Communication system, control device, communication method, and program
By integrating a SIM authentication system with edge devices, the complexity of connecting edge devices to edge controllers is reduced, enabling secure and automated setup and application distribution.
Patent Information
- Application Number
- JP2022116481
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-21
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2042-07-21
AI Technical Summary
Conventional edge devices require complex initial setup processes to connect to edge controllers, making it difficult for users to make them usable.
Equipping edge devices with a SIM mounting section for wireless network connectivity and integrating a SIM authentication system with edge controllers to facilitate secure and automated connection and authentication, allowing for initial setup and application distribution based on SIM information.
Enables easy and secure connection of edge devices to edge controllers, automating initial setup and application distribution, and reducing the complexity of the setup process.
Smart Images

Figure 0007910712000001 
Figure 0007910712000002 
Figure 0007910712000003
Abstract
Description
Technical Field
[0001] The present invention relates to a technique for starting the use of an edge device in edge computing.
Background Art
[0002] The global edge computing market is growing significantly due to the increase in data volume, the demand for real-time processing, and the influence of the social background caused by COVID-19.
[0003] That is, first, the range of data that can be collected in the IoT field has expanded, increasing the amount of data stored in the cloud. On the other hand, the demand for real-time processing is increasing, and the number of use cases that require more immediacy than before, such as autonomous driving and anomaly detection, is increasing. Furthermore, in order to reduce the risk of pandemic due to the influence of COVID-19, the demand for online services such as remote asset maintenance and monitoring and telemedicine has increased rapidly.
[0004] Edge computing means one of the network techniques of "distributing servers near the terminals". Especially in the manufacturing site, edge computing enables high-speed or real-time application processing (visualization of data) for a large amount of data obtained from a large number of sensors and measuring instruments installed in the factory.
[0005] The "server placed near the terminal" is called an edge device. The biggest reason for deploying the workload to the edge device is often to counteract the delay, but by bringing the processing and storage closer to the users and "things" that are the data sources, it is expected that concerns regarding bandwidth, data privacy (security), and autonomy can also be addressed.
[0006] In recent years, general-purpose edge devices capable of running various edge-oriented applications, such as AI and IoT, have emerged to realize edge computing. Conventional edge devices are installed on-premises in places like factories, stores, and campuses, or in carrier data centers.
[0007] Furthermore, a system has been developed that uses edge controllers to centrally control general-purpose edge devices that are distributed on-premises. [Prior art documents] [Patent Documents]
[0008] [Patent Document 1] Japanese Patent Publication No. 2022-023707 [Overview of the Initiative] [Problems that the invention aims to solve]
[0009] However, with conventional technology, users must go through a complicated initial setup process to connect edge devices to edge controllers and make them usable. For example, users of edge devices receive them by mail from the provider, but it is often difficult for them to make the edge devices usable themselves after receiving them.
[0010] This invention has been made in view of the above points, and aims to provide a technology for easily utilizing edge devices that are connected to and used with edge controllers. [Means for solving the problem]
[0011] According to the disclosed technology, a communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device is a communication system that authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and establishes a VPN with the edge device if the authentication is successful. The edge device is equipped with an eSIM, and the SIM information is written to the eSIM from a SIM management device via the network. Communication system It will be provided. [Effects of the Invention]
[0012] The disclosed technology provides a technology for easily utilizing edge devices that are connected to and used with edge controllers. [Brief explanation of the drawing]
[0013] [Figure 1] This diagram shows an example of the overall system configuration. [Figure 2] This is a system configuration diagram of the first embodiment. [Figure 3] This is a flowchart illustrating the operation of the first embodiment. [Figure 4] This figure shows an example of an edge device management table for the first embodiment. [Figure 5] This is a diagram illustrating VPN authentication in the first embodiment. [Figure 6] This figure shows an example of configuration information generated by the edge device of the first embodiment. [Figure 7] This figure shows the edge device of the second embodiment. [Figure 8] This figure shows the edge device of the second embodiment. [Figure 9] This is a flowchart illustrating the operation of the second embodiment. [Figure 10] This figure shows the edge controller of the third embodiment. [Figure 11]It is a diagram showing an example of an edge device management table according to the third embodiment. [Figure 12] It is a diagram showing an example of an app template according to the third embodiment. [Figure 13] It is a system configuration diagram according to the third embodiment. [Figure 14] It is a flowchart for explaining the operation of the third embodiment. [Figure 15] It is a system configuration diagram according to the fourth embodiment. [Figure 16] It is a flowchart for explaining the operation of the fourth embodiment. [Figure 17] It is a diagram showing an example of an edge device management table according to the fourth embodiment. [Figure 18] It is a diagram for explaining the VPN authentication according to the fourth embodiment. [Figure 19] It is a diagram showing an example of the setting information generated by the edge device according to the fourth embodiment. [Figure 20] It is a diagram showing an example of the hardware configuration of the device.
