Network system, communication control device, communication control method, and program

The network system with a terminal identification device addresses the challenge of identifying IoT devices via mobile routers by using ARP and NAPT tables to manage their connectivity, ensuring secure connections to the backbone network.

JP7789629B2Active Publication Date: 2025-12-22HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2022101778
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-24
Publication Date
2025-12-22
Estimated Expiration
2042-06-24

AI Technical Summary

Technical Problem

Existing methods for identifying IoT devices connecting to a local 5G network via a mobile router fail to accurately identify these devices due to address translation functions, which obscure the source IP addresses, making it difficult to control their connectivity to a backbone network.

Method used

A network system with a terminal identification device that acquires and updates address information from a mobile router, using ARP and NAPT tables to associate IoT device identifiers with their translated addresses, enabling identification and control of connectivity to the backbone network.

Benefits of technology

Enables accurate identification and management of IoT devices connecting through mobile routers, ensuring secure connectivity to the backbone network by determining whether each device can connect based on updated address information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007789629000001
    Figure 0007789629000001
  • Figure 0007789629000002
    Figure 0007789629000002
  • Figure 0007789629000003
    Figure 0007789629000003
Patent Text Reader

Abstract

To identify IoT apparatuses to control whether connection to a backbone network is permitted for each apparatus.SOLUTION: A network system in which data is transferred includes: a terminal identification device that determines whether to permit a terminal to connect to a second network; and a gateway device that converts address information provided to data that is transferred between a first network and a third network. The terminal identification device holds terminal identification information in which address information of the gateway device in the first network, an identifier of the terminal, and whether to permit the terminal to connect to the second network are associated with each other; determines whether to permit the terminal to connect to the second network on the basis of the terminal identification information; and obtains the address information of the gateway device in the first network and the identifier of the terminal from the gateway device, and registers or updates the terminal identification information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a network system, and more particularly to a method for identifying and managing communication terminals. [Background technology]

[0002] Local 5G, which was institutionalized in December 2019, offers the advantage of being faster, less latency-intensive, and more secure than Wi-Fi, allowing for flexible construction of wireless communication infrastructure. It is expected to be utilized in various industries, including manufacturing, logistics, and buildings, as a stable wireless communication infrastructure to replace Wi-Fi. In recent years, particularly in the manufacturing sector, interest has been growing in aggregating data acquired by IoT devices such as sensors and cameras in each factory into a core system within the core network, with the aim of monitoring and optimizing manufacturing processes through factory-wide equipment management. This has led to a demand for interconnection between each factory's local 5G network and the core network. IoT devices have limited hardware resources, making it difficult to implement adequate security measures, making them vulnerable. Therefore, to reduce security risks to the core network during interconnection, it is necessary to control whether each IoT device can connect to the core network.

[0003] There are two ways for IoT devices to connect to a local 5G network: directly connecting to the local 5G network, or connecting via a mobile router with address translation functionality. When interconnecting a local 5G network with a backbone network, it is necessary to identify IoT devices connected by these connection methods in order to control whether or not each IoT device can connect.

[0004] To identify IoT devices, for example, a terminal identification device can be installed at the connection interface between the local 5G and the backbone network, and the local 5G network administrator can input and manage the correspondence between the IoT device identifier (e.g., ID, fixed IP address, MAC address) and packet header information into the terminal identification device in advance. The terminal identification device can then search a correspondence table using the header information of the received packet to obtain the IoT device identifier and identify the IoT device.

[0005] The following prior art exists as background technology in this technical field. Non-Patent Document 1 describes a terminal identification device installed between a local 5G network that transfers packets using IP at Layer 3 of the OSI model and a backbone network that transfers packets using MAC at Layer 2 of the OSI model in an interconnection between the local 5G network and the backbone network. The terminal identification device associates the local 5G-side IP, backbone network-side MAC, and backbone network-side IP of an IoT device and stores them as a table. Before communication, the terminal identification device receives authentication from an authentication mechanism in the backbone network using the backbone network-side MAC entered by the network administrator. If authenticated, the terminal identification device obtains the backbone network-side IP from the DHCP server and updates the table. For each packet transferred from the local 5G network to the backbone network, the terminal identification device identifies the IoT device by the source IP. If the IoT device is authenticated, the terminal identification device converts the source of the packet from the local 5G-side IP to the backbone network-side IP and forwards it to the backbone network. If the IoT device is not authenticated, the terminal identification device discards the packet. This makes it possible to identify IoT devices and control whether or not they can connect to the backbone network when IoT devices connect directly to a local 5G network. [Prior art documents] [Non-patent literature]

[0006] [Non-Patent Document 1] Y.Oishi et al, IEICE Communications Express 10,888 (2021) Summary of the Invention [Problem to be solved by the invention]

[0007] The background art described above focuses on a method in which an IoT device directly connects to a local 5G network, and identifies the IoT device based on the source IP address of the packet at the connection interface. However, it does not consider identifying the IoT device when the IoT device connects to the local 5G network via a mobile router. When an IoT device connects to the local 5G network via a mobile router, the address translation function of the mobile router translates the source IP address and port number of the packet from the IP address and port number of the IoT device accommodated within the network to the IP address and port number of the mobile router. Therefore, when an IoT device connects to the local 5G network via a mobile router, the terminal identification device at the connection interface cannot identify the IoT device based on the source IP address.

[0008] Therefore, the present invention provides a technology in which, when an IoT device connects to a backbone network via an address translation function, a terminal identification device at the connection interface acquires and updates address information for identifying the IoT device from a device having an address translation function, thereby identifying the IoT device and controlling whether or not each device can connect to the backbone network. [Means for solving the problem]

[0009] A representative example of the invention disclosed in the present application is as follows: That is, a network system for transferring data, comprising a first network, a second network connected to the first network and to which a server is connected, and a network device connected to the first network. Included in a third network accommodating terminals having address information different from that of the first network; logically located between the first network and the second network;a terminal identification device that determines whether the terminal is allowed to connect to the second network; and a gateway device that converts address information attached to data transferred between the first network and the third network, wherein the gateway device converts address information of the gateway device in the first network that is attached to data transferred from the first network to the third network into address information of the terminal in the third network, and fart The address information of the terminal in the third network attached to the data to be transferred is converted into address information of the gateway device in the first network, and the terminal identification device holds terminal identification information that associates the address information of the gateway device in the first network, an identifier of the terminal, and whether the terminal can be connected to the second network, determines whether the terminal can be connected to the second network based on the terminal identification information, and obtains the address information of the gateway device in the first network and the identifier of the terminal from the gateway device to register or update the terminal identification information. [Effects of the Invention]

