Rule conversion device, rule conversion method, and program

The rule conversion device and method convert first-level security policy conditions into second-level conditions that can be evaluated by access control programs, addressing the challenge of applying security policies across diverse network systems with different security functions.

JP2026136729APending Publication Date: 2026-08-26NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025022418
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-08-26

AI Technical Summary

Technical Problem

Existing systems for controlling access based on security policies do not provide a method to convert security policies into a form that can be processed by access control programs, especially when the access control programs cannot evaluate certain attributes related to network access.

Method used

A rule conversion device and method that includes a processor to obtain system information, first-level policy information, and transformation rules to convert first-level conditions into second-level conditions that can be evaluated by access control programs, using system and conversion rule information to determine applicable transformation rules for each first-level condition.

Benefits of technology

Enables the conversion of security policies into a form that can be processed by access control programs, facilitating the application of security policies across various network systems with different security functions without the need for separate policies for each system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026136729000001_ABST
    Figure 2026136729000001_ABST
Patent Text Reader

Abstract

The present invention provides a rule conversion device, method, and program that convert information indicating security policies into information acceptable to an access control program. [Solution] The rule conversion device acquires system information relating to a target system including security functions and an access control program, first-level policy information relating to attributes and including first-level conditions that the access control program cannot evaluate, and conversion rules for converting each first-level condition to a second-level condition relating to an attribute and which is evaluated by the access control program when the target system includes security functions that provide values ​​to the attributes in the second-level condition. For each first-level condition, it determines a conversion rule that is applicable to that condition and generates a second-level condition that the access control program can evaluate, and converts each first-level condition to a second-level condition using one of the determined conversion rules.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to a rule conversion device, a rule conversion method, and a program.

Background Art

[0002] Systems for controlling access based on security policies have been developed. For example, Patent Document 1 discloses a security server that controls access to a document based on a security policy. Specifically, the security server abstracts the information acquired from an application system to the same level as the security policy, and controls access using the abstracted information.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Patent Document 1 does not disclose cases where it is necessary to convert a security policy. An object of the present disclosure is to provide a novel technique for converting information representing a security policy so that an access control program can process the security policy.

Means for Solving the Problems

[0005] The present disclosure provides a rule conversion device including at least one memory configured to store instructions and at least one processor. At least one processor is configured to execute instructions to obtain system information about a target system, to obtain first-level policy information including first-level conditions, that the target system includes one or more security functions and one or more access control programs that control network access to the target system, to obtain transformation rules that define rules for converting first-level conditions to second-level conditions, that the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control programs, each of which defines a rule for converting a first-level condition to a second-level condition, that the second-level conditions relate to attributes related to network access and can be evaluated by the access control programs if the target system includes security functions that provide values ​​to the attributes in the second-level conditions, and for each first-level condition, to determine one or more transformation rules as candidates for the first-level condition that can generate a second-level condition that is applicable to that first-level condition and can be evaluated by the access control programs, and to convert each first-level condition to a second-level condition according to one of the candidates for the transformation rule determined for that first-level condition.

[0006] This disclosure further provides a rule transformation method performed by one or more computers, the method comprising: obtaining system information relating to a target system, wherein the target system includes one or more security features and one or more access control programs that control network access relating to the target system; obtaining first-level policy information including first-level conditions, wherein the first-level conditions relate to attributes relating to network access and cannot be evaluated by the access control programs; obtaining transformation rules, each defining a rule for transforming a first-level condition into a second-level condition, wherein the second-level conditions relate to attributes relating to network access and can be evaluated by the access control programs if the target system includes security features that provide values ​​for the attributes in the second-level conditions; determining, for each first-level condition, one or more transformation rules as candidates for the first-level condition, which are applicable to that first-level condition and can generate second-level conditions that can be evaluated by the access control programs; and transforming each first-level condition into a second-level condition according to one of the candidates for the transformation rule determined for that first-level condition.

[0007] This disclosure further provides a program which causes one or more computers to perform the following steps: acquiring system information relating to a target system, wherein the target system includes one or more security features and one or more access control programs that control network access relating to the target system; acquiring first-level policy information including first-level conditions, wherein the first-level conditions relate to attributes relating to network access and cannot be evaluated by the access control programs; acquiring transformation rules which define rules for each first-level condition to be converted to a second-level condition, wherein the second-level conditions relate to attributes relating to network access and can be evaluated by the access control programs if the target system includes security features that provide values ​​for the attributes in the second-level conditions; determining, for each first-level condition, as one or more transformation rule candidates for that first-level condition, which are applicable to that first-level condition and can generate a second-level condition that can be evaluated by the access control programs; and converting each first-level condition to a second-level condition according to one of the transformation rule candidates determined for that first-level condition. [Effects of the Invention]

[0008] This disclosure provides a novel technology for converting information representing security policies into information acceptable to access control programs. [Brief explanation of the drawing]

[0009] [Figure 1] This is a diagram illustrating the layout of a rule conversion device. [Figure 2] This is a diagram showing an example of the functional configuration of a rule conversion device. [Figure 3] This is a block diagram showing an example of a computer hardware configuration for implementing a rule conversion device. [Figure 4]This flowchart shows an example of the processing flow of a rule conversion device. [Figure 5] This figure shows an example of a network graph. [Figure 6] This diagram shows an example of the structure of conversion rule information. [Figure 7] This figure shows another example of the configuration of conversion rule information. [Modes for carrying out the invention]

[0010] Embodiments of this disclosure will be described below with reference to the drawings. In each drawing, the same elements are denoted by the same reference numerals, and redundant explanations will be omitted as necessary. In addition, unless otherwise specified, predetermined information (for example, a predetermined value or a predetermined threshold) is pre-stored in a memory unit accessed by the computer using that information. In this disclosure, the memory unit can be implemented with one or more storage devices such as a hard disk drive (HDD), a solid-state drive (SSD), or random-access memory (RAM).

