Program, Virtual Network Allocation Method, and Virtual Network Allocation System

By using position information to allocate virtual networks, the program and method address the lack of location-based network connection in existing systems, achieving secure and efficient network access and data transmission in shared facilities.

JP7703950B2Active Publication Date: 2025-07-08DAI NIPPON PRINTING CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021140022
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-30
Publication Date
2025-07-08
Estimated Expiration
2041-08-30

AI Technical Summary

Technical Problem

Existing wireless communication systems fail to consider the position information of information terminals when establishing connections to access networks, leading to inadequate network allocation.

Method used

A program and method that utilize position information to allocate virtual networks by acquiring first and second position information, allowing a control device to assign a virtual network to an information terminal based on its location and the base station it can communicate with, using network slicing to generate logical networks tailored to specific needs.

Benefits of technology

Enables secure and efficient network allocation by ensuring appropriate network access based on location, providing fine-grained control and security in shared facilities, and ensuring data integrity through encrypted log data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007703950000001
    Figure 0007703950000001
  • Figure 0007703950000002
    Figure 0007703950000002
  • Figure 0007703950000003
    Figure 0007703950000003
Patent Text Reader

Abstract

To provide a program and the like that allocate a virtual network to an information terminal based on positional information on the information terminal.SOLUTION: A program causes a computer to perform processes of acquiring first positional information about the position where an information terminal exists, acquiring second positional information identifying a base station of a local network with which the information terminal can communicate, and allocating a virtual network to be connected to the information terminal according to the acquired first positional information and second positional information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a program, a virtual network allocation method, and a virtual network allocation system.

Background Art

[0002] There is known a wireless communication system capable of simultaneously establishing connections with a basic access network capable of signaling communication related to continuous communication switching control and an access network for performing data communication other than the signaling communication, using at least two or more types of communication networks including a wireless communication network (for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the wireless communication system described in Patent Document 1, there is a problem that consideration is not given to establishing a connection to an access network based on the position information of an information terminal that serves as a communication node of the wireless communication system.

[0005] The present invention has been made in view of such circumstances, and an object thereof is to provide a program or the like capable of allocating a virtual network to an information terminal based on the position information of the information terminal.

Means for Solving the Problems

[0006] In one aspect, the program causes a computer to acquire first position information regarding the location where the information terminal is located, acquire second position information for identifying a base station of a local network with which the information terminal can communicate, and assign a virtual network connected to the information terminal according to the acquired first position information and the second position information.

[0007] In one aspect, a virtual network allocation method causes a computer to acquire first position information regarding the location where the information terminal is located, acquire second position information for identifying a base station of a local network with which the information terminal can communicate, and execute a process of allocating a virtual network connected to the information terminal according to the acquired first position information and the second position information.

[0008] In one aspect, a virtual network allocation system is a virtual network allocation system including an information terminal and a control device that allocates a virtual network to the information terminal. The information terminal acquires first position information regarding the location where the self-terminal is located, acquires second position information for identifying a base station of a local network with which the location where the self-terminal is located can communicate, and outputs the acquired first position information and the second position information to the control device. The control device acquires the first position information and the second position information from the information terminal, and allocates a virtual network connected to the information terminal according to the acquired first position information and the second position information.

Advantages of the Invention

[0009] According to the present invention, it is possible to provide a program or the like that allocates a virtual network to an information terminal based on the position information of the information terminal.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Embodiments for Carrying Out the Invention

[0011] (Embodiment 1) FIG. 1 is a system overview diagram exemplifying a virtual network allocation system S according to Embodiment 1. FIG. 2 is a block diagram showing a configuration example of an information terminal 2, a control device 1, etc. included in the virtual network allocation system S. The virtual network allocation system S includes, for example, a plurality of base stations KK (RAN: Radio Access Network) constituting a 5G (5th Generation) communication network and a control device 1 (5G Core network / EPC (Evolved Packet Core)), and an information terminal 2 connected to a virtual network KN generated and allocated by the control device 1 (5G Core network). The information terminal 2 is communicably connected to a reader 41 that transmits information (first position information) indicating the physical position of the own terminal. A SIM card 3 compatible with 5G is inserted into the information terminal 2.

[0012] The reader 41 is provided, for example, at the entrance (gate) of each room 4 such as an individual office or a conference room provided in a shared office or a rental conference room building, and may be configured as a part of a so-called door gate (entrance / exit management device). As shown in the illustration in this embodiment, there are three offices (rooms 4) in the shared office, and a reader 41 (door gate) is placed at each entrance (gate) of each room 4. When a user of the office (room 4) enters the room 4, the user holds an information terminal 2 such as a smartphone owned by himself / herself in front of the reader 41, and the reader 41 performs entrance / exit control (entrance / exit management). An identification number (reader ID) for identifying each individual reader 41 is set for each reader 41 placed in each room 4, and the reader ID is transmitted from the reader 41 to the information terminal 2. The information terminal 2 acquires the reader ID transmitted from the reader 41 as the first position information.

