Network configuration device, information system, network configuration method, and program
The network configuration device addresses the issue of high-cost networks by determining device authenticity and configuring virtual networks to balance reliability and cost, optimizing network setup based on authenticity requirements.
Patent Information
- Application Number
- JP2023559336
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-11-12
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-11-12
AI Technical Summary
Existing network configuration technologies do not consider the cost of communication services, leading to high-reliability and high-performance networks that may not be necessary for all applications, resulting in unnecessary costs.
A network configuration device that acquires authenticity requirement information, device information, determines the authenticity of network devices, and configures virtual networks based on these factors to balance reliability and cost.
Enables cost-effective configuration of virtual networks by selectively using authentic devices, reducing unnecessary expenditure on high-reliability components where not required.
Smart Images

Figure 0007704210000001 
Figure 0007704210000002 
Figure 0007704210000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a network configuration device, an information system, a network configuration method, and a recording medium.
Background Art
[0002] Communication services that meet various demands from users, such as the use of high-speed lines and high-quality lines with uninterrupted data communication, are being operated on the network. For this reason, there is a technology called network slicing in which slices are selected for each service and operated on a plurality of virtual networks in the network.
[0003] For example, Patent Document 1 discloses a network service management device that determines resources for allocating functions that meet the requirements of a virtual network constituting a network service.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] High-reliability and high-performance networks have high construction and operation costs, but depending on the application of communication, they may not necessarily need to be highly reliable or high-performance. The invention described in Patent Document 1 does not configure a network service considering the cost of communication services.
[0006] An example of the object of the present disclosure is to provide a network configuration device capable of configuring a network while considering the cost of communication services.
Means for Solving the Problems
[0007] The network configuration device according to one aspect of the present disclosure includes: an authenticity requirement information acquisition means for acquiring authenticity requirement information regarding the necessity of authenticity for communication services; a device information acquisition means for acquiring device information from a device information storage device; an authenticity determination means for determining the authenticity of network devices based on the acquired device information; and a network configuration means for configuring a virtual network on a physical network based on the authenticity requirement information and the determination result of the authenticity of network devices.
[0008] An information system according to one aspect of the present disclosure includes: a network configuration device; a service slice management device for managing and controlling the network configuration device; and a device information storage device for storing device information that visualizes the configuration and risks of network devices connected to a physical network. The network configuration device includes: an authenticity requirement information acquisition means for acquiring authenticity requirement information regarding the necessity of authenticity for communication services; a device information acquisition means for acquiring device information from the device information storage device; an authenticity determination means for determining the authenticity of network devices based on the acquired device information; and a network configuration means for configuring a virtual network on a physical network based on the authenticity requirement information and the determination result of the authenticity of network devices.
[0009] A network configuration method according to one aspect of the present disclosure includes: acquiring authenticity requirement information regarding the necessity of authenticity for communication services; acquiring device information that visualizes the configuration and risks of network devices connected to a network; determining the authenticity of network devices based on the acquired device information; and configuring a virtual network on a physical network based on the authenticity requirement information and the determination result of the authenticity of network devices.
[0010] A recording medium in one aspect of the present disclosure acquires authenticity requirement information regarding the necessity of authenticity for a communication service, acquires device information that visualizes the configuration and risks of a network device connected to a network, determines the authenticity of the network device based on the acquired device information, and configures a virtual network on a physical network based on the authenticity requirement information and the determination result of the authenticity of the network device, and stores a program for causing a computer to execute the above.
Advantages of the Invention
[0011] An example of the effect according to the present disclosure can provide a network configuration device capable of configuring a virtual network while considering the cost of a communication service.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Modes for Carrying Out the Invention
[0013] Next, the embodiments will be described in detail with reference to the drawings.
[0014] [First Embodiment] The network configuration device 100 in the first embodiment is a device for performing network slicing that constitutes a plurality of virtual networks (slices) consisting of one physical network and assigns functions required for communication services. A virtual network refers to a network in which physical resources are abstracted by software and can be logically grouped or divided for use.