[0011] First Embodiment <Overview> Figure 1 shows an overview of the rule conversion device 2000. Note that Figure 1 does not limit the operation of the rule conversion device 2000, but merely shows one example of the operations it can perform.

[0012] The rule conversion device 2000 operates on the premise that access control is applied to a network system hereafter referred to as the target system. The target system includes one or more nodes. Access control may include decisions on whether network access between nodes related to the target system is permitted or denied. Network access may occur (i) between a source node and a destination node within the target system, (ii) between a source node within the target system and a destination node outside the target system, or (iii) between a source node outside the target system and a destination node within the target system.

[0013] The target system also includes one or more access control programs. These access control programs implement access control based on a set of control rules. Each control rule includes one or more attribute conditions and one or more control actions. Attribute conditions are conditions on attributes related to network access, such as the subject or object of network access. The subject of network access may be a user on the source node or an application running on the source node initiating network access. The object of network access may be a resource (e.g., specific data) or a service being accessed. Control actions instruct how network access is managed, such as granting or denying access.

[0014] A control rule represents the security policy applied to the target system. Suppose there is a security policy that states, "Only employees can access client data." In this case, the access control program must deny network access to client data if the network access is not performed by an employee. Therefore, the control rule corresponding to this security policy includes an attribute condition that indicates "the network access is not performed by an employee" and a control action that indicates "deny access."

[0015] The target system also includes one or more security functions. A security function is a mechanism for implementing or enforcing security measures in an organizational network. Security measures are implemented by configuring security policies specific to the security function mechanism. Examples of security functions can include web application firewalls, virtual private networks, software design networks, or authentication components.

[0016] The access control program uses a security function to obtain the values of the attributes included in the attribute conditions of the evaluation target, and determines whether the attribute conditions are met. For example, using a web application firewall, the IP address of the source or destination node, the protocol of network access, the source or destination port number, and the uniform resource locator (URL) of network access can be obtained.

[0017] The rule conversion device 2000 is configured to generate a set of control rules representing the security policies applied to the target system. Specifically, the rule conversion device  2000 obtains the first-level policy information 10 and converts it into the second-level policy information 50. The first-level policy information 10 includes a set of first-level control rules 12, and the second-level policy information 50 includes a set of second-level control rules 52.

[0018] The first-level control rule 12 is represented using the first-level condition 14 and the control operation 16. The first-level condition 14 is an attribute condition in a more abstract form that can be evaluated by the access control program. Since the first-level condition 14 cannot be evaluated by the access control program, the first-level policy information 10 cannot be directly applied to the access control program. The first-level policy information 10 may be represented in an abstract form to enable its application not only to the target system but also to various network systems with different security functions.

[0019] The second-level control rule 52 is represented using the second-level condition 54 and the control operation 56. The second-level condition 54 is an attribute condition in a form sufficient for the access control program to evaluate. Since the second-level condition 54 can be evaluated by the access control program, the second-level policy information 50 can be applied to the target system. The control operation 56 can be the same as the control operation 16, and thus there is no need to convert the control operation.

[0020] To generate the second-level policy information 50, the rule conversion device 2000 converts the first-level condition 14 in the first-level policy information 10 into the second-level condition 54. For this conversion, the rule conversion device 2000 also acquires the system information 20 and the conversion rule information 30. The system information 20 includes information about the target system. At least, the system information 20 indicates the security functions available in the target system. The conversion rule information 30 indicates two or more conversion rules 32 showing how to convert the first-level condition 14 into the second-level condition 54.

[0021] For each first-level condition 14 in the first-level policy information 10, the rule conversion device 2000 determines the conversion rule 32 used to convert the first-level condition 14 into the second-level condition 54, and uses the corresponding conversion rule 32 to convert each first-level condition 14. The conversion rule 32 that can be used to convert a specific first-level condition 14 must meet the following two criteria: (i) being applicable to this first-level condition 14, and (ii) being able to generate a second-level condition 54 that can be evaluated by the access control program in the target system. Hereinafter, the conversion rule 32 that meets the criteria for the first-level condition 14 is referred to as the conversion rule candidate for this first-level condition 14.

[0022] Suppose there is a first-level condition 14, "subject != EMPLOYEE". There are various ways to determine whether the subject is an employee or not. One method is to check whether the source node's device certificate is included in the list of device certificates for the employee's device. Another method is to check whether the source node's Internet Protocol (IP) address is included in the list of IP addresses for the employee's device. Therefore, there may be translation rules 32 applicable to this first-level condition 14, i.e., satisfying criterion (i). These are rule R1, which translates the first-level condition 14 to "source_node.IPaddr is not included in EMPLOYEE_IP_LIST", and rule R2, which translates the first-level condition 14 to "source_node.certificate is not included in EMPLOYEE_DEVICE_CERTIFICATE_LIST".

[0023] Furthermore, it is assumed that the target system does not have a security function F1 that can provide the source node's device certificate, but does have a security function that can provide the source node's IP address. Under this assumption, the access control program can provide the source node's IP address through security function F1, and therefore can evaluate the second-level condition 54 obtained using translation rule R1. Conversely, since the target system does not have a security function that can provide the source node's device certificate, the access control program cannot evaluate the second-level condition 54 obtained using translation rule R2. In this way, the rule translation device 2000 determines translation rule R1 as a candidate translation rule for the first-level condition 14 "subject != EMPLOYEE", thereby generating the second-level condition 54 "source_node.IPaddr is not included in EMPLOYEE_IP_LIST".

