COMMUNICATION CONTROL DEVICE, COMMUNICATION CONTROL SYSTEM, COMMUNICATION CONTROL METHOD, AND PROGRAM

The communication control device and system address security level inadequacies by determining encryption ranges based on trust scores, ensuring appropriate encryption and decryption according to security needs, thus enhancing security and maintaining throughput.

JP7800648B2Active Publication Date: 2026-01-16NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024507239
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-15
Publication Date
2026-01-16
Estimated Expiration
2042-03-15

AI Technical Summary

Technical Problem

Existing methods for encrypting information based on trustworthiness and communication state do not adequately address the security level requirements, leading to potential security risks and reduced throughput.

Method used

A communication control device and system that acquires communication path information, determining an encryption range based on trust scores to appropriately encrypt and decrypt data according to the security level, balancing security and throughput.

Benefits of technology

Enhances information security by suitably encrypting data based on the security level while minimizing throughput reduction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007800648000001
    Figure 0007800648000001
  • Figure 0007800648000002
    Figure 0007800648000002
  • Figure 0007800648000003
    Figure 0007800648000003
Patent Text Reader

Abstract

So as to make it possible to appropriately instruct the encryption or decryption of information in accordance with a security level, this communication control device (1) comprises: an acquisition means (11) that acquires communication channel information; and an instruction means (12) that instructs at least one among the encryption and the decryption of a target flow using an encryption range in the target flow which is determined in accordance with the acquired communication channel information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a communication control device, a communication device, a communication control system, a communication control method, and a program. [Background technology]

[0002] In recent years, networks have been increasingly constructed by connecting multiple information processing devices via relay devices. As a result, security risks between the devices have also increased. Related technologies include the inventions disclosed in the following Patent Documents 1 and 2.

[0003] Patent Document 1 discloses that when an information processing device stores information consisting of a plurality of items with different security levels in an information management device, the encryption level of the information is changed according to a predetermined trustworthiness.

[0004] Patent document 2 discloses a method of monitoring the state of a communication unit, acquiring quality information that identifies the current communication state, determining an encryption level based on the acquired quality information, and encrypting transmission data based on the determined encryption level. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2006-157883 [Patent Document 2] Japanese Patent Publication No. 2004-064652 Summary of the Invention [Problem to be solved by the invention]

[0006] Patent Document 1 discloses that an information processing device varies the encryption level of information depending on a predetermined trustworthiness. However, simply varying the encryption level may not be enough to encrypt information appropriately depending on the security level.

[0007] Furthermore, Patent Document 2 discloses that the encryption level is determined based on quality information that identifies the current communication state. However, as with Patent Document 1, simply changing the encryption level may not result in the information being encrypted appropriately according to the security level.

[0008] One aspect of the present invention has been made in view of the above problems, and an object of the present invention is to provide a technique that can suitably encrypt information according to the security level. [Means for solving the problem]

[0009] A communication control device according to one embodiment of the present invention includes an acquisition means for acquiring communication path information, and an instruction means for instructing at least one of encryption and decryption of a target flow using an encryption range determined according to the acquired communication path information, the encryption range being determined in accordance with the encryption range of the target flow.

[0010] A communication device according to one aspect of the present invention includes an acquisition means for acquiring communication path information, and an execution means for performing at least one of encryption and decryption of a target flow using an encryption range determined according to the acquired communication path information, the encryption range being determined in accordance with the acquired communication path information.

[0011] A communication control system according to one embodiment of the present invention includes an acquisition means for acquiring communication path information, an instruction means for instructing at least one of encryption and decryption of a target flow using an encryption range in the target flow, the encryption range being determined according to the acquired communication path information, and an execution means for executing at least one of encryption and decryption of the target flow using the encryption range in the target flow.

[0012] A communication control method according to one aspect of the present invention acquires communication path information, and instructs at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information.

[0013] A communication control method according to one aspect of the present invention acquires communication path information, and performs at least one of encryption and decryption of a target flow using an encryption range for the target flow that is determined according to the acquired communication path information.

[0014] A program according to one aspect of the present invention causes a computer to execute a process of acquiring communication path information and a process of instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information.

[0015] A program according to one aspect of the present invention causes a computer to perform the following processes: acquiring communication path information; and performing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information. [Effects of the Invention]

[0016] According to one aspect of the present invention, information can be suitably encrypted according to the security level. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a block diagram showing an example of the configuration of a communication control device according to a first exemplary embodiment of the present invention. [Figure 2] 3 is a flowchart showing the flow of a communication control method for a communication control device according to a first exemplary embodiment of the present invention. FIG. [Figure 3] 1 is a block diagram showing an example of the configuration of a communication device according to a first exemplary embodiment of the present invention. [Figure 4]1 is a flowchart showing the flow of a communication control method for a communication device according to a first exemplary embodiment of the present invention. [Figure 5] 1 is a block diagram showing an example of the configuration of a communication control system according to a first exemplary embodiment of the present invention. [Figure 6] FIG. 10 is a block diagram showing an example of the configuration of a communication control device and a communication device according to a second exemplary embodiment of the present invention. [Figure 7] FIG. 10 is a diagram schematically illustrating a connection between a communication control device and a communication device according to a second exemplary embodiment of the present invention. [Figure 8] FIG. 10 is a diagram illustrating an example of a packet encryption range. [Figure 9] FIG. 10 is a diagram illustrating a trust score between communication devices. [Figure 10] FIG. 10 is a diagram for explaining a method for calculating a risk score. [Figure 11] FIG. 10 is a diagram illustrating the relationship between a risk score and an encryption range. [Figure 12] FIG. 1 is a diagram for explaining a processing flow (part 1) when a terminal is newly connected to a network. [Figure 13] FIG. 10 is a diagram for explaining the processing flow (part 2) when a new terminal is connected to a network. [Figure 14] FIG. 10 is a diagram for explaining the processing flow (part 3) when a new terminal is connected to a network. [Figure 15] FIG. 10 is a diagram for explaining a processing flow (part 1) when changing the encryption range of a packet. [Figure 16] FIG. 10 is a diagram for explaining a second processing flow when changing the encryption range of a packet. [Figure 17] FIG. 10 is a block diagram showing an example of the configuration of a communication device according to a third exemplary embodiment of the present invention. [Figure 18] 1 is a block diagram illustrating a configuration of a computer that functions as a communication control device and a communication device according to each exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0018] Exemplary Embodiment 1 <Background of the invention> The OSI (Open Systems Interconnection) reference model, developed by the ISO (International Organization for Standardization), divides computer communication functions into a hierarchical structure, and defines communication functions (communication protocols) as being divided into seven layers.

