Program, virtual network allocation method, and virtual network allocation system

The described system addresses the issue of inefficient network allocation by using location information to assign virtual networks, ensuring secure and efficient network services tailored to individual locations, enhancing communication efficiency and security in shared facilities.

JP7845558B2Active Publication Date: 2026-04-14DAI NIPPON PRINTING CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing wireless communication systems fail to consider the position information of information terminals when establishing connections with access networks, leading to inefficient network allocation.

Method used

A program and system that utilize first and second location information to assign a virtual network to an information terminal, where the first location information is obtained from a reader identifying the terminal's location and the second from a base station, enabling precise network allocation through 5G network slicing.

Benefits of technology

Enables secure and efficient network allocation based on location, providing tailored network services to each user or device, ensuring security and bandwidth on a per-room basis in shared facilities, and enhancing communication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007845558000001
    Figure 0007845558000001
  • Figure 0007845558000002
    Figure 0007845558000002
  • Figure 0007845558000003
    Figure 0007845558000003
Patent Text Reader

Abstract

To provide a program, a method, and a virtual network allocation system for allocating a virtual network to an information terminal based on location information on the information terminal.SOLUTION: A virtual network allocation system S acquires first location information regarding the location where an information terminal 2 is located, acquires second location information that identifies a base station KK of a local network with which the information terminal 2 can communicate, and allocates a virtual network A, B, or C to be connected to the information terminal 2 according to the acquired first location information and second location information. The communication protocol of the local network is 5G, and the virtual networks A, B, and C are generated by network slicing in 5G. The generation by network slicing is performed after selecting the base station KK of the local network and confirming location information, on the base station KK of the local network and the location where the information terminal 2 is located.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a program, a virtual network allocation method, and a virtual network allocation system.

Background Art

[0002] There is known a wireless communication system capable of simultaneously establishing connections with a basic access network enabling signaling communication related to continuous communication switching control and an access network performing data communication other than the signaling communication by using at least two or more types of communication networks including a wireless communication network (for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the wireless communication system described in Patent Document 1, there is a problem in that the establishment of connection of an access network is not considered based on the position information of an information terminal serving as a communication node of the wireless communication system.

[0005] The present invention has been made in view of such circumstances, and an object thereof is to provide a program or the like capable of allocating a virtual network to an information terminal based on the position information of the information terminal.

Means for Solving the Problems

[0006] One approach involves a program that obtains first location information regarding the location of an information terminal, second location information identifying a base station of a local network from which the information terminal can communicate, and then instructs a computer to perform the process of assigning a virtual network to which the information terminal is connected, based on the obtained first and second location information.

[0007] One proposed virtual network assignment method involves having a computer acquire first location information relating to the location where an information terminal is located, acquire second location information identifying a base station of a local network from which the information terminal can communicate, and then assign a virtual network to which the information terminal is connected based on the acquired first and second location information.

[0008] In one proposed solution, the virtual network allocation system includes an information terminal and a control device that allocates a virtual network to the information terminal, wherein the information terminal acquires first location information relating to the location where the terminal is located, acquires second location information identifying a base station that makes the location where the terminal is located a local network to which communication is possible, outputs the acquired first location information and second location information to the control device, and the control device acquires the first location information and second location information from the information terminal and allocates a virtual network to which the information terminal is connected according to the acquired first location information and second location information. [Effects of the Invention]

[0009] According to the present invention, it is possible to provide a program, etc., that assigns a virtual network to an information terminal based on the location information of the information terminal. [Brief explanation of the drawing]

[0010] [Figure 1] This is a system overview diagram illustrating a virtual network allocation system according to Embodiment 1. [Figure 2]This block diagram shows an example configuration of mobile terminals and control devices included in a virtual network allocation system. [Figure 3] This is an explanatory diagram showing an example of an authentication table. [Figure 4] This is an explanatory diagram (sequence diagram) illustrating one aspect of processing performed by a mobile terminal and control device. [Figure 5] This is a flowchart illustrating an example of the virtual network allocation process. [Figure 6] This flowchart shows an example of the virtual network allocation process related to Embodiment 2 (multiple mobile terminals). [Modes for carrying out the invention]

[0011] (Embodiment 1) Figure 1 is a system overview diagram illustrating a virtual network allocation system S according to Embodiment 1. Figure 2 is a block diagram showing an example configuration of an information terminal 2 and a control device 1 included in the virtual network allocation system S. The virtual network allocation system S includes, for example, multiple base stations KK (RAN: Radio Access Network) and a control device 1 (5G core network: 5th Generation Core network / EPC (Evolved Packet Core)) that constitute a 5G (5th Generation) communication network, and an information terminal 2 connected to a virtual network KN generated and allocated by the control device 1 (5G core network). The information terminal 2 is communicably connected to a reader 41 that transmits information indicating the physical location of the terminal (first location information). A 5G-compatible SIM card 3 is inserted into the information terminal 2.