[0024] It should be noted that in some implementations, the rule converter 2000 may be configured to retrieve only a set of first-level conditions 14 from the first-level policy information 10, rather than the entire first-level policy information 10. In this case, the rule converter 2000 generates a set of second-level conditions 54 based on the retrieved first-level conditions 14. The second-level policy information 50 may be generated outside the rule converter 2000 using the second-level conditions 54 provided by the rule converter 2000.

[0025] <Examples of effects and benefits> According to the rule conversion device 2000, a first-level condition 14 in an abstract form that the access control program cannot evaluate is converted into a second-level condition 54 in a specific form that the access control program can evaluate. Therefore, the rule conversion device 2000 can provide a novel technique for converting information representing a security policy so that the access control program can process the security policy.

[0026] Furthermore, the rule conversion device 2000 has the advantage of making it easier to prepare security policies applicable to various network systems, for example, the following reasons: Each network system may include different security features, making it difficult to define security policies that are generally applicable to various network systems and specific enough to be handled by access control programs within those network systems. Preparing different security policies for each network system is burdensome.

[0027] According to the rule conversion device 2000, the first-level policy information 10 is abstract enough to be applicable to network systems with different security functions, so there is no need to prepare different security policies for each network system. Next, it can be converted into second-level policy information 50 for each network system, taking into account the security functions within the system.

[0028] The following provides a more detailed explanation of the rule conversion device 2000.

[0029] <Example of functional configuration> Figure 2 is a block diagram showing an example of the functional configuration of the rule conversion device 2000. In the example shown in Figure 2, the rule conversion device 2000 includes an acquisition unit 2020, a determination unit 2040, and a generation unit 2060. The acquisition unit 2020 acquires first-level policy information 10, system information 20, and conversion rule information 30. For each first-level condition 14 in the first-level policy information 10, the determination unit 2040 determines one or more conversion rule candidates that are applicable to this first-level condition 14 and can generate a second-level condition 54 that can be evaluated by an access control program in the target system. The generation unit 2060 generates second-level policy information 50 by converting the first-level condition 14 to a second-level condition 54 using the corresponding conversion rule candidate 32.

[0030] <Example hardware configuration> The rule conversion device 2000 may be implemented using one or more computers. Each of these computers can be a personal computer (PC), a server machine, a mobile device, or an integrated circuit such as a system-on-chip (SoC). The computer may be a dedicated computer designed specifically for the rule conversion device 2000, or it may be a general-purpose computer.

[0031] The Rule Conversion Device 2000 can be implemented by installing an application on one or more computers. This application is a program that allows the computers to function as the Rule Conversion Device 2000. In other words, the program implements the functional components of the Rule Conversion Device 2000.

[0032] Figure 3 is a block diagram showing an example of the hardware configuration of a computer 1000 that implements a rule conversion device 2000. As shown in Figure 3, the computer 1000 includes a bus 1020, a processor 1040, a memory 1060, a storage device 1080, an input / output (I / O) interface 1100, and a network interface 1120.

[0033] Bus 1020 functions as a data transmission channel, enabling the processor 1040, memory 1060, storage device 1080, input / output interface 1100, and network interface 1120 to exchange data. The processor 1040 may be a CPU (Central Processing Unit), MPU (Microprocessor Unit), GPU (Graphics Processing Unit), FPGA (Field-Programmable Gate Array), or DSP (Digital Signal Processor). Memory 1060 functions as a main memory element such as RAM (Random Access Memory) or ROM (Read-Only Memory). Storage device 1080 functions as an auxiliary storage element such as a hard disk, SSD (Solid-State Drive), or memory card. The input / output interface 1100 connects the computer 1000 to peripheral devices such as a keyboard, mouse, and display. The network interface 1120 connects the computer 1000 to a network which can be a LAN (Local Area Network) or a WAN (Wide Area Network).

[0034] The storage device 1080 may store the program described above. By the processor 1040 reading and executing this program from the storage device 1080, the computer 1000 can realize each functional part of the rule conversion device 2000.

[0035] Note that the hardware configuration of computer 1000 is not limited to the example shown in Figure 3. For example, as described above, the rule conversion device 2000 may be implemented using multiple computers. In this case, these computers may be connected to each other via a network.

[0036] <Processing flow> Figure 4 is a flowchart illustrating an example of the processing flow performed by the rule conversion device 2000. The acquisition unit 2020 acquires the first-level policy information 10 (S102). The acquisition unit 2020 acquires the system information 20 (S104). The acquisition unit 2020 acquires the conversion rule information 30 (S106).

[0037] Steps S108 to S114 constitute a loop process L1 that is executed for each first-level condition 14 in the first-level policy information 10. In step S108, the decision unit 2040 determines whether or not the loop process L1 has been executed for all first-level conditions 14. If the rule conversion device 2000 determines that the loop process L1 has been executed for all first-level conditions 14, after completing the loop process L1, it executes step S114 to generate second-level policy information 50 based on the set of second-level conditions 54. If the decision unit 2040 determines that the loop process L1 has not been executed for all first-level conditions 14, it selects the first-level conditions 14 for which the loop process L1 has not been executed. Let the first-level conditions 14 selected here be Cf.

[0038] The determination unit 2040 determines one or more candidate conversion rules for the first-level condition Cf (S110). The generation unit 2060 uses one of the candidate conversion rules to convert the first-level condition Cf into the second-level condition 54 (S112). The rule conversion device 2000 finishes the current iteration of the loop process L1 (S114) and executes the next iteration of the loop process L1 (S108).

[0039] Note that the flow shown in Figure 4 is just one example, and various other flows are possible. For example, the acquisition of information (S102, S104, S106) may be performed in a different order than that shown in Figure 4.

[0040] <Acquisition of Level 1 Policy Information 10: S102> The acquisition unit 2020 acquires the first-level policy information 10 (S102). There are various ways to acquire the first-level policy information 10. For example, the first-level policy information 10 is pre-stored in a storage unit accessible to the rule converter 2000. In this case, the acquisition unit 2020 acquires the first-level policy information 10 from the storage unit. The identifier of the first-level policy information 10 (for example, a file path) may be specified by the user of the rule converter 2000.

