Data processing path management system and data processing path management method

The data processing path management system addresses IoT security challenges by dividing resources and paths into multiple paths with tailored security functions, enhancing security and convenience in managing diverse IoT devices.

JP7771006B2Active Publication Date: 2025-11-17HITACHI LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022110854
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-08
Publication Date
2025-11-17
Estimated Expiration
2042-07-08

AI Technical Summary

Technical Problem

IoT systems face security challenges due to constant exposure to attacks, requiring continuous updates and uniform access control that does not consider device vulnerabilities or user convenience, especially for critical services like autonomous driving.

Method used

A data processing path management system that logically or physically divides information processing resources and transmission paths into multiple paths with different security functions, associating security requirements with device attributes and services to dynamically select paths based on security requirement information.

Benefits of technology

Ensures security in IoT systems, improves user convenience, and simplifies management of large numbers of devices by adapting to individual device vulnerabilities and service needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007771006000001
    Figure 0007771006000001
  • Figure 0007771006000002
    Figure 0007771006000002
  • Figure 0007771006000003
    Figure 0007771006000003
Patent Text Reader

Abstract

To provide a data processing route management system and a data processing route management method that ensure security in an IoT system, provide user convenience, and facilitate the management of a large number of devices.SOLUTION: A data processing route management system includes a function for an application apparatus 109 to receive data via a data transmission / reception route from a device 114 connected via a network, and a function of providing a service by the application apparatus. The application apparatus and the data transmission / reception route are logically or physically divided into a plurality of data processing routes, and different security functions are set for each data processing route to control the data processing routes. A service management apparatus 105 manages security requirement information that associates necessary security functions with combinations of service and device attributes, and selects a data processing route based on the security requirement information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system that manages Internet of Things (IoT) devices such as sensor devices and actuators, and collects and controls data from the IoT devices. In particular, the present invention relates to an IoT system that handles a huge number of IoT devices. Note that hereinafter, IoT devices will be simply referred to as devices. [Background technology]

[0002] Recently, with the spread of the fifth-generation mobile communication system (5G), there have been advances in communication speeds, capacity increases, enhanced security through the use of slicing, and Quality of Service (QoS) guarantees. In addition, the number of IoT devices is rapidly increasing, and the automation of the control and monitoring of various devices and equipment is expanding.

[0003] The first characteristic of IoT systems is that they are accessed by a large number of devices. Furthermore, the services provided are diversifying, and the devices are also diverse. Therefore, it is desirable for IoT systems to be able to support services with different security requirements and devices with different vulnerability levels.

[0004] Patent Document 1 discloses a method of calculating a vulnerability score of a terminal and performing access control based on the vulnerability score when connecting to a secure network. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Publication No. 2019-83478 Summary of the Invention [Problem to be solved by the invention]

[0006] IoT systems that communicate via external networks are constantly exposed to attacks, and devices require continuous updates to protect against vulnerabilities. In particular, for services such as autonomous driving, strong security is required for communication routes and information processing resources to prevent equipment malfunctions.

[0007] In Patent Document 1, access to a secure network is determined based on a vulnerability score calculated for each device. While this protects system resources, it does not take into consideration the convenience of system users. Older devices that cannot be protected from vulnerabilities will be unable to connect, which may require a large number of devices to be updated simultaneously. Furthermore, access control is limited to two options: connectable or not, and the processing applied to devices after connection is uniform, making it difficult to respond to the vulnerability level of each device.

[0008] The present invention has been made in light of the above background, and an object of one aspect of the present invention is to provide a technology that ensures security in IoT systems, improves user convenience, and facilitates the management of a large number of devices. [Means for solving the problem]

[0009] A preferred aspect of the present invention is a data processing path management system that controls the data processing paths for an information processing system that includes an information processing resource and a data transmission / reception path, and is equipped with a function for the information processing resource to receive data via the data transmission / reception path from a device connected via a network, and a function for providing a service using the information processing resource, wherein the information processing resource and data transmission / reception path are logically or physically divided into multiple data processing paths, and each data processing path has different security functions set up, and wherein an information processing device manages security requirement information that associates the required security functions with combinations of the service and the device attributes, and selects the data processing path based on the security requirement information.

[0010] Another preferred aspect of the present invention is a data processing path management method for controlling the data processing paths of an information processing system that includes an information processing resource and a data transmission / reception path, and is equipped with a function for the information processing resource to receive data via the data transmission / reception path from a device connected via a network, and a function for providing a service by the information processing resource, wherein the information processing resource and the data transmission / reception path are logically or physically divided into multiple data processing paths, and each data processing path has a different security function set, wherein an information processing device manages security requirement information that associates the required security functions with combinations of the service and device vulnerability information, which is an attribute of the device, and selects the data processing path based on the security requirement information. [Effects of the Invention]

[0011] We can provide technology that ensures security in IoT systems, improves user convenience, and simplifies the management of large numbers of devices. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a block diagram showing a schematic configuration of an information processing system. [Figure 2] FIG. 2 is a block diagram illustrating an example of a data processing path. [Figure 3] FIG. 1 is a block diagram showing an example of an information processing device that can be used as a component of an information processing system. [Figure 4] FIG. 2 is a functional block diagram showing an overview of functions and data of the integrated management device. [Figure 5] FIG. 2 is a functional block diagram showing an overview of functions and data of a device management apparatus. [Figure 6] FIG. 10 is a table illustrating an example of attribute information data of a device. [Figure 7] FIG. 2 is a functional block diagram showing an overview of functions and data of the data processing path management device. [Figure 8]FIG. 10 is a table illustrating an example of data processing path attribute information data. [Figure 9] FIG. 10 is a table showing an example of service status information data of a device. [Figure 10] FIG. 2 is a functional block diagram showing an overview of functions and data of the service management device. [Figure 11] FIG. 10 is a table showing an example of security requirement information data. [Figure 12] FIG. 2 is a functional block diagram showing an overview of the functions and data of the security device. [Figure 13] FIG. 10 is a table illustrating an example of setting information data. [Figure 14] FIG. 1 is a functional block diagram showing an overview of the functions and data of an IoT device GW. [Figure 15] FIG. 2 is a functional block diagram showing an overview of functions and data of a data storage device. [Figure 16] FIG. 2 is a functional block diagram showing an overview of functions and data of the data processing device. [Figure 17] FIG. 2 is a functional block diagram showing an overview of functions and data of an application device. [Figure 18] FIG. 10 is an image diagram showing an example of a management screen. [Figure 19A] FIG. 10 is an image diagram showing an example of a management screen for data processing paths. [Figure 19B] FIG. 10 is an image diagram showing an example of a management screen for data processing paths. [Figure 19C] FIG. 10 is an image diagram showing an example of a management screen for data processing paths. [Figure 20A] FIG. 10 is an image diagram illustrating an example of a service management screen. [Figure 20B] FIG. 10 is an image diagram illustrating an example of a service management screen. [Figure 20C] FIG. 10 is an image diagram illustrating an example of a service management screen. [Figure 21A] FIG. 10 is an image diagram showing an example of a device management screen. [Figure 21B] FIG. 10 is an image diagram showing an example of a device management screen. [Figure 21C] FIG. 10 is an image diagram showing an example of a device management screen. [Figure 22A] FIG. 10 is an image diagram showing an example of a management screen of the security device. [Figure 22B] FIG. 10 is an image diagram showing an example of a management screen of the security device. [Figure 23] FIG. 10 is a sequence diagram illustrating message processing. [Figure 24] FIG. 10 is a sequence diagram showing a process of moving a data processing path. [Figure 25] 10 is a flowchart showing a route movement process in the integrated management device. [Figure 26] 10 is a flowchart illustrating a route movement process in the device. [Figure 27] FIG. 10 is a sequence diagram showing a route movement process based on a service request from a device. [Figure 28] 10 is a flowchart showing a process of reviewing a data path in response to an update of a security requirement of a service. [Figure 29] FIG. 10 is an image diagram showing an example of a data processing path change screen. [Figure 30] 10 is a flowchart illustrating a process for a device when an abnormality is detected. [Figure 31] 10 is a flowchart showing processing on a data processing path when a large amount of abnormality is detected. [Figure 32] 10 is a flowchart showing a process of evacuating normal devices when a large number of abnormalities are detected; DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments of the present invention will be described with reference to the drawings. However, the present invention should not be interpreted as being limited to the description of the embodiments shown below. Those skilled in the art will easily understand that the specific configuration can be changed within the scope of the idea or purpose of the present invention.

[0014] In the configurations of the embodiments described below, the same parts or parts having similar functions are denoted by the same reference numerals in different drawings, and redundant explanations may be omitted.

[0015] When there are multiple elements having the same or similar functions, they may be described using the same reference numeral with different subscripts. However, when there is no need to distinguish between multiple elements, the subscripts may be omitted.

