Trust management system, system management methods
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- HITACHI LTD
- Filing Date
- 2022-09-22
- Publication Date
- 2026-08-03
AI Technical Summary
【0012】 本発明によれば、システム内の装置やソフトウェアが持つ内部状態の実証を行うトラスト管理システムにおいて、高度なトラスト管理を維持しつつ、装置やネットワークのリソース不足を抑制可能なトラスト管理システム及びそれを用いたシステム管理方法を実現することができる。
Smart Images

Figure 0007899026000001 
Figure 0007899026000002 
Figure 0007899026000003
Abstract
Description
Technical Field
[0001] The present invention relates to a configuration of a control system and a system management method using the same, and particularly relates to a technology effective when applied to a control system that requires advanced security control.
Background Art
[0002] With the development of new businesses and production reforms, the smartening of factories using DX (Digital Transformation) is accelerating. To utilize DX, it is essential to link with systems inside and outside the company and introduce devices with standard interfaces, and security threats that affect business continuity, safety, quality, production planning, and costs more than ever are increasing.
[0003] Therefore, with the progress of DX in the control system, individual security control of devices, software, etc. that make up the system is required. Specifically, it is necessary to build a trust relationship (trust chain) for individual devices and software within different organizations and systems, and to create a mechanism to realize security control based on the trust chain.
[0004] As background art in this technical field, there is a technology such as Patent Document 1, for example. Patent Document 1 discloses "a system and method for determining whether to provide secure access by comparing access authorization information held outside the client with client information for an access request from the client to an embedded device".
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] By the way, building a trust chain in a control system requires "verification" that provides evidence of the internal state of the device itself (such as the presence or absence of vulnerabilities).
[0007] However, performing verification every time a trust chain is built on equipment (especially edge devices) increases the load on the equipment and network, leading to resource shortages and other negative impacts from the perspective of control system computations or network resources.
[0008] The technology described in Patent Document 1 above has room for improvement in building trust chains, such as the inability to update access authorization information.
[0009] Therefore, the object of the present invention is to provide a trust management system and a system management method using the same that can suppress resource shortages of devices and networks while maintaining advanced trust management in a trust management system that verifies the internal state of devices and software within a system. [Means for solving the problem]
[0010] To solve the above problems, the present invention provides a trust management system for verifying the internal state of a device or software within a system, comprising: an effective time setting unit that sets the effective time of the verification result using the verification execution time and the characteristics of the internal information for the internal state of the verification target which has been verified in advance; an internal state storage unit that stores information including the internal state and the effective time as a prior verification result outside the verification target; and an alternative verification execution unit that substitutes for the verification execution of the internal state of the verification target by confirming the effective time. A demonstration content analysis unit selects an internal state to substitute for the demonstration execution in the alternative demonstration execution unit based on the demonstration request from the demonstration request source, It is characterized by having the following features.
[0011] Furthermore, the present invention is Using a trust management system A system management method for verifying the internal state of devices or software within a system, wherein (a) The effective time setting unit, (b) The steps include setting the validity period of the demonstration results using the demonstration execution time and the characteristics of the internal information for the internal state of the demonstration target which has been demonstrated in advance, and The internal state memory unit, (c) The alternative demonstration unit, (d) A step in which the verification of the internal state of the subject to be demonstrated is replaced by confirming the effective time, The Demonstration Content Analysis Department, The present invention is characterized by having the step of selecting an internal state that substitutes for the demonstration execution in step (c) based on a demonstration request from the demonstration request source. [Effects of the Invention]
[0012] According to the present invention, in a trust management system that verifies the internal state of devices and software within a system, it is possible to realize a trust management system that can suppress resource shortages of devices and networks while maintaining advanced trust management, and a system management method using the same.
[0013] This can contribute to improving the reliability and efficiency of the control system.