[0041] In another example, the first-level policy information 10 is sent to the rule converter 2000 from another computer, such as a user terminal operated by a user of the rule converter 2000. In this case, the acquisition unit 2020 receives the first-level policy information 10.

[0042] As described above, the first-level policy information 10 includes first-level control rules 12, each of which includes one or more first-level conditions 14 and control actions 16. The first-level conditions 14 represent the security policy to be applied to the target system in an abstract form that cannot be evaluated by the access control program.

[0043] Specifically, the first-level condition 14 represents attributes related to network access in abstract forms such as "subject," "object," and "resource." These abstract expressions are then translated into more concrete expressions in the second-level condition 54. For example, "subject" can be translated into specific identifiers of the subject, such as "source node biometric ID" or "subject node IP address." The same applies to "object." Attributes of "resource" can be translated into specific identifiers of the resource, such as "file name of accessed data" or "path of accessed data."

[0044] In the actual implementation of Level 2 Condition 54, the specific expressions exemplified above can be made more specific in order to ensure interpretability by the access control program. For example, "source node biometric ID" can be represented as "src.BIO_ID".

[0045] The first-level condition 14 may also express conditions related to network access in an abstract form. For example, there may be a first-level condition 14 concerning the subject's role, such as "the subject is a nurse." In this case, the abstract condition "is a nurse" is translated into a more specific condition, such as "is included in the list of nurses' IP addresses." Again, it should be noted that in the actual implementation of the second-level condition 54, more specific expressions may be used to ensure interpretability by the access control program. For example, "is included in the list of nurses' IP addresses" can be expressed as "in NURSE_IP_ADDR_LIST."

[0046] <Acquisition of system information 20: S104> The acquisition unit 2020 acquires system information 20 (S104). An example of how to acquire system information 20 is the same as the example of how to acquire first-level policy information 10 described above.

[0047] System information 20 indicates at least the security features available in the target system. For example, system information 20 includes a list of security features available in the target system.

[0048] In another example, system information 20 includes a network graph representing the location of security functions for resources within the target system.

[0049] An example of a network graph is shown in Figure 5. In Figure 5, resources are represented by solid rectangles, and security functions are represented by dotted rectangles. By referring to the network graph, the rule translation device 2000 can determine which security functions are provided by the target system.

[0050] <Acquisition of conversion rule information 30: S106> The acquisition unit 2020 acquires the conversion rule information 30 (S106). An example of how to acquire the conversion rule information 30 is the same as the example of how to acquire the first-level policy information 10 described above.

[0051] The conversion rule information 30 includes the conversion rule 32. The conversion rule 32 represents the rule for converting the first-level condition 14 to the second-level condition 54.

[0052] The conversion of attribute conditions may be divided into attribute conversion and condition conversion. Therefore, conversion rule 32 can show an attribute map and a condition map. The attribute map shows how attributes in the first-level condition 14 are converted to attributes in the second-level condition 54, for example, "Subject → IP address of source node". The condition map shows how conditions in the first-level condition 14 are converted to conditions in the second-level condition 54, for example, "Included in group → Included in IP_ADDR_LIST".

[0053] Figure 6 shows an example of the configuration of the conversion rule information 30. In this figure, the conversion rule information 30 is represented in tabular form. The conversion rule 32 includes a pair of attribute map 34 and condition map 35.

[0054] For example, the first line of conversion rule 32 indicates (subject, src.IP_ADDR) in attribute map 34 and (in group, in IP_ADDR_LIST) in condition map 35. This conversion rule represents the conversion of a first-level condition to a second-level condition by replacing the attribute representing "subject" in first-level condition 14 with "src.IP_ADDR" and the condition indicating "in group" in first-level condition 14 with "in IP_ADDR_LIST". "src.IP_ADDR" represents the IP address of the source node, and IP_ADDR_LIST represents a list of IP addresses.

[0055] By using this conversion rule 32, the abstract attribute representing the subject in the first-level condition 14 is materialized as "the IP address of the source node," which is one concrete way of representing the subject identifier. Similarly, the abstract condition representing "being included in a group" is materialized as "being included in a list of specific IP addresses," which is one concrete way of representing the situation of belonging to a group.

[0056] In Figure 6, the conversion rule information 30 also includes capability 36. Capability 36 indicates which access control mechanisms can be implemented using the second-level condition 54 obtained by applying the corresponding conversion rule 32. In Figure 6, a check mark indicates that the corresponding access control mechanism can be implemented, and a cross mark indicates that the corresponding access control mechanism cannot be implemented.

[0057] In some implementations, capability 36 can indicate the degree of accuracy of the access control mechanism implemented using the second-level condition 54 obtained by the corresponding translation rule 32. Figure 7 shows another example of the translation rule information 30 configuration. In Figure 7, capability 36 indicates the accuracy of the access control mechanism. For example, capability 36 in the second row shown in Figure 7 indicates that user authentication can be performed with moderate accuracy, device authentication can be performed with high accuracy, but location identification cannot be performed.

[0058] <Determination of conversion rule candidates: S110> The determination unit 2040 determines one or more candidate conversion rules for the first-level condition Cf (S110). The candidate conversion rules for the first-level condition Cf satisfy the following two criteria: (i) they are applicable to the first-level condition Cf; and (ii) they can generate a second-level condition 54 that can be evaluated by an access control program in the target system.

[0059] To determine a conversion rule 32 that satisfies criterion (i), the determination unit 2040 determines which access control mechanism will be implemented based on the first-level condition Cf. The determination unit 2040 then determines a conversion rule 32 that satisfies criterion (i), which is indicated by capability that the determined access control mechanism is feasible.