[0019] The headers of communication packets are added according to the layer, and mainly include a MAC (Media Access Control) header, an IP (Internet Protocol) header, and a TCP / UDP (Transmission Control Protocol / User Datagram Protocol) header.

[0020] Each layer has inherent security risks. For example, the MAC header contains information such as the source MAC address and destination MAC address, which can be used to spoof or identify users.

[0021] In addition, the IP header contains information such as the source IP address and destination IP address, which can be used to spoof or identify users. In addition, the TCP / UDP header contains information such as the source port number and destination port number, which can be used to identify user information (such as the type of server). In addition, the data portion can lead to the leakage of information being exchanged.

[0022] As described above, because each area of ​​a communication packet poses a security risk, the security level can be increased by increasing the encryption range. However, increasing the encryption range also reduces throughput. For example, when encrypting destination information such as MAC addresses and IP addresses, the following processing must be performed in relay devices such as access points, switches, and routers. To confirm the packet destination, it is necessary to decrypt the encrypted destination of the received packet, and then encrypt the destination before sending the packet. A new destination frame needs to be added. If the packet destination is unknown, it must be broadcast so that the terminal receives only packets addressed to itself.

[0023] Furthermore, if the encryption range in a communication packet is increased, a random number must be generated for each area, which can further reduce throughput depending on the speed at which the random numbers are generated.

[0024] The present invention appropriately controls the encryption range of communication packets according to the required security level while suppressing a decrease in throughput.

[0025] <Communication control device 1 according to exemplary embodiment 1> A first exemplary embodiment of the present invention will be described in detail with reference to the drawings. This exemplary embodiment is a basic form of the exemplary embodiments described below. Note that the drawing reference symbols added to this overview are added to each element for convenience as an example to facilitate understanding, and are not intended to limit the present invention to the illustrated form. Furthermore, connection lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality. Furthermore, the connection points of inputs and outputs of each block in the drawings may be configured to include ports or interfaces, but these configurations are not shown in the drawings.

[0026] 1 is a block diagram showing an example of the configuration of a communication control device 1 according to a first exemplary embodiment of the present invention. As shown in FIG. 1, the communication control device 1 according to this exemplary embodiment includes an acquisition unit 11 and an instruction unit 12.

[0027] The communication control device 1 is a controller or the like that controls relay devices such as access points, switches, and routers, and mainly acquires communication path information from each relay device, and issues encryption and decryption instructions to each relay device and each adapter.

[0028] The acquisition means 11 acquires communication path information. The communication path information is information about each communication path in a communication flow, for example, information in which the reliability of each communication path is quantified as a trust score.

[0029] A communication flow is a communication path from one terminal (source) to another terminal (destination). If there are multiple relay devices between the terminals, the paths between the relay devices form a single communication path. In addition, the path between an adapter connected to a terminal and a relay device also forms a single communication path. Therefore, if there are relay devices between the terminals, the communication flow will include multiple communication paths.

[0030] The credit score of a communication path can be determined, for example, by the type of communication medium of the communication path. If the communication medium is wired, a high value is set as the credit score, and if the communication medium is wireless, a low value is set as the credit score.

[0031] The trust score of a communication path can also be determined based on information about the LAN (Local Area Network) to which the communication path belongs. Furthermore, the trust score of a communication path can also be determined based on the presence or absence of suspicious traffic. In this case, a high value is set as the trust score for a communication path without suspicious traffic, and a low value is set as the trust score for a communication path with suspicious traffic.

[0032] The instruction means 12 instructs at least one of encryption and decryption of the target flow using the encryption range for the target flow, which is determined according to the acquired communication path information. Specifically, a risk score indicating the risk level of the target flow is calculated by referring to the trust score for each communication path of the target flow. If the risk score is low (if the reliability is high), a narrow encryption range is set. On the other hand, if the risk score is high (if the reliability is low), a wide encryption range is set.

[0033] For example, if a packet contains data, a first header, a second header, and a third header, different encryption ranges can be set as follows: (1) the encryption range is set to only the data and the first header; (2) the encryption range is set to the data, the first header, and the second header; or (3) the encryption range is set to the data, the first header, the second header, and the third header.

[0034] The instruction unit 12 then instructs the relay devices and adapters present on each communication path of the target flow to encrypt and / or decrypt communication packets using the encryption range of the target flow. Therefore, if there are multiple communication flows from one terminal to another, different encryption ranges may be set for each communication flow.

[0035] <Effects of communication control device 1> As described above, according to the communication control device 1 of this exemplary embodiment, the instruction means 12 instructs at least one of encryption and decryption of the target flow using the encryption range determined according to the communication path information, so that encryption or decryption of information can be instructed appropriately according to the security level.

[0036] <Flow of communication control method by communication control device 1> The flow of the communication control method executed by the communication control device 1 configured as above will be described with reference to Fig. 2. Fig. 2 is a flow diagram showing the flow of the communication control method. As shown in Fig. 2, the communication control method includes steps S1 to S2.

[0037] First, the acquisition means 11 acquires communication path information (S1). The communication path information is information about each communication path in a communication flow, and is, for example, information in which the reliability of each communication path is quantified as a trust score.