[0016] The designations "first," "second," "third," etc. in this specification are used to identify components and do not necessarily limit the number, order, or content thereof. Furthermore, numbers used to identify components are used in different contexts, and numbers used in one context do not necessarily indicate the same configuration in another context. Furthermore, this does not prevent a component identified by a certain number from also serving the function of a component identified by another number.

[0017] In order to facilitate understanding of the invention, the position, size, shape, range, etc. of each component shown in the drawings etc. may not represent the actual position, size, shape, range, etc. Therefore, the present invention is not necessarily limited to the position, size, shape, range, etc. disclosed in the drawings etc.

[0018] All publications, patents, and patent applications cited herein are incorporated by reference in their entirety.

[0019] As used herein, elements referred to in the singular are intended to include the plural unless the context clearly indicates otherwise.

[0020] In an embodiment, an information processing system is disclosed that includes one or more information processing resources and one or more data transmission / reception paths, and has the function of receiving data from one or more devices connected via a network and the function of providing services to the devices, wherein the information processing resources and data transmission / reception paths are logically or physically divided into one or more data processing paths, and each data processing path has the function of managing the data transmission / reception path and the information processing resources, and different security functions set for each data processing path.

[0021] A representative example described in the embodiments is a data processing path management method for controlling the data processing paths of an information processing system that includes an information processing resource and a data transmission / reception path, and is equipped with a function in which the information processing resource receives data from devices connected via a network via the data transmission / reception path and a function in which the information processing resource provides services using the information processing resource, and in which the information processing resource and the data transmission / reception path are divided into multiple data processing paths, and each data processing path has a different security function set. This method manages security requirement information that associates required security functions with combinations of service and device vulnerability information, and selects a data processing path based on the security requirement information.

[0022] The data processing path can be dynamically selected and changed while the information processing system is running. For example, by using an integrated management device and a data processing path management device, the integrated management device instructs the data processing path management device to select a data processing path, and the data processing path management device performs a switching process to switch from the first data processing path to the second data processing path.

[0023] In a specific example, the system further manages data processing path attribute information that associates available security functions with data processing paths, and device attribute information that associates vulnerability information with available services for devices.When at least one of the device attribute information, data processing path attribute information, and security requirement information is changed, a data processing path based on the security requirement information is selected, and the data processing path used by the device is switched. [Example]

[0024] A first embodiment will be described with reference to Figures 1 to 27. In this embodiment, an example will be described in which information is collected from a plurality of devices in an information processing system 101 having a plurality of information processing devices, and a service is provided.

[0025] In this embodiment, the data transmission / reception paths and information processing resources between the device and the information processing system are logically or physically separated into one or more paths. The data processing paths include one or more separated data transmission / reception paths and one or more information processing resources, and are managed. In addition, different security functions are installed for each data processing path. Data collection from the device and service provision to the device are performed using a data processing path that matches the device's vulnerabilities and the service's security requirements.

[0026] 1 shows an example of a schematic configuration of an information processing system 101 in this embodiment. In this example, the information processing system 101 is constructed on a cloud 117. The information processing system 101 includes, for example, an IoT device gateway (GW) 111, an integrated management device 102, a device management device 103, a data processing path management device 104, a service management device 105, a security device 106, a data storage device 107, a data processing device 108, and an application device 109, and is connected to devices 114 via the Internet 112 and a carrier network (hereinafter referred to as a carrier NW) 113.

[0027] The IoT device GW111 (hereinafter referred to as IoT device GW), the integrated management device 102, the device management device 103, the data processing path management device 104, the service management device 105, the security device 106, the data storage device 107, the data processing device 108, and the application device 109 are connected via a communication network 110.

[0028] The information processing system 101 transmits and receives data to and from the device 114 via the IoT device gateway 111, and performs various processes and services based on the received data. Note that this configuration is just an example, and for example, a dedicated line, optical fiber, a local area network (LAN), a wide area network (WAN), or the like may be used instead of the Internet 112 or the carrier network 113. Furthermore, the information processing system 101 does not necessarily need to be configured on the cloud, and may be configured in an on-premise environment.

[0029] The devices 114 are IoT devices such as sensors and actuators equipped with communication functions, and include temperature sensors, vibration sensors, motion sensors, network cameras, factory equipment, refrigeration equipment, automobiles, etc. Alternatively, the functions of sensors and actuators may be separated from the communication functions, and assets 115 such as various sensors, actuators, network cameras, factory equipment, refrigeration equipment, and automobiles may be connected to the devices 114 wirelessly or by wire, and the devices 114 may transmit and receive data between the assets 115 and the information processing system 101.

[0030] Furthermore, in cooperation with a function provided by a communication carrier, the carrier NW 113 may implement a restriction 116 on the destination address of the device.

[0031] The IoT device GW 111 is a communication destination of the device 114, and has a message relay function such as an MQTT (Message Queuing Telemetry Transport) broker, and relays data transmission and reception between the device 114 and the information processing system 101.

[0032] The integrated management device 102 has a user interface, accepts instructions from a system administrator, and manages the entire information processing system 101 in accordance with a preset program. It also registers services provided by the information processing system 101 and registers data processing paths in response to operations by the administrator. It also receives service provision requests from devices 114 and issues instructions to move the devices 114 to data processing paths suitable for the requested services. It also receives notifications of device abnormalities from the security device 106 and issues instructions to process the abnormal devices and evacuate normal devices. It also has a function to instruct operations (such as restricting destination IP addresses, limiting communication speeds, and suspending SIMs) on SIMs (Subscriber Identity Modules) used by devices in cooperation with a carrier collaboration function.

[0033] The device management apparatus 103 has functions such as registering and deleting devices 114, and manages information such as the type and vulnerability of the registered devices 114, services that can be provided to the devices 114, and attribute information such as assets 115 connected to the devices 114. The device management apparatus 103 also issues instructions to the devices 114 to fix vulnerabilities (for example, updating firmware or applying security patches).

[0034] The data processing path management device 104 manages data transmission / reception paths between the information processing system 101 and the devices 114, information processing resources, and security functions set for each data processing path. It also manages the service status of the device 114 using each data processing path, such as the service being used, the state of the device 114 (for example, whether it is moving along the path), and the presence or absence of an abnormality.

[0035] The service management device 105 manages security requirements for services provided by the information processing system 101, and selects a data processing path that satisfies the security requirements for each service.

[0036] The security device 106 provides security functions such as anomaly detection and intrusion prevention, detects anomalies in the data received from the device 114, and notifies the integrated management device 102 of the detected anomalies.

[0037] The data storage unit 107 stores data received from the device 114 .

[0038] The data processing device 108 performs data shaping and statistical processing of the data received from the device 114 .

[0039] The application device 109 provides a service to the device 114. For example, in the case of a data collection service, the application device 109 collects and stores data from the device 114. The stored data may be transmitted to a customer's data center, for example, each time data is received, periodically, or in accordance with an instruction. In addition, for example, in a temperature control service, the application device 109 receives temperature information sensed by the asset 115 or the device 114, and transmits instructions to the device 114, such as increasing or decreasing the intensity of air conditioning, based on the difference between a preset target temperature and the received temperature. In addition, for example, in an autonomous driving service, an AI for autonomous driving is provided, and the AI ​​analyzes information from the device 114 and transmits control information to the device 114.

[0040] FIG. 2 shows an example of using multiple data processing paths (201-A to 201-C). In the example of FIG. 2, a device using a data collection service uses data processing paths 201-A and 201-B. Data processing path 201-A accommodates a device 114 for which vulnerability countermeasures have not been implemented, and is equipped with a security device 106 with an intrusion prevention function as a security measure. Data processing path 201-B accommodates a device 114 for which vulnerability countermeasures have been implemented. Data processing path 201-C accommodates a device 114 being remotely controlled. Data processing path 201-C performs destination address restriction 116 in cooperation with a carrier function to prevent unauthorized external access to a remotely controlled device 114. Furthermore, the device 114 moves between data processing paths 201 depending on the service it uses. For example, if a device 114 accommodated in data processing path 201-B and using a data collection service switches to using a remote control service, the device 114 moves to data processing path 201-C.

[0041] 2 shows three data processing paths 201-A to 201-C as an example, the number of data processing paths 201 may be more or less than three. Furthermore, one data processing path 201 may be used by multiple services, and one service may use multiple data processing paths 201 depending on the vulnerability level of the device 114. Furthermore, the destination address restriction 116 can provide a secure communication path by blocking external communications not only for devices 114 that are being remotely controlled, but also for older devices 114 for which security support has expired, for example.

