Evaluation device, terminal, evaluation system, evaluation method, and program

JPWO2024069875A5Pending Publication Date: 2025-05-22
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024548979
Authority / Receiving Office
JP · JP
Patent Type
Applications
Priority Date
2022-09-29
Filing Date
2022-09-29
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

The calculation of cyber insurance premiums for network equipment lacks systematic approaches, and the evaluation of trustworthiness varies by standpoint, making it challenging to meet insurance company standards.

Method used

An evaluation device and system that acquires and uses trust evaluation indices to inspect and evaluate the trustworthiness of network equipment, issuing certified results that align with insurance company standards, including indicators for outage risk, information leakage, backdoors, risk assessment, incident response, and supply chain trustworthiness.

Benefits of technology

Enables objective evaluation of network equipment trustworthiness, facilitating accurate determination of cyber insurance premiums by insurance companies, ensuring compliance with industry standards and reliable risk assessment.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

An evaluation device according to the present disclosure comprises: an evaluation index acquisition means that acquires a trust evaluation index for evaluating trustworthiness, the trust evaluation index being employed by an insurance company; an apparatus information acquisition means that acquires apparatus information pertaining to network apparatuses on a network for which a user entrepreneur purchases insurance; an inspection means that, on the basis of the trust evaluation index, inspects the network apparatuses using the apparatus information; an evaluation means that evaluates trustworthiness on the basis of the result of inspection; and an output means that outputs the result of evaluating trustworthiness.
Need to check novelty before this filing date? Find Prior Art

Description

Evaluation device, terminal, evaluation system, evaluation method, and recording medium

[0001] The present disclosure relates to an evaluation device, a terminal, an evaluation system, an evaluation method, and a recording medium.

[0002] Methods for calculating insurance premiums for network devices are being considered.

[0003] For example, Patent Document 1 discloses calculating the premium for computer and related equipment damage insurance using information assessed by selecting assessment items related to computers, etc. Patent Document 2 discloses calculating the premium for industrial machinery from the reliability rate of the industrial machinery calculated based on a reliability index that indicates the degree to which various functions contribute to the reliability of various elements related to the industrial machinery.

[0004] JP 2006-235961 A JP 2022-011368 A

[0005] Demand for cyber insurance, which provides compensation for security risks, is on the rise. However, calculation of cyber insurance premiums and payment amounts when an incident occurs are not always done systematically.

[0006] Furthermore, the criteria for determining the trustworthiness (reliability) of network devices vary depending on the standpoint and perspective of the evaluator. In the inventions described in Patent Documents 1 and 2, the information that forms the basis for calculating insurance premiums is assessed based on the criteria from the standpoint of the evaluator. The trustworthiness required for calculating cyber insurance premiums must be evaluated based on the index adopted by the insurance company that sells cyber insurance.

[0007] An example of an objective of the present disclosure is to provide an evaluation device that can evaluate trustworthiness in accordance with cyber insurance standards adopted by insurance companies.

[0008] An evaluation device in one aspect of the present disclosure includes an evaluation index acquisition means for acquiring a trust evaluation index used by an insurance company to evaluate trustworthiness, a device information acquisition means for acquiring device information of network devices on a network insured by a user business, an inspection means for inspecting the network devices using the device information based on the trust evaluation index, an evaluation means for evaluating trustworthiness based on the inspection results, and an output means for outputting the trustworthiness evaluation results.

[0009] An evaluation system according to one aspect of the present disclosure is an evaluation system having a device information storage device that stores device information of network devices, and the evaluation device described above. The evaluation device comprises an evaluation index acquisition means that acquires a trust evaluation index used by an insurance company to evaluate trustworthiness, a device information acquisition means that acquires, from the device information storage device, device information of network devices on a network that a user operator insures, an inspection means that inspects the network devices using the device information based on the trust evaluation index, an evaluation means that evaluates trustworthiness based on the inspection results, and an output means that issues a certificate to certify the trustworthiness evaluation result, affixes an electronic signature to the certificate, and stores it in the device information storage device.