[0014] Other issues, configurations, and effects not mentioned above will be clarified by the following description of the embodiments. [Brief explanation of the drawing]
[0015] [Figure 1] This figure shows a schematic configuration of a trust management system according to Embodiment 1 of the present invention. [Figure 2] This figure shows an example of the hardware configuration of the trust management system shown in Figure 1. [Figure 3] This figure shows an example of a control system configuration using the trust management system shown in Figure 1. [Figure 4] This figure shows an example of internal state information 400. [Figure 5] This is a flowchart showing the processing in the valid time setting unit 111. [Figure 6] This is a flowchart showing the processing in the alternative demonstration execution unit 114. [Figure 7]It is a diagram showing an example of the timing of state input (preliminary verification) in the trust management system of FIG. 1. [Figure 8] It is a diagram showing a schematic configuration of the trust management system according to Example 2 of the present invention. [Figure 9] It is a diagram showing an example of the adjusted internal state information 900. [Figure 10] It is a flowchart showing the processing in the valid time adjustment unit 800. [Figure 11] It is a diagram showing a schematic configuration of the trust management system according to Example 3 of the present invention. [[ID=1As shown in Figure 1, the trust management system 110 of this embodiment comprises, as its main components, an effective time setting unit 111, an internal state storage unit 112, a demonstration content analysis unit 113, and an alternative demonstration execution unit 114.
[0020] The trust management system 110 is connected via a network, etc., as described later, to enable mutual communication with the demonstration targets 120, such as devices and software within the system, and the demonstration request sources 130, such as host computers and systems installed in external organizations or factories.
[0021] The verification target 120, which is the source of the trust-building request, performs its own verification in advance and inputs the results of that verification as a status input to the valid time setting unit 111.
[0022] The validity time setting unit 111 sets the validity time of the pre-demonstration results based on the internal state of the demonstration target 120 input from the demonstration target 120, using the demonstration execution time (e.g., elapsed time since the demonstration) and the characteristics of the internal information, outputs it as an internal state with validity time, and inputs it to the internal state storage unit 112. The internal state with validity time input to the internal state storage unit 112 is stored in the internal state storage unit 112 as internal state information 400.
[0023] When a trust-building request is sent from the verification target 120, which is the source of the trust-building request, to the verification request source 130, which is the trust-building destination, the verification request source 130 sends a verification request to the trust management system 110.
[0024] Upon receiving a demonstration request from the demonstration request source 130, the trust management system 110 analyzes (selects) the demonstration content to be executed and the devices and software to be demonstrated based on the demonstration request in the demonstration content analysis unit 113, outputs them as an internal state to be confirmed, and inputs them to the alternative demonstration execution unit 114.
[0025] The alternative demonstration execution unit 114 reads the pre-demonstration results (internal state with validity period) corresponding to the device or software to be demonstrated from the internal state storage unit 112 based on the input demonstration content and information on the device or software to be demonstrated, and substitutes the demonstration execution of the internal state of the device or software to be demonstrated by checking the validity period of the pre-demonstration results (internal state with validity period).
[0026] In this case, the alternative demonstration execution unit 114 determines whether the pre-demonstration result (internal state with validity period) is within the validity period. If it is within the validity period, it does not actually perform the demonstration of the demonstration target 120, but instead sends the pre-demonstration result (internal state with validity period) to the demonstration request source 130 as the demonstration result.
[0027] This eliminates the need to actually perform a demonstration of the demonstration target 120 each time a trust building request is sent from the demonstration target 120 to the demonstration request source 130. As a result, the load on the demonstration target 120 and the network is reduced, and the negative impacts of building a trust chain, such as insufficient resources, can be mitigated.
[0028] Figure 2 illustrates a specific hardware configuration example of the trust management system 110.
[0029] As shown in Figure 2, the trust management system 110 consists of a trust management device 20, a storage device 24, an input device 26a, and an output device 26b, which are interconnected via a network 25 and further connected to the internet 27.