Modes for Carrying Out the Invention
[0014] Hereinafter, embodiments (the present embodiments) of the present invention will be described with reference to the drawings. The embodiments described below are merely examples, and the embodiments to which the present invention is applied are not limited to the following embodiments.
[0015] (Overview of the Embodiment) As described above, in the prior art, in order to connect an edge device to an edge controller and make it actually available, complicated setting work is required, and it is often difficult for the user himself / herself to perform the setting work.
[0016] Specifically, for example, in order for edge devices to securely connect to edge controllers, the use of IPsec VPN or SSL VPN is required, which necessitates manually entering authentication keys, certificates, passwords, etc., previously issued by the service provider into the edge devices. Performing such tasks accurately is difficult for users.
[0017] Therefore, in this embodiment, the edge device is newly equipped with a SIM mounting section, and by simply mounting a SIM for connecting to a wireless network (e.g., 3G, LTE, 5G, 6G) in the SIM mounting section, a communication path independent of the existing on-premises IT environment is secured.
[0018] Furthermore, the edge authentication unit in the edge controller is linked with the SIM authentication unit in the conventional SIM management device, allowing the edge controller to determine whether to permit a connection from the relevant edge device based on the SIM information. In addition to authentication, it is also possible to perform initial setup and application distribution within the edge device based on the SIM information.
[0019] (Example of the overall system configuration) Figure 1 shows an example of the overall configuration of the communication system in this embodiment. As shown in Figure 1, this communication system has a configuration in which a SIM management device 300, an edge controller 100, and an edge device 200 are connected to the network 1. The edge device 200 is installed, for example, at each user location.
[0020] The SIM management device 300 is, for example, a device provided by a mobile communications carrier. The SIM management device 300 may also be a subscriber management device provided by a mobile communications carrier.
[0021] The edge controller 100 is a device that manages and controls one or more edge devices 200. The edge devices 200 are used while connected to the edge controller 100 via a VPN (Virtual Private Network). The edge controller 100 performs processes such as authentication processing and application distribution, which will be described later. In addition, when the edge devices 200 are used, the edge controller 100 monitors whether the edge devices 200 are operating normally via the VPN.
[0022] The edge device 200 is a computer capable of running applications. Furthermore, by using a SIM card, the edge device 200 can access mobile networks (including wireless networks) and communicate with other devices via the mobile network. Network 1 is a network that includes a mobile network capable of communication using a SIM card.
[0023] The configuration and operation of the system comprising the SIM management device 300, edge controller 100, and edge device 200 will be described in detail below. The first to fourth embodiments will be described below. The first embodiment is the most basic example, and the second to fourth embodiments will mainly be described in terms of the differences from the first embodiment. Note that the first to fourth embodiments can be implemented in any combination.
[0024] Furthermore, the SIM management device 300, the edge controller 100, and the edge device 200 are all computers with communication capabilities. The functional configurations of each device will be illustrated as appropriate below, but these configurations will show the configurations of functions particularly relevant to the technology according to the present invention.
[0025] Furthermore, "edge device" may be replaced with "communication device," "processing device," "server," etc. Also, "VPN" may be replaced with "line," "private network," etc. Furthermore, the edge controller 100 may be called a control device.
[0026] (First Embodiment) First, the first embodiment will be described. The configuration of each device in the first embodiment is shown in FIG. 2. As shown in FIG. 2, the edge controller 100 includes an edge device management unit 110, an edge authentication unit 120, and a GW (gateway) 130.