[0012] The reader 41 may be installed at the entrance (gate) of individual offices or conference rooms 4 in a shared office or rental conference room building, and may be configured as part of a so-called door gate (access control device). As shown in the figure in this embodiment, the shared office has three offices (rooms 4), and a reader 41 (door gate) is installed at the entrance (gate) of each room 4. When a user of the office (room 4) enters room 4, they hold their own information terminal 2, such as a smartphone, over the reader 41, and the reader 41 controls their entry and exit. Each reader 41 installed in each room 4 is assigned an identification number (reader ID) to identify the individual reader 41, and this reader ID is transmitted from the reader 41 to the information terminal 2. The information terminal 2 acquires the reader ID transmitted from the reader 41 as first location information.

[0013] Information terminal 2 further acquires the base station ID transmitted from base station KK as second location information. After storing the acquired reader ID (first location information) and base station ID (second location information) in the SIM card 3 installed in its terminal, information terminal 2 combines (associates) the first and second location information and transmits it to the control device 1 (5G core network) via base station KK.

[0014] The control device 1 (5G core network) performs mutual authentication based on the first and second location information transmitted from the information terminal 2. If the result of the mutual authentication is positive, it assigns the virtual network KN to the information terminal 2.

[0015] The virtual network KN is a logical network created by network slicing, a function of 5G. By using network slicing, a single network infrastructure (base station KK and 5G core network) can be virtually divided (sliced) and provided and operated as multiple logical networks to offer services tailored to diverse needs and applications. An information terminal 2 to which the virtual network KN is assigned can then use the virtual network KN to communicate with a management server KS or application server connected to a wide-area network BN, such as the internet.

[0016] As described above, since each individual office (room 4) of a shared office, etc., has a different reader 41 (door gate), the reader ID (first location information) transmitted from each of these readers 41 will be different. Therefore, since a different virtual network KN can be assigned to each of these individual offices (room 4) and to the reader ID (first location information), precise control can be performed on a room 4 basis, such as ensuring security and bandwidth on a room 4 basis. Thus, even in facilities used by an unspecified number of users, such as shared offices, a secure network environment can be provided to each user of each room 4 by generating and assigning a virtual network KN (logical network by 5G network slicing) for each room 4 used by each user. In this embodiment, the reader 41 (door gate) is installed in each individual office (room 4) of a shared office, etc., but it is not limited to this, and the reader 41 (door gate) may be provided in, for example, individual facilities. In other words, Room 4 in this embodiment includes, for example, each office in a shared office, each conference room in a rental conference room building, each retail store in a shopping mall, and facilities in a mixed-use building.

[0017] In this embodiment, it is assumed that the virtual network KN is assigned to the information terminal 2, but it is not limited thereto. The virtual network KN may be assigned to various devices equipped with the SIM card 3 based on the first position information and the second position information. That is, a plurality of readers 41 that output the first position information are provided, for example, in each of a plurality of areas of a factory. When the SIM card 3 is mounted on a transport vehicle traveling in the factory, the virtual network KN may be assigned to each transport vehicle according to the first position information transmitted from the corresponding reader 41 in each area where the transport vehicle is located and the second position information from the base station KK.

[0018] The information terminal 2 is constituted by a terminal device (mobile terminal) having a mobile phone function, such as a smartphone, a tablet PC, or a personal computer. The information terminal 2 includes a control unit 21, a storage unit 22, a communication unit 23, and a display unit 24, and a SIM card 3 compatible with 5G is inserted inside the terminal.

[0019] The control unit 21 has an arithmetic processing device having a timing function and a GPS function, such as one or more CPUs (Central Processing Units), MPUs (Micro-Processing Units), GPUs (Graphics Processing Units), etc., and reads and executes a program (program product) stored in the storage unit 22 to perform various information processing, control processing, etc. related to the information terminal 2.

[0020] The storage unit 22 includes a volatile storage area such as SRAM (Static Random Access Memory), DRAM (Dynamic Random Access Memory), flash memory, and a non-volatile storage area such as EEPROM or a hard disk. The storage unit 22 stores a program (program product) and data to be referred to during processing in advance. The program stored in the storage unit 22 may be one that stores the program read from the recording medium 221 readable by the terminal device. Alternatively, it may be a program downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 22.

[0021] The communication unit 23 is, for example, a communication IF corresponding to 5G and functions as a wide-area communication unit. The communication unit may further include a narrow-area communication unit having a WiFi (registered trademark) or an NFC function for performing short-range wireless communication of information of an IC chip corresponding to, for example, the NFC (Near field communication) standard.