[0030] The trust management device 20 consists of a processing unit 21, which is a arithmetic processing unit such as a CPU (Central Processing Unit), a memory 22, and an input / output I / F (interface) 23.
[0031] The processing unit 21 includes the functions of the effective time setting unit 111, the demonstration content analysis unit 113, and the alternative demonstration execution unit 114 as described in Figure 1, as well as the function of the effective time adjustment unit 800, which will be described later in Example 2 (Figure 8).
[0032] Each part of the processing unit 21 performs processing based on input information from the input device 26a, which is input via the input / output interface 23, and information obtained from the storage device 24 and the internet 27. The results processed by each part of the processing unit 21 are temporarily stored in the memory 22 and output to the storage device 24, the output device 26b, and the internet 27 via the input / output interface 23 and the network 25.
[0033] The storage device 24 has the functions of the internal state storage unit 112 described in Figure 1. This storage device 24 can utilize RAM (Random Access Memory), HDD (Hard Disk Drive), SSD (Solid State Disk), etc.
[0034] The internal state memory unit 112 stores internal state information 400, which will be described later using Figure 4, adjusted internal state information 900, which will be described later in Example 2 (Figure 9), and internal state information 1200, which includes the verification results described later in Example 3 (Figure 12).
[0035] Using Figure 3, an example configuration of a control system 300 to which the trust management system 110 is applied will be explained.
[0036] Figure 3 explains the system assuming that the trust management system 110 is stored on a PC (personal computer) 31. However, it is not limited to this, and it may also be stored on devices or equipment within the control system 300 that are not subject to demonstration, or on devices or equipment with sufficient computing power and other resources, such as external organizations or factories 34 or cloud 37 connected to the control system 300 via an external network 33.
[0037] As shown in Figure 3, the control system 300 consists of a PC 31 on which the trust management system 110 is stored, a robot control device 30, a robot 35 controlled by the robot control device 30, a robot system 36, and a network 32 that connects them to each other. The robot system 36 is a system that combines the robot control device 30 and the robot 35.
[0038] The control system 300 is connected to an external organization or factory 34 or cloud 37 via an external network 33.
[0039] Referring to Figure 1, the establishment of trust relationships (trust chains) in the control system 300 will be explained.
[0040] In Figure 3, for example, if the robot control device 30 is designated as the demonstration target 120, which is the source of the trust-building request, and the external organization or factory 34 is designated as the demonstration request source 130, which is the destination of the trust-building request, the robot control device 30 transmits the trust-building request to the external organization or factory 34 via the external network 33.
[0041] An external organization or factory 34 sends a verification request to the trust management system 110 stored in PC 31 via external networks 33 and 32.
[0042] When the trust management system 110 receives a demonstration request from an external organization or factory 34 (demonstration request source 130), the demonstration content analysis unit 113 analyzes (selects) the demonstration content to be executed based on the demonstration request and the robot control device 30 to be demonstrated, outputs it as an internal state to be confirmed, and inputs it to the alternative demonstration execution unit 114.
[0043] The alternative demonstration execution unit 114 reads the pre-demonstration result (internal state with validity period) corresponding to the robot control device 30 to be demonstrated from the internal state storage unit 112 based on the input demonstration content and information of the robot control device 30 to be demonstrated, and substitutes the demonstration execution of the internal state of the robot control device 30 (demonstration target 120) by confirming the validity period of the pre-demonstration result (internal state with validity period).
[0044] The alternative demonstration execution unit 114 determines whether the pre-demonstration result (internal state with validity period) is within the validity period. If it is within the validity period, it transmits the pre-demonstration result (internal state with validity period) as the demonstration result to the external organization or factory 34 (demonstration request source 130) without actually demonstrating the robot control device 30 (demonstration target 120).