[0038] Next, the instruction means 12 instructs the relay devices present on each communication path of the target flow to encrypt and / or decrypt communication packets using the encryption range for the target flow, which is determined according to the acquired communication path information (S2). Specifically, the instruction means 12 instructs the relay devices present on each communication path of the target flow to encrypt and / or decrypt communication packets using the encryption range for the target flow.

[0039] <Effects of communication control methods> As described above, according to the communication control method of this exemplary embodiment, the instruction means 12 instructs at least one of encryption and decryption of the target flow using the encryption range determined according to the communication path information, so that it is possible to instruct encryption or decryption of information appropriately according to the security level.

[0040] <Configuration of communication device 2> 3 is a block diagram showing an example of the configuration of a communication device 2 according to a first exemplary embodiment of the present invention. As shown in FIG. 3, the communication device 2 according to this exemplary embodiment includes an acquisition unit 21 and an execution unit 22.

[0041] The communication device 2 is a relay device such as an access point, switch, or router, and mainly performs tasks such as obtaining communication path information for each communication path and encrypting and decrypting information within the encryption range specified by the communication control device 1.

[0042] The acquisition means 21 acquires communication path information. The communication path information is information about each communication path in a communication flow, for example, information in which the reliability of each communication path is quantified as a trust score.

[0043] The execution means 22 executes at least one of encryption and decryption of the target flow using the encryption range for the target flow, which is determined according to the acquired communication path information. Specifically, the execution means 22 executes at least one of encryption and decryption of the communication packets using the encryption range instructed by the communication control device 1.

[0044] <Effects of communication device 2> As described above, according to the communication device 2 of this exemplary embodiment, the execution means 22 performs at least one of encryption and decryption of the target flow using the encryption range determined according to the communication path information, so that information can be encrypted or decrypted appropriately according to the security level.

[0045] <Flow of communication control method by communication device 2> The flow of the communication control method executed by the communication device 2 configured as above will be described with reference to Fig. 4. Fig. 4 is a flow diagram showing the flow of the communication control method. As shown in Fig. 4, the communication control method includes steps S11 to S12.

[0046] First, the acquisition means 21 acquires communication path information (S11). The communication path information is information about each communication path in a communication flow, and is, for example, information in which the reliability of each communication path is quantified as a trust score.

[0047] Next, the execution means 22 executes at least one of encryption and decryption of the target flow using the encryption range for the target flow, which is determined according to the acquired communication path information (S12). Specifically, at least one of encryption and decryption of the communication packets is executed using the encryption range instructed by the communication control device 1.

[0048] <Effects of the communication control method of the communication device 2> As described above, according to the communication control method of this exemplary embodiment, the execution means 22 performs at least one of encryption and decryption of the target flow using the encryption range determined according to the communication path information, so that information can be encrypted or decrypted appropriately according to the security level.

[0049] <Configuration of communication control system 100> 5, the communication control system 100 according to this exemplary embodiment includes an acquisition unit 31, an instruction unit 32, and an execution unit 33. The acquisition unit 31, the instruction unit 32, and the execution unit 33 are configured to be able to communicate with each other via a network N, for example. The specific configuration of the network N does not limit this exemplary embodiment, but may be, for example, a wireless LAN, a wired LAN, a WAN, a public line network, a mobile data communication network, or a combination of these networks.

[0050] Each function of the communication control system 100 may be implemented on the cloud. For example, the acquisition means 31 and the instruction means 32 may be one device, and the execution means 33 may be one device. These may be implemented in one device, or may be implemented in separate devices. For example, when implemented in separate devices, information from each unit is sent and received via a network N to proceed with processing.

[0051] The acquisition means 31 acquires communication path information. The communication path information is information about each communication path in a communication flow, and is, for example, information in which the reliability of each communication path is quantified as a credit score.

[0052] The instruction means 32 instructs at least one of encryption and decryption of the target flow using the encryption range for the target flow, which is determined according to the acquired communication path information.

[0053] The execution means 33 executes at least one of encryption and decryption of the target flow using the encryption range for the target flow, which is determined according to the acquired communication path information.

[0054] <Effects of the communication control system 100> As described above, according to the communication control system 100 of this exemplary embodiment, the instruction means 32 instructs at least one of encryption and decryption of the target flow using the encryption range determined according to the communication path information, so that encryption or decryption of information can be instructed appropriately according to the security level.

[0055] Furthermore, since the execution means 33 performs at least one of encryption and decryption of the target flow using the encryption range determined according to the communication path information, it is possible to encrypt or decrypt information appropriately according to the security level.

[0056] Exemplary Embodiment 2 A second exemplary embodiment of the present invention will be described in detail with reference to the drawings. Note that components having the same functions as those described in the first exemplary embodiment are given the same reference numerals, and their description will be omitted as appropriate.

[0057] <Configuration Example of Communication Control Device 1A According to Exemplary Embodiment 2> 6 is a diagram showing the configuration of a communication control system 100A including a communication control device 1A and a communication device 2A according to a second exemplary embodiment of the present invention. The communication control system 100A according to this exemplary embodiment includes the communication control device 1A and communication devices 2A-1 to 2A-N. As shown in FIG. 6, the communication control device 1A includes a communication unit 41, a control unit 42, a storage unit 43, and an input unit 44.

[0058] The communication unit 41 transmits and receives information to and from the communication devices 2A-1 to 2A-N. The communication unit 41 includes an acquisition unit 11. The acquisition unit 11 is configured to realize an acquisition means in this exemplary embodiment.

[0059] 7 is a diagram schematically illustrating a connection between a communication control device 1A and a communication device 2A according to a second exemplary embodiment of the present invention. The communication devices 2A-1 to 2A-N illustrated in FIG. 6 correspond to relay devices 2A-1 to 2A-3, such as access points, switches, and routers, and adapters 2A-4 to 2A-6, illustrated in FIG. 7. The terminals 4-1 to 4-3 are connected to the adapters 2A-4 to 2A-6, respectively. Note that while FIG. 7 schematically illustrates that the communication control device 1A controls the relay devices 2A-1 to 2A-3 and the adapters 2A-4 to 2A-6, in reality, the communication control device 1A controls the relay devices 2A-1 to 2A-3 and the adapters 2A-4 to 2A-6 by transmitting and receiving information via a communication unit 41.

