Relay equipment and network systems
Patent Information
- Application Number
- JP2023135200
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-08-23
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2043-08-23
AI Technical Summary
【0010】 本願において開示される発明のうち、代表的な実施の形態によって得られる効果を簡単に説明すると、通信帯域の低下を抑制しつつ、セキュリティを高めることが可能になる。
Smart Images

Figure 0007917501000001 
Figure 0007917501000002 
Figure 0007917501000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a relay device and a network system. [Background Art]
[0002] Patent Literature 1 discloses a communication control device that simplifies user procedures for authentication processing of multiple services via a communication network. The communication control device receives, from an authentication system that associates a specific user with the communication control device, an authentication request including user identification information of the specific user, the authentication request being transmitted from a terminal device to the authentication system, and controls the authentication system to transmit an input instruction for authentication information to the terminal device. Then, the communication control device receives input information input to the terminal device via the authentication system, authenticates the specific user by collating the input information with the authentication information, and transmits the authentication result to the authentication system. [Prior Art Literature] [Patent Literature]
[0003] [Patent Literature 1] Japanese Unexamined Patent Publication No. 2022-89435 [Summary of the Invention] [Problem to be Solved by the Invention]
[0004] For example, in a 5G (5th Generation) network, it is possible to construct an in-house network or the like using local 5G. Such an in-house network is provided with a core device that performs SIM (Subscriber Identity Module) authentication to ensure security. For example, when accessing an in-house network from a terminal device provided in an external network, by permitting only communication that passes through the core device, only terminal devices for which SIM authentication has been permitted can access the in-house network.
[0005] On the other hand, in order to further improve security, it may be desirable to apply SIM authentication not only to external networks but also to terminal devices installed on the internal network. In this case, for example, it would be sufficient to allow only communication via the core device from terminal devices installed on the internal network. More specifically, the internal network should be configured to allow only communication via the core device. However, in this case, all communication from all terminal devices will pass through the core device. As a result, the performance of the core device may become a bottleneck, potentially reducing the communication bandwidth.
[0006] This invention has been made in view of the above, and one of its objectives is to provide a relay device and network system that can enhance security while suppressing a decrease in communication bandwidth.
[0007] The aforementioned and other objects and novel features of the present invention will become apparent from the description herein and the accompanying drawings. [Means for solving the problem]
[0008] A brief overview of a representative embodiment of the invention disclosed in this application is as follows:
[0009] A relay device according to one embodiment is responsible for relaying frames between a terminal device and a core device, and comprises a connection request packet detection unit, a MAC authentication application unit, and a MAC filter execution unit. The connection request packet detection unit detects connection request packets sent from the terminal device that have the core device as the destination IP address and are necessary to establish encrypted communication with the core device. When the MAC authentication application unit detects a connection request packet, it applies MAC authentication to the source MAC address attached to the connection request packet. If MAC authentication is permitted, the MAC filter execution unit allows the frame sent from the terminal device to pass through based on the permission of the MAC filter. [Effects of the Invention]
[0010] To briefly explain the effects obtained by a representative embodiment of the invention disclosed in this application, it becomes possible to enhance security while suppressing a decrease in communication bandwidth. [Brief explanation of the drawing]
[0011] [Figure 1] This is a schematic diagram showing an example of the configuration and operation of a network system according to the first embodiment. [Figure 2] Figure 1 is a schematic diagram showing an example of the frame format configuration used in underlay communication and the frame format used in IPsec communication. [Figure 3] Figure 1 is a sequence diagram illustrating an example of the main processing steps in the network system shown. [Figure 4A] This block diagram shows an example of the main components of the terminal device in Figure 1. [Figure 4B] Figure 4A is a flowchart showing the main operation examples of the agent unit. [Figure 5A] This block diagram shows an example of the main components of the L2 switch in Figure 1. [Figure 5B] Figure 5A is a block diagram showing an example of the configuration related to the access control unit. [Figure 6A] Figure 1 is a block diagram showing an example of the configuration of the main parts of the core device. [Figure 6B] Figure 6A is a schematic diagram showing an example of the configuration of the IT asset table. [Figure 7] This is a sequence diagram showing an example of the main processing content in the network system according to the second embodiment. [Figure 8] Figure 7 is a block diagram showing an example of the configuration of the core device. [Figure 9A] This is a block diagram showing an example configuration of the core device in a network system according to the third embodiment. [Figure 9B] Figure 9A is a schematic diagram showing an example of the configuration of the IT asset table. [[Mode for Carrying Out the Invention]]
[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all the drawings for explaining the embodiments, the same members are basically denoted by the same reference numerals, and repeated description thereof will be omitted.
[0013] (First Embodiment) <Outline of Network System> FIG. 1 is a schematic diagram showing a configuration example and an operation example of a network system according to the first embodiment. The network system shown in FIG. 1 includes an internal network (NW) 10, an external network (NW) 40, and a terminal device 15b provided in the external network 40. For example, the internal network 10 is an in-house network, and the external network 40 is an external network such as the Internet. The terminal device 15b is, for example, a personal computer (PC) used by a user, or a mobile terminal such as a smartphone, a tablet PC, or the like.
[0014] The internal network 10 is provided with a terminal device 15a, a Layer 2 (L2) switch 16, a Layer 3 (L3) switch 17, a firewall (FW) device 18, an L3 network (L3NW) 19, and a DeMilitarized Zone (DMZ) 20. The firewall device 18 is provided at a boundary between the internal network 10 and the external network 40. The firewall device 18 prevents, for example, unauthorized access from the external network 40 by monitoring communication based on predetermined rules.
[0015] A DMZ 20 and an L3 switch 17 are connected to the firewall device 18. The firewall device 18 permits access requests from the external network 40 to the DMZ 20 side, and rejects access requests from the external network 40 to the L3 switch 17 side. In the present configuration, a core device 35 and a DNS (Domain Name System) server 36 are provided in the DMZ 20.
[0016] The core device 35 is implemented by, for example, a server device including a processor and a memory. The core device 35 has, for example, functions as a base station (gNB) and a 5G core network (5GC) in local 5G, and further has a function as a VPN (Virtual Private Network) server. Specifically, the core device 35 includes at least a function of determining permission / denial of SIM authentication, and a function as a connection request destination, i.e., a responder, for IPsec (Security Architecture for Internet Protocol) communication which is one type of encrypted communication.
[0017] The L3 switch 17 relays received packets based on destination IP addresses. An L3 network 19 is connected to the L3 switch 17. In the present configuration, a network (NW) management unit 30, an authentication server 31, a DHCP (Dynamic Host Configuration Protocol) server 32, and a service server 33 are provided in the L3 network 19. The authentication server 31 is, for example, a RADIUS (Remote Authentication Dial In User Service) server or the like, and authenticates the terminal device 15a and the like based on the RADIUS protocol. The service server 33 provides various functions necessary for employees' work.
[0018] The network management unit 30 manages the internal network 10 by performing various settings and status monitoring on various devices such as those shown in Figure 1 that are installed in the internal network 10. The network management unit 30 can be implemented in the form of, for example, a network management server or network management software. In the latter case, the network management unit 30 can be implemented in, for example, the core device 35, DNS server 36, authentication server 31, DHCP server 32, or business server 33.
[0019] The L2 switch 16 is connected between the L3 switch 17 and the terminal device 15a, and forwards received frames based on their destination MAC address. The terminal device 15a is a PC or mobile terminal, similar to the terminal device 15b. The terminal device 15a includes a physical interface (IF) 25 such as a NIC (Network Interface Card) and an agent unit 26. Although not shown in the diagram, the terminal device 15b is configured similarly to the terminal device 15a.
[0020] The agent unit 26 is implemented by the processor in the terminal device 15a executing an agent program stored in the memory of the terminal device 15a. The agent unit 26 has at least the function of requesting SIM authentication from the core device 35, and, assuming that SIM authentication is permitted, the function of being a source of connection request for IPsec communication, which is one type of encrypted communication, i.e., an initiator.
[0021] This allows IPsec communication to be established with terminal device 15a as the initiator and core device 35 as the responder. In other words, as shown in Figure 1, encrypted communication can be established between terminal device 15a and core device 35, and an IPsec communication tunnel 22 can be constructed here. Note that the network system is not limited to the configuration shown in Figure 1 and can be modified in various ways. For example, multiple firewall devices may be provided, the DNS server 36 may be provided within the L3 network 19, the DNS servers may be separated into internal and external use, or other servers may be added to the DMZ 20 or L3 network 19.