[0045] As a result, each time a trust-building request is sent from the robot control device 30 (demonstration target 120) to an external organization or factory 34 (demonstration request source 130), it is no longer necessary to actually perform a demonstration of the robot control device 30 (demonstration target 120). This reduces the load on the robot control device 30 (demonstration target 120) and the external network 33 and network 32, and mitigates the negative effects of building a trust chain, such as resource shortages.
[0046] An example of internal state information 400 stored in the internal state storage unit 112 will be explained using Figure 4.
[0047] For example, if the robot control device 30 is the subject of demonstration 120, the internal states 420 to be demonstrated in advance include the presence or absence of vulnerabilities (reliability), the presence or absence of failures (protection), the presence or absence of security settings (reliability), and the presence or absence of serial number verification (authenticity). These internal states are demonstrated in advance, and the validity period setting unit 111 sets the validity period for each internal state 420 to 3 months, 3 months, 1 year, and 5 years, respectively.
[0048] Similarly, if robot 35 is the subject of demonstration 120, the internal states 420 to be demonstrated in advance include the presence or absence of malfunctions (protection) and the presence or absence of verification of the serial number (authenticity). These internal states are demonstrated in advance, and the effective time setting unit 111 sets the effective time for each internal state 420 to 3 months, 5 years, and so on.
[0049] Furthermore, if the robot system 36 is designated as the demonstration target 120, the internal state 420 to be demonstrated in advance includes whether or not it is operating properly (reliability). This internal state is demonstrated in advance, and the effective time setting unit 111 sets the effective time for the internal state 420 to 6 months.
[0050] Furthermore, in order to perform advanced security control in the control system 300, the internal state 420 must include information to verify at least one of the following: authenticity, reliability, or protection.
[0051] Figure 5 illustrates the processing flow in the effective time setting unit 111.
[0052] First, in step S501, the device or software within the system to be demonstrated is identified.
[0053] Next, in step S502, the internal state corresponding to the device or software identified in step S501 is extracted.
[0054] Next, in step S503, the effective time is set for the internal state extracted in step S501 based on the results of prior verification.
[0055] Finally, in step S504, structured data as shown in the internal state information 400 in Figure 4 is generated, and the process is terminated.
[0056] Figure 6 illustrates the processing flow in the alternative demonstration execution unit 114.
[0057] First, in step S601, the effective time corresponding to the subject of demonstration is extracted from the internal state storage unit 112.
[0058] Next, in step S602, the validity period is checked. At this time, it is determined whether or not the pre-verification result (internal state with validity period) is within the validity period.
[0059] Finally, in step S603, if it is determined in step S602 that the pre-verification result (internal state with validity period) is within the validity period, the verification result data is generated based on the pre-verification result (internal state with validity period) without performing the verification of the target of verification, and the process is terminated.
[0060] Using Figure 7, we will explain the timing of status input (preliminary verification) in the trust management system 110.
[0061] In Figure 7, the horizontal axis represents time, and the vertical axis represents the computing or network resource usage of devices and software within the system. The white arrows in the figure indicate the normal operating period of the system.
[0062] As shown in Figure 7, the timing for performing the state input (preliminary verification) of the 120 devices under verification will be during periods when the computational or network resources used by the devices and software within the system are small, i.e., during periods when resources are available. Furthermore, the timing of the preliminary verification will be adjusted according to the characteristics of the devices and software within the system and the operating environment.
[0063] For example, it could be run during the annual system maintenance period. Alternatively, if periods of low computational or network resource usage occur periodically (e.g., every 5 seconds), it could be run periodically to coincide with those times. [Examples]
[0064] Referring to Figures 8 to 10, a trust management system and system management method according to Embodiment 2 of the present invention will be described.
[0065] Figure 8 shows a schematic configuration of the trust management system 110 in this embodiment. Figure 9 shows an example of the adjusted internal state information 900. Figure 10 is a flowchart of the processing in the effective time adjustment unit 800. The following will focus on the differences from Embodiment 1.
