Communication system, configuration method, and program
Patent Information
- Application Number
- JP2024566928
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-26
- Publication Date
- 2026-09-09
- Estimated Expiration
- 2042-12-26
AI Technical Summary
【0011】 本発明により、電気通信事業者の意図に反する動作がサービス提供に与える影響を抑制可能である。
Smart Images

Figure 0007917802000001 
Figure 0007917802000002 
Figure 0007917802000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication system, a setting method, and a program. [Background Art]
[0002] As one of commercial telecommunications facilities installed at a user's premises, there is a communication device (transceiver accommodation device) that accommodates a transceiver used for digital coherent communication. The transceiver accommodation device is, for example, a white box transponder including a white box switch (WBS) and a transponder. It is also called an open transponder (see, for example, Non-Patent Document 1). Specific examples of the white box switch include Galileo and Cassini.
[0003] Device software (for example, Goldstone) is installed on the hardware of the white box switch. A communication system (optical transmission system) that provides large-capacity services is constructed by combining a large-capacity coherent optical transceiver and the white box switch. [Prior Art Documents] [Non-Patent Documents]
[0004] [Non-Patent Document 1] Nishizawa et al., “Open whitebox architecture for smart integration of optical networking and data center technology”,Jocn-13-1-A78. [Summary of the Invention] [Problem to be Solved by the Invention]
[0005] A user logged in via the management port of the transceiver accommodation device may perform actions contrary to the telecommunications carrier's intentions by controlling the transceiver accommodation device. Actions contrary to the telecommunications carrier's intentions include, for example, changing or reading predetermined settings (related settings) of the transceiver accommodation device installed at a user's home or other location, or the transceivers it accommodates, which should not be changed for service purposes, or rewriting (replacing or adding) software that should not be changed for service purposes.
[0006] Thus, there is a problem in that if actions are performed contrary to the intentions of the telecommunications carrier, it is impossible to mitigate the impact on service provision.
[0007] In view of the above circumstances, the present invention aims to provide a communication system, configuration method, and program that can suppress the impact of operations contrary to the intentions of the telecommunications carrier on the provision of services. [Means for solving the problem]
[0008] One aspect of the present invention is a communication system comprising: a receiving control unit that constructs a path for control signals from a control device located in the communication network before communication conduction of the main signal between the communication network and the main signal transmitting / receiving unit is permitted; and a login control unit that enables login from the control device, disables login from a user-side control terminal that can change the related settings of the main signal transmitting / receiving unit, permits communication conduction if the disablement of login from the user-side control terminal is maintained, and disables login from the user-side control terminal again if the disablement of login from the user-side control terminal is not maintained.
[0009] One aspect of the present invention is a setting method performed by a communication system, comprising the steps of: constructing a path for control signals from a control device located in the communication network before allowing communication of main signals between the communication network and the main signal transmitting / receiving unit; enabling login from the control device, disabling login from a user-side control terminal capable of changing the associated settings of the main signal transmitting / receiving unit, allowing communication if the disabling of login from the user-side control terminal is maintained, and disabling login from the user-side control terminal again if the disabling of login from the user-side control terminal is not maintained.
[0010] One aspect of the present invention is a program for causing a computer to execute the following steps: construct a path for control signals from a control device located in the communication network before communication of the main signal between the communication network and the main signal transmitting / receiving unit is permitted; enable login from the control device, disable login from a user-side control terminal that can change the associated settings of the main signal transmitting / receiving unit, permit communication if the disablement of login from the user-side control terminal is maintained, and disable login from the user-side control terminal again if the disablement of login from the user-side control terminal is not maintained. [Effects of the Invention]
[0011] This invention makes it possible to suppress the impact on service provision caused by operations contrary to the intentions of telecommunications carriers. [Brief explanation of the drawing]
[0012] [Figure 1] This figure shows an example of the configuration of the communication system in the first embodiment. [Figure 2] This is a flowchart showing an example of the operation of the communication system in the first embodiment. [Figure 3] This figure shows an example of the configuration of the communication system in the second embodiment. [Figure 4] This is a flowchart showing an example of the operation of the communication system in the second embodiment. [Figure 5] This figure shows an example of the configuration of a communication system in the third embodiment. [Figure 6] This is a sequence diagram showing an example of the operation of the communication system in the third embodiment. [Figure 7] This figure shows examples of the hardware configuration of the communication system in each embodiment. [Modes for carrying out the invention]
[0013] Embodiments of the present invention will be described in detail with reference to the drawings. (First Embodiment) Figure 1 shows an example configuration of the communication system 1 in the first embodiment. The communication system 1 comprises a transceiver accommodation device 10 and a control device 20. The communication system 1 is, for example, an optical transmission system in an all-photonic network (APN). The transceiver accommodation device 10 is, for example, located at the user's home. The transceiver accommodation device 10 is, for example, a white-box transponder. The control device 20 is, for example, located in the communication network 2.
[0014] A user device 40 is connected to the transceiver housing device 10. Furthermore, a user-side control terminal 30 may be connected to a management port such as a serial bus in order to control the transceiver housing device 10. The possibility of connection is not limited to a serial bus. The transceiver housing device 10 comprises a control signal transmission / reception unit 11 (control signal transceiver), a main signal transmission / reception unit 12 (main signal transceiver), a switch 13, a control unit 14, and a main signal transmission / reception unit 15. The control unit 14 comprises a reception control unit 141 and a login control unit 142 (detection unit).
[0015] The receiving control unit 141 constructs control signal paths SR between the control device 20 and the control unit 14, between the control unit 14 and the main signal transmitting / receiving unit 12, and between the login control unit 142 within the control unit 14 and the main signal transmitting / receiving unit 12.
[0016] Note that, if the space between the control unit 14 and the main signal transmitting / receiving unit 12 is a secure environment, the reception control unit 141 does not need to establish the control signal path SR on the path indicated by the broken line between the main signal transmitting / receiving unit 12 shown in FIG. 1 and the login control unit 142 in the control unit 14. Here, the secure environment between the control unit 14 and the main signal transmitting / receiving unit 12 refers to an environment where at least the exchange between the control unit 14 and the main signal transmitting / receiving unit 12 is not intercepted, and data is not falsified.
[0017] Note that the reception control unit 141 and the login control unit 142 may be arranged in the control signal transmitting / receiving unit 11 or the main signal transmitting / receiving unit 12. In this case, processing can be completed within the control signal transmitting / receiving unit 11 or the main signal transmitting / receiving unit 12 without intervention of the software of the transceiver accommodation device 10. Therefore, there are fewer loopholes in handling actions that contradict the intention of a telecommunications carrier, and it is possible to speed up handling of actions that contradict the intention of a telecommunications carrier (e.g., an authenticated control device).
[0018] [Control from Authenticated Control Device] Here, the control from an authenticated control device includes, for example, any of the following controls from an authenticated control device. · Main signal block release (main signal conduction) · Main signal blocking (main signal non-conduction) · Power supply stop (power supply cutoff) or power supply (power supply permission) for functional units or devices related to main signals · Setting values related to the main signal or the quality of the main signal, such as the wavelength (optical frequency), wavelength width (frequency width), polarization, multi-level modulation order, or transmission scheme of the main signal · It represents control related to setting or changing setting values that affect the quality of the target main signal itself, or other main signals that share channels or the like therewith or use adjacent channels, such as setting values related to the main signal or the quality of the main signal including the wavelength (optical frequency), wavelength width (frequency width), polarization, multi-level modulation order, or transmission scheme of the main signal.
[0019] If the login control unit 142 is located within the transceiver accommodation device 10, the transceiver accommodation device 10 can respond more quickly to the issue of enabling or disabling local user logins. If the receiving control unit 141 is located within the transceiver housing device 10, the transceiver housing device 10 can respond more quickly to the activation or deactivation of communication with the control device 20 on the communication network 2 side. If the login control unit 142 is located within the transceiver accommodation device 10, the communication network 2 can respond more quickly to the validation or invalidation of local user logins on the communication network 2 side.
[0020] The transceiver accommodation device 10 functions by having software (applications) installed (implemented) on, for example, a white-box switch. The transceiver accommodation device 10 performs optical communication with the communication network 2 (for example, the control device 20). The software executed on the control unit 14 includes, for example, the NOS (Network Operating System) and device software (for example, Goldstone) of a typical white-box switch, as well as software such as a login restriction function.
[0021] In the following description, the first, second, and third embodiments will be described using as an example a configuration in which the NOS and device software for the white box switch are installed on the white box switch. In the fourth embodiment, a configuration in which Goldstone is installed on the white box switch will be described using as an example.
[0022] The control device 20 is, for example, a photonic gateway. The control device 20 may also be, for example, a controller for a photonic gateway. The control device 20 controls predetermined settings (related settings) of the main signal transmitting / receiving unit 12 provided in the transceiver accommodation device 10 that should not be changed for service purposes (for example, the setting of the wavelength of the main signal optical signal). For example, the control device 20 controls the settings of the main signal transmitting / receiving unit 12 by transmitting a control signal to the transceiver accommodation device 10. Furthermore, the controlled settings may be confirmed by receiving the response. Examples of control contents for the settings of the main signal transmitting / receiving unit 12 include starting, stopping or restarting the main signal transmitting / receiving unit 12, setting, changing and deleting predetermined parameters, and starting or stopping the transmission of the main signal.
[0023] The user-side control terminal 30 is, for example, an information processing device (for example, a personal computer). The user-side control terminal 30 is operated, for example, by a user at the user's home where the transceiver housing device 10 is installed. A user who logs in to the transceiver housing device 10 from the user-side control terminal 30, using, for example, the local account of the transceiver housing device 10, can change predetermined related settings of the main signal transmitting / receiving unit 12 provided in the transceiver housing device 10, provided the local account is valid. The user-side control terminal 30 cannot change predetermined related settings of the transceiver housing device 10 and the main signal transmitting / receiving unit 12 provided therein if the account used by the user for the transceiver housing device 10, such as the local account, is invalid.
[0024] The user-side control terminal 30 operated by the user may perform actions that change the settings of the main signal transmitting / receiving unit 12, which may be contrary to the intentions of the telecommunications carrier (for example, changing and reading related settings of the main signal transmitting / receiving unit 12 (transceiver), and rewriting (replacing and adding) related software).
[0025] The user device 40 communicates (sends and receives) main signals with the opposing device (not shown) via the communication network 2 and the transceiver housing device 10. The user device 40 is, for example, Customer Premises Equipment (CPE). The user device 40 is connected to the main signal transmission / reception unit 15 in the transceiver housing device 10, which communicates (sends and receives) main signals with the user side.
[0026] Next, we will describe the specific configuration of the transceiver housing device 10. The control signal transmitting / receiving unit 11 is a transceiver for control signals. The control signal transmitting / receiving unit 11 may communicate (transmit and receive) control signals with the control device 20 in the communication network 2 using optical signals. The signals are not limited to optical signals. Communication may also be conducted via another communication network (not shown) instead of through the communication network 2. The connection is not limited to the communication network 2, the control signal transmitting / receiving unit 11, and the switch 13. The control signal transmitting / receiving unit 11 may be connected from the management port of the transceiver housing device 10 via a dongle or the like connected to another communication network (not shown). The control signals transmitted from the control device 20 include information for instructing a change in the settings of the transceiver housing device 10.
[0027] The control signals transmitted and received between the control signal transmission / reception unit 11 and the control device 20 in the communication network may be electrical signals or optical signals. When the control signal is wavelength-division multiplexed with the main signal, the control signal is an optical signal.
