Network management device, network management method and program

The network management system addresses the inefficiencies in creating data models and disclosure conditions by enabling inheritance of policy information, thereby reducing the workload in managing new networks or devices.

JP7798199B2Active Publication Date: 2026-01-14NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024540156
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-08-10
Publication Date
2026-01-14
Estimated Expiration
2042-08-10

AI Technical Summary

Technical Problem

Existing network management systems require significant work to create and manage data models for each network type, and defining disclosure conditions for specification information is also labor-intensive, especially when adding new networks or devices.

Method used

A network management system that allows for inheritance control of policy information, reducing the need to redefine disclosure conditions by inheriting policy information from existing networks, thereby minimizing the workload in defining policy information for new networks or devices.

Benefits of technology

This approach reduces the workload in defining policy information by allowing inheritance of disclosure conditions, thus streamlining the process of adding new networks or devices to the management system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007798199000001
    Figure 0007798199000001
  • Figure 0007798199000002
    Figure 0007798199000002
  • Figure 0007798199000003
    Figure 0007798199000003
Patent Text Reader

Abstract

One aspect of the present invention involves registering, when first specification information relating to registered first network equipment and first specification information representing a disclosure condition thereof are already registered and second policy information representing a disclosure condition of second specification information relating to second network equipment is to be additionally registered, inheritance control information that serves as the second policy information and indicates inheritance or non-inheritance of the disclosure condition from the first policy information to the second policy information. When a request for disclosure of entity information registered in association with the second specification information is input, it is determined whether or not the second policy information is the inheritance control information, and if it is determined that the second policy information is the inheritance control information, it is determined whether or not the disclosure request satisfies a second disclosure condition on the basis of the inheritance control information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] One aspect of the present invention relates to a network management device, a network management method, and a program used to manage, for example, multiple networks or devices that use the networks. [Background technology]

[0002] One method proposed for managing different types of networks and the devices that use them is to build and manage a data model for each network or device to be managed. This type of method requires building a data model for each type of network, which requires a lot of work to develop and subsequently manage the network management system.

[0003] Therefore, for example, when constructing or operating a network management system, a technology has been proposed for managing networks by defining the characteristics of various networks or the devices that use them using multiple attributes according to a predetermined common model format, and registering the specification information and entity information represented by the multiple attributes in a database within the system (see, for example, Patent Document 1).

[0004] By applying the technology disclosed in Patent Document 1, it becomes possible to apply information used for network management to any network without creating and modifying it as a data model for each individual network. In other words, even if there are multiple types of networks to be managed, there is no need to define a data model for each type of network or device, which can significantly reduce the amount of work required for developing a network management system and for subsequent management.

[0005] On the other hand, when managing information using a shared database, there are cases where information cannot be disclosed unconditionally, depending on, for example, the type of information or the qualifications of the administrator. This is no exception in network management systems. Therefore, the present inventors are considering defining disclosure conditions for specification information when creating the specification information for each network or its devices. This will make it possible to appropriately control the disclosure of specification information or entity information for each network or its devices, i.e., network equipment. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent No. 6655524 Summary of the Invention [Problem to be solved by the invention]

[0007] However, in the system described in Patent Document 1, for example, when a network or a device using that network is added as a new managed object after the system has started operation, all of the specification information must be newly created regardless of the type of network or device being added. In other words, for each newly added network or device, all of the attributes that make up the specification information must be defined without omission. As a result, the task of creating specification information still requires a lot of work.

[0008] Furthermore, in the system described in Patent Document 1, when attempting to define disclosure conditions for specification information of networks, devices, etc., the disclosure conditions must be defined each time new specification information is created, which also requires a lot of work.

[0009] This invention has been made with the above-mentioned circumstances in mind, and aims to provide a technology that reduces the amount of work involved in defining at least policy information among the various management information related to network equipment that is to be added and registered, thereby making it possible to reduce the workload involved in defining policy information. [Means for solving the problem]

[0010] In order to solve the above problem, one aspect of a network management device or method according to the present invention is configured to register, when second policy information representing disclosure conditions for second specification information for second network equipment is additionally registered in a state in which first specification information for already registered first network equipment and first specification information representing disclosure conditions for second specification information are registered, inheritance control information representing whether or not disclosure conditions are inherited from the first policy information to the second policy information as the second policy information. Then, when a disclosure request for entity information registered in association with the second specification information is input, it is determined whether or not the second policy information is the inheritance control information, and if it is determined that the second policy information is the inheritance control information, it is determined whether or not the disclosure request satisfies the second disclosure conditions based on the inheritance control information.

[0011] According to one aspect of the present invention, when additionally registering second policy information to be newly set as second specification information, if the second policy information is identical to the registered first policy information and the registered first specification information can be inherited by the second policy information, inheritance control information indicating whether or not the inheritance is present is defined as the second policy information. Therefore, when newly defining second policy information, it is only necessary to define disclosure conditions when no inheritable policy information is registered. This reduces the amount of work required for the network administrator to define policy information externally, compared to when disclosure conditions are unconditionally defined for all second policy information. As a result, it is possible to reduce the workload required for external definition processing of policy information. [Effects of the Invention]