[0013] The information terminal 2 further acquires the base station ID transmitted from the base station KK as the second position information. After storing the acquired reader ID (first position information) and base station ID (second position information) in the SIM card 3 attached to its own terminal, the information terminal 2 combines (associates) the first position information and the second position information and transmits them to the control device 1 (5G core network) via the base station KK.

[0014] The control device 1 (5G core network) performs mutual authentication based on the first position information and the second position information transmitted from the information terminal 2, and if the result of the mutual authentication is positive, assigns the virtual network KN to the information terminal 2.

[0015] The virtual network KN is a logical network generated by network slicing, which is a 5G function. By using network slicing, a single network infrastructure (base station KK and 5G core network) can be virtually divided (sliced) and provided and operated as multiple logical networks so as to provide services according to various needs and applications. The information terminal 2 to which the virtual network KN is assigned can then communicate with a management server KS or an application server connected to a wide-area network BN such as the Internet using the virtual network KN.

[0016] As described above, since different readers 41 (door gates) are placed in each individual office (room 4) such as a shared office, the reader IDs (first position information) transmitted from each of these readers 41 are different. Therefore, different virtual networks KN can be assigned to these individual offices (rooms 4) with respect to the reader ID (first position information), so that fine control can be performed in units of each room 4, such as ensuring security and bandwidth in units of each room 4. Therefore, even in a facility used by an unspecified number of users such as a shared office, a secure network environment can be provided to each user of each room 4 by generating and assigning a virtual network KN (logical network by 5G network slicing) in units of each room 4 used by each user. In the present embodiment, the reader 41 (door gate) is assumed to be placed in each individual office (room 4) such as a shared office, but it is not limited thereto, and the reader 41 (door gate) may be provided, for example, in each individual facility. That is, the room 4 in the present embodiment includes, for example, each office in a shared office, each conference room in a rental conference room building, each retail store in a shopping mall, and facilities in a complex facility building.

[0017] In this embodiment, it is assumed that the virtual network KN is assigned to the information terminal 2, but it is not limited thereto. The virtual network KN may be assigned to various devices equipped with the SIM card 3 based on the first position information and the second position information. That is, a plurality of readers 41 that output the first position information are provided, for example, in each of a plurality of areas of a factory. When the SIM card 3 is mounted on a transport vehicle traveling within the factory, the virtual network KN may be assigned to each transport vehicle according to the first position information transmitted from the corresponding reader 41 in each area where the transport vehicle is located and the second position information from the base station KK.

[0018] The information terminal 2 is constituted by a terminal device (mobile terminal) having a mobile phone function, such as a smartphone, a tablet PC, or a personal computer. The information terminal 2 includes a control unit 21, a storage unit 22, a communication unit 23, and a display unit 24, and a SIM card 3 compatible with 5G is inserted inside the terminal.

[0019] The control unit 21 has an arithmetic processing device having a timekeeping function and a GPS function, such as one or more CPUs (Central Processing Units), MPUs (Micro-Processing Units), GPUs (Graphics Processing Units), etc., and reads and executes a program (program product) stored in the storage unit 22 to perform various information processing and control processing related to the information terminal 2.

[0020] The storage unit 22 includes a volatile storage area such as SRAM (Static Random Access Memory), DRAM (Dynamic Random Access Memory), or flash memory, and a non-volatile storage area such as EEPROM or a hard disk. The storage unit 22 stores a program (program product) and data to be referred to during processing in advance. The program stored in the storage unit 22 may be one that stores the program read from the record medium 221 readable by the terminal device. Alternatively, it may be one that downloads a program from an external computer (not shown) connected to a communication network (not shown) and stores it in the storage unit 22.

[0021] The communication unit 23 is, for example, a communication IF corresponding to 5G and functions as a wide-area communication unit. The communication unit may further include a narrow-area communication unit having a WiFi (registered trademark) or an NFC function for short-range wireless communication that communicates information of an IC chip corresponding to, for example, the NFC (Near field communication) standard.

[0022] The display unit 24 is, for example, a liquid crystal display and is provided integrally with the main body (housing) of the information terminal 2. The display unit 24 may function as an input unit using, for example, a touch panel or the like. The display unit 24 may display a QR code (registered trademark) or the like to be read (read target) by the reading machine 41.

[0023] The SIM card 3 corresponds to the 5G standard, includes a microcomputer 31, an input / output unit 32, and a non-volatile memory 33, and is inserted into a slot provided inside the information terminal 2. The microcomputer 31 of the SIM card 3 may be responsible for the reception process of the virtual network KN assigned by the control device 1 (5G core network).