[0010] In one aspect of the present disclosure, an evaluation method includes a computer obtaining a trust evaluation index used by an insurance company to evaluate trustworthiness, obtaining device information for network devices on a network that a user business is insuring, inspecting the network devices using the device information based on the trust evaluation index, evaluating the trustworthiness based on the inspection results, and outputting the trust evaluation results.

[0011] In one aspect of the present disclosure, a recording medium stores a program that causes a computer to acquire a trust evaluation index used by an insurance company to evaluate trustworthiness, acquire device information of network devices on a network that a user business is insuring, inspect the network devices using the device information based on the trust evaluation index, evaluate trustworthiness based on the inspection results, and output the trustworthiness evaluation results.

[0012] One example of the effect of the present disclosure is that it can provide an evaluation device that can evaluate trustworthiness in accordance with the cyber insurance standards adopted by insurance companies.

[0013] Fig. 1 is a block diagram showing the configuration of an evaluation system according to a first embodiment. Fig. 2 is a diagram showing the hardware configuration in which an evaluation device according to the first embodiment is realized by a computer device and its peripheral devices. Fig. 3 is a flowchart of the evaluation system according to the first embodiment.

[0014] Next, an embodiment will be described in detail with reference to the drawings.

[0015] [First Embodiment] The evaluation device 100 in the first embodiment is a device used by, for example, an insurance company that takes out cyber insurance on a user company's network to evaluate the trustworthiness of network devices that make up the network. The cyber insurance in this embodiment covers liability for damages to third parties due to cyber incidents such as cyber attacks, as well as repair costs required to restore the network. Network devices are devices that relay or transfer data on a network, such as routers, hubs, gateways, or switches. Furthermore, the network in this embodiment refers to a network configured with network devices installed by the user company.

[0016] The evaluation system 10 in this embodiment includes an evaluation device 100, an insurance company terminal 200 of an insurance company that requests the evaluation device 100 to evaluate the trustworthiness of a network device, and a device information storage device 300 that stores device information for each network device. The device information storage device 300 is owned by a platform operator that manages the device information for each network device. The insurance company may, for example, request a third-party evaluation agency to evaluate the trustworthiness of the network device through the platform operator.

[0017] The insurance company terminal 200 includes an evaluation index sending unit 201, a certificate acquisition unit 202, a matching unit 203, and a determination unit 204, which send the trust evaluation index adopted by the user business to the evaluation device 100. When sending the trust evaluation index to the evaluation device 100, the evaluation index sending unit 201 may also send information indicating that the user business has requested cyber insurance. The insurance company terminal 200 is not limited to being a terminal, and may be realized as a server (including a cloud).

[0018] The device information storage device 300 stores at least configuration information and inspection information of the network devices as device information. The device information stored in the device information storage device 300 is updated in accordance with replacement of the network devices or software upgrades.

[0019] Fig. 1 is a block diagram showing the configuration of an evaluation device 100 according to the first embodiment. Referring to Fig. 1, the evaluation device 100 includes an evaluation index acquisition unit 101, a device information acquisition unit 102, an inspection unit 103, an evaluation unit 104, and an output unit 105. The evaluation device 100 according to this embodiment will be described in detail below.

[0020] 2 is a diagram illustrating an example of a hardware configuration in which the evaluation device 100 according to the first embodiment of the present disclosure is realized by a computer device 500 including a processor. As shown in FIG. 2, the evaluation device 100 includes a central processing unit (CPU) 501, memories such as a read-only memory (ROM) 502 and a random access memory (RAM) 503, a storage device 505 such as a hard disk for storing a program 504, a communication interface (I / F) 508 for network connection, and an input / output interface 511 for inputting and outputting data. In the first embodiment, the trust evaluation index acquired by the evaluation index acquisition unit 101 is input to the evaluation device 100 via the communication I / F 508, for example.

[0021] The CPU 501 runs an operating system to control the entire evaluation device 100 according to the first embodiment of the present invention. The CPU 501 also reads programs and data into memory from a recording medium 506 attached to, for example, a drive device 507. The CPU 501 also functions as the evaluation index acquisition unit 101, device information acquisition unit 102, inspection unit 103, evaluation unit 104, output unit 105, or parts of these units in the first embodiment, and executes processing or commands in the flowchart shown in FIG. 3, which will be described later, based on the program.