[0012] In other words, according to one aspect of the present invention, it is possible to provide a technology that reduces the amount of work involved in defining at least policy information among the various management information related to network equipment that is being added and registered, thereby enabling a reduction in the amount of work involved in defining policy information. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a network management system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of a hardware configuration of an operator terminal used in the network management system shown in FIG. [Figure 3] FIG. 3 is a block diagram showing an example of a software configuration of an operator terminal used in the network management system shown in FIG. [Figure 4] FIG. 4 is a block diagram showing an example of a hardware configuration of a network management device used in the network management system shown in FIG. [Figure 5] FIG. 5 is a block diagram showing an example of the software configuration of a network management device used in the network management system shown in FIG. [Figure 6] FIG. 6 is a flowchart showing an example of the procedure and content of the input reception process of various registration information and the transmission process of a registration request executed by the control unit of the operator terminal shown in FIGS. [Figure 7] FIG. 7 is a flowchart showing an example of the procedure and content of the registration process of specification / policy information and entity information executed by the control unit of the network management device shown in FIGS. [Figure 8] FIG. 8 is a flowchart illustrating an example of the processing procedure and processing content of the entity information registration processing shown in FIG. [Figure 9] FIG. 9 is a flowchart showing an example of the procedure and content of the access control process executed by the control unit of the network management device shown in FIGS. [Figure 10]FIG. 10 is a diagram for explaining an example of the operation of the specification and policy information registration process. [Figure 11] FIG. 11 is a diagram illustrating a first example of the operation executed by the access control process illustrated in FIG. [Figure 12] FIG. 12 is a diagram illustrating a second example of the operation executed by the access control process illustrated in FIG. [Figure 13] FIG. 13 is a diagram illustrating a third example of the operation executed by the access control process illustrated in FIG. [Figure 14] FIG. 14 is a diagram illustrating a fourth example of the operation executed by the access control process shown in FIG. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0015] [One embodiment] (Configuration example) (1) System FIG. 1 is a diagram showing an example of the configuration of a network management system according to an embodiment of the present invention.

[0016] In one embodiment, the network management system has a network management device NM as its core component, and is capable of transmitting information data via a network NW between this network management device NM and an operator terminal OT used by the network manager, and multiple user terminals UT1 to UTn used by other managers or users.

[0017] The network NW includes multiple types of networks, such as the IP (Internet Protocol) network that constitutes the Internet, Ethernet (registered trademark) that constitutes a LAN (Local Area Network), and other transmission networks, but any network that is capable of transmitting the above information data may be used.

[0018] (2) Equipment (2-1) Operator terminal (OT) 2 and 3 are block diagrams showing an example of the hardware configuration and software configuration of the operator terminal OT.

[0019] The operator terminal OT includes a control unit 1A that uses a hardware processor such as a central processing unit (CPU). A storage unit having a program storage unit 2A and a data storage unit 3A, a communication interface (hereinafter, the interface will be referred to as I / F) unit 4A, and an input / output I / F unit 5A are connected to the control unit 1A via a bus 6A.

[0020] An input device 51 and an output device 52 are connected to the input / output I / F unit 5A. The input device 51 includes, for example, a keyboard, a mouse, and operation buttons. The input device 51 is used by a network administrator to input specification information, entity information, and policy information related to the network to be managed or the devices used in this network (hereinafter collectively referred to as network equipment).

[0021] Specification information is expressed as a plurality of pieces of attribute information defining the characteristics of network equipment, associated with identification information such as the name of the specification information. Entity information, for example, defines the resources actually available for the network equipment in correspondence with a plurality of attributes of the specification information, and is expressed as a plurality of pieces of attribute information associated with identification information such as the name of the entity information. Policy information, for example, defines the disclosure conditions for all, each, or a combination of the plurality of pieces of attribute information constituting the specification information. Policy information is also referred to as an access control policy.

[0022] The output device 52 includes, for example, a display, and displays display data required for input processing of the above-mentioned specification information and entity information.

[0023] The communication I / F unit 4A, under the control of the control unit 1A, transmits information data to and from the network management device NM using a communication protocol defined by the network NW.

[0024] The program storage unit 2A is configured by combining, for example, a nonvolatile memory such as a solid-state drive (SSD) as a storage medium that can be written to and read from at any time, and a nonvolatile memory such as a read-only memory (ROM), and stores middleware such as an operating system (OS), as well as application programs required for inputting the above-mentioned information required for network management in one embodiment and transmitting a registration request for that information. Hereinafter, the OS and each application program will be collectively referred to as the program.

[0025] The data storage unit 3A is, for example, a combination of a non-volatile memory such as an SSD that can be written to and read from at any time as a storage medium, and a volatile memory such as RAM (Random Access Memory), and its storage area includes a specification / policy information storage unit 31A and an entity information storage unit 32A as the main storage units required to implement one embodiment of the present invention.

[0026] The specification and policy information storage unit 31A stores the input specification information and policy information until the transmission of the registration request is completed. The entity information storage unit 32A stores the input entity information until the transmission of the registration request is completed.

[0027] The control unit 1A includes, as processing functions necessary for carrying out one embodiment of the present invention, a specification information input reception processing unit 11A, a policy information input reception processing unit 12A, an entity information input reception processing unit 13A, a specification / policy registration request transmission processing unit 14A, and an entity registration request transmission processing unit 15A. All of these processing units 11A to 15A are realized by causing a hardware processor of the control unit 1A to execute an application program stored in the program storage unit 2A.

[0028] In addition to storing the above application programs in advance in the program storage unit 2A, they may also be downloaded from the network management device NM or other application servers when necessary and stored in the program storage unit 2A.

[0029] The specification information input reception processing unit 11A receives specification information input by the network administrator at the input device 51 via the input / output I / F unit 5A, and stores the received specification information in the specification / policy information storage unit 31A.

[0030] The specification information includes specification information that includes all attribute information that is entered when registering a new network or device, and differential specification information that is entered when additionally registering a similar network or device that shares some of the attribute information with an already registered network or device. An example of this will be described in the operational example.

[0031] The policy information input reception processing unit 12A receives, via the input / output I / F unit 5A, policy information that defines the disclosure conditions of the specification information, input by the network administrator via the input device 51. Then, the received policy information is stored in the specification / policy information storage unit 31A in association with the corresponding specification information.