[0015] Network slicing is a technology for constructing, in an end-to-end manner across domains, a plurality of independent slices in software according to the requirements of communication services while commonly using network devices such as general-purpose servers and transport devices. Also, by using network slicing and arranging resources such as data processing functions and storage in each slice, communication services with different requirements can be separately constructed in each slice. The network configuration device 100 is realized, for example, by a plurality of resource controllers that respectively manage and control various devices for each domain (for example, radio access, transport, and data center).
[0016] Further, the information system 10 in the present embodiment includes a network configuration device 100, a service slice management device 200 that manages and controls the network configuration device 100, and a device information storage device 300 that stores device information of network devices connected to the network slice.
[0017] FIG. 1 is a block diagram showing the configuration of the network configuration device 100 in the first embodiment. Referring to FIG. 1, the network configuration device 100 includes an authenticity requirement information acquisition unit 101, a device information acquisition unit 102, an authenticity determination unit 103, and a network configuration unit 104. Hereinafter, the network configuration device 100, which is an essential configuration of the present embodiment, will be described in detail.
[0018] FIG. 2 is a diagram showing an example of a hardware configuration in which the network configuration device 100 according to the first embodiment of the present disclosure is realized by a computer device 500 including a processor. As shown in FIG. 2, the network configuration device 100 includes a CPU (Central Processing Unit) 501, a ROM (Read Only Memory) 502, a memory such as a RAM (Random Access Memory) 503, a storage device 505 such as a hard disk for storing a program 504, a communication I / F (Interface) 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the first embodiment, the authenticity requirement information acquired by the authenticity requirement information acquisition unit 101 is input to the network configuration device 100 via the input / output interface 511, for example. Further, the device information acquired by the device information acquisition unit 102 is input to the network configuration device 100 via the communication I / F.
[0019] The CPU 501 operates an operating system to control the entire network configuration device 100 according to the first embodiment of the present invention. Further, the CPU 501 reads a program and data from the memory from a recording medium 506 mounted on, for example, a drive device 507. Further, the CPU 501 functions as the authenticity requirement information acquisition unit 101, the device information acquisition unit 102, the authenticity determination unit 103, the network configuration unit 104 in the first embodiment, and a part thereof, and executes the processing or instructions in the flowchart shown in FIG. 3 described later based on the program.
[0020] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium of the storage device is a non-volatile storage device, and a program is recorded therein. Further, the program may be downloaded from an external computer (not shown) connected to the communication network.
[0021] The input device 509 is realized by, for example, a mouse, a keyboard, built-in keyboard buttons, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or built-in keyboard buttons, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display and is used to check the output.
[0022] As described above, the first embodiment shown in FIG. 1 is realized by the computer hardware shown in FIG. 2. However, the realization means of each part included in the network configuration device 100 in FIG. 1 is not limited to the configuration described above. Also, the network configuration device 100 may be realized by a single physically coupled device, or may be realized by two or more physically separated devices connected by wire or wirelessly. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network. Also, the network configuration device 100 in the first embodiment shown in FIG. 1 can also be configured by cloud computing or the like.
[0023] In FIG. 1, the authenticity requirement information acquisition unit 101 is a means for acquiring authenticity requirement information regarding the necessity of authenticity for a communication service. The authenticity requirement information is information regarding whether authenticity is required for the target communication service. In the present embodiment, that authenticity is required means that authenticity is required for all network devices to be used. Regarding fields that require reliability for communication services, the authenticity of the network devices to be used is required. The reliability of a communication service is particularly required in fields that handle highly confidential information. Fields that handle highly confidential information are, for example, fields such as space, defense, medical, or finance. Also, examples of highly confidential information include know-how such as design information and the quality of resin properties in a factory. On the other hand, examples of low-confidentiality information generally include game images and videos taken for video surveillance. The authenticity requirement information acquisition unit 101 acquires authenticity requirement information, for example, by receiving an input regarding the necessity of authenticity from the input device 509.