[0022] Next, the prerequisite operations for the network system shown in Figure 1 will be explained. For example, a terminal device 15b, specifically the agent unit 26, located on the external network 40 (not shown in the figure), requests SIM authentication from the core device 35. If SIM authentication is permitted, it establishes an IPsec communication tunnel with the core device 35. As a result, the terminal device 15b can access the internal network 10, specifically the area of the internal network 10 excluding the DMZ 20, via the core device 35, and can use, for example, the business server 33.
[0023] On the other hand, to further enhance security, it is desirable to apply SIM authentication to terminal devices 15a located on the internal network 10. In this case, terminal devices 15a, and more specifically the agent unit 26, should request SIM authentication from the core device 35, and if SIM authentication is permitted, an IPsec communication tunnel 22 should be established between them and the core device 35. Then, only communication via the tunnel 22 should be permitted to terminal devices 15a. Specifically, for example, the L2 switch 16 should be configured to allow only frames FRe that pass through the tunnel 22. As a result, terminal devices 15a can access the external network 40 or the internal network 10, such as the business server 33, via the core device 35.
[0024] However, in this case, all communications from all terminal devices 15a and 15b will pass through the core device 35. As a result, the performance of the core device 35 may become a bottleneck, potentially reducing the communication bandwidth. On the other hand, if underlay communication from terminal device 15a that does not pass through the core device 35, such as the passage of frame FR1 toward the external network 40 as shown in Figure 1, is unconditionally permitted, security may be reduced. In other words, in this case, terminal device 15a is not necessarily a device that is permitted for SIM authentication. Therefore, it is beneficial to use a method as shown in Figure 3, which will be described later.
[0025] Figure 2 is a schematic diagram showing an example of the frame format configuration used in underlay communication and the frame format used in IPsec communication in Figure 1. First, the frame FR used in underlay communication has a configuration in which a MAC header 45a is added to the IP packet PK. In Figure 1, this frame FR corresponds to frame FR1 transmitted from the terminal device 15a, or frame FR2 which has been decapsulated by the core device 35 after passing through the IPsec communication tunnel 22.
[0026] The IP packet PK consists of data 48a with a TCP / UDP header 47a and an IP header 46a added. The TCP / UDP header 47a includes the port number (TCP port number or UDP port number) PT#. The IP header 46a includes the source IP address SIP, destination IP address DIP, and IP protocol number PR#. The MAC header 45a includes the source MAC address SMAC and destination MAC address DMAC.
[0027] Next, the frame FRe used in IPsec communication has a structure in which a MAC header 45b is added to an ESP (Encapsulating Security Payload) packet PKe. The ESP packet PKe is also called an IPsec packet. In the ESP packet PKe, the IP packet PK, which consists of an IP header 46b, a TCP / UDP header 47b, and data 48b, is encrypted according to the ESP protocol after an ESP trailer 52 is added. The ESP packet PKe has an ESP header 51 and authentication data 53 added to the beginning and end of the encrypted information, and furthermore, an encapsulation IP header 50 is added to the beginning.
[0028] The encapsulation IP header 50 and ESP header 51 also serve as the tunnel header 54. The encapsulation IP header 50 includes the source IP address SIPc and destination IP address DIPc for encapsulation, and the IP protocol number PR#. The ESP header 51 includes an SPI (Security Parameter Index) value to identify information such as the encryption algorithm and encryption key used for encryption. The ESP trailer 52 is primarily provided to keep the size of the IP packet constant using padding. The authentication data 53 stores a calculated value of the message digest, i.e., a hash value, to detect tampering.
[0029] For example, consider the case where terminal device 15a sends frame FRe to external network 40 via tunnel 22, as shown in Figure 1. In this case, the source IP address SIPc in the encapsulated IP header 50 is set to the IP address assigned to the physical interface 25 of terminal device 15a. The destination IP address DIPc is set to the IP address of core device 35. In addition, the IP protocol number PR# is set to 50, which represents the ESP packet PKe based on the ESP protocol.
[0030] Meanwhile, in the IP header 46b within the capsule, the source IP address SIP is set to the IP address separately assigned to the agent unit 26 of the terminal device 15a. The destination IP address DIP is set to the IP address of the communication partner located on the external network 40. In addition, in the MAC header 45b, the source MAC address SMAC is set to the MAC address of the terminal device 15a, and the destination MAC address DMAC is set to the MAC address of the L3 switch 17.
[0031] The core device 35 receives such ESP packets PKe via the L2 switch 16 and L3 switch 17. The core device 35 then extracts the IP packet PK from the ESP packet PKe through decapsulation and decoding, adds a MAC header 45a to the extracted IP packet PK, and sends it to the external network 40.
[0032] <Network System Operation> Figure 3 is a sequence diagram showing an example of the main processing steps in the network system shown in Figure 1. In Figure 3, terminal device 15a requests an IP address for the physical interface 25 from DHCP server 32 (step S101). In response, DHCP server 32 assigns an IP address to terminal device 15a (step S102). Subsequently, terminal device 15a, more specifically agent unit 26, queries DNS server 36 for the IP address of core device 35 (step S103). In response, DNS server 36 replies with the IP address of core device 35 (step S104).
[0033] Next, the agent unit 26 sends a SIM authentication request packet to the core device 35, using the IP address of the core device 35 obtained in step S104 as the destination IP address (step S105). In response, the core device 35 determines whether to allow or deny SIM authentication, and in this example, it determines to allow it. The core device 35 sends the determination result to the agent unit 26 and assigns the agent unit 26, which has allowed SIM authentication, an IP address for IPsec communication, that is, the IP address used in the IP header 46b in Figure 2 (step S106).
[0034] Here, the L2 switch 16 is initialized to allow frames used for ARP (Address Resolution Protocol), DHCP, and DNS to pass through in order to perform the processing in steps S101 to S104. Furthermore, the L2 switch 16 is initialized to allow frames used for SIM authentication to pass through in order to perform the processing in steps S105 and S106. For example, when performing SIM authentication using TCP port number PT# 10000, the L2 switch 16 is initialized to allow SIM authentication request packets with TCP port number PT# set to 10000, and consequently, frames containing such packets to pass through.
[0035] The L2 switch 16 is then initially configured to block frames other than those used for ARP, DHCP, DNS, and SIM authentication, based on the fact that the MAC address being allowed in the MAC address filtering (hereinafter also referred to as "MAC filter") is not registered. In other words, the L2 switch 16 is initially configured to block frames sent from the terminal device 15a, excluding SIM authentication request packets, etc., based on the MAC filter's denial of permission.
[0036] After step S106, the agent unit 26 sends a connection request packet to the core device 35 that is necessary to establish IPsec communication with the core device 35, that is, to construct the tunnel 22 (step S107). In detail, this connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. The IKE packet is composed of the IP packet PK format shown in Figure 2. The destination IP address DIP is set to the IP address of the core device 35, and the UDP port number PT# is set to 500, which represents the IKE packet. In detail, the agent unit 26 sends a frame FR generated by adding a MAC header 45a to the IKE packet.
[0037] Here, the connection request packet sent in step S107 is blocked by the L2 switch 16 due to the initial setup described above, and therefore does not reach the core device 35. In the first embodiment, the L2 switch 16 detects a connection request packet with the core device 35 as the destination IP address DIP (step S108). That is, the L2 switch 16 detects a packet in which the destination IP address DIP is the IP address of the core device 35 and the UDP port number PT# is 500.
[0038] Then, when the L2 switch 16 detects the connection request packet in step S108, it applies MAC authentication to the source MAC address SMAC attached to the connection request packet, i.e., the MAC address of the terminal device 15a (steps S109, S110). In the example shown in Figure 3, the L2 switch 16 requests the authentication server 31 to determine whether to grant or deny MAC authentication based on an authentication database or the like which defines MAC addresses that are permitted to be authenticated in advance, and sends the determination result back to the L2 switch 16 (step S110). In this example, the determination result is permission.
[0039] The L2 switch 16 receives the result of the determination in step S110, in this case the determination result of permission, and adds the MAC address of the terminal device 15a to the permission filter of the access control list (ACL). In this example, the L2 switch 16 uses an external authentication server 31 such as a RADIUS server to apply MAC authentication, but it is also possible to use a configuration that does not use an external authentication server 31. That is, the L2 switch 16 itself may maintain the authentication database described above.
