Network configuration device, information system, network configuration method, and program
The network configuration device addresses the security risk in virtual networks by authenticating network devices, ensuring secure virtual network configuration.
Patent Information
- Application Number
- JP2023559335
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-12
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-11-12
AI Technical Summary
Existing network configuration technologies do not consider the authenticity of resources allocated to virtual networks, posing a security risk in communication services.
A network configuration device that acquires device information, determines the authenticity of network devices, and configures virtual networks based on the authenticity determination results to ensure security.
Ensures the configuration of secure virtual networks by utilizing a device that acquires and verifies the authenticity of network devices, thereby enhancing network security.
Smart Images

Figure 0007704209000001 
Figure 0007704209000002 
Figure 0007704209000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a network configuration device, an information system, a network configuration method, and a recording medium.
Background Art
[0002] Communications services that meet various demands from users, such as the use of high-quality lines without interruption of data communication, are being operated on the network. For this reason, there is a technology called network slicing in which slices are selected and operated for each service in a plurality of virtual networks within the network.
[0003] For example, Patent Document 1 discloses a network service management device that determines resources to be allocated to a virtual network for a function that matches the resource requirements of a virtual network function that constitutes a network service.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the invention described in Patent Document 1, the authenticity of the resources allocated to the virtual network is not considered. For this reason, there is a risk in terms of security when providing communication services.
[0006] An example of the object of the present disclosure is to provide a network configuration device capable of configuring a virtual network while ensuring network security.
Means for Solving the Problems
[0007] The network configuration device according to one aspect of the present disclosure includes: a device information acquisition unit that acquires device information visualizing the configuration and risks related to network devices connected to a physical network; an authenticity determination unit that determines the authenticity of network devices based on the acquired device information; and a network configuration unit that configures a virtual network on the physical network based on the determination result of the authenticity of network devices.
[0008] An information system according to one aspect of the present disclosure includes: a network configuration device; a service slice management device that manages and controls the network configuration device; and a device information storage device that stores device information visualizing the configuration and risks related to network devices connected to a physical network. The network configuration device includes: a device information acquisition unit that acquires device information from the device information storage device; an authenticity determination unit that determines the authenticity of network devices based on the acquired device information; and a network configuration unit that configures a virtual network on the physical network based on the determination result of the authenticity of network devices.
[0009] A network configuration method according to one aspect of the present disclosure includes: acquiring device information visualizing the configuration and risks related to network devices connected to a physical network; determining the authenticity of network devices based on the acquired device information; and configuring a virtual network on the physical network based on the determination result of the authenticity of network devices.
[0010] A recording medium according to one aspect of the present disclosure stores a program that causes a computer to execute: acquiring device information visualizing the configuration and risks related to network devices connected to a physical network; determining the authenticity of network devices based on the acquired device information; and configuring a virtual network on the physical network based on the determination result of the authenticity of network devices.
Advantages of the Invention
[0011] One example of the effect according to the present disclosure is to provide a network configuration device that can configure a virtual network while ensuring security.
Brief Description of Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0013] Next, the embodiments will be described in detail with reference to the drawings.
[0014] [First Embodiment] The network configuration device 100 in the first embodiment is a device for performing network slicing that configures a plurality of virtual networks (slices) composed of one physical network and assigns functions necessary for communication services. A virtual network refers to a network in which physical resources are abstracted by software and can be logically grouped or divided for use.
[0015] A network slice is a technology that constructs multiple independent slices in software in an end-to-end manner across domains while commonly using network devices such as general-purpose servers and transport devices, according to the requirements of communication services. With network slice technology, by allocating resources such as data processing functions and storage to each slice, communication services with different requirements can be separated and constructed for each slice. The network configuration device 100 is realized, for example, by a plurality of resource controllers that respectively manage and control various devices for each domain (for example, radio access, transport, and core).
[0016] In addition, the information system 10 in the present embodiment includes a network configuration device 100, a service slice management device 200 that manages and controls the network configuration device 100, and a device information storage device 300 that stores device information visualizing the configuration and risks related to network devices connected to the network.
[0017] FIG. 1 is a block diagram showing the configuration of the network configuration device 100 in the first embodiment. Referring to FIG. 1, the network configuration device 100 includes a device information acquisition unit 101, an authenticity determination unit 102, and a network configuration unit 103. Hereinafter, the network configuration device 100, which is an essential configuration of the present embodiment, will be described in detail.