[0027] The edge device management unit 110 manages the edge device 200 and the like. The edge authentication unit 120 authenticates the edge device 200 and the like. The GW 130 includes a function of constructing a VPN with the edge device 200 and a function of performing data communication with the edge device 200 using the VPN. The VPN according to the present embodiment is constructed using, for example, a mobile network in which the edge device 200 is permitted to connect based on SIM information. Note that there is no particular limitation on the network for constructing the VPN according to the present embodiment, and in addition to the above mobile network, for example, the Internet or a closed network may be used for construction.
[0028] The edge device 200 includes a VPN termination unit 210, a controller communication unit 220, and a SIM mounting unit 230. The VPN termination unit 210 includes a function of constructing a VPN with the GW 130 and a function of terminating the VPN and performing data communication between the controller communication unit 220 and the edge controller 100 via the VPN. In the example of FIG. 2, the SIM 240 is mounted on the SIM mounting unit 230. The SIM management device 300 includes a SIM authentication unit 310 that performs SIM authentication.
[0029] Referring to the flowchart of FIG. 3, an operation example of the system having the above configuration will be described.
[0030] <S101: Preparation in advance> In S101, the SIM 240 to be used in the edge device 200 is issued from the SIM management device 300 side (e.g., mobile communication carrier). Issuing the SIM 240 includes physically sending the SIM 240 to the base where the edge device 200 is provided.
[0031] Also, in S101, the SIM management device 300 notifies the edge controller 100 of the SIM information of the SIM 240.
[0032] The SIM information notified to the edge controller 100 in S101 is, for example, any one or any two or all three of IMSI, Ki, and OPC. IMSI, Ki, and OPC may all be referred to as authentication information. The SIM information is not limited to these and may be any information. Also, the SIM information may include management information related to the SIM in addition to IMSI, Ki, OPC, etc.
[0033] The SIM information can be automatically notified directly from the SIM management device 300 to the edge controller 100. However, an operator may intervene and manually notify (input) it to the edge controller 100 from the outside.
[0034] <S102: Edge registration> In S102, the edge controller 100 performs edge registration to create a template (edge device management table) of the edge device 200.
[0035] Specifically, the edge device management unit 110 registers each edge device in the form of the edge device management table shown in FIG. 4 based on the SIM information acquired in S101. That is, the edge device management unit 110 holds the edge device management table in a storage means such as a memory in the edge device management unit 110, and when registering a new edge device 200, it adds information to the edge device management table. The "edge device management table" may be referred to as the "storage unit".
[0036] As shown in FIG. 4, the edge device management table in the first embodiment has, as items, an edge device name, an edge UID (edge user ID), a VPN user ID, and a VPN password. The edge UID, VPN user ID, and VPN password may all be referred to as "authentication information". Also, the combination of the VPN user ID and the VPN password may be referred to as "authentication information".
[0037] Hereinafter, as an example, the entry of "Factory A" will be described. The same applies to other entries.
[0038] Regarding Factory A, the "XXX" used for the edge UID, VPN user ID, and VPN password is, for example, the SIM information itself of the SIM of Factory A. The SIM information used as "XXX" may be any one of the IMSI, Ki, and OPC, or any combination of two or all of them.
[0039] As described above, using the SIM information itself as "XXX" is just an example. Information obtained by processing the SIM information may also be used as "XXX". For example, a new identifier may be generated by combining a globally unique identifier (or other related information) that identifies the SIM of Factory A with the SIM information, and this new identifier may be used as "XXX".
[0040] Also, information obtained by processing the SIM information using the above unique identifier (or other related information) may be used as "XXX".
[0041] Note that when referring to using SIM information, the "SIM information" includes not only the SIM information itself but also information generated from the SIM information.
[0042] <S103: SIM Authentication> In S103, in the activation operation of the edge device 200, the SIM authentication unit 310 of the SIM management device 300 determines whether the edge device 200 can connect to an external network (e.g., a mobile network such as LTE, 5G, etc.) using the SIM 240. Note that the "external network" means an external network, not an internal network built on-premises.
[0043] Specifically, first, at the base where the edge device 200 is deployed, the SIM 240 issued in S101 is installed on the edge device 200. The edge device 200 automatically connects to the SIM management device 300 using the SIM information, and the SIM authentication unit 310 of the SIM management device 300 authenticates the edge device 200 based on the SIM information to determine whether the edge device 200 can be connected to the external network. The authentication method here itself is a general authentication method using a SIM.