[0040] However, in a configuration that does not use the authentication server 31, if the number of terminal devices 15a increases and the number of L2 switches 16 increases accordingly, each of the multiple L2 switches 16 will need to hold duplicate authentication database information, i.e., information on permitted MAC addresses. As a result, memory utilization efficiency decreases, and due to memory capacity limitations, some L2 switches 16 may not be able to register some of the MAC addresses included in the authentication database.
[0041] In contrast, in the configuration using the authentication server 31, each of the multiple L2 switches 16 only needs to retain the MAC addresses of the terminal devices 15a connected under its own network. This improves memory utilization efficiency and makes it easier to handle large-scale networks. If the terminal device 15a is a mobile terminal, the L2 switch 16 to which it is connected may change due to wireless LAN roaming. In this case, MAC authentication is still performed via the authentication server 31 even at the changed L2 switch 16. Therefore, even when roaming occurs, each L2 switch 16 only needs to retain the MAC addresses of the terminal devices 15a connected under its own network.
[0042] After step S110, the agent unit 26 resends the connection request packet because the connection request packet sent in step S107 was blocked by the L2 switch 16 (step S111). As a result of step S110, this connection request packet passes through the L2 switch 16 and reaches the core device 35. As a result, IPsec communication is established between the agent unit 26 and the core device 35, and the tunnel 22 is constructed (step S112).
[0043] In step S112, negotiation based on the IKE protocol takes place between the agent unit 26 and the core device 35, during which the encryption algorithm and encryption key to be used in IPsec communication are determined. The agent unit 26 and the core device 35 store the information determined by the negotiation, linked to the SPI value. As a result, when performing IPsec communication, as shown in Figure 2, encryption / decryption based on the SPI value becomes possible by storing the SPI value in the ESP header 51.
[0044] After the tunnel 22 is established, the agent unit 26 transmits terminal information to the core device 35 via the tunnel 22 (step S113). The terminal information includes, for example, the computer account of terminal device 15a, the user account of the logged-in user, and information indicating the antivirus status of terminal device 15a. In other words, the terminal information includes security information of terminal device 15a or the user using terminal device 15a. Although the processing in step S113 may be omitted, it is desirable to include it for the processing in step S116, which will be described later.
[0045] In step S112, the tunnel 22 is constructed, enabling the terminal device 15a, specifically the agent unit 26, to perform encrypted communication with the external network 40 via the tunnel 22 (step S114). In this case, the IPsec communication frame FRe shown in Figure 2 is used. Furthermore, the terminal device 15a can also communicate with the external network 40 using an underlay communication path that does not go through the tunnel 22, for example, the frame FR1 path shown in Figure 1 (step S115). In this case, the normal frame FR shown in Figure 2 is used.
[0046] In detail, in step S115, the L2 switch 16 receives a normal frame FR, for example, with a device located on the external network 40 as the destination IP address DIP. The L2 switch 16 allows the normal frame FR to pass through because the source MAC address SMAC of the received frame FR, i.e., the MAC address of the terminal device 15a, has been added to the allow filter in step S110. At this time, by using the method shown in Figure 3, the L2 switch 16 can consider the terminal device 15a as a device authorized for SIM authentication.
[0047] Specifically, the agent unit 26 sends a connection request packet in step S107 if SIM authentication is permitted in step S106, and does not send a connection request packet if SIM authentication is not permitted. Then, in steps S108 to S110, MAC authentication is applied to the terminal device 15a that sent the connection request packet, and therefore SIM authentication has been permitted. For this reason, terminal devices 15a that have been permitted MAC authentication are also devices that have been permitted SIM authentication. On the other hand, terminal devices 15a that have not been permitted MAC authentication are devices that were not permitted SIM authentication in step S106, or devices that did not request SIM authentication in step S105.
[0048] In addition, the L2 switch 16 detects the ESP packet PKe passing through the tunnel 22 as described in step S114, in addition to the connection request packet in step S107. The connection request packet is, as previously mentioned, a packet with the core device 35 as the destination IP address DIP and UDP port number PT# 500. The ESP packet PKe is, as shown in Figure 2, a packet with the core device 35 as the destination IP address DIPc and IP protocol number PR# 50.
[0049] When the L2 switch 16 detects an ESP packet PKE, it updates the validity period of the MAC filter for the source terminal device 15a, i.e., the aging timer of the allow filter. Alternatively, when the L2 switch 16 detects an ESP packet PKE or a connection request packet, it updates the aging timer of the allow filter.
[0050] On the other hand, for example, in a 5G network, if the PDU (Protocol Data Unit) session corresponding to tunnel 22 is disconnected, the core device 35 changes the SIM authentication of the terminal device 15a to disallow. In this case, the L2 switch 16 will no longer receive ESP packets PKe from the terminal device 15a, and therefore, based on the aging timer, changes the MAC filter of the terminal device 15a to disallow. That is, the L2 switch 16 removes the MAC address of the terminal device 15a from the allowed filter.
[0051] This synchronizes the SIM authentication status and the MAC filter status, enhancing security. Furthermore, to further improve security, it is desirable that the MAC filter be quickly changed to a disallowed state when the SIM authentication status is changed to disallowed. Therefore, the aging timer setting for the allow filter should ideally be a value that includes a margin over the maximum communication interval allowed in normal communication.
[0052] In step S116, the core device 35 performs a security check. Specifically, the terminal information transmitted in step S113 includes security information such as the computer account of terminal device 15a, the user account of the logged-in user, and information indicating the antivirus status of terminal device 15a, as described above. In step S113, the core device 35 obtains security information from terminal device 15a using IPsec communication, and in step S116, it determines whether the obtained security information is acceptable or not.
[0053] For example, the SIM information authenticated in steps S105 and S106 is merely an identification number. Therefore, SIM authentication alone cannot verify that the SIM information is held by a legitimate terminal device or that the SIM information is being used by a legitimate user. Using the process in step S116 enables such verification, thereby enhancing security. Here, if the core device 35 determines that the security information is unacceptable, it changes the permitted SIM authentication to unapproved and disconnects the established tunnel 22. In this case, the MAC filter also needs to be changed to unapproved.
[0054] When tunnel 22 is disconnected, the aging timer of the allow filter mentioned above can change the MAC filter to deny. However, in this case, there is a possibility of a certain time lag. Therefore, the core device 35 sends a denial request to the NW management unit 30, including the IP address of terminal device 15a, in order to quickly deny the MAC filter (step S117). In this example, the denial request sent is a request to add the MAC address of terminal device 15a to the discard filter of L2 switch 16. In other words, the MAC filter is implemented by, for example, an allow filter and a discard filter. The discard filter is a filter that temporarily denies MAC addresses that are allowed by the allow filter.
[0055] The NW management unit 30 maintains the correspondence between the IP address and MAC address of the terminal device 15a, for example, by periodically acquiring ARP (Address Resolution Protocol) tables held by various devices installed in the internal network 10. Using this correspondence, the NW management unit 30 acquires the MAC address corresponding to the IP address included in the disallowance request from the core device 35. Then, in order to quickly disallow the MAC filter, the NW management unit 30 sends a disallowance command including the MAC address of the terminal device 15a to the L2 switch 16 (step S118).
[0056] In this example, a disallowance command is sent to add the MAC address of terminal device 15a to the discard filter of L2 switch 16. In response to the disallowance command, L2 switch 16 adds the MAC address of terminal device 15a to the discard filter. As a result, L2 switch 16 blocks both communication from terminal device 15a via tunnel 22 and communication on the underlay, i.e., communication not via the tunnel (step S119).
[0057] The discard filter of the L2 switch 16 also has an aging timer, similar to the permit filter. The L2 switch 16 blocks communication from MAC addresses registered in the discard filter only for the duration set by the discard filter's aging timer. The duration set by the discard filter's aging timer is preferably slightly longer than the duration set by the permit filter's aging timer. In this case, while communication is blocked by the discard filter, it is also blocked by the permit filter, and then the discard filter is deactivated. Note that in step S117, a request to add to the discard filter was made, but instead, a request to remove from the permit filter may be made.
[0058] Furthermore, in IPsec communication, NAT (Network Address Translation) traversal may be used as an extended function. NAT traversal is used when a NAPT (Network Address Port Translation) device exists on the communication path between the terminal device 15a and the core device 35. In this case, a problem arises because the UDP header is not present in the tunnel header 54 of the ESP packet PKe shown in Figure 2, but this problem can be solved by using NAT traversal.
[0059] When using NAT traversal, a UDP header is inserted into the tunnel header 54, and the UDP port number in this UDP header is set to 4500. The presence of a NAPT device is detected during the IKE protocol-based negotiation in step S112. If the presence of a NAPT device is detected, the UDP port number PT# in the IKE packet is changed from 500 to 4500.