[0028] The control signals transmitted from the control device 20 include information that instructs predetermined parameters of the main signal transmission / reception unit 12 of the transceiver housing device 10. The predetermined parameters of the main signal transmitting / receiving unit 12 include, for example, light emission or extinction (e.g., tx-dis false / true), light intensity, wavelength (e.g., wavelength grid (100-GHz|50-GHz|33-GHz|25-GHz|12-5-GHz|6-25-GHz etc.)), light frequency, channel number, etc.). The predetermined parameters of the main signal transmitting / receiving unit 12 include the transmission format (e.g., bpsk|dp-bpsk|qpsk|dp-qpsk|8-qam|dp-8-qam|16-qam|dp-16-qam|32-qam|dp-32-qam|64-qam|dp-64-qam etc.), line rate (e.g., 100g|200g|300g|400g etc.), and forward error correction (FEC). The system may include information such as the type of correspondence (e.g., sc (Staircase) - fec | c (Concatenated) fec | o (Open) fec, etc.).
[0029] The control signal transmitting / receiving unit 11 converts the received control signal into an electrical signal and outputs the electrical signal to the switch 13 when the control signal is an optical signal. Figure 1 illustrates a control signal transmitting / receiving unit 11 that exchanges signals (e.g., optical signals) with the control device 20 in the communication network 2 and connects to the receiving control unit 141 via the switch 13. If the management port of the transceiver housing device 10 is a serial port, USB (Universal Serial Bus), or Ethernet® interface, the control signal transmitting / receiving unit 11 may be a replaceable transceiver or dongle that connects to the serial port, USB, or Ethernet® interface and can communicate with the control device 20 on the communication network 2 side.
[0030] The main signal transmitting / receiving unit 12 is a transceiver for the main signal. The main signal transmitting / receiving unit 12 is usually a replaceable transceiver. The main signal transmitting / receiving unit 12 communicates (transmits and receives) the main signal to the communication network 2 using optical signals or the like. The main signal transmitting / receiving unit 12 may also communicate (transmits and receives) the main signal or control signal to the control device 20 in the communication network 2 using optical signals.
[0031] If the main signal transmitting / receiving unit 12 is an analog-coherent optical system (ACO) transceiver, a digital signal processing unit (not shown) may be provided between the control signal transmitting / receiving unit 11 and the switch 13, and between the main signal transmitting / receiving unit 12 and the switch 13. This digital signal processing unit (not shown) performs signal processing on the electrical signals output from the control signal transmitting / receiving unit 11 or the main signal transmitting / receiving unit 12, such as error correction including OTN (Optical Transport Network) framing and FEC processing.
[0032] If the main signal transmitting / receiving unit 12 is a digital coherent optical system (DCO) transceiver, the main signal transmitting / receiving unit 12 may also include a digital signal processing unit. The digital signal processing unit of the main signal transmitting / receiving unit 12 performs, for example, OTN framing, FEC processing, modulation / demodulation processing, and optical degradation correction.
[0033] In the following description, the signal from the control signal transmission / reception unit 11 and the signal from the main signal transmission / reception unit 12 are multiplexed, for example, by wavelength division multiplexing. The multiplexed signals are transmitted, for example, over the same core wire (for example, a transmission line such as an optical fiber).
[0034] The main signal transmitting / receiving unit 15 communicates (transmits and receives) the main signal with the user device 40. The main signal transmitting / receiving unit 15 is a transceiver or a NIC (Network Interface Card).
[0035] Switch 13 connects the control signal transmission / reception unit 11 and the control unit 14. Furthermore, when the control signal is communicated via the main signal, the frame transmitting it, or AMCC, switch 13 connects the main signal transmission / reception unit 12 and the control unit 14. For example, switch 13 conducts the main signal by connecting the main signal transmission / reception unit 12 and the main signal transmission / reception unit 15. For example, switch 13 forwards the control signal transmitted from the control device 20 to the control unit 14 by connecting the control signal transmission / reception unit 11 and the control unit 14. Thus, switch 13 also functions as an adapter for passing the control signal transmitted from the control device 20 to the control unit 14.
[0036] The control unit 14 controls each functional part of the transceiver housing device 10. The control unit 14 performs control at least with respect to the main signal transmission / reception unit 12. The control unit 14 is composed of one or more processors such as a CPU (Central Processing Unit) and one or more memories. The control unit 14 realizes the functions of the reception control unit 141 and the login control unit 142 by having one or more processors execute a program. Here, all or part of the functions of the control unit 14 may be realized using hardware such as an ASIC (Application Specific Integrated Circuit), a PLD (Programmable Logic Device), or an FPGA (Field Programmable Gate Array). The above program may be recorded on a computer-readable recording medium. Computer-readable recording media include, for example, portable media such as flexible disks, magneto-optical disks, ROMs (Read Only Memory), CD-ROMs (Compact Disc Read Only Memory), semiconductor storage devices (e.g., SSDs: Solid State Drives), and storage devices such as hard disks and semiconductor storage devices built into computer systems. The above program may be transmitted via a telecommunications line.
[0037] It is desirable for the control unit 14 to establish a control signal path SR with the control device 20 via the control signal transmission / reception unit 11 and switch 13 before allowing communication of the main signal between the user device 40, the main signal transmission / reception unit 12, and the communication network 2. Furthermore, it is even more desirable that the control unit 14 not only establishes the control signal path SR, but also allows it only after it has been configured to receive control only from the receiving control unit 141 with respect to predetermined settings. This is because if permission is granted before either of these is completed, there is a risk that the main signal will be transmitted unintentionally. In this way, the control unit 14 allows communication of the main signal only after login is restricted. However, this does not apply if it has been blocked in advance by the blocking unit described later. The control signal path SR allows changes to the settings related to the main signal transmission / reception unit 12, or access to predetermined related settings that should be restricted from being read. Here, it is desirable that the control signal path SR is a highly secure communication path, but it is sufficient if it is a control signal path that allows access to related settings. The security of the control signal path SR does not necessarily have to be high. A highly secure communication path is, for example, a virtual private network (VPN). This makes it possible to keep the contents of control communications confidential from the user.
[0038] The control signal path SR is preferably a highly secure communication path such as a VPN, but it does not necessarily have to be a highly secure communication path, as long as it is a control signal path that allows access to related settings and prevents access from unauthenticated devices (e.g., user-side control terminal 30) to the functional units (e.g., the receiving control unit 141 and the login control unit 142) of the transceiver accommodation device 10. By using such a control signal path SR, it is possible to prevent malicious users from intercepting or tampering with communications between functional units.
[0039] Furthermore, the receiving control unit 141 notifies or responds to the control device 20 of the setting status (completion of setting execution or setting value).
[0040] The receiving control unit 141 may communicate related settings with the main signal transmitting / receiving unit 12 using a predetermined client signal, a GCC channel for control signals, or AMCC (Auxiliary Management and Control Channel), etc. In this case, the receiving control unit 141 may construct a control signal path SR between the main signal transmitting / receiving unit 12 and the control device 20. When a control signal path SR is constructed between the main signal transmitting / receiving unit 12 and the control device 20, the receiving control unit 141 constructs the control signal path SR after communication conduction between the transceiver housing device 10 and the opposing device (not shown) is permitted. If the control signal is not time-division multiplexed, for example, in a form where the control signal is frame-multiplexed with the user signal, or in a form such as a frame carrying the user signal (e.g., GCC (Generic Communications Channel)), the user signal may be discarded by the switch 13 or by a predetermined functional unit other than the switch 13.
[0041] The login control unit 142 controls logins, but does not necessarily require parameter settings. The login control unit 142 enables logins from the control device 20 (administrator privileges, etc.) under conditions that are hidden from the user (local) via the user-side control terminal 30. In addition, the login control unit 142 disables logins from the user-side control terminal 30, which can change and read the related settings of the main signal transmission / reception unit 12 using a local account, etc., under conditions that are hidden from the user-side control terminal 30.
[0042] The receiving control unit 141 sets the parameters of the main signal transmitting / receiving unit 12 according to control signals (instructions) from sources other than the user-side control terminal 30. For example, the receiving control unit 141 performs the settings of the main signal transmitting / receiving unit 12 according to control signals (instructions) from the control device 20 only. Here, the login control unit 142 performs changes to and reading of predetermined related settings other than the login settings of the main signal transmitting / receiving unit 12 based solely on control signals from the control device 20.
[0043] In the first embodiment, the login control unit 142 of the control unit 14 may detect (determine) whether or not the invalidation of login from the user-side control terminal 30 is maintained (whether or not the login restriction is maintained) based, for example, on output to standard output and logs.
[0044] The above primarily describes the invalidation of account IDs and passwords, but access restrictions that make it difficult for users to log in would, for example, block a signal path that can control a predetermined state of the main signal transmission / reception unit 12. The login control unit 142 may not provide the user-side control terminal 30 with an address for identifying such a signal path. The login control unit 142 may not provide the user with an address and may not respond to user inquiries (e.g., "ping") that attempt to identify the address. The login control unit 142 may detect if a dictionary attack has occurred. If the receiving control unit 141 does not exchange control information at the management port of the transceiver accommodation device 10, the login control unit 142 may not allow access from specific ports (e.g., serial ports) such as the management port of the transceiver accommodation device 10. If the login control unit 142 does not use teletype (tty) as a control signal, it may not allow user sessions (access) from tty.
[0045] Next, an example of the operation of communication system 1 will be described. First, communication system 1 disables the login from the user-side control terminal 30 and remotely enables it from the communication network. Next, an example will be shown of performing the disabling and enabling again when the disabling or enabling that was performed becomes impossible. Figure 2 is a flowchart showing an example of the operation of the communication system 1 in the first embodiment. The receiving control unit 141 constructs a control signal path SR of the control signal from the control device 20 before communication conduction of the main signal between the main signal transmitting / receiving unit 12 and the communication network 2 is permitted (step S001).
[0046] The login control unit 142 enables login from the control device 20. The login control unit 142 disables login from the user-side control terminal 30, which is capable of changing and reading the related settings of the main signal transmission / reception unit 12 (step S002). Disabling can involve disabling and deleting the ID information and changing the password. When disabling, it is preferable to disconnect communication if there are any remaining login sessions that are to be disabled.
[0047] The login control unit 142 performs changes to and reads predetermined related settings of the main signal transmitting / receiving unit 12 based solely on control signals (step S003). The login control unit 142 determines whether or not the login from the user-side control terminal 30 is disabled (step S004). If the login from the user-side control terminal 30 is disabled (step S004: YES), the login control unit 142 permits or continues to permit communication between the main signal transmitting / receiving unit 12 and the communication network 2 (step S005). The login control unit 142 returns to step S004.
[0048] The transceiver accommodation device 10 raises an alarm indicating an abnormality, but the control device 20 on the communication network side may determine whether the system is valid or invalid based on the inability to communicate with the transceiver accommodation device 10 normally, or on the occurrence of abnormal traffic inflow into the communication network. Abnormal traffic is traffic that does not conform to the value of a predetermined related setting. For example, if the value of the related setting is wavelength, it would be a signal of an inappropriate wavelength; if it is intensity, it would be a signal of inappropriately high or low intensity. Furthermore, the control device 20 may receive a control signal including setting instructions transmitted from the control device 20, or retain setting information obtained through snooping, etc., and determine whether the system is valid or invalid based on the inability to set or confirm the settings using the retained setting information, notification or detection of a setting abnormality, the setting being rewritten from a route other than the communication network route (for example, a route other than the control signal route SR), or the occurrence of a phenomenon that attempts to rewrite the setting.