[0010] According to one aspect of the present invention, it is possible to control whether or not each IoT device under the control of a gateway device can connect to another network. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiment. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 illustrates an example of the configuration of a network system according to a first embodiment. [Figure 2] 1 is a diagram illustrating an example of the configuration of a terminal identification device according to a first embodiment. [Figure 3] FIG. 2 is a diagram illustrating a configuration example of a mobile router according to a first embodiment. [Figure 4] FIG. 10 is a diagram illustrating an example of the configuration of a mobile router management table according to the first embodiment. [Figure 5]FIG. 10 is a diagram illustrating an example of the configuration of a connection permission management table according to the first embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of the configuration of an IoT device identification table according to the first embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of a configuration of a routing table according to the first embodiment. [Figure 8] FIG. 2 is a diagram illustrating an example of the configuration of an ARP table according to the first embodiment. [Figure 9] FIG. 2 is a diagram illustrating an example of the configuration of a NAPT table according to the first embodiment. [Figure 10] FIG. 10 is a sequence diagram of an example of an address information update process for an IoT device accommodated by a mobile router according to the first embodiment. [Figure 11] FIG. 10 is a sequence diagram illustrating an example of an address information update process for an IoT device according to the first embodiment. [Figure 12] 10 is a flowchart illustrating an example of an address information update process according to the first embodiment. [Figure 13] 10A and 10B are diagrams illustrating changes in the mobile router management table, the connection permission management table, and the IoT device identification table when an address information update process is executed for an IoT device accommodated by the mobile router of the first embodiment. [Figure 14] 10A and 10B are diagrams illustrating changes in a mobile router management table, a connection permission management table, and an IoT device identification table when an address information update process is executed for an IoT device of the first embodiment. [Figure 15A] FIG. 10 is a diagram illustrating an example of a user interface used in the address information update process according to the first embodiment. [Figure 15B] FIG. 10 is a diagram illustrating an example of a user interface used in the address information update process according to the first embodiment. [Figure 16] FIG. 10 is a sequence diagram of an example of an IoT device identification process for an IoT device accommodated by a mobile router according to the first embodiment. [Figure 17] FIG. 10 is a sequence diagram of an example of an IoT device identification process for an IoT device according to the first embodiment. [Figure 18] 10 is a flowchart illustrating an example of an IoT device identification process including an address information update process according to the first embodiment. [Figure 19] 10 is a flowchart illustrating an example of an IoT device identification process according to the first embodiment. [Figure 20] FIG. 10 is a diagram illustrating an example of a network system configuration according to a second embodiment. [Figure 21] FIG. 10 is a diagram illustrating an example of the configuration of a terminal identification device 1 according to a second embodiment. [Figure 22] FIG. 10 is a diagram illustrating an example of the configuration of an IoT device identification table according to the second embodiment. [Figure 23] FIG. 10 is a sequence diagram of an example of an IoT device authentication process according to the second embodiment. [Figure 24] 10 is a flowchart illustrating an example of an IoT device authentication process according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Example 1 In the following description, "memory" refers to one or more memory devices, which are an example of one or more storage devices, and may typically be a primary storage device. At least one memory device in the memory may be a volatile memory device or a non-volatile memory device.

[0013] In the following description, a "non-transitory storage device" may refer to one or more non-transitory storage devices, which are an example of one or more storage devices. The non-transitory storage device may typically be a non-volatile storage device (e.g., an auxiliary storage device), and specifically, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), NVMe (Non-Volatile Memory Express) drive or SCM (Storage Class Memory) is acceptable.

[0014] Also, in the following description, "storage device" may refer to either memory or non-transitory storage device.

[0015] In the following description, a "processor" may refer to one or more processor devices. The at least one processor device may typically be a microprocessor device such as a CPU (Central Processing Unit), but may also be another type of processor device such as a GPU (Graphics Processing Unit). The at least one processor device may be a single-core or multi-core. The at least one processor device may also be a processor core. The at least one processor device may be With hardware description language It may also be a broad processor device such as a circuit that is a collection of gate arrays that perform some or all of the processing (for example, an FPGA (Field-Programmable Gateway Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)).

[0016] In the following description, information that provides an output for an input may be described using expressions such as "xxx table." However, this information may be data of any structure (for example, structured data or unstructured data), or may be a learning model such as a neural network, genetic algorithm, or random forest that generates an output for an input. Therefore, the "xxx table" may be referred to as "xxx information." In the following description, the structure of each table is an example, and one table may be divided into two or more tables, or all or part of two or more tables may be one table.

[0017] In the following description, functions are sometimes described using the expression "yyy unit." However, the functions may be realized by one or more computer programs executed by a processor, by one or more hardware circuits (e.g., FPGAs or ASICs), or by a combination thereof. When a function is realized by a program executed by a processor, the specified processing is performed using a storage device and / or a communication device, etc., as appropriate, and therefore the function may be considered to be at least a part of the processor. Processing described using a function as the subject may be processing performed by a processor or a device having the processor. A program may be installed from a program source. The program source may be, for example, a program distribution computer or a computer-readable recording medium (e.g., a non-transitory recording medium). The description of each function is an example; multiple functions may be combined into one function, or one function may be divided into multiple functions.

[0018] FIG. 1 is a diagram illustrating an example of the configuration of a network system according to a first embodiment.

[0019] The network system of Example 1 illustrated in FIG. 1 includes a backbone network 3, a local 5G network 2, and a terminal identification device 1 installed between the backbone network 3 and the local 5G network 2. The terminal identification device 1 may be installed logically between the backbone network 3 and the local 5G network 2 at a position through which packets transferred between the backbone network 3 and the local 5G network 2 pass. The local 5G network 2 and the backbone network 3 are networks that transfer packets using IP (Internet Protocol) at Layer 3 of the OSI model. The terminal identification device 1 identifies source IoT devices 24 accommodated by a mobile router and IoT devices 22 not accommodated by a mobile router based on header information such as the IP address and port number of packets transferred from the local 5G network 2 to the backbone network 3, and controls whether or not the packets can be connected to the backbone network 3. The IP address is an address used at Layer 3 of the OSI model, and the port number is identification information used at Layer 4 of the OSI model. A setting terminal 4 is connected to the terminal identification device 1. The setting terminal 4 accepts setting input from the network administrator, and registers the local 5G side IP (local 5G side IP 150) of the mobile router 21 used in the local 5G network 2 in the mobile router management table 15 of the terminal identification device 1. The setting terminal 4 also accepts setting input from the network administrator, and registers identifiers (IoT device identifiers 160) such as the IP addresses and MAC addresses of IoT devices 24 accommodated by the mobile router and IoT devices 22 not accommodated by the mobile router that are permitted to connect to the backbone network 3 in the connection permission management table 16 of the terminal identification device 1. The configurations of the mobile router management table 15 and the connection permission management table 16 will be described later with reference to FIGS. 4 and 5.

[0020] The local 5G network 2 includes a mobile router 21, an IoT device 22 not accommodated by the mobile router, a LAN network 23 of the mobile router 21, an IoT device 24 accommodated by the mobile router, a base station device 25, and a mobile core device 26. The mobile router 21 and the IoT device 22 have an interface with the local 5G network 2 and connect to the base station device 25 via a local 5G wireless line. The mobile core device 26 has a function of authenticating the mobile router 21 and the IoT device 22 based on identification information (e.g., IMSI) assigned to the inserted SIM card, assigning an IP address (local 5G-side IP address) to be used in the local 5G network 2, session management, traffic aggregation, and the like, thereby controlling the local 5G network 2. The mobile router 21 and the IoT device 22 connect to the local 5G network 2 using the local 5G-side IP address assigned by the mobile core device 26.

[0021] The mobile router 21 has a NAPT conversion function, and converts the source IP address and source port number of a packet sent from an IoT device 24 accommodated by the mobile router from the IP address and port number of the IoT device 24 accommodated by the mobile router to the IP address and port number of the mobile router 21. The IoT device 24 accommodated by the mobile router connects to the LAN network 23 of the mobile router 21. By using the NAPT conversion function of the mobile router 21, multiple IoT devices 24 accommodated by the mobile router can connect to the local 5G network 2 using the local 5G side IP address of the mobile router 21.

[0022] The backbone network 3 includes a remote site 32 including a backbone network server 33, and an intranet 31. The intranet 31 is configured, for example, by IP-VPN or wide area Ethernet, and connects the local 5G network 2 and multiple remote sites 32. The remote site 32 is a site where a network connecting to the intranet 31 is installed, and the backbone network server 33 is a server connected to the backbone network 3. For example, the remote site 32 may be a data center, and the backbone network server 33 may be an execution server of a production management system.

[0023] FIG. 2 is a diagram illustrating an example of the configuration of the terminal identification device 1 according to the first embodiment.

