Network Management Device, Network Management Method, and Program
The network management device addresses the challenge of high development costs by standardizing access control across different network types, reducing costs and periods for integrating multiple network operators.
Patent Information
- Application Number
- JP2024540157
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-08-10
- Publication Date
- 2025-07-17
- Estimated Expiration
- 2042-08-10
AI Technical Summary
Existing network management technologies require each network operator to develop access control means individually, leading to increased development costs and periods when accessing multiple network types.
A network management device that includes a first registration processing unit for self-operator information, a second unit for entity information, and a third unit for registering information from other operators, allowing standardized access control across different network types.
Reduces development costs and periods for other operators by enabling standardized access control, facilitating efficient integration of multiple network types into a network management system.
Smart Images

Figure 0007709666000001 
Figure 0007709666000002 
Figure 0007709666000003
Abstract
Description
Technical Field
[0001] One aspect of the present invention relates to a network management system, a network management device, a network management method, and a program used for managing a network.
Background Art
[0002] When managing information using a database, for example, depending on the type of information and the qualifications of the administrator, etc., there may be cases where the information cannot be disclosed unconditionally. Therefore, in the general data management field, for example, disclosure conditions are set in units of databases, files, or records, and when a user requests disclosure of information, it is determined whether the request content of the user satisfies the above disclosure conditions, and when the request content satisfies the disclosure conditions, the information corresponding to the above unit can be disclosed.
[0003] On the other hand, in the field of network management, when constructing or operating a network management system, for example, the characteristics of various networks or devices using them are defined using a plurality of attributes according to a predetermined model format, and specification information and entity information represented by the above plurality of attributes are generated and registered in a database within the system, and a technique for network management has been proposed (for example, refer to Patent Document 1).
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, the network management technology disclosed in Patent Document 1 can only be used within a network operator who constructs or operates a database in the network management system. Therefore, the network operator provides access control means for each type of network served by the network operator, and other operators, who are different from the network operator, have to develop access means corresponding to the individual access control means.
[0006] Furthermore, every time the above-mentioned other operators increase the number of network operators to be accessed, they have to develop access means corresponding to each of the multiple network types of the new network operator, which requires development costs and development periods.
[0007] This invention has been made paying attention to the above circumstances, and aims to provide a technology capable of reducing the development costs and development periods of other operators different from the operator who constructs or operates a database in a network management system.
Means for Solving the Problem
[0008] In order to solve the above problems, a network management device according to an aspect of the present invention includes a first registration processing unit, a second registration processing unit, and a third registration processing unit. The first registration processing unit receives an input of specification information that defines the characteristics of the network facilities of the self-operator to be managed using a plurality of attribute information, and stores the specification information in a specification information storage unit. The second registration processing unit receives an input of entity information that defines actual resources to be set for the network facilities corresponding to a plurality of attribute information, and stores the entity information in an entity information storage unit. The third registration processing unit receives a registration request for at least one of the specification information and the entity information from one or more other operators different from the self-operator, and makes it possible to store at least one of the received specification information and the entity information in at least one of the specification information storage unit and the entity information storage unit.
Effects of the Invention
[0009] That is, according to one aspect of the present invention, other operators only need to develop access means for the third registration means, and it is possible to provide a technology that can reduce the development cost and development period of other operators.
Brief Description of Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11A
Figure 11B
Figure 12
Figure 13
Figure 14
Figure 15
[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0012] [One Embodiment] (Configuration Example) (1) System FIG. 1 is a diagram showing an example of a configuration of a network management system according to an embodiment of the present invention.
[0013] A network management system according to an embodiment includes a network management device NM as its main component. The network management system enables the transmission of information data via a network NW between the network management device NM, an operator terminal OT used by a network administrator, a plurality of in-house user terminals OUT1 to OUTn (n is an arbitrary integer) used by other administrators or users belonging to the same business operator (the same company) as the operator terminal OT, and a plurality of other business operator terminals ACT1 to ACTm (m is an arbitrary integer) used by users belonging to a business operator (a different company) other than the operator terminal OT.
[0014] The network NW includes a plurality of types of networks such as an IP (Internet Protocol) network that constitutes the Internet, Ethernet (registered trademark) that constitutes a LAN (Local Area Network), and other transmission networks. Any network may be used for the network NW as long as it enables the transmission of the above information data.
[0015] (2) Device (2-1) Operator terminal OT FIG. 2 and FIG. 3 are block diagrams showing an example of the hardware configuration and software configuration of the operator terminal OT.
[0016] The operator terminal OT includes a control unit 1A, and a storage unit having a program storage unit 2A and a data storage unit 3A, a communication interface (hereinafter referred to as an interface as I / F) unit 4A, and an input / output I / F unit 5A are connected to the control unit 1A via a bus 6A.
[0017] The control unit 1A is a hardware processor such as a CPU (Central Processing Unit). For example, by using a multi-core and multi-thread CPU, a plurality of information processes can be executed simultaneously. The control unit 1A may include a plurality of hardware processors.