[0022] The display unit 24 is, for example, a liquid crystal display and is provided integrally with the main body (housing) of the information terminal 2. The display unit 24 may function as an input unit using, for example, a touch panel or the like. The display unit 24 may display a QR code (registered trademark) or the like to be read by the reader 41 (the object to be read).

[0023] The SIM card 3 conforms to the 5G standard, includes a microcontroller 31, an input / output unit 32, and a non-volatile memory 33, and is inserted into a slot provided inside the information terminal 2. The microcontroller 31 of the SIM card 3 may be responsible for receiving and processing the virtual network KN assigned by the control device 1 (5G core network).

[0024] The input / output unit 32 is a connection interface for connecting to the information terminal 2. By connecting to a slot (connection unit) provided on the information terminal 2, information can be exchanged between the control unit 21 of the information terminal 2 and the SIM card 3. The microcontroller 31 and the non-volatile memory 33 may be formed on a single semiconductor circuit or may be composed of separate semiconductor circuits.

[0025] The non-volatile memory 33 is configured, for example, with an EEPROM, similar to the storage unit 22 of the information terminal 2, and stores (remembers) the first location information and the second location information acquired (received) by the information terminal 2 in combination (associated). In this embodiment, the first location information and the second location information are stored (remembered) in the non-volatile memory 33 of the SIM card 3, but this is not limited to this, and the first location information and the second location information may also be stored (remembered) in the storage unit 22 of the information terminal 2.

[0026] Control device 1 is a device that configures and controls the 5G core network and performs processing such as the creation, allocation, and destruction of the virtual network KN. The 5G core network is composed of multiple devices working together, such as MME (Mobility Management Entity), SGW (Serving Gateway), and PGW (Packet data network Gateway). Control device 1 is a collective term for these multiple devices, and the control unit 11, storage unit 12, and communication unit 13 etc. that are included in control device 1 are intended to refer to the control units etc. that are included in these multiple devices.

[0027] The control unit 11 of the control device 1 is composed of multiple CPUs and the like, and reads and executes control programs (program products) stored in the memory unit 12 to perform all control processing as a 5G core network, including relay control in 5G communication, and the creation, allocation, and deletion of virtual networks KN through network slicing. The communication unit 13 of the control device 1 includes a 5G-side communication interface for communication with base station KK, and a wide-area network BN-side communication interface such as the Internet.

[0028] The storage unit 12 of the control device 1 is composed of volatile and non-volatile storage areas and stores a control program for performing overall control processing as a 5G core network. This control program may be one read from a recording medium 121 that the control device 1 can read. Alternatively, the program may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 12.

[0029] The storage unit 12 of the control device 1 stores an authentication table used when assigning a virtual network KN to the information terminal 2. The control device 1 refers to the authentication table stored in the storage unit to determine the legitimacy of the combination of first location information and second location information transmitted from the information terminal 2, that is, it performs mutual authentication based on the first location information and second location information.

[0030] Figure 3 is an explanatory diagram showing an example of an authentication table. The authentication table includes, as management items (fields), a first location information that indicates the physical location of the information terminal 2, and a second location information that identifies the base station KK. The first location information field stores, for example, the reader IDs of the readers 41 installed in each of the multiple rooms 4, such as a shared office. The second location information field stores the base station ID of the base station KK that is controlled by the control device 1.

[0031] Each record in the authentication table is composed of fields for the first location information and the second location information, thereby managing the combination of the first and second location information. In other words, a combination of the first and second location information stored (defined) in any record is determined to be a valid combination of the first and second location information, and the mutual authentication by the control device 1 results in a positive outcome. If the combination of the first and second location information transmitted by the information terminal 2 does not match any combination of the first and second location information in any record, the mutual authentication by the control device 1 results in a negative outcome.

[0032] The second location information field is said to store, for example, the reader ID of a reader 41 installed in each of the multiple rooms 4, such as a shared office, but it is not limited to this, and may also contain GPS data (latitude, longitude) indicating the location of the room 4.

[0033] Figure 4 is an explanatory diagram (sequence diagram) illustrating one mode of processing by the information terminal 2 and the control device 1, etc. The reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2 as entry / exit control when a user of the information terminal 2 enters the room (S11). The reader 41 may also perform entry / exit control when a user of the information terminal 2 enters the room by reading a QR code displayed on the display unit 24 of the information terminal 2, for example. Alternatively, the reader 41 and the information terminal 2 may have NFC (Near Field Communication) functionality, and the reader 41 may acquire information associated with the information terminal 2 by reading information from an NFC-compliant IC chip inserted into the information terminal 2 using NFC-compliant narrow-range communication.