[0024] The terminal identification device 1 of Example 1 has multiple types of physical hardware resources such as a local 5G side interface 10, an IoT device identification unit 11, a backbone network side interface 12, a storage device 6, and a processor 7 connected to them.

[0025] Data is sent and received through each interface 10, 12, and 18. The storage device 6 stores a mobile router management table 15, a connection permission management table 16, and an IoT device identification table 17. These tables 15, 16, and 17 are tables in which the terminal identification device 1 stores and deletes information. The processor 7 executes a program in the storage device 6 to realize an address information update unit 13, an IoT device identification unit 11, and a control unit 14. The processor 7 includes an arithmetic unit such as one or more CPU cores, and executes predetermined programs.

[0026] The local 5G side interface 10 is an interface that connects the terminal identification device 1 to the local 5G network 2. The backbone network side interface 12 is an interface that connects the terminal identification device 1 to the backbone network 3. The setting interface 18 is an interface that connects the terminal identification device 1 to the setting terminal 4.

[0027] The IoT device identification table 17 holds address information such as IP addresses and port numbers for identifying the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router, identifiers for identifying the IoT devices 22, 24, and information on whether or not the device can be connected to the backbone network 3. The IoT device identification table 17 is registered by the address information update process of the terminal identification device 1. The configuration of the IoT device identification table 17 will be described later with reference to FIG. 6 . The IoT device identification unit 11 searches for address information such as the IP address and port number in the IoT device identification table 17, which is header information such as the source IP address and source port number of a packet transferred from the local 5G network 2 to the backbone network 3, to identify the source IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router. If the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router can be connected to the backbone network 3, the IoT device identification unit 11 forwards the packet to the backbone network server 33, and if the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router cannot be connected to the backbone network 3, the IoT device identification unit 11 discards the packet. In addition, packets forwarded from the backbone network 3 to the local 5G network 2 undergo header processing before being forwarded to the local 5G network 2.

[0028] The mobile router management table 15 holds information for managing the mobile routers 21 used in the local 5G network 2. The connection permission management table 16 holds information for controlling whether the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router can connect to the backbone network 3. The mobile router management table 15 and the connection permission management table 16 are set from the setting terminal 4 based on settings input by the network administrator via the user interface 40 (see FIG. 10 ). The configurations of the mobile router management table 15 and the connection permission management table 16 will be described later with reference to FIGS. 4 and 5 . The address information update unit 13 references the mobile router management table 15, requests the NAPT table 217 and the ARP table 216 from the mobile router 21, creates correspondence between the identifiers of the IoT devices 24 accommodated by the mobile router and address information (IP addresses and port numbers) from the acquired tables, and updates the IoT device identification table 17. The correspondence between the identifiers and address information (IP addresses and port numbers) of IoT devices 24 accommodated by the mobile router may be created by receiving the NAPT table 217 and ARP table 216 by the terminal identification device 1, or may be created by the mobile router 21 and sent to the terminal identification device 1.

[0029] The control unit 14 accepts setting input from the setting terminal 4 and controls the operation of the terminal identification device 1, such as controlling the registration of data in the mobile router management table 15, the connection feasibility management table 16, and the IoT device identification table 17.

[0030] FIG. 3 is a diagram illustrating an example of the configuration of the mobile router 21 according to the first embodiment.

[0031] The mobile router 21 is a gateway device having multiple types of physical hardware resources, such as a LAN side interface 210, a local 5G side interface 211, a mobile router storage device 8, and a mobile router processor 9 connected to them.

[0032] Data is sent and received through each interface 210, 211. Mobile router storage device 8 stores routing table 215, ARP table 216, and NAPT table 217. These tables 215, 216, and 217 are tables in which mobile router 21 stores and deletes information. Mobile router processor 9 executes the programs in mobile router storage device 8 to realize routing processing unit 213, address conversion unit 212, and address information transmission unit 214. Mobile router processor 9 includes one or more CPU cores and executes predetermined programs.

[0033] The LAN side interface 210 is an interface that connects the mobile router 21 to the LAN network 23. The local 5G side interface 211 is an interface that connects the mobile router 21 to the local 5G network 2. The local 5G side interface 211 determines whether the destination of a received packet is the mobile router 21. If the destination of the received packet is the mobile router 21, it executes reception processing. If the destination is not the mobile router 21, it forwards the packet to the address conversion unit 212. For example, a request message for the ARP table 216 and the NAPT table 217 to the mobile router 21 is forwarded in a packet addressed to the terminal identification device 1.

[0034] The ARP table 216 associates and holds the IP addresses 2160, MAC addresses 2161, and output destination interfaces 2162 of the IoT devices 24 accommodated by the mobile router and the backbone network server 33. The ARP table 216 is registered, for example, by the address conversion unit 212 performing ARP protocol processing to associate an IP address with a MAC address in response to a request for the MAC address of the IP address. The routing table 215 also associates and holds the destination network addresses 2150, next hop terminal IP addresses 2151, and packet output destination interfaces 2152 of packets transferred between the LAN network 23 and the local 5G network 2.

[0035] The routing table 215 is registered, for example, by OSPF routing protocol processing executed by the routing processing unit 213. The routing processing unit 213 searches the destination network address 2150 of the routing table 215 with the destination IP address of the packet transferred from the address conversion unit 212, and determines the next hop terminal IP address 2151 and output destination interface 2152 of the matching entry.

[0036] Furthermore, the ARP table 216 is searched for the IP address of the next hop terminal, the destination MAC address of the packet is rewritten with the MAC address 2161 of the matching entry, and the packet is output from the determined output destination interface. On the other hand, if a matching entry does not exist, an ARP request is sent from the output destination interface to the IP address of the next hop terminal, and the output destination interface 2152 waits for reception of an ARP reply. After reception, the MAC of the next hop terminal is obtained from the ARP reply and recorded in MAC address 2161 of the ARP table 216, and then the destination MAC address of the packet is rewritten with the MAC address of the next hop terminal, and the packet is sent from the output destination interface 2152. The configurations of the ARP table 216 and routing table 215 will be described later with reference to Figures 7 and 8.

[0037] The NAPT table 217 stores the IP address (local 5G side IP address 2170) and port number (local 5G side port number 2171) of the mobile router 21 in association with the IP address (LAN side IP address 2172) and port number (LAN side port number 2173) of the IoT device 24 accommodated by the mobile router. The NAPT table 217 is registered, for example, by the address conversion unit 212 executing an address conversion process. The configuration of the NAPT table 217 will be described later with reference to FIG. 9.

[0038] The address conversion unit 212 searches the LAN side IP address 2172 and LAN side port number 2173 in the NAPT table 217 using the source IP address and source port number of the packet being transferred from the LAN network 23 to the local 5G network 2, and rewrites the source IP address and port number of the packet with the local 5G side IP address 2170 and local 5G side port number 2171 of the matching entry.

[0039] In addition, the local 5G side IP address 2170 and local 5G side port number 2171 in the NAPT table 217 are searched for using the source IP address and source port number of a packet transferred from the local 5G network 2 to the LAN network 23, and the source IP address and port number of the packet are rewritten using the LAN side IP address 2172 and LAN side port number 2173 of the matching entry. This allows for mutual conversion between the address information of the LAN network 23 and the address information of the local 5G network 2, which are included in packets transferred between the LAN network 23 and the local 5G network 2.

[0040] When the local 5G side interface 211 receives a request message for the ARP table 216 and the NAPT table 217 from the terminal identification device 1, the address information transmission unit 214 acquires the ARP table 216 and the NAPT table 217 held by the mobile router 21 and transmits them from the local 5G side interface 211 to the terminal identification device 1.

[0041] FIG. 4 is a diagram showing an example of the configuration of the mobile router management table 15 in the first embodiment.