[0024] The input / output unit 32 is a connection interface for connecting to the information terminal 2. By being connected to a slot (connection part) provided in the information terminal 2, information can be exchanged between the control unit 21 of the information terminal 2 and the SIM card 3. The microcomputer 31 and the non-volatile memory 33 may be formed on a single semiconductor circuit or may be constituted by separate semiconductor circuits.

[0025] The non-volatile memory 33 is constituted by, for example, an EEPROM or the like, similar to the storage unit 22 of the information terminal 2. The first position information and the second position information acquired (received) by the information terminal 2 are combined (associated) and stored (remembered). In this embodiment, it is assumed that the first position information and the second position information are stored (remembered) in the non-volatile memory 33 of the SIM card 3, but it is not limited thereto, and the first position information and the second position information may be stored (remembered) in the storage unit 22 of the information terminal 2.

[0026] The control device 1 is a device that configures and controls a 5G core network, and is a device that performs processes such as generation, allocation, and disappearance of the virtual network KN. The 5G core network is constituted by the cooperation of a plurality of devices such as, for example, an MME (Mobility Management Entity), an SGW (Serving Gateway), and a PGW (Packet data network Gateway). The control device 1 means the general term of these plurality of devices, and the control unit 11, the storage unit 12, the communication unit 13, etc. provided in the control device 1 are intended to indicate the control units, etc. provided in these plurality of devices.

[0027] The control unit 11 of the control device 1 is constituted by a plurality of CPUs or the like, and reads and executes a control program (program product) stored in the storage unit 12 to perform relay control in 5G communication and control processes in general as a 5G core network, such as generation, allocation, and deletion of the virtual network KN by network slicing. The communication unit 13 of the control device 1 includes a 5G-side communication IF for communicating with the base station KK and a communication IF on the wide-area network BN side such as the Internet.

[0028] The storage unit 12 of the control device 1 is composed of a volatile and a non-volatile storage area, and stores a control program for performing all control processes as a 5G core network. The control program may store the control program read from the recording medium 121 readable by the control device 1. Alternatively, it may be a program downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 12.

[0029] The storage unit 12 of the control device 1 stores an authentication table used when allocating the virtual network KN to the information terminal 2. The control device 1 determines the validity of the combination of the first location information and the second location information transmitted from the information terminal 2 by referring to the authentication table stored in the storage unit, that is, performs mutual authentication based on the first location information and the second location information.

[0030] Figure 3 is an explanatory diagram showing an example of the authentication table. The authentication table includes, as management items (fields), for example, the first location information indicating the physical location of the information terminal 2 and the second location information specifying the base station KK. In the field of the first location information, for example, the reader IDs of the readers 41 provided in each of the plurality of rooms 4 such as a shared office are stored. In the field of the second location information, the base station ID of the base station KK to be controlled by the control device 1 is stored.

[0031] Each record in the authentication table is composed of these fields of the first position information and the second position information, so that the combination of the first position information and the second position information is managed. That is, the combination of the first position information and the second position information stored (defined) in any record is determined to be a legitimate combination of the first position information and the second position information, and the mutual authentication by the control device 1 results in a positive result. When the combination of the first position information and the second position information transmitted by the information terminal 2 does not correspond to the combination of the first position information and the second position information in any record, the mutual authentication by the control device 1 results in a negative result.

[0032] In the field of the second position information, for example, the reader IDs of the readers 41 provided in each of a plurality of rooms 4 such as a shared office are stored, but it is not limited to this, and GPS data (latitude, longitude) indicating the position information of the room 4 may be used.

[0033] FIG. 4 is an explanatory diagram (sequence diagram) illustrating an aspect of each process by the information terminal 2, the control device 1, etc. The reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2 as entry / exit control when the user of the information terminal 2 enters the room (S11). The reader 41 may perform entry / exit control when the user of the information terminal 2 enters the room by reading, for example, the QR code displayed on the display unit 24 of the information terminal 2. Alternatively, the reader 41 and the information terminal 2 have an NFC (Near field communication) function, and the reader 41 may obtain the information associated with the information terminal 2 by reading the information of the NFC standard IC chip inserted into the information terminal 2 using short-range communication according to the NFC standard.

[0034] The reader 41 transmits (outputs) a reader ID (first location information) to the information terminal 2 (S12). The reader 41 and the information terminal 2 communicate with each other using a short-range communication function such as WiFi, NFC, or infrared communication. The information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as the first location information. The first location information is not limited to the reader ID transmitted from the reader 41, and may be, for example, GPS data indicating the current location of the information terminal 2. The information terminal 2 may use, as a trigger, a signal transmitted from a door gate such as the reader 41 used for entry / exit control when the user of the information terminal 2 enters the room, and set the GPS data acquired by the GPS module included in the information terminal 2 as the first location information.