[0018] An input / output I / F unit 5A is connected to an input device 51 and an output device 52. The input device 51 includes, for example, a keyboard, a mouse, and operation buttons. The input device 51 is used for a network administrator to input specification information, entity information, and policy information related to a network to be managed or devices used in this network (hereinafter also collectively referred to as network facilities).
[0019] The specification information is represented as, for example, a plurality of attribute information defining the characteristics of network facilities, associated with the identification information of the network facilities. The entity information is represented as, for example, a plurality of attribute information defining the actual resources to be set for the network facilities, associated with the identification information of the network facilities. The policy information defines access conditions related to cooperation with other operators. For example, the access conditions can include disclosure conditions of the above specification information and entity information to other operator terminals ACT1 to ACTm, registration conditions of the above specification information and entity information from other operator terminals ACT1 to ACTm, and the like.
[0020] The output device 52 includes, for example, a display and displays display data necessary for the input processing of the above specification information, entity information, and policy information.
[0021] Under the control of the control unit 1A, the communication I / F unit 4A transmits information data to and from a network management device NM using a communication protocol defined by a network NW.
[0022] The program storage unit 2A is configured by combining, for example, a non-volatile memory such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive) that can be written and read at any time as a storage medium, and a non-volatile memory such as a ROM (Read Only Memory). In addition to middleware such as an OS (Operating System), the program storage unit 2A stores application programs necessary for inputting the above-mentioned various information required for network management in one embodiment and transmitting registration requests therefor. Hereinafter, the OS and each application program are collectively referred to as a program.
[0023] The data storage unit 3A is, for example, a combination of a non-volatile memory such as an HDD or an SSD that can be written and read at any time as a storage medium, and a volatile memory such as a RAM (Random Access Memory). The data storage unit 3A includes, in its storage area, a specification information storage unit 31A, an entity information storage unit 32A, and a policy information storage unit 33A as main storage units necessary for implementing one embodiment of the present invention.
[0024] The specification information storage unit 31A stores the input specification information until the transmission of the registration request is completed. The entity information storage unit 32A stores the input entity information until the transmission of the registration request is completed. The policy information storage unit 33A stores the input policy information until the transmission of the registration request is completed.
[0025] The control unit 1A includes, as processing functions necessary for implementing one embodiment, a specification registration request transmission processing unit 11A, an entity registration request transmission processing unit 12A, and a policy registration request transmission processing unit 13A. These processing units 11A to 13A are all realized by causing the hardware processor of the control unit 1A to execute the application programs stored in the program storage unit 2A.
[0026] In addition to pre-storing the above application program in the program storage unit 2A, it may be downloaded from the network management device NM or other application servers, etc. when needed and stored in the program storage unit 2A.
[0027] Also, for at least some of the processing functions of at least one of the processing units 11A to 13A, instead of being realized by the application program and the hardware processor of the control unit 1A, it may be realized by integrated circuits such as ASIC (Application Specific Integrated Circuit), DSP (Digital Signal Processor), FPGA (field-programmable gate array), GPU (Graphics Processing Unit), etc.
[0028] The specification registration request transmission processing unit 11A receives the specification information input by the input device 51 via the input / output I / F unit 5A, and transmits a specification registration request including the received specification information from the communication I / F unit 4A to the network management device NM.
[0029] The entity registration request transmission processing unit 12A receives the entity information input by the input device 51 via the input / output I / F unit 5A, and transmits an entity registration request including the received entity information from the communication I / F unit 4A to the network management device NM.
[0030] The policy registration request transmission processing unit 13A receives the policy information input by the input device 51 via the input / output I / F unit 5A, and transmits a policy registration request including the received policy information from the communication I / F unit 4A to the network management device NM.
[0031] An example of the above specification information, entity information, and policy information will be described in the operation example.
[0032] (2-2) Network Management Device NM Figures 4 and 5 are block diagrams showing an example of the hardware configuration and software configuration of the network management device NM.
[0033] The network management device NM consists of, for example, a server computer installed on the web or in the cloud. Note that the network management device NM may be an information processing device such as a personal computer used by an administrator.
[0034] The network management device NM includes a control unit 1B that uses a hardware processor such as a CPU. A storage unit having a program storage unit 2B and a data storage unit 3B, and a communication I / F unit 4B are connected to the control unit 1B via a bus 6B.
[0035] Under the control of the control unit 1B, the communication I / F unit 4B uses the communication protocol defined by the network NW to transmit and receive information data with the operator terminal OT, the in-house user terminals OUT1 to OUTn, and the other company terminals ACT1 to ACTm, respectively.
[0036] The program storage unit 2B is configured by combining, for example, a non-volatile memory such as an HDD or SSD that can be written to and read from at any time as a storage medium, and a non-volatile memory such as a ROM. In addition to the program storage unit 2B and middleware such as an OS, programs necessary for executing various control processes according to an embodiment of the present invention are stored.
[0037] The data storage unit 3B is a combination of, for example, a non-volatile memory such as an HDD or SSD that can be written to and read from at any time as a storage medium, and a volatile memory such as a RAM. In the storage area of the data storage unit 3B, as storage units necessary for implementing an embodiment, a specification information database (hereinafter abbreviated as database DB) 31B, an entity information DB 32B, and a policy information DB 33B are provided.