[0042] 3 shows an example of the hardware configuration of an information processing device that can be used as each of the integrated management device 102, device management device 103, data processing path management device 104, service management device 105, security device 106, data storage device 107, data processing device 108, and application device 109. As shown in Fig. 3, the information processing device 3000 includes, for example, a processor 3001, a main memory device 3002, an auxiliary memory device 3003, an input device 3004, an output device 3005, and a communication device 3006. These are connected to each other so as to be able to communicate with each other via communication means such as a bus (not shown).

[0043] The processor 3001 is configured using, for example, a CPU (Central Processing Unit) or an MPU (Micro Processing Unit). The processor 3001 reads and executes computer programs stored in the main memory device 3002, thereby realizing various functions of the integrated management device 102, the device management device 103, the data processing path management device 104, the service management device 105, the security device 106, the data storage device 107, the data processing device 108, and the application device 109. The main memory device 3002 is a device that stores computer programs and data, and is, for example, a ROM (Read Only Memory), a RAM (Random Access Memory), or a non-volatile semiconductor memory.

[0044] The auxiliary storage device 3003 is, for example, a hard disk drive, a solid state drive (SSD), an optical storage medium (i.e., a compact disc (CD) and a digital versatile disc (DVD)), a storage system, an integrated circuit card (IC card), an SD memory card, or other storage medium read / write device, or a storage area of ​​a cloud server. The computer programs and data stored in the auxiliary storage device 3003 are read into the main storage device 3002 as needed. The input device 3004 is, for example, a keyboard, a mouse, a touch panel, a card reader, an audio input device, etc. The output device 3005 is a user interface that provides the user with various information such as processing progress and processing results. The output device 305 is, for example, a screen display device (i.e., a liquid crystal monitor, LCD (Liquid Crystal Display), or a graphics card), an audio output device (i.e., a speaker, etc.), or a printer, etc. Note that, for example, the information processing device 3000 may input and output information to and from other devices via the communication device 3006.

[0045] The communication device 3006 is a wired or wireless communication interface that realizes communication with other devices via communication means such as a LAN, the Internet, etc. The communication device 3006 is, for example, a network interface card (NIC), a wireless communication module, a universal serial bus (USB) module, or a serial communication module.

[0046] While FIG. 3 illustrates an example of a hardware configuration in which each device is implemented using a physical machine, each device may be implemented using various methods, such as a physical machine, a virtual machine, or a container. Furthermore, multiple devices may be implemented on the same physical machine using technologies such as a virtual machine or a container. Furthermore, when using the cloud, devices may be implemented using a managed service provided by a cloud provider. Although each device is described as a separate device in this embodiment, the functions of multiple devices may be combined into a single device. Furthermore, the functions of one device may be implemented by another device. Furthermore, there may be multiple devices of each type. Similarly, the IoT device GW 111 may be implemented using various methods, such as a physical machine, a virtual machine, a container, or a managed service. Furthermore, the number of IoT device GWs 111 is not limited to three and may be more or less than three. In this specification, unless otherwise specified, the numbers are not limited to the numbers described above and may be more or less than the numbers described above.

[0047] 4 shows the main functions of the integrated managing device 102 and the main information recorded by the integrated managing device 102. The integrated managing device 102 has a user interface function 401, a carrier cooperation function 402, an alert processing function 403, and a device processing function 404, and records resource information 405.

[0048] The resource information 405 records information on resources managed by the information processing system 101 (for example, access destination information for the device management device 103, the data processing path management device 104, the service management device 105, the security device 106, the data storage device 107, the data processing device 108, the application device 109, and the IoT device GW 111). The resource information 405 stores records having items such as resource names and access destinations (for example, uniform resource locators (URLs)).

[0049] 5 shows the main functions of the device management apparatus 103 and the main information recorded by the device management apparatus 103. The device management apparatus 103 has a device registration function 501 and a vulnerability management function 502, and records device attribute information 503.

[0050] The device registration function 501 registers the input information in device attribute information 503. The vulnerability management function 502 performs security management for the device 114 registered in the device attribute information 503, and updates the device attribute information 503. Details of the vulnerability management function 502 will be described in FIG. 29 and subsequent figures.

[0051] 6 shows an example of device attribute information 503. The device attribute information 503 stores records having items such as a device ID 601, a SIM ID 602, a device type 603, a vulnerability level 604 (e.g., a protection registration 605, a firmware version 606, and a security patch 607), an available service 608, and an asset 609. The protection registration 605 indicates that the device is an older model that cannot support the latest firmware or security patches and therefore requires device protection through destination address restrictions.

[0052] 7 shows the main functions of the data processing path management device 104 and the main information recorded by the data processing path management device 104. The data processing path management device 104 has a data processing path registration function 701 and a data processing path management function 702, and records data processing path attribute information 703 and device service status information 704.

[0053] The data processing path registration function 701 registers, deletes, and updates data processing paths in the data processing path attribute information 703. The data processing path management function 702 manages the service status of the device 114 by recording, updating, and referencing device service status information 704, and upon receiving instructions from the integrated management device 102, transmits various instructions to the device 114 via the IoT device GW 111.

[0054] 8 shows an example of the data processing path attribute information 703. Data recorded by each device included in the information processing system 101 is recorded, for example, in a table format. The data processing path attribute information 703 stores records having items such as a data processing path identifier 801, an IoT device gateway 802, a data processing device 803, a path status 804, a security function 805, an expected use 806, and a priority 807.

[0055] The IoT device gateway 802 and the data processing device 803 record the identifiers and access destination information of each device. The path status 804 indicates whether or not there is an abnormality in the data processing path 201. The security function 805 indicates the security function provided by the data processing path 201. In this embodiment, intrusion prevention, abnormality detection, and connection destination address restriction are provided, but this is not limited to these. Further, security functions such as monitoring of the utilization rate of the IoT device gateway 111 and the data processing device 108 may be provided. Furthermore, there may be multiple data processing paths 201 with the same attribute.

[0056] 9 shows an example of device service status information 704. The device service status information 704 stores records having items such as a device ID 901, a service in use 902, a data processing path 903, a device status (e.g., data processing path switching in progress) 904, and whether or not an abnormality has occurred 905.

[0057] 10 shows the main functions of the service management device 105 and the main information stored in the service management device 105. The service management device 105 has a service registration function 1001 and a data processing path selection function 1002, and records security requirement information 1003.

[0058] 11 shows an example of security requirement information 1003. The security requirement information 1003 stores records having items such as a service ID 1101, a service name 1102, a device attribute 1103, a required security function 1107, and an available data processing path 1108. The device attribute 1103 further has detailed items such as whether a device is registered 1104, a device type 1105, and a vulnerability level 1106 (for example, protected device registration, firmware version, security patch, etc.).

[0059] Required security functions 1107 specify the required security functions 1107 for each combination of service and device attributes 1103. Available data processing paths 1108 record data processing paths 201 that have security functions that match the required security functions 1107.

[0060] In this example, the service ID 1101 and the service name 1102 are recorded separately, but it is not necessary to use both as long as it is possible to uniquely identify the service. Device registration 1104 indicates that the device is registered in the device management apparatus 103. A case where the device is not registered corresponds to, for example, a case where a service application is installed on a personal smartphone or the like and a service is received from the information processing system 101 without being registered in the device management apparatus 103.

[0061] 12 shows the main functions of the security device 106 and the main information recorded by the security device 106. The security device 106 has a data reception function 1201, an abnormality detection function 1202, an intrusion prevention function 1203, an alert function 1204, and a management function 1205, and records setting information 1206.

[0062] 13 shows an example of the setting information 1206. The setting information 1206 records items such as a data processing path 1301, a security function 1302, an input 1303, an output 1304, and an analysis method etc. 1305.

[0063] Data processing path 1301 records the identifier of data processing path 201 where a security function is installed, and security function 1302 records intrusion prevention or anomaly detection. Input 1303 records the identifier of the device from which the data to be analyzed is obtained, or access information. Output 1304 records the identifier of the device to which data is output, or access information, in cases where an intrusion prevention function is used. Analysis method 1305 records the analysis method to be used when multiple analysis methods are provided.

[0064] Note that one security device may provide both anomaly detection and intrusion prevention functions. Also, one security device may provide security functions for two or more data processing paths. Also, two or more security devices may provide anomaly detection and intrusion prevention functions for one data processing path.

[0065] 14 shows the main functions of the IoT device GW 111 and the main information recorded by the IoT device GW 111. The IoT device GW 111 has a device registration function 1401, a data relay function 1402, and a device authentication function 1403, and records device information 1404. The device information 1404 records, for example, the device ID of the device that uses the IoT device GW 111 and information for authentication thereof.

[0066] 15 shows the main functions of the data storage device 107 and the main information recorded by the data storage device 107. The data storage device 107 has a data writing function 1501, a data reading function 1502, and a data deleting function 1503, and records received data information 1504. The received data information 1504 records, for example, a device ID, received data, and the date and time of reception in association with each other.