[0066] The trust management system 110 in this embodiment differs from that of Embodiment 1 (Figure 1) in that it further includes an effective time adjustment unit 800 between the effective time setting unit 111 and the internal state storage unit 112. The other configurations are the same as those of Embodiment 1 (Figure 1).
[0067] The effective time adjustment unit 800 adjusts the length of the effective time according to the type or characteristics of the device or software, and outputs it as an internal state with adjusted effective time. The internal state with adjusted effective time output from the effective time adjustment unit 800 is stored in the internal state storage unit 112 as adjusted internal state information 900.
[0068] For example, even for internal states such as "whether or not there is a malfunction," those with high utilization rates or long operating hours are more likely to change, so adjustments are made to shorten their effective period.
[0069] An example of the adjusted internal state information 900 stored in the internal state storage unit 112 will be explained using Figure 9.
[0070] For example, if the operating rate of the robot 35, which is the subject of demonstration 120, is high for the internal state information 400 in Figure 4, the effective time adjustment unit 800 adjusts the effective time of the presence or absence of failure (protection) in the internal state 420 from 3 months to 1 month, and creates the adjusted internal state information 900.
[0071] Figure 10 illustrates the processing flow in the effective time adjustment unit 800.
[0072] First, in step S1001, structured data such as the internal state information 400 shown in Figure 4 is analyzed.
[0073] Next, in step S1002, the type and characteristics of the device or software that is the subject of demonstration 120 are identified.
[0074] Next, in step S1003, the effective time is adjusted based on the type and characteristics of the device or software identified in step S1002.
[0075] Finally, in step S1004, structured data as shown in the adjusted internal state information 900 in Figure 9 is generated, and the process is terminated.
[0076] According to the trust management system 110 of this embodiment, trust relationships (trust chains) can be established based on a more accurate status of the devices and software within the system. [Examples]
[0077] Referring to Figures 11 and 12, a trust management system and system management method according to Embodiment 3 of the present invention will be described.
[0078] Figure 11 shows a schematic configuration of the trust management system 110 in this embodiment. Figure 12 shows an example of internal state information 1200 including the verification results. The following will focus on the differences from Embodiment 1.
[0079] As shown in Figure 11, the trust management system 110 of this embodiment differs from that of Embodiment 1 (Figure 1) in that it includes the track record of building trust with other devices and software as an internal state. The other configurations are the same as those of Embodiment 1 (Figure 1).
[0080] In other words, the pre-verification results of the internal state storage unit 112 are corrected based on the verification results.
[0081] Using Figure 12, an example of internal state information 1200, including the verification results, stored in the internal state storage unit 112 will be explained.
[0082] For example, if the robot 35, which is the subject of demonstration 120, has a track record of building trust with other devices or software (for example, an external organization or factory 34 in Figure 3) in relation to the internal state information 400 in Figure 4, the internal state information 400 is corrected by adding that track record to create internal state information 1200 that includes the demonstration results.
[0083] According to the trust management system 110 of this embodiment, the number of times the demonstration can be performed can be reduced.