[0035] The base station KK transmits (outputs) a base station ID (second location information) to the information terminal 2 (S13). The base station KK broadcasts, for example, its own base station ID using a 5G carrier, and the information terminal 2 receives (acquires) the base station ID from the base station KK as the second location information.

[0036] The information terminal 2 stores (records) the reader ID (first location information) and the base station ID (second location information) in the SIM card 3 (S14). The information terminal 2 associates (combines) the acquired first location information and second location information and stores them in the non-volatile memory 33 of the SIM card 3, thereby storing them in the SIM card 3.

[0037] The information terminal 2 transmits (outputs) the reader ID (first location information) and the base station ID (second location information) stored in the SIM card 3 to the control device 1 via the base station KK (S15). The information terminal 2 and the control device 1 communicate with each other using, for example, a 5G carrier, and the control device 1 receives (acquires) the reader ID (first location information) and the base station ID (second location information) transmitted from the information terminal 2.

[0038] The control device 1 performs mutual authentication based on the combination of the received reader ID (first position information) and the base station ID (second position information) (S16). The control device 1 may, for example, perform an authentication process (determination process) of whether the combination of the first position information and the like transmitted from the information terminal 2 is appropriate (positive) or not (negative) by referring to the authentication table stored in the storage unit.

[0039] When the mutual authentication results in an affirmative outcome, the control device 1 assigns the virtual network KN to the information terminal 2 (S17). The information terminal 2 connects to the virtual network KN assigned by the control device 1. As described above, the control device 1 is, for example, a 5G core network (a group of multiple devices that control the 5G core network), and by using network slicing, which is a 5G function, it generates individual independent logical networks (virtual networks KN) while using the same physical infrastructure. The control device 1 provides access permission to the virtual network KN for the information terminal 2 and communication resources such as bandwidth by assigning the thus-generated virtual network KN to the information terminal 2. The information terminal 2 to which the virtual network KN is assigned can be connected to, for example, a management server KS connected to a wide-area network BN such as the Internet or various application servers using a secure network environment using the virtual network KN.

[0040] The information terminal 2 transmits (outputs) to the management server KS the log data obtained by adding and encrypting the first position information and the second position information via the assigned virtual network KN (S18). When performing data communication with the management server KS that manages log data such as the operation log and communication log of the information terminal 2 via the assigned virtual network KN, the information terminal 2 may generate log data obtained by adding and encrypting the first position information and the second position information and transmit the encrypted log data to the management server KS.

[0041] When the user of the information terminal 2 checks out, the reader 41 reads information associated with the information terminal 2, such as a QR code, etc., from the information terminal 2 as access control (S19). When the user of the information terminal 2 checks out, the reader 41 reads information associated with the information terminal 2, such as a QR code, etc., from the information terminal 2 in the same way as when the user checks in.

[0042] The reader 41 transmits (outputs) a reader ID (first position information) to the information terminal 2 (S20). The information terminal 2 receives (acquires) the reader ID (first position information) from the reader 41. When the user of the information terminal 2 checks out, the information terminal 2 receives (acquires) the reader ID (first position information) from the reader 41 in the same way as when the user checks in.

[0043] The information terminal 2 transmits (outputs) the checkout information generated based on the received reader ID (first position information) to the control device 1 via the base station KK (S21). When the user of the information terminal 2 checks out, the information terminal 2 generates checkout information based on the reader ID (first position information) received at that time, and transmits (outputs) the generated checkout information to the control device 1. The checkout information is, for example, data obtained by attaching a predetermined flag (checkout flag) to the reader ID (first position information).

[0044] The control device 1 receives (acquires) the checkout information from the information terminal 2. Thereby, the control device 1 can recognize that the information terminal 2 to which the virtual network KN is assigned has checked out from the room 4 specified by the first position information. That is, by receiving the checkout information from the information terminal 2, the control device 1 can recognize that the information terminal 2 to which the virtual network KN is assigned based on a positive result of mutual authentication is in a state that does not correspond to the positive result at the current time.

[0045] The control device 1 terminates the allocation of the virtual network KN to the information terminal 2 (S22). By terminating the allocation of the virtual network KN to the information terminal 2, access by the information terminal 2 to the virtual network KN is blocked. When terminating the allocation of the virtual network KN to the information terminal 2, the control device 1 may eliminate the virtual network KN. Alternatively, the control device 1 may maintain the virtual network KN for which the allocation is to be terminated, but transition the state of the virtual network KN to an inactive state and block access (connection) from the information terminal 2, thereby terminating the allocation of the virtual network KN to the information terminal 2.