[0022] The recording medium 506 is, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. A part of the recording medium in the storage device is a non-volatile storage device, and the program is recorded therein. The program may also be downloaded from an external computer (not shown) connected to a communication network.

[0023] The input device 509 is realized by, for example, a mouse, a keyboard, built-in key buttons, etc., and is used for input operations. The input device 509 is not limited to a mouse, a keyboard, or built-in key buttons, and may be, for example, a touch panel. The output device 510 is realized by, for example, a display, and is used to check output.

[0024] As described above, the first embodiment shown in FIG. 1 is realized by the computer hardware shown in FIG. 2. However, the means for realizing each unit of the evaluation device 100 in FIG. 1 is not limited to the configuration described above. The evaluation device 100 may be realized by a single physically coupled device, or may be realized by two or more physically separated devices connected by wire or wirelessly. For example, the input device 509 and the output device 510 may be connected to the computer device 500 via a network. The evaluation device 100 in the first embodiment shown in FIG. 1 may also be configured using cloud computing or the like.

[0025] 1, an evaluation index acquisition unit 101 is a means for acquiring a trust evaluation index used by an insurance company to evaluate trustworthiness. In this embodiment, the evaluation index acquisition unit 101 acquires the trust evaluation index from an evaluation index transmission unit 201 via a network.

[0026] Trustworthiness refers to the reliability of an entire network consisting of multiple network devices, for example, reliability in maintaining stable operation of the entire network. Trust evaluation indicators are perspectives for evaluating trustworthiness, and include the existence of risks in network devices, countermeasures against those risks, the existence of malicious functions such as backdoors, inspection status, and the visibility status of device information.

[0027] The results of the trust evaluation are referenced by insurance companies when underwriting insurance for user businesses, etc. Since trust is used for judgment by third parties, including user businesses and insurance companies, it is desirable that it be expressed in a manner that makes it easy to make an objective judgment. However, trust is not limited to numerical values, and may be data in a format other than numerical values ​​such as A to C. Specifically, trust is, for example, as follows:

[0028] (1) Outage Risk Trustworthiness regarding outage risk is the possibility that a network device will be outage and the predicted outage time in the event of an outage. Alternatively, outage risk is the mean interval between outages or the mean time to recovery. Outage risk may also be the risk of outage of a portion of a network device. For example, a network device with a low outage risk is more trustworthy than a network device with a high outage risk.

[0029] (2) Information Leakage Risk Trustworthiness regarding information leakage risk refers to the presence or possibility of information leakage for a network device, and the status of measures to prevent information leakage. The status of measures to prevent information leakage may be, for example, whether all measures to prevent information leakage have been implemented, whether measures to prevent serious information leakage have been implemented, whether measures to prevent information leakage have been identified, or whether measures are not identified. For example, a network device with a low risk of information leakage is more trustworthy than a network device with a high risk of information leakage.

[0030] (3) Backdoor The trustworthiness of a backdoor refers to the presence or absence of a backdoor in a network device, or the possibility of the existence of a backdoor. Alternatively, the trustworthiness of a backdoor may refer to the backdoor inspection status, such as the backdoor inspection method, inspection scope, or inspection time of the network device. Examples of the backdoor inspection method include inspection using an inspection application, binary inspection of a program running on the network device, or source code inspection of the program. For example, a network device that has been inspected for a backdoor has higher trustworthiness than a network device that has not been inspected for a backdoor.

[0031] (4) Risk Assessment The reliability of risk assessment refers to whether or not a risk assessment inspection has been conducted on the vulnerabilities of network devices, the inspection results, the implementation status of countermeasures, the timing of the inspection, or the time elapsed since the inspection, etc. The implementation status of vulnerability countermeasures includes whether countermeasures have been implemented for all vulnerabilities, whether countermeasures for serious vulnerabilities have been implemented, whether countermeasures for vulnerabilities have been identified, or whether countermeasures are not identified, etc. For example, network devices that have undergone risk assessment inspections are more trustworthy than network devices that have not undergone risk assessment inspections.