[0060] Adapters 2A-4 to 2A-6 encrypt communication packets from terminals 4-1 to 4-3 and transmit them to relay device 2A-2 or 2A-3. Adapters 2A-4 to 2A-6 also decrypt communication packets received from relay device 2A-2 or 2A-3 and output them to terminals 4-1 to 4-3.

[0061] The relay devices 2A-1 to 2A-3 decrypt the received communication packets, confirm the destination, and then re-encrypt and transmit the communication packets. The relay devices 2A-1 to 2A-3 also acquire communication path information of the communication path and notify the communication control device 1A.

[0062] The acquisition unit 11 acquires communication path information from the communication devices 2A-1 to 2A-N. The communication path information is information about each communication path in a communication flow, and is, for example, information in which the reliability of each communication path is quantified as a credit score.

[0063] The control unit 42 is a part that performs overall control of the communication control device 1A, and includes an instruction unit 12 and a determination unit 13. The instruction unit 12 is configured to realize the instruction means in this exemplary embodiment. The determination unit 13 is configured to realize the determination means in this exemplary embodiment.

[0064] The control unit 42 periodically causes the acquisition unit 11 to acquire communication path information from the communication devices 2A-1 to 2A-N, and stores the acquired communication path information in the storage unit 43.

[0065] The determination unit 13 determines the encryption scope for a target flow by referring to communication path information for each communication path in the target flow stored in the storage unit 43. Specifically, the communication path information is information in which the reliability of each communication path in the target flow is quantified as a credit score, and the determination unit 13 calculates a risk score for the target flow from the credit score of each communication path in the target flow stored in the storage unit 43, and determines the encryption scope for the target flow according to the risk score.

[0066] FIG. 8 is a diagram showing an example of the encryption range of a packet. (1) in FIG. 8 shows a case where the risk score is equal to or less than the first threshold, and only the data and TCP / UDP header of the communication packet are encrypted. In (1) in FIG. 8, the entire data and TCP / UDP header are encrypted. However, for example, only part of the data and the source port number in the TCP / UDP header may be encrypted, or only part of the data and the destination port number in the TCP / UDP header may be encrypted. Furthermore, the security level may be improved by encrypting only part of the data and part of the TCP / UDP header and periodically changing the encryption range.

[0067] 8(2) shows the case where the risk score is equal to or greater than the first threshold and equal to or less than the second threshold, and the encryption range is set to the communication packet data, TCP / UDP header, and IP header. As with the TCP / UDP header, the encryption range may be set to only the source IP address in the IP header, or only the destination IP address.

[0068] 8(3) shows the case where the risk score is equal to or greater than the second threshold, and the encryption range is the communication packet data, TCP / UDP header, IP header, and MAC header. As with the TCP / UDP header and IP header, the encryption range may be set to only the source MAC address in the MAC header, or only the destination MAC address.

[0069] 9 is a diagram showing a schematic diagram of the trust scores between communication devices. The relay device 2A-1 is an L3 switch and has the function of routing only TCP / IP of Layer 3 (network layer). The relay device 2A-2 is an L2 switch and has the function of routing multiple protocols including Layer 2 (data link layer).

[0070] The relay device 2A-3 is an access point and communicates wirelessly with the adapter 2A-6. In Fig. 9, the trust score of the communication path between the access point 2A-3 and the adapter 2A-6 is low, and the trust score of the communication path between the L3 switch 2A-1 and the access point 2A-3 is medium. The trust scores of the other communication paths are high.

[0071] 9, in the communication flow of terminal 4-2 - adapter 2A-5 - L2 switch 2A-2 - L3 switch 2A-1 - adapter 2A-7 - terminal 4-4, the risk score calculated from the credit score is low, so the encryption range is up to the IP header corresponding to L3. Also, in the communication flow of terminal 4-3 - adapter 2A-6 - access point 2A-3 - L3 switch 2A-1 - adapter 2A-7 - terminal 4-4, the risk score calculated from the credit score is high, so the encryption range is up to the MAC header corresponding to L2.

[0072] FIG. 10 is a diagram for explaining a method for calculating a risk score. For example, the reliability of each communication path is evaluated as a credit score of 1 to 5. If the communication path is wired and no suspicious traffic is detected, the credit score is "5." If the communication path is wireless and no suspicious traffic is detected, the credit score is "4." If the communication path is wired and suspicious traffic is detected, the credit score is "2." If the communication path is wireless and suspicious traffic is detected, the credit score is "1."

[0073] 10, the trust score between the adapter 2A-7 and the L3 switch 2A-1 is "2," the trust score between the L3 switch 2A-1 and the access point 2A-3 is "5," and the trust score between the access point 2A-3 and the adapter 2A-6 is "4." If the sum of the trust scores of the communication paths included in the communication flow is calculated and the difference from the perfect score is taken as the risk score of that communication flow, the risk score is as shown in the following formula (Formula 1).

[0074] Risk score = 5 × 3 - (2 + 5 + 4) = 4 (Equation 1) In FIG. 10, the number of communication paths is "3", but since the risk score tends to increase as the number of communication paths increases, it may be normalized by dividing by the number of communication paths.

[0075] 11 is a diagram illustrating the relationship between the risk score and the encryption scope. When the risk score is equal to or less than the first threshold, the determination unit 13 sets the encryption scope to the data and the first header of the packet transmitted through the target flow. For example, the first header is a TCP ( / UDP) header. The first header may also be an IP header or a MAC header.

[0076] The determination unit 13 may set the encryption range to the data of the packet transmitted through the target flow and a part of the first header. For example, the encryption range may be only a part of the data and the source port number in the TCP / UDP header, or only a part of the data and the destination port number in the TCP / UDP header.