[0046] When terminating the allocation of the virtual network KN to the information terminal 2, the control device 1 may transmit alert information indicating that the allocation of the virtual network KN has been terminated to the information terminal 2. By, for example, displaying the alert information on the display unit 24 of the information terminal 2, the user of the information terminal 2 can be efficiently notified that the allocation of the virtual network KN has been terminated.

[0047] When the control device 1 receives (acquires) logout information from the information terminal 2, it may terminate the allocation of the virtual network KN to the information terminal 2 after a predetermined grace period, such as 5 minutes, has elapsed. In this case, if the reader ID (first position information) and the base station ID (second position information) are transmitted (retransmitted) from the information terminal 2 within the grace period (before the grace period has elapsed), it goes without saying that the allocation of the virtual network KN to the information terminal 2 is continued.

[0048] FIG. 5 is a flowchart showing an example of the allocation process of the virtual network KN. The processing flows of the control unit 21 of the information terminal 2 and the control unit 11 of the control device 1, and the relationship between these processes will be described.

[0049] When the user of the information terminal 2 enters the room, the control unit 21 of the information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as the first position information (T101). When the user of the information terminal 2 enters the room, the reader 41 (the door gate of room 4) reads the information associated with the information terminal 2 from the information terminal 2, for example, by a QR code or an NFC function, and transmits its own reader ID to the information terminal 2. The control unit 21 of the information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as the first position information.

[0050] The control unit 21 of the information terminal 2 receives (acquires) the base station ID from the base station KK as the second position information (T102). The control unit 21 of the information terminal 2 receives (acquires) the base station ID from the base station KK whose communication area is the place where the reader 41 is placed, that is, room 4 where the user has entered, as the second position information.

[0051] The control unit 21 of the information terminal 2 stores (records) the reader ID (the first position information) and the base station ID (the second position information) in the SIM card 3 (T103). The microcontroller 31 of the SIM card 3 stores the reader ID (the first position information) and the base station ID (the second position information) acquired from the control unit 21 of the information terminal 2 in an associated (combined) manner in the non-volatile memory 33.

[0052] The control unit 21 of the information terminal 2 transmits (outputs) the reader ID (the first position information) and the base station ID (the second position information) stored in the SIM card 3 to the control device 1 via the base station KK (T104). The control unit 21 of the information terminal 2 uses the 5G carrier (bandwidth) provided by the base station KK to transmit (output) the reader ID (the first position information) and the base station ID (the second position information) stored in the SIM card 3 to the control device 1 (5G core network).

[0053] The control unit 21 of the information terminal 2 transmits (outputs) the log data obtained by adding and encrypting the first position information and the second position information to the management server KS via the assigned virtual network KN (T105). When the virtual network KN is assigned by the control device 1 (5G core network), the control unit 21 of the information terminal 2 accepts the assignment, connects to the virtual network KN as a communication node, and thereafter transmits (outputs) the log data obtained by adding and encrypting the first position information and the second position information to the management server KS. Further, the control unit 21 of the information terminal 2 may access (perform data communication) an application server or the like connected to a wide area network BN such as the Internet via the virtual network KN.

[0054] When the user of the information terminal 2 leaves the room, the control unit 21 of the information terminal 2 transmits (outputs) the departure information generated based on the reader ID transmitted from the reader 41 to the control device 1 via the base station KK (T106). When the user of the information terminal 2 leaves the room, for example, the control unit 21 of the information terminal 2 transmits (outputs) the departure information generated by attaching a predetermined flag (departure flag) to the reader ID (first position information) to the control device 1 via the base station KK. Thereby, the assignment of the virtual network KN to the information terminal 2 is canceled, and the access from the information terminal 2 to the virtual network KN is blocked.

[0055] The control unit 11 of the control device 1 receives (acquires) the reader ID (first position information) and the base station ID (second position information) transmitted from the information terminal 2 (S101). The control unit 11 of the control device 1 performs mutual authentication based on the combination of the received reader ID (first position information) and the base station ID (second position information) (S102). The control device 1 performs mutual authentication based on the combination of the first position information and the second position information transmitted from the information terminal 2 by referring to the authentication table stored in the storage unit.

[0056] The control unit 11 of the control device 1 determines whether the result of mutual authentication is positive or negative (S103). The control unit 11 of the control device 1 may determine whether the result of mutual authentication is positive or negative based on whether the combination of the first position information and the second position information transmitted from the information terminal 2 is defined (stored in any record) in the authentication table. If the result of mutual authentication is negative (S103: NO), the control unit 11 of the control device 1 ends the processing in this flowchart. Or, the control unit 11 of the control device 1 may perform a loop process to execute the processing of S101 again when the result of mutual authentication is negative.