[0049] If the login from the user-side control terminal 30 is not disabled (step S004: NO), the login control unit 142 disables login from the user-side control terminal 30 again (step S006). The login control unit 142 returns to step S004.
[0050] Furthermore, the step of changing the login may be added before or after the device authentication process of the user-side control terminal 30. Alternatively, the step of changing the login may be added as part of the device authentication process.
[0051] As described above, the receiving control unit 141 constructs a control signal path SR of control signals from the control device 20 located in the communication network 2 before blocking the main signal between the main signal transmitting / receiving unit 12 and the communication network 2 to allow communication. The control signal path SR is constructed, for example, between the control device 20 and the receiving control unit 141.
[0052] The login control unit 142 enables login from the control device 20. The login control unit 142 disables login from the user-side control terminal 30, which is capable of changing and reading the related settings of the main signal transmitting / receiving unit 12. If the login from the user-side control terminal 30 remains disabled, the login control unit 142 releases the blockage between the communication network 2 and the main signal transmitting / receiving unit 12, allowing communication of the main signal. If the login from the user-side control terminal 30 is no longer disabled, the login control unit 142 again disables or blocks login from the user-side control terminal 30, which is capable of changing and reading the related settings of the main signal transmitting / receiving unit 12.
[0053] This makes it possible to suppress the impact on service provision caused by actions contrary to the telecommunications carrier's intentions (changes that users should not perform). Here, the scale of modification to the transceiver accommodation device 10 is small.
[0054] Except for operations contrary to the intentions of the telecommunications carrier, user control may be permitted. Compared to the case where the login control unit 142 etc. is implemented in software on the control signal transmission / reception unit 11 or the main signal transmission / reception unit 12, implementation on the control unit 14 allows for more advanced control due to the abundance of computing resources. Furthermore, switching of control is easy, and faster response is possible compared to the third embodiment (described later). In addition, responses can be handled without frequently communicating with the communication network 2.
[0055] (Modified version of the first embodiment) The login control unit 142 may erase existing sessions in the transceiver accommodation device 10 and then change the login from the user-side control terminal 30 to a value unknown to the user-side control terminal 30. Here, the reception control unit 141 and the login control unit 142 retain the session that went through the highly secure control signal path SR, among the sessions that went through the highly secure control signal path SR. This makes it possible to prevent the user-side control terminal 30 from obtaining the changed login (a value unknown to the user-side control terminal 30).
[0056] (Second Embodiment) In the second embodiment, the difference from the first embodiment is that the control unit includes a shut-off unit.
[0057] Figure 3 shows an example configuration of the communication system 1a in the second embodiment. The communication system 1a comprises a transceiver accommodation device 10a and a control device 20a. The communication system 1a is, for example, an optical transmission system in an all-photonic network (APN). The transceiver accommodation device 10a is, for example, located at the user's home. The transceiver accommodation device 10a is, for example, a white-box transponder. The control device 20a is, for example, located in the communication network 2.
[0058] A user device 40 is connected to the transceiver housing device 10a. Furthermore, a user-side control terminal 30 may be connected to a management port such as a serial bus in order to control the transceiver housing device 10. The possibility of connection is not limited to a serial bus. The transceiver housing device 10a comprises a control signal transmission / reception unit 11 (control signal transceiver), a main signal transmission / reception unit 12 (main signal transceiver), a switch 13, a control unit 14a, and a main signal transmission / reception unit 15. The control unit 14a comprises a reception control unit 141, a login control unit 142 (detection unit), and a blockage unit 143 (blockage unit).
[0059] The receiving control unit 141 constructs control signal paths SR between the control device 20a and the control unit 14a, between the control unit 14a and the main signal transmitting / receiving unit 12, between the login control unit 142 and the blockage unit 143 within the control unit 14a, and between the blockage unit 143 within the control unit 14a and the main signal transmitting / receiving unit 12. However, if the environment within the control unit 14a is secure, the receiving control unit 141 does not need to construct a control signal path SR in the path shown by the dashed line between the login control unit 142 and the blockage unit 143 within the control unit 14a.
[0060] Furthermore, if the environment between the control unit 14a and the main signal transmitting / receiving unit 12 is secure, the receiving control unit 141 does not need to construct a control signal path SR in the path shown by the dashed line between the main signal transmitting / receiving unit 12 and the blocking unit 143 in the control unit 14a as shown in Figure 3. Here, a secure environment between the control unit 14a and the main signal transmitting / receiving unit 12 means an environment in which communication between the control unit 14a and the main signal transmitting / receiving unit 12 is not intercepted or data is not tampered with.
[0061] Furthermore, the receiving control unit 141, the login control unit 142, and the blocking unit 143 may be located in the control signal transmission / reception unit 11 or the main signal transmission / reception unit 12. In this case, processing can be handled closed off by the control signal transmission / reception unit 11 or the main signal transmission / reception unit 12 without going through the software of the transceiver housing device 10, thus reducing loopholes in dealing with operations contrary to the telecommunications carrier's intentions and enabling faster responses to such operations.
[0062] If the login control unit 142 is located within the transceiver housing device 10a, the transceiver housing device 10a can respond more quickly to the issue of enabling or disabling local user logins. If the receiving control unit 141 is located within the transceiver housing device 10a, the transceiver housing device 10a can respond more quickly to the activation or deactivation of communication with the control device 20 on the communication network 2 side. If the blocking unit 143 and the login control unit 142 are located within the transceiver housing device 10a, the transceiver housing device 10a can respond more quickly to the issue of enabling or disabling local user logins. If the blocking unit 143 and the receiving control unit 141 are located within the transceiver housing device 10, the transceiver housing device 10a can respond more quickly to the activation or deactivation of communication with the control device 20 on the communication network 2 side. If the login control unit 142 is located within the transceiver accommodation device 10a, the communication network 2 can respond more quickly to the validation or invalidation of local user logins on the communication network 2 side. If the blocking unit 143 and the login control unit 142 are located within the transceiver housing device 10a, the communication network 2 can respond more quickly to the validation or invalidation of local user logins on the communication network 2 side.
[0063] The transceiver accommodation device 10a functions by having software (applications) installed (implemented) on, for example, a white-box switch. The transceiver accommodation device 10a performs optical communication with the communication network 2 (for example, the control device 20a). The software executed on the control unit 14a includes, for example, the NOS and device software (for example, Goldstone) of a typical white-box switch, and software such as a login restriction function.
[0064] The control device 20a is, for example, a photonic gateway. The control device 20a may also be, for example, a controller for a photonic gateway. The control device 20a controls predetermined settings (related settings) (for example, the wavelength of the optical signal of the main signal) of the main signal transmitting / receiving unit 12 provided in the transceiver accommodation device 10a that should not be changed for service purposes. For example, the control device 20a controls the settings of the main signal transmitting / receiving unit 12 by transmitting a control signal to the transceiver accommodation device 10a. Furthermore, the controlled settings may be confirmed by receiving the response. Examples of control contents for the settings of the main signal transmitting / receiving unit 12 include starting, stopping or restarting the main signal transmitting / receiving unit 12, setting, changing and deleting predetermined parameters, starting or stopping the transmission of the main signal, and blocking. Interruption of the user signal (main signal) includes, for example, stopping transmission by the main signal transmitting / receiving unit 12, reducing output strength, stopping, restarting or powering off the main signal transmitting / receiving unit 12, interrupting the main signal conduction inside the switch 13, powering off the transceiver housing device 10a, and interruption on the communication network side.
[0065] The user-side control terminal 30 is, for example, an information processing device (for example, a personal computer). The user-side control terminal 30 is operated, for example, by a user at the user's home where the transceiver housing device 10a is installed. A user who logs in to the transceiver housing device 10a from the user-side control terminal 30, using, for example, the local account of the transceiver housing device 10a, can change predetermined related settings of the main signal transmitting / receiving unit 12 provided in the transceiver housing device 10a, provided the local account is valid. The user-side control terminal 30 cannot change predetermined related settings of the transceiver housing device 10a and the main signal transmitting / receiving unit 12 provided therein if the account used by the user for the transceiver housing device 10a, such as the local account, is invalid.
[0066] The user-side control terminal 30 operated by the user may perform actions that change the settings of the main signal transmitting / receiving unit 12, which may be contrary to the intentions of the telecommunications carrier (for example, changing and reading related settings of the main signal transmitting / receiving unit 12 (transceiver), and rewriting (replacing and adding) related software).
[0067] The user device 40 communicates (sends and receives) main signals with the opposing device (not shown) via the communication network 2 and the transceiver housing device 10a. The user device 40 is, for example, customer premises equipment (CPE). The user device 40 is connected to the main signal transmission / reception unit 15 in the transceiver housing device 10a, which communicates (sends and receives) main signals with the user side.
[0068] Next, we will describe the specific configuration of the transceiver housing device 10a. The control signal transmitting / receiving unit 11 is a transceiver for control signals. The control signal transmitting / receiving unit 11 may communicate (transmit and receive) control signals with the control device 20a in the communication network 2 using optical signals. The signals are not limited to optical signals. Communication may also be conducted via another communication network (not shown) instead of through the communication network 2. The connection is not limited to the communication network 2, the control signal transmitting / receiving unit 11, and the switch 13. The control signal transmitting / receiving unit 11 may be connected from the management port of the transceiver housing device 10a via a dongle or the like connected to another communication network (not shown). The control signals transmitted from the control device 20a include information for instructing a change in the settings of the transceiver housing device 10a.
[0069] The control signals transmitted and received between the control signal transmission / reception unit 11 and the control device 20a in the communication network may be electrical signals or optical signals. When the control signal is wavelength-division multiplexed with the main signal, the control signal is an optical signal.
[0070] The control signals transmitted from the control device 20a include information that specifies predetermined parameters for the main signal transmitting / receiving unit 12 of the transceiver housing device 10a. These predetermined parameters for the main signal transmitting / receiving unit 12 include, for example, (light emission or extinction, light intensity, wavelength). The predetermined parameters for the main signal transmitting / receiving unit 12 may also include information such as transmission format and line rate.
[0071] The control signal transmitting / receiving unit 11 converts the received control signal into an electrical signal and outputs the electrical signal to the switch 13 when the control signal is an optical signal. Figure 3 illustrates a control signal transmitting / receiving unit 11 that exchanges signals (e.g., optical signals) with the control device 20a in the communication network 2 and connects to the receiving control unit 141 via the switch 13. If the management port of the transceiver housing device 10a is a serial port, USB, or Ethernet® interface, the control signal transmitting / receiving unit 11 may be a replaceable transceiver or dongle that connects to the serial port, USB, or Ethernet® interface and can communicate with the control device 20a on the communication network 2 side.
[0072] The main signal transmitting / receiving unit 12 is a transceiver for the main signal. The main signal transmitting / receiving unit 12 is usually a replaceable transceiver. The main signal transmitting / receiving unit 12 communicates (transmits and receives) the main signal to the communication network 2 using optical signals or the like. The main signal transmitting / receiving unit 12 may also communicate (transmits and receives) the main signal or control signal to the control device 20a in the communication network 2 using optical signals.