[0067] 16 shows the main functions of the data processing device 108 and the main information recorded by the data processing device 108. The data processing device 108 has a data receiving function 1601, a data transmitting function 1602, a data shaping function 1603, and a statistical processing function 1604, and records service information 1605. The data shaping function 1603 and the statistical processing function 1604 may have multiple methods. The service information 1605 records, for example, the required data shaping method and statistical processing method for each service.

[0068] 17 shows the main functions of the application device 109 and the main information recorded by the application device 109. The application device 109 has a data receiving function 1701, a data transmitting function 1702, and a data processing function 1703, and records received data information 1704. The received data information 1704 records, for example, a device ID, received data, and the date and time of reception in association with each other.

[0069] The communication network 110 is a wireless or wired network that enables data transfer between devices. If multiple devices are implemented on the same physical machine, data transfer may be within the same physical machine.

[0070] 18 is an example of a management screen 1801 displayed by the user interface function 401 of the integrated managing device 102. The management screen 1801 includes menus 1802 such as system status, data processing paths, services, devices, and security functions, and by selecting each menu, a detailed screen 1803 for that menu is displayed.

[0071] The user interface function 401 accesses the data processing path management device 104, the service management device 105, the device management device 103, and the security device 106 according to the selected menu, and displays various setting screens. A management screen 1801 is an example in which the system status is selected from the menu, and the user interface function 401 queries the data processing path management function 702 of the data processing path management device 104 about the presence or absence of an abnormality in the data processing path, and displays the result. Furthermore, when an alert is received from the alert issuing function of the security device 106, the alert processing function 403 may display the presence or absence of an alert and the processing result.

[0072] 19A to 19C show examples of data processing path setting scenes. FIG. 19A is an example of a setting screen that is displayed when a data processing path is selected on the management screen 1801. When a data processing path is selected, the user interface function 401 accesses the data processing path management device 104 and displays a data processing path list screen 1901 provided by the data processing path registration function 701. The data processing path registration function 701 displays a list 1902 of data processing paths that have been registered based on the data processing path attribute information 703. From this screen, the administrator can call up a new data processing path registration screen 1908, call up a registered data processing path editing screen 1912, delete a data processing path, and edit the priority order, and then press a save button 1906 to save the updated information, or press a cancel button 1907 to cancel the update of the registered information.

[0073] FIG. 19B shows an example of a new registration screen for a data processing path displayed on the management screen 1801. By pressing a new registration button 1903 in the data processing path list 1902, the screen transitions to a new registration screen 1908 for a data processing path. The administrator inputs the path name, the IoT device GW to be used, and information about the data processing device (e.g., an identifier or URL) into an information input table 1909. Furthermore, the administrator inputs the presence or absence of security functions provided by the data processing path (intrusion prevention, anomaly detection, and destination address restriction in the example of this figure), as well as the expected use, and presses a save button 1910. The data processing path registration function 701 reflects the input information in the data processing path attribute information 703. Furthermore, if there are any duplicate path names, this is pointed out.

[0074] 19C shows an example of a data processing path editing screen displayed on the management screen 1801. On the data processing path list screen 1901, a data processing path is selected from the data processing path list 1902 and an edit button 1904 is pressed to transition to a data processing path editing screen 1912. The administrator corrects the changes in the information input table 1913 and presses the save button 1914. The data processing path registration function 701 reflects the input information in the data processing path attribute information 703.

[0075] On the data processing path list screen 1901, by selecting a data processing path from the data processing path list 1902 and pressing the delete button 1905 for the selected row, the data processing path registration function 701 deletes the information for the selected data processing path from the data processing path attribute information 703. When deleting a data processing path, the data processing path registration function 701 queries the data processing path management function 702 to check whether there are any devices using the data processing path to be deleted, and if there are any services and devices in use, may display on the operation screen that the services and devices in use exist, and may display an operation screen for reconfirming the deletion of the data processing path and for inputting processing for the services and devices in use.

[0076] In this embodiment, it is assumed that the creation and connection settings of the IoT device gateway 111, the data processing device 108, and the security device 106 are performed in advance. The registration and editing of data processing paths involves inputting the attributes set for each data processing path and recording them in the data processing path attribute information 703. The same applies to the deletion of a data processing path, and the resources of each device are released after the data processing path is deleted.

[0077] Although the present embodiment shows examples of security functions such as intrusion prevention, anomaly detection, and destination address restriction, the present invention is not limited to these and there may be multiple methods for intrusion prevention and anomaly detection. Also, different security functions may be set, such as a firewall, resource monitoring, and DDoS countermeasures.

[0078] 20A to 20C show examples of service setting screens. Fig. 20A is an example of a details screen 1803 that is displayed when a service is selected on the management screen 1801. When a service is selected, the user interface function 401 accesses the service management device 105 and displays a registered service list screen 2001, provided by the service registration function 1001, on the details screen 1803. The service registration function 1001 displays a list 2002 of services that have been registered based on security requirement information 1003. The administrator can use this screen to register a new service, edit a registered service, and delete a service.

[0079] 20B shows an example of a new service registration screen displayed on the management screen 1801. Pressing a new service registration button 2003 on the registered service list screen 2001 transitions to a new service registration screen 2006.

[0080] The administrator enters the name of the service 2007, and enters the device attributes and required security functions in the information input table 2008. In cases where the required security functions differ depending on the device attributes, the administrator presses the add row button 2010 to add a row and selects the security functions required for each device attribute. After entering the device attributes and required security functions, the administrator presses the select data path button 2011, and the data processing path selection function 1002 queries the data processing path management function 702 and selects a data processing path equipped with the required security functions.

[0081] If there are multiple data processing paths that match the conditions, they may be selected based on priority. Also, if the priorities are the same, multiple data processing paths may be selected as available data processing paths. When the administrator presses the save button 2012, the service registration function 1001 reflects the input information in the security requirement information 1003. At this time, the service registration function 1001 may automatically create a service ID.

[0082] Furthermore, if there is no data processing path that satisfies the required security functions, the available data processing path column indicates that there is no data processing path that matches the conditions. If there is no available data processing path, the administrator must either create a new data processing path that has the required security functions, add security functions to an existing data processing path, or discontinue providing the service.

[0083] 20C shows an example of a service edit screen displayed on the management screen 1801. On the registered service list screen 2001, a service is selected and the edit button 2004 is pressed to transition to a service edit screen 2014.

[0084] When the administrator corrects the changes in the information input table 2016 and presses the data path selection button 2019, the data processing path selection function 1002 selects and sets an available processing path. When the administrator presses the save button 2020, the service registration function 1001 reflects the input information in the security requirement information 1003.

[0085] By selecting a service on the registered service list screen 2001 and pressing the delete button 2005 for the selected line, the service registration function 1001 deletes the information of the selected service from the security requirement information 1003. When deleting a service, the service registration function 1001 queries the data processing path management function 702 to check whether there are any devices using the service to be deleted, and if there are any devices in use, it may display on the management screen that the devices in use exist, and display a screen for reconfirming the deletion of the service or for inputting processing for the devices in use.

[0086] 21A to 21C show examples of device registration screens. Fig. 21A is an example of a details screen 1803 that is displayed when a device is selected on the management screen 1801. When a device is selected, the user interface function 401 accesses the device management apparatus 103 and the data processing path management apparatus 104, and displays a registered device list screen 2101 based on the device attribute information 503 and the device service status information 704.

[0087] From this screen, the administrator can register new devices, edit registered devices, and delete devices. The devices to be displayed can also be narrowed down based on the data processing path, the services in use, and whether or not there are any abnormalities. Furthermore, filtering by device type and vulnerability level may also be possible.

[0088] 21B shows an example of a new device registration screen displayed on the management screen 1801. On the registered device list screen 2101, pressing the add device button 2103 causes a transition to a new device registration screen 2106.

[0089] The administrator may individually register information such as device IDs using the information input table 2107, or may register devices in bulk by entering information for one or more devices in a file and selecting and reading the file in which the device information is registered. By entering device information on the new device registration screen 2106 and pressing the save button 2108, the device registration function 501 reflects the entered information in the device attribute information 503. Note that if a device ID has already been registered or if a duplicate device ID exists among the newly registered devices, the device registration function 501 may display the duplicate device ID and request the administrator to change the device ID.

[0090] Note that information other than the device ID may be set later. Furthermore, a reporting function may be placed in the device to determine the device type and vulnerability level, and the device registration function 501 may modify the device attribute information 503 based on a report from the device. Furthermore, the device registration function 501 transmits the device ID of the newly registered device to the data processing path management function 702. The data processing path management function 702 reflects the received device ID in the device's service status information 704. Note that when a new device ID is added to the device's service status information, the data processing path registers path 0 for the initial connection.