[0060] Accordingly, when the L2 switch 16 detects connection request packets in step S107, it only needs to detect packets where the destination IP address DIP is the core device 35 and the UDP port number PT# is 500 or 4500. Also, when the L2 switch 16 detects ESP packets PKe in step S114 in conjunction with the aging timer management, it only needs to detect packets where the destination IP address DIPc is the core device 35 and the IP protocol number PR# is 50.
[0061] <Regarding variations> While SIM authentication was used here, it is possible to replace it with something else. In other words, any terminal authentication or user authentication based on a predetermined authentication method can be applied in place of SIM authentication. Specifically, for example, user authentication based on user ID and user password, user authentication based on user biometric information, or terminal authentication based on digital certificates can be applied in place of SIM authentication. Furthermore, encrypted communication is not limited to IPsec communication; any communication that can be tunneled and encrypted is acceptable, such as OpenVPN (Virtual Private Network) communication.
[0062] <Terminal device details> Figure 4A is a block diagram showing an example of the configuration of the main parts of the terminal devices 15a and 15b in Figure 1. The terminal device 15 shown in Figure 4A comprises a physical interface 25, an agent unit 26, a data processing unit 60, and a memory 61. The physical interface 25 is composed of a NIC, as described above. The memory 61 is composed of a combination of volatile memory and non-volatile memory. The memory 61 holds SIM information 63 in advance.
[0063] The agent unit 26, although not shown in the diagram, is implemented by the processor executing an agent program stored in memory 61. The same applies to the data processing unit 60. The data processing unit 60 generates communication data associated with the communication in steps S114 and S115 in Figure 3. The agent unit 26 includes a SIM authentication request unit 65, an encrypted communication establishment unit 66, a split tunnel setting unit 67, and a packet processing unit 68. As shown in step S105 in Figure 3, the SIM authentication request unit 65 sends a SIM authentication request packet to the core device 35 to request SIM authentication of the SIM information 63.
[0064] Split tunneling refers to a technology that separates communication that goes through a VPN from normal communication that does not go through a VPN. In the split tunneling of this embodiment, communication that uses IPsec communication with the core device 35 is separated from communication that does not use IPsec communication and does not go through the core device 35.
[0065] As shown in step S107 in Figure 3, the encrypted communication establishment unit 66 sends a connection request packet to the core device 35 if SIM authentication is permitted. The connection request packet is a packet with the core device 35 as the destination IP address DIP, which is necessary to establish encrypted communication with the core device 35. If the encrypted communication establishment unit 66 does not receive a response to the connection request packet, it resends the connection request packet as shown in step S111 in Figure 3. If the encrypted communication establishment unit 66 receives a response to the connection request packet, it establishes encrypted communication with the core device 35 by performing negotiation based on the IKE protocol, as shown in step S112 in Figure 3.
[0066] The split tunnel configuration unit 67 determines whether the terminal device 15 is located on the external network 40 or the internal network 10. In other words, the split tunnel configuration unit 67 determines whether the terminal device 15 is terminal device 15a or 15b in Figure 1. Specifically, the split tunnel configuration unit 67 determines the location of terminal devices 15a and 15b based on, for example, the IP addresses of the default gateway and DNS server that are initially configured on terminal devices 15a and 15b.
[0067] When the split tunnel configuration unit 67 determines that the installation location is the external network 40, it configures an external split tunnel and applies only IPsec communication to communications destined for the core device 35. As a result, terminal devices 15b located on the external network 40 apply IPsec communication to all communications destined for the internal network 10. Furthermore, the split tunnel configuration unit 67 applies underlay communication to communications that do not have the core device 35 as their destination, i.e., communications within the external network 40.
[0068] On the other hand, if the split tunnel configuration unit 67 determines that the installation location is the internal network 10, it configures an internal split tunnel and applies IPsec communication to communications destined for the core device 35. The split tunnel configuration unit 67 also applies underlay communication, which does not apply IPsec communication, to some communications destined for the external network 40. In step S113 in Figure 3, the split tunnel configuration unit 67 may also transmit the location determination result to the core device 35. In this case, the core device 35 can calculate, for example, the telework rate based on the information of the determination result.
[0069] The packet processing unit 68 generates various packets, including SIM authentication request packets, connection request packets, ESP packets PKe, and regular IP packets PK, in response to requests from the SIM authentication request unit 65, the encrypted communication establishment unit 66, or the data processing unit 60. The packet processing unit 68 then generates a frame containing these packets and transmits it to the outside of the device via the physical interface 25.
[0070] Furthermore, the packet processing unit 68 receives various packets from outside the device via the physical interface 25 and distributes the received packets to the SIM authentication request unit 65, the encrypted communication establishment unit 66, or the data processing unit 60 according to their content. In addition, the packet processing unit 68 performs communication restrictions based on the split tunnel set by the split tunnel setting unit 67.
[0071] Figure 4B is a flowchart showing a main example of the operation of the agent unit 26 in Figure 4A. In Figure 4B, the SIM authentication request unit 65 requests SIM authentication from the core device 35 (step S201). If SIM authentication is permitted (step S202: Yes), the SIM authentication request unit 65 activates the encrypted communication establishment unit 66 and proceeds to step S203. On the other hand, if SIM authentication is not permitted (step S202: No), the SIM authentication request unit 65 sets IPsec communication to unavailable (step S206).
[0072] In step S203, the encrypted communication establishment unit 66 requests the core device 35 to establish an IPsec connection and executes a sequence based on the IKE protocol necessary to establish IPsec communication with the core device 35 (step S203). If IPsec communication is established in step S203 (step S204: Yes), the encrypted communication establishment unit 66 sets IPsec communication to be available (step S205). On the other hand, if IPsec communication is not established in step S203 (step S204: No), the encrypted communication establishment unit 66 sets IPsec communication to be unavailable (step S206).
[0073] <Details of the relay device> Figure 5A is a block diagram showing an example configuration of the main part of the L2 switch 16 in Figure 1. Figure 5B is a block diagram showing an example configuration of the access control unit related to Figure 5A. Here, an example configuration of the L2 switch 16 is shown as an example of a relay device. However, the relay device may be an L3 switch 17 equipped with L2 and L3 functions. In this case, the L2 switch 16 in Figure 1 is not necessary. The L2 switch 16 shown in Figure 5A includes a plurality of physical ports P[1] to P[n], an interface 70, a frame processing unit 71, and a memory 72.
[0074] Multiple physical ports P[1] to P[n] and interface 70 are implemented, for example, by an ASIC (Application Specific Integrated Circuit). The frame processing unit 71 is implemented, for example, by an FPGA (Field Programmable Gate Array), or a combination of an FPGA and a processor. The memory 72 consists of a combination of volatile memory and non-volatile memory.
[0075] Interface 70 mediates the transmission and reception of frames between multiple physical ports P[1] to P[n] and the frame processing unit 71. Memory 72 holds an FDB (Forwarding Database) 80 and a filter 81. The FDB 80 maintains the correspondence between multiple physical ports P[1] to P[n] and MAC addresses located beyond those physical ports P[1] to P[n]. The filter 81 is, for example, an access control list (ACL) for controlling whether access is permitted or denied.
[0076] The frame processing unit 71 comprises a relay processing unit 75 and an access control unit 76. The relay processing unit 75 relays frames based on the FDB 80. Specifically, the relay processing unit 75 determines the relay destination for a frame received at one of the multiple physical ports P[1] to P[n] based on the FDB 80, and relays the received frame to the physical port of that destination. The relay processing unit 75 also updates the FDB 80 by associating the source MAC address SMAC of the received frame with the receiving physical port.
[0077] The access control unit 76 controls whether access is permitted, i.e., whether frames can be relayed, based on the filter 81. The access control unit 76 also sets, changes, and updates the filter 81. In detail, as shown in Figure 5B, the access control unit 76 includes a connection request packet detection unit 85, a MAC authentication application unit 86, a MAC filter execution unit 87, an encrypted packet detection unit 88, a validity period management unit 89, and a MAC filter application unit 84. The memory 72 also holds detection conditions 82 in addition to the filter 81, and holds an allow filter 81a and a discard filter 81b as filters 81 that implement MAC filtering.
[0078] The detection conditions 82 include conditions for detecting connection request packets with the core device 35 as the destination IP address, as described in Figure 3, and conditions for detecting encrypted packets, in this example ESP packets (IPsec packets) PKe, with encrypted communication applied and the core device 35 as the destination IP address. Based on the detection conditions 82, the connection request packet detection unit 85 detects connection request packets as shown in step S107 in Figure 3. Similarly, the encrypted packet detection unit 88 also detects ESP packets PKe as shown in step S114 in Figure 3, based on the detection conditions 82.