[0024] The device information acquisition unit 102 is a means for acquiring device information that visualizes the configuration and risks related to network devices connected to the network. The device information acquisition unit 102 acquires the device information of each network device on the network that is connected to a plurality of resource controllers. The number of network devices on the network may be single or plural. In the present embodiment, the device information is information necessary for determining the authenticity of network devices, and includes information of different types such as configuration information, event information, and inspection information. The event information and the inspection information are information that visualizes the risks of network devices. The device information acquisition unit 102 acquires the device information of the network devices to be monitored from the device information storage device 300. Here, each device information stored in the device information storage device 300 will be described. In the device information storage device 300, for example, the configuration information, event information, and inspection information are stored together with the time when the information was acquired for each network device.
[0025] The configuration information is, for example, the hardware information and software information of network devices. The hardware information is the manufacturer information, the model numbers of chips, substrates, ports, etc. that make up the hardware, and the identifiers given to the hardware. The software information is the manufacturer information, the name of software such as an OS (Operating System), library, or application that processes the hardware, the version information of the software, or the hash value, etc. The hash value is a value calculated from data composed of the binary of software, etc., and by comparing it with the hash value distributed from the software manufacturer, the identity with the software distributed from the manufacturer can be confirmed. The configuration information is updated at the timing when the configuration information such as the timing of software version upgrade is updated.
[0026] Event information is, for example, log information generated within a network device. As log information, for example, packet communication information such as the communication data volume, communication error rate, or number of packet retransmissions of each network port connected to the network device is stored. Event information is updated at intervals of, for example, several seconds.
[0027] Inspection information is information regarding the results of inspection and analysis based on the configuration information and event information of the device to be monitored. The inspection results are stored with the result of the authenticity of the device linked to time information. Inspection information is updated, for example, at the timing when the configuration changes such as a software version upgrade of the network device or at the timing when the event information changes significantly.
[0028] The authenticity determination unit 103 is a means for determining the authenticity of the network device based on the device information acquired by the device information acquisition unit 102. In the present embodiment, authenticity means that the settings of the hardware information and software information of the network device have not been erased, tampered with, or replaced. The authenticity determination unit 103 first determines the authenticity of the network device using a known method for each of the configuration information, event information, and inspection information, and outputs authenticity individual information as the result of the authenticity determination.
[0029] Regarding the configuration information, the authenticity determination unit 103 determines whether there is authenticity based on, for example, the difference between the configuration information at the time of system delivery and the configuration information stored in the device information storage device 300. Also, regarding the event information, the authenticity determination unit 103 determines whether the device has authenticity based on, for example, the obtained event information. The device information acquisition unit 102 determines whether there is authenticity regarding the inspection information based on, for example, the analysis results of the inspection and the presence or absence of the inspection.
[0030] Next, the authenticity determination unit 103 comprehensively determines the authenticity of the network device based on the authenticity individual information, which is the determination result of the authenticity of the configuration information, event information, and inspection information. The authenticity determination unit 103 outputs authenticity information as the determination result of authenticity. The authenticity information is information indicating whether the authenticity is guaranteed, and may be represented by a binary value indicating the presence or absence of authenticity. Alternatively, the authenticity information may be represented by a numerical value (score) such as 0 to 100%.
[0031] For example, when the authenticity information is represented by the presence or absence of authenticity, the authenticity determination unit 103 determines that the network device has authenticity if any of the configuration information, event information, and inspection information of the network device has authenticity. The authenticity determination unit 103 determines that the network device has no authenticity if none of the device information of the network device has authenticity. When the device information of the network device includes information with authenticity and information without authenticity, the authenticity determination unit 103 determines authenticity according to the number and type of information determined to have authenticity. For example, if the authenticity determination unit 103 determines that the configuration information has no authenticity but determines that the event information and inspection information have authenticity, it determines that there is authenticity. However, the method for determining authenticity by the authenticity determination unit 103 is not limited to this.