[0077] When the risk score is equal to or greater than a first threshold and equal to or less than a second threshold that is greater than the first threshold, the determination unit 13 determines the encryption scope to be the data, first header, and second header of the packet transmitted through the target flow. For example, the first header may be a TCP / UDP header, and the second header may be an IP header. Alternatively, the first header may be an IP header, and the second header may be a MAC header. The combination of the first header and the second header is arbitrary.

[0078] If the risk score is equal to or greater than the second threshold, the determination unit 13 sets the encryption range to the data, first header, second header, and third header of the packet transmitted through the target flow. For example, the first header is a TCP / UDP header, the second header is an IP header, and the third header is a MAC header.

[0079] The communication path information is information that is quantified according to the communication medium of each communication path in the target flow. For example, if the communication medium of the communication path is wired, a high value is set as the trust score, which is communication path information, and if the communication medium is wireless, a low value is set as the trust score, which is communication path information.

[0080] The communication path information is information that is quantified according to the presence of suspicious traffic on each communication path in the target flow. For example, if a communication path does not have suspicious traffic, a high value is set as the trust score, which is communication path information, and if a communication path has suspicious traffic, a low value is set as the trust score, which is communication path information.

[0081] Returning to the explanation of Fig. 6, the instruction unit 12 instructs the relay devices and adapters present on each communication path of the target flow to at least encrypt and decrypt communication packets using the encryption range determined by the determination unit 13. At this time, the instruction unit 12 generates random numbers corresponding to each area of ​​the encryption range and transmits them to the relay devices and adapters present on each communication path of the target flow.

[0082] For example, if the encryption scope is data, TCP / UDP header, and IP header, a random number corresponding to the data, a random number corresponding to the TCP / UDP header, and a random number corresponding to the IP header are generated, and the three random numbers are sent to the relay devices and adapters present on each communication path of the target flow to instruct them to at least encrypt and decrypt the communication packets.

[0083] In order to periodically update the random numbers, the instruction unit 12 may generate random numbers corresponding to each area of ​​the encryption range and transmit the random numbers to the relay devices and adapters present on each communication path of the target flow.

[0084] The input unit 44 is configured with, for example, switches and is used to set the mode of the communication control device 1 A. The control unit 42 acquires the value set in the input unit 44 and sets or changes the operation mode and the like.

[0085] <Configuration Example of Communication Device 2A According to Exemplary Embodiment 2> As shown in Fig. 6, the communication device 2A-1 includes a communication unit 51, a control unit 52, a storage unit 53, and an input unit 54. The communication unit 51 transmits and receives information to and from the communication control device 1A. The communication unit 51 includes an acquisition unit 21 and a reception unit 23. The acquisition unit 21 is configured to realize the acquisition means in this exemplary embodiment. The reception unit 23 is configured to realize the reception means in this exemplary embodiment.

[0086] The acquisition unit 21 acquires communication path information. The communication unit 51 transmits the communication path information acquired by the acquisition unit 21 to the communication control device 1A. The communication path information is information about each communication path in a communication flow, and is, for example, information in which the reliability of each communication path is quantified as a credit score.

[0087] The receiving unit 23 receives the encryption range for the target flow from the communication control device 1A that controls the communication devices 2A-1 to 2A-N, and stores the encryption range in the storage unit 53. The receiving unit 23 also receives random numbers corresponding to each area of ​​the encryption range from the communication control device 1A, and stores the random numbers in the storage unit 53.

[0088] The control unit 52 is a component that performs overall control of the communication device 2A-1 and includes an execution unit 22. The execution unit 22 is configured to realize the execution means in this exemplary embodiment. The execution unit 22 performs at least one of encryption and decryption of the target flow using the encryption range for the target flow stored in the storage unit 53. At this time, a random number corresponding to each area of ​​the encryption range stored in the storage unit 53 is used.

[0089] The input unit 54 is configured with, for example, switches and is used to set the mode of the communication device 2A-1, etc. The control unit 52 acquires the value set in the input unit 54 and sets or changes the operation mode, etc.

[0090] 12 to 14 are diagrams illustrating the flow of processing when a new terminal is connected to the network. First, a plaintext data packet is sent from terminal 4-4 to adapter 2A-7 (S21). Next, adapter 2A-7 confirms that there is no information about the encryption range of flow a (S22). Note that flow a is a communication flow from terminal 4-4 to adapter 2A-7 to L3 switch 2A-1 to access point 2A-3 to adapter 2A-6.

[0091] Next, the adapter 2A-7 requests information on the encryption range of flow a from the communication control device 1A (S23). When the communication unit 41 of the communication control device 1A receives the encryption range request from the adapter 2A-7, the acquisition unit 11 of the communication control device 1A requests the relay devices 2A-1 and 2A-3 through which flow a passes to report communication path information (S24).

[0092] Next, when the relay devices 2A-1 and 2A-3 report the communication path information to the communication control device 1A (S25), the decision unit 13 of the communication control device 1A uses the reported communication path information as a trust score for each communication path (S26).The decision unit 13 of the communication control device 1A then calculates a risk score for flow a from the trust scores of each communication path, and decides the encryption scope of flow a based on the risk score (S27).

[0093] Next, the communication unit 41 of the communication control device 1A transmits the encryption range of the flow a determined by the determination unit 13 to the adapter 2A-7, the L3 switch 2A-1, the access point 2A-3, and the adapter 2A-6 (S28).

[0094] The adapter 2A-7 encrypts the packet in the encryption range specified by the communication control device 1A and transmits the packet to the L3 switch 2A-1 (S29). When the L3 switch 2A-1 receives the packet from the adapter 2A-7, if the encryption range is up to the MAC header or IP header, it decrypts the packet in the encryption range specified by the communication control device 1A, confirms the destination, encrypts the packet again, and transmits it to the access point 2A-3.

[0095] Similarly, when the access point 2A-3 receives a packet from the L3 switch 2A-1, if the encryption range is up to the MAC header or IP header, it decrypts the packet within the encryption range instructed by the communication control device 1A, confirms the destination, and then re-encrypts the packet and sends it to the adapter 2A-6 (S30).