[0079] When a connection request packet is detected, the MAC authentication application unit 86 applies MAC authentication to the source MAC address SMAC attached to the connection request packet, i.e., the MAC address of the terminal device 15a, as shown in steps S108 and S109 in Figure 3. In the example shown in Figure 3, the MAC authentication application unit 86 sends a determination request to the authentication server 31 and applies MAC authentication upon receiving the determination result from the authentication server 31. If MAC authentication for the MAC address of the terminal device 15a is permitted, the MAC authentication application unit 86 registers the MAC address in the permission filter 81a.
[0080] The MAC filter application unit 84 registers and deletes MAC addresses in the MAC filter in response to requests from the NW management unit 30 or orders from the validity period management unit 89. Specifically, as shown in step S118 in Figure 3, for example, the MAC filter application unit 84 registers the MAC address in the discard filter 81b in response to a request for denial from the NW management unit 30.
[0081] Furthermore, based on the detection results of the encrypted packet detection unit 88, the validity period management unit 89 changes the permitted MAC filter to a disapproved one if it has not received an encrypted packet, which is an ESP packet PKe, for a predetermined period of time. Specifically, the validity period management unit 89 removes the target MAC address from the permitted filter 81a via the MAC filter application unit 84. As a result, the validity period management unit 89 synchronizes the SIM authentication state and the MAC filter state using the aging timer of the permitted filter 81a, as described in Figure 3.
[0082] The MAC filter execution unit 87 controls the passage / blocking of frames based on the allow filter 81a and the discard filter 81b, i.e., the MAC filter. As one example, if MAC authentication is permitted, the MAC filter execution unit 87 allows frames sent thereafter from the permitted terminal device 15, i.e., frames from the terminal device 15 having a MAC address registered in the allow filter 81a, to pass through based on the MAC filter's permission.
[0083] The access control unit 76, although not shown in the diagram, also includes a management interface for controlling filters 81 other than the MAC filter in response to commands from outside the device, such as commands from the NW management unit 30. In other words, the filter 81 is, for example, an ACL, and by using an ACL, access control can be performed based on various frame information such as IP addresses and IP protocol numbers, not just MAC addresses. As a result, the access control unit 76 can initialize the filter 81 to allow frames associated with steps S101 to S106 to pass through, as described in Figure 3.
[0084] <Core device details> Figure 6A is a block diagram showing an example configuration of the main parts of the core device 35 in Figure 1. Figure 6B is a schematic diagram showing an example configuration of the IT asset table 100 in Figure 6A. The core device 35 shown in Figure 6A is, for example, a server device and comprises a physical interface 91, a virtual base station (virtual gNB) 92, a 5G core network (5GC) 93, and memory 94.
[0085] The physical interface 91 is composed of, for example, a NIC. The memory 94 is composed of a combination of volatile and non-volatile memory. The virtual base station 92 and the 5G core network 93 are components of the 5G network and, although not shown in the diagram, are realized, for example, by a processor executing a program stored in the memory 94. The memory 94 holds the IT asset table 100 and the communication log 102. The virtual base station 92 stores, for example, information contained in packets received by the physical interface 91 as the communication log 102 in the memory 94.
[0086] As shown in Figure 6B, the IT asset table 100 pre-registers legitimate terminal information 105, IP addresses 106, legitimate user information 107, and legitimate SIM information 108. Legitimate terminal information 105 is, for example, the computer accounts CNa and CNb that are legitimately set for each of the multiple terminal devices 15. IP addresses 106 are the IP addresses for each of the multiple terminal devices 15, for example, the IP addresses assigned in step S106 in Figure 3.
[0087] The legitimate user information 107 is, for example, user accounts UNa and UNb that have been legitimately registered in advance. The legitimate SIM information 108 is information legitimately assigned to the terminal device 15 and is information that the terminal device 15 should hold. The legitimate SIM information 108 is, for example, identification numbers IMSIa and IMSIb. In this example, the terminal device 15, the users who are permitted to log in to the terminal device 15, and the SIM information that the terminal device 15 should hold are linked in advance.
[0088] The virtual base station 92 includes an encrypted communication establishment unit 96. The 5G core network 93 includes a SIM authentication unit 97 and a security information determination unit 98. The SIM authentication unit 97 performs SIM authentication in response to a SIM authentication request packet from the terminal device 15a, as shown in step S106 in Figure 3. Specifically, the SIM authentication unit 97 permits SIM authentication if the SIM information 63 of the terminal device 15a included in the SIM authentication request packet is registered in the IT asset table 100 as legitimate SIM information 108.
[0089] As shown in steps S111 and S112 in Figure 3, the encrypted communication establishment unit 96 establishes encrypted communication, in this case IPsec communication, with the terminal device 15a in response to a connection request packet from the terminal device 15a that has been authorized for SIM authentication. As shown in step S113 in Figure 3, the security information determination unit 98 obtains security information from the terminal device 15a using IPsec communication. Then, as shown in step S116, the security information determination unit 98 determines whether the obtained security information is valid or invalid.
[0090] Specifically, the security information discrimination unit 98 verifies the correspondence between the SIM information 63 authorized for SIM authentication and the terminal information and user information included in the security information, based on the IT asset table 100. For example, if the legitimate terminal information 105 corresponding to the SIM information 63 is different from the terminal information included in the security information, the security information discrimination unit 98 determines that the security information is unacceptable.
[0091] If the security information is unacceptable, the security information determination unit 98 sends the IP address of terminal device 15a to the network management unit 30 in order to disallow the MAC filter for the MAC address of terminal device 15a, as shown in step S117 in Figure 3. The transmitted IP address of terminal device 15a is, for example, the IP address assigned to the physical interface 25 in Figure 3, and the source IP address SIPc in the encapsulated IP header 50 in Figure 2. The security information determination unit 98 can obtain this source IP address SIPc, for example, from the communication log 102 associated with step S113.
[0092] <Main effects of Embodiment 1> As described above, in the method of Embodiment 1, the relay device detects connection request packets from terminal devices 15a authorized for SIM authentication and applies MAC authentication to said terminal devices 15a. As a result, terminal devices 15a authorized for MAC authentication, and therefore authorized for SIM authentication, can perform underlay communication, not limited to encrypted communication. Consequently, it becomes possible to enhance security while suppressing a decrease in communication bandwidth. In other words, terminal devices 15a located in the internal network 10, if authorized for SIM authentication, do not necessarily need to go through the core device 35 when communicating, unlike terminal devices 15b located in the external network 40.
[0093] (Second Embodiment) <Network System Operation> Figure 7 is a sequence diagram showing an example of the main processing content in the network system according to the second embodiment. The configuration of the network system according to the second embodiment is the same as in Figure 1. The difference from the first embodiment is that in the method shown in Figure 3, the MAC filter was applied starting from the relay device, i.e., the L2 switch 16. On the other hand, in the method shown in Figure 7, the MAC filter is applied starting from the core device 35a.
[0094] In Figure 7, the processing in steps S101 to S106 is the same as in Figure 3. Following step S106, the terminal device 15a sends a connection request packet. In Figure 3, the L2 switch 16 blocked the connection request packet based on the MAC filter's denial (step S107). On the other hand, in Figure 7, the L2 switch 16 is initialized to allow the connection request packet to pass through (step S301).
[0095] Accordingly, in Figure 7, a tunnel 22 is established between the terminal device 15a and the core device 35a (step S302), similar to steps S112 to S114 in Figure 3, enabling the transmission of terminal information via tunnel 22 (step S303) and communication with the external network 40 via tunnel 22 (step S304). However, in Figure 3, the L2 switch 16 allowed frames passing through the tunnel based on MAC filter permission. On the other hand, in Figure 7, the L2 switch 16 allows frames passing through the tunnel based on initial settings.
[0096] In detail, the L2 switch 16 is initially configured to allow, in addition to frames used for ARP, DHCP, DNS, and SIM authentication, as in Figure 3, to also allow frames containing connection request packets and ESP packets PKe, unlike in Figure 3. In other words, the L2 switch 16 is initially configured to block frames transmitted from the terminal device 15a based on MAC filter denials, excluding SIM authentication request packets, connection request packets, and encrypted packets used for encrypted communication. Therefore, if communication from the terminal device 15a occurs immediately after step S304 without going through the tunnel, the L2 switch 16 will block the frames associated with that communication.