[0073] If the main signal transmitting / receiving unit 12 is an analog coherent optical system (ACO) transceiver, a digital signal processing unit (not shown) may be provided between the control signal transmitting / receiving unit 11 and the switch 13, and between the main signal transmitting / receiving unit 12 and the switch 13. This digital signal processing unit (not shown) performs signal processing on the electrical signals output from the control signal transmitting / receiving unit 11 or the main signal transmitting / receiving unit 12, such as error correction including OTN framing and FEC processing.
[0074] If the main signal transmitting / receiving unit 12 is a digital coherent optical system (DCO) transceiver, the main signal transmitting / receiving unit 12 may also include a digital signal processing unit. The digital signal processing unit of the main signal transmitting / receiving unit 12 performs, for example, optical network framing, forward error correction processing, modulation / demodulation processing, and optical degradation correction.
[0075] The main signal transmitting / receiving unit 15 communicates (transmits and receives) the main signal with the user device 40. The main signal transmitting / receiving unit 15 is a transceiver or a NIC.
[0076] Switch 13 connects the control signal transmission / reception unit 11 and the control unit 14a. Furthermore, when communicating control signals via the main signal, the frame transmitting it, or AMCC, switch 13 connects the main signal transmission / reception unit 12 and the control unit 14a. For example, switch 13 conducts the main signal by connecting the main signal transmission / reception unit 12 and the main signal transmission / reception unit 15. Similarly, switch 13 forwards the control signal transmitted from the control device 20a to the control unit 14a by connecting the control signal transmission / reception unit 11 and the control unit 14a. Thus, switch 13 also functions as an adapter for passing control signals transmitted from the control device 20a to the control unit 14a.
[0077] The control unit 14a controls each functional part of the transceiver housing device 10a. The control unit 14a performs control of at least the main signal transmission / reception unit 12. The control unit 14a is configured using one or more processors such as a CPU and one or more memories. The control unit 14a realizes the functions of the reception control unit 141, the login control unit 142, and the blockage unit 143 by having one or more processors execute a program. Here, all or part of the functions of the control unit 14a may be realized using hardware such as an ASIC, PLD, or FPGA. The above program may be recorded on a computer-readable recording medium. Computer-readable recording media include, for example, portable media such as flexible disks, magneto-optical disks, ROMs, CD-ROMs, and semiconductor storage devices (e.g., SSDs), and storage devices such as hard disks and semiconductor storage devices built into computer systems. The above program may be transmitted via a telecommunications line.
[0078] It is desirable for the control unit 14a to establish a control signal path SR with the control device 20a via the control signal transmission / reception unit 11 and the switch 13 before allowing communication of the main signal between the user device 40, the main signal transmission / reception unit 12, and the communication network 2. Furthermore, it is even more desirable to allow communication only after the control unit 14a has been configured to receive control only from the receiving control unit 141 with respect to predetermined settings. This is because if permission is granted before either of these is completed, there is a risk that the main signal will be transmitted unintentionally. In this way, the control unit 14a allows communication of the main signal only after login is restricted. However, this does not apply if the connection has been blocked in advance by the blocking unit described later. The control signal path SR allows changes to the settings related to the main signal transmission / reception unit 12, or access to predetermined related settings that should be restricted from being read. Here, it is desirable that the control signal path SR be a highly secure communication path, but it is sufficient if it is a control signal path that allows access to related settings. The security of the control signal path SR does not necessarily have to be high. A highly secure communication path is, for example, a virtual private network (VPN). This makes it possible to keep the contents of control communications confidential from the user.
[0079] Furthermore, the receiving control unit 141 notifies or responds to the control device 20a of the setting status (completion of setting execution or setting value).
[0080] The receiving control unit 141 may communicate related settings with the main signal transmitting / receiving unit 12 using a predetermined client signal, a GCC channel for control signals, or AMCC, etc. In this case, the receiving control unit 141 may construct a control signal path SR between the main signal transmitting / receiving unit 12 and the control device 20a. When a control signal path SR is constructed between the main signal transmitting / receiving unit 12 and the control device 20a, the receiving control unit 141 constructs the control signal path SR after communication conduction between the transceiver housing device 10a and the opposing device (not shown) is permitted. If the control signal is not time-division multiplexed, for example, in a form in which the control signal is frame-multiplexed with the user signal, or in a form such as a frame carrying the user signal (e.g., GCC), the user signal may be discarded by the switch 13 or by a predetermined functional unit other than the switch 13.
[0081] The login control unit 142 controls logins, but does not necessarily require parameter settings. The login control unit 142 enables logins from the control device 20a (administrator privileges, etc.) under conditions that are hidden from the user (local) via the user-side control terminal 30. In addition, the login control unit 142 disables logins from the user-side control terminal 30, which can change and read the related settings of the main signal transmission / reception unit 12 using a local account, etc., under conditions that are hidden from the user-side control terminal 30.
[0082] In accordance with control signals (instructions) from sources other than the user-side control terminal 30, the receiving control unit 141 or the control device 20a sets the parameters of the main signal transmitting / receiving unit 12. For example, the login control unit 142 performs the settings of the main signal transmitting / receiving unit 12 solely in accordance with control signals (instructions) from the control device 20a. Here, the login control unit 142 performs changes to and reading of predetermined related settings other than the login settings of the main signal transmitting / receiving unit 12 based solely on control signals from the control device 20a.
[0083] In the second embodiment, the login control unit 142 of the control unit 14a detects (determines) whether or not the invalidation of login from the user-side control terminal 30 is maintained (whether or not the login restriction is maintained) based, for example, output to standard output and logs.
[0084] The login control unit 142 or the blocking unit 143 allows communication between the main signal transmitting / receiving unit 12 and the communication network 2 if the login from the user-side control terminal 30 remains disabled. The blocking unit 143 releases the blocking of communication between the main signal transmitting / receiving unit 12 and the communication network 2 if the login from the user-side control terminal 30 remains disabled.
[0085] If the login from the user-side control terminal 30 is not disabled, the blocking unit 143 blocks communication between the main signal transmitting / receiving unit 12 and the communication network 2. The login control unit 142 or the blocking unit 143 may revoke permission for communication between the main signal transmitting / receiving unit 12 and the communication network 2 if the login from the user-side control terminal 30 is not disabled.
[0086] The blocking unit 143 blocks the conduction between the main signal transmitting / receiving unit 12 and the control device 20a in the communication network 2. The blocking unit 143 may also block the connection if the transceiver accommodation device 10a raises an alarm indicating an abnormality, if the control device 20a on the communication network side is unable to communicate with the transceiver accommodation device 10a normally, or if there is an abnormal inflow of traffic into the communication network. Abnormal traffic is traffic that does not conform to the predetermined associated setting value. For example, if the associated setting value is wavelength, it is a signal of an inappropriate wavelength; if it is intensity, it is a signal of inappropriately high or low intensity. Furthermore, the blocking unit 143 may also block the connection if it receives a control signal including setting instructions transmitted from the control device 20a, or if it obtains setting information through snooping, etc., and if it is unable to set or confirm the settings, if it is notified or detected that there is a setting abnormality, if the settings are rewritten from a route other than the communication network route (for example, a route other than the control signal route SR), or if a phenomenon occurs that attempts to rewrite the settings. Furthermore, the blocking unit 143 may block if there is no notification or response regarding the setting, or if there is a setting failure or abnormality.
[0087] For example, the blocking unit 143 may reduce the optical output of the main signal transmitting / receiving unit 12 (transceiver) to a negligible level by writing to the registers of the main signal transmitting / receiving unit 12. The blocking unit 143 may turn off the transmission of optical signals with respect to input to hardware pins. The blocking unit 143 may cut off the power supply to the main signal transmitting / receiving unit 12 (transceiver). The blocking unit 143 may cut off the power supply to the transceiver housing device 10a. Signals may be blocked on the communication network 2 side. The blocking unit 143 may detect the main signal transmitting / receiving unit 12's inability to communicate and changes in its state based on the results of exchanging signals such as a "Keep Alive" signal or a "Health check" signal with the communication network 2 (photonic gateway). If a state is detected that does not meet the conditions for allowing communication continuity, the blocking unit 143 may cut off communication continuity using at least one of the photonic gateway's blocking function and changing the distribution settings of the photonic gateway's optical distribution unit. The blocking unit 143 may transmit a blocking instruction to the control device 20a in the communication network 2.
[0088] The above primarily describes the invalidation of account IDs and passwords, but access restrictions that make it difficult for users to log in would, for example, block a signal path that can control a predetermined state of the main signal transmission / reception unit 12. The login control unit 142 or the blocking unit 143 may not provide the user-side control terminal 30 with an address for identifying such a signal path. The login control unit 142 or the blocking unit 143 may not provide the address to the user and may not respond to user inquiries (e.g., "ping") that attempt to identify the address. The login control unit 142 or the blocking unit 143 may detect if a dictionary attack has occurred. The login control unit 142 or the blocking unit 143 may not allow access from specific ports (e.g., serial ports) such as the management port of the transceiver accommodation device 10 if the receiving control unit 141 does not exchange control information at the management port of the transceiver accommodation device 10a. The login control unit 142 or the blocking unit 143 may, if a teletype (tty) or the like is not used as a control signal, not allow user sessions (access) from a tty or the like.
[0089] Next, we will explain an example of the operation of the communication system 1a. Figure 4 is a flowchart showing an example of the operation of the communication system 1a in the second embodiment. The receiving control unit 141 constructs a control signal path SR of the control signal from the control device 20a before communication conduction of the main signal between the main signal transmitting / receiving unit 12 and the communication network 2 is permitted (step S101).
[0090] The login control unit 142 enables login from the control device 20a. The login control unit 142 disables login from the user-side control terminal 30, which is capable of changing and reading the related settings of the main signal transmission / reception unit 12 (step S102).
[0091] The login control unit 142 performs changes to and reads predetermined related settings of the main signal transmitting / receiving unit 12 based solely on control signals (step S103). The login control unit 142 determines whether or not the invalidation of login from the user-side control terminal 30 is maintained (step S104). If the invalidation of login from the user-side control terminal 30 is maintained (step S104: YES), the login control unit 142 or the blocking unit 143 allows communication between the main signal transmitting / receiving unit 12 and the communication network 2. The blocking unit 143 may release the blocking of communication between the main signal transmitting / receiving unit 12 and the communication network 2 (step S105). The login control unit 142 and the blocking unit 143 return to step S104.
[0092] Here, methods for interrupting the continuity of the transceiver housing device 10a include reducing the optical output of the main signal transmitting / receiving unit 12 to a negligible level (by writing to a register, etc.), turning off optical transmission (by inputting to a hard pin or writing to a corresponding register, etc.), stopping the main signal transmitting / receiving unit 12, restarting the main signal transmitting / receiving unit 12, cutting off the power to the main signal transmitting / receiving unit 12, interrupting the main signal continuity between the main signal transmitting / receiving unit 12 between the user device 40 and the control device 20, cutting off the power supply to the main signal transmitting / receiving unit 12, cutting off the power to the transceiver housing device 10a, and cutting off the signal on the communication network side.
[0093] If the login from the user-side control terminal 30 is not disabled (step S104: NO), the blocking unit 143 blocks communication. The login control unit 142 or the blocking unit 143 may revoke the permission for communication. The login control unit 142 may disable the login from the user-side control terminal 30 again (step S106). The login control unit 142 and the blocking unit 143 return to step S104.
[0094] Furthermore, the step of changing the login may be added before or after the device authentication process of the user-side control terminal 30. Alternatively, the step of changing the login may be added as part of the device authentication process.