[0042] The mobile router management table 15 holds the local 5G side IP address 150 of the mobile router 21 used within the local 5G network 2.

[0043] FIG. 5 is a diagram illustrating an example of the configuration of the connection permission management table 16 according to the first embodiment.

[0044] The connection permission management table 16 holds IoT device identifiers 160, which are identifiers of IoT devices 24 accommodated by a mobile router and IoT devices 22 not accommodated by a mobile router that are permitted to connect to the backbone network 3. The IoT device identifiers 160 may be either IP addresses or MAC addresses. The IoT device identifiers 160 registered in the connection permission management table 16 are preferably MAC addresses, but may also be unique identifiers assigned by an administrator.

[0045] FIG. 6 is a diagram illustrating an example of the configuration of the IoT device identification table 17 according to the first embodiment.

[0046] The IoT device identification table 17 associates and stores the local 5G side IP address 170 of the mobile router 21 or IoT device 22, the port number used by the mobile router 21 (mobile router port number 171), the identifiers of the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router (IoT device identifier 172), and connection availability 173 to the backbone network 3. The local 5G side IP address 170 is the IP address of the IoT device 22 for an IoT device 22 not accommodated by the mobile router, and is the IP address of the mobile router 21 for an IoT device 24 accommodated by the mobile router. A different value is set for the mobile router port number 171 for each IoT device 24, and is used to identify the IoT device 24 accommodated by the mobile router. The IoT device identifier 172 may be a MAC address, or may be a unique identifier assigned by an administrator, and the same identifier as the IoT device identifier 160 in the connection availability management table 16 is used.

[0047] FIG. 7 is a diagram illustrating an example of the configuration of the routing table 215 according to the first embodiment.

[0048] The routing table 215 stores the destination network address 2150 of packets forwarded between the LAN network 23 and the local 5G network 2, the next hop terminal IP address 2151 which is the IP address to which the packet is forwarded, and the output destination interface 2152 which is the interface from which the packet is output, in correspondence with each other.

[0049] FIG. 8 is a diagram illustrating an example of the configuration of the ARP table 216 according to the first embodiment.

[0050] The ARP table 216 stores the destination IP address and destination MAC address of packets transferred between the LAN network 23 and the local 5G network 2 in correspondence with each other.

[0051] FIG. 9 is a diagram illustrating an example of the configuration of the NAPT table 217 according to the first embodiment.

[0052] The NAPT table 217 holds a local 5G side IP address 2170, a local 5G side port number 2171, a LAN side IP address 2172, and a LAN side port number 2173 in association with each other.

[0053] 10 and 11 are diagrams showing examples of sequence diagrams of the address information update process in Example 1. The address information update process registers, in the IoT device identification table 17, combinations of address information, such as IP addresses and port numbers, and connection availability of the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router, thereby enabling execution of the IoT device identification process, which requires reference to the IoT device identification table 17. The address information process sequence is triggered by the control unit 14 of the terminal identification device 1 when the execute button 414 on the user interface 40 (see FIG. 15) of the setting terminal 4 is operated, at a time interval specified by the periodic execution interval 415, or when an IoT device accommodated by the mobile router cannot be identified in the IoT device identification sequence (S204 in FIG. 16).

[0054] FIG. 10 is a sequence diagram of an example of address information update processing for an IoT device 24 accommodated by a mobile router.

[0055] First, the setting terminal 4 accepts setting input from the network administrator, and registers the IP address of the mobile router 21 used in the local 5G network 2 in the local 5G side IP address 150 in the mobile router management table 15. The setting terminal 4 also accepts setting input from the network administrator, and registers the identifier of the IoT device 24 accommodated by the mobile router that is permitted to connect to the backbone network 3 in the IoT device identifier 160 in the connection permission management table 16 (S100).

[0056] Next, the address information update unit 13 of the terminal identification device 1 sends a request message for the ARP table 216 and the NAPT table 217 from the local 5G side interface 10 to the mobile router 21, using the local 5G side IP address 150 in the mobile router management table 15 as the destination IP address (S101).

[0057] The address information transmission unit 214 of the mobile router 21 receives a request message for the ARP table 216 and the NAPT table 217 from the local 5G side interface 211. After receiving the request message, the address information transmission unit 214 acquires the ARP table 216 and the NAPT table 217 held by the mobile router 21 and transmits them from the local 5G side interface 211 to the terminal identification device 1 (S102). In step S102, the ARP table 216 and the NAPT table 217 may be sent as is, or data that combines the local 5G side IP address of the mobile router 21, the port number used by the mobile router 21, and the identifier of the IoT device 24 accommodated by the mobile router may be sent. Which of these processes is adopted may be determined depending on the processing capabilities and amount of surplus resources of the mobile router 21 and the terminal identification device 1.

[0058] The address information update unit 13 of the terminal identification device 1 receives the ARP table 216 and the NAPT table 217 from the local 5G side interface 10. In the NAPT table 217, the IP address of the IoT device 24 accommodated by the mobile router, the port number of the IoT device 24 accommodated by the mobile router, the IP address of the mobile router 21, and the port number of the mobile router 21 are registered as a local 5G side IP address 2170, a local 5G side port number 2171, a LAN side IP address 2172, and a LAN side port number 2173, respectively. In addition, in the ARP table 216, the IP address of the IoT device 24 accommodated by the mobile router and the MAC of the IoT device 24 accommodated by the mobile router are registered as an IP address 2160 and a MAC 2161, respectively.

[0059] Therefore, after receiving the ARP table 216 and the NAPT table 217, the local 5G side IP address 2170, local 5G side port number 2171 in the NAPT table 217 corresponding to the IP address 2160 in the ARP table 216, and the MAC 2161 in the ARP table 216 are registered as the local 5G side IP address 170, mobile router port number 171, and IoT device identifier 172 in the IoT device identification table 17, respectively.

[0060] At this time, if an entry with a matching local 5G side IP address 170 exists in the IoT device identification table 17, the entry is updated. Furthermore, the IoT device identifier 172 in the IoT device identification table 17 is searched for using the IoT device identifier 160 in the connection permission management table 16, and if a matching entry exists, the connection permission 173 is set to "yes," and if a matching entry does not exist, the connection permission 173 is set to "no," and the entry is updated (S103).

[0061] FIG. 11 is a sequence diagram of an example of an address information update process for an IoT device 22 that is not accommodated by a mobile router.

[0062] First, the setting terminal 4 accepts setting input from the network administrator and registers the identifier of the IoT device 22 that is permitted to connect to the backbone network 3 in the IoT device identifier 160 of the connection permission management table 16 (S104).

[0063] In addition, the setting terminal 4 accepts setting input from the network administrator and registers the local 5G side IP address and identifier of the IoT device 22 in the local 5G side IP address 170 and IoT device identifier 172 of the IoT device identification table 17 (S105).

[0064] Furthermore, the address information update unit 13 of the terminal identification device 1 searches for the IoT device identifier 172 in the IoT device identification table 17 using the IoT device identifier 160 in the connection feasibility management table 16, and updates the entry so that the connection feasibility 173 is set to "yes" if a matching entry is found, or the connection feasibility 173 is set to "no" if a matching entry is not found (S106).

[0065] FIG. 12 is a flowchart illustrating an example of the address information update process according to the first embodiment.

[0066] The following describes the case where address information update processing is executed for IoT devices 24 accommodated by a mobile router. Fig. 13 shows changes in the mobile router management table 15, connection permission management table 16, and IoT device identification table 17 when address information update processing is executed for IoT devices 24 accommodated by a mobile router.