[0018] FIG. 2 is a diagram showing an example of a hardware configuration in which the network configuration device 100 according to the first embodiment of the present disclosure is realized by a computer device 500 including a processor. As shown in FIG. 2, the network configuration device 100 includes a CPU (Central Processing Unit) 501, a ROM (Read Only Memory) 502, a memory such as a RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication I / F (Interface) 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the first embodiment, the device information acquired by the device information acquisition unit 101 is input to the network configuration device 100 via the input / output interface 511.
[0019] The CPU 501 operates an operating system to control the entire network configuration device 100 according to the first embodiment of the present invention. Further, the CPU 501 reads programs and data from the memory from a recording medium 506 mounted on, for example, a drive device 507. Further, the CPU 501 functions as the device information acquisition unit 101, the authenticity determination unit 102, and the network configuration unit 103 in the first embodiment and executes the processes or instructions in the flowchart shown in FIG. 3 described later based on the program.
[0020] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. Some recording media of the storage device are non-volatile storage devices, and programs are recorded therein. Further, the program may be downloaded from an external computer (not shown) connected to the communication network.
[0021] The input device 509 is realized by, for example, a mouse, a keyboard, a built-in key button, etc. and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or a built-in key button, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display and is used to confirm the output.
[0022] As described above, the first embodiment shown in FIG. 1 is realized by the computer hardware shown in FIG. 2. However, the implementation means of each part included in the network configuration device 100 in FIG. 1 is not limited to the configuration described above. Further, the network configuration device 100 may be realized by a single physically connected device, or may be realized by two or more physically separated devices connected by wire or wirelessly. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network. Further, the network configuration device 100 in the first embodiment shown in FIG. 1 may also be configured by cloud computing or the like.
[0023] In FIG. 1, the device information acquisition unit 101 is a means for acquiring device information that visualizes the configuration and risks of network devices connected to the network. The network includes a physical network and a plurality of virtual networks constructed on the physical network. The device information acquisition unit 101 acquires the device information of each network device connected on the network from the device information storage device 300. The network devices on the network may be singular or plural.
[0024] In this embodiment, the device information is information necessary for determining the authenticity of network devices, and includes different types of device information such as configuration information, event information, and inspection information. The event information and the inspection information are information that visualizes the risks of network devices. Here, each device information stored in the device information storage device 300 will be described. In the device information storage device 300, for example, configuration information, event information, and inspection information are stored together with the time when the information was acquired for each network device.
[0025] Configuration information is, for example, the hardware information and software information of network devices. Hardware information includes manufacturer information, model numbers of chips, circuit boards, ports, etc. that make up the hardware, and identifiers assigned to the hardware. Software information includes manufacturer information, software names such as the OS (Operating System), libraries, or applications that process the hardware, version information of the software, or hash values. A hash value is a value calculated from data composed of the binary of software, etc., and by comparing it with the hash value distributed by the software manufacturer, the identity with the software distributed by the manufacturer can be confirmed. Configuration information is updated when the configuration information, such as the timing of software version updates, is updated.
[0026] Event information is, for example, the log information generated within network devices. As log information, for example, packet communication information such as the communication data volume, communication error rate, or the number of packet retransmissions of each network port connected to the network device is stored. Event information is updated, for example, at intervals of several seconds.
[0027] Inspection information is information regarding the results of inspection and analysis based on the configuration information and event information of the device under monitoring. The inspection results are stored with the time information linked to the result of whether the device is genuine or not. Inspection information is updated, for example, at the timing when the configuration changes, such as a software version update of the network device, or at the timing when the event information changes significantly.
[0028] The authenticity determination unit 102 is a means for determining the authenticity of a network device based on the device information acquired by the device information acquisition unit 101. In the present embodiment, authenticity means a state in which the settings of the hardware information and software information of the network device have not been erased, altered, or replaced. The authenticity determination unit 102 first determines the authenticity of the network device using a known method for each of the configuration information, event information, and inspection information, and outputs the individual authenticity information that is the determination result.
[0029] For the configuration information, the authenticity determination unit 102 determines whether there is authenticity based on, for example, the difference between the configuration information at the time of system delivery and the configuration information stored in the device information storage device 300. Also, for the event information, the authenticity determination unit 102 determines whether there is authenticity based on, for example, the event information of normal values and the event information stored in the device information storage device 300. For the inspection information, the authenticity determination unit 102 determines whether there is authenticity based on, for example, the analysis result of the inspection or the presence or absence of the implementation of the inspection.