[0032] (5) Incident Response The reliability of incident response is the defined state of the response when an incident occurs in a network. The reliability of incident response may include the range of incidents for which a response is defined, such as a response for a serious incident. For example, a network device for which an incident response is defined is more reliable than a network device for which an incident response is not defined.

[0033] (6) Performance Evaluation Test Results The reliability of the performance evaluation test results is the presence or absence of the performance evaluation test results and the performance content of the test results. The reliability of the performance evaluation test results may be the test status of the performance evaluation, such as the performance evaluation test method, test scope, test time, or elapsed time since the test was conducted. For example, a network device whose performance has been tested is more reliable than a network device whose performance has not been tested.

[0034] (7) Business The trustworthiness of a business is the user business's understanding of the business and its preparation for business recovery work. The understanding of the business is, for example, the understanding of the scope of impact of each business, or the understanding of the priority of each business. For example, a network device whose business is understood is more trustworthy than a network device whose business is not understood. The preparation for recovery work is, for example, the preparation for recovering a business with a large scope of impact or a business with a high priority when an incident occurs. For example, a network device for which recovery work is prepared is more trustworthy than a network device for which recovery work is not prepared.

[0035] (8) Developer The trustworthiness of a developer is the state of understanding of the attributes of the developer of a network device. The understanding state may be, for example, that the attributes of all developers are understood, that some attributes are not understood, or that some developers' attributes are not understood. The attributes may be, for example, nationality, affiliation, development location, or past experience. The developer attributes are not limited to the attributes of individuals, but may also be the attributes of corporations or organizations, such as development manufacturers. For example, a network device whose developer attributes are understood is more trustworthy than a network device whose developer attributes are not understood.

[0036] (9) Supply Chain The trustworthiness of a supply chain refers to the trustworthiness of companies, etc., associated with the supply chain of network devices. Companies associated with the supply chain are, for example, companies that design, provide, maintain, and manage network devices. Furthermore, the trustworthiness of a company refers, for example, to the status of trust testing at each company and the details of the testing results. The status of testing refers to whether testing has been conducted, the extent to which testing has been conducted, or the extent to which testing has not been conducted. For example, a network device whose trustworthiness has been tested by companies that make up the supply chain is more trustworthy than a network device whose trustworthiness has not been tested by companies that make up the supply chain.

[0037] The trust evaluation index is an evaluation index for evaluating the trustworthiness of network devices that meets the needs of user businesses. For example, the trust evaluation index is an evaluation index for the above-mentioned trust items, such as "presence or absence of a backdoor." The trust evaluation index may be a single evaluation index, a collection of multiple evaluation indexes, an integration of multiple evaluation indexes, or an evaluation index calculated using multiple evaluation indexes, such as an average. The insurance company may create a trust evaluation index in accordance with the trustworthiness required of the user business's network devices, or may obtain a trust evaluation index from a third-party organization or a platform operator. The evaluation index acquisition unit 101 outputs the acquired trust evaluation index to the inspection unit 103.

[0038] The device information acquisition unit 102 is a means for acquiring device information of network devices on a network for which a user operator takes out insurance. The device information acquisition unit 102 acquires device information of a network device to be evaluated, for example, from the device information storage device 300. The device information is information necessary for evaluating the trustworthiness of a network device, and includes configuration information and inspection information. The device information storage device 300 stores, for example, the configuration information and inspection information associated with each network device.

[0039] Configuration information is, for example, hardware information and software information of network devices. Hardware information includes developer information, model numbers of chips, boards, ports, etc. that make up the hardware, and identifiers assigned to the hardware. Software information includes developer information, the OS (Operating System) that processes the hardware, software names such as libraries or applications, version information of the software, and code information of the software. Configuration information is updated when the configuration information is updated, such as when the software is upgraded.

[0040] The inspection information is information about the results of inspections based on the configuration information of network devices conducted by businesses along the supply chain from the procurement of network device components to delivery. The inspection information includes the above-mentioned backdoor or risk assessment inspections. After acquiring the device information of the network device to be evaluated, the device information acquisition unit 102 outputs the device information to the inspection unit 103.