[0084] It should be noted that the present invention is not limited to the embodiments described above, and various modifications are included. For example, the embodiments described above are described in detail to make the present invention easier to understand, and are not necessarily limited to those having all the configurations described. Furthermore, it is possible to replace parts of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of each embodiment with other configurations. [Explanation of symbols]
[0085] 20… Trust Management Device 21… Processing Unit 22...Memory 23… Input / Output I / F (Interface) 24…Storage device 25,32… Network 26a...Input device 26b…Output device 27…Internet 30…Robot control device 31…PC (Personal Computer) 33…External network 34…External organization or factory 35... Robot 36…Robot systems 37…Cloud 110... Trust Management System 111... Effective time setting section 112...Internal state memory unit 113…Demonstration Content Analysis Department 114... Alternative Demonstration Execution Unit 120...Target of verification (source requesting trust building) 130…Source of verification request (trust building target) 300... Control System 400...Internal status information 410, 910, 1210… Names of subjects of demonstration 420,920,1220…Internal status 430, 930, 1230… valid time 800... Effective time adjustment unit 900... Internal status information after adjustment 1200...Internal status information including demonstration results
Claims
1. A trust management system that verifies the internal state of devices or software within a system, A valid time setting unit sets the valid time of the demonstration results using the demonstration execution time and the characteristics of the internal information, based on the internal state of the demonstration target which has been demonstrated in advance. An internal state storage unit that stores information including the internal state and the effective time as a pre-verification result outside the subject of the demonstration, An alternative demonstration execution unit that substitutes for the demonstration execution of the internal state of the subject to demonstration by confirming the aforementioned validity period, A demonstration content analysis unit selects an internal state to substitute for the demonstration execution in the alternative demonstration execution unit based on the demonstration request from the demonstration request source, A trust management system characterized by having the following features.
2. A trust management system for verifying the internal state of devices or software within a system, A valid time setting unit sets the valid time of the demonstration results using the demonstration execution time and the characteristics of the internal information, based on the internal state of the demonstration target which has been demonstrated in advance. An internal state storage unit that stores information including the internal state and the effective time as a pre-verification result outside the subject of the demonstration, The system includes an alternative demonstration execution unit that substitutes for the demonstration execution of the internal state of the subject to be demonstrated by confirming the aforementioned validity period, A trust management system characterized in that the aforementioned internal state is information for confirming at least one of the following: authenticity, reliability, or protection.
3. A trust management system for verifying the internal state of devices or software within a system, A valid time setting unit sets the valid time of the demonstration results using the demonstration execution time and the characteristics of the internal information, based on the internal state of the demonstration target which has been demonstrated in advance. An internal state storage unit that stores information including the internal state and the effective time as a pre-verification result outside the subject of the demonstration, The system includes an alternative demonstration execution unit that substitutes for the demonstration execution of the internal state of the subject to be demonstrated by confirming the aforementioned validity period, The trust management system is characterized in that it is stored in a device or equipment with available resources within the system.
4. A trust management system according to any one of claims 1 to 3, A trust management system characterized by replacing the execution of a demonstration of the internal state of the subject of demonstration by confirming the demonstration results within the aforementioned valid time.
5. A trust management system according to any one of claims 1 to 3, A trust management system characterized by comprising an effective time adjustment unit capable of adjusting the effective time based on the type or characteristics of the aforementioned device or software.
6. A trust management system according to any one of claims 1 to 3, A trust management system characterized by correcting the pre-verification results of the internal state storage unit based on the aforementioned verification results.
7. A system management method for verifying the internal state of devices or software within a system using a trust management system, (a) The validity period setting unit sets the validity period of the demonstration results using the demonstration execution time and the characteristics of the internal information, based on the internal state of the demonstration target that has been demonstrated in advance. (b) The internal state storage unit stores information including the internal state and the effective time as a pre-verification result outside the object to be demonstrated, (c) The alternative demonstration execution unit replaces the demonstration execution of the internal state of the subject to demonstration by confirming the effective time, (d) The demonstration content analysis unit selects an internal state that will substitute for the demonstration execution in step (c) based on the demonstration request from the demonstration request source, A system management method characterized by having the following features.
8. A system management method for verifying the internal state of devices or software within a system using a trust management system, (a) The validity period setting unit sets the validity period of the demonstration results using the demonstration execution time and the characteristics of the internal information, based on the internal state of the demonstration target that has been demonstrated in advance. (b) The internal state storage unit stores information including the internal state and the effective time as a pre-verification result outside the object to be demonstrated, (c) The alternative demonstration execution unit replaces the demonstration execution of the internal state of the subject to demonstration by confirming the effective time, It has, A system management method characterized in that the internal state is information for confirming at least one of the following: authenticity, reliability, or protection.