[0032] The entity information input reception processing unit 13A receives entity information including multiple attribute information defining the resources actually used in the network equipment, input by the network administrator at the input device 51, via the input / output I / F unit 5A, and stores the received entity information in the entity information storage unit 32A.

[0033] In response to input of a transmission instruction, the specification / policy registration request transmission processing unit 14A reads out the specification information and policy information from the specification / policy information storage unit 31A, generates a specification / policy registration request including the read specification information and policy information, and transmits the generated specification / policy registration request from the communication I / F unit 4A to the network management device NM.

[0034] In response to input of a transmission instruction, the entity registration request transmission processing unit 15A reads the entity information from the entity information storage unit 32A, generates a registration request for the read entity information, and transmits the generated entity registration request from the communication I / F unit 4A to the network management device NM.

[0035] An example of the specification information, policy information, and entity information will be described in the operation example.

[0036] (2-2) Network Management Device NM 4 and 5 are block diagrams showing an example of the hardware and software configurations of the network management device NM.

[0037] The network management device NM is, for example, a server computer installed on the web or in the cloud, or may be a personal computer used by an administrator.

[0038] The network management device NM has a control unit 1B that uses a hardware processor such as a CPU, and this control unit 1B is connected to a memory unit having a program memory unit 2B and a data memory unit 3B, and a communication I / F unit 4B via a bus 5B.

[0039] Under the control of the control unit 1B, the communication I / F unit 4B transmits and receives information data to and from the operator terminal OT and the user terminals UT1 to UTn, respectively, using a communication protocol defined by the network NW.

[0040] The program storage unit 2B is configured, for example, by combining a non-volatile memory such as an HDD or SSD as a storage medium that can be written to and read at any time, with a non-volatile memory such as a ROM, and stores middleware such as an OS as well as programs necessary to execute various control processes according to one embodiment of the present invention.

[0041] The data storage unit 3B is, for example, a combination of a non-volatile memory such as an HDD or SSD as a storage medium that can be written to and read from at any time, and a volatile memory such as RAM, and its storage area is equipped with a specification and policy information database (hereinafter the database will be referred to as DB) 31B and an entity information DB 32B as storage units necessary for implementing one embodiment of the present invention.

[0042] The specification information DB 31B stores specification information that defines the characteristics of the network equipment to be managed, and is sent from the operator terminal OT in response to a specification registration request. The entity information DB 32B stores entity information that defines the actual resources of the network equipment, and is sent from the operator terminal OT in response to an entity registration request.

[0043] The control unit 1B includes, as processing functions according to an embodiment of the present invention, a specification / policy registration request receiving processing unit 11B, a specification / policy information registration processing unit 12B, an entity registration request receiving processing unit 13B, and an entity information registration processing unit 14B, as well as an access control processing unit 15B. All of these processing units 11B to 15B are realized by causing a hardware processor of the control unit 1B to execute an application program stored in the program storage unit 2B.

[0044] Note that part or all of the processing units 11B to 15B may be realized using hardware such as an LSI (Large Scale Integration) or an ASIC (Application Specific Integrated Circuit).

[0045] The specification and policy registration request receiving processing unit 11B receives the specification and policy registration request sent from the operator terminal OT via the communication I / F unit 4B, and passes the received specification and policy registration request to the specification and policy information registration processing unit 12B.

[0046] The specification and policy information registration processing unit 12B registers the specification information and policy information included in the specification and policy registration request passed from the specification and policy registration request receiving processing unit 11B in the specification and policy information DB 31B in a mutually associated state.

[0047] The entity registration request reception processing unit 13B receives the entity registration request transmitted from the operator terminal OT via the communication I / F unit 4B, and passes the received entity registration request to the entity information registration processing unit 14B.

[0048] The entity information registration processing unit 14B determines whether or not the entity information represented by the received entity registration request satisfies the registration conditions, and if the registration conditions are met, registers the entity information in the entity information DB 32B.

[0049] In determining whether the above entity information satisfies the registration conditions, complete specification information including all attribute information is generated based on the corresponding differential specification information registered in the specification / policy information DB31B and the specification information of the network or device from which it is inherited, and a process is performed to determine whether the above entity information satisfies the registration conditions based on the generated complete specification information; an example of this process will be described in the operation example.

[0050] When a disclosure request for entity information defined for a desired network or device is transmitted from a user terminal UT1-UTn, the access control processing unit 15B receives the disclosure request via the communication I / F unit 4B. The access control processing unit 15B then determines whether the entity information specified by the received disclosure request satisfies the disclosure conditions based on the policy information linked to the corresponding specification information, and if the disclosure conditions are satisfied, performs processing to transmit the entity information from the communication I / F unit 4B to the requesting user terminal UT1-UTn. An example of this access control processing will be described in the operation example.

[0051] (Example of operation) Next, an example of the operation of the network management system configured as above will be described. In this example, we will assume that specification information regarding the communication termination point (Termination Point Encapsulation: TPE) of a network that uses Ethernet, for example, and policy information representing the disclosure conditions of this specification information, have already been registered in the specification / policy information DB31B of the network management device NM.

[0052] (1) Registration of specification information and policy information (1-1) Input and transmission of specification information and policy information via the operator terminal OT FIG. 6 is a flowchart showing an example of the processing procedure and processing contents of the input reception processing of specification information, policy information, and entity information and the registration request transmission processing thereof, which are executed by the control unit 1A of the operator terminal OT.

[0053] In the standby state, the control unit 1A of the operator terminal OT determines whether the specification and policy information input mode or the entity information input mode has been set in steps S10 and S20, respectively.