[0041] The inspection unit 103 is a means for inspecting a network device using device information based on a trust evaluation index. A specific inspection method is as follows. That is, the inspection unit 103 creates inspection items for the network device to evaluate the trustworthiness of the network device based on the configuration information and the trust evaluation index. For example, the inspection unit 103 creates inspection items for evaluating the trust evaluation index for the network device to be evaluated.

[0042] That is, items to be inspected are predetermined for the above-mentioned trust evaluation indicators (1) to (9), and the inspection unit 103 selects an inspection item according to the trust evaluation indicator selected for the network device or network to be insured. For example, if the trust evaluation indicator is a backdoor, the inspection unit 103 creates an inspection item to inspect the possibility of a backdoor in the network device to be inspected. The inspection unit 103 may create multiple inspection items for one trust evaluation indicator, or may create one inspection item for multiple trust evaluation indicators.

[0043] Next, the inspection unit 103 inspects the network device using the evaluation criteria of the trust evaluation index for each created inspection item. The inspection unit 103 may indicate the inspection result for each trust evaluation index as a binary value of 0 or 100, or may indicate it as a specific rank such as A to C. Furthermore, the inspection unit 103 may indicate the inspection result for each trust evaluation index as a numerical value (score) such as 0 to 100%.

[0044] The evaluation unit 104 is a means for evaluating the trustworthiness based on the test results, and evaluates the trustworthiness of the network device comprehensively based on the test results of the trust evaluation indexes.

[0045] The evaluation unit 104 evaluates the trustworthiness by, for example, calculating the sum or average value of the test results of each trust evaluation index. Furthermore, the evaluation unit 104 may determine that the trustworthiness is not satisfied if the test result of any of the trust evaluation indexes is 0, or may determine that the trustworthiness is not satisfied if the test result of a predetermined trust evaluation index is equal to or less than a predetermined value. However, the method of evaluating the trustworthiness by the evaluation unit 104 is not limited to these.

[0046] The output unit 105 is a means for outputting the evaluation result of the trustworthiness of the network device. For example, the output unit 105 displays the evaluation result of the trustworthiness on an output device 510 such as a display. The output unit 105 may also output the evaluation result of the trustworthiness of the network device to a user business operator or an insurance company. The output unit 105 may also issue a certificate to certify the evaluation result of the trustworthiness. The certificate is issued to certify the evaluation result of the trustworthiness of the network device to third parties including the user business operator and the insurance company. In this case, the output unit 105 affixes a digital signature to the certificate describing the evaluation result of the trustworthiness and stores it in the device information storage device 300 together with the public key.

[0047] Next, the configuration of the insurance company terminal 200 will be described. When a certificate of the trust evaluation result is issued by the output unit 105, the insurance company terminal 200 performs processing up to determining the insurance premium. The certificate acquisition unit 202 is a means for acquiring the certificate issued by the evaluation device 100. The certificate acquisition unit 202 acquires the certificate stored in the device information storage device 300. The certificate acquisition unit 202 may also acquire from the user business the certificate that the user business acquired from the device information storage device 300. The certificate acquisition unit 202 outputs the acquired certificate to the comparison unit 203.

[0048] The matching unit 203 is a means for matching, based on the certificate, whether the network device installed in the user business is the same as the network device that is the subject of the insurance. Specifically, the matching unit 203 decrypts the hash value of the electronic signature included in the certificate input from the certificate acquisition unit 202 using the public key, and compares it with the hash value of the network device installed in the user business to match it with the network device installed in the user business. If the two network devices are not the same, the matching unit 203 requests a third-party organization to again evaluate the trustworthiness of the network device that is the same as the network device installed in the user business.

[0049] The determination unit 204 is a means for determining an insurance premium based on the evaluation result of the trustworthiness. The determination unit 204 increases or decreases the insurance premium from a predetermined standard insurance premium based on the level of trustworthiness for each trust evaluation index. For example, for (4) risk assessment, among the examples of the trust evaluation indexes described above, the determination unit 204 increases the insurance premium from the standard insurance premium if measures to address vulnerabilities are not known. On the other hand, the determination unit 204 decreases the insurance premium from the standard insurance premium if measures to address vulnerabilities are known. Note that the determination unit 204 may determine the degree of increase or decrease from the standard insurance premium based on the degree to which measures to address vulnerabilities are known.

