Repository device, repository configuration method, and program for sharing vulnerability information in hardware supply chains
The repository device categorizes and links product, company, and vulnerability information to address the lack of vulnerability sharing in hardware supply chains, enhancing risk analysis and management efficiency.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- KDDI CORP
- Filing Date
- 2023-03-15
- Publication Date
- 2026-04-28
AI Technical Summary
Conventional methods fail to organize and share useful information about product vulnerabilities in hardware supply chains, lacking specifications on information format, collection methods, and repository construction.
A repository device and method that categorizes and links product, company, and vulnerability information, allowing for defined relationships and limited recursive references, enabling comprehensive risk analysis and sharing.
Minimizes information management costs and enables comprehensive risk analysis and sharing of vulnerabilities, facilitating proactive countermeasures and supply chain risk assessment.
Smart Images

Figure 0007853245000002 
Figure 0007853245000003 
Figure 0007853245000004
Abstract
Description
Technical Field
[0001] The present invention relates to a repository device, a repository configuration method, and a program for sharing and utilizing vulnerable information in a hardware supply chain among multiple users. Note that the hardware supply chain in the present invention refers to a series of processes from the procurement of raw materials and parts of a product to its sale. Also, a repository means a storage or storage facility, and the object of storage and storage in the present invention is data. Therefore, the repository can also be referred to as a database.
Background Art
[0002] Non-Patent Document 1 proposes a method for organizing information including supply chain information as a knowledge graph. Specifically, it discusses a domain knowledge graph based on multi-source heterogeneous data consisting of dynamic data generated from daily transactions between companies where the supply chains intersect and static data indicating basic properties (such as business partners, nationality, etc.) of these companies.
[0003] Patent Document 1 proposes a method for verifying, without receiving the circuit data itself, that no malicious circuit (hardware trojan) that realizes unauthorized data or functions is mixed in the design and manufacturing process of large-scale hardware (circuits) where the supply chain is often formed by outsourcing some parts.
Prior Art Documents
Non-Patent Documents
[0004]
Non-Patent Document 1
Patent Documents
[0005] [Patent Document 1] Japanese Patent Publication No. 2023-18349 [Overview of the Initiative] [Problems that the invention aims to solve]
[0006] However, conventional methods only show the relationships between companies where supply chains intersect. Therefore, they do not include information on product vulnerabilities, and it is not possible to organize and share useful information about product vulnerabilities. Furthermore, the specific format of the information that should be shared, the method of collection, and the method of constructing a repository after collection are not specified.
[0007] The present invention aims to provide a repository device, a repository configuration method, and a program that automatically configure and provide useful information regarding product vulnerabilities by associating information about hardware components, information about their suppliers, discovered vulnerabilities, and the conditions under which they manifest. [Means for solving the problem]
[0008] In this invention, the types of information collected (input) from external systems and stored in a repository are organized into three categories: product information concerning products that constitute the hardware, company information concerning the company that provides the hardware, and vulnerability information concerning vulnerabilities in the hardware. For each type of information, the information is recorded in a database by an external system or human operation that possesses the corresponding information. When sharing information with external parties, fields for linking various types of information are provided. This linking allows for the definition of relationships between each type of information, as well as parent-child relationships between items of the same type. Furthermore, for items that can be recursively linked, the number of references is limited by specifying the maximum depth. The linked and aggregated information is then utilized in cooperation with external systems.
[0009] The repository device according to the present invention comprises: an information input unit having the function of acquiring information regarding vulnerabilities in the hardware supply chain from an input-side external system or input by a person; an information storage unit having the function of storing the information in a repository table; and an information formatting unit having the function of transmitting the information to an output-side external system. The information types of the information stored in the repository include product information relating to products constituting the hardware, company information relating to companies providing the hardware, and vulnerability information relating to vulnerabilities in the hardware. The functions of the information input unit include the function of acquiring or inputting the information from an input-side external system or a person corresponding to each of the information types. The functions of the information storage unit include the function of configuring a table for each of the information types and recording the information acquired or input by the information input unit in the corresponding table. The information recorded in each of the tables for each information type is interconnected via identifiers. The functions of the information formatting unit include the function of aggregating the information recorded by the information storage unit and outputting it to an output-side external system.