[0054] When the specification and policy information input mode is set, for example, if the network administrator attempts to register additional specification information for network equipment provided by another vendor, the network administrator first determines whether the network equipment from the other vendor to be registered has some similar characteristics to the registered network equipment. If the characteristics are similar, the network administrator generates unique attribute information that is different from the specification information of the registered network equipment, i.e., different attribute names or possible ranges among the multiple attribute information included in the specification information.

[0055] In addition, the network administrator generates inheritance relationship information that represents the inheritance relationship between the specification information of the registered network equipment and the specification information of the network equipment to be registered, in order to have the specification information of the network equipment to be registered inherit attribute information that has common attribute names and possible values ​​from the multiple attribute information of the specification information of the registered network equipment.

[0056] Then, the network administrator inputs the generated attribute information specific to the network equipment to be registered and the inheritance relationship information from the input device 51 to the operator terminal OT.

[0057] The process of defining the specific attribute information and inheritance relationship information is performed by, for example, acquiring specification information about registered network equipment from a database independently managed by the network administrator or from the specification and policy information DB31B of the network management device NM, and referencing the acquired specification information. Furthermore, the inheritance relationship information may be automatically generated by the operator terminal OT based on information about the first and second network equipment selected by the network administrator when defining the specific attribute information about the network equipment to be registered.

[0058] The control unit 1A of the operator terminal OT, under the control of the specification information input reception processing unit 11A, retrieves the attribute information and inheritance relationship information specific to the network equipment to be registered, which are input via the input device 51, in steps S11 and S12, respectively. Then, the retrieved attribute information and inheritance relationship information specific to the network equipment to be registered are temporarily stored in the specification / policy information storage unit 31A as differential specification information representing the difference from the specification information of the inheritance source.

[0059] After inputting the differential specification information, the network manager then defines policy information for the differential specification information, and inputs this policy information from the input device 51 to the network management device NM.

[0060] Policy information is typically defined to include a specification information name indicating the target to which the policy applies, disclosure conditions, and an action indicating the content of the processing. However, in one embodiment of the present invention, inheritance control information or policy change information is defined as policy information. Among these, inheritance control information is information that specifies whether or not to allow the inheritance of policy information associated with the specification information from which the policy is inherited to the differential specification information. In contrast, policy change information changes the policy information associated with the specification information from which the policy is inherited, and includes the content of the changed policy information.

[0061] When the policy information is input, the control unit 1A of the operator terminal OT, under the control of the policy information input reception processing unit 12A, imports the policy information via the input / output I / F unit 5A using the input device 51 in step S13. Then, the imported policy information is associated with the previously acquired differential specification information and temporarily stored in the specification / policy information storage unit 31A.

[0062] Next, when the control unit 1A of the operator terminal OT detects the network administrator's input operation of a transmission instruction in step S14, under the control of the specification / policy registration request transmission processing unit 14A, in step S15, it reads the differential specification information and policy information from the specification / policy information storage unit 31A, and transmits a specification / policy registration request including the read information from the communication I / F unit 4A to the network management device NM.

[0063] When the control unit 1A of the operator terminal OT has completed the input acceptance and transmission process of the specification information and policy information for one of the network facilities to be added, it determines in step S16 whether there is a next network facility to be registered, and if there is, it returns to step S11 and executes the series of input acceptance and transmission processes of the specification information in steps S11 to S16. Then, when an instruction to end the registration of the specification and policy information is input, it returns to the standby state.

[0064] (1-2) Registration of specification information and policy information by the network management device NM FIG. 7 is a flowchart showing an example of the procedure and content of the registration process of specification information, policy information, and entity information executed by the control unit 1B of the network management device NM.

[0065] In the standby state, the control unit 1B of the network management device NM monitors the reception of a specification / policy registration request and an entity registration request in steps S30 and S40, respectively.

[0066] In this state, when a specification / policy registration request is sent from the operator terminal OT and this specification / policy registration request is received by the communication I / F unit 4B, the specification / policy registration request receiving processing unit 11B captures the specification / policy registration request in step S30 and passes the captured specification / policy registration request to the specification / policy information registration processing unit 12B.

[0067] In step S31, the specification and policy information registration processing unit 12B associates the differential specification information and policy information included in the specification and policy registration request with identification information indicating the name of the specification information to be registered, and registers them in the specification and policy information DB 31B.

[0068] FIG. 10 is a diagram showing an example of the registration result of the differential specification information and policy information. In this example, TPE_Ethernet_Spec, which represents specification information, and policy information defining its disclosure conditions have already been registered in the specification / policy information DB31B, and in this state, differential specification information and policy information for TPE_Ethernet_A_Company_Spec, TPE_Ethernet_B_Company_Spec, and TPE_Ethernet_C_Company_Spec, which represent specification information for network equipment provided by vendors A, B, and C, respectively, are additionally registered.

[0069] In this example, the registered specification information TPE_Ethernet_Spec includes four attribute information items. Each attribute information item is represented by a pair of Resource Spec Characteristic (RSC), which indicates the name of the attribute, and Resource Spec Characteristic Value (RSCV), which indicates the range that the attribute can take.

[0070] And the specification information, e.g. TPE_Ethernet_Spec RSC:vlan / RSCV:1-4096 RSC: Bandwidth / RSCV: 1-1000Mbps RSC:physicalpor / RSCV:pp name ·RSC:owner / RSCV:Owner name It is defined as follows:

[0071] The policy information associated with the registered specification information defines the application destination, disclosure conditions, and actions as attributes. These attributes are, for example, Applies to: TPE_ Ethernet_Spec Condition: "Requester is equal to owner" Action: "Discloseable" It is written as follows.