[0091] 21C is an example of a device edit screen displayed on the management screen 1801. On the registered device list screen 2101, one or more devices are selected from the registered device list 2102, and an edit button 2104 is pressed to transition to a device edit screen 2109. When the administrator corrects the information in the information input table 2110 and presses the save button 2111, the device registration function 501 reflects the input information in the device attribute information 503.

[0092] 22A and 22B show examples of security function setting screens. Fig. 22A is an example of a details screen 1803 that is displayed when security is selected on the management screen 1801. When security is selected, the user interface function 401 displays a security device list screen 2201. The user interface function 401 accesses the security device 106 based on the information in the resource information 405, and displays a security device list 2202 that associates the identifiers of the security devices with the data processing paths on which the security devices are installed.

[0093] 22B is an example of a security device settings screen 2203. Transition to this screen is made by selecting a security device from a security device list 2202 on a security device list screen 2201. On the security device settings screen 2203, for example, the data processing path supported by the security device, the security functions provided, the acquisition destination of the data to be analyzed, the output destination of the analyzed data, and the analysis method are set in an information input table 2204. The input and output include the identifier of the target device, access information of the target device, etc.

[0094] 18 to 22 are merely examples, and are not limited to these formats, and the setting method is not limited to the table format. For example, various settings may be made by accessing each device using SSH (secure shell), or by using a method provided by a cloud vendor.

[0095] 23 is an example of a message processing sequence. Note that although the Internet 112 is omitted in this sequence, the Internet 112 is located between the carrier NW 113 and the IoT device GW 111 and relays messages. Here, the message refers to user data and control data sent from the device 114.

[0096] The device 114 transmits a connection request (S2301) to the IoT device GW 111 belonging to the data processing path 201 to be used. The carrier NW 113 transmits the received connection request to the IoT device GW 111 (S2302). The device authentication function 1403 verifies the received authentication information (S2303) and transmits the authentication result to the device 114 (S2304). The carrier NW 113 transmits the received authentication result to the device 114 (S2305). If the authentication is successful (yes in S2306), the device 114 establishes a communication session with the IoT device GW 111 (S2309). If the authentication is unsuccessful (no in S2306), an error is displayed on an operation screen of the device 114 or the like (S2307), and the process ends (S2308).

[0097] The authentication process (S2303) and the establishment of the communication session (S2309) are performed in accordance with the communication protocol being used. A common authentication method is, for example, PKI (Public Key Infrastructure). By distributing a device certificate to each device 114 in advance and registering a root certificate for verifying the validity of the device certificate in the IoT device gateway 111, authentication using PKI can be used.

[0098] The device 114 transmits messages such as sensed data (i.e., user data) and various requests (i.e., control data) to the IoT device GW via the carrier NW 113 (S2310). If the message is user data, the message may include the name and identifier of the service to be used. The carrier NW 113 transmits the received message to the IoT device GW 111 (S2311). The IoT device GW 111 transmits the received message to the security device A106 (S2312).

[0099] The intrusion prevention function 1203 verifies the received message, and if it detects an abnormality (yes in S2313), it discards the message (S2314) and issues an alert including the device ID and the type of abnormality to the integrated management device 102 (S2315).If no abnormality is detected (no in S2313), it sends a message to the data processing device 108 (S2316).

[0100] The data receiving function 1601 of the data processing device 108 determines whether the message is user data or control data (S2317), and if it is a control message, the data transmitting function transmits the received data to the integrated managing device 102 (S2327). If it is user data, the data shaping function 1603 and the statistical processing function perform data shaping processing and statistical processing according to a pre-specified method (S2318), and the data transmitting function 1602 transmits the processed data to the data storage device 107 (S2319). The data shaping processing and statistical processing are intended to shape the data into a form suitable for subsequent applications and anomaly detection as necessary.

[0101] The data writing function 1501 of the data storage device 107 stores the received data in the received data information 1504 (S2320).

[0102] The data receiving function 1201 of the security device B 106 periodically reads data from the data storage device 107 (S2321), the abnormality detection function 1202 analyzes the read data (S2323), and if an abnormality is detected (yes in S2324), the alert function 1204 notifies the integrated management device 102 of the ID of the device in which the abnormality was detected and the type of abnormality.

[0103] The data reception function 1701 of the application device 109 periodically reads data from the data storage device 107 (S2322) and performs processing set for each service (S2326). For example, in the case of a service that remotely adjusts the temperature of a refrigeration device, the user data is sensed temperature data, and the data processing function 1703 issues an instruction to adjust the strength of cool air by comparing the user data with a target temperature. Although not shown in the sequence, this adjustment instruction is sent to the device 114 via the IoT device GW 111. Also, in the case of a data collection service, for example, the received data is recorded in received data information 1704.

[0104] The device 114 stores in advance a device certificate and access destination information of the IoT device GW 111 belonging to the data processing path 201 for initial connection, and connects to the IoT device GW 111 for initial connection at the time of initial connection. At the second or subsequent connection, the device 114 connects to the IoT device GW 111 that was used when the previous connection ended.

[0105] 23, with regard to the transmission and reception methods of messages and data between devices in the information processing system 101, the methods of obtaining messages and data described as pull type and push type may be changed from pull type to push type, or vice versa. In the case of pull type message and data acquisition, settings for reading messages and data are made in the receiving device, and in the case of push type message and data transmission are made in the sending device.

[0106] Furthermore, in a data processing path that does not have an intrusion prevention function, the processing performed by the security device A 106 is omitted. Similarly, in a data processing path 201 that does not perform anomaly detection, the processing performed by the security device B 106 is omitted. Furthermore, in a data processing path 201 that performs destination address restriction, the carrier NW checks the IP address of the destination, and communication with IP addresses other than those registered in advance is blocked.

[0107] Furthermore, the data processing device 108 may transmit the processed user data to the security device B 106 and the application device 109 without going through the data storage device 107 .

[0108] Fig. 24 shows an example of a sequence for moving a data processing path of the device 114. The execution procedure for moving a data processing path from path 1 to path 2 will be described using Fig. 24. Note that this sequence is a processing sequence when the movement of the device 114 is successful.

[0109] The device processing function 404 of the integrated managing device 102 transmits a path transfer instruction including the device ID of the processing target device 114 and the destination data processing path ID to the data processing path managing device 104 (S2401).

[0110] The data processing path management function 702 of the data processing path management apparatus 104 sends a path movement instruction including the device ID and access information of the movement destination to the IoT device GW 111 of path 1 (S2402), and updates the device's service status information 704 (S2407). Specifically, "moving path" and the destination data processing path ID are recorded in the device status 904. The data processing path management function 702 also sends a device registration request including the device ID to the IoT device GW 111 of path 2, which is the movement destination (S2408). The IoT device GW 111 of path 2 registers the received device ID in the device information 1404 (S2409).

[0111] When the IoT device GW111 of path 1 receives the path movement instruction, it transmits the path movement instruction including access information for the destination IoT device GW111 to the device (S2403). The carrier NW113 transmits the received path movement instruction to the device 114 (S2404). The device 114 transmits a request to disconnect the communication session established with the IoT device GW111 of path 1 (S2405), and the carrier NW transmits the received communication session disconnection request to the IoT device GW111 of path 1 (S2406). As a result, the communication session between the device 114 and the IoT device GW111 of path 1 is disconnected.

[0112] Next, the device 114 transmits a connection request including authentication information to the IoT device GW 111 of path 2, which is the new connection destination, via the carrier NW 113 (S2410). The carrier NW 113 transmits the received connection request to the IoT device GW 111 of path 2 (S2411). The IoT device GW of path 2 verifies the authentication information (S2412) and transmits the authentication result to the device 114 via the carrier NW 113 (S2413). The carrier NW 113 transmits the received authentication result to the device 114 (S2414).

[0113] If the authentication is successful (yes in S2415), the device 114 establishes a communication session with the IoT device GW 111 of path 2 (S2416). Next, the device 114 transmits a path movement end notification including the device ID to the IoT device GW 111 of path 2 via the carrier NW 113 (S2417). The carrier NW 113 transmits the received path movement end notification to the IoT device GW 111 of path 2 (S2418).

[0114] The IoT device GW 111 of path 2 transmits a path movement end notification including the device ID to the data processing device 108 (S2419). The data processing device 108 transmits a path movement end notification to the integrated management device 102 (S2420). The device processing function 404 of the integrated management device 102 transmits a path movement end notification (S2421) to the data processing path management device 104 (S2421). The data processing path management function 702 of the data processing path management device 104 transmits a device deletion request including the device ID to the IoT device GW 111 of path 1 (S2422), and updates the device service status information 704 (S2423). Specifically, the data processing path 903 is updated to path 2, and the device status 904 is updated to normal.

[0115] When the IoT device gateway 111 on route 1 receives the device deletion request, it deletes the registration of the device (S2424).