[0057] When the result of mutual authentication is positive (S103: YES), the control unit 11 of the control device 1 assigns the virtual network KN to the information terminal 2 (S104). The control unit 11 of the control device 1 that functions as a 5G core network generates the virtual network KN using network slicing, which is a 5G function, and assigns it to the information terminal 2. As a result, the information terminal 2 is connected to the virtual network KN, and communication with the management server KS becomes possible via the virtual network KN.

[0058] The control unit 11 of the control device 1 determines whether it has received logout information from the information terminal 2 (S105). If it has not received logout information from the information terminal 2 (S105: NO), the control unit 11 of the control device 1 performs a loop process to execute the processing of S105 again.

[0059] When the control device 1 receives the exit information from the information terminal 2 (S105: YES), the control unit 11 of the control device 1 stops assigning the virtual network KN to the information terminal 2 (S106). When the control unit 11 of the control device 1 receives the exit information from the information terminal 2, it recognizes that the information terminal 2 to which the virtual network KN was assigned based on the positive result of mutual authentication is not in a state corresponding to the positive result at the current time, and stops assigning the virtual network KN to the information terminal 2. When stopping the assignment of the virtual network KN to the information terminal 2, the control device 1 may transition the state of the virtual network KN to an inactive state (non-connectable state) while either eliminating the virtual network KN or maintaining the virtual network KN for which the assignment is to be stopped.

[0060] According to an embodiment of the present disclosure, the control device 1 assigns the virtual network KN to the information terminal 2 based on the first position information and the second position information acquired from the information terminal 2, and connects the information terminal 2 to the virtual network KN. The first position information indicates the physical position information of the information terminal 2, and may be, for example, the identification information of the gate through which the information terminal 2 has passed, or GPS data indicating the location where the information terminal 2 is located. The second position information is information for specifying the base station KK of the local network that the information terminal 2 can communicate with when the information terminal 2 exists at the location specified by the first position information, and is, for example, the base station KK number (base station ID).

[0061] The control device 1 assigns the virtual network KN to the information terminal 2 according to the combination of the first position information and the second position information, so that the appropriateness (security) of the information terminal 2 that is assigned the virtual network KN, that is, the communication node in the virtual network KN, can be ensured. The control device 1 may assign a pre-generated virtual network KN to the information terminal 2, or may newly generate a virtual network KN when the assignment of the virtual network KN is required and assign this.

[0062] According to an embodiment of the present disclosure, the control device 1 performs mutual authentication based on a combination of acquired first position information and second position information by referring to, for example, a predetermined authentication table. When the result of the mutual authentication is positive, the control device 1 performs a process of allocating the virtual network KN to the information terminal 2. By referring to the authentication table in this way, it is possible to efficiently determine the appropriateness of the combination of the first position information and the second position information. When the result of the mutual authentication is negative, the control device 1 may output, for example, error information indicating that the mutual authentication has failed to the information terminal 2 without performing the process of allocating the virtual network KN to the information terminal 2.

[0063] According to an embodiment of the present disclosure, since the virtual network KN generated (constructed) by network slicing (5G network slicing) in 5G (the fifth-generation mobile communication system) is allocated to the information terminal 2, it is possible to multiplex virtual independent logical networks on the same physical network architecture.

[0064] According to an embodiment of the present disclosure, the first position information indicating the physical position of the information terminal 2 is, for example, information related to the readers 41 provided in each of a plurality of rooms 4 such as a shared office, and is, for example, a reader 41 number (reader ID) for individually identifying the reader 41. When a user having the information terminal 2 enters the room 4, the reader 41 reads the information associated with the information terminal 2 by using, for example, a QR code or an NFC (Near Field Communication) function, thereby performing entry / exit control (room entry / exit management) of the room 4 by the user. When the reader 41 successfully reads the information (such as a QR code) of the information terminal 2, the reader 41 number (reader ID) is transmitted (output) from the reader 41 to the information terminal 2, and the reader 41 number (reader ID) is combined with the second position information (base station ID) as the first position information and transmitted to the control device 1.

[0065] The control device 1 assigns a virtual network KN based on the first position information and the second position information that identify the room 4 where the information terminal 2 is located. Even when there are a plurality of rooms 4 within the communicable area of a single base station KK, a virtual network KN can be assigned corresponding to each room 4 where each information terminal 2 is located. As a result, in a facility having a plurality of rooms 4 such as a shared office, different virtual networks KN can be assigned to each room 4, and security for each room 4 can be efficiently ensured.