[0044] If it is determined in the SIM authentication of S103 that connection to the external network is possible, the process proceeds to S104.
[0045] <S104: VPN Authentication> In S104, the edge authentication unit 120 of the edge controller 100 determines whether a VPN can be established between the edge device 200 and the edge controller 100 through processes such as authenticating the edge device 200.
[0046] A specific example of the process of S104 will be described with reference to FIG. 5. Here, the process based on the EAP-MD5 authentication method will be described. However, using the EAP-MD5 authentication method is just an example, and other methods other than the EAP-MD5 authentication method may be used, or the EAP-MD5 authentication method may be combined with other methods for use.
[0047] Here, it is assumed that the SIM information is XXX. Also, it is assumed that the VPN termination part 210 in the edge device 200 holds the CA certificate 211, and the GW130 in the edge controller 100 holds the server certificate 131 and the CA certificate 132.
[0048] S1: First, the VPN termination part 210 acquires the SIM information from the SIM 240.
[0049] S2: The VPN termination unit 210 automatically generates configuration information used to establish a VPN between the edge device 200 and the edge controller 100, based on the SIM information (XXX). Figure 6 shows an example of this configuration information. Figure 6 shows an example of configuration information when using an IPsec VPN as the VPN. Configuration information can be generated similarly for other types of VPNs (e.g., SSL VPN).
[0050] As shown in Figure 6, in the configuration information, XXX@abc.def is used as the VPN user ID (eap-username) and XXX is used as the VPN password (eap-password). The VPN termination unit 210 sends authentication information (e.g., eap-username and eap-password) to the edge controller 100.
[0051] S3: Next, the edge authentication unit 120 of the edge controller 100 performs authentication (referred to as authentication 1) to the edge device 200 based on the authentication information (e.g., eap-username, eap-password) received from the edge device 200. Specifically, the edge authentication unit 120 performs authentication 1 by comparing the authentication information received from the edge device 200 with the authentication information (VPN user ID and VPN password) in the edge device management table (Figure 4). The edge authentication unit 120 determines that authentication 1 has been successful if the authentication information in the edge device management table matches the authentication information received from the edge device 200. The edge authentication unit 120 decides to establish a VPN with the edge device 200 if it has succeeded in authentication 1. Specifically, the edge authentication unit 120 decides to establish a VPN with the edge device 200 if it has succeeded in authentication 1 and also succeeded in authentication 2, which will be described later.
[0052] S4: The VPN termination part 210 of the edge device 200 obtains the server certificate 131 from GW130 and performs authentication 2 by matching the server certificate 131 with the CA certificate 211 held by the VPN termination part 210. This process corresponds to authenticating the edge controller 100 using the server certificate 131 and the CA certificate 211.
[0053] Through the processes of S1 to S4 described above, when both authentication 1 and authentication 2 are successful, a VPN is constructed between the VPN termination part 210 of the edge device 200 and the GW130 of the edge controller 100.
[0054] <S105: Edge device authentication> After the VPN is constructed in S104, the edge authentication part 120 of the edge controller 100 determines whether the edge device 200 can be registered with the edge controller 100 as a management target by authenticating the edge device 200 based on the SIM information of the edge device 200.
[0055] Specifically, the controller communication part 220 of the edge device 200 obtains SIM information (e.g., XXX) from the SIM 240 and transmits the SIM information to the edge authentication part 120 in the edge controller 100 via the VPN.
[0056] The edge authentication part 120 compares the SIM information received from the edge device 200 with the edge UID of the edge device 200 in the edge device management table (e.g., Figure 4), and determines that the authentication is successful if the SIM information matches the edge UID.
[0057] If the authentication is successful, the edge controller 100 registers the edge device 200 as a management target in a storage means such as a memory. Thereby, the use of the edge device 200 is officially started. For example, the edge controller 100 monitors the operating status of the edge device 200 via the VPN.
[0058] (Second Embodiment) Next, a second embodiment will be described. The following will primarily focus on the differences from the first embodiment.