[0116] In the message processing sequence of Figure 23 and the data processing path migration processing sequence of Figure 24, the data processing path management function 702 sends a device registration request to the IoT device GW111. However, if the IoT device GW111 itself has the function of authenticating and automatically registering the device 114 when the device 114 is connected for the first time, the device registration request (S2408) is not necessarily required.

[0117] 25 is a flowchart showing an example of a data processing path migration processing flow in the integrated management device 102. The device processing function 404 instructs the data processing path management device 104 to move the path of the device 114 (S2502). When the device processing function 404 receives an end notification from the device 114 (yes in S2503), it notifies the data processing path management device 104 of the end of the path migration (S2504) and ends the processing (S2505).

[0118] If the device processing function 404 does not receive a completion notification (no in S2503) and receives a route relocation failure notification (yes in S2506), it notifies the data processing route management device 104 of the route relocation failure and that a switchback will be performed (S2507), and displays on the management screen that the relocation process has failed and the route has been switched back (S2508).

[0119] Furthermore, if neither the route movement completion notification nor the route movement failure notification is received (no in S2506), the data processing route management device 104 is notified of the route movement processing failure (S2509), and the route movement processing failure and the connection switchback failure are displayed on the management screen (S2510).

[0120] 26 is a flowchart showing an example of a route movement process in the device 114. When the device 114 receives a route movement instruction (S2601), it disconnects the currently connected session (S2602) and transmits a connection request to the IoT device GW 111 on the destination data processing route (route 2 in this example) (S2603).

[0121] If the connection is permitted (yes in S2604), a communication session is established with the IoT device GW111 on route 2 (S2605), a route movement end notification is sent (S2606), and the route movement process is terminated (S2607).

[0122] If the connection is not permitted by the IoT device GW111 on path 2 (no in S2604), the device 114 sends a connection request to the IoT device GW111 on the original data processing path (path 1 in this example) (S2608), and upon obtaining permission for the connection (yes in S2609), the device 114 establishes a communication session with the IoT device GW111 on path 1 (S2610) and sends a path change failure notification (S2611).

[0123] Next, the failure of the route change and the current communication status (i.e., connected to route 1) are displayed (S2612). Also, if connection to route 1 is not permitted (no in S2609), the failure of the route change and the current communication status (i.e., no connection destination) are displayed (S2612).

[0124] The route migration process shown in Figures 24 to 26 enables a device to dynamically change its data processing route.

[0125] 27 shows an example of a service request processing sequence executed when a device changes services. The device 114 sends a service request including service identification information to the IoT device gateway 111 of the currently used data processing path (path 1 in this example) via the carrier network 113 (S2701). The carrier network 113 sends the received service request to the IoT device gateway 111 of path 1 (S2702).

[0126] The IoT device gateway 111 on route 1 transmits a service request including the service identification information to the integrated managing device 102 via the data processing device 108 (not shown in the figure) (S2703).

[0127] The device processing function 404 of the integrated management device 102 acquires the attribute information 503 of the requesting device from the device management device 103 and the security requirement information 1003 of the requested service from the service management device 105 (S2704). Based on the acquired device attributes, the device processing function 404 checks whether the requested service is permitted for the requesting device. If permitted (yes in S2705), the device processing function 404 compares the vulnerability level 604 of the device 114 attribute with the device vulnerability level 1106 recorded in the security requirement information 1003. If the vulnerability level of the requesting device satisfies the security requirements of the service (yes in S2706), it selects a data processing path (S2707). Note that, for multiple data processing paths, if the vulnerability level of the device 114 satisfies the security requirements of the service, the data processing path with the highest priority is selected. If the priorities are the same, a random selection may be made. Next, the device processing function 404 determines that the service provision is permitted (S2708). If the device 114 is requesting an unauthorized service (no in S2705) and the vulnerability level of the device does not meet the security requirements of the service in any of the data processing paths used by the service (no in S2706), the provision of the service is not permitted (S2709).

[0128] The device processing function 404 transmits the result of the service provision availability determination to the data processing path management device 104 (S2710), and the data processing path management device 104 transmits the received result of the service provision availability determination to the IoT device GW 111 on path 1 (S2711). The IoT device GW 111 on path 1 transmits the received result of the service provision availability determination to the device 114 via the carrier NW 113 (S2712). The carrier NW 113 transmits the received result of the service provision availability determination to the device 114 (S2713).

[0129] If the determination as to whether the service can be provided is permitted (yes in S2714), the device 114 waits for an instruction from the integrated managing device 102 and performs data processing path migration processing (S2719). If the determination as to whether the service can be provided is not permitted (no in S2714), the device 114 notifies the operator by displaying a message on the screen or the like (S2715) and ends the processing (S2716).

[0130] If the result of the service provision determination is not permitted (no in S2717), the device processing function 404 ends the processing (S2718). If the result of the service provision determination is permitted (yes in S2717), the device processing function 404 performs a route movement process for the device 114 to the data processing route selected in step S2707 (S2719). Note that in cases where the route movement process (S2719) is triggered by a service request from the device, as in this sequence, the device processing function 404 also transmits identification information of the service requested by the device 114 when transmitting a route movement completion notification (S2421) to the data processing route management device 104.

[0131] Next, in a case where a change to the destination address restriction is required (i.e., either Route 1 or Route 2 has the destination address restriction function) (yes in S2720), the carrier interoperation function 402 of the integrated managing device 102 notifies the carrier of the SIM ID of the device 114 and the IP address information of the destination IoT device GW 111, and requests the carrier to start, cancel, or change the destination IP address restriction (S2721). For example, if the carrier provides an API for device management, the carrier interoperation function 402 uses the API to request the carrier to start, cancel, or change the destination IP address restriction in the carrier network. For example, the carrier's device management API receives the request and starts, cancels, or changes the destination IP address restriction of the target SIM.

[0132] In addition, when comparing the vulnerability level 604 of the device 114 with the device vulnerability level 1106 in the security requirements of the service, in a case where the service can be received by registering the device 114 as a protected device, the device 114 may be temporarily registered as a protected device until the vulnerability is corrected.

[0133] Although omitted in the sequence diagram of Figure 27, for example, in a case where an asset 115 is connected to a device 114, a service request may be generated by an operator operating the asset 115, the service request may be sent from the asset 115 to the device 114, and the service request received by the device 114 may be sent to the IoT device GW111 on path 1.

[0134] According to this embodiment configured as described above, in the information processing system 101 connected to a plurality of devices 114, it is possible to dynamically and automatically select and use the data processing path 201 according to the combination of the vulnerability level 604 of the device 114 and the security requirement information 1003 of the service, and it is possible to use the data processing path 201 having the appropriate security function in accordance with changes in the device status (i.e., updates to the vulnerability level due to the implementation of security measures, and changes in the service being used). This makes it possible to simplify the operation and management even for a large number of devices.

[0135] Additionally, by using carrier functions to restrict the IP addresses to which devices can be connected, it is possible to protect older devices that cannot be protected against vulnerabilities from external attacks. Also, by blocking external connections when remotely controlling a device, it is possible to prevent unauthorized control from the outside, enabling stronger protection for the device. [Example]

[0136] In this embodiment, an example of a procedure for reviewing a data processing path in response to an update of a security requirement for a service will be described.

[0137] FIG. 28 is a flowchart showing an example of a processing flow when the data processing path 201 is reviewed in accordance with an update of the security requirement information 1003 of the service.

[0138] The administrator selects the service to be edited from the registered service list screen 2001, edits the security requirements of the service (i.e., the device attributes 1103 and / or the required security functions 1107) on the service edit screen 2014 (S2802), and presses the data path selection button 2019 to reselect the data processing path 201 (S2803).

[0139] Next, the data processing path management function 702 of the data processing path management device 104, triggered by the reselection of the data processing path, refers to the data processing path attribute information 703 and recalculates the data processing path of each device 114 (here, the data processing path selected by the recalculation is referred to as a data processing path candidate) (S2804), and extracts devices 114 that require a change of data processing path (S2805). Devices 114 that require a change of data processing path are devices 114 whose currently used data processing path 903 and a data processing path candidate differ in the device service status information 704, and devices 114 for which no data processing path candidate exists. Next, the data processing path management function 702 instructs devices 114 for which a data processing path candidate exists to move to the data processing path candidate (S2806).

[0140] Next, the data processing path management function 702 extracts, from the devices 114 for which no data processing path candidates exist, devices 114 that are using a service that can provide service to a protected device and that can be registered as a protected device (S2807), performs protected device registration (S2808), and instructs path migration to the data processing path for the protected device (S2808). Whether or not a protected device can be registered is registered in advance in the device attribute information 503 as, for example, a device attribute.

[0141] Next, the data processing path management function 702 instructs the device 114 that could not be relocated to end the service and move to the path for initial connection (S2810), and ends the processing (S2811).