[0032] The network configuration unit 104 is a means for configuring a virtual network based on the authenticity necessity information acquired by the authenticity necessity information acquisition unit 101 and the determination result of the authenticity of the device determined by the authenticity determination unit 103. When the network configuration unit 104 acquires from the authenticity necessity information acquisition unit 101 information indicating that the authenticity of the communication service is necessary, the network configuration unit 104 configures a virtual network to include only network devices determined to be authentic by the authenticity determination unit 103. On the other hand, when the network configuration unit 104 acquires from the authenticity necessity information acquisition unit 101 information indicating that the authenticity of the communication service is not necessary, the network configuration unit 104 configures a virtual network to include network devices determined to be inauthentic by the authenticity determination unit 103. When the network configuration unit 104 acquires from the authenticity necessity information acquisition unit 101 information indicating that the authenticity of the communication service is not necessary, the network configuration unit 104 may configure a virtual network using only network devices determined to be inauthentic by the authenticity determination unit 103. Further, the network configuration unit 104 transmits information on network devices constituting the virtual network to the service slice management device 200.
[0033] The operation of the network configuration device 100 configured as described above will be described with reference to the flowchart of FIG. 3.
[0034] FIG. 3 is a flowchart showing an outline of the operation of the network configuration device 100 in the first embodiment. The processing according to this flowchart may be executed based on program control by the above-described processor.
[0035] As shown in FIG. 3, first, the authenticity requirement information acquisition unit 101 acquires authenticity requirement information regarding the necessity of authenticity for a communication service (step S101). Next, the device information acquisition unit 102 acquires device information of a network device connected to the network (step S102). Next, the authenticity determination unit 103 determines the authenticity of the network device based on the device information acquired by the device information acquisition unit 102 (step S103). Finally, the network configuration unit 104 configures a virtual network based on the authenticity requirement information acquired by the authenticity requirement information acquisition unit 101 and the determination result of authenticity determined by the authenticity determination unit 103 (step S104). Thus, the network configuration device 100 ends the operation of network configuration.
[0036] In the network configuration device 100 according to the present embodiment, the network configuration unit 104 configures a virtual network based on the authenticity requirement information acquired by the authenticity requirement information acquisition unit 101 and the determination result of authenticity determined by the authenticity determination unit 103. Thereby, for example, when providing a communication service that does not require high reliability, the network configuration device 100 can configure a virtual network without using a costly device with guaranteed authenticity. Thereby, a balance between the reliability and cost of the communication service can be achieved, and the network can be configured while considering the cost of the communication service.
[0037] [Modification Example of the First Embodiment] Next, a modification example of the first embodiment of the present disclosure will be described in detail with reference to the drawings. Hereinafter, the description of the same content as the above description will be omitted as long as the description of the present embodiment is not made unclear.
[0038] FIG. 4 is a block diagram showing the configuration of a network configuration device 110 according to a modified example of the first embodiment of the present disclosure. Referring to FIG. 4, the network configuration device 110 according to the modified example of the first embodiment will be described centering on the parts different from the network configuration device 100 according to the first embodiment. The network configuration device 110 includes an authenticity necessity information acquisition unit 111, a device information acquisition unit 112, a risk score calculation unit 113, an authenticity determination unit 114, and a network configuration unit 115. That is, this embodiment is different from the first embodiment in that it includes a risk score calculation unit 113. Since the operations of the authenticity necessity information acquisition unit 111 and the device information acquisition unit 112 are the same as those of the authenticity necessity information acquisition unit 101 and the device information acquisition unit 102, the description thereof will be omitted here.
[0039] The risk score calculation unit 113 is a means for calculating a risk score, which is a degree of authenticity, based on device information. The risk score calculation unit 113 calculates a risk score based on each of the device configuration information, event information, and inspection information. First, the risk score calculation unit 113 scores the authenticity of each information by a known method based on the device information acquired by the device information acquisition unit 102. Specifically, in the case of configuration information, if it is close to the configuration information at the time of delivery, the risk score calculation unit 113 increases the score, and as the different parts increase, the score decreases. Note that the risk score calculation unit 113 may score the software configuration information by comparing it with the configuration information at the time of update instead of the configuration information at the time of delivery. That is, if it is close to the software configuration information at the time of update, the risk score calculation unit 113 increases the score, and as the different parts increase, the score decreases. For event information, if it is close to the normal value, the risk score calculation unit 113 increases the score, and as the different parts become larger, the score decreases. For inspection information, the risk score calculation unit 113 scores according to the inspection result.