[0059] In the second embodiment, as shown in Figure 7, a card-type eSIM 241 is mounted in the SIM mounting section 230 of the edge device 200. As shown in Figure 8, a chip-type eSIM, the eSIM chip 242, may be built into the edge device 200.
[0060] Referring to Figure 9, an example of the process in S101 (preparation) in the second embodiment will be described. In the second embodiment, remote SIM provisioning is performed in S101-1. Specifically, first, for example, a third-party server (or SIM management device 300) generates a profile of the SIM to be used by the edge device 200. Then, the SIM management device 300 remotely writes the SIM profile to the eSIM 241 (or eSIM chip 242) via the network. The SIM profile includes SIM information.
[0061] In S101-2, the SIM management device 300 notifies the edge controller 100 of the SIM information.
[0062] (Third embodiment) Next, a third embodiment will be described. The following will primarily focus on the differences from the first embodiment.
[0063] In the third embodiment, as shown in Figure 10, the edge device management unit 110 of the edge controller 100 holds application templates 111 in addition to the edge device management table 112. Furthermore, as shown in Figure 11, an "application template" item is added to the edge device management table 112. The application to which edge device is applied can be pre-configured, for example.
[0064] Figure 12 shows an example of an application template 111. Figure 12 is an example of an application template for "App A". "App A" is an example of application identification information. The attributes shown in Figure 12 are just examples. Attributes other than those shown in Figure 12 may be used in the application template. Furthermore, a composite application consisting of multiple applications may be applied to a single edge device 200. Also, the application itself may be stored within the edge controller 100 or outside the edge controller 100.
[0065] As described above, by providing an application template 111 and extending the edge device management table, it becomes possible to associate a specific application template with each edge device 200 and manage them accordingly.
[0066] For example, by using the name of the application template (e.g., Application A), it is possible to link the application template with the applications used for each edge device in the edge device management table.
[0067] In the third embodiment, as shown in Figure 13, the edge device 200 can obtain the applications it should use from the remote edge controller 100 and execute the obtained applications on the virtualization infrastructure 250.
[0068] The application management unit is, for example, a VM or a container. Furthermore, the virtualization infrastructure 250 shown in Figure 13 is, for example, a hypervisor (e.g., KVM) or a container engine (e.g., Docker).
[0069] Refer to the flowchart in Figure 14 to explain an example of the operations involved in obtaining the application.
[0070] After successfully authenticating the edge device in S105, in S106, the edge device management unit 110 of the edge controller 100 uses the extended edge device management table 112 to obtain the target application to be distributed to the edge device 200. Then, the edge device management unit 110 distributes the application to the edge device 200 via the VPN constructed in S104.
[0071] In S107, the edge device 200 loads the distributed application onto the virtualization platform 250 and executes the application.
[0072] Note that in the above example, the information distributed from the edge controller 100 to the edge device 200 is an application. However, information other than the application (e.g., configuration information) may be distributed from the edge controller 100 to the edge device 200 using the same method as described above.
[0073] (Fourth Embodiment) Next, the fourth embodiment will be described. In the fourth embodiment, in addition to the SIM information, the edge device 200 is authenticated using the HW information (hardware information) that can identify the edge device 200. For example, as the HW information, the serial number of the motherboard 221 of the edge device 200 (computer) as shown in FIG. 15 can be used.
[0074] Referring to the flowchart of FIG. 16, the operations in the fourth embodiment will be described.
[0075] <S101-1: Preparation 1> S101-1 is the same as S101 in the first embodiment.
[0076] <S101-2: Preparation 2> In S101-2, the HW information for identifying the edge device 200 is notified to the edge controller 100.
[0077] As for the HW information, as described above, the serial number of the motherboard 221 of the edge device 200 can be used, but it is not limited thereto. Any HW information can be used as long as it can identify the edge device 200.
[0078] Also, HW information such as the serial number of the motherboard 221 can be obtained offline from, for example, the device manufacturer. Also, the edge controller 100 can be connected to an external order management system or an external inventory management system, and as part of the order processing of the edge device 200, the HW information can be automatically dispensed from the order management system or the inventory management system to the edge controller 100. That is, for example, when an order for an edge device 200 to be shipped to a certain site is placed with the order management system, the order management system automatically notifies the edge controller 100 of the HW information of that edge device 200.