[0072] On the other hand, the differential specification information of each of the additionally registered network facilities of companies A, B, and C all contains only unique attribute information. TPE_Ethernet_Company A_Spec RSC:vlan / RSCV:1-1000 TPE_Ethernet_Company B_Spec RSC: Bandwidth / RSCV: 1-500Mbps TPE_Ethernet_CompanyC_Spec RSC: Bandwidth / RSCV: 1-500Mbps It is defined as follows:

[0073] In addition, the differential specification information of each company includes inheritance relationship information. For simplicity, FIG. 10 shows an example of the information representing this inheritance relationship, in which the inheritance relationship is represented by lines and arrows. However, in reality, for example, ·TPE_Ethernet_Spec→TPE_Ethernet_CompanyA_Spec ·TPE_Ethernet_Spec→TPE_Ethernet_CompanyB_Spec ·TPE_Ethernet_Spec→TPE_Ethernet_CompanyC_Spec The inheritance relationship information may be expressed using other symbols or text data, and may be written in any way that can be recognized by the control unit 1B.

[0074] Furthermore, of the above differential specification information, for the differential specification information of company A and company B, "Do not inherit policy" and "Inherit policy" are defined as inheritance control information, respectively, and for the differential specification information of company C, the following information is defined as information indicating the change content of the specification: Applicable to: TPE_Ethernet_CompanyC_Spec Condition: "Anyone who requests it" Action: "Discloseable" is defined.

[0075] The disclosure conditions defined in the policy information may also set whether to disclose attributes that define other attributes such as VLAN, bandwidth, number of wavelengths, and IP address of the device, or may set whether to disclose all attributes that make up the specification information. Furthermore, the disclosure conditions may set whether to disclose multiple attributes by using, for example, an AND condition or an OR condition, either alone or in combination.

[0076] (2) Registering entity information (2-1) Input and transmission of entity information by the operator terminal OT With the entity information input mode set, the network administrator then defines entity information representing the resources actually used for the network equipment to be added, and inputs the defined entity information into the input device 51 .

[0077] The control unit 1A of the operator terminal OT, under the control of the entity information input reception processing unit 13A, takes in the entity information inputted through the input device 51 in step S21 and temporarily stores it in the entity information storage unit 32A.

[0078] Next, when the control unit 1A of the operator terminal OT detects the network administrator's input operation of a transmission instruction in step S22, under the control of the entity registration request transmission processing unit 15A, in step S23, it reads the entity information from the entity information storage unit 32A and transmits a registration request for the read entity information from the communication I / F unit 4A to the network management device NM.

[0079] When the control unit 1A of the operator terminal OT has completed the input acceptance and transmission process of the entity information for one of the added network facilities, it determines in step S16 whether there is any other entity information to be registered, and if there is, it returns to step S11 and executes the series of input acceptance and transmission processes of the entity information in steps S11 to S16. Then, when an instruction to end the registration of the entity information is input, it returns to the standby state.

[0080] (2-2) Registration of entity information by the network management device NM When an entity registration request is sent from the operator terminal OT and received by the communication I / F unit 4B, the entity registration request receiving processing unit 13B captures the entity registration request in step S40 and passes the captured entity registration request to the entity information registration processing unit 14B.

[0081] Upon receiving the entity registration request, the entity information registration processing unit 14B executes a series of processes for registering entity information in step S41 as follows.

[0082] FIG. 8 is a flowchart showing an example of the processing procedure and processing contents of the entity information registration processing executed by the entity information registration processing unit 14B.

[0083] That is, first, in step S411, the entity information registration processing unit 14B reads the differential specification information of the network equipment specified by the entity registration request from the specification and policy information DB 31B. Next, in step S412, the entity information registration processing unit 14B reads the specification information of the network equipment that is the inheritance source from the specification and policy information DB 31B based on the inheritance relationship information included in the read differential specification information.

[0084] Next, in step S413, the entity information registration processing unit 14B combines the attribute information contained in the specification information of the network equipment that is the source of inheritance that has been read with the unique attribute information contained in the differential specification information, thereby generating complete specification information that includes all the attribute information necessary to define the characteristics of the network equipment.

[0085] Next, in step S414, the entity information registration processing unit 14B compares the attribute information defined by the entity information included in the entity registration request with the attribute information included in the generated complete specification information. Then, in step S415, it determines whether the possible values ​​of the attributes requested in the entity registration request are within the range of possible values ​​of attributes with matching names among the attribute information included in the complete specification information of the network equipment to be registered. In other words, it determines whether the contents of the entity registration request satisfy the registration conditions defined by the attributes in the specification information of the network equipment to be registered.

[0086] If the result of this determination is that the contents of the entity registration request satisfy the registration conditions, the entity information registration processing unit 14B proceeds to step S416, where it registers the entity information included in the entity registration request in the entity information DB 32B. Finally, in step S417, it transmits a registration completion message from the communication I / F unit 4B to the operator terminal OT that originated the request.

[0087] The entity information includes multiple pieces of attribute information corresponding to the above specification information. Each piece of attribute information is represented by a pair of an RSC that represents the name of the attribute and a Resource Characteristic Value (RCV) that represents the value for the attribute. An example of this is shown in the section on access control.

[0088] It is also possible that when a specification / policy registration request is received, the specification information of the inheritance source is read from the specification / policy information DB 31B based on the inheritance relationship information included in the specification / policy registration request, and complete specification information is generated based on this specification information of the inheritance source and the differential specification information included in the specification / policy registration request, and registered in the specification / policy information DB 31B. In this case, when determining whether or not to register entity information, the entity information registration processing unit 14B does not need to perform the process of generating the complete specification information, but can obtain the complete specification information from the specification / policy information DB 31B and determine whether or not to register the entity information.