[0096] Finally, the adapter 2A-6 decrypts the packet received from the access point 2A-3 within the encryption range specified by the communication control device 1A, and transmits it to the terminal 4-3 (S31), thereby completing the process.

[0097] 15 and 16 are diagrams illustrating the flow of processing when changing the encryption range of a packet. The communication control device 1A periodically requests communication path information from the L3 switch 2A-1 and the access point 2A-3 (S41).

[0098] When the L3 switch 2A-1 and the access point 2A-3 report the communication path information to the communication control device 1A (S42), the decision unit 13 of the communication control device 1A uses the reported communication path information as the trust score of each communication path (S43).

[0099] Next, the determination unit 13 of the communication control device 1A calculates a risk score for each flow from the credit score, and determines the encryption scope for each flow based on the risk score (S44). The determination unit 13 of the communication control device 1A compares the current encryption scope for each flow stored in the storage unit 43 with the encryption scope for each flow calculated in step S44. Then, for flows with different encryption scopes, the instruction unit 12 instructs the relay devices and adapters through which the flows pass to change the encryption scope (S45). For example, to change the encryption scope for flow a, the instruction unit 12 instructs the adapter 2A-7, L3 switch 2A-1, access point 2A-3, and adapter 2A-6 to change the encryption scope.

[0100] The adapter 2A-7 encrypts the packet received from the terminal 4-4 in the encryption range specified in step S45 and transmits the packet to the L3 switch 2A-1 (S46). When the L3 switch 2A-1 receives the packet from the adapter 2A-7, if the encryption range is up to the MAC header or IP header, it decrypts the packet in the encryption range specified by the communication control device 1A to confirm the destination, encrypts the packet again, and transmits it to the access point 2A-3.

[0101] Similarly, when the access point 2A-3 receives a packet from the L3 switch 2A-1, if the encryption range is up to the MAC header or IP header, it decrypts the packet within the encryption range instructed by the communication control device 1A, confirms the destination, and then re-encrypts the packet and sends it to the adapter 2A-6 (S47).

[0102] Finally, the adapter 2A-6 decrypts the packet received from the access point 2A-3 within the encryption range specified by the communication control device 1A, and transmits it to the terminal 4-3 (S48), thereby completing the process.

[0103] <Effects of the communication control system 100A> As described above, according to the communication control device 1A of this exemplary embodiment, the determination unit 13 determines the encryption range for the target flow by referring to the communication path information of each communication path in the target flow, so that the encryption range for the target flow can be suitably determined according to the security level.

[0104] Furthermore, since the determination unit 13 of the communication control device 1A determines the encryption range for the target flow according to the risk score, it is possible to suitably determine the encryption range for the target flow according to the risk score.

[0105] Furthermore, when the risk score is low, the decision unit 13 of the communication control device 1A can set the encryption range to only the data and the first header of the packet.

[0106] Furthermore, the determination unit 13 of the communication control device 1A can reduce the processing load on the communication device by encrypting only part of the data and header of the packet.

[0107] Furthermore, when the risk score is medium, the decision unit 13 of the communication control device 1A can set the encryption range to the packet data, the first header, and the second header.

[0108] Furthermore, when the risk score is high, the decision unit 13 of the communication control device 1A can set the encryption range to the data, the first header, the second header, and the third header of the packet.

[0109] Furthermore, since the communication path information is quantified information according to the communication medium of each communication path in the target flow, the decision unit 13 of the communication control device 1A can increase the trust score, which is the communication path information, in the case of wired communication, and can decrease the trust score, which is the communication path information, in the case of wireless communication.

[0110] Furthermore, since the communication path information is information that has been quantified according to the presence of suspicious traffic on each communication path in the target flow, the decision unit 13 of the communication control device 1A can increase the trust score, which is the communication path information, in the case of a communication path where no suspicious traffic exists, and can decrease the trust score, which is the communication path information, in the case of a communication path where suspicious traffic exists.

[0111] Furthermore, the execution unit 22 of the communication device 2A can encrypt or decrypt information according to the encryption range received from the communication control device 1A.

[0112] Exemplary Embodiment 3 A third exemplary embodiment of the present invention will be described in detail with reference to the drawings. Components having the same functions as those described in the first and second exemplary embodiments are given the same reference numerals, and their description will be omitted as appropriate. In this exemplary embodiment, there is no communication control device, and the communication device itself determines the encryption range and encrypts and decrypts information.

[0113] <Configuration Example of Communication Device 2B According to Exemplary Embodiment 3> 17 is a diagram showing the configuration of a communication control system 100B including a communication device 2B according to a third exemplary embodiment of the present invention. The communication control system 100B according to this exemplary embodiment includes communication devices 2B-1 to 2B-N. As shown in FIG. 17, the communication device 2B-1 includes a communication unit 51B, a control unit 52B, a storage unit 53, and an input unit 54.

[0114] The communication unit 51B transmits and receives information to and from the communication devices 2B-2 to 2B-N. The communication unit 51B includes an acquisition unit 21. The acquisition unit 21 is configured to realize an acquisition means in this exemplary embodiment.

[0115] The acquiring unit 21 acquires communication path information. Specifically, the acquiring unit 21 acquires communication path information of the communication path to which the communication device 2B-1 itself is connected and communication path information of other communication paths of the target flows received from the communication devices 2B-2 to 2B-N, and stores the acquired information in the storage unit 53.

[0116] The determination unit 24 determines the encryption scope for a target flow by referring to communication path information for each communication path in the target flow stored in the storage unit 53. Specifically, the communication path information is information in which the reliability of each communication path in the target flow is quantified as a credit score, and the determination unit 24 calculates a risk score for the target flow from the credit score of each communication path in the target flow stored in the storage unit 53, and determines the encryption scope for the target flow according to the risk score.

[0117] The execution unit 22 uses the encryption range determined by the determination unit 24 to perform at least one of encryption and decryption of the target flow.