[0097] After steps S303 and S304, the core device 35a determines whether the security information obtained in step S303 is acceptable, similar to step S116 in Figure 3 (step S305). Then, unlike in Figure 3, if the tunnel 22 is established and the security information is acceptable, the core device 35a sends a permission request to the NW management unit 30, including the IP address of the terminal device 15a, to allow the MAC filter for the terminal device 15a (step S306). In this example, the permission request sent is a request to add the MAC address of the terminal device 15a to the permission filter 81a of the L2 switch 16.
[0098] The NW management unit 30 obtains the MAC address from the IP address of the terminal device 15a included in the authorization request and sends an authorization command to the L2 switch 16, which includes the MAC address of the terminal device 15a, in order to allow the MAC filter for the terminal device 15a (step S307). In this example, the authorization command sent is an instruction to add the MAC address of the terminal device 15a to the authorization filter 81a of the L2 switch 16. As a result, the terminal device 15a becomes able to communicate without going through the tunnel, i.e., underlay communication (step S308).
[0099] Furthermore, the core device 35a monitors whether the PDU session is disconnected, that is, whether the tunnel 22, which is the communication path for encrypted communication, is disconnected. If the core device 35a detects that the PDU session is disconnected (step S309), it sends a disallowance request to the NW management unit 30, which includes the IP address of the terminal device 15a, in order to disallow the MAC filter for the terminal device 15a (step S310). In this example, the disallowance request sent is a request to remove the MAC address of the terminal device 15a from the allow filter 81a of the L2 switch 16.
[0100] The NW management unit 30 obtains the MAC address from the IP address of the terminal device 15a included in the disallowance request and sends a disallowance command to the L2 switch 16 that includes the MAC address of the terminal device 15a in order to disallow the MAC filter for the terminal device 15a (step S311). In this example, the disallowance command sent is a command to remove the MAC address of the terminal device 15a from the L2 switch 16's allow filter 81a. As a result, the L2 switch 16 blocks frames associated with communication from the terminal device 15a that does not go through the tunnel, based on the disallowance of the MAC filter (step S312).
[0101] As described above, the processing in steps S309 to S311 allows the SIM authentication state and the MAC filter state to be synchronized, as shown in Figure 3. However, in the case of Figure 3, this synchronization is achieved by the aging timer of the authorization filter 81a in the L2 switch 16, i.e., the validity period management unit 89 in Figure 5B. On the other hand, in the case of Figure 7, this synchronization is achieved by the cooperation between the core device 35a and the NW management unit 30. Note that the processing in steps S309 to S311 can also be applied to the method shown in Figure 3.
[0102] Furthermore, the processes in steps S303 and S305 in Figure 7 are optional. However, performing these processes can further enhance security, as described in the first embodiment. In addition, in Figure 7, as in Figure 3, the L2 switch 16 may be initialized to allow SIM authentication, and the core device 35a may apply a MAC filter to the terminal device 15a via the NW management unit 30 when SIM authentication is permitted in step S106. In this case, the L2 switch 16 will allow connection request packets to pass based on the MAC filter's permission.
[0103] However, with this method, in step S301, the connection request packet may not reach the core device 35a. More specifically, even if the connection request packet is retransmitted within a certain time, it may not reach the core device 35a. This is because the time required in steps S306 and S307 may be longer than the time required in steps S109 and S110 in Figure 3.
[0104] Therefore, in Figure 7, the L2 switch 16 is initially configured to allow connection request packets and IPsec packets to pass through. After IPsec communication is established, the L2 switch 16 applies a MAC filter to the terminal device 15a via the NW management unit 30. This ensures that the process up to the construction of the tunnel 22 is carried out reliably. Furthermore, it becomes possible to permit the MAC filter for terminal devices 15a that have been granted SIM authentication and have been able to construct the tunnel 22. In other words, the MAC filter can be denied for terminal devices that have been granted SIM authentication but have not been able to construct the tunnel 22.
[0105] Furthermore, considering wireless LAN roaming, the core device 35a needs to send the authorization request in step S306 via the NW management unit 30 so that all L2 switches 16 installed in the internal network 10 can register the same MAC address. In this case, similar to the case where the authentication server 31 is not used as described in the first embodiment, the memory utilization efficiency of the L2 switches 16 decreases, and due to memory capacity limitations, some L2 switches 16 may not be able to register the MAC address. Therefore, from this perspective, it is beneficial to use the method shown in Figure 3 in the first embodiment.
[0106] <Core device details> Figure 8 is a block diagram showing an example configuration of the core device 35a in Figure 7. The core device 35a shown in Figure 8 differs from that in Figure 6A in the configuration of the 5G core network 93a. The 5G core network 93a includes a SIM authentication unit 97 similar to that in Figure 6A, as well as a security information discrimination unit 98a that is slightly different from that in Figure 6A, and further includes a MAC filter application unit 110 and a session management unit 111. The SIM authentication unit 97 can be any terminal / user authentication unit that performs terminal authentication or user authentication, as described in the first embodiment.
[0107] As shown in step S306 in Figure 7, the MAC filter application unit 110 directly or indirectly transmits the MAC address of the terminal device 15a to the L2 switch 16, which has established encrypted communication with the terminal device 15a, in order to allow the L2 switch 16 to pass frames from the terminal device 15a based on the permission of the MAC filter. In the example shown in Figure 7, the MAC filter application unit 110 indirectly transmits the MAC address of the terminal device 15a to the L2 switch 16 via the NW management unit 30. However, if, for example, the core device 35a is equipped with the NW management unit 30, the MAC filter application unit 110 can cooperate with the NW management unit 30 to directly transmit the MAC address of the terminal device 15a to the L2 switch 16.
[0108] As shown in steps S309 and S310 in Figure 7, when the session management unit 111 detects a PDU session disconnection, it directly or indirectly transmits the MAC address of the terminal device 15a to the L2 switch 16 so that the L2 switch 16 can block frames from the terminal device 15a based on MAC filter denial. In the example shown in Figure 7, the MAC address of the terminal device 15a is transmitted indirectly. In the example shown in Figure 8, the session management unit 111 also accesses the network management unit 30 via the MAC filter application unit 110.
[0109] Here, the session management unit 111 can detect the disconnection of the PDU session, i.e., the tunnel 22, based on the communication log 102 which indicates the disconnection of the PDU session. Alternatively, the session management unit 111 may detect the disconnection of the PDU session based on the URR (Usage Reporting Rules) information in PFCP (Packet Forwarding Control Protocol), i.e., the results of monitoring the communication bitrate.
[0110] The security information discrimination unit 98a determines whether the security information obtained from the terminal device 15a is acceptable, similar to the case in Figure 6A. However, unlike the case in Figure 6A, as shown in step S305 in Figure 7, the security information discrimination unit 98a causes the MAC filter application unit 110 to directly or indirectly transmit the MAC address of the terminal device 15a if the security information is acceptable.
[0111] In other words, the MAC filter application unit 110 applies the MAC filter to terminal devices 15a that have established encrypted communication and whose security information has passed the inspection. Note that in step S306 in Figure 7, the IP address of terminal device 15a transmitted from the MAC filter application unit 110 can be obtained from the communication log 102 associated with step S303, as in the case of Figure 3.
[0112] The configuration of the L2 switch 16 in Figure 7 is the same as in Figure 5A. However, the access control unit 76 does not need to have all the parts shown in Figure 5B, and only needs to have a management interface that sets, updates, and modifies the filter 81 in response to commands from the NW management unit 30. In detail, for example, one of the management interfaces may be a MAC filter application unit 84 as shown in Figure 5B. The MAC filter application unit 84 sets, updates, and modifies the filter 81 in response to commands from the NW management unit 30. Also, the configuration of the terminal device 15a is the same as in Figures 4A and 4B.
[0113] <Main effects of the second embodiment> As described above, the same effects as those described in the first embodiment can be obtained by using the method of the second embodiment. Furthermore, the method of the second embodiment is advantageous compared to the method of the first embodiment in that it does not require the implementation of special functions in the L2 switch 16 and can be applied to a relatively general L2 switch 16.