[0050] Furthermore, for (5) incident response, one of the examples of the evaluation indexes for trustworthiness, the determination unit 204 reduces the insurance premium from the standard insurance premium if measures against risks are defined and incident response is easy. On the other hand, the determination unit 204 increases the insurance premium from the standard insurance premium if measures against risks are not defined and incident response is difficult.

[0051] Furthermore, the determination unit 204 further reduces the insurance premium for (7) business from the standard insurance premium if the company is ready to recover from a business range with a high priority when an incident occurs. On the other hand, the determination unit 204 increases the insurance premium from the standard insurance premium if the company is not ready to recover from a business range with a high priority when an incident occurs.

[0052] The determination unit 204 may notify the user operator of the insurance premium for the user operator's network determined in this manner.

[0053] The operation of the evaluation system 10 configured as above will be described with reference to the flowchart of FIG.

[0054] 3 is a flowchart showing an outline of the operation of the evaluation device 100 according to the first embodiment. Note that the processing according to this flowchart may be executed based on program control by the processor described above.

[0055] As shown in FIG. 3 , first, the evaluation index sending unit 201 in the insurance company terminal 200 sends the trust evaluation index used by the insurance company to the evaluation device 100 (step S101). Next, the evaluation index acquiring unit 101 in the evaluation device 100 acquires the trust evaluation index used by the insurance company from the insurance company terminal 200 (step S102). Next, the device information acquiring unit 102 acquires device information of the network devices on the network insured by the user company (step S103). Next, the inspection unit 103 inspects the network devices based on the trust evaluation index (step S104). Next, the evaluation unit 104 evaluates the trust based on the inspection results (step S105). Next, the output unit 105 issues a certificate to certify the trust evaluation results (step S106).

[0056] Meanwhile, the certificate acquisition unit 202 in the insurance company terminal 200 acquires the certificate issued by the evaluation device 100 (step S107). The verification unit 203 uses the certificate to verify whether the network device installed in the user company is the same as the insured network device (step S108). Finally, the determination unit 204 verifies the identity of both network devices, and then determines the insurance premium for the network configured by the network devices based on the trust evaluation result (step S109). This completes the operation of the evaluation system 10.

[0057] In the evaluation device 100 of this embodiment, the evaluation index acquisition unit 101 acquires trust evaluation indexes adopted by insurance companies, the inspection unit 103 inspects network devices based on the trust evaluation indexes, and the evaluation unit 104 evaluates the trustworthiness based on the inspection results. This makes it possible to evaluate the trustworthiness in accordance with the cyber insurance standards adopted by insurance companies.

[0058] In this embodiment, the output unit 105 issues a certificate by attaching a digital signature to the trust evaluation result. This ensures the legitimacy of the trust evaluation result. An insurance company that obtains a trust certificate can use the valid trust evaluation result, and can determine cyber insurance premiums for the user company's network based on the highly reliable trust evaluation result.

[0059] A modified example of this embodiment will be described, focusing on differences from the first embodiment. In the first embodiment, the inspection unit 103 performs all inspections for evaluating the trust evaluation index. In contrast, in the modified example, it is assumed that the user operator has already evaluated the trustworthiness of the network device. In this case, the inspection unit 103 uses the results of the already performed trust evaluation to inspect the network device only for items that have not been inspected. That is, the inspection unit 103 creates inspection items that have not been performed to evaluate the trust evaluation index. Next, the inspection unit 103 inspects the network device using the evaluation criteria of the trust evaluation index for each created inspection item. For example, if the presence or absence of a backdoor is included as an inspection item for the trust evaluation index, but a backdoor inspection has already been performed, the inspection unit 103 omits creating an inspection item for the presence or absence of a backdoor. Furthermore, the evaluation unit 104 evaluates the trustworthiness based on the inspection results performed by the inspection unit 103 and the inspection results already performed by the user operator. However, even if the user operator has evaluated the trustworthiness of the network device, if the inspection time is before the predetermined time, the inspection unit 103 may perform all inspections for evaluating the trust evaluation index without using the inspection results performed by the user operator. Note that the configuration of the evaluation device 100 other than the inspection unit 103 and the evaluation unit 104 is the same.