[0067] First, the control unit 14 of the terminal identification device 1 accepts registration of the mobile router management table 15, the connection permission management table 16, and the IoT device identification table 17 from the setting terminal 4 (S1000). The setting terminal 4 accepts setting input from the network administrator and registers the identifier of the IoT device 24 accommodated by the mobile router in the IoT device identifier 160 in the connection permission management table 16 (S1001). The setting terminal 4 also accepts setting input from the network administrator and registers the IP address of the mobile router 21 in the local 5G side IP address 150 in the mobile router management table 15 (S1002).

[0068] When step 1002 is completed, as shown in the upper part of Figure 13, the IP address of the mobile router 21 is registered as the local 5G side IP address 150 in the mobile router management table 15, and the identifier of the IoT device 24 accommodated by the mobile router is registered as the IoT device identifier 160 in the connection feasibility management table 16.

[0069] Next, the control unit 14 of the terminal identification device 1 determines whether an entry has been added to the mobile router management table 15 in step S1002 or whether an entry has been added to the IoT device identification table 17 (S1003).

[0070] When performing an address information update process for an IoT device 24 accommodated by the mobile router, an entry is added to the mobile router management table 15 (Yes in S1003), and the address information update unit 13 of the terminal identification device 1 sends a request message for the ARP table 216 and the NAPT table 217 from the local 5G side interface 10 to the mobile router 21, using the local 5G side IP address 150 in the mobile router management table 15 as the destination IP address (S1004).

[0071] Furthermore, the address information update unit 13 of the terminal identification device 1 determines whether the ARP table 216 and the NAPT table 217 can be received from the setting terminal 4 within the set timeout period (S1005).

[0072] If the ARP table 216 and the NAPT table 217 are received within the timeout period (Yes in S1005), after receiving the ARP table 216 and the NAPT table 217, the local 5G side IP address 2170 and local 5G side port number 2171 in the NAPT table 217 corresponding to the IP address 2160 in the ARP table 216, and the MAC 2161 in the ARP table 216 are registered as the local 5G side IP address 170, the mobile router port number 171, and the IoT device identifier 172 in the IoT device identification table 17, respectively. At this time, if an entry with a matching local 5G side IP address 170 exists in the IoT device identification table 17, the entry is updated (S1006). If the ARP table 216 and the NAPT table 217 are not received within the timeout period (No in S1005), an error is notified to the setting terminal 4 (S1014).

[0073] At the time step S1014 is completed, as shown in the middle of Figure 13, the IP address of the mobile router 21, the port number of the mobile router 21, and the identifier of the IoT device 24 accommodated by the mobile router are registered in the IoT device identification table 17 as the local 5G side IP address 170, the mobile router port number 171, and the IoT device identifier 172, respectively.

[0074] Next, the control unit 14 of the terminal identification device 1 searches the IoT device identifier 172 in the IoT device identification table 17 using the IoT device identifier 160 in the connection permission management table 16 (S1007), and determines whether a matching entry exists (S1008). If a matching entry exists (Yes in S1008), the connection permission 173 of the entry is updated to "Yes" (S1009). If a matching entry does not exist (No in S1008), the connection permission 173 of the entry is updated to "No" (S1013).

[0075] When step 1013 is completed, as shown in the lower part of Figure 13, the IP address of the mobile router 21, the port number of the mobile router 21, the identifier of the IoT device 24 accommodated by the mobile router, and the connection availability of the IoT device 24 accommodated by the mobile router are registered in the IoT device identification table 17 as local 5G side IP address 170, mobile router port number 171, IoT device identifier 172, and connection availability 173, respectively.

[0076] This completes the address information update process, and the terminal identification device 1 can start the IoT device identification sequence (see FIG. 16) for the IoT device 24 accommodated by the mobile router.

[0077] Next, a case where address information update processing is executed for an IoT device 22 that is not accommodated by a mobile router will be described. Fig. 14 shows changes in the mobile router management table 15, connection permission management table 16, and IoT device identification table 17 when address information update processing is executed for an IoT device 22.

[0078] First, the control unit 14 of the terminal identification device 1 accepts registration of the mobile router management table 15, the connection permission management table 16, and the IoT device identification table 17 from the setting terminal 4 (S1000). The setting terminal 4 accepts setting input from the network administrator and registers the identifier of the IoT device 22 in the IoT device identifier 160 of the connection permission management table 16 (S1001). The setting terminal 4 also accepts setting input from the network administrator and registers the IP address and identifier of the IoT device 22 in the local 5G side IP address 170 and the IoT device identifier 172 of the IoT device identification table 17 (S1002).

[0079] 14, the identifier of the IoT device 22 is registered as the IoT device identifier 160 in the connection permission management table 16. In addition, the IP address and identifier of the IoT device 22 are registered as the local 5G side IP address 170 and the IoT device identifier 172 in the IoT device identification table 17.

[0080] Next, the control unit 14 of the terminal identification device 1 determines whether an entry has been added to the mobile router management table 15 in step S1002 or whether an entry has been added to the IoT device identification table 17 (S1003).

[0081] When the address information update process is executed for the IoT device 22, an entry is added to the IoT device identification table 17 ( S1003 If the answer is No, the local 5G side IP address 150 in the mobile router management table 15 is searched for using the local 5G side IP address 170 of the entry (S1010), and it is determined whether a matching entry exists (S1011).

[0082] If a matching entry exists (Yes in S1011), the entry including the local 5G side IP address 170 and IoT device identifier 172 of the IoT device 22 registered in the IoT device identification table 17 in step S1002 is deleted (S1012), and the process returns to step S1002.

[0083] If a matching entry does not exist (No in S1011), the control unit 14 of the terminal identification device 1 searches for the IoT device identifier 172 in the IoT device identification table 17 using the IoT device identifier 160 in the connection permission management table 16 (S1007), and determines whether a matching entry exists (S1008). If a matching entry exists (Yes in S1008), the connection permission 173 of the entry is updated to "Yes" (S1009). If a matching entry does not exist (No in S1008), the connection permission 173 of the entry is updated to "No" (S1013).

[0084] When step 1013 is completed, as shown in the lower part of Figure 14, the IP address of the mobile router 21, the identifier of the IoT device 24 accommodated by the mobile router, and the connection availability of the IoT device 24 accommodated by the mobile router are registered in the IoT device identification table 17 as the local 5G side IP address 170, the IoT device identifier 172, and the connection availability 173, respectively.

[0085] This completes the address information update process, and the terminal identification device 1 can start the IoT device identification sequence for the IoT device 22 (see FIG. 16).

[0086] 15A and 15B are diagrams showing an example of the user interface 40 used in the address information update process of the first embodiment.

[0087] 15A, before the address information update process is executed, the local 5G side IP address 150 in the mobile router management table 15 is entered into the local 5G side IP address field 410 in the connection management area 41, and a check is entered into the corresponding mobile router check field 411. In addition, the combination of the local 5G side IP address 170 and IoT device identifier 172 of the IoT device 22 is entered into the combination of the local 5G side IP address field 410 and the IoT device identifier field 412 in the connection management area 41. Furthermore, the combination of the IoT device 24 accommodated by the mobile router and the IoT device identifier 160 of the IoT device 22 not accommodated by the mobile router in the connection feasibility management table 16 is entered into the combination of the IoT device identifier field 420 and the connection feasibility field 421 in the connection feasibility management area 42. The address information update process is executed when the execute button 414 in the connection management area 41 is operated or at the timing set in the periodic execution interval 415.

[0088] After the address information update process is executed, as shown in Figure 15B, the local 5G side IP address 170, IoT device identifier 172, and connection feasibility 173 of the IoT device identification table 17 are displayed in the local 5G side IP address column 410, IoT device identifier column 412, and connection feasibility column 413 of the connection management area 41, respectively.