[0060] The access control mechanism implemented by a first-level condition Cf can be determined using first-level policy information 10. In some implementations, the first-level policy information 10 explicitly or implicitly indicates the access control mechanism to be implemented. For example, if explicitly mentioned, the relevant access control mechanism is attached as a label to each first-level condition 14. In another example, if implicitly mentioned, the relevant access control mechanism can be extracted from the first-level condition 14. Extraction can be performed by a machine learning-based model that has learned many first-level conditions and knows how to classify the first-level conditions 14 into the access control mechanisms to which they belong.

[0061] The following describes how to determine a transformation rule 32 that satisfies criterion (ii) and can generate a second-level condition 54 that can be evaluated by an access control program in the target system. Conceptually, a transformation rule 32 satisfies criterion (ii) if one or more security functions in the target system provide the attribute values ​​used in the second-level condition 54 generated by this transformation rule 32.

[0062] Therefore, in some implementations, the determination unit 2040 refers to the system information 20 to determine the security functions in the target system. The determination unit 2040 then determines, for each conversion rule 32, whether the target system has at least one security function that provides the attribute values ​​used in the conversion rule 32 generated by the conversion rule 32. If the determination unit 2040 determines that the target system has at least one security function that provides the attribute values ​​used in the conversion rule 32 generated by the conversion rule 32, it determines that the conversion rule 32 satisfies criterion (ii). Conversely, if the determination unit 2040 determines that the target system does not have a security function that provides the attribute values ​​used in the conversion rule 32 generated by the conversion rule 32, it determines that the conversion rule 32 does not satisfy criterion (ii).

[0063] In other embodiments, there is predefined information called security feature information that indicates which security features support which translation rule 32. Support for a translation rule 32 of a security feature means that, if the security feature is available in the target system, the translation rule 32 satisfies criterion (ii). In other words, the security feature provides the attribute values ​​used in the second-level condition 54 generated by the corresponding translation rule 32. Hereinafter, a security feature that supports a translation rule 32 will also be referred to as the security feature corresponding to that translation rule 32.

[0064] If security function information is predefined, the determination unit 2040 refers to the security function information to determine the conversion rules 32 supported by the security functions of the target system and determines the conversion rules 32 that satisfy criterion (ii). The security information indicates that security functions F1, F2, and F3 are available in the target system. The security function information also indicates that security function F1 supports conversion rules R1 and R2, security function F2 supports conversion rules R3 and R4, and security function F3 supports conversion rules R1 and R5. In this case, conversion rules R1, R2, R3, R4, and R5 satisfy criterion (ii).

[0065] <Attribute condition conversion: S110> The generation unit 2060 converts the first-level condition Cf to the second-level condition 54 using one of the conversion rule candidates called the final conversion rule. If there is only one conversion rule candidate, this candidate is used as the final conversion rule. If there are multiple conversion rule candidates, the generation unit 2060 selects one of them as the final conversion rule. First, we will explain how the generation unit 2060 converts the first-level condition Cf to the second-level condition 54 using the final conversion rule. How the final conversion rule is selected from the conversion rule candidates will be explained later.

[0066] The generation unit 2060 converts the first-level condition Cf to the second-level condition 54 by converting the attributes and conditions of the first-level condition Cf using the attribute map and condition map in the final conversion rule. Specifically, the generation unit 2060 determines the attribute in the first-level condition Cf that matches the first element of the attribute map 34 in the final conversion rule (e.g., "subject"), and converts this attribute to the second element of the attribute map 34 (e.g., src.IP_ADDR). As a result, the attributes of the first-level condition Cf are converted to the attributes of the second-level condition (e.g., "subject" is converted to "src.IP_ADDR"). The generation unit 2060 also determines the condition in the first-level condition Cf that matches the first element of the condition map 35 in the final conversion rule (e.g., "in group"), and converts this condition to the second element of the attribute map 34 (e.g., "in IP_ADDR_LIST"). This converts the conditions of the first-level condition Cf into second-level conditions (for example, "in group" is converted to "in IP_ADDR_LIST").

[0067] In some implementations, the content of the first-level condition Cf and the content of the final transformation rule are literally identical. In this case, the string in the first-level condition Cf that exactly matches the first element of attribute map 34 in the final transformation rule is determined as the corresponding attribute. Suppose attribute map 34 in the final transformation rule specifies (subject, src.IP_ADDR). In this case, the string "subject" in the first-level condition Cf is transformed to "src.IP_ADDR".

[0068] When the first-level condition Cf matches the final transformation rule, it is preferable that the transformation rule 32 specifies some specific attributes or conditions. For example, rather than using a general term like "subject," the final transformation rule should preferably specify a more specific type of subject, such as "employee," "nurse," or "contractor." The same applies to condition matching.

[0069] In other embodiments, the content of the first-level condition Cf and the content of the final transformation rule may be semantically identical. In this case, the string in the first-level condition Cf that semantically matches the first element of the attribute map 34 in the final transformation rule is determined as the corresponding attribute. Suppose the attribute map 34 in the final transformation rule specifies (subject, src.IP_ADDR). In this case, the string in the first-level condition Cf representing the subject, such as "employee," "nurse," or "contractor," is transformed into "src.IP_ADDR." The same applies to condition matching.

[0070] Semantic matching can be performed using machine learning-based models, such as neural networks. These models are configured to take two strings as input and be pre-trained to determine whether these two strings are semantically identical.

[0071] ≪Selection of Final Conversion Rule≫ The generation unit 2060 selects the final transformation rule to be used for the transformation of the first-level condition Cf from among the transformation rule candidates determined for the first-level condition Cf. There are various ways to select one of the transformation rule candidates. For example, the generation unit 2060 randomly selects one of the transformation rule candidates as the final transformation rule. In another example, the generation unit 2060 selects one of the transformation rule candidates using one or more factors.