[0089] (3) Access control for registered specification information FIG. 9 is a flowchart showing an example of the procedure and content of the access control process executed by the control unit 1B of the network management device NM.

[0090] (3-1) When policies are not inherited FIG. 11 is a diagram showing an example of access control in the case where a policy is not inherited and a disclosure request is unconditionally rejected.

[0091] Assume that a network administrator of, for example, X company, transmits a disclosure request for specification information registered in the network management device NM using a terminal UTi, which is one of the user terminals UT1 to UTn.

[0092] In response to this, the control unit 1B of the network management device NM detects the receipt of the disclosure request in step S50 under the control of the access control processing unit 15B. When the disclosure request is received, the access control processing unit 15B first acquires, in step S51, entity information corresponding to the entity name specified in the disclosure request from the entity information DB 32B.

[0093] In the example shown in FIG. 11, since TPE_Ethernet 1 is specified in the disclosure request, the access control processing unit 15B acquires the entity information indicated by TPE_Ethernet 1 from the entity information DB 32B, as shown in (1) of FIG. 11.

[0094] Next, in step S52, the access control processing unit 15B reads, from the specification / policy information DB 31B, policy information associated with the differential specification information that is the source of the entity information requested to be disclosed.

[0095] 11, the entity information TPE_Ethernet 1 requested to be disclosed includes TPE_Ethernet_Company A_spec as the differential specification information of the generating source. Therefore, the access control processing unit 15B first searches for the differential specification information TPE_Ethernet_Company A_spec, as shown in (2) in Fig. 11, and acquires the policy information associated with the retrieved differential specification information TPE_Ethernet_Company A_spec from the specification / policy information DB 31B.

[0096] After acquiring the policy information, the access control processing unit 15B next determines in step S53 whether the content of the policy information is "inheritance control information" or "policy change information." If the result of this determination is "inheritance control information," the access control processing unit 15B further determines in step S54 whether the "inheritance control information" is "inherit" or "not inherit."

[0097] In the example shown in Fig. 11, the "inheritance control information" is set to "not inherit." Therefore, as shown in (3) of Fig. 11, the access control processing unit 15B determines that no policy information is set in the differential specification information TPE_Ethernet_Company A_spec corresponding to the entity information TPE_Ethernet 1 for which disclosure has been requested. Based on the result of this determination, the access control processing unit 15B does not permit disclosure of the entity information TPE_Ethernet 1 specified by the disclosure request. Instead, in step S58, the access control processing unit 15B generates a disclosure-prohibited message and returns the generated disclosure-prohibited message from the communication I / F unit 4B to the requesting user terminal UTi.

[0098] (3-2) When the disclosure request satisfies the disclosure conditions of the inherited policy FIG. 12 is a diagram showing an example of access control when a policy is inherited and a disclosure request satisfies the disclosure condition of the inherited policy.

[0099] In addition, since the processing from step S50 to step S54 in FIG. 9 is the same as that in the case of (3-1) described above, the description thereof will be omitted.

[0100] As shown in (2) of Fig. 12, it is assumed that "inherit" is described in the policy information associated with the differential specification information TPE_Ethernet_Company_B_Spec corresponding to the entity information TPE_Ethernet_1 for which disclosure is requested. In this case, in step S55, the access control processing unit 15B searches for the specification information TPE_Ethernet_Spec that is the inheritance source of the differential specification information TPE_Ethernet_Company_B_Spec, and acquires the policy information associated with this inheritance source specification information from the specification / policy information DB 31B, as shown in (3) of Fig. 12. Then, in step S56, the access control processing unit 15B determines whether the request content of the disclosure request satisfies the disclosure conditions defined in the inherited policy information.

[0101] In the example shown in Fig. 12, the inherited policy information defines the disclosure condition as "the requester is equal to the owner," whereas the requester described in the disclosure request is "Company X." Therefore, as shown in (4) of Fig. 12, the access control processing unit 15B determines that the request content of the disclosure request satisfies the disclosure condition, because the requester, Company X, matches the owner of the entity information that is the target of the request.

[0102] Based on the result of the determination, the access control processing unit 15B transmits the entity information specified by the disclosure request from the communication I / F unit 4B to the requesting user terminal UTi in step S57. Thus, the entity information TPE_Ethernet 1 is disclosed, as shown in (5) of FIG.

[0103] (3-3) When the disclosure conditions of the inherited policy are not met FIG. 13 is a diagram showing an example of access control in a case where the policy is continued but the disclosure request does not satisfy the disclosure information of the inherited policy.

[0104] In addition, since the processing from step S50 to step S55 in FIG. 9 is the same as that in the case of (3-2) described above, the description thereof will be omitted.

[0105] In step S55, the access control processing unit 15B obtains the inherited policy information from the specification / policy information DB 31B, as shown in (3) of Figure 13, and then in step S56, determines whether the request content of the disclosure request sent from the user terminal UTi satisfies the disclosure conditions defined in the inherited policy information.

[0106] 13, the requester described in the disclosure request is "Company Y," and the inherited policy information defines the disclosure condition as "the requester is equal to the owner." Therefore, the requester, Company Y, does not match the owner of the entity information that is the target of the request, and the access control processing unit 15B determines that the request content of the disclosure request does not satisfy the disclosure condition defined in the policy, as shown in (4) of FIG.

[0107] As a result of this determination, the access control processing unit 15B denies disclosure of the entity information TPE_Ethernet 1 specified in the disclosure request, and instead generates a disclosure-prohibited message in step S58 and returns this disclosure-prohibited message from the communication I / F unit 4B to the requesting user terminal UTi.