[0118] <Effects of the communication control system 100B> As described above, according to the communication device 2B of this exemplary embodiment, the determination unit 24 determines the encryption range for the target flow by referring to the communication path information for each communication path in the target flow, and therefore, the encryption range for the target flow can be suitably determined according to the security level.

[0119] [Software implementation example] Some or all of the functions of the communication control devices 1, 1A, communication devices 2, 2A, 2B, and communication control systems 100, 100A, 100B may be realized by hardware such as an integrated circuit (IC chip), or by software.

[0120] In the latter case, the communication control devices 1 and 1A, the communication devices 2, 2A, and 2B, and the communication control systems 100, 100A, and 100B are realized, for example, by a computer that executes program instructions, which are software that realizes each function. An example of such a computer (hereinafter referred to as computer C) is shown in FIG. 9. The computer C includes at least one processor C1 and at least one memory C2. The memory C2 stores a program P for causing the computer C to operate as the communication control devices 1 and 1A, the communication devices 2, 2A, and 2B, and the communication control systems 100, 100A, and 100B. In the computer C, the processor C1 reads and executes the program P from the memory C2, thereby realizing each function of the communication control devices 1 and 1A, the communication devices 2, 2A, and 2B, and the communication control systems 100, 100A, and 100B.

[0121] The processor C1 may be, for example, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a micro processing unit (MPU), a floating point number processing unit (FPU), a physics processing unit (PPU), a microcontroller, or a combination thereof. The memory C2 may be, for example, a flash memory, a hard disk drive (HDD), a solid state drive (SSD), or a combination thereof.

[0122] The computer C may further include a RAM for expanding the program P during execution and for temporarily storing various data. The computer C may also include a communication interface for transmitting and receiving data to and from other devices. The computer C may also include an input / output interface for connecting input / output devices such as a keyboard, mouse, display, and printer.

[0123] Furthermore, the program P can be recorded on a non-transitory tangible recording medium M that can be read by the computer C. Such a recording medium M can be, for example, a tape, a disk, a card, a semiconductor memory, or a programmable logic circuit. The computer C can acquire the program P via such a recording medium M. The program P can also be transmitted via a transmission medium. Such a transmission medium can be, for example, a communication network or broadcast waves. The computer C can also acquire the program P via such a transmission medium.

[0124] [Appendix 1] The present invention is not limited to the above-described embodiments, and various modifications are possible within the scope of the claims. For example, embodiments obtained by appropriately combining the technical means disclosed in the above-described embodiments are also included in the technical scope of the present invention.

[0125] [Appendix 2] Some or all of the above-described embodiments can also be described as follows: However, the present invention is not limited to the following described aspects.

[0126] (Appendix 1) an acquisition means for acquiring communication path information; an instruction means for instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; A communication control device comprising:

[0127] According to the above configuration, it is possible to instruct encryption or decryption of information appropriately according to the security level.

[0128] (Appendix 2) The encryption method further includes a determination unit that determines the encryption range of the target flow by referring to the communication path information of each communication path in the target flow. 2. The communication control device of claim 1.

[0129] According to the above configuration, the encryption range of the target flow can be suitably determined according to the security level.

[0130] (Appendix 3) the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, The determining means Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; 3. The communication control device according to claim 2.

[0131] According to the above configuration, the encryption range for the target flow can be suitably determined according to the risk score.

[0132] (Appendix 4) When the risk score is equal to or less than a first threshold, the determination means sets the encryption range to the data and the first header of the packet transmitted through the target flow. 4. The communication control device according to claim 3.

[0133] According to the above configuration, when the risk score is low, only the data and the first header of the packet can be set as the encryption range.

[0134] (Appendix 5) The determination means determines the encryption range as part of the data and first header of a packet transmitted through the target flow. 5. The communication control device according to claim 4.

[0135] According to the above configuration, by encrypting only part of the packet data and the first header, it is possible to reduce the processing load on the communication device.

[0136] (Appendix 6) When the risk score is equal to or greater than a first threshold and equal to or less than a second threshold that is greater than the first threshold, the determination means sets the encryption range to the data, first header, and second header of packets transmitted through the target flow. 6. A communication control device according to claim 4 or 5.

[0137] According to the above configuration, when the risk score is medium, the encryption range can be the data, the first header, and the second header of the packet.

[0138] (Appendix 7) When the risk score is equal to or greater than the second threshold, the determination means sets the encryption range to the data, the first header, the second header, and the third header of the packet transmitted through the target flow. 7. The communication control device according to claim 6.

[0139] According to the above configuration, when the risk score is high, the encryption range can be set to the data, the first header, the second header, and the third header of the packet.

[0140] (Appendix 8) The communication path information is information quantified according to the communication medium of each communication path in the target flow. 8. A communication control device according to any one of appendices 1 to 7.

[0141] According to the above configuration, the trust score, which is communication path information, can be increased in the case of wired communication, and the trust score, which is communication path information, can be decreased in the case of wireless communication.

[0142] (Appendix 9) The communication path information is information that is quantified according to the presence of suspicious traffic on each communication path in the target flow. 9. A communication control device according to any one of appendices 1 to 8.

[0143] According to the above configuration, the trust score, which is communication path information, can be increased when there is no suspicious traffic on the communication path, and the trust score, which is communication path information, can be decreased when there is suspicious traffic on the communication path.

[0144] (Appendix 10) an acquisition means for acquiring communication path information; an execution means for executing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; A communication device comprising:

[0145] According to the above configuration, information can be suitably encrypted or decrypted according to the security level.

[0146] (Appendix 11) The encryption method further includes a determination unit that determines the encryption range of the target flow by referring to the communication path information of each communication path in the target flow. 11. The communication device of claim 10.

[0147] According to the above configuration, the encryption range of the target flow can be suitably determined according to the security level.

[0148] (Appendix 12) a receiving unit configured to receive the encryption range of the target flow from a communication control device that controls the communication device; 11. The communication device of claim 10.