[0038] The specification information DB31B stores specification information that defines the characteristics of network facilities to be managed, which is sent from the operator terminal OT by a specification registration request. The entity information DB32B stores entity information that defines the actual resources of network facilities, which is sent from the operator terminal OT by an entity registration request. The policy information DB33B stores policy information that defines access conditions related to cooperation with other businesses, which is sent from the operator terminal OT by a policy registration request.
[0039] The control unit 1B includes a specification information registration processing unit 11B, an entity information registration processing unit 12B, a policy information registration processing unit 13B, and an access control processing unit 14B as processing functions according to an embodiment of the present invention. The access control processing unit 14B includes an other business operator cooperation processing unit 15B. These processing units 11B to 14B (and 15B) are all realized by causing the hardware processor of the control unit 1B to execute an application program stored in the program storage unit 2B. Note that at least one of the processing units 11B to 14B (and 15B), for at least some of the processing functions, may be realized by using an integrated circuit such as an ASIC, DSP, FPGA, GPU, etc., instead of being realized by an application program and the hardware processor of the control unit 1B.
[0040] The specification information registration processing unit 11B receives the specification registration request sent from the operator terminal OT via the communication I / F unit 4B, and registers the specification information included in the received specification registration request in the specification information DB31B.
[0041] The entity information registration processing unit 12B receives the entity registration request sent from the operator terminal OT via the communication I / F unit 4B, and determines whether the entity information represented by the received entity registration request meets the registration requirements based on the specification information of the corresponding network facilities registered in the specification information DB31B. If the registration requirements are met, the entity information is registered in the entity information DB32B.
[0042] The policy information registration processing unit 13B receives the policy registration request transmitted from the operator terminal OT via the communication I / F unit 4B, and registers the policy information included in the received policy registration request in the policy information DB 33B.
[0043] When a disclosure request for entity information set for a desired network facility, for example, is transmitted from the in-house user terminals OUT1 to OUTn, the access control processing unit 14B receives this disclosure request via the communication I / F unit 4B. Then, the access control processing unit 14B performs a process of transmitting the entity information specified by the received disclosure request from the communication I / F unit 4B to the in-house user terminals OUT1 to OUTn that are the request sources.
[0044] Also, when a disclosure request for entity information set for a desired network facility, for example, is transmitted from the other operator terminals ACT1 to ACTm, the access control processing unit 14B receives this disclosure request via the communication I / F unit 4B. For accesses from such other operator terminals ACT1 to ACTm, the access control processing unit 14B operates as the other operator cooperation processing unit 15B. That is, the other operator cooperation processing unit 15B determines whether or not the access conditions are satisfied based on the policy information set for the other operator terminals ACT1 to ACTm that are the request sources. The access conditions in this case are disclosure conditions. When the access conditions are satisfied, the other operator cooperation processing unit 15B performs a process of transmitting the entity information specified by the received disclosure request and the specification information corresponding to the entity information from the communication I / F unit 4B to the other operator terminals ACT1 to ACTm that are the request sources.
[0045] In addition, when a registration request for specification information and entity information set for a desired network facility is transmitted from other operator terminals ACT1 to ACTm, the access control processing unit 14B receives this registration request via the communication I / F unit 4B. For such a registration request from other operator terminals ACT1 to ACTm, the other operator cooperation processing unit 15B of the access control processing unit 14B determines whether or not the access conditions are satisfied based on the policy information set for the source other operator terminals ACT1 to ACTm. The access conditions in this case are registration conditions. When the other operator cooperation processing unit 15B satisfies the registration conditions, it performs a process of registering the specification information and entity information included in the received registration request in the specification information DB 31B and the entity information DB 32B.
[0046] (Operation example) Next, an operation example of the apparatus configured as described above will be described.
[0047] (1) Registration of management information related to network facilities to be managed FIG. 6 is a flowchart showing an example of the processing procedure and processing content of the input reception of management information and the transmission process of its registration request executed by the control unit 1A of the operator terminal OT. FIG. 7 is a flowchart showing an example of the processing procedure and processing content of the registration process of management information executed by the control unit 1B of the network management device NM.
[0048] The network administrator operating the operator terminal OT selects a management information registration process mode from the input device 51. When the control unit 1A receives the selection information of this management information registration process mode from the input device 51 via the input / output I / F unit 5A in the standby state, it starts the operation of the flowchart shown in FIG. 6. When starting the operation, the control unit 1A determines, in steps S10, S20, and S30, which of the specification registration process mode, entity registration process mode, and policy registration process mode the received selection information of the management information registration process mode is.
[0049] When the control unit 1B of the network management device NM receives a registration request from the operator terminal OT via the communication I / F unit 4B in the standby state, it starts the operation of the flowchart shown in FIG. 7. When starting the operation, the control unit 1B determines in steps S40, S50, and S60 which of the specification registration request, entity registration request, and policy registration request the received registration request is.