[0030] Next, the authenticity determination unit 102 comprehensively determines the authenticity of the network device based on the individual authenticity information that is the determination result of the authenticity of the configuration information, event information, and inspection information. The authenticity determination unit 102 outputs authenticity information as the determination result of the authenticity. The authenticity information is information indicating whether the authenticity is guaranteed, and may be indicated by a binary value of the presence or absence of authenticity. Alternatively, the authenticity information may be indicated by a numerical value (score) such as 0 to 100%.
[0031] When the authenticity information is indicated by the presence or absence of authenticity, for example, the authenticity determination unit 102 determines that the network device has authenticity if any of the configuration information, event information, and inspection information of the network device has authenticity. If none of the device information of the network device has authenticity, the authenticity determination unit 102 determines that the network device has no authenticity. When the device information of the network device includes information with authenticity and information without authenticity, the authenticity determination unit 102 determines authenticity according to the number of information determined to have authenticity and the types of information determined to have authenticity. For example, if the authenticity determination unit 102 determines that the configuration information has no authenticity but determines that the event information and inspection information have authenticity, it determines that there is authenticity. However, the method for determining authenticity by the authenticity determination unit 102 is not limited to this.
[0032] The network configuration unit 103 is a means for configuring a virtual network based on the determination result of the authenticity of the device determined by the authenticity determination unit 102. The network configuration unit 103 configures a virtual network using only the network devices determined to have authenticity by the authenticity determination unit 102. On the other hand, the network configuration unit 103 incorporates the network devices determined to have no authenticity by the authenticity determination unit 102 into the virtual network. None In addition, the network configuration unit 103 transmits the information of the network devices incorporated into the virtual network to the service slice management device 200.
[0033] The operation of the network configuration device 100 configured as described above will be described with reference to the flowchart of FIG. 3.
[0034] FIG. 3 is a flowchart showing an overview of the operation of the network configuration device 100 in the first embodiment. The processing according to this flowchart may be executed based on program control by the aforementioned processor.
[0035] As shown in FIG. 3, first, the device information acquisition unit 101 acquires device information about a network device connected to the network (step S101). Next, the authenticity determination unit 102 determines the authenticity of the network device based on the device information acquired by the device information acquisition unit 101 (step S102). Finally, the network configuration unit 103 configures a virtual network based on the authenticity determination result determined by the authenticity determination unit 102 (step S103). Thus, the network configuration device 100 ends the operation of network configuration.
[0036] In the network configuration device 100 in the present embodiment, the network configuration unit 103 configures a virtual network based on the authenticity determination result determined by the device information acquisition unit 101. Thereby, since the network configuration device 100 can configure a virtual network using a network device with guaranteed authenticity, it is possible to configure a network while ensuring security.
[0037] A modification of the present embodiment will be described. In the present embodiment, the authenticity determination unit 102 first determines the authenticity of the network device by a known method for each of the configuration information, event information, and inspection information, and comprehensively determines the authenticity of the network device based on the authenticity individual information that is the determination result of each authenticity. However, the authenticity determination unit 102 may acquire each authenticity individual information determined by the network device based on various device information, and determine the authenticity of the network device based on the acquired authenticity individual information.
[0038] [Second Embodiment] Next, a second embodiment of the present disclosure will be described in detail with reference to the drawings. Hereinafter, as long as the description of the present embodiment is not unclear, the description of the overlapping content with the above description will be omitted. Each component in each embodiment of the present disclosure can be realized by a computer device or software based on program control as well as hardware-implementing its function in the same manner as the computer device shown in FIG. 2.
[0039] FIG. 4 is a block diagram showing the configuration of the network configuration device 110 according to the second embodiment of the present disclosure. Referring to FIG. 4, the network configuration device 110 according to the second embodiment will be described centering on the parts different from the network configuration device 100 according to the first embodiment. The network configuration device 110 according to the second embodiment includes a device information acquisition unit 111, a risk score calculation unit 112, an authenticity determination unit 113, and a network configuration unit 114. That is, this embodiment is different from the first embodiment in that it includes a risk score calculation unit 112.