[0040] The risk score calculation unit 113 scores the risk score based on various types of information including configuration information, event information, and inspection information by the method described above. Next, the risk score of the entire network device is calculated by summing up the numerical values of various genuine information items associated with the target network device using methods such as logical OR, arithmetic mean, or total. However, the calculation method by the risk score calculation unit 113 is not limited to this. Also, the risk score may be calculated using an AI (artificial intelligence) model generated based on the correlation between various genuine information and the actual genuineness result. The risk score calculation unit 113 outputs the risk score of the device calculated in this way to the genuineness determination unit 114.
[0041] The genuineness determination unit 114 determines the genuineness of the network device based on the risk score calculated by the risk score calculation unit 113. When the calculated risk score is greater than a predetermined threshold, the genuineness determination unit 114 determines that there is genuineness. On the other hand, when the calculated risk score is not greater than the predetermined threshold, the genuineness determination unit 114 determines that there is no genuineness. The information on the threshold is stored, for example, in the storage device 505. The genuineness determination unit 114 outputs the determination result of genuineness to the network configuration unit 115.
[0042] The network configuration unit 115 configures a virtual network based on the genuineness requirement information acquired by the genuineness requirement information acquisition unit 111 and the determination result of the genuineness of the device determined by the genuineness determination unit 114. The method of configuring a specific virtual network by the network configuration unit 115 is the same as that in the first embodiment.
[0043] In a modification of the first embodiment of the present disclosure, the genuineness determination unit 114 determines the genuineness of the network device based on the risk score calculated by the risk score calculation unit 113. Thereby, the conditions for the genuineness of the network device can be set in detail.
[0044] Also, in the present embodiment and the modified examples of the present embodiment, the authenticity requirement information acquisition unit 101 has acquired information on whether authenticity is required for the target communication service as authenticity requirement information regarding the necessity of authenticity for the communication service. However, the authenticity requirement information acquisition unit 101 may acquire information on the degree to which authenticity is required. In this case, the network configuration unit 104 configures a virtual network so as to include network devices determined to be authentic or network devices determined to be inauthentic by the authenticity determination unit 103 according to the degree of necessity of authenticity acquired by the authenticity requirement information acquisition unit 101.
[0045] Also, in the present embodiment, the authenticity determination unit 103 first determines the authenticity of network devices for each of the configuration information, event information, and inspection information by a known method, and comprehensively determines the authenticity of network devices based on the individual authenticity information that is the determination result of each authenticity. However, the authenticity determination unit 103 may acquire the individual authenticity information determined by network devices based on various device information, and determine the authenticity of network devices based on the acquired individual authenticity information. Also, in a modified example of the present embodiment, the risk score calculation unit 113 scored the authenticity of various device information based on device information, but the network devices may acquire information (individual authenticity information) in which the authenticity of various device information is scored.
[0046] [Second Embodiment] Next, a modified example of the first embodiment of the present disclosure will be described in detail with reference to the drawings. Hereinafter, the description of the content overlapping with the above description will be omitted as long as the description of the present embodiment is not made unclear. Each component in each embodiment of the present disclosure can be realized by a computer device, software based on program control as well as hardware realizing its function in the same manner as the computer device shown in FIG. 2.