[0050] (1-1) Registration of specification information (1-1-1) Processing by the operator terminal OT When the network administrator who operates the operator terminal OT selects the specification registration processing mode as the registration processing mode of management information from the input device 51, the network administrator further inputs specification information regarding the network equipment to be managed by the input device 51. Then, the control unit 1A of the operator terminal OT, which determines that it is in the specification registration processing mode in step S10 above, receives the input specification information via the input / output I / F unit 5A in step S11 under the control of the specification registration request transmission processing unit 11A and temporarily stores it in the specification information storage unit 31A. When the network administrator inputs a transmission instruction after the input of the above specification information is completed, the specification registration request transmission processing unit 11A detects the input of the above transmission instruction in step S12, and in step S13, transmits a specification registration request including the above specification information stored in the specification information storage unit 31A from the communication I / F unit 4A to the network management device NM. If the network administrator has not yet completed the input and transmission of the desired specification information, the network administrator continues to input the specification information, and when all the input and transmission are completed, issues an end instruction for the specification registration processing mode. Therefore, the control unit 1A repeats the operations of steps S11 to S13 until it detects the input of the above end instruction after transmitting the specification registration request in step S13.
[0051] (1-1-2) Processing by the network management device NM When the control unit 1B of the network management device NM determines that a specification registration request has been received in step S40 above, under the control of the specification information registration processing unit 11B, the specification information included in the above specification registration request received via the communication I / F unit 4B is registered in the specification information DB 31B in step S41.
[0052] FIG. 8 shows an example of the specification information registered in the specification information DB 31B in this way. In this example, the specification information regarding the communication termination point TPE (Termination Point Encapsulation) of the network equipment using Ethernet to be managed and the specification information regarding the communication termination point TPE of the network equipment using the IP network to be managed are registered. Each specification information associates two pieces of attribute information for defining the characteristics of the above network equipment with the identification name. Each piece of attribute information is represented by a pair of an RSC (Resource Spec Characteristic) representing the name of the attribute and an RSCV (Resource Spec Characteristic Value) representing the range that the attribute can take. For example, the specification information regarding the communication termination point TPE of the network equipment using Ethernet has two pieces of attribute information RSC: vlan / RSCV: 1 - 4096 RSC: Bandwidth / RSCV: 1 - 1000 Mbps defined for the identification name TPE_Ethernet_Spec. Also, the specification information regarding the communication termination point TPE of the network equipment using the IP network has two pieces of attribute information RSC: IP address / RSCV: 0.0.0.0 - 256.256.256.256 RSC: MTU / RSCV: 1 - 1500 defined for the identification name TPE_IP_Spec.
[0053] (1 - 2) Registration of entity information (1 - 2 - 1) Processing by the operator terminal OT When a network administrator who operates the operator terminal OT selects the entity registration processing mode as the registration processing mode of management information from the input device 51, the network administrator further inputs, using the input device 51, entity information that defines actual resources for the network facilities to be managed. Then, the control unit 1A of the operator terminal OT, which determined in step S20 that it is in the entity registration processing mode, receives the input entity information via the input / output I / F unit in step S21 under the control of the entity registration request transmission processing unit 12A, and temporarily stores it in the entity information storage unit 32A. When the network administrator inputs a transmission instruction after finishing the input of the entity information, the entity registration request transmission processing unit 12A detects the input of the transmission instruction in step S22, and in step S23, transmits an entity registration request including the entity information stored in the entity information storage unit 32A from the communication I / F unit 4A to the network management device NM. If the network administrator has not yet finished inputting and transmitting the desired entity information, the network administrator continues to input the entity information, and when all input and transmission are completed, gives an end instruction for the entity registration processing mode. Therefore, after transmitting the entity registration request in step S23, the control unit 1A repeats the operations in steps S21 to S23 until it detects the input of the end instruction in step S24.
[0054] (1-2-2) Processing by the network management device NM The control unit 1B of the network management device NM, which determined in step S50 that it has received a specification registration request, registers, in step S51, the entity information included in the entity registration request received via the communication I / F unit 4B in the entity information DB32B under the control of the entity information registration processing unit 12B.
[0055] Entity information is represented by the name of a resource specification and a plurality of attribute information. Each piece of attribute information is represented by a pair of an RSC (Resource Specification Characteristic) representing the name of the attribute and an RCV (Resource Characteristic Value) representing the value for the attribute. FIG. 9 shows an example of entity information registered in the entity information DB 32B. In this example, as entity information with the identifier TPE_Ethernet1, the name of its resource specification and two pieces of attribute information are Resource Spec:TPE_Ethernet_Spec RSC:vlan / RCV:123 RSC:Bandwidth / RCV:1000Mbps defined as such. Also, as entity information with the identifier TPE_IP1, the name of its resource specification and two pieces of attribute information are Resource Spec:TPE_IP_Spec RSC:IP address / RCV:192.168.1.1 RSC:MTU / RCV:1500 defined as such.