[0040] The device information acquisition unit 111 in the second embodiment acquires device information when the device information of the network devices incorporated in the virtual network is updated. When the device information is updated means the timing when the device information is updated. When the device information in the device information storage device 310 is updated, the device information acquisition unit 111 receives information indicating that the device information is updated from the device information storage device 310. Also, the device information acquisition unit 111 may sequentially monitor the information in the device information storage device 310 and detect that the device information in the device information storage device 310 has been updated. The method of acquiring device information by the device information acquisition unit 111 is the same as that of the device information acquisition unit 101.
[0041] The risk score calculation unit 112 is a means for calculating a risk score, which is a degree of authenticity, based on device information. The risk score calculation unit 112 calculates the risk score based on each of the configuration information, event information, and inspection information of the network device. First, the risk score calculation unit 112 scores the authenticity of each piece of information by a known method based on the device information acquired by the device information acquisition unit 111. Specifically, in the case of configuration information, if it is close to the configuration information (hardware and software) at the time of delivery, the score is high, and as the different parts increase, the score is lowered. Note that the risk score calculation unit 112 may score the configuration information of the software by comparing it with the configuration information at the time of update instead of the configuration information at the time of delivery. That is, if it is close to the configuration information of the software at the time of update, the score is high, and as the different parts increase, the score is lowered. Also, in the case of event information, if it is close to the normal value, the score is high, and as the different parts become larger, the score is lowered. The risk score calculation unit 112 scores the inspection information according to the inspection result.
[0042] The risk score calculation unit 112 scores the risk score based on each of the configuration information, event information, and inspection information by the method described above. Next, the risk score calculation unit 112 calculates the risk score of the entire network device by summing up the numerical values of various authenticity information associated with the target network device using a method such as logical sum, arithmetic mean, or total. However, the calculation method by the risk score calculation unit 112 is not limited to this. Also, the risk score may be calculated using an AI (artificial intelligence) model generated based on the correlation between various authenticity information and the actual authenticity result. The risk score calculation unit 112 outputs the calculated risk score of the device to the authenticity determination unit 113.
[0043] The authenticity determination unit 113 determines the authenticity of the network device based on the risk score calculated by the risk score calculation unit 112. When the calculated risk score is greater than a predetermined threshold, the authenticity determination unit 113 determines that there is authenticity. On the other hand, when the calculated risk score is not greater than the predetermined threshold, the authenticity determination unit 113 determines that there is no authenticity. The information of the threshold is stored in, for example, the storage device 505. The authenticity determination unit 113 outputs the determination result of authenticity to the network configuration unit 114.
[0044] Based on the determination result of authenticity determined by the authenticity determination unit 113, the network configuration unit 114 reconfigures the virtual network by configuring the virtual network. That is, the network configuration unit 114 excludes the network device determined to have no authenticity by the authenticity determination unit 113 from the network configuration. In addition, the network configuration unit 114 incorporates the network device determined to have authenticity by the authenticity determination unit 113 in place of the excluded network device.
[0045] The operation of the network configuration device 110 configured as described above will be described with reference to the flowchart of FIG. 5.
[0046] FIG. 5 is a flowchart showing an overview of the operation of the network configuration device 110 in the second embodiment. The processing according to this flowchart may be executed based on the program control by the processor described above.
[0047] As shown in FIG. 5, first, when the device information acquisition unit 111 detects an update of the device information in the device information storage device 310 (step S201), it acquires the device information of the network devices connected to the network (step S202). Next, the risk score calculation unit 112 calculates the risk score of the network devices based on the device information acquired by the device information acquisition unit 111 (step S203). Next, the authenticity determination unit 113 determines the authenticity of the network devices based on the calculated risk score (step S204). Finally, the network configuration unit 114 reconfigures the virtual network based on the authenticity result determined by the authenticity determination unit 113 (step S205). The network configuration device 110 repeats a series of flows every time it detects an update of the device information in the device information storage device 310. Thus, the network configuration device 110 ends the operation of network configuration.
[0048] In the second embodiment of the present disclosure, the authenticity determination unit 113 determines the authenticity of the network devices based on the calculated risk score, and the network configuration unit 114 reconfigures the virtual network based on the determined authenticity result. Thereby, the authenticity conditions of the network devices to be reconfigured can be set in detail. Also, in the second embodiment of the present disclosure, when the device information of the network devices is updated, the network configuration unit 114 reconfigures the virtual network based on the authenticity determination result by the authenticity determination unit 113. Thereby, even if the authenticity of the network devices collapses after the virtual network is configured, the security of the network can be ensured.