[0010] A field for association may be provided for the information recorded in each of the tables for each information type, and the information may be associated through the identifier added to the field, thereby enabling the definition of relationships between different information types and the definition of parent-child relationships between the same information types.
[0011] In the acquisition of product information and company information, which recursively reference information for association purposes, the number of recursive references may be limited by specifying a maximum depth to prevent the references from continuing indefinitely.
[0012] Furthermore, the repository configuration method according to the present invention includes an information input step of acquiring information regarding vulnerabilities in the hardware supply chain from an input-side external system or inputting it by a person, an information storage step of storing the information in a table of the repository, and an information formatting step of transmitting the information to an output-side external system, wherein the information types of the information stored in the repository include product information regarding products constituting the hardware, company information regarding companies that provide the hardware, and vulnerability information regarding vulnerabilities in the hardware, the information input step acquires or inputs the information from an input-side external system or a person corresponding to each of the information types, the information storage step configures a table for each of the information types and records the information acquired or input in the information input step in the corresponding table, the information recorded in each of the tables for each information type is related to each other via an identifier, and the information formatting step aggregates the information recorded in the information storage step and outputs it to an output-side external system.
[0013] Furthermore, the registry configuration program according to the present invention may be a program for causing a computer to function as the aforementioned registry device. [Effects of the Invention]
[0014] According to the present invention, by classifying and organizing each type of information, it is possible to minimize the cost of information management. Furthermore, compared to conventional methods, it becomes possible to comprehensively share and analyze risks arising from the supply chain and risks based on vulnerabilities during use, based on hardware product information, and to utilize vulnerability information. [Brief explanation of the drawing]
[0015] [Figure 1] This diagram shows the configuration of the repository device according to the embodiment. [Figure 2] This figure shows the functional block of the repository device according to the embodiment. [Figure 3]It is a flowchart showing the information acquisition / input procedure in the information input section of the embodiment. [Figure 4] It is an algorithm showing the procedure for acquiring vulnerability information in the information shaping section of the embodiment. [Figure 5] It is an algorithm showing the procedure for acquiring product information in the information shaping section of the embodiment. [Figure 6] It is an algorithm showing the procedure for acquiring company information in the information shaping section of the embodiment.
Mode for Carrying Out the Invention
[0016] Hereinafter, an example of an embodiment of the present invention will be described. First, the types of information (information types) collected (input) by the repository device of the embodiment from an external system will be described. As described above, there are three types of information types: product information, company information, and vulnerability information. The details of each are as follows.
[0017] Product information is information including information about products constituting the hardware. Specifically, it includes a value (product information ID) that uniquely identifies the product information, product name, product model number, information about the manufacturing company of the product (company information ID), the use and application of the product (product use), and a list of products used in the product (parts list).
[0018] Company information is information including information about the company providing the hardware. Specifically, it includes a value (company information ID) that uniquely identifies the company information, company name, nationality of the company (company nationality), information about the company's subsidiaries, affiliated companies, business partners, etc. (related company list).
[0019] Vulnerability information includes known hardware vulnerabilities and specifically includes a unique identifier for the vulnerability (vulnerability ID), a value indicating the degree of threat posed by the vulnerability (vulnerability threat level), the vulnerability registration date, the vulnerability update date, the conditions under which the vulnerability occurs (vulnerability conditions), the impact of an attack on the vulnerability (vulnerability impact), the source of the vulnerability information (vulnerability source), and a list of affected products (product list). Vulnerability information may also include information such as flags indicating that suspicions arose during inspection.
[0020] It should be noted that the above are merely examples of information that may be included in each information category, and are not exhaustive. In other words, each information category may include information other than that shown above.