[0047] FIG. 5 is a block diagram showing the configuration of the network configuration device 120 according to the second embodiment of the present disclosure. Referring to FIG. 5, the network configuration device 120 according to the second embodiment will be described centering on the parts different from the network configuration device 100 according to the first embodiment. In the second embodiment, when information indicating that authenticity is not required is obtained in the authenticity requirement information acquisition unit 121, a scenario of configuring a virtual network is assumed based on the cost conditions of the communication service. The network configuration device 120 in the second embodiment includes an authenticity requirement information acquisition unit 121, a cost condition acquisition unit 122, a device information acquisition unit 123, an authenticity determination unit 124, a cost information acquisition unit 125, and a network configuration unit 126. That is, the second embodiment is different from the first embodiment in that it includes a cost condition acquisition unit 122 and a cost information acquisition unit 125.
[0048] In this embodiment, it is also different in that the device information storage device 320 stores cost information required for using the network device in addition to the device information of the network device. In the device information storage device 320, as cost information, for example, the costs of using each network device when authenticity is guaranteed and when authenticity is not guaranteed are stored. The authenticity requirement information acquisition unit 121 is the same as the authenticity requirement information acquisition unit 101 in the first embodiment, and thus the description thereof will be omitted.
[0049] The cost condition acquisition unit 122 is means for acquiring the cost conditions of the communication service when information indicating that the authenticity of the communication service is not required is acquired from the authenticity requirement information acquisition unit 121. The cost condition acquisition unit 122 acquires the authenticity requirement information, for example, by receiving the input of information regarding the cost conditions from the input device 509. The cost condition is, for example, the upper limit of the cost borne by the user for the network device of the communication service. The cost condition acquisition unit 122 outputs information regarding the cost conditions to the network configuration unit 126.
[0050] The device information acquisition unit 123 acquires device information that visualizes the configuration and risks of network devices connected to the network. The method for acquiring device information by the device information acquisition unit 123 is the same as the operation performed by the device information acquisition unit 102 in the first embodiment.
[0051] The authenticity determination unit 124 determines the authenticity of the network device based on the device information acquired by the device information acquisition unit 123. The method for determining authenticity by the authenticity determination unit 124 is the same as the operation performed by the authenticity determination unit 103 in the first embodiment.
[0052] The cost information acquisition unit 125 is a means for acquiring cost information required for using the network device corresponding to the authenticity determination result determined by the authenticity determination unit 124. When the authenticity determination unit 124 determines that the authenticity exists, the cost information acquisition unit 125 acquires the cost information of each network device when the authenticity is guaranteed from the device information storage device 320. On the other hand, when the authenticity determination unit 124 determines that there is no authenticity, the cost information acquisition unit 125 acquires the cost information of each network device when the authenticity is not guaranteed from the device information storage device 320. The cost information acquisition unit 125 outputs the acquired cost information of each network device to the network configuration unit 126.
[0053] The network configuration unit 126 configures a virtual network based on the cost information acquired by the cost information acquisition unit 125 so as to satisfy the cost condition acquired by the cost condition acquisition unit 122.
[0054] Here, a specific example will be given to explain how the virtual network is configured by the network configuration unit 126. For example, assume that the cost condition obtained by the cost condition acquisition unit 122 is 300. Also, assume that there are five network devices connected to the network, and the cost information obtained by the cost information acquisition unit 125 is such that the cost of a device with guaranteed authenticity is 100, and the cost of a device without guaranteed authenticity is 50. For the sake of explanation, the cost information for each network device is set to the same amount, but in reality, it can be different. The network configuration unit 126 selects network devices so that the total cost of the five network devices does not exceed the cost condition of 300. In this case, when one device with guaranteed authenticity (100) and four devices without guaranteed authenticity (50×4) are selected, the cost condition of 300 is not exceeded. Therefore, the network configuration unit 126 configures the virtual network to include one device with guaranteed authenticity and four devices without guaranteed authenticity.
[0055] The operation of the network configuration device 110 configured as described above will be described with reference to the flowchart of FIG. 6.
[0056] FIG. 6 is a flowchart showing an overview of the operation of the network configuration device 110 in the second embodiment. The processing according to this flowchart may be executed based on program control by the processor described above.