[0072] Various factors can be considered in selecting the final conversion rule. For example, the generation unit 2060 may select the conversion rule candidate that exhibits the highest accuracy in capability for the access control mechanism corresponding to the first-level condition Cf as the final conversion rule. Assume that the access control mechanism corresponding to the first-level condition Cf is M1, and the capabilities of conversion rule candidates R1, R2, and R3 for M1 are high, medium, and low, respectively. In this case, conversion rule candidate R1 is selected as the final conversion rule because it has the highest accuracy.

[0073] In another example, one or more factors related to a security feature are used to determine the final transformation rule. Factors related to a security feature may include the availability of the security feature, the cost of using the security feature, the security state of the security feature, and the load-bearing capacity of the security feature. The cost of using the security feature may include the operational costs of the security feature, the network costs for sending policy information to the security feature, the computational costs of the security feature, or the power consumption of the security feature. The security state of the security feature may include the security state of the current software version, the existence of exploitation cases, vulnerability reports, and security assessments provided by or derived from reports. The load-bearing capacity of the security feature may include the maximum number of policies that can be deployed to the security feature per unit of time and per unit of memory. For example, if a firewall uses access control lists as policies, the load-bearing capacity may be the maximum number of statements in the list, as well as how quickly it is updated (e.g., daily).

[0074] The security function information may specify these factors for each security function, taking these factors into consideration. The generation unit 2060 refers to the security information and determines the factors of the security function associated with the conversion rule candidate.

[0075] Other factors that can be used to determine the final conversion rules may include factors related to access needs (e.g., priority requirements and response time requirements), factors related to resource security (e.g., resource confidentiality and resource security requirements), and factors related to the access subject (e.g., subject trustworthiness and subject access frequency).

[0076] Prioritization requirements are initiated by the subject. For example, in an emergency, it is preferable to prioritize access solutions that can resolve the emergency. Similarly, if there is a deadline, it is preferable to have access solutions that prevent delays in delivery. In such cases, security features that help resolve the situation may be prioritized. For example, during an "emergency" situation, a security feature that can provide immediate connection establishment is preferred over another security feature that has latency. For example, a shorter path to a resource (even if slightly less secure) may be preferred, or a communication channel with lower latency (even if more expensive) may be preferred. One example might be preventing the use of two-factor authentication in an emergency because it would result in further latency.

[0077] Assume the organization has a "device certificate" to authenticate devices and a "password" and "2FA" to authenticate users. Furthermore, Level 1 policy information 10 represents the policy "if(("User.auth"=="success") and ("device.auth"=="success") and ("customer.data"==True)) -> Allow, else Deny". Note that auth and 2FA represent authentication and two-factor authentication, respectively.

[0078] In this case, the first-level condition can be converted to a second-level condition under normal conditions, as follows: - (“device.auth”==“success”) -> (“device.certificate”==“valid”) - (“User.auth”==“success”) -> (“password”==“matched”) and (“2FA”==“success”) - (“customer.data”==True) -> (“access.file” in “f.list”)

[0079] This means that the policy that can be enforced under normal conditions is "if(("password"=="matched") and ("2FA"=="success")and("device.certificate"=="valid") and ("access.file" in "f.list")) -> Allow, else Deny".

[0080] Furthermore, let's assume that the device certificate check takes 0.5 seconds, the password check takes 1 second, and the 2FA process takes an average of 5 seconds. In an emergency, 5 seconds is too long, so the password check takes priority over 2FA, and the use of 2FA is completely discontinued.

[0081] As a result, the enforceable policy in an emergency is "if(("password"=="matched") and ("device.certificate"=="valid") and ("access.file" in "f.list")) -> Allow, else Deny".

[0082] Subjects that are more trustworthy can be given similar priority. For example, if an administrator is more trustworthy than an employee, a relaxed policy may be applied to the administrator (e.g., not using 2FA for each access).

[0083] The generation unit 2060 calculates a score for each conversion rule candidate based on one or more factors related to the conversion rule candidate. Then, the generation unit 2060 selects the conversion rule candidate with the highest score as the final conversion rule.

[0084] In some implementations, the generator 2060 can solve the optimization problem and determine the final transformation rule. The optimization program is predefined using one or more of the factors described above. The generator 2060 determines a candidate transformation rule that gives the optimal solution to this optimization problem and decides this candidate transformation rule as the final transformation rule.

[0085] <Generating Level 2 Policy Information: S116> The generation unit 2060 generates second-level policy information 50 using the set of second-level conditions 54 (S116). Specifically, the generation unit 2060 converts the first-level policy information 10 into second-level policy information 50 by replacing each first-level condition 14 in the first-level policy information 10 with the corresponding second-level condition 54.

[0086] <Output of results> The rule conversion device 2000 can output the results of its processing, which are called output information. For example, the rule conversion device 2000 outputs second-level policy information 50 as output information.

[0087] In some implementations, as described above, the rule converter 2000 can be configured to obtain a set of first-level conditions 14 instead of the entire first-level policy information 10, and to generate a set of second-level conditions 54 based on the obtained set of first-level conditions 14. In this case, the rule converter 2000 may output the set of second-level conditions 54 as output information.

[0088] There are various ways to output output information. For example, the rule conversion device 2000 stores the output information in a memory unit. In another example, the rule conversion device 2000 outputs the output information to a display device, thereby displaying the contents of the output information on the display device. In yet another example, the rule conversion device 2000 sends the output information to another device, such as a computer that runs an access control program.