[0021] Figure 1 shows the configuration of the repository device 1 in this embodiment. The repository device 1 collects and inputs information from an input-side external system (or person) 2, formats and aggregates it to form information (repository 50), and transmits (outputs) the information in response to a request from an output-side external system 3. The repository device 1 is an information processing device (computer) equipped with a control unit 10, an input unit 20, an output unit 30, a storage unit 40, a repository 50, etc.
[0022] The control unit 10 controls the entire repository device 1 and realizes the functions of each functional block described later by appropriately reading and executing various programs stored in the memory unit 40. The control unit 10 is not particularly limited, but may be a CPU.
[0023] The memory unit 40 is a storage area for various programs and data necessary for the hardware group to function as a repository device 1, and is not particularly limited to ROM, RAM, flash memory, hard disk drive (HDD), solid state drive (SSD), etc.
[0024] Figure 2 shows the functional block of the repository device 1 in this embodiment. The repository device 1 comprises an information input unit 11, an information storage unit 12, and an information formatting unit 13 as functional (processing) blocks. Note that these functional (processing) blocks are not separate hardware blocks, but rather logical blocks that group hardware components by function (processing). The details of each part are described below.
[0025] (1) Information input unit 11 The information input unit 11 acquires information from an external source according to its type and registers it in the information storage unit 12. These operations can be performed manually by a person or automatically by a computer. The input functions are divided into product information input function, company information input function, and vulnerability information input function, corresponding to the three types of information mentioned above.
[0026] In manual operation by a human, information corresponding to each type of information is manually entered through a screen or other means. In automated operation by a computer, the computer acquires and inputs information from an external system. The following explains the information acquisition and input procedure, referring to the flowchart in Figure 3.
[0027] Step 1: Register in advance the information necessary to connect with the external system from which to acquire information (specifically, the connection URL and authentication information, etc.) and the correspondence between the information to be acquired and the information to be registered in the information storage unit 12 (i.e., the correspondence between the field names of the information to be acquired and the field names of the information to be registered, hereinafter referred to as "field correspondence") (Step S11 of the flowchart in Figure 3).
[0028] Step 2: Triggered by a trigger (YES in step S12), access an external system and retrieve / input new or updated information from the external system (step S13). Specific examples of triggers include the arrival of a predetermined time or the receipt of an information update notification from an external system.
[0029] Step 3: For information among the acquired and entered information that includes relationships with other information types, such as parts lists and related company lists (e.g., product information) (YES in step S14), the system searches for information registered in the information storage unit 12 (S15). If the search results show that information that meets the criteria for matching is found (YES in step S16), it is associated with the ID of that information (S17). If no information is found (NO in step S16), new information is added to the extent known, an ID is assigned, and it is associated with that ID (S18). Specific examples of methods for determining the degree of matching include methods based on indicators such as the number of matching characters, edit distance, and the matching rate of n-gram segmented words (for example, by comparing with a set threshold).
[0030] Step 4: Organize the information obtained from external sources based on the field correspondence. Here, add the list of IDs obtained for association in Step 3 and configure the information (same step S19). The configured information is registered in the information storage unit 12 (same step S20 NO, same step S22). If information is already registered (same step S20 YES), update the content of that information (same step S21).
[0031] By processing information input and storage for each type of information, automatic integration and information synchronization with existing external systems become possible. Examples of external systems that can be integrated and synchronized for each type of information include the following: Product information can be linked and synchronized with, for example, information registered in each company's own product database, information obtained from online retail, etc. Corporate information can be linked and synchronized with, for example, information published by individual companies, and IR (Investor Relations) information provided by securities companies, etc. Vulnerability information can be linked and synchronized with, for example, information registered in the NVD (National Vulnerability Database) and information registered in vulnerability detection systems.
[0032] The three functions included in the information input unit 11 operate independently of each other. For example, consider the case where information is obtained and input from an external system that provides vulnerability information, and vulnerability information b corresponding to a certain product a is registered. Even if information about product a is not registered as product information, vulnerability information b can be registered in association with product a by registering product a with the information that can be determined from the obtained information. Subsequently, if information about product a is obtained from the external system that provides product information, the already recorded information will be appended to and updated.