[0108] (3-4) When the disclosure request satisfies the disclosure conditions of the revised policy FIG. 14 is a diagram showing an example of access control when a policy is changed and, as a result, a disclosure request satisfies the disclosure conditions of the changed policy.

[0109] In addition, since the processing from step S50 to step S52 in FIG. 9 is the same as the above-mentioned cases (3-1) and (3-2), the description thereof will be omitted.

[0110] If the content of the policy information associated with the differential specification information corresponding to the entity information requested to be disclosed is "policy change information," the access control processing unit 15B proceeds to step S56. Then, in step S56, it determines whether the request content of the disclosure request sent from the user terminal UTi satisfies the changed disclosure conditions defined in the policy change information.

[0111] The example shown in Figure 14 shows a case where, when registering policy information, policy information different from the policy information associated with TPE_Ethernet_Spec of the specification information from which the policy information is inherited is defined for TPE_Ethernet_C_Spec of the differential specification information, that is, a case where policy information is redefined without inheriting the policy information of the specification information from which the policy information is inherited.

[0112] In this state, when requester Y requests disclosure of entity information TPE_Ethernet 2, the owner defined for this entity information TPE_Ethernet 2 is "Company X," and this requester "Company X" satisfies the disclosure conditions and actions defined in the policy information after the change in the differential specification information corresponding to the above entity information TPE_Ethernet 2, i.e., the condition that "anyone can disclose by any requester."

[0113] As a result, based on the result of the determination, the access control processing unit 15B transmits the entity information specified by the disclosure request from the communication I / F unit 4B to the requesting user terminal UTi in step S57. Thus, the entity information TPE_Ethernet 2 is disclosed, as shown in (5) of FIG.

[0114] If the disclosure request content does not satisfy the disclosure conditions of the changed policy information in the determination of the disclosure conditions in step S56, the access control processing unit 15B proceeds to step S58. In step S58, the disclosure of the entity information TPE_Ethernet 2 is not permitted, and instead a disclosure-prohibited message is generated and returned from the communication I / F unit 4B to the requesting user terminal UTi.

[0115] (Actions and Effects) As described above, in one embodiment of the network management device NM, when externally defining specification information that defines the characteristics of network equipment similar to registered network equipment and policy information that defines the disclosure conditions thereof, differential specification information that indicates the differences between the specification information of the registered network equipment is defined as the inheritance source, and information indicating whether or not to inherit the policy information is defined, and this information is registered.

[0116] Furthermore, when a disclosure request for registered information is sent from a user in this state, the system first determines whether the policy information associated with the differential specification information corresponding to the information to be disclosed is "inherit" or "not inherit." If it is determined that the information to be disclosed is not to be inherited, the system refuses to disclose the information to be disclosed, and if it is determined that the information to be disclosed is to be inherited, the system further determines whether the disclosure request satisfies the disclosure conditions based on the policy information of the inheritor, and if the disclosure conditions are satisfied, the information to be disclosed is sent to the source of the disclosure request.

[0117] Furthermore, if "policy change information" is defined in the policy information associated with the differential specification information, it is determined whether the disclosure request satisfies the disclosure conditions based on this policy change information, and if the disclosure conditions are satisfied, the information to be disclosed is sent to the requester.

[0118] Therefore, according to one embodiment, when setting policy information for differential specification information, if the policy information to be set is identical to the policy information associated with registered specification information and this registered policy information can be inherited by the policy information, inheritance control information indicating whether or not inheritance is possible is defined as second policy information. Therefore, when setting new policy information, it is only necessary to define disclosure conditions when inheritable policy information has not already been registered. This reduces the amount of work required for network administrators to define policy information externally, compared to when disclosure conditions are unconditionally defined for all policy information each time policy information is set. As a result, it is possible to reduce the workload required for external definition processing of policy information.

[0119] Furthermore, when determining whether or not to disclose information in response to a disclosure request, even if disclosure conditions are not defined in the policy information, the policy information is inherited from the specification information from which it is inherited, so that the determination of whether or not to disclose can be made without any problems.

[0120] That is, according to one embodiment, it is possible to reduce the amount of work required for external definition processing of policy information and to reliably determine whether disclosure is permitted or not.

[0121] [Other embodiments] (1) In one embodiment, a series of processes from inputting specification information and policy information to registering them is performed simultaneously. However, the present invention is not limited to this. The series of processes from inputting specification information to registering it and the series of processes from inputting policy information to registering it may be performed independently. In this way, the network administrator can register policy information at any time, for example, after registering specification information.

[0122] (2) In one embodiment, a case has been described in which a network administrator uses an operator terminal OT to remotely register specification information, entity information, and policy information in a network management device NM. However, the present invention is not limited to this. For example, if the functions of the network management device NM are provided in an information processing device such as a personal computer located in an office, the specification information, entity information, and policy information may be registered directly in the information processing device.

[0123] (3) In one embodiment, the registration operations for specification information, entity information, and policy information are performed from a single operator terminal OT, but the registration operations for specification information, entity information, and policy information may also be performed from separate operator terminals.

[0124] (4) In one embodiment, the network management device NM is provided with the specification and policy information DB 31B and the entity information DB 32B. However, the specification and policy information DB 31B and the entity information DB 32B may be provided in a database server or the like separate from the network management device NM, and the network management device NM may access the specification and policy information DB 31B and the entity information DB 32B provided in the database server or the like to perform registration processing of the specification information, entity information, and policy information. Furthermore, the specification information registration processing function, entity information registration processing function, and policy information registration function may be distributed and located in multiple information processing devices.

[0125] (5) In addition, the functions, processing procedures and processing contents, format and data structure of specification information, entity information and policy information of the network management device can be modified and implemented in various ways without departing from the spirit of this invention.