[0089] Programs can be stored in and provided to a computer using any type of non-temporary computer-readable medium. Non-temporary computer-readable medium includes any type of tangible storage medium. Examples of non-temporary computer-readable mediums include magnetic storage media (e.g., floppy disks, magnetic tapes, hard disk drives), magneto-optical storage media (e.g., magneto-optical disks), CD-ROMs (compact disc read-only memory), CD-Rs (compact disc recordable), CD-R / Ws (compact disc rewritable), and semiconductor memory (e.g., mask ROMs, PROMs (programmable ROMs), EPROMs (erasable PROMs), flash ROMs, RAMs (random access memory)). Programs can also be provided to a computer using any type of temporary computer-readable medium. Embodiments of temporary computer-readable mediums include electrical signals, optical signals, and electromagnetic waves. Temporary computer-readable mediums can be provided to a computer via wired communication lines (e.g., electric wires and optical fibers) or wireless communication lines.

[0090] While the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications that will be understood by those skilled in the art can be made to the structure and details of the present disclosure within the scope of the present invention.

[0091] All or part of the embodiments disclosed above may be described as follows, but are not limited to these. <Note> (Note 1) A rule conversion device, At least one memory configured to store instructions, A system comprising at least one processor, wherein the processor executes the instruction, The system acquires system information relating to the target system, and the target system includes one or more security functions and one or more access control programs that control network access relating to the target system. First-level policy information including first-level conditions is obtained, the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control program, Each obtains a conversion rule that defines a rule for converting the first level condition to a second level condition, the second level condition relating to an attribute related to the network access, and the target system includes the security function that provides a value for the attribute in the second level condition, which can be evaluated by the access control program. For each first-level condition, one or more transformation rules are determined as candidates for the first-level condition, which are applicable to that first-level condition and capable of generating the second-level condition that can be evaluated by the access control program. A rule conversion device configured to convert each first-level condition into a second-level condition according to one of the conversion rule candidates determined for that first-level condition. (Note 2) The system information indicates the security functions included in the target system, The determination of the candidate transformation rule for each condition at the first level is: Using the aforementioned system information, determine the security functions included in the target system, This includes determining the transformation rules, each having an attribute for which a value is provided by the security function in the target system, as transformation rules capable of generating the second level of conditions that can be evaluated by the access control program, The rule conversion device described in Appendix 1. (Note 3) The acquisition of the aforementioned conversion rules includes acquiring conversion rule information representing each conversion rule, associated with a capability indicating which access control mechanism can implement it. The determination of the candidate transformation rule for each condition at the first level is: The access control mechanism to be implemented based on the conditions of the first level, This includes determining that the transformation rule associated with the capability representing that the determined access control mechanism can be implemented is applicable to the first level condition, The rule conversion device described in Appendix 1. (Note 4) The aforementioned conversion rule information indicates, for each conversion rule, the accuracy of each access control mechanism realized using the second-level conditions generated by that conversion rule. The transformation of the first level condition is Among the conversion rule candidates determined for the first level conditions, select the conversion rule candidate that shows the highest accuracy for the access control mechanism implemented by the first level conversion, This includes transforming the first-level condition using the selected transformation rule candidate, The rule conversion device described in Appendix 3. (Note 5) The transformation of the first level condition is The score of each transformation rule candidate determined for the first level of conditions is calculated based on one or more factors associated with that transformation rule candidate, This includes transforming the first-level condition using the candidate transformation rule having the highest score, The rule conversion device described in Appendix 1. (Note 6) The transformation of the first level condition includes selecting from one of the transformation rule candidates determined for the first level condition a transformation rule candidate that provides an optimal solution to an optimization problem defined using one or more factors associated with the transformation rule candidate, The rule conversion device described in Appendix 1. (Note 7) The one or more factors related to the conversion rule candidate include one or more factors related to the security function that provides the value of the attribute in the second-level condition generated using the conversion rule candidate, The rule conversion device described in Appendix 5 or Appendix 6. (Note 8) A rule transformation method performed by one or more computers, A step of obtaining system information relating to a target system, wherein the target system includes one or more security functions and one or more access control programs that control network access relating to the target system. A step of obtaining first-level policy information including first-level conditions, wherein the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control program, A step of obtaining a conversion rule that defines a rule for converting the first level condition to a second level condition, wherein the second level condition relates to an attribute related to the network access and can be evaluated by the access control program if the target system includes the security function that provides values ​​for the attribute in the second level condition, For each first-level condition, one or more conversion rules are determined as candidates for one or more conversion rules for that first-level condition, which are applicable to that first-level condition and capable of generating the second-level condition that can be evaluated by the access control program. A rule transformation method comprising the step of transforming each first-level condition into a second-level condition according to one of the candidate transformation rules determined for that first-level condition. (Note 9) The system information indicates the security functions included in the target system, The determination of the candidate transformation rule for each condition at the first level is: Using the aforementioned system information, determine the security functions included in the target system, This includes determining the transformation rules, each having an attribute for which a value is provided by the security function in the target system, as transformation rules capable of generating the second level of conditions that can be evaluated by the access control program, The rule conversion method described in Appendix 8. (Note 10) A program that can be installed on one or more computers. A step of obtaining system information relating to a target system, wherein the target system includes one or more security functions and one or more access control programs that control network access relating to the target system. A step of obtaining first-level policy information including first-level conditions, wherein the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control program, A step of obtaining a conversion rule that defines a rule for converting the first level condition to a second level condition, wherein the second level condition relates to an attribute related to the network access and can be evaluated by the access control program if the target system includes the security function that provides values ​​for the attribute in the second level condition, For each first-level condition, one or more conversion rules are determined as candidates for one or more conversion rules for that first-level condition, which are applicable to that first-level condition and capable of generating the second-level condition that can be evaluated by the access control program. A program that performs the steps of: converting each first-level condition to a second-level condition according to one of the candidate conversion rules determined for that first-level condition.