[0114] <Note> (1-1) A terminal device to which terminal authentication or user authentication based on a prescribed authentication method is applied, A core device that performs terminal authentication or user authentication on the terminal device, A relay device responsible for relaying frames between the terminal device and the core device, A network management unit maintains the correspondence between IP addresses and MAC addresses and manages the relay device, Equipped with, The terminal device sends an authentication request packet to the core device to request terminal authentication or user authentication, and if the terminal authentication or user authentication is permitted by the core device, it sends a connection request packet to the core device necessary to establish encrypted communication with the core device. The relay device controls the passage / blocking of frames from the terminal device based on the MAC filter. The core device is In response to the authentication request packet from the terminal device, terminal authentication or user authentication is performed, and in response to the connection request packet from the terminal device that has authorized terminal authentication or user authentication, encrypted communication is established with the terminal device. When the encrypted communication is established, the IP address of the terminal device is sent to the network management unit in order to allow the MAC filter for the terminal device. The network management unit obtains the MAC address from the IP address of the terminal device and sends a permission command including the MAC address of the terminal device to the relay device in order to allow the MAC filter for the terminal device. Network system.
[0115] (1-2) In the network system described in (1-1), The aforementioned encrypted communication is IPsec communication. The aforementioned connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. Network system.
[0116] (1-3) In the network system described in (1-1), The relay device is initially configured to block frames transmitted from the terminal device based on the MAC filter's denial, excluding the authentication request packets, connection request packets, and encrypted packets used in encrypted communication. Network system.
[0117] (1-4) In the network system described in (1-1), The aforementioned terminal authentication or user authentication is SIM authentication. Network system.
[0118] (1-5) In the network system described in (1-1) or (1-4), Before transmitting the IP address of the terminal device to the network management unit, the core device obtains security information from the terminal device using encrypted communication, determines whether the obtained security information is acceptable, and transmits the IP address of the terminal device to the network management unit if the security information is acceptable. Network system.
[0119] (1-6) In the network system described in (1-1), When the core device detects a disconnection in the encrypted communication path, it sends the IP address of the terminal device to the network management unit in order to disable the MAC filter for the terminal device. The network management unit obtains the MAC address from the IP address of the terminal device and sends a disallowance command including the MAC address of the terminal device to the relay device in order to disallow the MAC filter for the terminal device. Network system.
[0120] (2-1) A server device connected to a terminal device to which terminal authentication or user authentication based on a predetermined authentication method is applied, via a relay device responsible for relaying frames, A terminal / user authentication unit that performs terminal authentication or user authentication in response to an authentication request packet from the terminal device, An encrypted communication establishment unit establishes encrypted communication with the terminal device in response to a connection request packet from the terminal device for which terminal authentication or user authentication has been permitted. A MAC filter application unit that directly or indirectly transmits the MAC address of the terminal device to the relay device in order to allow the relay device to pass frames from the terminal device based on the permission of the MAC filter, with respect to the terminal device that has established the encrypted communication, Equipped with, Server device.
[0121] (2-2) In the server device described in (2-1), The aforementioned encrypted communication is IPsec communication. The aforementioned connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. Server device.
[0122] (2-3) In the server device described in (2-1), The aforementioned terminal authentication or user authentication is SIM authentication. Server device.
[0123] (2-4) In the server device described in (2-1) or (2-3), Before the MAC address of the terminal device is transmitted to the relay device, the security information determination unit obtains security information from the terminal device using encrypted communication, determines whether the obtained security information is acceptable or not, and if the security information is acceptable, causes the MAC filter application unit to directly or indirectly transmit the MAC address of the terminal device. Server device.
[0124] (2-5) In the server device described in (2-1), The relay device includes a session management unit that, when it detects a disconnection in the communication path of the encrypted communication, directly or indirectly transmits the MAC address of the terminal device to the relay device so that the relay device can block frames from the terminal device based on the MAC filter's denial. Server device.
[0125] (2-6) In the server device described in (2-1), The MAC filter application unit transmits the MAC address of the terminal device to the relay device via the network management unit, which maintains the correspondence between IP addresses and MAC addresses. Server device.
[0126] (Third embodiment) <Understanding Issues> For example, the internal network 10 shown in Figure 1 may include terminal devices that do not hold SIM information, such as printers or fixed servers, in addition to the terminal device 15a that holds SIM information. In the first or second embodiment, a MAC filter is applied according to SIM authentication, so the L2 switch 16 can pass frames from the terminal device 15a that holds SIM information based on the MAC filter. However, the L2 switch 16 does not allow MAC filtering for terminal devices that do not hold SIM information, and therefore blocks frames from such terminal devices.
[0127] As a countermeasure, for example, one could individually register the MAC addresses of terminal devices that do not hold SIM information and whose communication should always be permitted in the permission filter 81a of each L2 switch 16. However, in this case, network management may become complicated. To simplify network management, it is desirable to have the core device 35 centrally manage not only terminal devices 15a that hold SIM information, but also terminal devices that do not hold SIM information. Specifically, a mechanism is desired that allows the core device 35 to perform appropriate access control to the L2 switch 16, even for terminal devices that do not hold SIM information.
[0128] <Core device details> Figure 9A is a block diagram showing an example configuration of the core device in a network system according to the third embodiment. Figure 9B is a schematic diagram showing an example configuration of the IT asset table 100b in Figure 9A. Here, the explanation is based on the method in Figure 7, but it can also be applied to the method in Figure 3. The core device 35b shown in Figure 9A differs from the case in Figure 8 in the configuration of the IT asset table 100b in the memory 94 and the configuration of the 5G core network 93b. In addition to the SIM authentication unit 97, security information discrimination unit 98a, MAC filter application unit 110, and session management unit 111, which are the same as in the case in Figure 8, the 5G core network 93b includes a MAC filter initial setting unit 115.
[0129] As shown in Figure 9B, the IT asset table 100b pre-registers not only the same legitimate terminal information 105, IP address 106, legitimate user information 107, and legitimate SIM information 108 as in Figure 6B, but also SIM authentication application information 120. The SIM authentication application information 120 indicates whether SIM authentication is applied or not for each of the multiple terminal devices. For example, in Figure 9B, the terminal device with terminal information CNa (the first terminal device) is a PC, etc., to which SIM authentication is applied. On the other hand, the terminal device with terminal information CNa (the second terminal device) is a printer, etc., to which SIM authentication is not applied. The IP address IPAc of the printer, etc., is set fixedly in advance.
[0130] The MAC filter initial setup unit 115 extracts terminal devices to which SIM authentication is not applied based on the application information 120 registered in the IT asset table 100b during the initial setup of the network system. In the example in Figure 9B, terminal devices with terminal information CNc are extracted. The MAC filter initial setup unit 115 then directly or indirectly transmits the MAC address of the extracted terminal device to the L2 switch 16 so that the L2 switch 16 can pass frames from the extracted terminal device based on MAC filter permission.
[0131] Assuming the method shown in Figure 7, the MAC filter initial setup unit 115 sends a permission request to the NW management unit 30, including the extracted IP address IPAc of the terminal device, similar to step S306 in Figure 7. The NW management unit 30 obtains the MAC address from the IP address IPAc and sends a permission command to the L2 switch 16, including the obtained MAC address, similar to step S307 in Figure 7.
[0132] <Main effects of the third embodiment> As described above, by using the method of the third embodiment, in addition to the various effects described in the first or second embodiment, terminal devices that do not hold SIM information can be operated normally on the network system described in the first or second embodiment. Furthermore, since terminal devices can be centrally managed by the core device 35b regardless of whether SIM authentication is applied or not, network management can be simplified.
[0133] <Note> (3-1) A server device connected to a plurality of terminal devices, including a first terminal device to which SIM authentication is applied and a second terminal device to which the SIM authentication is not applied, via a relay device responsible for relaying frames, A SIM authentication unit that performs SIM authentication in response to a SIM authentication request packet from the first terminal device, An encrypted communication establishment unit establishes encrypted communication with the first terminal device in response to a connection request packet from the first terminal device for which the SIM authentication has been authorized, A memory that holds an IT asset table in which the IP addresses of each of the multiple terminal devices, application information indicating whether the SIM authentication is applied or not for each of the multiple terminal devices, and SIM information that is properly assigned to the first terminal device are registered, A MAC filter initial setup unit extracts the second terminal device based on the application information registered in the IT asset table, and transmits the MAC address of the second terminal device directly or indirectly to the relay device so that the relay device can pass frames from the second terminal device based on MAC filter permission, Equipped with, Server device.
[0134] (3-2) In the server device described in (3-1), For the first terminal device that has established the encrypted communication, the relay device is provided with a MAC filter application unit that directly or indirectly transmits the MAC address of the first terminal device, in order to allow the relay device to pass frames from the first terminal device based on the permission of the MAC filter. Server device.
[0135] (3-3) In the server device described in (3-1), The aforementioned encrypted communication is IPsec communication. The aforementioned connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. Server device.