[0095] As described above, the receiving control unit 141 constructs a control signal path SR of control signals from the control device 20a located in the communication network 2 before blocking the main signal between the main signal transmitting / receiving unit 12 and the communication network 2 to allow communication conduction. The control signal path SR is constructed, for example, between the control device 20a and the receiving control unit 141.
[0096] The login control unit 142 enables login from the control device 20a. The login control unit 142 disables login from the user-side control terminal 30, which can change and read the related settings of the main signal transmission / reception unit 12 using a local account. The login control unit 142 or the blocking unit 143 releases the blockage between the communication network 2 and the main signal transmission / reception unit 12 and allows communication of the main signal if the login from the user-side control terminal 30 is disabled. The blocking unit 143 may release the blockage of communication of the main signal between the communication network 2 and the main signal transmission / reception unit 12 if the login from the user-side control terminal 30 is disabled. The blocking unit 143 blocks communication of the main signal between the communication network 2 and the main signal transmission / reception unit 12 if the login from the user-side control terminal 30 is not disabled.
[0097] This makes it possible to suppress the impact on service provision of actions that are contrary to the telecommunications carrier's intentions (changes that users should not perform). Here, the scale of modification to the transceiver accommodation device 10a is small.
[0098] Except for operations contrary to the intentions of the telecommunications carrier, user control may be possible. Compared to the case where the blocking unit 143, etc., is implemented in software on the control signal transmission / reception unit 11 or the main signal transmission / reception unit 12, more computing resources are available, enabling more advanced control. In addition, control can be easily switched, and it is possible to respond faster compared to the third embodiment (described later). Furthermore, it is possible to respond without frequently communicating with the communication network 2.
[0099] (Modified version of the second embodiment) The login control unit 142 may erase existing sessions in the transceiver accommodation device 10a and then change the login from the user-side control terminal 30 to a value unknown to the user-side control terminal 30. Here, the reception control unit 141 and the login control unit 142 retain the control signal path SR, which is more secure than the session that passed through the control signal path SR. This makes it possible to prevent the user-side control terminal 30 from obtaining the changed login (a value unknown to the user-side control terminal 30).
[0100] (Third embodiment) In the third embodiment, the main difference from the second embodiment is that the control device located in the communication network 2 is equipped with a login control unit and a blocking unit. The third embodiment will be explained focusing on the differences from the second embodiment.
[0101] Figure 5 shows an example configuration of the communication system 1b in the third embodiment. The communication system 1b comprises a transceiver housing device 10b and a control device 20b. The transceiver housing device 10b is located, for example, at the user's home. The control device 20b is located, for example, in the communication network 2.
[0102] A user-side control terminal 30 may be connected to the transceiver housing device 10b, for example, via a serial bus. The transceiver housing device 10b comprises a control signal transmission / reception unit 11 (control signal transceiver), a main signal transmission / reception unit 12 (main signal transceiver), a switch 13, and a control unit 14b. The control unit 14b includes a reception control unit 141. The control device 20b located in the communication network 2 comprises a login control unit 142 (detection unit) and a blocking unit 143. The blocking unit 143 provided in the control device 20b and the transceiver housing device 10b may communicate via a control signal path SR.
[0103] In the third embodiment, the login control unit 142 of the control device 20b detects (determines) whether or not the invalidation of login from the user-side control terminal 30 is maintained, based on, for example, the communication result for confirming the status of the user-side control terminal 30 and the communication status detected by the control device 20b. The detected communication status is, for example, a state indicating whether or not the wavelength and intensity of the optical signal are the predetermined wavelength and intensity as set, or a state indicating whether or not the main signal transmitting and receiving unit 12 complies with the change instruction such as drift correction.
[0104] The blocking unit 143 allows communication between the main signal transmission / reception unit 12 and the communication network 2 if the login from the user-side control terminal 30 remains disabled.
[0105] The blocking unit 143 prohibits communication between the main signal transmitting / receiving unit 12 and the communication network 2 if the login from the user-side control terminal 30 is not disabled. The blocking unit 143 may also revoke permission for communication between the main signal transmitting / receiving unit 12 and the communication network 2 if the login from the user-side control terminal 30 is not disabled.
[0106] For example, the blocking unit 143 may reduce the optical output of the main signal transmitting / receiving unit 12 (transceiver) to a negligible level by writing to the registers of the main signal transmitting / receiving unit 12. The blocking unit 143 may turn off the transmission of optical signals with respect to input to hardware pins. The blocking unit 143 may cut off the power supply to the main signal transmitting / receiving unit 12 (transceiver). The blocking unit 143 may cut off the power supply to the transceiver housing device 10b. Signals may be blocked on the communication network 2 side. The blocking unit 143 may detect the main signal transmitting / receiving unit 12's inability to communicate and changes in its state based on the results of exchanging signals such as a "Keep Alive" signal or a "Health check" signal with the transceiver housing device 10b. If a state is detected that does not meet the conditions for allowing communication continuity, the blocking unit 143 may block communication continuity using at least one of the photonic gateway's blocking function and changing the distribution settings of the photonic gateway's optical distribution unit. The blocking unit 143 may transmit a blocking instruction to the transceiver housing device 10b.
[0107] The transceiver housing device 10b and the control device 20b may each perform a blocking process.
[0108] The receiving control unit 141 constructs control signal paths SR between the control device 20b and the control unit 14b, and between the control unit 14b and the main signal transmitting / receiving unit 12.
[0109] The login control unit 142 establishes a control signal path SR between the login control unit 142 and the blocking unit 143. However, if the environment within the control device 20b is secure, the login control unit 142 does not need to establish the control signal path SR in the path shown by the dashed line between the login control unit 142 and the blocking unit 143 in Figure 5.
[0110] The blocking unit 143 and the login control unit 142 are not limited to being located within the control device 20b, but may be located anywhere within the communication network. In this case, the vicinity of the control device 20b or within or near the operating system that controls the communication network is preferable. However, if the blocking unit 143 is located outside the control device 20b, it is assumed that the communication network is configured to be resistant to hacking. When the blocking unit 143 blocks the main signal output from the main signal transmitting / receiving unit 12 of the transceiver housing device 10b within the communication network, it is desirable that the blocking unit 143 be located on the path of the main signal. When the blocking unit 143 instructs the main signal transmitting / receiving unit 12 to stop or cut off power, causes the transceiver housing device 10b to cut off power to the main signal transmitting / receiving unit 12, cuts off signal conduction between the main signal transmitting / receiving unit 12 on the communication network side and the main signal transmitting / receiving unit 15 on the user device 40 side using a switch 13, or cuts off power to the transceiver housing device 10b itself, it is desirable that the blocking unit 143 be located within the control device 20b.
[0111] Next, we will explain an example of the operation of communication system 1b. Figure 6 is a sequence diagram showing an example of the operation of the communication system 1b in the third embodiment. The receiving control unit 141 constructs a control signal path SR of the control signal from the control device 20b before communication conduction of the main signal between the main signal transmitting / receiving unit 12 and the communication network 2 is permitted (step S201).
[0112] The login control unit 142 of the control device 20b enables login from the control device 20b. The login control unit 142 of the control device 20b disables login from the user-side control terminal 30, which is capable of changing and reading the related settings of the main signal transmission / reception unit 12 using a local account (step S202).
[0113] The login control unit 142 of the control device 20b restricts login using control signals. The login control unit 142 of the control device 20b instructs the receiving control unit 141 to change and read predetermined related settings of the main signal transmitting / receiving unit 12 using control signals (step S203). The receiving control unit 141 performs the change and reading of predetermined related settings of the main signal transmitting / receiving unit 12 based solely on control signals (step S204).
[0114] The login control unit 142 of the control device 20b determines the status of the disabled login from the user-side control terminal 30 (step S205). If the disabled login from the user-side control terminal 30 is maintained, the reception control unit 141, in response to the control by the blocking unit 143 of the control device 20b, allows communication between the main signal transmitting / receiving unit 12 and the communication network 2 (step S206).
[0115] For example, the user-side control terminal 30 may perform an action to enable login from the user-side control terminal 30. For example, the user-side control terminal 30 may attempt to infiltrate with a computer virus. For example, the user-side control terminal 30 may attempt to update the software (step S207). The login control unit 142 of the control device 20b determines the status of disabled login from the user-side control terminal 30, etc. For example, since the user-side control terminal 30 may perform an action to enable login from the user-side control terminal 30, the login control unit 142 detects the activation of the login. For example, the login control unit 142 may detect an infiltration of a computer virus. For example, the login control unit 142 may detect a software update (step S208). If the disabled login from the user-side control terminal 30 is not maintained, the receiving control unit 141 prohibits communication conduction in accordance with the control by the blocking unit 143 of the control device 20b. The receiving control unit 141 may revoke the permission for communication conduction in response to control by the blocking unit 143 of the control device 20b if the login from the user-side control terminal 30 is not maintained (step S209).
[0116] As described above, the receiving control unit 141 constructs a control signal path SR of the control signal from the control device 20b located in the communication network 2 before blocking the main signal between the main signal transmitting / receiving unit 12 and the communication network 2 to allow communication. The control signal path SR is constructed between the control device 20b and the receiving control unit 141.
[0117] The login control unit 142 of the control device 20b enables login from the control device 20b. The login control unit 142 of the control device 20b disables login from the user-side control terminal 30, which is capable of changing and reading the related settings of the main signal transmission / reception unit 12 using a local account. The blocking unit 143 of the control device 20b releases the blocking between the communication network 2 and the main signal transmission / reception unit 12, allowing communication of the main signal, if the disabling of login from the user-side control terminal 30 is maintained. The blocking unit 143 of the control device 20b may release the blocking of communication of the main signal between the communication network 2 and the main signal transmission / reception unit 12 if the disabling of login from the user-side control terminal 30 is not maintained. The blocking unit 143 of the control device 20b blocks communication of the main signal between the communication network 2 and the main signal transmission / reception unit 12.
[0118] This makes it possible to suppress the impact on service provision caused by operations contrary to the telecommunications carrier's intentions. Here, the scale of modification to the transceiver accommodation device 10b is small. In addition, it is less susceptible to attacks compared to the first and second embodiments, and it is possible to quickly block the main signal on the communication network (gateway) side.
[0119] (Fourth embodiment) In the fourth embodiment, the device software implemented in the control unit is, for example, Goldstone. The fourth embodiment will be described primarily in terms of the differences from the first to third embodiments.
[0120] The fourth embodiment is generally illustrated using the container orchestration tool Kubernetes, and then a specific configuration using Goldstone is shown.
[0121] Containers isolate execution processes using kernel functionality through the implementation of namespaces ("namespaces") where execution processes are grouped and run only within isolated spaces, and control groups ("cgroups") that restrict hardware resources to execution processes. They also share container images via a Copy-On-Write (COW) mechanism, consisting of a read-only container image and a thin R / W layer file that can be written to by the execution process.
[0122] Container deletion only removes writable layers, so to save the contents after startup, you need to either create a new image of the container along with the new layers, or configure a mechanism to write to an external file separately.
[0123] A container image is a TAR (Tape ARchive) file containing the root filesystem, a combination of the filesystem on which the application runs and JSON (JavaScript Object Notation) metadata that describes settings such as startup commands and ports.