[0033] (2) Information storage unit 12 The information storage unit 12 records the information obtained from the information input unit 11 as database tables. Hereinafter, the tables corresponding to the three types of information mentioned above will be referred to as the product information table, the company information table, and the vulnerability information table, respectively. Note that each table can also be constructed by combining multiple tables to form a single logical table.
[0034] Parts lists and related company lists refer to other records of the same information type. These references imply parent-child relationships. Specifically, for each product specified in the parts list of product information A (let's say product information B is the representative), product information A is the parent and product information B is the child. Similarly, for each company specified in the related company list of company information C (let's say company information D is the representative), a parent-child relationship can be assigned between company information C and company information D according to the actual relationship.
[0035] (3) Information shaping department 13 The system aggregates information from one of the three tables in the information storage unit 12 to form information for transmission to an external system (external service). As a specific example, starting with vulnerability information ID: Vln_ID, product information and company information are associated using the procedure shown in the algorithms in Figures 4, 5, and 6 to form aggregated information. Note that this procedure is just one example showing how to obtain information from each information type through individual processing; it is also possible to describe this in a single SQL statement or to add items to each information type.
[0036] The procedures for retrieving product information and company information each involve recursively referencing information, potentially leading to an infinite number of references. To limit the number of recursive references, a non-negative integer d is used. max Specify.
[0037] In the algorithms in Figures 4, 5, and 6, the subscripted variable D represents a dictionary (a set of item names and values), and the variable L represents a list. Furthermore, Vln represents a vulnerability, Prd represents a product, and Cmp represents a company. For example, D Vln L represents the value and data of vulnerability information. Prd This will represent a product list. Furthermore, the dash symbol (´) indicates that it is the child in the aforementioned parent-child relationship. For example, when product information A is the parent and product information B is the child, Prd_ID' represents the identification value (ID) of product information B, which is different from the parent product information A. Similarly, when company information C and its related company information D are represented in a parent-child relationship, Cmp_ID' represents the identification value (ID) of company information D, which is different from the parent company information C. Note that step 4 in each algorithm represents the initialization of the list.
[0038] By obtaining the vulnerability information ID through the above procedure, it becomes possible to access related product and company information.
[0039] Table 1 shows the specific content of the information that will be shared.
[0040] [Table 1]
[0041] The information obtained as described above can be used, for example, in systems that perform wide-area security monitoring. A specific example is its use in security measures. Vulnerabilities corresponding to product names present in the monitored system are listed, and the information shown in Table 1 is obtained for each vulnerability. This allows for understanding the threat level of the vulnerability, the conditions under which it occurs, and the impact if it occurs, which can be used for proactive countermeasures.
[0042] Another example is the analysis of supply chain threats present in a monitored system. By obtaining the information shown in Table 1, the country of manufacture of the product and the uses and countries of manufacture of the components it contains can be determined. By identifying critical components (such as communication modules) manufactured in countries considered to be high geopolitical risk, risks in the supply chain can be analyzed. In existing systems, the information necessary for such analysis is managed separately for each type of information, and there was no system that automatically aggregated this information. However, by using the repository device, repository configuration method, or program of the present invention, it becomes possible to easily perform the above analysis.
[0043] According to the present invention, by classifying and organizing each type of information, it is possible to minimize the cost of information management. For example, if there is a change in the company name, only the company information needs to be updated. Also, if a new known vulnerability is discovered in a product, that product can be added to the existing product list of vulnerability information. Furthermore, compared to conventional methods, the present invention makes it possible to comprehensively share and analyze risks arising from the supply chain and risks based on vulnerabilities during use, based on information about hardware products, and to utilize vulnerability information.