[0066] According to an embodiment of the present disclosure, when the user of the information terminal 2 exits from the room 4 corresponding to the first position information, information attached to the information terminal 2 such as a QR code is read by a reader 41 that performs entry / exit control of the room 4. At this time, the information terminal 2 transmits exit information indicating that the information terminal 2 (own terminal) is located outside the room 4 corresponding to the first position information to the control device 1. When the control device 1 acquires the exit information from the information terminal 2, in order to cancel the assignment of the virtual network KN to the information terminal 2, it can efficiently prohibit the information terminal 2 outside the room 4 corresponding to the first position information from connecting (accessing) to the virtual network KN, and can efficiently ensure the security in the virtual network KN.

[0067] According to an embodiment of the present disclosure, the information terminal 2 to which the virtual network KN is assigned transmits data (log data) such as operation log data or communication log data to a management server KS connected via the virtual network KN, for example, to the Internet. Since the data is encrypted with the first position information and the second position information added when mutually authenticated by the control device 1, not only at the time of assignment of the virtual network KN but also in the communication state using the virtual network KN after assignment, the security of the transmitted data based on the first position information and the second position information can be ensured.

[0068] In an embodiment of the present disclosure, the virtual network KN is generated by network slicing, which is a 5G function, but is not limited thereto. The virtual network KN may be generated by network slicing for next-generation communications such as 6G or 7G, which are applied after 5G.

[0069] (Embodiment 2) FIG. 6 is a flowchart showing an example of the allocation process of the virtual network KN according to Embodiment 2 (a plurality of information terminals 2). Embodiment 2 relates to a state in which a plurality of information terminals 2 exist in a single room 4 (users of the plurality of information terminals 2 enter the room). Since the processing in each information terminal 2 is the same as that in Embodiment 1, the processing related to the control device 1 will be described.

[0070] The control unit 11 of the control device 1 determines whether or not the first position information and the second position information have been received from the information terminal 2 (S201). If the first position information and the second position information have not been received (S201: NO), the control unit 11 of the control device 1 performs a loop process to execute the process of S201 again.

[0071] When the first position information and the second position information have been received (S201: YES), the control unit 11 of the control device 1 allocates the virtual network KN to the information terminal 2 that has transmitted the first position information and the second position information (S202).

[0072] The control unit 11 of the control device 1 increases by one the number of information terminals 2 to which the virtual network KN is assigned (S203). The control unit 11 of the control device 1 stores the number of information terminals 2 to which the virtual network KN is assigned at the current time, for example, by storing the number in a predetermined variable or the like in a storage unit or the like. The variables for storing the number of information terminals 2 are defined for each generated virtual network KN, and the number of information terminals 2 to which the corresponding virtual network KN is assigned is stored in each variable corresponding to each virtual network KN. The control unit 11 of the control device 1 increases by one the number of information terminals 2 to which the virtual network KN is assigned, and performs a loop process to execute the process of S201 again.

[0073] The control unit 11 of the control device 1 determines whether or not it has received withdrawal information from the information terminal 2 (S204). If it has not received the withdrawal information (S204: NO), the control unit 11 of the control device 1 performs a loop process to execute the process of S204 again.

[0074] If it has received the withdrawal information (S204: YES), the control unit 11 of the control device 1 cancels the assignment of the virtual network KN to the information terminal 2 that sent the withdrawal information (S205). The control unit 11 of the control device 1 cancels the assignment of the virtual network KN to the information terminal 2 that sent the withdrawal information, but maintains the virtual network KN itself without eliminating it. As a result, the assignment of the virtual network KN to the information terminals 2 that have not sent the withdrawal information, that is, the information terminals 2 existing in the room 4 corresponding to the first position information, continues. When the information terminal 2 that sent the withdrawal information is in a state of existing again in the room 4 corresponding to the first position information, that is, when the user of the information terminal 2 re-enters the room 4, the control unit 11 of the control device 1 resumes (re-assigns) the assignment of the virtual network KN to the re-entered information terminal 2. By performing the re-assignment process in this way, the assignment process of the virtual network KN to the re-entered information terminal 2 can be efficiently performed.

[0075] The control unit 11 of the control device 1 decreases the number of information terminals 2 to which the virtual network KN is assigned by one (S206). The control unit 11 of the control device 1 decreases the number of information terminals 2 to which the virtual network KN is assigned by one and performs a loop process to execute the process of S206 again.

[0076] The control unit 11 of the control device 1 determines whether the number of information terminals 2 to which the virtual network KN is assigned is 0 (S207). When the number of information terminals 2 to which the virtual network KN is assigned is not 0 (S207: NO), the control unit 11 of the control device 1 performs a loop process to execute the process of S207 again.

[0077] When the number of information terminals 2 to which the virtual network KN is assigned is 0 (S207: YES), the control unit 11 of the control device 1 causes the virtual network KN assigned to these plurality of information terminals 2 to disappear (S208). When the number of information terminals 2 to which the virtual network KN is assigned is 0, the control unit 11 of the control device 1 causes the virtual network KN assigned to these plurality of information terminals 2 to disappear and prevents reallocation by these information terminals 2, thereby canceling the assignment of the virtual network KN to all of the plurality of information terminals 2.