[0092] Furthermore, elements described in Appendices 3 to 7 that reference Appendice 1 (e.g., structure and function) may also reference Appendice 8 in the same subordinate relationship as Appendices 3 to 7. Furthermore, elements described in Appendices 2 to 7 that reference Appendice 1 (e.g., structure and function) may also reference Appendice 10 in the same subordinate relationship as Appendices 2 to 7. Some or all of the elements described in the appendices may apply to various hardware, software, storage media for software, systems, and methods. [Explanation of Symbols]

[0093] 10. Level 1 Policy Information 10 12. First-level control rules 14. First Level Conditions 16 Control operation 20 System Information 30 Conversion Rule Information 32 Conversion Rules 34 Attribute Map 35 Condition Map 36 Capabilities 50. Level 2 Policy Information 52. Second-level control rules 54. Second Level Conditions 56 Control operation 1000 computers 1020 Bus 1040 processor 1060 memory 1080 storage device 1100 Input / Output Interface 1120 Network Interface 2000 Rule Converter 2020 Acquisition Department 2040 Decision Section 2060 Generation part

Claims

1. A rule conversion device, At least one memory configured to store instructions, A system comprising at least one processor, wherein the processor executes the instruction, The system acquires system information relating to the target system, and the target system includes one or more security functions and one or more access control programs that control network access relating to the target system. First-level policy information including first-level conditions is obtained, the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control program, Each obtains a conversion rule that defines a rule for converting the first level condition to a second level condition, the second level condition relating to an attribute related to the network access, and the target system can be evaluated by the access control program if it includes the security function that provides values ​​for the attribute in the second level condition. For each first-level condition, one or more conversion rules are determined as candidates for the first-level condition, which are applicable to that first-level condition and capable of generating the second-level condition that can be evaluated by the access control program. A rule conversion device configured to convert each first-level condition into a second-level condition according to one of the conversion rule candidates determined for that first-level condition.

2. The system information indicates the security functions included in the target system, The determination of the candidate transformation rule for each condition at the first level is: Using the aforementioned system information, determine the security functions included in the target system, This includes determining the transformation rules, each having an attribute for which a value is provided by the security function in the target system, as transformation rules capable of generating the second level of conditions that can be evaluated by the access control program, The rule conversion device according to claim 1.

3. The acquisition of the aforementioned conversion rules includes acquiring conversion rule information representing each conversion rule, associated with a capability indicating which access control mechanism can implement it. The determination of the candidate transformation rule for each condition at the first level is: The access control mechanism to be implemented is determined by the conditions of the first level, This includes determining that the transformation rule associated with the capability representing that the determined access control mechanism can be implemented is applicable to the first level condition, The rule conversion device according to claim 1.

4. The aforementioned conversion rule information indicates, for each conversion rule, the accuracy of each access control mechanism realized using the second-level conditions generated by that conversion rule. The conversion of the first level condition is Among the conversion rule candidates determined for the first level conditions, select the conversion rule candidate that shows the highest accuracy for the access control mechanism implemented by the first level conversion, This includes transforming the first-level condition using the selected transformation rule candidate, The rule conversion device according to claim 3.

5. The conversion of the first level condition is The score of each transformation rule candidate determined for the first level of conditions is calculated based on one or more factors associated with that transformation rule candidate, This includes transforming the first-level condition using the candidate transformation rule having the highest score, The rule conversion device according to claim 1.

6. The transformation of the first level condition includes selecting from one of the transformation rule candidates determined for the first level condition a transformation rule candidate that provides an optimal solution to an optimization problem defined using one or more factors associated with the transformation rule candidate, The rule conversion device according to claim 1.

7. The one or more factors related to the conversion rule candidate include one or more factors related to the security function that provides the attribute values ​​in the second-level conditions generated using the conversion rule candidate, The rule conversion device according to claim 5 or 6.

8. A rule transformation method performed by one or more computers, A step of acquiring system information relating to a target system, wherein the target system includes one or more security functions and one or more access control programs that control network access relating to the target system. A step of obtaining first-level policy information including first-level conditions, wherein the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control program, A step of obtaining a conversion rule that defines a rule for converting the first level condition to a second level condition, wherein the second level condition relates to an attribute related to the network access and can be evaluated by the access control program if the target system includes the security function that provides values ​​for the attribute in the second level condition, For each first-level condition, one or more conversion rules are determined as one or more candidate conversion rules for that first-level condition, which are applicable to that first-level condition and capable of generating the second-level condition that can be evaluated by the access control program. A rule transformation method comprising the step of transforming each first-level condition into a second-level condition according to one of the candidate transformation rules determined for that first-level condition.

9. The system information indicates the security functions included in the target system, The determination of the candidate transformation rule for each condition at the first level is: Using the aforementioned system information, determine the security functions included in the target system, This includes determining the transformation rules, each having an attribute for which a value is provided by the security function in the target system, as transformation rules capable of generating the second level of conditions that can be evaluated by the access control program, The rule conversion method according to claim 8.

10. A program, which can be installed on one or more computers. A step of acquiring system information relating to a target system, wherein the target system includes one or more security functions and one or more access control programs that control network access relating to the target system. A step of obtaining first-level policy information including first-level conditions, wherein the first-level conditions relate to attributes related to network access and cannot be evaluated by the access control program, A step of obtaining a conversion rule that defines a rule for converting the first level condition to a second level condition, wherein the second level condition relates to an attribute related to the network access and can be evaluated by the access control program if the target system includes the security function that provides values ​​for the attribute in the second level condition, For each first-level condition, one or more conversion rules are determined as one or more candidate conversion rules for that first-level condition, which are applicable to that first-level condition and capable of generating the second-level condition that can be evaluated by the access control program. A program that performs the steps of: converting each first-level condition into a second-level condition according to one of the candidate conversion rules determined for that first-level condition.

Citation Information

Patent Citations

  • Access control decision system, and access control execution system

    JP2005038372A