[0044] Furthermore, this embodiment makes it possible to minimize the cost of information management, for example, and to comprehensively share and analyze risks arising from the supply chain and risks based on vulnerabilities during use, based on information about hardware products, and to utilize vulnerability information. This makes it possible to contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0045] Although embodiments of the present invention have been described above, the present invention is not limited to the embodiments described above. Furthermore, the effects described in the embodiments described above are merely a list of the most preferred effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0046] For example, the following are possible examples of further utilization and effects of information acquired by the repository device, repository configuration method, and program of the present invention. (Example of use 1) By examining the vulnerability's threat level, impact, product application, and usage locations, companies can utilize this information for recalls and other measures if the impact of the vulnerability is particularly high. (Example of use 2) By checking the vulnerability registration date, vulnerability update date, and vulnerability source, it becomes possible to verify the update status of the vulnerability information and estimate the reliability of the information.
[0047] (Example of use 3) By examining vulnerability threat levels, vulnerability conditions, vulnerability impacts, and product applications, it is possible to understand vulnerabilities found in similar products and the conditions under which they manifest, which can then be used to protect your own products and for new product development. (Example of use 4) By examining vulnerability threat levels, product applications, product manufacturers, their nationalities, and their trading partners, it's possible to analyze supply chain risks and trends related to vulnerabilities. [Explanation of Symbols]
[0048] 1. Repository device 2. Input side external system (service) or person 3. Output-side external system (service) 10 Control Unit 11. Information Input Section 12 Information Storage Unit 13 Information formatting department 20 Input section 30 Output section 40 Storage section 50 repositories (databases)
Claims
1. An information input unit having the function of obtaining information on vulnerabilities in the hardware supply chain from an external input system or inputting it manually, An information storage unit having the function of storing the aforementioned information in a repository table, It comprises an information formatting unit having a function for transmitting the information to an output-side external system, The information types of the information stored in the repository include product information relating to products constituting the hardware related to the hardware supply chain, company information relating to companies that provide the hardware, and vulnerability information relating to vulnerabilities in the hardware. The functions of the aforementioned information input unit include the function of acquiring or inputting the information from an external input system or person corresponding to each of the aforementioned information types. The functions of the information storage unit include configuring a table for each type of information and recording the information acquired or entered by the information input unit into the corresponding table. The information recorded in each of the tables for each type of information is related to each other via identifiers. The functions of the information formatting unit include a repository device that aggregates the information recorded by the information storage unit and outputs it to an external system on the output side.
2. The repository device according to claim 1, wherein each of the tables for each information type has a field for association with the information recorded therein, and the information is associated through the identifier added to the field, thereby enabling the definition of relationships between different information types and the definition of parent-child relationships between the same information types.
3. The repository device according to claim 1 or 2, wherein in the acquisition or input of product information and the acquisition or input of company information, which each recursively reference information for the purpose of association, the number of recursive references is limited by specifying a maximum depth, thereby preventing the references from continuing indefinitely.
4. Information input step involves obtaining information about vulnerabilities in the hardware supply chain from an external input system or inputting it manually. An information storage step involves storing the aforementioned information in a repository table, A method for configuring a repository performed by a computer, comprising: an information formatting step of transmitting the information to an output-side external system, The information types of the information stored in the repository include product information relating to products constituting the hardware related to the hardware supply chain, company information relating to companies that provide the hardware, and vulnerability information relating to vulnerabilities in the hardware. The aforementioned information input step involves acquiring or inputting the information from an external input system or person corresponding to each of the aforementioned information types. The information storage step involves configuring a table for each type of information and recording the information acquired or entered in the information input step into the corresponding table. The information recorded in each of the tables for each type of information is related to each other via identifiers. The information formatting step is a repository configuration method that aggregates the information recorded in the information storage step and outputs it to an external system on the output side.
5. A repository configuration program for causing a computer to function as a repository device according to claim 1 or claim 2.
6. A repository configuration program for causing a computer to function as a repository device according to claim 3.
Citation Information
Patent Citations
Method for evaluating risk and method for support selection of security management measures and program
JP2005234840A
Log management control system and log management control method
JP2016170568A
Verification device, verification method, and verification program
JP2023018349A
Automated vulnerability assessment with policy-based mitigation
US20220046050A1