[0034] The reader 41 transmits (outputs) a reader ID (first location information) to the information terminal 2 (S12). The reader 41 and the information terminal 2 communicate using a narrow-range communication function such as WiFi, NFC, or infrared communication, and the information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as first location information. The first location information is not limited to the reader ID transmitted from the reader 41, but may also be GPS data indicating the current location of the information terminal 2, for example. The information terminal 2 may also use GPS data acquired by a GPS module included in the information terminal 2 as first location information, triggered by a signal transmitted from a door gate such as the reader 41 used for entry and exit control when a user of the information terminal 2 enters a room.

[0035] Base station KK transmits (outputs) the base station ID (second location information) to information terminal 2 (S13). For example, base station KK broadcasts its own base station ID using a 5G carrier, and information terminal 2 receives (acquires) the base station ID from base station KK as second location information.

[0036] Information terminal 2 stores (memorizes) the reader ID (first location information) and the base station ID (second location information) in SIM card 3 (S14). Information terminal 2 stores the acquired first location information and second location information in the non-volatile memory 33 of SIM card 3 by associating (combining) them.

[0037] Information terminal 2 transmits (outputs) the reader ID (first location information) and base station ID (second location information) stored in the SIM card 3 to control device 1 via base station KK (S15). Information terminal 2 and control device 1 communicate using, for example, a 5G carrier, and control device 1 receives (acquires) the reader ID (first location information) and base station ID (second location information) transmitted from information terminal 2.

[0038] The control device 1 performs mutual authentication based on the combination of the received reader ID (first location information) and base station ID (second location information) (S16). The control device 1 may, for example, refer to an authentication table stored in the memory unit to perform authentication processing (determination processing) to determine whether the combination of the first location information transmitted from the information terminal 2 is valid (affirmative) or not (negative).

[0039] If mutual authentication yields a positive result, the control device 1 assigns the virtual network KN to the information terminal 2 (S17). The information terminal 2 connects to the virtual network KN assigned by the control device 1. As described above, the control device 1 is, for example, a 5G core network (a group of devices that control the 5G core network), and by using network slicing, a function of 5G, it generates individually independent logical networks (virtual network KN) while using the same physical infrastructure. By assigning the virtual network KN thus generated to the information terminal 2, the control device 1 provides the information terminal 2 with access permission to the virtual network KN and communication resources such as bandwidth. The information terminal 2 to which the virtual network KN has been assigned can use the secure network environment using the virtual network KN to connect to, for example, a management server KS connected to a wide-area network BN such as the Internet, or to various application servers.

[0040] Information terminal 2 transmits (outputs) encrypted log data with first location information and second location information added to it to the management server KS via the assigned virtual network KN (S18). Information terminal 2 may also generate encrypted log data with first location information and second location information added to it when communicating data with the management server KS, which manages log data such as operation logs and communication logs of information terminal 2, via the assigned virtual network KN, and transmit the encrypted log data to the management server KS.

[0041] The reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2 as entry / exit control when a user of the information terminal 2 leaves the room (S19). When a user of the information terminal 2 leaves the room, the reader 41 reads information associated with the information terminal 2, such as a QR code, from the information terminal 2, just as it does when a user enters the room.

[0042] The reader 41 transmits (outputs) the reader ID (first location information) to the information terminal 2 (S20). The information terminal 2 receives (acquires) the reader ID (first location information) from the reader 41. When the user of the information terminal 2 leaves the room, the information terminal 2 receives (acquires) the reader ID (first location information) from the reader 41, just as when the user enters the room.

[0043] Information terminal 2 transmits (outputs) the exit information generated based on the received reader ID (first location information) to control device 1 via base station KK (S21). Information terminal 2 generates exit information based on the reader ID (first location information) received when the user of information terminal 2 leaves the room, and transmits (outputs) the generated exit information to control device 1. This exit information is, for example, data with a predetermined flag (exit flag) attached to the reader ID (first location information).

[0044] The control device 1 receives (acquires) exit information from the information terminal 2. This allows the control device 1 to recognize that the information terminal 2, to which the virtual network KN was assigned, has left room 4, which is identified by the first location information. In other words, by receiving the exit information from the information terminal 2, the control device 1 can recognize that the information terminal 2, to which the virtual network KN was assigned based on a positive result of mutual authentication, is currently in a state that does not correspond to that positive result.

[0045] The control device 1 cancels the assignment of the virtual network KN to the information terminal 2 (S22). By canceling the assignment of the virtual network KN to the information terminal 2, access to the virtual network KN by the information terminal 2 is blocked. When canceling the assignment of the virtual network KN to the information terminal 2, the control device 1 may also delete the virtual network KN. Alternatively, the control device 1 may maintain the virtual network KN whose assignment is being canceled, but transition the state of the virtual network KN to an inactive state, thereby blocking access (connection) from the information terminal 2 and canceling the assignment of the virtual network KN to the information terminal 2.