[0057] As shown in FIG. 6, first, when the authenticity requirement information acquisition unit 121 acquires authenticity requirement information indicating that authenticity is not required (step S201), the cost condition acquisition unit 122 acquires information regarding the cost condition of the communication service (step S202). Next, the device information acquisition unit 123 acquires device information of the network device connected to the network (step S203). Next, the authenticity determination unit 124 determines the authenticity of the network device based on the device information acquired by the device information acquisition unit 123 (step S204). Next, the cost information acquisition unit 125 acquires cost information required for using the network device corresponding to the authenticity determination result determined by the authenticity determination unit 124 (step S205). Finally, the network configuration unit 126 configures a virtual network based on the cost information acquired by the cost information acquisition unit 125 so as to satisfy the cost condition acquired by the cost condition acquisition unit 122 (step S206). When configuring the virtual network, the network configuration device 120 repeats a series of flows when the authenticity requirement information acquisition unit 121 acquires authenticity requirement information indicating that authenticity is not required. Thus, the network configuration device 120 ends the operation of network configuration.
[0058] In the present embodiment, a virtual network is configured based on the cost information acquired by the cost information acquisition unit 125 so as to satisfy the cost condition acquired by the cost condition acquisition unit 122. Thereby, the network configuration device 120 can configure a virtual network using, for example, a device with guaranteed authenticity within the range that satisfies the cost condition. Therefore, it is possible to configure a virtual network while considering the cost of the communication service.
[0059] As described above, the present invention has been described with reference to each embodiment, but the present invention is not limited to the above embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0060] For example, a plurality of operations are described in order in the form of a flowchart, but the order of the description does not limit the order of executing the plurality of operations. Therefore, when implementing each embodiment, the order of the plurality of operations can be changed as long as there is no problem in terms of content. Also, in the present embodiment, the network configuration unit 126 configured a virtual network based on the cost information acquired by the cost information acquisition unit 125 so as to satisfy the cost condition acquired by the cost condition acquisition unit 122. However, in addition to the cost condition, the network configuration unit 126 may configure a virtual network using network devices so as to satisfy performance conditions such as the communication speed of the communication service and power saving. In this case, information regarding the performance of the network devices is stored, for example, in the device information storage device 320. The network configuration device 120 acquires information regarding the performance conditions of the network devices from the device information storage device 310. Furthermore, in each embodiment, the virtual network configured by the network configuration unit may further include means for allocating communication functions necessary for the communication service.
[0061] Also, in the present embodiment, a scenario is assumed in which a virtual network is configured based on the cost condition of the communication service when information indicating that authenticity is not required is acquired by the authenticity necessity information acquisition unit 121. However, in the present embodiment as well, the authenticity necessity information acquisition unit 121 may acquire information regarding the degree of necessity of authenticity. In this case, the cost condition acquisition unit 122 acquires the cost condition of the communication service regardless of the information acquired by the authenticity necessity information acquisition unit 121. Also, the network configuration unit 126 configures a virtual network based on the cost information acquired by the cost information acquisition unit 125 so as to satisfy the cost condition acquired by the cost condition acquisition unit 122.
Explanation of Reference Numerals
[0062] 10, 11, 12 Information System 100, 110, 120 Network Configuration Device 101, 111, 121 Authenticity Necessity Information Acquisition Unit 102, 112, 123 Machine Information Acquisition Unit 103, 114, 124 Authenticity Determination Unit 104, 115, 126 Network Configuration Unit 113 Risk Score Calculation Unit 122 Cost Condition Acquisition Unit 125 Cost Information Acquisition Unit 200, 210, 220 Service Slice Management Device 300, 310, 320 Machine Information Storage Device
Claims
1. An authenticity requirement information acquisition means for acquiring authenticity requirement information regarding the necessity of authenticity for a communication service, A device information acquisition means for acquiring device information that visualizes the configuration and risks of network devices connected to a physical network, An authenticity determination means for determining the authenticity of the network device based on the acquired device information, A network configuration means for configuring a virtual network on the physical network based on the authenticity requirement information and the determination result of the authenticity of the network device, comprising: The device information includes information of different types such as configuration information, event information, and inspection information of the network device, The authenticity determination means determines the authenticity of the network device based on the results of determining the authenticity of each of the configuration information, event information, and inspection information included in the device information. A network configuration device.