[0056] (1-3) Registration of policy information (1-3-1) Processing by the operator terminal OT When a network administrator who operates the operator terminal OT selects the policy registration process mode as the input mode of management information from the input device 51, the network administrator further inputs, using the input device 51, policy information that defines access conditions related to cooperation with other companies. Then, the control unit 1A of the operator terminal OT, which determined in step S30 that it is in the policy registration process mode, receives the input policy information via the input / output I / F unit in step S31 under the control of the policy registration request transmission processing unit 13A and temporarily stores it in the policy information storage unit 33A. When the network administrator inputs a transmission instruction after finishing the input of the above policy information, the policy registration request transmission processing unit 13A detects the input of the above transmission instruction in step S32, and in step S33, transmits a policy registration request including the above policy information stored in the policy information storage unit 33A from the communication I / F unit 4A to the network management device NM. If the network administrator has not yet finished inputting and transmitting the desired policy information, the network administrator continues to input policy information, and when all input and transmission are completed, gives an instruction to end the policy registration process mode. Therefore, after transmitting the policy registration request in step S33, the control unit 1A repeats the operations in steps S31 to S33 until it detects the input of the above end instruction in step S34.
[0057] (1-3-2) Processing by Network Management Device NM The control unit 1B of the network management device NM, which determined in step S60 that it has received a policy registration request, registers, in step S61, the policy information included in the policy registration request received via the communication I / F unit 4B in the policy information DB 33B under the control of the policy information registration processing unit 13B.
[0058] The policy information includes access conditions for each of a plurality of other operators who use other operator terminals ACT1 to ACTm. FIG. 10 is a diagram showing an example of the policy information registered by the policy information registration process. In this example, as the policy information with the identifier Policy_Cooperation1, the name of the other operator and two access conditions, the disclosure condition and the registration condition are Company OO Disclosure: Unrestricted Registration: Specification, Entity defined as such. Also, as the policy information with the identifier Policy_Cooperation2, Company XX Disclosure: Not allowed Registration: Entity is defined, and as the policy information with the identifier Policy_Cooperation3, Company △△ Disclosure: Unrestricted Registration: Not allowed is defined.
[0059] Note that "unrestricted" in the disclosure condition indicates that it is possible to read all the specification information and entity information registered in the specification information DB31B and the entity information DB32B. "Specification, Entity" in the registration condition indicates that it is possible to register specification information and entity information in the specification information DB31B and the entity information DB32B. "Entity" in the registration condition indicates that it is not possible to register specification information in the specification information DB31B, but it is possible to register entity information in the entity information DB32B. Although not shown in FIG. 10, it goes without saying that in the disclosure condition, it is also possible to specify that only one of the specification information and the entity information can be disclosed.
[0060] (2) Access control FIG. 11A and FIG. 11B are a series of flowcharts showing an example of the processing procedure and processing content of access control executed by the control unit 1B of the network management device NM. When the control unit 1B of the network management device NM receives a request from the in-house user terminals OUT1 to OUTn or the other company terminals ACT1 to ACTm via the communication I / F unit 4B in the standby state, it starts the operation of this flowchart.
[0061] When starting the operation, under the control of the access control processing unit 14B, the control unit 1B determines in step S70 whether the received request is a request from the other company terminals ACT1 to ACTm.
[0062] (2-1) Processing for requests from in-house user terminals OUT1 to OUTn Suppose a disclosure request for the entity information registered in the network management device NM is sent from an in-house user terminal OUTi, which is one of the in-house user terminals OUT1 to OUTn. In this case, the control unit 1B of the network management device NM determines that it has received a disclosure request from the in-house user terminal OUTi, not a request from the other company terminals ACT1 to ACTm, in step S70 above. Then, first, in step S71, the control unit 1B acquires the entity information corresponding to the entity name specified in the disclosure request from the entity information DB32B. Subsequently, in step S72, the access control processing unit 14B transmits the entity information for which disclosure has been requested from the communication I / F unit 4B to the in-house user terminal OUTi that is the request source.
[0063] (2-2) Processing for requests from other company terminals ACT1 to ACTm The control unit 1B of the network management device NM that has determined in step S70 above that the received request is a request from the other company terminals ACT1 to ACTm determines in step S80 whether the request is a registration request under the control of the other company cooperation processing unit 15B of the access control processing unit 14B.
[0064] (2-2-1) Registration processing Suppose a registration request for specification information and entity information not registered in the network management device NM is sent from a third - party terminal ACTi, which is one of the third - party terminals ACT1 to ACTm. In this case, the control unit 1B determines that the request received in step S80 above is a registration request. In this case, the control unit 1B, in step S81, acquires the policy information corresponding to the third - party terminal ACTi that is the request source from the policy information DB33B. Then, in step S82, the control unit 1B determines whether registration is possible based on the acquired policy information, that is, whether the access conditions are met. If registration is possible, the control unit 1B, in step S83, registers the information specified as registrable among the specification information and / or entity information requested by the received registration request in the corresponding specification information DB31B and / or entity information DB32B. Also, if registration is not possible, the control unit 1B, in step S84, transmits from the communication I / F unit 4B to the third - party terminal ACTi that is the request source that registration is not possible.
[0065] (2 - 2 - 1 - 1) Example of operation when registration conditions are met FIG. 12 is a diagram showing an example of the operation of the registration process from the third - party terminal ACTi. In this example, in (1) of FIG. 12, a registration request is sent from the third - party terminal ACTi of "Company XX" as the request source, specifying the specification information "TPE_Transmission_Spec" and the entity information "TPE_Transmission1" as the registration targets.