[0046] When the control device 1 cancels the allocation of the virtual network KN to the information terminal 2, it may also send alert information to the information terminal 2 indicating that the allocation of the virtual network KN has been canceled. This alert information can be displayed, for example, on the display unit 24 of the information terminal 2, thereby efficiently informing the user of the information terminal 2 that the allocation of the virtual network KN has been canceled.

[0047] When the control device 1 receives (acquires) exit information from the information terminal 2, it may, for example, stop assigning the virtual network KN to the information terminal 2 after a predetermined grace period has elapsed, such as 5 minutes. In this case, it goes without saying that if the reader ID (first location information) and base station ID (second location information) are transmitted (retransmitted) from the information terminal 2 within the grace period (before the grace period has elapsed), the assignment of the virtual network KN to the information terminal 2 will continue.

[0048] Figure 5 is a flowchart illustrating an example of the virtual network KN allocation process. The processing flow of the control unit 21 of the information terminal 2 and the control unit 11 of the control device 1, and the relationship between these processes will be explained.

[0049] The control unit 21 of the information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as first location information when a user of the information terminal 2 enters the room (T101). When a user of the information terminal 2 enters the room, the reader 41 (door gate of room 4) reads information associated with the information terminal 2 from the information terminal 2, for example, using a QR code or NFC function, and transmits its own reader ID to the information terminal 2. The control unit 21 of the information terminal 2 receives (acquires) the reader ID transmitted from the reader 41 as first location information.

[0050] The control unit 21 of the information terminal 2 receives (acquires) the base station ID from base station KK as second location information (T102). The control unit 21 of the information terminal 2 receives (acquires) the base station ID as second location information from base station KK, which has the communication area of ​​the room 4 into which the user has entered, where the reader 41 is installed.

[0051] The control unit 21 of the information terminal 2 stores (remembers) the reader ID (first location information) and the base station ID (second location information) on the SIM card 3 (T103). The microcontroller 31 of the SIM card 3 associates (combines) the reader ID (first location information) and the base station ID (second location information) obtained from the control unit 21 of the information terminal 2 and stores them in the non-volatile memory 33.

[0052] The control unit 21 of the information terminal 2 transmits (outputs) the reader ID (first location information) and base station ID (second location information) stored in the SIM card 3 to the control device 1 via base station KK (T104). The control unit 21 of the information terminal 2 uses the 5G carrier (bandwidth) provided by base station KK to transmit (outputs) the reader ID (first location information) and base station ID (second location information) stored in the SIM card 3 to the control device 1 (5G core network).

[0053] The control unit 21 of the information terminal 2 transmits (outputs) encrypted log data with the first and second location information added to it to the management server KS via the assigned virtual network KN (T105). When the control unit 21 of the information terminal 2 is assigned the virtual network KN by the control device 1 (5G core network), it accepts the assignment, connects to the virtual network KN as a communication node, and thereafter transmits (outputs) encrypted log data with the first and second location information added to it to the management server KS. The control unit 21 of the information terminal 2 may also access (data communicate) application servers etc. connected to a wide area network BN such as the Internet via the virtual network KN.

[0054] When a user of information terminal 2 leaves the room, the control unit 21 of information terminal 2 transmits (outputs) exit information generated based on the reader ID transmitted from the reader 41 to the control device 1 via the base station KK (T106). When a user of information terminal 2 leaves the room, the control unit 21 of information terminal 2 transmits (outputs) exit information generated by, for example, assigning a predetermined flag (exit flag) to the reader ID (first location information) to the control device 1 via the base station KK. As a result, the assignment of the virtual network KN to information terminal 2 is canceled, and access from information terminal 2 to the virtual network KN is blocked.

[0055] The control unit 11 of the control device 1 receives (acquires) the reader ID (first location information) and base station ID (second location information) transmitted from the information terminal 2 (S101). The control unit 11 of the control device 1 performs mutual authentication based on the combination of the received reader ID (first location information) and base station ID (second location information) (S102). The control device 1 performs mutual authentication based on the combination of the first location information and second location information transmitted from the information terminal 2 by referring to the authentication table stored in the memory unit.

[0056] The control unit 11 of the control device 1 determines whether the result of mutual authentication is positive or negative. (S103). The control unit 11 of the control device 1 may determine whether the result of mutual authentication is positive or negative based on whether the combination of the first location information and the second location information transmitted from the information terminal 2 is defined (stored in one of the records) in the authentication table. If the result of mutual authentication is negative (S103: NO), the control unit 11 of the control device 1 terminates the processing in this flowchart. Alternatively, if the result of mutual authentication is negative, the control unit 11 of the control device 1 may perform loop processing to execute the process of S101 again.

[0057] If the result of mutual authentication is positive (S103: YES), the control unit 11 of the control device 1 assigns the virtual network KN to the information terminal 2 (S104). The control unit 11 of the control device 1, which functions as a 5G core network, generates the virtual network KN using network slicing, a 5G function, and assigns it to the information terminal 2. As a result, the information terminal 2 is connected to the virtual network KN and can communicate with the management server KS via the virtual network KN.

