in that when the user terminal transmits the authentication information that identifies the individual, which has been pre-integrated or linked in the authentication linkage platform, to the authentication server, the authentication server transmits the authentication information to the authentication linkage platform, and the authentication linkage platform uses the authentication information to authenticate the user's connection to the virtual private network.
Citation Information
Patent Citations
Creating a virtual network across multiple public clouds
JP2022043118A
Information processing device, information processing method, and information processing system
JP2022091771A