[0142] For example, the service registration function 1001 of the service management device 105 may periodically check information such as firmware and security patches provided by companies and automatically update the security requirement information 1003 a certain period of time after the firmware and security patch are provided. For example, when an important security patch is released, the timing of updating the security requirement information 1003 may be accelerated depending on the level of importance. Furthermore, the automatic update of the security requirement information 1003 of the service may be used as a trigger to perform a review process of the data processing path. This makes it possible to automatically review the data processing path of the device 114 and move the path when the security requirement information 1003 of the service is updated.

[0143] Furthermore, for example, when devices requiring a change in data processing path are extracted in step S2805, a list of the extracted devices may be displayed on the management screen, and the administrator may check the list before proceeding with the subsequent processing.

[0144] 29 shows an example of a data processing path update screen 2901 when manually instructing the movement of a data processing path. The data processing path management function 702 displays a list 2902 of devices 114 whose data processing paths require movement on the data processing path update screen. The administrator selects a device 114 and issues instructions for movement to a data processing path candidate, protection device registration, and service termination. For example, after selecting a device and registering it as a protection device, it is also possible to press the data path reselection button to calculate a new data processing path and instruct the movement of the path to the data processing path candidate.

[0145] Also, for example, it may be possible to select whether to automatically or manually review the data processing path associated with the update of service requirement information for each service. Furthermore, it may be possible to set the system so that some of the review is performed automatically and the rest is performed manually, for example, by automatically moving the path for devices for which a data processing path candidate exists and manually processing for devices for which no data processing path candidate exists. The automatic or manual setting for the data processing path review process may be registered when registering or editing a service and recorded in the security requirement information 1003.

[0146] Furthermore, the review of the data processing path may be performed in conjunction with vulnerability countermeasures for the device 114. The vulnerability management function 502 periodically checks information such as firmware and security patches provided by companies, and if, for example, firmware or security patches are provided, instructs the registered device 114 to update the firmware or apply the security patch. When the device 114 updates the firmware or applies the security patch in response to these instructions, it notifies the vulnerability management function 502 of the changed attributes, and the vulnerability management function 502 updates the device attribute information 503. The update of the device attribute information 503 triggers the data processing path management function 702 to review the data processing path of the device 114, and if a data processing path with a higher priority can be used, the path may be changed.

[0147] In addition, security functions may be added or removed from existing data processing paths. For example, in a case where an unknown attack is detected and anomaly detection functions need to be strengthened across the entire information processing system, an anomaly detection function or an intrusion prevention function may be added to an existing data processing path. Furthermore, after a security patch is provided and applied to all devices in service, the added security function may be removed to return to the original state.

[0148] Furthermore, for example, in a case where a data processing path is assigned to a specific service, when the security requirements of the service change, security functions of the data processing path may be added or deleted in accordance with the security requirements of the service.

[0149] In this embodiment, in response to updates to the vulnerability level of the device, changes to the services used by the device, updates to the security requirements of the services, changes in the status of the information processing system, and the acquisition of new security information from outside, the data processing path to be used by the device is reselected and moved to the reselected data processing path so as to satisfy the conditions required by the device attribute information 503, data processing path attribute information 703, device service status information 704, and security requirement information 1003 that reflect the changes.

[0150] According to this embodiment, it is possible to dynamically change the data processing path used by a device in response to updates to the security requirements of the service and updates to the vulnerability level of the device. It is also possible to change the security functions of the data processing path. This makes it possible to easily provide the necessary security functions in accordance with the security requirements of the service and the vulnerabilities of the device, even when providing a service to a large number of devices. [Example]

[0151] In this embodiment, processing for a device 114 in which an abnormality has been detected is shown. The intrusion prevention function 1203 of the security device 106 analyzes, for example, messages sent and received between the IoT device gateway 111 and the data processing device 108, and upon detecting an unauthorized or abnormal message, deletes the message, and the alert function 1204 notifies the integrated managing device 102 of the device ID and the type of abnormality. The abnormality detection function 1202 analyzes, for example, data received from the device 114, and upon detecting an abnormality or unauthorized action, the alert function 1204 notifies the integrated managing device 102 of the device ID and the type of abnormality. The content of the notification to the integrated managing device 102 may include identification information of the asset 115.

[0152] Methods for detecting anomalies and fraud include, for example, a method of detecting a message that matches a pre-registered signature by matching it with the signature and determining that the message is fraudulent. Other methods include, for example, detection methods using outlier detection and change-point detection through machine learning, and anomaly detection methods using threshold judgment. It is also possible to select one or more items to be analyzed, such as the frequency of message reception, message size, or data value, and use these methods to detect anomalies. For example, a combination of these functions may be used, such as the intrusion prevention function 1203 performing fraud detection by matching with a signature and the anomaly detection function 1202 performing change-point detection or threshold detection.

[0153] Furthermore, in the data processing path attribute information 703 and the service security requirement information 1003, three security functions are listed as examples: intrusion prevention, anomaly detection, and destination address restriction. However, by further detailing the security functions 805 and 1007, it is also possible to record them for each analysis method.

[0154] In addition, two or more analysis methods for intrusion prevention and anomaly detection may be provided in a data processing path. A service does not necessarily need to apply all of the anomaly detection methods provided by the data processing path, and may specify the required analysis method. Data processing path attribute information 703 records security functions 805 that can be provided for each data processing path, and analysis is performed according to the required security functions 1007 specified in security requirement information 1003 of the service. In addition, if a service has its own anomaly detection method, it may use this.

[0155] In addition, for example, a firewall and DDoS attack countermeasures may be installed in the IoT device GW 111. In addition, for example, these security functions may be realized by using a service provided by a cloud provider.

[0156] FIG. 30 is a flowchart showing an example of a processing flow when an abnormality is detected.

[0157] When the alert processing function 403 of the integrated managing device 102 receives an alert (S3001), it queries the data processing path managing function 702 and acquires the name of the service being used by the device 114.

[0158] Next, if the service being used by the device 114 is remote operation (yes in S3002), the alert processing function 403 instructs the device 114 to degrade the remote operation (that is, switch back to manual operation) (S3003).

[0159] Next, the alert processing function 403 analyzes the anomaly detection information (S3004), and if the detected anomaly is an increase in data volume, it sends an instruction to the device 114 to cut off communication with the asset 115 (S3005). Also, if the detected anomaly is fraud detected by pattern matching using a signature (for example, a virus, buffer overflow attack, SQL injection attack, cross-site scripting attack, etc.), the carrier cooperation function 402 uses an API provided by the carrier to suspend the SIM (S3006).

[0160] Next, the alert processing function 403 notifies the administrator of the occurrence of the abnormality (S3007). For example, the device ID, the type of abnormality, and the processing performed on the device may be displayed on the management screen 1801. This flowchart is an example of processing when an abnormality is detected, and a different processing flow may be defined for each service, for example.

[0161] When an abnormality is detected, any action such as data deletion, communication suspension, service degradation, service termination, SIM suspension, and speed restriction on the SIM, or a combination of these, may be performed on the device in which the abnormality is detected.

[0162] When an alert is received, the content of the alert may be displayed on the management screen 1801, and the administrator may manually instruct how to deal with the device in which the abnormality was detected. Alternatively, automatic processing or manual processing may be selected in advance for each service, and the administrator may handle services that require individual handling.

[0163] In addition to sending an alert to the integrated managing device 102, the alert function 1204 may also send an alert to a mobile terminal owned by the administrator, for example, by using an email or an alert application.

[0164] According to this embodiment, when an abnormality is detected in a device, the process can be automatically executed, which makes it easier to manage and operate a large number of devices. Also, by allowing manual processing to be selected, flexible responses can be made according to the impact of an abnormality occurring for each service. [Example]

[0165] This embodiment shows the process when abnormalities are detected in a large number of devices within a certain period of time. When a large number of abnormal devices are detected in a data processing path, available data processing paths are reselected for normal devices currently using the data processing path based on the attributes of each normal device and the security requirements of the service, excluding the data processing paths currently in use, and the data processing paths are then moved from the currently used data processing paths to the newly selected data processing paths.

[0166] It also has the function of creating a new data processing path and setting the necessary security functions when a large number of abnormal devices are detected in the data processing path, and the function of moving normal devices to the created data processing path.

[0167] FIG. 31 is a flowchart showing an example of a processing flow in units of data processing paths when an abnormal device is detected.

[0168] When the number of abnormal devices detected within a certain period of time in each data processing path exceeds a predetermined threshold (S3101), the alert processing function 403 of the integrated managing device 102 verifies whether or not there is a bias in the attributes of the abnormal devices (for example, device type 603, firmware version 606, and security patch 607) (S3102). For example, if there is a bias, such as many abnormalities detected in devices of a particular type, or abnormalities detected in devices with old firmware versions or devices with unupdated security patches (yes in S3102), the alert processing function 403 extracts devices with the same attributes as the devices in which many abnormalities were detected as candidate abnormal devices (S3103).