[0136] (3-4) In the server device described in (3-1), The MAC filter initial setting unit transmits the MAC address of the second terminal device to the relay device via the network management unit, which maintains the correspondence between IP addresses and MAC addresses. Server device.
[0137] (4-1) A plurality of terminal devices including a first terminal device to which SIM authentication is applied and a second terminal device to which the SIM authentication is not applied, A core device that performs the SIM authentication on the first terminal device, A relay device responsible for relaying frames between the aforementioned multiple terminal devices and the core device, A network management unit maintains the correspondence between IP addresses and MAC addresses and manages the relay device, Equipped with, The first terminal device sends a SIM authentication request packet to the core device to request the SIM authentication, and if the SIM authentication is permitted by the core device, it sends a connection request packet to the core device necessary to establish encrypted communication with the core device. The relay device controls the passage / blocking of frames from the plurality of terminal devices based on the MAC filter. The core device is A SIM authentication unit that performs SIM authentication on the first terminal device in response to a SIM authentication request packet from the first terminal device, An encrypted communication establishment unit establishes encrypted communication with the first terminal device in response to a connection request packet from the first terminal device for which the SIM authentication has been authorized, A memory that holds an IT asset table in which the IP addresses of the plurality of terminal devices, application information indicating whether the SIM authentication is applied or not to the plurality of terminal devices, and SIM information that is legally assigned to the first terminal device are registered, A MAC filter initial setup unit extracts the second terminal device based on the application information registered in the IT asset table, and transmits the IP address of the second terminal device to the network management unit in order to allow the relay device to pass frames from the second terminal device based on MAC filter permission, Equipped with, The network management unit obtains the MAC address from the IP address of the second terminal device and sends a permission command to the relay device, including the MAC address of the second terminal device, in order to allow the MAC filter for the second terminal device. Network system.
[0138] (4-2) In the network system described in (4-1), The core device includes a MAC filter application unit that transmits the IP address of the first terminal device to the network management unit, in order to enable the relay device to pass frames from the first terminal device based on MAC filter permission, targeting the first terminal device that has established encrypted communication. The network management unit obtains the MAC address from the IP address of the first terminal device and sends a permission command to the relay device, including the MAC address of the first terminal device, in order to permit the MAC filter for the first terminal device. Network system.
[0139] (4-3) In the network system described in (4-1), The aforementioned encrypted communication is IPsec communication. The aforementioned connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. Network system.
[0140] The present invention has been described in detail above based on embodiments, but the present invention is not limited to the embodiments described above and can be modified in various ways without departing from its essence. For example, the embodiments described above are described in detail in order to explain the present invention in an easy-to-understand manner and are not necessarily limited to those having all the described configurations. Furthermore, it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add a configuration from another embodiment to the configuration of one embodiment. In addition, it is possible to add, delete, or replace a part of the configuration of each embodiment with a configuration from another embodiment.
[0141] For example, the various programs mentioned above can be stored in a non-temporary, tangible, computer-readable recording medium and then supplied to a computer. Examples of such recording media include magnetic recording media such as hard disk drives, optical recording media such as DVDs (Digital Versatile Discs) and Blu-ray discs, and semiconductor memory such as flash memory. [Explanation of Symbols]
[0142] 10: Internal Network, 15: Terminal Device, 16: L2 Switch (Relay Device), 26: Agent Unit, 30: Network Management Unit, 31: Authentication Server, 35: Core Device (Server Device), 40: External Network, 76: Access Control Unit, 81: Filter, 85: Connection Request Packet Detection Unit, 86: MAC Authentication Application Unit, 87: MAC Filter Execution Unit, 88: Encrypted Packet Detection Unit, 89: Validity Period Management Unit, 96: Encrypted Communication Establishment Unit, 97: SIM Authentication Unit, 98: Security Information Discrimination Unit, 100: IT Asset Table, 110: MAC Filter Application Unit, 111: Session Management Unit, 115: MAC Filter Initial Setup Unit
Claims
1. A relay device that is responsible for relaying frames between terminal devices and core devices, A connection request packet detection unit detects connection request packets that are transmitted from the terminal device and have the core device as the destination IP address, which are necessary to establish encrypted communication with the core device. A MAC authentication application unit that, upon detecting the aforementioned connection request packet, applies MAC authentication to the source MAC address attached to the connection request packet, If the MAC authentication is permitted, the MAC filter execution unit allows frames transmitted from the terminal device to pass through based on the MAC filter's permission, Equipped with, The terminal device sends an authentication request packet to the core device to request terminal authentication or user authentication based on a predetermined authentication method, and if the terminal authentication or user authentication is permitted, it sends the connection request packet to the core device. The MAC filter execution unit is initially configured to allow the authentication request packet to pass through. Relay device.
2. In the relay device described in claim 1, The encrypted communication is IPsec communication. The aforementioned connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. Relay device.
3. In the relay device described in claim 1, An encrypted packet detection unit that detects encrypted packets to which the aforementioned encrypted communication has been applied, If the encrypted packets mentioned above are not received for a predetermined period, the validity period management unit changes the permitted MAC filter to a disapproved one. Equipped with, Relay device.
4. In the relay device described in claim 1, The MAC authentication application unit sends a request to the authentication server to determine whether to allow or deny the MAC authentication, and receives the MAC authentication determination result from the authentication server. Relay device.
5. In the relay device described in claim 1, The MAC filter execution unit is initially configured to exclude the authentication request packet and block frames transmitted from the terminal device, including the frame containing the connection request packet, based on the MAC filter's denial. Relay device.
6. In the relay device according to claim 5, The aforementioned terminal authentication or user authentication is SIM authentication. Relay device.
7. A terminal device to which terminal authentication or user authentication based on a prescribed authentication method is applied, A core device that performs terminal authentication or user authentication on the terminal device, A relay device responsible for relaying frames between the terminal device and the core device, Equipped with, The terminal device sends an authentication request packet to the core device to request terminal authentication or user authentication, and if the terminal authentication or user authentication is permitted by the core device, it sends a connection request packet with the core device as the destination IP address, which is necessary to establish encrypted communication with the core device. The core device performs terminal authentication or user authentication in response to the authentication request packet from the terminal device, and establishes encrypted communication with the terminal device in response to the connection request packet from the terminal device that has authorized the terminal authentication or user authentication. The relay device is, The system is configured to allow the aforementioned authentication request packet to pass through. The connection request packet from the terminal device is detected, When the aforementioned connection request packet is detected, MAC authentication is applied to the source MAC address attached to the connection request packet. If the MAC authentication is permitted, the frame transmitted from the terminal device is allowed to pass through based on the MAC filter's permission. Network system.
8. In the network system described in claim 7, The encrypted communication is IPsec communication. The aforementioned connection request packet is an IKE packet based on the IKE (Internet Key Exchange) protocol. Network system.
9. In the network system described in claim 7, The relay device is, The encrypted packet to which the aforementioned encrypted communication has been applied is detected, If the encrypted packet is not received within a predetermined time, the permitted MAC filter is changed to a disallowed one. Network system.
10. In the network system described in claim 7, The system includes an authentication server that determines whether to allow or deny the MAC authentication, When applying MAC authentication, the relay device sends a request to the authentication server to determine whether to allow or deny the MAC authentication, and receives the MAC authentication determination result from the authentication server. Network system.
11. In the network system described in claim 7, The relay device is initially configured to block frames transmitted from the terminal device, including frames containing connection request packets, based on the MAC filter's denial, excluding the authentication request packets. Network system.
12. In the network system described in claim 7, The aforementioned terminal authentication or user authentication is SIM authentication. Network system.
13. In the network system according to claim 7 or 12, It includes a network management unit that maintains the correspondence between IP addresses and MAC addresses and manages the relay device, The core device uses the encrypted communication to obtain security information from the terminal device, determines whether the obtained security information is acceptable or unacceptable, and if the security information is unacceptable, transmits the IP address of the terminal device to the network management unit in order to deny the MAC filter for the terminal device's MAC address. The network management unit obtains the MAC address from the IP address of the terminal device and sends a disallowance command to the relay device, which includes the MAC address of the terminal device, in order to disallow the MAC filter for the terminal device. Network system.
Citation Information
Patent Citations
Improved security method and apparatus for communicating over a network
JP2005530404A
Tunnel communication system
JP2014090241A
Network system and server device
JP2016134733A
Communication control device, communication control system, communication control method, and communication control program
JP2022089435A
Network system and server device
JP2023086211A