[0066] Then, the third - party cooperation processing unit 15B of the access control processing unit 14B of the network management device NM first acquires the policy information "Policy_Cooperation1" corresponding to the above "Company XX" that is the request source from the policy information DB33B in (2) of FIG. 12.
[0067] Subsequently, in step (3) of FIG. 12, the other-operator cooperation processing unit 15B determines whether the request content of the above registration request satisfies the registration conditions described in the obtained policy information "Policy_Cooperation1". In this example, the request content is the registration of specification information and entity information, and since the registration conditions described in the policy information allow the registration of both specification information and entity information, the other-operator cooperation processing unit 15B determines that the above registration request satisfies the registration conditions.
[0068] Therefore, in step (4) of FIG. 12, the other-operator cooperation processing unit 15B registers the entity information "TPE_Transmission1" specified by the registration request as the registration target in the entity information DB 32B. Further, in step (5) of FIG. 12, the other-operator cooperation processing unit 15B registers the specification information "TPE_Transmission_Spec" specified by the registration request as the registration target in the specification information DB 31B.
[0069] (2-2-1-2) Example of operation when the registration conditions are not satisfied FIG. 13 is a diagram showing an example of the operation when the registration conditions are not satisfied as another example of the operation of the registration process from the other-operator terminal ACTi.
[0070] In this example, in step (1) of FIG. 13, a registration request is sent from the other-operator terminal ACTi of "XX Company" as the request source, specifying the specification information "TPE_Transmission_Spec" and the entity information "TPE_Transmission1" as the registration targets.
[0071] Then, the other-operator cooperation processing unit 15B of the access control processing unit 14B of the network management device NM first obtains the policy information "Policy_Cooperation3" corresponding to the above "XX Company" from the policy information DB 33B in step (2) of FIG. 13.
[0072] Subsequently, in (3) of FIG. 13, the other-operator cooperation processing unit 15B determines whether the request content of the above registration request satisfies the registration conditions described in the acquired policy information "Policy_Cooperation3". In this example, since the request content is the registration of specification information and entity information, and the registration conditions described in the policy information are non-registrable, the other-operator cooperation processing unit 15B determines that the above registration request does not satisfy the registration conditions.
[0073] Therefore, in (4) of FIG. 12, the other-operator cooperation processing unit 15B generates a non-registrable message and returns it to the other-operator terminal ACTi that is the request source.
[0074] In FIGS. 12 and 13, the case where a registration request for one entity information is made for one network type (specification information) has been described as an example. However, it is also possible to collectively request the registration of a plurality of entity information and individually determine whether registration is possible. Furthermore, it goes without saying that it is possible to perform a collective registration process not only for one network type (specification information) but also for a plurality of network types.
[0075] (2-2-2) Disclosure process Suppose that a disclosure request for entity information set for a desired network facility is transmitted from the other-operator terminal ACTi, which is one of the other-operator terminals ACT1 to ACTm. In this case, the control unit 1B determines that the request received in step S80 above is not a registration request, that is, a disclosure request. In this case, in step S90, the control unit 1B acquires the entity information requested by the received disclosure request from the entity information DB 32B. Further, in step S91, the control unit 1B acquires the specification information referred to by the requested entity information from the specification information DB 31B.
[0076] After that, in step S92, the control unit 1B acquires the policy information corresponding to the requesting other operator terminal ACTi from the policy information DB 33B. Then, in step S93, the control unit 1B determines whether disclosure is possible based on the acquired policy information, that is, whether the access conditions are satisfied. If disclosure is possible, in step S94, the control unit 1B transmits, from the communication I / F unit 4B to the requesting other operator terminal ACTi, the information specified as being disclosable among the specification information and / or entity information requested by the received disclosure request and acquired in steps S90 and S91 above. Also, if disclosure is not possible, in step S95, the control unit 1B transmits from the communication I / F unit 4B to the requesting other operator terminal ACTi that disclosure is not possible.
[0077] (2-2-2-1) Example of operation when disclosure conditions are satisfied FIG. 14 is a diagram showing an example of the operation of the disclosure process from the other operator terminal ACTi. In this example, in FIG. 14(1), a start request designating the entity information "TPE_Ethernet1" as the disclosure target is transmitted from the other operator terminal ACTi of "Company XX" as the requester.
[0078] Then, the other operator cooperation processing unit 15B of the access control processing unit 14B of the network management device NM first acquires the entity information "TPE_Ethernet1" specified by the disclosure request as the disclosure target from the entity information DB 32B in FIG. 14(2). Further, in FIG. 14(3), the other operator cooperation processing unit 15B acquires "TPE_Ethernet_Spec", which is the specification information referred to by the entity information "TPE_Ethernet1" specified as the disclosure target, from the specification information DB 31B.