2. Further comprising a risk score calculation means for calculating a risk score that is the degree of authenticity, The authenticity determination means determines the authenticity of the network device based on the calculated risk score. The network configuration device according to claim 1.
3. When the network configuration means acquires information that authenticity is required for the communication service from the authenticity requirement information acquisition means, the virtual network is configured to include only the network devices determined to be authentic by the authenticity determination means. The network configuration device according to claim 1 or claim 2.
4. When the network configuration means acquires information that authenticity is not required for the communication service from the authenticity requirement information acquisition means, the virtual network is configured to include the network devices determined to be inauthentic by the authenticity determination means. The network configuration device according to claim 1 or claim 2.
5. When information that authenticity of the communication service is not required is acquired from the authenticity requirement information acquisition means, a cost condition acquisition means for acquiring cost conditions of the communication service, A cost information acquisition means for acquiring cost information required for using the network device corresponding to the determined determination result of authenticity, Further comprising The network configuration means configures the virtual network based on the cost information so as to satisfy the cost condition, and the network configuration apparatus according to claim 1 or claim 2.
6. The network configuration apparatus according to any one of claims 1 to 5, further comprising communication function assignment means for assigning the communication function of the network device constituting the virtual network to the virtual network.
7. A network configuration apparatus, A service slice management apparatus for managing and controlling the network configuration apparatus, An equipment information storage device that stores equipment information visualizing the configuration and risks of network equipment connected to a physical network, and includes: The network configuration apparatus, Authenticity requirement information acquisition means for acquiring authenticity requirement information regarding the necessity of authenticity for a communication service, Equipment information acquisition means for acquiring the equipment information from the equipment information storage device, Authenticity determination means for determining the authenticity of the network equipment based on the acquired equipment information, Network configuration means for configuring a virtual network on the physical network based on the authenticity requirement information and the determination result of the authenticity of the network equipment, and comprises: The equipment information includes information of different types of configuration information, event information, and inspection information of the network equipment, The authenticity determination means determines the authenticity of the network equipment based on the results of determining the authenticity of each of the configuration information, event information, and inspection information included in the equipment information, information system.
8. A computer, Acquires authenticity requirement information regarding the necessity of authenticity for a communication service, Acquires equipment information visualizing the configuration and risks of network equipment connected to a physical network, Based on the acquired equipment information, determines the authenticity of the network equipment, A network configuration method for configuring a virtual network on the physical network based on the authenticity requirement information and the determination result of the authenticity of the network equipment, and comprises: The equipment information includes information of different types of configuration information, event information, and inspection information of the network equipment, In the determination of authenticity, the authenticity of the network equipment is determined based on the results of determining the authenticity of each of the configuration information, event information, and inspection information included in the equipment information, network configuration method.
9. Obtaining authenticity requirement information regarding the necessity of authenticity for a communication service, Obtaining device information that visualizes the configuration and risks related to network devices connected to a physical network, Determining the authenticity of the network device based on the obtained device information, A program for causing a computer to configure a virtual network on the physical network based on the authenticity requirement information and the determination result of the authenticity of the network device, The device information includes different types of information such as configuration information, event information, and inspection information of the network device, In the determination of authenticity, a program for determining the authenticity of the network device based on the results of determining the authenticity of each of the configuration information, event information, and inspection information included in the device information.
Citation Information
Patent Citations
5G Network Slicing Topology Design and Reliable Mapping Method for Low-Level Node Failure
CN109067579B
Network slice reliability mapping algorithm based on service type
CN111526057A
Virtual network resource allocation method based on reliability and shunting strategy under network slice
CN112636961A
Network control apparatus
JP2017192096A
Network service management device, network service management method, and network service management program
JP2020036105A