[0124] A container execution engine is a library that implements Kernel functions as an API (Application Programming Interface). It internally calls the container runtime, which creates and runs containers, to achieve container execution. When a container is executed, the container image is unpacked (Filesystem Bundle) and passed to the container runtime. The runtime consists of a low-level Container Runtime such as runC, which creates the container's isolation environment and directly manipulates it, and a high-level Container Runtime such as containerd, which unpacks the container image and passes the container execution task to the low-level Container Runtime.
[0125] Cubenetis invokes the High-level Container Runtime using the CRI (Container Runtime Interface) API standard.
[0126] Kubernetes is a container orchestration tool that manages containerized workloads and services by deploying containers (the execution forms of applications) according to business workloads, scheduling to allocate appropriate resources by declaring desired states, self-healing, and abstracting infrastructure. Kubernetes is often referred to as "k8s," and its lightweight version is sometimes referred to as "k3s."
[0127] The two elements that make up a Kubernetes cluster are the Object, which is an abstract configuration management file that defines the ideal state of resources such as containers, networks, and storage running on the Kubernetes cluster, as well as the deployment details of containers and policies such as restarts, upgrades, and connectivity; and the Control Plane, which is the cluster infrastructure that implements and processes to realize those requirements.
[0128] Objects defined in YAML (YAML Ain't Markup Language) format are called manifests.
[0129] The four basic objects related to the control plane are Pod, Service, ReplicaSet, and Deployment. A Pod is an object that manages the unit for deploying containers on a cluster, and is a unit that groups containers that share a Volume and network group. A Pod is an object that manages the unit for deploying containers on a cluster and can launch multiple containers within it. A Service is an object that configures access routing for Pods. A ReplicaSet is an object that manages the number of Pods (replicas) required in the cluster using a PodTemplate template for creating Pods. A Deployment is an object that manages the release of new versions. Note that CubeNetis does not handle resources at the container level.
[0130] The control plane consists of two groups: Master Nodes and Worker Nodes. The Master Node receives requests from manifests and schedules tasks for running containers and infrastructure resources. Worker Nodes start and delete containers according to instructions from the Master Node, and also monitor the status of containers running on their own servers and notify the Master Node.
[0131] A master node is an interface that receives resource requests in the form of manifests defining the etcd state of the distributed storage, such as the kube-apiserver (kubenetis API), and also includes kube-shedder and kube-controller-manager, which receive processing requests from these. Ideally, it should refer to the state of resources stored in etcd.
[0132] The CubeNetis API includes filters that allow only user accounts or services (service accounts) with specific permissions to access or modify object information stored in etcd. The filtering process authenticates the connecting account, determines authorization for which resources to grant what permissions, and determines user-specific resource restrictions. Authentication sources are broadly categorized into user accounts, which are authentication accounts for operators or processes connecting from outside the cluster, and service accounts, which are authentication accounts for processes running in Pods within the cluster's namespace. User accounts are defined globally for the cluster and are unique within the cluster regardless of namespace, while service accounts are managed separately for each namespace and are unique within each namespace. Service account tokens are mounted to Pods as Secrets. In a CubeNetis cluster, container registry authentication can be performed by creating a Secret for the registered account. However, since Secrets are not encrypted, they are not typically secure objects, and countermeasures such as RBAC are necessary.
[0133] Among the access granted through authentication, the authorization modules, following the order specified by the authorization-mode option, control which operations are permitted depending on the source of the connection. If all specified modules deny the access, a "403" response is returned. If any authorization module approves the access, the process moves to evaluation by the Admission Controller. Evaluation modules include RBAC (Role-based access), which uses a Role object to define usage rights and a RoleBinding to associate them with user accounts and groups to regulate access. In RBAC, a Role object is a combination of resource and verbs, out of three elements: subject (the user account or process to be authenticated), resource (a set of API resources available in the cluster such as Pods, Deployments, Services, and Nodes), and verbs (a series of CRUD (Create / Read / Update / Delete) operations that can be performed on the resources). The Role and subject are associated with a RoleBinding. For example, cluster-wide restrictions can be defined using ClusterRole and ClusterRoleBinding, while namespace-level restrictions can be defined using a combination of Role and RoleBinding.
[0134] Admission Control checks the content of API requests and modifies or controls them. Admission Control is a general term for Admission Controllers, which are plug-in type implementation components that perform various filtering tasks. Among these components, AlwaysPullImages, which authenticates image usage when a Pod is started by enforcing an image acquisition policy, may be used to force the Pod to be equipped with the functional unit used in this embodiment (for example, any of the receiving control unit 141, login control unit 142, and blocking unit 143), or a ServiceAccount, which mounts a ServiceAccountToken for accessing the Kubenetis API, may be used to mount a token for a predetermined policy. MutatingAdmissionWebhook and ValidatingAdmissionWebhook may also be used to flexibly restrict access.
[0135] <Protection against modification> Therefore, in this embodiment, if the modification prevention function is mainly placed in the transceiver accommodation device, the transceiver accommodation device may be treated as a cluster, and cluster-wide restrictions such as ClusterRole and ClusterRoleBinding or ClusterRole and RoleBinding may be used.
[0136] When using user accounts, a user with lower privileges than the user controlled by the control device on the communication network 2 side is set up. This user is then given separate namespaces for Pods containing the functional components of this embodiment and other Pods, or separate namespaces for Pods that can control settings that the user should not control and other Pods, thereby preventing the user from controlling them.
[0137] When using a service account, if user access can be limited to tty (teletypewriter) input only or COM input compatible with serial connections, the restriction is at the namespace level, and can be defined using the Role or a combination of Role and RoleBinding. (For monitoring, if the monitoring function itself is not placed on the driver housing device, restrictions are not required. If the function is placed on the transceiver, restrictions are not required unless part of the function is placed on the transceiver housing device.)
[0138] For example, the target could be the customer (Login ID), TTY (via CUI), or Management Port (IP address) as the Subject. To prevent network connectivity, the Resource should not exchange or control information related to Service operations. This includes Pod access prohibition and login suspension, where the Node (hardware / driver housing device) is the target.
[0139] In this embodiment, the namespace secret related to the settings that restrict access to the functional parts or users should be hidden. However, deletion or modification of functional parts, or access to settings that should restrict access, may be suppressed by authorization or access control.
[0140] However, since changes and other modifications could be accessed by falsifying the ID if the Secret is visible, it is preferable to perform a connection check with the network control device and disconnect the control signal transceiver 11 from the communication network 2, thereby interrupting the connection. Alternatively, if the control device of the communication network 2 checks the settings and other information and detects a connection or modification other than the connection from the communication network 2, the main signal should be cut off, and the settings and authentication information should be checked to confirm that everything is normal before the connection is restored.
[0141] From the standpoint of preventing users from changing settings or other information that they should not access by disconnecting the control signal transceiver 11 from the communication network 2, it is also desirable in previous embodiments to perform a connection check with the control device of the communication network 2, and if the connection is broken by disconnecting the control signal transceiver 11 from the communication network 2, or if the control device of the communication network 2 checks the setting values, etc. and detects a connection or change other than the connection from the communication network 2, the main signal should be turned off, and after checking the settings and authentication information, etc. and confirming that they are normal, the connection should be restored.
[0142] <Prevention of deletion of the functional part of this embodiment> It is desirable that a Pod equipped with the functional unit of this embodiment (for example, any of the receiving control unit 141, the login control unit 142, and the blocking unit 143) be given a high priority so that the functions of this embodiment are not stopped.
[0143] Specifically, when creating or recreating a Pod, if the NodeName field (the node on which the Pod should run) is not specified in the Pod definition, and the Worker Node is also not specified, kube-scheduler, which constantly monitors unspecified Pods, will select a suitable Worker Node, update the NodeName, notify the kubelet running on the target Worker Node of the request to add a new Pod, and start the Worker Node Pod. Conversely, if a Pod cannot fit on a specific node, the Pod deemed inappropriate by the filtering Predicate that removes inappropriate nodes will be removed.
[0144] Therefore, it is desirable that a Pod equipped with the functional unit of this embodiment be weighted such that it receives a request to add a new Pod when there are not enough Pods for the functional unit to operate, and is not deleted when its deletion would make the Pod insufficient for the functional unit to operate.
[0145] Similarly, when configuring Pod autoscaling, ensure that the number of Pods is not reduced when scaling out or scaling in with the Horizontal Pod Autoscaler (HPA). If the number increases, ensure that security is not compromised. Ensure that the processing capacity of the Pod itself is maintained when scaling up or down with the Vertical Pod Autoscaler (VPA) to ensure that the processing capacity required for this embodiment (communication speed and frequency with the functions on the communication network 2 side, and in the case of monitoring, the speed and frequency of monitoring and blocking, etc.) is maintained. Furthermore, in VPAs that do not allow dynamic resource changes for running Pods and delete Pods via operations via the Eviction API, etc., and recreate Pods with appropriate resources using the ReplicaSet's self-healing function, etc., ensure that Pods involved in the processing of this embodiment are not deleted if the number falls below one. Alternatively, it is desirable to ensure that the time during which the processing of this embodiment is interrupted in a series of steps is less than or equal to a predetermined time, or to suppress the processing if it exceeds the predetermined time. If a Pod Disruption Budget is set, it is desirable to keep its value for Pods involved in the processing of this embodiment sufficiently smaller than the duration of abnormal conditions that are permissible on the service.
[0146] <Settings that should not be accessed, the TLS type used as a certificate with the control device on the communication network 2 side, and ensuring the confidentiality of authentication information for Docker images> The manifest allows you to register Secret and ConfigMap objects, such as encrypted key-value pairs, for each user account at startup. These can then be read by the Pod either as environment variables or by mounting a volume. Here, Secrets and ConfigMaps are volumes used to manage environment variables and application configuration files as separate objects from the Pod, without including them within the container. Secrets are objects that handle credential information; they are appropriately encrypted and stored in etcd, and when used, they are expanded into a temporary file system (tmpfs) allocated in the worker node's memory area, so no persistent data remains on the worker node. ConfigMaps manage plaintext content as volumes.
[0147] When using these methods, you can update the Deployment and switch Pods to reflect the changes in already running Pods, or you can reload or restart the process to reflect the changes in the container process. You can also use fields such as "valueFrom.configMapkeyRef" or "envFrom[].configMapRef" as environment variables to reflect the changes in the Pod.
[0148] Instead of using a Pod manifest, you can use PodPreset, a hook feature that adds specific information when a Pod is created based on a label selector, to dynamically specify specific environment variables at the time of Pod startup. When using PodPreset, you can use common information without having to specify all the information for each Pod every time, and you can dynamically add necessary or sensitive information regardless of the deployment environment.
[0149] <Method for confirming whether the application is one used in this embodiment> You may also utilize cataloging using service catalogs defined in ITIL (Information Technology Infrastructure Library), which are sets of functional templates that define various business requirements for applications and services, and can include not only configuration information but also designs that can guarantee the deployment process, its operation, or its quality.
[0150] Here, the service catalog refers to an extension API that allows applications running on a Kubernetes cluster to use software and services located outside the cluster, such as managed databases and object storage provided by cloud providers, to connect to non-containerized resources. It does not refer to Kubernetes' Service Catalog using the Open Service Broker API standard.