[0058] The control unit 11 of the control device 1 determines whether or not it has received exit information from the information terminal 2 (S105). If it has not received exit information from the information terminal 2 (S105: NO), the control unit 11 of the control device 1 performs a loop process to execute the S105 process again.

[0059] If exit information is received from information terminal 2 (S105: YES), the control unit 11 of the control device 1 cancels the assignment of the virtual network KN to information terminal 2 (S106). When the control unit 11 of the control device 1 receives exit information from information terminal 2, it recognizes that information terminal 2, which was assigned the virtual network KN based on a positive result of mutual authentication, is currently not in a state corresponding to that positive result, and cancels the assignment of the virtual network KN to information terminal 2. When the control device 1 cancels the assignment of the virtual network KN to information terminal 2, it may either delete the virtual network KN or maintain the virtual network KN whose assignment has been canceled, while transitioning the state of the virtual network KN to an inactive state (unconnectable state).

[0060] According to embodiments of this disclosure, the control device 1 assigns a virtual network KN to the information terminal 2 based on first and second location information acquired from the information terminal 2, and connects the information terminal 2 to the virtual network KN. The first location information indicates the physical location of the information terminal 2, and may be, for example, identification information of a gate that the information terminal 2 has passed through, or GPS data indicating the location where the information terminal 2 is located. The second location information identifies the base station KK of the local network that the information terminal 2 can communicate with at the time the information terminal 2 is located at the location identified by the first location information, and may be, for example, the base station KK number (base station ID).

[0061] The control device 1 assigns a virtual network KN to the information terminal 2 according to the combination of the first and second location information, thereby ensuring the appropriateness (security) of the information terminal 2 to which the virtual network KN is assigned, i.e., to which the information terminal 2 becomes a communication node in the virtual network KN. The control device 1 may assign a pre-generated virtual network KN to the information terminal 2, or it may generate a new virtual network KN when the assignment of a virtual network KN becomes necessary and assign it.

[0062] According to embodiments of this disclosure, the control device 1 performs mutual authentication based on the combination of acquired first location information and second location information by referring to a predetermined authentication table, for example, and if the result of mutual authentication is positive, it performs a process of assigning a virtual network KN to the information terminal 2. By referring to the authentication table in this way, the appropriateness of the combination of first location information and second location information can be efficiently determined. If the result of mutual authentication is negative, the control device 1 may, for example, output error information to the information terminal 2 indicating that mutual authentication failed, without performing the process of assigning a virtual network KN to the information terminal 2.

[0063] According to the embodiments of this disclosure, the information terminal 2 is assigned a virtual network KN generated (constructed) by network slicing (5G network slicing) in 5G (fifth-generation mobile communication system), so that virtual independent logical networks can be multiplexed on the same physical network architecture.

[0064] According to the embodiments of this disclosure, the first location information indicating the physical location of the information terminal 2 is, for example, information relating to a reader 41 installed in each of the multiple rooms 4 of a shared office, and is, for example, a reader 41 number (reader ID) for individually identifying the reader 41. When a user with an information terminal 2 enters a room 4, the reader 41 reads the information associated with the information terminal 2, for example, by using a QR code or NFC (Near Field Communication) function, thereby controlling the user's entry and exit to the room 4 (entry and exit management). If the reader 41 successfully reads the information (QR code, etc.) of the information terminal 2, the reader 41 transmits (outputs) the reader 41 number (reader ID) to the information terminal 2, and the reader 41 number (reader ID) is combined with the second location information (base station ID) as the first location information and transmitted to the control device 1.

[0065] The control device 1 assigns a virtual network KN based on first location information and second location information that identify the room 4 where the information terminal 2 is located. Therefore, even if there are multiple rooms 4 within the communication area of ​​a single base station KK, the control device 1 can assign a virtual network KN to each room 4 where each information terminal 2 is located. This makes it possible to assign a different virtual network KN to each room 4 in a facility with multiple rooms 4, such as a shared office, and to efficiently ensure security on a room-by-room basis.

[0066] According to the embodiment of this disclosure, when a user of information terminal 2 exits room 4 corresponding to the first location information, information associated with information terminal 2, such as a QR code, is read by a reader 41 that controls entry and exit to room 4. At this time, information terminal 2 transmits exit information to the control device 1 indicating that it is located outside room 4 corresponding to the first location information. When the control device 1 receives exit information from information terminal 2, it cancels the assignment of the virtual network KN to information terminal 2, thereby efficiently prohibiting connection (access) to the virtual network KN by information terminal 2 outside room 4 corresponding to the first location information, and efficiently ensuring security in the virtual network KN.