[0169] If the ratio of devices in which an abnormality has been detected and devices that are considered to be abnormal device candidates exceeds a predetermined threshold (yes in S3104), the alert processing function 403 performs a backup process for normal devices (i.e., devices that are neither abnormal devices nor abnormal device candidates) (S3105).

[0170] Next, the vulnerability management function 502 instructs the implementation of security measures for candidate abnormal devices for which security measures have not been implemented (old firmware version or security patch not applied). If a device for which security measures have been implemented has already been registered, the vulnerability level 604 of the device attribute information 503 is updated (S3106). The alert processing function 403 performs normal device evacuation processing for devices whose vulnerability level 604 has been updated by the implementation of security measures and which are no longer candidate abnormal devices (S3107).

[0171] 32 is a flowchart showing an example of a processing flow for saving a normal device. The data processing path selection function 1002 references the data processing path attribute information 703 and checks whether there is a data processing path that has security functions at the same level or higher than the data processing path to be processed (i.e., has all the security functions that the data processing path to be processed has) (S3202).

[0172] If a data processing path of the same level or higher exists (yes in S3202), the path is recalculated for each service excluding the data processing path to be processed (S3203), and the security requirement information 1003 is updated (S3203). Next, the data processing path management function 702 recalculates the data processing paths of the normal device group based on the security requirement information 1003 and the device attribute information 503 (S3204). Next, the alert processing function 403 instructs the normal device group to move to the candidate data processing path (S3205).

[0173] If there is no data processing path with security functions at the same level or higher than the data processing path to be processed (no in S3202), the administrator creates a new data processing path and installs the necessary security functions (S3207). Next, the administrator registers the newly created data processing path (S3208) and instructs normal devices to move to the newly created data processing path (S3209).

[0174] In order to accommodate a large number of devices, in a system having two or more data processing paths with the same level of security functions, step S3023 of this processing flow becomes "yes," and normal devices can be automatically evacuated. Note that the recalculation of the data processing path for normal devices (S3204) and the instruction to move the path to the normal device (S3205) may be performed in parallel for two or more devices, and the path may be moved sequentially starting from the device for which the recalculation is completed.

[0175] Furthermore, a new data processing path may be established and all normal devices may be migrated to the newly established data processing path without checking whether or not there is a data processing path with the same level of security functions as the target data processing path (S3202).Furthermore, while migrating normal devices that can use existing data processing paths, a new data processing path may be established in parallel and normal devices that could not be migrated to the existing data processing path may be migrated to the newly established data processing path.

[0176] According to this embodiment, in an IoT system, security functions can be adjusted according to the vulnerability of devices and the security requirements of services, thereby ensuring system security and facilitating the management of a large number of devices. In particular, when an abnormality occurs in a large number of devices, normal devices can be quickly evacuated, and the impact of the abnormal device on the normal devices can be prevented.

[0177] The present invention has been specifically described above based on the embodiments, but the present invention is not limited to the above-described embodiments and various modifications are possible within the scope of the gist of the present invention. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, some of the configurations of the above-described embodiments may be added to, deleted from, or replaced with other configurations.

[0178] In addition, the control lines and information lines in each diagram are those that are considered necessary for explanation, and do not necessarily show all the control lines and information lines in the actual implementation. For example, it may be considered that almost all components are actually connected to each other.

[0179] Furthermore, the above-described embodiments may be implemented independently, or some or all of them may be combined and implemented.

[0180] In the above description, the components (e.g., each function, database, element step, etc.) are not necessarily essential unless otherwise specified or considered to be clearly essential. Furthermore, each function, database, etc. may be provided in a device different from the device described in the embodiment. Furthermore, a configuration different from this embodiment may be adopted, such as dividing a function and executing it in separate devices, or dividing and recording a database.

[0181] Furthermore, the data recorded by each information processing device may include more or fewer items than those shown in the examples. Furthermore, while a table representation is used as an example of each piece of data, this does not limit the method of recording each piece of data to a table format; various methods, such as a list or chain, may be used to record data. Furthermore, the recorded elements may be expressed in various forms, such as numbers, symbols, or mathematical formulas.

[0182] According to the above embodiment, efficient data collection and control of IoT devices becomes possible, which reduces energy consumption, reduces carbon emissions, prevents global warming, and contributes to the realization of a sustainable society. [Explanation of symbols]

[0183] 101: Information processing system, 102: Integrated management device, 103: Device management device, 104: Data processing path management device, 105: Service management device, 106: Security device, 109: Application device, 111: IoT device GW, 113: Carrier NW, 114: Device, 115: Asset, 201: Data processing path

Claims

1. A data processing path management system for an information processing system including an information processing resource and a data transmission / reception path, the system having a function for the information processing resource to receive data via the data transmission / reception path from a device connected via a network, and a function for providing a service by the information processing resource, the information processing resource and the data transmission / reception path being logically or physically divided into a plurality of data processing paths, and each of the data processing paths having a different security function, the system controlling the data processing path, an information processing device manages security requirement information that associates the required security functions with combinations of the service and the device attributes, and selects the data processing path based on the security requirement information; A data processing path management device is provided, the data processing path management device instructs the device to switch from a first data processing path to a second data processing path based on the selected data processing path; Data processing route management system.

2. the security requirement information includes vulnerability information of the device as an attribute of the device; 2. The data processing path management system according to claim 1.

3. managing data processing path attribute information that associates the available security functions with the data processing paths; 3. The data processing path management system according to claim 2.

4. managing device attribute information that associates the vulnerability information with the available services for the device; selecting the data processing path based on the security requirement information when at least one of the device attribute information, the data processing path attribute information, and the security requirement information is changed; 4. The data processing path management system according to claim 3.

5. Equipped with an integrated management device, When the number of abnormal devices detected within a certain period of time in any of the data processing paths exceeds a threshold, the integrated management device designates the data processing path as a target data processing path and extracts candidate abnormal devices based on a bias in the attributes of the abnormal devices; instructing the devices other than the abnormal device and the candidate abnormal device that use the target data processing path to switch to a data processing path other than the target data processing path; 5. The data processing path management system according to claim 4.

6. The integrated management device selecting a data processing path other than the target data processing path from among data processing paths that can use all of the security functions available to the target data processing path; 6. The data processing path management system according to claim 5.

7. The integrated management device When the vulnerability information corresponding to the abnormal device candidate is updated in the device attribute information, an instruction is given to the abnormal device candidate to switch to a data processing path other than the target data processing path.

7. The data processing path management system according to claim 6.

8. A data processing path management method for an information processing system including an information processing resource and a data transmission / reception path, the information processing resource having a function of receiving data via the data transmission / reception path from a device connected via a network, and a function of providing a service by the information processing resource, the information processing resource and the data transmission / reception path being logically or physically divided into a plurality of data processing paths, and each of the data processing paths having a different security function, the method comprising: the information processing device manages security requirement information that associates the necessary security functions with combinations of the service and vulnerability information of the device, which is an attribute of the device, and selects the data processing path based on the security requirement information; Data processing path management method.

9. the information processing device instructs the device to switch from the first data processing path to the second data processing path based on the selected data processing path; 9. The data processing path management method according to claim 8.

10. the information processing device manages data processing path attribute information that associates the available security functions with the data processing paths; 10. The data processing path management method according to claim 9.

11. an information processing device manages device attribute information that associates the vulnerability information with the available services for the device; an information processing device, triggered by a change in at least one of the device attribute information, the data processing path attribute information, and the security requirement information, selecting the data processing path based on the security requirement information; 11. The data processing path management method according to claim 10.

12. When the number of abnormal devices detected within a certain period of time in any of the data processing paths exceeds a threshold, the information processing device designates the data processing path as a target data processing path, and extracts candidate abnormal devices based on a bias in the attributes of the abnormal devices; the information processing device instructs the devices other than the abnormal device and the candidate abnormal device that use the target data processing path to switch to a data processing path other than the target data processing path; 12. The data processing path management method according to claim 11.

13. the information processing device selects a data processing path other than the target data processing path from among data processing paths that can use all of the security functions that can be used by the target data processing path; 13. The data processing path management method according to claim 12.

14. when the vulnerability information corresponding to the abnormal device candidate is updated in the device attribute information, the information processing device instructs the abnormal device candidate to perform a path change to switch to a data processing path other than the target data processing path.

14. The data processing path management method according to claim 13.

Citation Information

Patent Citations

  • Security management system and route designation program

    JP2003174483A

  • Secure communication system and communication path selecting device

    JP2006180280A

  • Method of controlling network connection, program, and computer

    JP2009064128A

  • Security server system

    JP2011258018A

  • Communication system, control device, gateway, communication control method, and program

    JP2019083478A