[0126] Although the embodiments of the present invention have been described in detail above, the above description is merely an example of the present invention in every respect. It goes without saying that various improvements and modifications can be made without departing from the scope of the present invention. In other words, when implementing the present invention, specific configurations according to the embodiments may be appropriately adopted.

[0127] In short, this invention is not limited to the above-described embodiments, and in the implementation stage, the components can be modified and embodied without departing from the spirit of the invention. Furthermore, various inventions can be formed by appropriately combining multiple components disclosed in the above-described embodiments. For example, some components may be omitted from all the components shown in the embodiments. Furthermore, components from different embodiments may be appropriately combined. [Explanation of symbols]

[0128] NM...Network management device OT: Operator terminal UT1~UTn...User terminal NW...Network 1A, 1B...Control section 2A, 2B...Program memory section 3A, 3B…Data storage unit 4A, 4B...Communication I / F section 5A…I / O I / F section 6A, 5B...bus 51...Input device 52...Output device 11A...Specification information input reception processing section 12A...Policy information input reception processing unit 13A...Entity information input reception processing unit 14A...Specification / policy registration request transmission processing unit 15A...Entity registration request transmission processing unit 11B...Specification / policy registration request reception processing unit 12B...Specification and policy information registration processing section 13B...Entity registration request receiving processing unit 14B...Entity information registration processing unit 15B...Access control processing section 31A...Specification and policy information storage section 32A...Entity information storage unit 31B...Specification and policy information DB 32B...Entity information DB

Claims

1. a storage unit in which first specification information defining characteristics of a first network equipment to be managed and first policy information defining first disclosure conditions related to the first specification information are registered in a mutually associated state; a first registration processing unit that additionally registers second specification information in the storage unit, the second specification information defining characteristics of second network equipment that are partially common to the first specification information; a second registration processing unit that registers entity information, which defines actual resources to be set for the second network equipment in correspondence with a plurality of pieces of attribute information included in the second specification information, in an entity information storage unit; a third registration processing unit that registers second policy information that defines a second disclosure condition related to the second specification information in the storage unit in a state where the second policy information is associated with the second specification information; an access control processing unit that, when a disclosure request for the entity information is input, determines whether the disclosure request satisfies the second disclosure condition based on the second policy information associated with the second specification information corresponding to the entity information; Equipped with The second registration processing unit additionally registering inheritance control information indicating whether or not a disclosure condition is inherited from the first policy information to the second policy information as the second policy information; The access control processing unit It is determined whether the second policy information is the inheritance control information, and if it is determined that the second policy information is the inheritance control information, it is determined whether the disclosure request satisfies the second disclosure condition based on the inheritance control information. Network management device.

2. The access control processing unit a process of determining whether the inheritance control information indicates that there is inheritance or that there is no inheritance when it is determined that the second policy information is the inheritance control information; a process of determining that the disclosure request does not satisfy the second disclosure condition when it is determined that the inheritance is not present; If it is determined that the inheritance is present, a process of determining whether or not the disclosure request satisfies the first disclosure condition based on the first policy information that is the inheritance source; Do The network management device according to claim 1 .

3. a third registration processing unit that additionally registers policy change information representing third disclosure conditions obtained by changing at least a part of the second disclosure conditions represented by the second policy information as the second policy information in the storage unit in a state where the policy change information is associated with the second specification information; When the disclosure request for the entity information is input, the access control processing unit determines whether the second policy information associated with the second specification information corresponding to the entity information is the inheritance control information or the policy change information, and when it is determined to be the policy change information, determines whether the disclosure request satisfies the third disclosure condition based on the policy change information. The network management device according to claim 1 .

4. 4. A network management device according to claim 1, wherein the access control processing unit transmits the entity information to the sender of the disclosure request when it is determined that the disclosure request satisfies the first disclosure condition, the second disclosure condition, or the third disclosure condition defined by the second policy information.

5. when it is determined that the disclosure request does not satisfy the first disclosure condition, the second disclosure condition, or the third disclosure condition defined by the second policy information, the access control processing unit generates a disclosure not permitted message and returns the message to a sender of the disclosure request.

4. The network management device according to claim 1.

6. A network management method executed by an information processing device, comprising: a first step of registering, in a storage unit, first specification information that defines characteristics of a first network equipment to be managed and first policy information that defines first disclosure conditions related to the first specification information in a state in which the first specification information and the first policy information are associated with each other; a second step of additionally registering in the storage unit second specification information that defines characteristics of second network equipment that are partially common to the first specification information; a third step of registering entity information, which defines actual resources to be set for the second network equipment in correspondence with a plurality of pieces of attribute information included in the second specification information, in an entity information storage unit; a fourth step of registering second policy information, which defines second disclosure conditions related to the second specification information, in the storage unit in a state where the second policy information is associated with the second specification information; a fifth step of determining, when a disclosure request for the entity information is input, whether or not the disclosure request satisfies the second disclosure condition based on the second policy information associated with the second specification information corresponding to the entity information; Equipped with The fourth step is additionally registering inheritance control information indicating whether or not a disclosure condition is inherited from the first policy information to the second policy information as the second policy information; The fifth step is It is determined whether the second policy information is the inheritance control information, and if it is determined that the second policy information is the inheritance control information, it is determined whether the disclosure request satisfies the second disclosure condition based on the inheritance control information. Network management methods.

7. 4. A program for causing a processor included in the network management device to execute at least one process of each processing unit included in the network management device according to claim 1.

Citation Information

Patent Citations

  • System and method for executing hierarchical policy to computer system management

    JP1997069077A

  • How to control access by applications or application users to the management information base through the communication infrastructure

    JP1999504145A

  • Network management device, method, and program

    JP2018078523A

  • Network management device, method and program

    JP6655524B2