[0079] <S102´: Edge Registration> In S102´, the edge controller 100 performs edge registration to create a template (edge device management table) of the edge device 200 based on the SIM information of the edge device 200 and the HW information of the edge device 200.
[0080] Specifically, the edge device management unit 110 registers each edge device in the form of the edge device management table shown in FIG. 17 based on the SIM information obtained in S101-1 and the HW information obtained in S101-2. That is, the edge device management unit 110 holds the edge device management table shown in FIG. 17 in a storage means such as a memory in the edge device management unit 110.
[0081] As shown in Figure 17, the edge device management table in the fourth embodiment has the same items as in the first embodiment: edge device name, edge UID, VPN user ID, and VPN password. The edge UID, VPN user ID, and VPN password may all be called "authentication information." Alternatively, the combination of VPN user ID and VPN password may also be called "authentication information." Below, we will explain the entry for "Factory A" as an example. The same applies to other entries.
[0082] Regarding Factory A, the "XXX-xxx" used in the Edge UID, VPN User ID, and VPN password is information generated by adding (concatenating) the HW information "xxx" to the SIM information "XXX".
[0083] The hardware information "xxx" may be the hardware information itself, or it may be information that has been processed from the hardware information itself. For example, a new identifier may be generated by combining the hardware information with a globally unique identifier (or other related information) that identifies the target hardware (such as a motherboard), and this new identifier may be used as "xxx".
[0084] Furthermore, the HW information may be processed using the unique identifier (or other related information) mentioned above and used as "xxx".
[0085] Alternatively, a new identifier "ZZZ" may be generated from the SIM information "XXX" and the HW information "xxx," which is information other than "XXX-xxx" (simply the two concatenated together), and this can be used as "XXX-xxx" in Figure 17. In other words, in this case, the edge UID would be ZZZ, the VPN user ID would be ZZZ@ntt.com, and the VPN password would be ZZZ.
[0086] Furthermore, when using "HW information," this "HW information" includes not only the HW information itself, such as the serial number, but also information generated from the HW information itself.
[0087] <S103: SIM Authentication> S103 in the fourth embodiment is the same as S103 in the first embodiment.
[0088] <S104´: VPN Authentication> In S104´, the edge authentication unit 120 of the edge controller 100 determines whether a VPN can be constructed between the edge device 200 and the edge controller 100 through processes such as authenticating the edge device 200. S104´ is basically the same as S104 in the first embodiment, but in the fourth embodiment, it is different from the first embodiment in that not only SIM information but also SIM information and HW information are used.
[0089] A specific example of the process of S104´ will be described with reference to FIG. 18. Here, the process based on the EAP-MD5 authentication method will be described. However, using the EAP-MD5 authentication method is just an example, and other methods besides the EAP-MD5 authentication method may be used, or the EAP-MD5 authentication method and other methods may be used in combination.
[0090] Here, assume that the SIM information is XXX and the HW information is xxx, and the information XXX-xxx obtained by concatenating these is used as the authentication information.
[0091] S1: First, the VPN termination unit 210 obtains SIM information from the SIM 240.
[0092] S2: The VPN termination unit 210 automatically generates the configuration information used to construct a VPN between the edge device 200 and the edge controller 100 based on the SIM information (XXX) and the HW information (xxx). Note that the VPN termination unit 210 can obtain HW information from, for example, the motherboard 221.
[0093] Figure 19 shows an example of the configuration information. Figure 19 shows an example of configuration information when using an IPsec VPN as the VPN. Configuration information can be generated similarly for other types of VPNs (e.g., SSL VPN).
[0094] As shown in Figure 19, in the configuration information, XXX-xxx@abc.def is used as the VPN user ID (eap-username) and XXX-xxx is used as the VPN password (eap-password). The VPN termination unit 210 sends authentication information (e.g., eap-username and eap-password) to the edge controller 100.
[0095] S3: Next, the edge authentication unit 120 performs authentication (referred to as authentication 1) to the edge device 200 based on the authentication information (e.g., eap-username, eap-password) received from the edge device 200. Specifically, the VPN termination unit 210 performs authentication 1 by comparing the authentication information received from the edge device 200 with the authentication information (VPN user ID and VPN password) in the edge device management table (Figure 17). The edge authentication unit 120 determines that authentication 1 has been successful if the authentication information in the edge device management table matches the authentication information received from the edge device 200. The edge authentication unit 120 decides to establish a VPN with the edge device 200 only if authentication 1 is successful. Specifically, the edge authentication unit 120 decides to establish a VPN with the edge device 200 only if authentication 1 is successful and authentication 2, described later, is also successful.