[0089] Fig. 16 is a sequence diagram of an example of an IoT device identification process for an IoT device 24 accommodated by the mobile router of Example 1. The IoT device identification process shown in Fig. 16 is executed after the address information update sequence and after other IoT device identification sequences.

[0090] First, the IoT device 24 accommodated by the mobile router transmits a packet to the backbone network server 33 (S200).

[0091] Using its NAPT conversion function, the mobile router 21 converts the source IP address and source port number of a packet sent from an IoT device 24 accommodated by the mobile router from the IP address and port number of the IoT device 24 accommodated by the mobile router to the IP address and port number of the mobile router 21, registers the correspondence in the NAPT table 217, and then forwards the packet to the backbone network server 33 (S201).

[0092] The terminal identification device 1 searches the local 5G side IP address 150 in the mobile router management table 15 using the source IP address of the packet to identify whether the source is the IoT device 24 accommodated by the mobile router or the IoT device 22. In Figure 16, since the source is the IoT device 24 accommodated by the mobile router, an entry exists, and the process proceeds to step S203 (S202).

[0093] The IoT device identification unit 11 of the terminal identification device 1 searches the local 5G side IP address 170 and mobile router port number 171 in the IoT device identification table 17 using the source IP address and port number of the packet (S203). If a matching entry is not found, the process proceeds to step S204, where an address information update sequence is executed. If a matching entry is found, the process proceeds to step S205. Note that even if a matching entry is not found in step S203, the address information update sequence may not be executed in step S204, and the IoT device 24 may be determined to be unconnectable. Furthermore, the address information update sequence (step S204) may be executed multiple times.

[0094] If a matching entry is not found in step S203, the address information update sequence is executed to update the IoT device identification table 17, and then the source IP address and port number of the packet are used to search again for the local 5G side IP address 170 and mobile router port number 171 in the IoT device identification table 17. If a matching entry is found in the IoT device identification table 17, proceed to step S205. If a matching entry is not found in the IoT device identification table 17, discard the packet (S204).

[0095] If the connection possibility 173 of the entry is "yes", the IoT device identification unit 11 of the terminal identification device 1 transfers the packet to the backbone network server 33, and if the connection possibility 173 of the entry is "no", the IoT device identification unit 11 discards the packet (S205).

[0096] The backbone network server 33 receives the packet, performs a predetermined process, and then returns a response to the mobile router 21 (S206).

[0097] The IoT device identification unit 11 of the terminal identification device 1 performs header processing on the received packet and transfers it to the mobile router 21 (S207).

[0098] The mobile router 21 searches the NAPT table 217 for the local 5G side IP address 2170 and the local 5G side port number 2171 using the destination IP address and port number of the received packet, rewrites the destination IP address and port number with the LAN side IP address 2172 and LAN side port number 2173 of the matching entry, and forwards the packet to the IoT device 24 accommodated by the mobile router. If a matching entry does not exist, the packet is discarded (S208).

[0099] As a result of the above, the IoT device 24 accommodated by the mobile router can communicate with the backbone network server 33 after being identified and controlled as to whether or not it can be connected by the terminal identification device 1 (S209).

[0100] Thereafter, the IoT device identification sequence is repeatedly executed every time a packet is transmitted from an IoT device 24 accommodated by the mobile router.

[0101] Fig. 17 is a sequence diagram of an example of an IoT device identification process for the IoT device 22 according to the embodiment 1. The IoT device identification process shown in Fig. 17 is executed after the address information update sequence or another IoT device identification sequence.

[0102] First, the IoT device 22 transmits a packet to the backbone network server 33 (S200).

[0103] In order to identify whether the sender is an IoT device 24 accommodated by the mobile router or an IoT device 22 not accommodated by the mobile router, the terminal identification device 1 searches the local 5G side IP address 150 in the mobile router management table 15 using the sender IP address of the packet. In Figure 17, since the sender is an IoT device 22 not accommodated by the mobile router, no entry exists, and the process proceeds to step S210 (S202).

[0104] Then, the IoT device identification unit 11 of the terminal identification device 1 searches the local 5G side IP address 170 in the IoT device identification table 17 using the source IP address of the packet (S210).

[0105] If the connection possibility 173 of the entry is "yes", the IoT device identification unit 11 of the terminal identification device 1 transfers the packet to the backbone network server 33, and if the connection possibility 173 of the entry is "no", the IoT device identification unit 11 discards the packet (S205).

[0106] The backbone network server 33 receives the packet, performs a predetermined process, and then returns a response to the mobile router 21 (S206).

[0107] The IoT device identification unit 11 of the terminal identification device 1 performs header processing on the received packet and transfers it to the IoT device 22 (S211).

[0108] As a result of the above, the IoT device 22 is able to communicate with the backbone network server 33 after being identified and controlled as to whether or not connection is possible by the terminal identification device 1 (S209).

[0109] Thereafter, the IoT device identification sequence is repeatedly executed every time a packet is transmitted from an IoT device 24 accommodated by the mobile router.

[0110] FIG. 18 is a flowchart illustrating an example of an IoT device identification process including an address information update process.

[0111] First, the address information update unit 13 of the terminal identification device 1 executes the address information update process (see FIGS. 10, 11, and 12) to update the IoT device identification table 17 (S2000).

[0112] Thereafter, the IoT device identification unit 11 waits for reception of a packet from the local 5G side interface 10 or the backbone network side interface 12 (S2001). When the IoT device identification unit 11 receives a packet, it determines the interface that received the packet (S2002). If the interface that received the packet is the local 5G side interface 10 (YES in S2002), it executes IoT device identification processing (see FIG. 19) (S2003). On the other hand, if the interface that received the packet is the backbone network side interface 12 (NO in S2002), it executes header processing and forwards the packet from the local 5G side interface (S2004).

[0113] FIG. 19 is an example of a flowchart of an IoT device identification process.

[0114] The IoT device identification unit 11 of the terminal identification device 1 searches the local 5G side IP address 150 in the mobile router management table 15 using the source IP address of the received packet (S20030), and determines whether the source IoT device is an IoT device 24 accommodated by the mobile router, or an IoT device 22 not accommodated by the mobile router (S20031).

[0115] If a matching entry exists (Yes in S20031), the source IoT device is an IoT device 24 accommodated by the mobile router, so the local 5G side IP address 170 and mobile router port number 171 in the IoT device identification table 17 are searched for using the source IP address and port number of the packet (S20032), and it is determined whether a matching entry exists (S20033). If a matching entry exists (Yes in S20033), step S20034 If a matching entry does not exist (No in S20033), execute the address information update process, update the IoT device identification table 17, and then proceed to step S20030 Proceed to.

[0116] If an entry including the source IP address of the received packet does not exist in the mobile router management table 15 (No in S20031), the source IoT device is an IoT device 22 that is not accommodated by the mobile router, so the local 5G side IP address 170 in the IoT device identification table 17 is searched for using the source IP address of the packet (S20036), and it is determined whether a matching entry exists (S20037). If a matching entry exists (Yes in S20037), step S20034 If a matching entry does not exist (No in S20037), the packet is discarded (S20038).

[0117] If an entry including the source IP address and port number of the packet exists in the IoT device identification table 17 (Yes in S20033), or if an entry including the source IP address of the packet exists in the IoT device identification table 17 (Yes in S20037), it is further determined whether the connection possibility 174 of the entry is "Yes" (S20034). If the connection possibility 174 of the entry is "Yes" (Yes in S20034), the packet is forwarded from the backbone network side interface 12 (S20035). If the connection possibility 174 of the entry is "No" (No in S20034), the packet is discarded (S20038).