[0049] Although the present invention has been described with reference to each of the embodiments above, the present invention is not limited to the above embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0050] For example, although a plurality of operations are described in order in the form of a flowchart, the order of the description does not limit the order in which the plurality of operations are executed. Therefore, when implementing each embodiment, the order of the plurality of operations can be changed as long as there is no problem in terms of content. Also, in the present embodiment, the authenticity determination unit 113 determines the authenticity of the network device based on the risk score calculated by the risk score calculation unit 112, and the network configuration unit 114 reconstructs the virtual network based on the authenticity result determined by the authenticity determination unit 113. However, the authenticity determination unit 113 does not have to determine the authenticity based on the risk score calculated by the risk score calculation unit 112. That is, similar to the authenticity determination unit 102 of the first embodiment, the authenticity can be determined based on the device information acquired by the device information acquisition unit 111, and the virtual network can be reconstructed based on the authenticity determined by the network configuration unit 114. Furthermore, the network configuration unit 114 may reconstruct the virtual network based on the risk score calculated by the risk score calculation unit 112 (for example, in the order of the risk scores). That is, in the second embodiment, a configuration without the authenticity determination unit 113 may be provided. Furthermore, although the risk score calculation unit 112 scores the authenticity of various device information based on the device information, information (authenticity individual information) obtained by scoring the authenticity of various device information from the network device may be acquired.
[0051] Also, in each embodiment, the virtual network configured by the network configuration units 103 and 114 may further include means for assigning communication functions necessary for the communication service.
Explanation of Reference Numerals
[0052] 10, 11 Information system 100, 110 Network configuration device 101, 111 Device information acquisition unit 102, 113 Authenticity determination unit 103, 114 Network configuration unit 112 Risk score calculation unit 200 Service Slice Management Device 300 Device Information Storage Device
Claims
1. Device information acquisition means for acquiring device information that visualizes the configuration and risks related to network devices connected to a physical network; Authenticity determination means for determining the authenticity of the network device based on the acquired device information; Network configuration means for configuring a virtual network on the physical network based on the determination result of the authenticity of the network device, comprising: The device information includes different types of information such as configuration information, event information, and inspection information of the network device, a network configuration device.
2. The network configuration means configures the virtual network using only network devices determined to be authentic by the authenticity determination means, the network configuration device according to claim 1.
3. The authenticity determination means acquires each piece of authenticity individual information determined by each piece of device information of different types, and determines the authenticity of the network device based on the acquired authenticity individual information, the network configuration device according to claim 1.
4. Further comprising risk score calculation means for calculating a risk score that is the degree of authenticity; The authenticity determination means determines the authenticity of the network device based on the calculated risk score, the network configuration device according to any one of claims 1 to 3.
5. The device information acquisition means acquires the device information when the device information of the network device constituting the virtual network is updated; The authenticity determination means determines the authenticity of the network device based on the acquired updated device information; The network configuration means configures the virtual network based on the determination result of the authenticity of the network device after the update, the network configuration device according to any one of claims 1 to 4.
6. Further comprising communication function assignment means for assigning the communication function of the network device constituting the virtual network to the virtual network, the network configuration device according to any one of claims 1 to 5.
7. A network configuration device; A service slice management device for managing and controlling the network configuration device; Including a device information storage device for storing device information that visualizes the configuration and risks related to network devices connected to a physical network. The network configuration device includes: device information acquisition means for acquiring the device information from the device information storage device; genuineness determination means for determining the genuineness of the network device based on the acquired device information; network configuration means for configuring a virtual network on the physical network based on the determination result of the genuineness of the network device, and includes an information system in which the device information includes information of different types of configuration information, event information, and inspection information of the network device.
8. A network configuration method, wherein a computer: acquires device information visualizing the configuration and risks of a network device connected to a physical network; determines the genuineness of the network device based on the acquired device information; configures a virtual network on the physical network based on the determination result of the genuineness of the network device, and the device information includes information of different types of configuration information, event information, and inspection information of the network device.
9. A program for causing a computer to execute: acquiring device information visualizing the configuration and risks of a network device connected to a physical network; determining the genuineness of the network device based on the acquired device information; configuring a virtual network on the physical network based on the determination result of the genuineness of the network device, and the device information includes information of different types of configuration information, event information, and inspection information of the network device.
Citation Information
Patent Citations
Functional part allocation device and functional part allocation method
JP2016208068A
Control device
JP2019041288A
Network service management device, network service management method, and network service management program
JP2020036105A