[0060] In this modification, when a user company evaluates the trustworthiness of network devices, the determination unit 204 in the insurance company terminal 200 determines the insurance premium based on the inspection items inspected by the inspection unit 103. Specifically, the determination unit 204 deducts from the insurance premium calculated based on the results of the trustworthiness evaluation the costs corresponding to the items not inspected by the inspection unit 103.

[0061] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.

[0062] For example, although multiple operations are described in a sequential order in the form of a flowchart, the order of description does not limit the order in which the multiple operations are performed. Therefore, when implementing each embodiment, the order of the multiple operations can be changed to the extent that it does not interfere with the content. In the flowchart of FIG. 3, in step S106, the output unit 105 issues a certificate to certify the trust evaluation result. However, the output unit 105 may simply output the trust evaluation result to the output device 510. In this case, subsequent processing in the insurance company terminal 200 is not performed.

[0063] REFERENCE SIGNS LIST 10 Evaluation system 100 Evaluation device 101 Evaluation index acquisition unit 102 Device information acquisition unit 103 Inspection unit 104 Evaluation unit 105 Output unit 200 Insurance company terminal 201 Evaluation index transmission unit 202 Certificate acquisition unit 203 Collation unit 204 Determination unit 300 Device information storage device

Claims

1. An evaluation index acquisition means for acquiring a trust evaluation index for evaluating the trustworthiness adopted by an insurance company; A device information acquisition means for acquiring device information of a network device on a network for which a user company is insured; an inspection means for inspecting the network device using the device information based on the trust evaluation index; An evaluation means for evaluating the trustworthiness based on the result of the inspection; and an output unit for outputting the evaluation result of the trustworthiness.

2. The evaluation device according to claim 1 , wherein the output means issues a certificate for certifying the result of the evaluation of the trustworthiness.

3. 2 . The evaluation device according to claim 1 , wherein, when the user company has evaluated the trustworthiness of the network device, the inspection means inspects the network device for items that were not inspected in the evaluation of the trustworthiness.

4. The evaluation device according to claim 1 , wherein the device information includes configuration information and inspection information of the network device.

5. A certificate acquisition means for acquiring a certificate issued by the evaluation device according to any one of claims 2 to 4; a verification means for verifying whether a network device installed in a user company is identical to a network device covered by the insurance based on the certificate; a determination means for determining an insurance premium for the network configured by the network devices based on a result of the evaluation of the trustworthiness after the verification; A terminal comprising:

6. The terminal according to claim 5 , wherein the determining means calculates the insurance premium based on the inspection items inspected when the user company has evaluated the trustworthiness of the network device.

7. a device information storage device that stores device information of the network device; An evaluation system comprising the evaluation device according to any one of claims 1 to 4, The evaluation device includes an evaluation index acquisition means for acquiring a trust evaluation index for evaluating the trustworthiness of an insurance company; a device information acquisition means for acquiring device information of a network device on a network insured by a user company from the device information storage device; an inspection means for inspecting the network device using the device information based on the trust evaluation index; An evaluation means for evaluating the trustworthiness based on the result of the inspection; an output means for issuing a certificate for attesting to the evaluation result of the trustworthiness, and storing the certificate in the device information storage device with an electronic signature attached thereto.

8. The computer Obtain a trust evaluation index to evaluate the trustworthiness of insurance companies, Obtaining device information of network devices on the network that the user company is insuring, Inspecting a network device using device information based on the trust evaluation index; Evaluating the reliability based on the results of the inspection; and outputting the evaluation result of the trust.

9. Obtain a trust evaluation index to evaluate the trustworthiness of insurance companies, Obtaining device information of network devices on the network that the user company is insuring, Inspecting a network device using device information based on the trust evaluation index; Evaluating the reliability based on the results of the inspection; A program for causing a computer to execute the process of outputting the evaluation result of the trust.