[0096] S4: The VPN termination unit 210 of the edge device 200 obtains the server certificate 131 from the GW 130 and performs authentication 2 by matching the server certificate 131 with the CA certificate 211 held by the VPN termination unit 210. This process is equivalent to authenticating the edge controller 100 using the server certificate 131 and the CA certificate 211.
[0097] Based on the S1-S4 processes described above, if both Authentication 1 and Authentication 2 are successful, a VPN connection is established between the VPN termination unit 210 of the edge device 200 and the GW130 of the edge controller 100.
[0098] (Example hardware configuration) The edge controller 100, edge device 200, and SIM management device 300 can all be implemented, for example, by having a computer run a program. This computer may be a physical computer or a virtual machine in the cloud. Hereinafter, the edge controller 100, edge device 200, and SIM management device 300 will be collectively referred to as "devices".
[0099] In other words, the device can be realized by using hardware resources such as the CPU and memory built into the computer to execute a program corresponding to the processing performed by the determination device 100. The program can be recorded on a computer-readable recording medium (such as portable memory), saved, and distributed. It can also be provided via a network such as the Internet or email.
[0100] Figure 20 shows an example of the hardware configuration of the computer described above. The computer in Figure 20 has a drive device 1000, an auxiliary storage device 1002, a memory device 1003, a CPU 1004, an interface device 1005, a display device 1006, an input device 1007, an output device 1008, etc., all of which are interconnected by a bus BS.
[0101] The program that enables processing on the computer is provided, for example, on a recording medium 1001 such as a CD-ROM or memory card. When the recording medium 1001 containing the program is set in the drive device 1000, the program is installed from the recording medium 1001 to the auxiliary storage device 1002 via the drive device 1000. However, the program does not necessarily have to be installed from the recording medium 1001; it may also be downloaded from another computer via a network. The auxiliary storage device 1002 stores the installed program as well as necessary files and data.
[0102] When a program startup command is received, the memory device 1003 reads the program from the auxiliary storage device 1002 and stores it. The CPU 1004 then implements the functions related to the memory device 1003 according to the program stored in the memory device 1003.
[0103] The interface device 1005 is used as an interface for connecting to a network, etc. The display device 1006 displays a GUI (Graphical User Interface) or the like using a program. The input device 1007 consists of a keyboard and mouse, buttons, or a touch panel, etc., and is used to input various operation instructions. The output device 1008 outputs the calculation results. Note that the device may be configured without any or all of the display device 1006, input device 1007, and output device 1008.
[0104] (Effects of the embodiment) The technology according to this embodiment makes it possible to easily utilize an edge device 200 that is connected to and used with an edge controller 100.
[0105] More specifically, the technology according to this embodiment utilizes a SIM card to separate the communication path with the edge controller 100 from the existing on-premises IT environment, thereby easily enabling connection to an external network for communication with the edge controller 100. Furthermore, by employing an authentication method using a SIM card and closely linking the SIM authentication function with the authentication function of the edge device 200, authentication of the edge device 200 can be achieved more securely and at a lower cost compared to conventional methods. In addition, initial deployment processes such as configuration settings within the edge device 200 and distribution of edge applications can be automated.