[0067] According to the embodiments of this disclosure, an information terminal 2 assigned to a virtual network KN transmits data such as operation log data or communication log data (log data) to a management server KS connected to the internet, for example, via the virtual network KN. Since this data is encrypted with the addition of first and second location information obtained when mutually authenticated by the control device 1, the security of the transmitted data based on the first and second location information can be ensured not only when the virtual network KN is assigned, but also in the communication state using the virtual network KN after it has been assigned.

[0068] In embodiments of this disclosure, the virtual network KN is generated by network slicing, a feature of 5G, but is not limited thereto. The virtual network KN may also be generated by network slicing using next-generation communications applicable after 5G, such as 6G or 7G.

[0069] (Embodiment 2) Figure 6 is a flowchart illustrating an example of the allocation process for the virtual network KN related to Embodiment 2 (multiple information terminals 2). Embodiment 2 concerns a state in which multiple information terminals 2 exist in a single room 4 (multiple users of information terminals 2 enter the room). Since the processing at each information terminal 2 is the same as in Embodiment 1, the processing related to the control device 1 will be explained.

[0070] The control unit 11 of the control device 1 determines whether or not it has received first location information and second location information from the information terminal 2 (S201). If it has not received first location information and second location information (S201: NO), the control unit 11 of the control device 1 performs a loop process to execute the process of S201 again.

[0071] When the first location information and the second location information are received (S201:YES), the control unit 11 of the control device 1 assigns the virtual network KN to the information terminal 2 that transmitted the first location information and the second location information (S202).

[0072] The control unit 11 of the control device 1 increases the number of information terminals 2 to which the virtual network KN is assigned by one (S203). The control unit 11 of the control device 1 stores the current number of information terminals 2 to which the virtual network KN is assigned in a memory unit, for example, by storing it in a predetermined variable. A variable for storing the number of information terminals 2 is defined for each generated virtual network KN, and the number of information terminals 2 to which the virtual network KN is assigned is stored in each variable corresponding to the virtual network KN. The control unit 11 of the control device 1 increases the number of information terminals 2 to which the virtual network KN is assigned by one and performs loop processing to execute the process of S201 again.

[0073] The control unit 11 of the control device 1 determines whether or not it has received exit information from the information terminal 2 (S204). If exit information has not been received (S204: NO), the control unit 11 of the control device 1 performs a loop process to execute the process in S204 again.

[0074] If exit information is received (S204: YES), the control unit 11 of the control device 1 stops assigning the virtual network KN to the information terminal 2 that sent the exit information (S205). The control unit 11 of the control device 1 stops assigning the virtual network KN to the information terminal 2 that sent the exit information, but maintains the virtual network KN itself without deleting it. As a result, the assignment of the virtual network KN to information terminal 2 that did not send exit information, i.e., information terminal 2 located in room 4 corresponding to the first location information, continues. If the information terminal 2 that sent the exit information is once again located in room 4 corresponding to the first location information, i.e., if the user of the information terminal 2 re-enters room 4, the control unit 11 of the control device 1 resumes (reassigns) the assignment of the virtual network KN to the re-entered information terminal 2. By performing this reassignment process, the assignment of the virtual network KN to the re-entered information terminal 2 can be performed efficiently.

[0075] The control unit 11 of the control device 1 reduces the number of information terminals 2 to which the virtual network KN is assigned by one (S206). The control unit 11 of the control device 1 reduces the number of information terminals 2 to which the virtual network KN is assigned by one and performs a loop process to execute the process in S206 again.

[0076] The control unit 11 of the control device 1 determines whether the number of information terminals 2 to which the virtual network KN is assigned is 0 (S207). If the number of information terminals 2 to which the virtual network KN is assigned is not 0 (S207: NO), the control unit 11 of the control device 1 performs a loop process to execute the process in S207 again.

[0077] If the number of information terminals 2 to which the virtual network KN is assigned is 0 (S207: YES), the control unit 11 of the control device 1 deletes the virtual network KN that was assigned to these multiple information terminals 2 (S208). If the number of information terminals 2 to which the virtual network KN is assigned is 0, the control unit 11 of the control device 1 deletes the virtual network KN that was assigned to these multiple information terminals 2 and prevents reassignment by these information terminals 2, thereby ceasing the assignment of the virtual network KN to all of the multiple information terminals 2.

[0078] According to the embodiments of this disclosure, when assigning a different virtual network KN to each room 4, if multiple information terminals 2 exist in the same room 4 (room 4 corresponding to the same first location information), the control device 1 assigns the same virtual network KN to these multiple information terminals 2. As a result, multiple information terminals 2 located in the same room 4 share the same virtual network KN, and while ensuring security through the virtual network KN, communication between these multiple information terminals 2 can be performed with a low number of hops, thereby improving communication efficiency.