[0079] Subsequently, the Other Business Operator Cooperation Processing Unit 15B obtains the policy information "Policy_Cooperation1" corresponding to the requesting "Company XX" from the Policy Information DB 33B in (4) of FIG. 14. Then, in (5) of FIG. 14, the Other Business Operator Cooperation Processing Unit 15B determines whether the content of the disclosure request satisfies the disclosure conditions described in the obtained policy information "Policy_Cooperation1". In this example, since the content of the request is the disclosure of entity information and the disclosure conditions described in the policy information are unrestricted, the Other Business Operator Cooperation Processing Unit 15B determines that the above disclosure request satisfies the disclosure conditions.
[0080] Therefore, in (6) of FIG. 14, the Other Business Operator Cooperation Processing Unit 15B returns the obtained "TPE_Ethernet1", which is the requested entity information, and the obtained "TPE_Ethernet_Spec", which is the specification information it references, from the Communication I / F Unit 4B to the other business operator terminal ACTi of the request source.
[0081] (2-2-2-2) Example of Operations When Disclosure Conditions are Not Met FIG. 15 is a diagram showing an example of operations when disclosure conditions are not met as another example of the operations of the disclosure process from the other business operator terminal ACTi.
[0082] In this example, in (1) of FIG. 15, a start request designating entity information "TPE_Ethernet1" as the disclosure target is sent from the other business operator terminal ACTi of "Company XX" as the request source.
[0083] Then, the Other Business Operator Cooperation Processing Unit 15B of the Access Control Processing Unit 14B of the Network Management Device NM obtains the entity information "TPE_Ethernet1" and the specification information "TPE_Ethernet_Spec" from the Entity Information DB 32B and the Specification Information DB 31B in (2) and (3) of FIG. 15, similar to (2) and (3) of FIG. 14.
[0084] Subsequently, the Other Business Operator Cooperation Processing Unit 15B acquires the policy information "Policy_Cooperation2" corresponding to the above-mentioned "XX Company" which is the requester from the Policy Information DB 33B in (4) of FIG. 15. Then, in (5) of FIG. 15, the Other Business Operator Cooperation Processing Unit 15B determines whether the content of the above disclosure request satisfies the disclosure conditions described in the acquired policy information "Policy_Cooperation2". In this example, since the content of the request is the disclosure of entity information and the disclosure conditions described in the policy information are "not allowed", the Other Business Operator Cooperation Processing Unit 15B determines that the above disclosure request does not satisfy the disclosure conditions.
[0085] Therefore, in (6) of FIG. 15, the Other Business Operator Cooperation Processing Unit 15B generates a non-disclosure message and returns it to the other business operator terminal ACTi which is the requester.
[0086] In FIGS. 14 and 15, the case of making a disclosure request for one piece of entity information for one network type (specification information) has been described as an example. However, it is also possible to make a batch disclosure request for a plurality of pieces of entity information and individually determine whether disclosure is possible. Furthermore, of course, it is also possible to perform batch disclosure processing not only for one network type (specification information) but also for a plurality of network types.
[0087] (Function and Effect) As described above, in one embodiment, the network management device NM manages the network by registering specification information and entity information, which define the characteristics of various networks or devices using them according to a predetermined model format using a plurality of attributes regardless of the type of network, in the specification information DB 31B and the entity information DB 32B. Then, when a registration request for desired unregistered specification information and / or entity information is received from the other operator terminals ACT1 to ACTm, the network management device NM, under the control of the other operator cooperation processing unit 15B, registers the specification information and / or entity information defined according to the predetermined model format in the registration request in the specification information DB 31B and / or the entity information DB 32B.
[0088] Therefore, according to one embodiment, an other operator can register desired specification information and / or entity information by creating the specification information and / or entity information defined according to the predetermined model format and transmitting it to the network management device NM. As a result, the other operator only needs to develop means for accessing the other operator cooperation processing unit 15B, and the development cost and development period can be reduced. Furthermore, when a plurality of network operators use a network management device NM as in one embodiment, the development cost and development period of the access means when increasing the network operators accessed by the other operator can also be reduced.
[0089] [Other Embodiments] In one embodiment, the case where the specification information DB31B and the entity information DB32B are provided in the network management device NM has been described as an example. However, the specification information DB31B and the entity information DB32B may be provided in a database server or the like separate from the network management device NM, and the network management device NM may access the specification information DB31B and the entity information DB32B provided in the database server or the like to perform registration processing and disclosure processing of specification information, entity information, and policy information. Further, the registration processing function and the disclosure processing function of the specification information, the entity information, and the policy information may be distributed and arranged in a plurality of information processing devices.
[0090] In addition, the functions, processing procedures and processing contents, formats and data structures of the specification information, entity information and policy information provided in the network management device can also be variously modified and implemented without departing from the gist of the present invention.
[0091] Also, the flow of each process described with reference to the flowchart is not limited to the described procedure. For example, the processes of steps S92 and S93 in FIG. 11B may be performed before the process of step S90, and the processes of steps S90 and S91 may be performed only when it is determined in step S93 that disclosure is possible. Thus, the order of some steps may be interchanged. Furthermore, some steps may be performed simultaneously, or the processing contents of some steps may be modified.