[0118] As a result of the above, the IoT device 24 accommodated by the mobile router and the IoT device 22 not accommodated by the mobile router can communicate with the backbone network server 33 after being identified and controlled by the terminal identification device 1 as to whether or not connection is possible.

[0119] As described above, in Example 1 of the present invention, when a local 5G network and a backbone network are interconnected, IoT devices connected to the backbone network can be identified via an address translation function, and whether or not each IoT device can connect to the backbone network can be controlled.

[0120] In addition, the terminal identification device 1 requests the identifier (MAC address) of the IoT device 24 from the mobile router 21 using the address information (IP address and port number) of the mobile router 21, and registers or updates the IoT device identification table 17 using the address information of the mobile router 21 in the local 5G network 2 and the identifier of the IoT device 24 obtained from the mobile router 21, so that the IoT device identification table 17 can be dynamically updated as needed.

[0121] In addition, if the address information (IP address and port number) of the mobile router 21 attached to data transferred from the local 5G network 2 to the backbone network 3 is not registered in the IoT device identification table 17, the terminal identification device 1 obtains the identifier of the terminal sending the data and registers it in the IoT device identification table 17, thereby enabling the IoT device identification table 17 to be updated in real time with information from the mobile router 21.

[0122] <Example 2> Next, a description will be given of Example 2. In Example 2, the terminal identification device 1 receives setting input from the setting terminal 4 as well as setting input from the authentication mechanism 5 in the backbone network 3, and registers the connection permission management table 16. In Example 2, the same configurations and functions as those in Example 1 described above are denoted by the same reference numerals, and their description will be omitted.

[0123] FIG. 20 is a diagram illustrating an example of a network system configuration according to the second embodiment.

[0124] The network system of Example 2 illustrated in FIG. 20 includes a backbone network 3, a local 5G network 2, a terminal identification device 1 installed between the backbone network 3 and the local 5G network 2, and an authentication mechanism 5. The terminal identification device 1 may be installed logically between the backbone network 3 and the local 5G network 2 at a position through which packets transferred between the backbone network 3 and the local 5G network 2 pass. The authentication mechanism 5 is connected to the terminal identification device 1, and upon receiving an authentication request message from the terminal identification device 1, transmits to the terminal identification device 1 a response message including an identifier of an IoT device 24 accommodated by a mobile router or an IoT device 22 not accommodated by a mobile router that is permitted to connect to the backbone network 3. This allows the authentication mechanism 5 of the backbone network 3 to manage whether or not an IoT device can connect to the backbone network 3.

[0125] FIG. 21 is a diagram illustrating an example of the configuration of the terminal identification device 1 of the second embodiment.

[0126] The terminal identification device 1 of Example 2 has multiple types of physical hardware resources such as a local 5G side interface 10, an IoT device identification unit 11, a backbone network side interface 12, a storage device 6, an authentication interface 19, an IoT device management table 20, and a processor 7 connected to them.

[0127] The authentication interface 19 is an interface that connects the terminal identification device 1 to the authentication mechanism 5. The IoT device management table 20 holds, as IoT device identifiers 200, the identifiers of IoT devices 24 accommodated by the mobile router and IoT devices 22 not accommodated by the mobile router that request authentication from the authentication mechanism 5. The IoT device management table 20 is set from the setting terminal 4 based on setting input by the network administrator via the user interface 40 (see FIG. 15). The configuration of the IoT device management table 20 will be described later with reference to FIG. 22.

[0128] The control unit 14 realized by the processor 7 controls the operation of the terminal identification device 1, such as accepting setting inputs from the setting terminal 4 and the authentication mechanism 5 and controlling the registration of data in the mobile router management table 15, the connection permission management table 16, and the IoT device identification table 17, in addition to the functions described in the first embodiment. The control unit 14 transmits an authentication request message to the authentication mechanism 5 for the IoT device identifier 200 to be entered in the IoT device management table 20. Thereafter, the control unit 14 registers the IoT device identifier 160 in the connection permission management table 16 based on the response message received from the authentication mechanism 5.

[0129] FIG. 22 is a diagram illustrating an example of the configuration of the IoT device management table 20 according to the second embodiment.

[0130] The IoT device management table 20 holds, as IoT device identifiers 200, the identifiers of the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router.

[0131] FIG. 23 is a sequence diagram of an example of IoT device authentication processing.

[0132] The IoT device authentication process sends an authentication request message for an IoT device 24 accommodated by a mobile router and an IoT device 22 not accommodated by a mobile router to the authentication mechanism 5 based on the IoT device identifier 200 entered in the IoT device management table 20, and registers the IoT device identifier 160 in the connection permission management table 16 based on the response message.

[0133] First, the setting terminal 4 accepts setting input from the network administrator and registers the identifiers of the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router that request authentication from the authentication mechanism 5 in the IoT device identifiers 200 of the IoT device management table 20 (S300).

[0134] Next, the control unit 14 of the terminal identification device 1 includes the IoT device identifier 200 in the IoT device management table 20 in the authentication request message and transmits the authentication request message from the authentication interface 19 to the authentication mechanism 5 (S301). At this time, the terminal identification device 1 may request authentication for each MAC address of the IoT device 24, or may transmit an authentication request message including the IoT device identification table 17 to the authentication mechanism 5 and request authentication of all IoT devices 24 accommodated by the mobile router.

[0135] The authentication mechanism 5 checks the IoT device identifier 200 included in the authentication request message against a list of IoT device identifiers that have been authorized for authentication, and includes the identifiers of the IoT devices that have been authorized to connect to the backbone network 3 in a response message and transmits the message to the terminal identification device 1 ( S302 ).

[0136] The control unit 14 of the terminal identification device 1 receives the response message from the authentication mechanism 5 via the authentication interface 19. The control unit 14 registers the identifier of the IoT device that is permitted to connect to the backbone network 3, which is included in the response message, in the IoT device identifier 160 of the connection permission management table 16. At this time, if there is an entry in the connection permission management table 16 that matches the IoT device identifier 160, the control unit 14 updates that entry (S303).

[0137] FIG. 24 is a flowchart illustrating an example of an IoT device authentication process.

[0138] First, the control unit 14 of the terminal identification device 1 accepts registration of the IoT device management table 20 from the setting terminal 4 (S3000). The setting terminal 4 accepts setting input from the network administrator and registers the identifiers of the IoT devices 24 accommodated by the mobile router and the IoT devices 22 not accommodated by the mobile router that request authentication by the authentication mechanism 5 in the IoT device identifiers 200 of the IoT device management table 20 (S3001).

[0139] The control unit 14 of the terminal identification device 1 includes the IoT device identifier 200 from the IoT device management table 20 in the authentication request message and sends the authentication request message to the authentication mechanism 5 (S3002), and determines whether a response message can be received from the setting terminal 4 within the timeout period set (S3003).

[0140] If a response message is received (Yes in S3003), the control unit 14 of the terminal identification device 1 registers the identifier of the IoT device permitted to connect to the backbone network 3, which is included in the response message, in the IoT device identifier 160 of the connection permission management table 16. At this time, if an entry with a matching IoT device identifier 160 exists in the connection permission management table 16, the entry is updated (S3004). If a response message is not received (No in S3003), an error is notified to the setting terminal 4 (S3005).

[0141] As described above, in addition to the effects of the first embodiment, the second embodiment of the present invention obtains information on whether the IoT devices 22 and 24 can be authenticated from the authentication mechanism 5, so that the backbone network 3 can centrally manage whether the IoT devices 22 and 24 can connect to the backbone network 3.

[0142] The present invention is not limited to the above-described embodiments, but includes various modifications and equivalent configurations within the spirit and scope of the appended claims. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to configurations including all of the described configurations. Furthermore, part of the configuration of one embodiment may be replaced with the configuration of another embodiment. Furthermore, the configuration of another embodiment may be added to the configuration of one embodiment. Furthermore, part of the configuration of each embodiment may be added, deleted, or replaced with other configurations.