[0079] According to the embodiments of this disclosure, when multiple information terminals 2 exist in the same room 4 (room 4 corresponding to the same first location information), the control device 1 can efficiently ensure security in the virtual network KN by, for example, deleting the virtual network KN when all of these multiple information terminals 2 are located outside the room 4, thereby ceasing the assignment of the virtual network KN to all of the multiple information terminals 2.

[0080] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims, not in the sense described above, and all modifications within the sense and scope equivalent to the claims are intended. [Explanation of symbols]

[0081] S Virtual Network Allocation System BN Wide Area Network KS Management Server KN Virtual Network KK base station 1 Control device 11 Control Unit 12 Storage section 121 Recording media 13 Communications Department P1 Control Program 2. Information terminals 21 Control Unit 22 Memory section 221 Recording media P2 Program 23 Communications Department 24 Display section 3 SIM cards 31 Microcontroller 32 Input / output section 33 Non-volatile memory 4 rooms 41. Readers (door gates, access control devices)

Claims

1. First location information regarding the location where the information terminal is located is obtained, The aforementioned information terminal acquires second location information to identify a base station of the local network with which it can communicate, In accordance with the acquired first location information and second location information, a virtual network connected to the information terminal is assigned. The communication protocol of the aforementioned local network is 5G. The aforementioned virtual network is generated by network slicing in 5G, The network slicing generation described above is performed after selecting a base station of the local network and confirming the location information between the base station of the local network and the location where the information terminal is located. A program that instructs a computer to perform a process.

2. Mutual authentication is performed using the combination of the acquired first location information and the second location information. If the result of mutual authentication is positive, the virtual network connected to the information terminal is assigned. The program according to claim 1.

3. The first location information is information relating to a reader provided in each of the multiple rooms, which reads information associated with the information terminal. The virtual network is assigned to each of the information terminals corresponding to each of the multiple rooms. The program according to claim 1 or claim 2.

4. When the information terminal acquires exit information indicating that it is located outside the room corresponding to the first location information, The assignment of the virtual network to the aforementioned information terminal is discontinued. The program according to any one of claims 1 to 3.

5. If multiple information terminals exist in a room corresponding to the same first location information, the same virtual network is assigned to the multiple information terminals. The program according to any one of claims 1 to 4.

6. If multiple information terminals are located in the same room corresponding to the same first location information, and after the same virtual network has been assigned to the multiple information terminals, if exit information indicating that an information terminal is located outside the room is obtained from all of the multiple information terminals, the assignment of the virtual network to all of the multiple information terminals is terminated. The program according to claim 5.

7. The data transmitted from the information terminal via the virtual network is encrypted with the first location information and the second location information added to it. The program according to any one of claims 1 to 6.

8. On the computer, First location information regarding the location where the information terminal is located is obtained, The aforementioned information terminal acquires second location information to identify a base station of the local network with which it can communicate, In accordance with the acquired first location information and second location information, a virtual network connected to the information terminal is assigned. The communication protocol of the aforementioned local network is 5G. The aforementioned virtual network is generated by network slicing in 5G, The network slicing generation described above is performed after selecting a base station of the local network and confirming the location information between the base station of the local network and the location where the information terminal is located. A method for assigning a virtual network to execute a process.

9. A virtual network assignment system including an information terminal and a control device for assigning a virtual network to the information terminal, The aforementioned information terminal is First location information regarding the location where the device is located is obtained, Second location information is obtained to identify a base station that makes the location where the device is located part of a local network capable of communication. The acquired first position information and second position information are output to the control device. The control device is The first location information and the second location information are obtained from the information terminal. In accordance with the acquired first location information and second location information, a virtual network connected to the information terminal is assigned. The communication protocol of the aforementioned local network is 5G. The aforementioned virtual network is generated by network slicing in 5G, The network slicing generation described above is performed after selecting a base station of the local network and confirming the location information between the base station of the local network and the location where the information terminal is located. Virtual network allocation system.

10. First location information regarding the location where the information terminal is located is obtained, The aforementioned information terminal acquires second location information to identify a base station of the local network with which it can communicate, In accordance with the acquired first location information and second location information, a virtual network connected to the information terminal is assigned. If the information terminal acquires exit information indicating that it is located outside the room corresponding to the first location information, the assignment of the virtual network to the information terminal is canceled. At the time of acquiring the exit information, the second location information acquired by the information terminal is the second location information at the time of the virtual network allocation. A program that instructs a computer to perform a process.

Citation Information

Patent Citations

  • JP1973011606B1

  • Conference room reservation system, conference room reservation method, and conference room reservation program

    JP2016184241A

  • Communication control method and connection target change method

    JP2021016014A

  • Network connection method and apparatus

    US20200205205A1

  • Controlling an operation mode of a communications network

    WO2020120647A1