[0151] As an example of defining application requirements, we showed how to individually associate objects such as Deployment, Service, and ConfigMap using labels and selectors. However, to simplify management by packaging manifests according to workloads, you could pre-determine the elements required for a specific application or service, package the corresponding objects into templates, and then use this package for application rollback and version control. For example, you could use Helm, a Kubernetes package management tool that can reduce the workload of managing Deployments and Services for each application workload, and handling variables and volumes using ConfigMaps. Helm is a client tool that manages Charts, which are packages that bundle Kubernetes manifests into templates and are sets of YAML files. In Helm version "2", the entire package management function consists of Helm (Client), a client tool that calls Charts from the console or CI / CD pipeline, and Tiller (Server), a service that runs on the Kubernetes cluster and deploys and manages Charts. The Helm client interacts with Tiller via gRPC, sending information about the Chart to be deployed and instructing it to request upgrades or uninstalls. Tiller instructs Kubernetes to configure the Chart as requested by the Helm client and manages resource deployment. With Helm version "3," instead of using Tiller to manage resources by comparing the version deployed on Kubernetes with the Chart release version, this release information is stored in a CRD (Custom Resource Definition) and manipulated from the client side.
[0152] This mechanism can be used to easily verify whether the application used in this embodiment is the correct version. For example, one could use predefined variables in Chart, such as Release.Time, which is the time the release was last updated, Release.Revision, which is the revision number that increases from 1 with each update, or the version field in Chart.yaml. If an inappropriate version is detected, the Pod with the difference or all Pods can be rolled back to the correct version, and if it is not possible to roll them back, they may be blocked.
[0153] Of course, Kubernetes is a mechanism that implements core resources such as Pods and Deployments managed by Kubernetes using Kubernetes resources and controllers. It uses a Control Loop consisting of three states: "Observe" to monitor the current operating state, "Diff" to compare the difference between the Current State and the Desired State, and "Act" to adjust to the appropriate state. It can monitor, detect, and adjust, adjust to the appropriate state, and if adjustment is not possible, it can be blocked. Here, if it is a Deployment, the Control Loop is managed by the Deployment controller.
[0154] In this embodiment, the operational implementation of the application (for example, any of the receiving control unit 141, login control unit 142, and blocking unit 143), which is a custom resource added as a unique resource, may be monitored, detected, and adjusted from Kubernetes using the "custom resource" and "custom controller".
[0155] Here, custom resources are unique data structures that extend the existing Kubernetes API. They create a container for extended resources to manage the Desired State and Current State of objects stored in etcd. They store application-specific state information and flags necessary for middleware crust management. By storing the state, which was previously managed solely by the application, as a Kubernetes resource, the controller can adjust the object's state using the Control Loop. In this case, if proper adjustment is not possible, blocking may be an option.
[0156] As a custom resource, API extensions can be defined and extended in detail by implementing a new object as an Aggregated API in the Kubernetes API using API Aggregation and registering the API with the Aggregation Layer, or by defining a new resource using Customer Resource Definition (CRD) without creating a custom API. Operators use the latter method of API extension using CRDs.
[0157] The custom controller checks (Diff) the state of custom and core resources, and adjusts (Acts) the managed objects if there is an event that triggers an update to the resource's Desired State.
[0158] Next, we will describe a configuration using Goldstone as the software incorporated into the transceiver housing device 10. In the embodiments described above, we described a transceiver housing device 10 without a blocking unit (for example, the first embodiment) and a transceiver housing device 10 with a blocking unit (for example, the second and third embodiments). In the description of the fourth embodiment, we will also describe separately the cases with and without a blocking unit.
[0159] (If a shutoff mechanism is not provided) As an example of a configuration without a blocking unit, the transceiver accommodation device 10 in the first embodiment will be described. As software that operates on the control unit 14 of the transceiver accommodation device 10 in the first embodiment, a set of white box switch network OS, Goldstone, and configuration functions is installed on the white box switch. The configuration functions, namely the receive control unit 141, the login control unit 142, and the blocking unit 143, may be applications on an OS other than Goldstone, or they may be applications on Goldstone.
[0160] If the receiving control unit 141, login control unit 142, and blocking unit 143 are applications on Goldstone, then the receiving control unit 141, login control unit 142, and blocking unit 143 are applications not normally included in Goldstone, and may be applications on different containers on different Pods, applications on different containers on the same Pod, applications on the same container on the same Pod, or a single application. They may also be modified versions of some existing Goldstone applications.
[0161] For example, in a configuration of the transceiver accommodation device 10 that requires minimal modification, the receiving control unit 141 is a North Management Interface pre-equipped with CLI (Command Line Interface), netfonf, SNMP (Simple Network Management Protocol), restconf, etc., or a Sysrepo on which these are written. The login control unit 142 and the blocking unit 143 are TAI or tai shell. Note that in the configuration shown in Fig. 9 of Non-Patent Literature 1, this corresponds to the South TAI of the South Management Layer. The function of logging in from the communication network via a predetermined route may be provided by modifying the North Management Interface, Sysrepo, or South TAI, or it may be provided separately in parallel with the North Management Interface or South TAI.
[0162] • Applications using Sysrepo (Sysrepo is a YANG-based datastore for UNIX® / Linux® systems that stores application configurations written in YANG format) may be restricted by NETCONF (Applications using Sysrepo, which is integrated with the Netopeer2 NETCONF server, can be managed by NETCONF). • Because Sysrepo lacks a master process that can enforce complex access control, it relies on standard filesystem permissions and should be used with the following in mind: Always set the correct permissions and owner for all YANG modules you install to prevent unauthorized processes from accessing sensitive data. The utility Sysrepoctl has the ability to display (--list) and change (--change) all permissions, in addition to the functionality available via the API. <module>This is used for both of the following: Completely suspending Sysrepo by writing to a shared file that needs to be accessible from all processes linked to Sysrepo. Reverse engineering can adjust two cmake variables, Sysrepo_umask and Sysrepogroup, to prevent denormalized processes from accessing data while data is being communicated through these shared files. Generally, a new system group is created and set to Sysrepo_group, and then Sysrepojmask is set to 00007 to restrict all external access. If all user accounts running the Sysrepo process belong to this group, other user accounts will not be able to access Sysrepo files or sensitive information.
[0163] (When equipped with a shutoff mechanism) As an example of a configuration that includes a blocking unit, the transceiver accommodation device 10a in the second embodiment will be described. The basic processing is the same for the transceiver accommodation device 10b in the third embodiment. As software that operates on the control unit 14 of the transceiver accommodation device 10a in the second embodiment, the NOS of the white box switch, Goldstone, setting function and blocking function, etc. are installed on the white box switch. The setting function, consisting of the receive control unit 141, login control unit 142 and blocking unit 143, may be an application other than Goldstone, or it may be an application on Goldstone.
[0164] If the receiving control unit 141, login control unit 142, and blocking unit 143 are applications on Goldstone, then the receiving control unit 141, login control unit 142, and blocking unit 143 are applications not normally included in Goldstone, and may be applications on different containers on different Pods, applications on different containers on the same Pod, applications on the same container on the same Pod, or a single application. They may also be modified versions of some existing Goldstone applications.
[0165] For example, in a configuration where the transceiver accommodation device 10a requires minimal modification, the receive control unit 141 is a North Management Interface pre-equipped with CLI, netfonf, SNMP, restconf, etc., or a Sysrepo on which these functions write values. The login control unit 142 and the blocking unit 143 are TAI or tai shell. Note that in the configuration shown in Fig. 9 of Non-Patent Literature 1, this corresponds to the South TAI of the South Management Layer. The function of logging in from the communication network via a predetermined route may be provided by modifying the North Management Interface, Sysrepo, or South TAI, or it may be provided separately in parallel with the North Management Interface or South TAI.
[0166] It is desirable to send a Dying GASP equivalent to the control device 20, but the control device 20 may also estimate it by observing the interruption of a Keep alive or Health check equivalent.
[0167] • Applications using Sysrepo (Sysrepo is a YANG-based datastore for UNIX® / Linux® systems that stores application configurations written in YANG format) may be restricted by NETCONF (Applications using Sysrepo, which is integrated with the Netopeer2 NETCONF server, can be managed by NETCONF). • Because Sysrepo lacks a master process that can enforce complex access control, it relies on standard filesystem permissions and should be used with the following in mind: Always set the correct permissions and owner for all YANG modules you install to prevent unauthorized processes from accessing sensitive data. The utility Sysrepoctl has the ability to display (--list) and change (--change) all permissions, in addition to the functionality available via the API. <module>This is used for both of the following: Completely suspending Sysrepo by writing to a shared file that needs to be accessible from all processes linked to Sysrepo. Reverse engineering can adjust two cmake variables, Sysrepo_umask and Sysrepogroup, to prevent denormalized processes from accessing data while data is being communicated through these shared files. Generally, a new system group is created and set to Sysrepo_group, and then Sysrepojmask is set to 00007 to restrict all external access. If all user accounts running the Sysrepo process belong to this group, other user accounts will not be able to access Sysrepo files or sensitive information.
[0168] (Variation 1) In the fourth embodiment, the transceiver accommodation devices 10, 10a, and 10b may be configured to restrict the addition or duplication of new Namespaces, Nodes, or containers using Kubernetes or the like, which would involve the deletion or modification of the functional units added in each embodiment, or would bypass the processing of the functional units added in each embodiment. In this case, it is sufficient that the container on the transceiver accommodation devices 10a, 10b where the blocking unit 143 is located, or the Node corresponding to the container, is not inaccessible from the control devices 20, 20b, or that the blocking unit 143 is unable to block when it is blocking.
[0169] (Modification 2) In the fourth embodiment, the transceiver accommodation devices 10, 10a, and 10b may be configured to start as follows: (shutting off at startup or shutdown, login control from startup, and connection to APNC). When restarting, the transceiver accommodation devices 10, 10a, and 10b may be configured to start only in a manner that accepts control from the control devices 20 and 20b, without requiring the user to log in and restart them (shutting off at startup or shutdown, login control from startup, and connection to APNC).
[0170] (Variation 3) In the fourth embodiment, the transceiver housing devices 10, 10a, and 10b may be configured to start up automatically as follows. Automatic startup is performed, for example, in the normal startup sequence, which is: Goldstone startup screen → immediately inside Kubernetes after startup → stop tai shell (tai.sh stop) → start tai shell (tai.sh start) → restart south-tai (k rollout restart ds / south-tai) → start tai shell (k exec -it deploy / tai -- taish) → enter each PIU (plug-in unit) from the tai shell (module / dev / piu1, here an example is piu1) → activate the main signal transmitting / receiving unit 12 (set admin-status up), and if so, this is also started up automatically.
[0171] (Modification 4) In the fourth embodiment, in the transceiver housing devices 10, 10a, and 10b, IDs with lower privileges than administrator privileges may be created, and only IDs with lower privileges may be allowed to access the user. Furthermore, with respect to software or setting files related to the deletion or modification of the functional parts added in each embodiment, the IDs with lower privileges may be set to read-only, read-only, write-only, execute-only, or otherwise unreadable. In the case of files, the mode shall be ---(0) or r--(4) (read / write / execute).
[0172] (Variation 5) In the fourth embodiment, the transceiver housing devices 10, 10a, and 10b may be configured to perform the following access restrictions related to the deletion or modification of the functional units added in each embodiment. • You can make it impossible to look up IP addresses. Access is restricted by suppressing address resolution and advertisement of IP addresses for the functional components themselves, configuration values, and containers containing them in the Kubernetes routing table, and by making the IP addresses difficult to guess. Access to the API Server (Kubernetes control plane) may be restricted by network access control lists to IP addresses necessary for cluster management, or by restricting access to related nodes. Network traffic between TAI-related services is encrypted using mTLS, etc. You can also use security policies or OPA Gatekeeper to enforce permissions for Pods and containers in Kubernetes. By default, Kubernetes does not have access restrictions, but you can use Network Policies to write ingress rules for Pods and control access on a per-Pod basis (per IP address) or per TCP / UDP port basis using ingress rules.