[0078] According to the embodiment of the present disclosure, when assigning different virtual networks KN for each room 4, when there are a plurality of information terminals 2 in the same room 4 (the room 4 corresponding to the same first position information), the control device 1 assigns the same virtual network KN to these plurality of information terminals 2. Thereby, a plurality of information terminals 2 existing (located) in the same room 4 share the same virtual network KN, and while ensuring the security by the virtual network KN, communication between these plurality of information terminals 2 can be performed with a low hop count, and the communication efficiency can be improved.

[0079] According to an embodiment of the present disclosure, when there are a plurality of information terminals 2 in the same room 4 (the room 4 corresponding to the same first position information), the control device 1, when all of these plurality of information terminals 2 are located outside the room 4, for example, by eliminating the virtual network KN, stops the allocation of the virtual network KN to all of the plurality of information terminals 2, so that the security in the virtual network KN can be efficiently ensured.

[0080] All of the embodiments disclosed this time should be considered as illustrative in all respects and not restrictive. The scope of the present invention is shown not by the above description but by the claims, and it is intended that all modifications within the meaning and scope equivalent to the claims are included.

Explanation of Signs

[0081] S Virtual network allocation system BN Wide area network KS Management server KN Virtual network KK Base station 1 Control device 11 Control unit 12 Storage unit 121 Recording medium 13 Communication unit P1 Control program 2 Information terminal 21 Control unit 22 Storage unit 221 Recording medium P2 Program 23 Communication unit 24 Display unit 3 SIM card 31 Microcomputer 32 Input / output unit 33 Non-volatile memory 4 Room 41 Reader (door gate, access control device)

Claims

1. Obtain first location information regarding the location where the information terminal exists, Obtain second location information for identifying a base station of a local network with which the information terminal can communicate, Assign a virtual network connected to the information terminal according to the obtained first location information and the second location information, The first location information is information regarding a reader that is provided in each of a plurality of rooms and reads information associated with the information terminal, The virtual network is assigned for each of the information terminals corresponding to each of the plurality of rooms A program for causing a computer to execute processing.

2. Perform mutual authentication based on the combination of the obtained first location information and the second location information, When the result of the mutual authentication is affirmative, assign the virtual network connected to the information terminal The program according to claim 1.

3. The communication protocol of the local network is 5G, The virtual network is generated by network slicing in 5G The program according to claim 1 or claim 2.

4. When obtaining exit information indicating that the information terminal is located outside the room corresponding to the first location information, Abort the assignment of the virtual network to the information terminal The program according to any one of claims 1 to 3.

5. When a plurality of information terminals exist in a room corresponding to the same first location information, assign the same virtual network to the plurality of information terminals The program according to any one of claims 1 to 4.

6. After the same virtual network is assigned to the plurality of information terminals due to the existence of the plurality of information terminals in a room corresponding to the same first location information, when obtaining exit information indicating that all of the plurality of information terminals are located outside the room from all of the plurality of information terminals, abort the assignment of the virtual network to all of the plurality of information terminals The program according to claim 5.

7. Data transmitted from the information terminal via the virtual network is encrypted with the first location information and the second location information added thereto The program according to any one of claims 1 to 6.

8. Cause a computer to Obtain first location information regarding the location where the information terminal exists, Obtain second location information that identifies a base station of a local network with which the information terminal can communicate, According to the obtained first location information and the second location information, allocate a virtual network connected to the information terminal, The first location information is information regarding a reader provided in each of a plurality of rooms and configured to read information associated with the information terminal, The virtual network is allocated for each information terminal corresponding to each of the plurality of rooms A virtual network allocation method for executing processing.

9. A virtual network allocation system including an information terminal and a control device that allocates a virtual network to the information terminal, The information terminal is configured to: Obtain first location information regarding the location where the own terminal is present, Obtain second location information that identifies a base station of a local network with which the location where the own terminal is present can communicate, Output the obtained first location information and the second location information to the control device, The control device is configured to: Obtain the first location information and the second location information from the information terminal, According to the obtained first location information and the second location information, allocate a virtual network connected to the information terminal, The first location information is information regarding a reader provided in each of a plurality of rooms and configured to read information associated with the information terminal, The virtual network is allocated for each information terminal corresponding to each of the plurality of rooms A virtual network allocation system.

Citation Information

Patent Citations

  • JP1973011606B1

  • Conference room reservation system, conference room reservation method, and conference room reservation program

    JP2016184241A

  • Communication control method and connection target change method

    JP2021016014A