[0092] Although the embodiments of the present invention have been described in detail above, the foregoing description is merely illustrative of the present invention in every respect. Needless to say, various improvements and modifications can be made without departing from the scope of the present invention. That is, in practicing the present invention, a specific configuration according to the embodiment may be appropriately adopted.
[0093] In short, the present invention is not limited to the above-described embodiments as they are, and at the implementation stage, the components can be modified and embodied without departing from the gist thereof. Further, various inventions can be formed by appropriately combining a plurality of components disclosed in the above-described embodiments. For example, some components may be deleted from all the components shown in the embodiments. Furthermore, components from different embodiments may be appropriately combined.
Explanation of Signs
[0094] 1A, 1B... Control unit 2A, 2B... Program storage unit 3A, 3B... Data storage unit 4A, 4B... Communication interface unit (communication interface I / F unit) 5A... Input / output interface unit (input / output I / F unit) 6A, 6B... Bus 11A... Specification registration request transmission processing unit 11B... Specification information registration processing unit 12A... Entity registration request transmission processing unit 12B... Entity information registration processing unit 13A... Policy registration request transmission processing unit 13B... Policy information registration processing unit 14B... Access control processing unit 15B... Third-party cooperation processing unit 31A... Specification information storage unit 31B... Specification information database (specification information DB) 32A... Entity information storage unit 32B... Entity information database (entity information DB) 33A... Policy information storage unit 33B... Policy information database (policy information DB) 51... Input device 52... Output device ACT1 to ACTm, ACTi... Third-party terminals NM... Network management device NW... Network OT... Operator terminal OUT1 to OUTn, OUTi... Own user terminal
Claims
1. A first registration processing unit that receives an input of specification information defining characteristics of network facilities of self-employed individuals to be managed using a plurality of pieces of attribute information and stores the specification information in a specification information storage unit; A second registration processing unit that receives an input of entity information defining actual resources to be set for the network facilities corresponding to the plurality of pieces of attribute information and stores the entity information in an entity information storage unit; A third registration processing unit that receives a registration request for at least one of the specification information and the entity information from one or more other business operators different from the self-employed individual, and makes it possible to store at least one of the received specification information and the entity information in at least one of the specification information storage unit and the entity information storage unit; A network management device comprising the above.
2. It further comprises a fourth registration processing unit that receives an input of policy information defining access conditions to the specification information storage unit and the entity information storage unit for each of the one or more other business operators, and stores the policy information in a policy information storage unit. When the third registration processing unit receives a registration request for at least one of the specification information and the entity information from one of the one or more other business operators, based on the access conditions defined by the policy information stored in the policy information storage unit, it determines whether it is possible to store at least one of the received specification information and the entity information in at least one of the specification information storage unit and the entity information storage unit. The network management device according to Claim 1.
3. The third registration processing unit Performs a process of obtaining the access conditions for the other business operator that is the source of the registration request from the policy information storage unit; A process of determining whether the obtained access conditions allow storage; When it is determined that the access conditions allow storage, a process of storing at least one of the specification information and the entity information requested for registration by the registration request in at least one of the specification information storage unit and the entity information storage unit. Performs the above processes. The network management device according to Claim 2.
4. When receiving a disclosure request that designates the entity information as a disclosure target from any of the one or more other operators, the access control processing unit further includes: disclosing the entity information designated as the disclosure target to the other operator that is the request source. The access condition includes disclosure permission information indicating whether information disclosure is possible for each of the one or more other operators. The access control processing unit determines whether to disclose at least one of the entity information and the corresponding specification information to the other operator that is the request source based on the access condition. The network management device according to claim 2.
5. The access control processing unit The process of acquiring the entity information designated by the disclosure request from the entity information storage unit, The process of acquiring the specification information referred to by the acquired entity information from the specification information storage unit, The process of acquiring the access condition for the other operator that is the source of the disclosure request from the policy information storage unit, The process of determining whether the disclosure permission information included in the acquired access condition indicates that disclosure is possible, When it is determined that the disclosure permission information indicates that disclosure is possible, the process of transmitting at least one of the acquired entity information and the specification information to the other operator that is the source of the transmission, Performs The network management device according to claim 4.
6. A network management method executed by an information processing device, comprising: A process in which the information processing device receives an input of specification information that defines the characteristics of the network equipment of its own business operator to be managed using a plurality of attribute information, and stores the specification information in a specification information storage unit; A process in which the information processing device receives an input of entity information that defines the actual resources to be set for the network equipment corresponding to the plurality of attribute information, and stores the entity information in an entity information storage unit; A process in which the information processing device receives a registration request for at least one of the specification information and the entity information from one or more other operators different from the own business operator, and enables the received at least one of the specification information and the entity information to be stored in at least one of the specification information storage unit and the entity information storage unit; A network management method comprising.
7. A program that causes a processor included in the network management device to execute processing performed by at least one of the processing units included in the network management device according to any one of claims 1 to 5.
Citation Information
Patent Citations
Network device, network management apparatus and network management system
JP2005071183A
Network managing device, relaying device, network management system, and network managing program
JP2006020031A
Network management device, method and program
JP6655524B2
Network management device, method, and program
WO2021048982A1