[0149] According to the above configuration, it is possible to encrypt or decrypt information in accordance with the encryption range received from the communication control device.

[0150] (Appendix 13) an acquisition means for acquiring communication path information; an instruction means for instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; an execution means for executing at least one of encryption and decryption of the target flow using the encryption range of the target flow; A communication control system comprising:

[0151] According to the above configuration, information can be suitably encrypted or decrypted according to the security level.

[0152] (Appendix 14) Obtain communication path information, an encryption range determined according to the acquired communication path information, the encryption range for the target flow being used to instruct at least one of encryption and decryption of the target flow; Communication control method.

[0153] According to the above configuration, it is possible to instruct encryption or decryption of information appropriately according to the security level.

[0154] (Appendix 15) Obtain communication path information, an encryption range determined according to the acquired communication path information, and using the encryption range for the target flow, at least one of encryption and decryption of the target flow is performed; Communication control method.

[0155] According to the above configuration, information can be suitably encrypted or decrypted according to the security level.

[0156] (Appendix 16) On the computer, A process of acquiring communication path information; a process of instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; A program that executes the following.

[0157] According to the above configuration, it is possible to instruct encryption or decryption of information appropriately according to the security level.

[0158] (Appendix 17) On the computer, A process of acquiring communication path information; a process of performing at least one of encryption and decryption of the target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; A program that executes the following.

[0159] According to the above configuration, information can be suitably encrypted or decrypted according to the security level.

[0160] (Appendix 18) at least one processor, the processor comprising: A process of acquiring communication path information; a process of instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; A communication control device that executes the above.

[0161] The communication control device may further include a memory that stores a program for causing the processor to execute the acquiring process and the instructing process. The program may be recorded on a computer-readable, non-transitory, tangible recording medium.

[0162] (Appendix 19) at least one processor, the processor comprising: A process of acquiring communication path information; a process of performing at least one of encryption and decryption of the target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; A communication device that performs the above.

[0163] The communication device may further include a memory that stores a program for causing the processor to execute the acquiring process and the executing process. The program may be recorded on a computer-readable, non-transitory, tangible recording medium. [Explanation of symbols]

[0164] 1,1A Communication Control Device 2,2A,2B Communication device 11,21 Acquisition unit (acquisition means) 12 Indication unit (instruction means) 13,24 Determination unit (determination means) 22 Execution unit (execution means) 23 Receiving unit (receiving means) 31 Acquisition means 32 Instruction means 33 Means of Implementation 41, 51, 51B Communications Department 42, 52, 52B Control section 43,53 Storage part 44,54 Input section 100, 100A, 100B communication control system

Claims

1. an acquisition means for acquiring communication path information; an instruction means for instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; a determination unit that determines the encryption range for the target flow by referring to the communication path information of each communication path in the target flow; Equipped with the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, The determining means Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; Communications control device.

2. When the risk score is equal to or less than a first threshold, the determination means sets the encryption range to the data and the first header of the packet transmitted through the target flow. The communication control device according to claim 1 .

3. the determining means determines the encryption range as part of data and a first header of a packet transmitted through the target flow; The communication control device according to claim 2 .

4. When the risk score is equal to or greater than a first threshold and equal to or less than a second threshold that is greater than the first threshold, the determination means sets the encryption range to the data, first header, and second header of packets transmitted through the target flow.

4. The communication control device according to claim 2 or 3.

5. When the risk score is equal to or greater than the second threshold, the determination means sets the encryption range to the data, the first header, the second header, and the third header of the packet transmitted through the target flow. The communication control device according to claim 4.

6. The communication path information is information quantified according to the communication medium of each communication path in the target flow. The communication control device according to any one of claims 1 to 5.

7. The communication path information is information that is quantified according to the presence of suspicious traffic on each communication path in the target flow. The communication control device according to any one of claims 1 to 6.

8. an acquisition means for acquiring communication path information; an execution means for executing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; a determination unit that determines the encryption range for the target flow by referring to the communication path information of each communication path in the target flow; Equipped with the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, The determining means Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; Communication equipment.

9. an acquisition means for acquiring communication path information; an instruction means for instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; an execution means for executing at least one of encryption and decryption of the target flow using the encryption range of the target flow; a determination unit that determines the encryption range for the target flow by referring to the communication path information of each communication path in the target flow; Equipped with the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, The determining means Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; Communications control system.

10. A computer comprising: Obtain communication path information, determining an encryption range for the target flow by referring to the communication path information for each communication path in the target flow; Instructing at least one of encryption and decryption of the target flow using the encryption range of the target flow; the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, In determining the encryption range, Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; Communication control method.

11. A computer comprising: Obtain communication path information, determining an encryption range for the target flow by referring to the communication path information for each communication path in the target flow; performing at least one of encryption and decryption of the target flow using the encryption range of the target flow; the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, In determining the encryption range, Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; Communication control method.

12. On the computer, A process of acquiring communication path information; a process of instructing at least one of encryption and decryption of a target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; a process of determining the encryption range for the target flow by referring to the communication path information of each communication path for the target flow; Execute the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, In the determining process, Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; program.

13. On the computer, A process of acquiring communication path information; a process of performing at least one of encryption and decryption of the target flow using an encryption range for the target flow, the encryption range being determined according to the acquired communication path information; a process of determining the encryption range for the target flow by referring to the communication path information of each communication path for the target flow; Execute the communication path information is information that quantifies the reliability of each communication path in the target flow as a trust score, In the determining process, Calculating a risk score for the target flow from the credit scores of each communication path in the target flow; determining the encryption scope in the target flow according to the risk score; program.

Citation Information

Patent Citations

  • Communication equipment

    JP2004064652A

  • Information management system, information processor, and information management method

    JP2006157883A

  • Systems and methods for applying encryption to network traffic on the basis of policy

    US20090327695A1

  • Context aware threat protection

    US9621575B1

  • Transmission apparatus, reception apparatus, communication system, transmission method, and reception method

    WO2013179551A1