[0106] (Note) This specification discloses at least the following communication systems, control devices, communication methods, and programs: (Additional note 1) A communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and establishes a VPN with the edge device if the authentication is successful. Communication system. (Additional note 2) The edge device is equipped with an eSIM, and the SIM information is written to the eSIM from a SIM management device via the network. The communication system described in Appendix 1. (Additional note 3) The edge information management table records, along with the first authentication information, the identification information of the application used by the edge device. The control device determines the application to be delivered to the edge device based on the edge information management table, and delivers the application to the edge device via the VPN. The communication system described in Appendix 1 or 2. (Additional note 4) The control device generates the first authentication information using the SIM information and hardware information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates the second authentication information using the SIM information and the hardware information, and transmits the generated second authentication information to the control device. A communication system as described in any one of the appendices 1 through 3. (Additional note 5) The control device in a communication system comprising an edge device and a control device, An edge device management unit generates first authentication information using the SIM information of the edge device and records the generated first authentication information in an edge information management table. An edge authentication unit receives second authentication information generated using the SIM information from the edge device, compares the received second authentication information with the first authentication information recorded in the edge information management table, authenticates the edge device, and, if the authentication is successful, decides to establish a VPN with the edge device. A control device equipped with the following features. (Additional note 6) A communication method in a communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and establishes a VPN with the edge device if the authentication is successful. Communication method. (Additional note 7) A program for causing the computer to function as a component of the control device described in Appendix 5.
[0107] Although this embodiment has been described above, the present invention is not limited to this specific embodiment, and various modifications and changes are possible within the scope of the gist of the invention as described in the claims. [Explanation of Symbols]
[0108] 1 Network 100 Edge Controllers 110 Edge Device Management Department 120 Edge Authentication Unit 130 GW 200 edge device 210 VPN termination section 220 Controller Communication Unit 230 SIM slot 300 SIM management device 310 SIM Authentication Section 1000 drive unit 1001 Recording media 1002 Auxiliary storage device 1003 Memory device 1004 CPU 1005 Interface device 1006 Display device 1007 Input device 1008 Output device
Claims
1. A communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device is a communication system that authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and establishes a VPN with the edge device if the authentication is successful. The edge device is equipped with an eSIM, and the SIM information is written to the eSIM from a SIM management device via the network. Communication system.
2. A communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device is a communication system that authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and establishes a VPN with the edge device if the authentication is successful. The edge information management table records, along with the first authentication information, the identification information of the application used by the edge device. The control device determines the application to be delivered to the edge device based on the edge information management table, and delivers the application to the edge device via the VPN. Communication system.
3. A communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device is a communication system that authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and establishes a VPN with the edge device if the authentication is successful. The control device generates the first authentication information using the SIM information and hardware information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates the second authentication information using the SIM information and the hardware information, and transmits the generated second authentication information to the control device. Communication system.
4. The control device in a communication system comprising an edge device and a control device, An edge device management unit generates first authentication information using the SIM information of the edge device and records the generated first authentication information in an edge information management table. The edge authentication unit receives second authentication information generated using the SIM information from the edge device, compares the received second authentication information with the first authentication information recorded in the edge information management table, authenticates the edge device, and, if the authentication is successful, decides to establish a VPN with the edge device. The edge information management table records, along with the first authentication information, the identification information of the application used by the edge device. The control device determines the application to be delivered to the edge device based on the edge information management table, and delivers the application to the edge device via the VPN. Control device.
5. A communication method in a communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and if the authentication is successful, establishes a VPN with the edge device. The edge device is equipped with an eSIM, and the SIM information is written to the eSIM from a SIM management device via the network. Communication method.
6. A communication method in a communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and if the authentication is successful, establishes a VPN with the edge device. The edge information management table records, along with the first authentication information, the identification information of the application used by the edge device. The control device determines the application to be delivered to the edge device based on the edge information management table, and delivers the application to the edge device via the VPN. Communication method.
7. A communication method in a communication system comprising an edge device and a control device, The control device generates first authentication information using the SIM information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates a second authentication information using the SIM information and transmits the generated second authentication information to the control device. The control device authenticates the edge device by comparing the second authentication information received from the edge device with the first authentication information recorded in the edge information management table, and if the authentication is successful, establishes a VPN with the edge device. The control device generates the first authentication information using the SIM information and hardware information of the edge device, and records the generated first authentication information in the edge information management table. The edge device generates the second authentication information using the SIM information and the hardware information, and transmits the generated second authentication information to the control device. Communication method.
8. A program for causing a computer to function as a component of the control device described in claim 4.
Citation Information
Patent Citations
Distributed system, backend service, edge server and method therefor
JP2019045970A
Edge device, data transmission device, communication system, communication method, and program
JP2019193190A
SIM, communication device, and application writing method
JP2022023707A
Edge device, communication control method of edge device, and communication control program
JP2022038588A
Radio communication device and communication system
JP2022074512A