[0173] Next, the transceiver accommodation device (control unit) or control unit executes a sequence using Kubernetes that restricts the addition and replication of new namespaces, nodes, and containers that bypass the processing of predetermined functional units. The transceiver accommodation device (control unit) or control unit restricts logins to ONL (Open Network Linux), K3s (lightweight Kubernetes), the "South management layer" (e.g., South-TAI, South-ONLP in Goldstone), and the "North management layer" (e.g., north-CLI, north-netconf in Goldstone). The transceiver accommodation device (control unit) or control unit restricts logins to, for example, bare operating systems. The transceiver accommodation device (control unit) or control unit restricts logins to Kubernetes. The transceiver accommodation device (control unit) or control unit restricts connections so that connections to Goldstone addresses in Kubernetes are only possible from the control unit.
[0174] When the transceiver housing device is restarted, the transceiver housing device (control unit) or the control unit repeats this sequence. If the setting is such that the user-side control terminal 30 logs back into the transceiver housing device at startup and the transceiver housing device restarts, the control unit shuts off the main signal transmission / reception unit 12 when the transceiver housing device restarts.
[0175] It is desirable for the transceiver coupling device to transmit a signal equivalent to "Dying GASP" to the communication network 2 (gateway), but the control device (gateway) may estimate (determine) a communication failure based on "Keep alive" or "Health check".
[0176] The transceiver accommodation device may be configured such that, even if the user-side control terminal 30 logs into the transceiver accommodation device during a reboot, the transceiver accommodation device does not reboot, and the transceiver accommodation device only accepts control from the control device (gateway) side (e.g., blocking during startup or shutdown, verification of the initial ID (identification information) and password during startup, or connection to the control device (APNC) of the all-photonic network).
[0177] In the automatic startup of the transceiver accommodation device, for example, using open-source software (TAI: Transponder Abstraction Interface) that enables the separation of hardware and software in optical transmission networks between data centers, if the normal startup sequence is "Goldstone startup screen" → "immediately after startup, inside Cubenetis" → "stop tai.shell (tai.sh stop)" → "start tai.shell (tai.sh start)" → "restart south-tai (k rollout restart ds / south-tai)" → "start tai shell (k exec -it deploy / tai -- taish)" → "enter each PIU (plugin unit) from tai shell (module / dev / piu1, here piu1 is an example)" → "activate the transceiver (set admin-status up)", then these will also be started automatically.
[0178] When changing a password, existing sessions are terminated. For example, when changing a password, user sessions from teletype (tty), etc., are temporarily terminated. This prevents further actions by users who remain logged in. Additionally, control serial ports, etc., are disabled.
[0179] To prevent unauthorized access, a bridging method using Cni0 (Container Network Interface 0) is employed. This involves creating a virtual bridge in the host's network namespace, and connecting the host side of the virtual network (veth) created for each Pod (the smallest unit for managing Docker containers) to the bridge, thereby enabling communication between the Pod and the host. For example, a CNI plugin (Flannel) is used. Primarily, Pods on the same node are filtered by the bridge if each Pod belongs to the same segment.
[0180] In the "Point to Point" method (primarily a method where each Pod is allocated an independent network segment) used by Kubernetes' "Calico" for host-container communication, instead of routing to a virtual bridge and resolving the MAC address (Media Access Control address) of the connected network interface card (NIC) via ARP (Address Resolution Protocol) to communicate, the traffic is routed directly to the virtual network (veth) corresponding to each Pod, thus bypassing the virtual bridge.
[0181] For managing login status, monitoring the POD status in Cubenetis (e.g., `k get pods`) may be used. At least the Pods listed below that are subject to disconnection, or Pods equivalent to those subject to disconnection, will be disconnected when login restrictions are in place.
[0182] Disconnection target: Serial connection " / dev / ttyS * The virtual terminal (terminal) connected via the network using "SSH" or "telnet" is located at " / dev / pts / * Disconnect the target indicated by '' (for clarification, " / dev / modem" for modems, " / dev / mouse" for mice, and " / dev / cua" (the old name for serials) are among those to be disconnected).
[0183] The connections to be suppressed are, for example, "GS_SOUTH_AGENTS' south-sonic south-tai south-onlp south-system south-gearbox south-dpll", "GS_NORTH_AGENTS' north-cli north-snmp north-netconf north-notif", and "GS_XLATE_AGENTS' xlate-ocn (related to tai, usonic-cli, gs-mgmt-np2, and snmp (gs-mgmt-snmp, svclb-gs-mgmt-snmp, svclb-netopeer2, etc.)".
[0184] <Access Restrictions> • The IP (Internet Protocol) address may be made unrecoverable. Address resolution or advertisement of IP addresses between the container containing the configuration values and the functional unit itself will be suppressed in the routing tables of Kubernetes and the operating system. In addition, access will be suppressed by setting the IP address to a value that is difficult to guess. Network access control lists may restrict access to the API server (Coobenetis control plane) to IP addresses necessary for cluster management, or to related nodes.
[0185] Network traffic between TAI-related services may be encrypted using TLS mutual authentication (mTLS: mutual Transport Layer Security), etc. • In CubeNetis, security policies that enforce permissions for Pods and containers, as well as the Open Policy Agent Gatekeeper (OPA Gatekeeper), may be used.
[0186] By default, Cubenetis does not have access restrictions, but network policies can be used to write "ingress rules" for Pods, and these "ingress rules" can be used to perform access control on a "Pod-by-Pod (IP address-by-IP address)" or "TCP / UDP port" basis.
[0187] Applications that use the system repository configuration "Sysrepo" may be restricted by "NETCONF". "Sysrepo" is a YANG (Yet Another Next Generation) based datastore for UNIX® / Linux® systems that stores application configurations written in YANG format. Applications that use "Sysrepo" integrated into the "Netopeer2 NETCONF server" can be managed by "NETCONF".
[0188] • Since "Sysrepo" does not have a master process that can enforce complex access control, it relies on standard file system permissions and should be used with the following points in mind.
[0189] To prevent unauthorized processes from accessing sensitive data, all installed YANG modules are always configured with the correct permissions and owners. The utility "sysrepoctl" (System Repository Configuration Control) offers this functionality via the Application Programming Interface (API), as well as the ability to view (--list) and change (--change) all permissions. <module>Both ) and are used.
[0190] Sysrepo is completely interrupted by writing to a shared file that needs to be accessible by all processes linked to Sysrepo. Reverse engineering can be used to adjust two cmake variables (sysrepo_umask and sysrepo_group) so that the data cannot be accessed by the denormalized process while data is being communicated through these shared files.
[0191] Generally, all external access is prohibited by creating a new system group, setting it to "sysrepo_group", and setting "sysrepo_jmask" to 00007. Alternatively, all external access may be prohibited by setting "sysrepo_umask" to "00007". If all user accounts running the "Sysrepo" process belong to this group, other user accounts may be prevented from accessing the "Sysrepo" files and sensitive information.
[0192] Login information may not be exchanged, and values held or generated by the transceiver accommodation device may be transmitted to the communication network 2.
[0193] As described above, by using the device software (Goldstone) pre-installed in the control unit 14b, it is possible to suppress the impact of operations contrary to the telecommunications carrier's intentions on service provision.
[0194] (Hardware configuration) Figure 7 shows examples of the hardware configuration of the communication system 1 in each embodiment. The communication system 1 illustrated in Figure 7 corresponds to the communication system 1 of the first embodiment, the communication system 1a of the second embodiment, the communication system 1b of the third embodiment, and the communication system 1 of the fourth embodiment, respectively. The communication system 1 illustrated in Figure 7 is implemented as software by a processor 201 such as a CPU executing a program stored in a storage device 203 having a non-volatile recording medium (non-temporary recording medium) and a memory 202. The program may be recorded on a computer-readable recording medium. A computer-readable recording medium is a non-temporary recording medium such as a flexible disk, magneto-optical disk, ROM, CD-ROM or other portable media, or a storage device such as a hard disk built into a computer system. The communication unit 204 performs communication processing.
[0195] The communication system 1 illustrated in Figure 7 may be implemented using hardware including electronic circuits (or circuits) such as LSI (Large Scale Integrated Circuit), ASIC (Application Specific Integrated Circuit), PLD (Programmable Logic Device), or FPGA (Field Programmable Gate Array).
[0196] While embodiments of this invention have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments and includes designs and the like that do not depart from the spirit of this invention. [Industrial applicability]
[0197] This invention is applicable to optical communication systems (optical transmission systems) such as APNs. [Explanation of symbols]
[0198] 1, 1a, 1b…Communication system, 2…Communication network, 10, 10a, 10b…Transceiver housing device, 11…Control signal transmission / reception unit, 12…Main signal transmission / reception unit, 13…Switch, 14, 14a, 14b…Control unit, 15…Main signal transmission / reception unit, 20, 20a, 20b…Control device, 30…User-side control terminal, 40…User device, 141…Receive control unit, 142…Login control unit, 143…Blocking unit, SR…Control signal path< / module> < / module> < / module>
Claims
1. A receiving control unit constructs a path for control signals from a control device located in the communication network before blocking the main signal between the communication network and the main signal transmitting / receiving unit to allow communication, A login control unit which enables login from the control device, disables login from a user-side control terminal that can change the related settings of the main signal transmission / reception unit, releases the blockage and allows communication conduction if the disablement of login from the user-side control terminal is maintained, and disables or blocks login from the user-side control terminal again if the disablement of login from the user-side control terminal is not maintained. A communication system equipped with [the following features].
2. The communication system according to claim 1, wherein the login control unit releases the blockage and allows communication conduction when the login from the user-side control terminal is disabled, and disables the login from the user-side control terminal again when the login from the user-side control terminal is not disabled.
3. The communication system according to claim 1 or claim 2, further comprising a blocking unit that blocks the communication connection when the inability to disable login from the user-side control terminal is not maintained, and releases the blocking of the communication connection when the inability to disable login from the user-side control terminal is maintained.
4. A configuration method performed by a communication system, Before blocking the main signal between the communication network and the main signal transmitting / receiving unit and allowing communication, the steps include constructing a path for control signals from a control device located in the communication network, The steps include: enabling login from the control device, disabling login from a user-side control terminal capable of changing the related settings of the main signal transmission / reception unit, releasing the blockage and allowing communication conduction if the disabling of login from the user-side control terminal is maintained, and disabling or blocking login from the user-side control terminal again if the disabling of login from the user-side control terminal is not maintained. Instructions for setting up, including the method described.
5. On the computer, Before blocking the main signal between the communication network and the main signal transmitting / receiving unit and allowing communication, a procedure for constructing a control signal path from a control device located in the communication network, A procedure to enable login from the control device, disable login from a user-side control terminal capable of changing the related settings of the main signal transmission / reception unit, release the blockage and allow communication conduction if the disablement of login from the user-side control terminal is maintained, and disable or block login from the user-side control terminal again if the disablement of login from the user-side control terminal is not maintained. A program to execute.
Citation Information
Patent Citations
Program downloading method and communication system
JP2006318383A
Optical communication system, optical communication device, program, and control method for optical network
JP2013017026A
Communication system and time information utilization method
JP2013201521A