[0143] Furthermore, the aforementioned configurations, functions, processing units, processing means, etc. may be realized in part or in whole in hardware, for example by designing them as integrated circuits, or may be realized in software by having a processor interpret and execute a program that realizes each function.

[0144] Information such as programs, tables, and files that realize each function can be stored in a storage device such as a memory, a hard disk, or an SSD (Solid State Drive), or in a recording medium such as an IC card, an SD card, or a DVD.

[0145] In addition, the control lines and information lines shown are those that are considered necessary for explanation, and do not necessarily represent all the control lines and information lines that are necessary for implementation. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]

[0146] 1 Terminal Identification Device 2. Local 5G Network 3. Backbone Network 4. Setting terminal 5 Authentication Mechanisms 6 Storage device 7 processors 8 Mobile Router Storage Device 9. Mobile Router Processor 10 Local 5G side interface 11 IoT device identification section 12 Backbone network side interface 13 Address information update section 14 Control Unit 15 Mobile Router Management Table 16 Connection availability management table 17 IoT Device Identification Table 18 Configuration Interface 19 Authentication Interface 20 IoT device management table 21 Mobile Router 22 IoT devices 23 LAN Network 24 IoT devices under mobile router 25 Base station equipment 26 Mobile Core Equipment 31 Intranet 32 remote sites 33 Core Network Server 40 User Interface 41 Connection Management Area 42 Connection availability management area 211 Local 5G side interface 212 Address translation unit 213 Routing processing unit 214 Address information transmission unit 215 Routing Table 216 ARP Table 217 NAPT Table 410 Local 5G side IP address field 411 Mobile Router Check Box 412 IoT device identifier field 413 Connection availability column 420 IoT device identifier field 421 Connection availability column

Claims

1. A network system for transferring data, comprising: a first network; a second network connected to the first network and to which a server is connected; a third network included in the first network and accommodating terminals having address information different from that of the first network; a terminal identification device that is logically installed between the first network and the second network and that determines whether or not the terminal is allowed to connect to the second network; a gateway device that converts address information attached to data transferred between the first network and the third network; the gateway device converts address information of the gateway device in the first network that is attached to data transferred from the first network to the third network into address information of the terminal in the third network, and converts address information of the terminal in the third network that is attached to data transferred from the third network to the first network into address information of the gateway device in the first network; The terminal identification device retaining terminal identification information that associates address information of the gateway device in the first network, an identifier of the terminal, and whether or not the terminal is connectable to the second network; determining whether or not the terminal is to be connected to the second network based on the terminal identification information; A network system characterized in that address information of the gateway device in the first network and an identifier of the terminal are acquired from the gateway device, and the terminal identification information is registered or updated.

2. 2. The network system according to claim 1, The address information is a combination of an IP address and a port number, the terminal identification information is information in which an IP address and a port number of the gateway device in the first network, an identifier of the terminal, and whether the terminal can be connected to the second network are associated with each other, a port number of the gateway device is set to a different value for each identifier of the terminal, A network system characterized in that the terminal identification device refers to the terminal identification information using the IP address and port number of the gateway device in the first network that are attached to data transferred from the first network to the second network, and determines whether or not the terminal can connect to the second network.

3. 2. The network system according to claim 1, The terminal identification device requesting an identifier of the terminal from the gateway device using address information of the gateway device; A network system characterized in that the terminal identification information is registered or updated using address information of the gateway device in the first network and an identifier of the terminal, which are acquired from the gateway device.

4. 2. The network system according to claim 1, The terminal identification device a first interface for transmitting and receiving data to and from the first network; a second interface for transmitting and receiving data to and from the second network; a terminal identification unit that refers to the terminal identification information and determines whether or not the terminal is allowed to connect to the second network; a gateway device for registering or updating the terminal identification information by acquiring address information of the gateway device in the first network from the gateway device;

5. 3. The network system according to claim 2, a terminal identification device that, when the IP address and port number of the gateway device in the first network that are attached to data transferred from the first network to the second network are not registered in the terminal identification information, obtains from the gateway device an identifier of the terminal that sends the data and registers it in the terminal identification information.

6. 2. The network system according to claim 1, an authentication mechanism for providing authentication information of the terminal to the terminal identification device; The terminal identification device requesting authentication of the terminal from the authentication mechanism based on the terminal identification information; A network system characterized in that, based on the authentication result obtained from the authentication mechanism, whether or not the terminal can connect to the second network is registered or updated in the terminal identification information.

7. A communication control device provided in a network system for transferring data, The network system includes: a first network; a second network connected to the first network and to which a server is connected; a third network included in the first network and accommodating terminals having address information different from that of the first network; a gateway device that is logically installed between the first network and the second network and converts address information attached to data transferred between the first network and the third network; the gateway device converts address information of the gateway device in the first network that is attached to data transferred from the first network to the third network into address information of the terminal in the third network, and converts address information of the terminal in the third network that is attached to data transferred from the third network to the first network into address information of the gateway device in the first network; The communication control device a first interface for transmitting and receiving data to and from the first network; a second interface for transmitting and receiving data to and from the second network; terminal identification information that associates address information of the gateway device in the first network, an identifier of the terminal, and whether the terminal can be connected to the second network; a terminal identification unit that determines whether or not the terminal is allowed to connect to the second network based on the terminal identification information; a terminal identification information update unit that acquires address information of the gateway device in the first network and an identifier of the terminal from the gateway device, and registers or updates the terminal identification information;

8. A communication control method in a network system for transferring data, comprising: The network system includes: a first network; a second network connected to the first network and to which a server is connected; a third network included in the first network and accommodating terminals having address information different from that of the first network; a terminal identification device that is logically installed between the first network and the second network and that determines whether or not the terminal is allowed to connect to the second network; a gateway device that converts address information attached to data transferred between the first network and the third network; the gateway device converts address information of the gateway device in the first network that is attached to data transferred from the first network to the third network into address information of the terminal in the third network, and converts address information of the terminal in the third network that is attached to data transferred from the third network to the first network into address information of the gateway device in the first network; the terminal identification device holds terminal identification information that associates address information of the gateway device in the first network, an identifier of the terminal, and whether the terminal is connectable to the second network; The communication control method includes: the terminal identification device acquires address information of the gateway device in the first network and an identifier of the terminal from the gateway device, and registers or updates the terminal identification information; A communication control method, characterized in that the terminal identification device determines whether or not the terminal can be connected to the second network based on the terminal identification information.

9. A program executed by a terminal identification device in a network system for transferring data, The network system includes: a first network; a second network connected to the first network and accommodating a server; a third network included in the first network and accommodating terminals having address information different from that of the first network; a terminal identification device that is logically installed between the first network and the second network and that determines whether or not the terminal is allowed to connect to the second network; a gateway device that converts address information attached to data transferred between the first network and the third network; the gateway device converts address information of the gateway device in the first network that is attached to data transferred from the first network to the third network into address information of the terminal in the third network, and converts address information of the terminal in the third network that is attached to data transferred from the third network to the first network into address information of the gateway device in the first network; the terminal identification device has a computing device that executes a program and a storage device, the storage device holds terminal identification information that associates address information of the gateway device in the first network, an identifier of the terminal, and whether the terminal can be connected to the second network; The program an update procedure in which the terminal identification device acquires address information of the terminal in the first network from the gateway device and registers or updates the terminal identification information; and an identification procedure in which the terminal identification device determines whether or not the terminal can be connected to the second network based on the terminal identification information.

Citation Information

Patent Citations

  • Network system, communication controller, and communication control method

    JP2022091272A