Edge network management node, application device, communication system, communication method, and program

The edge network management node addresses the challenge of verifying software image integrity by determining if the software image has been tampered with, ensuring that Edge Application Servers are deployed with unmodified images, thereby enhancing the reliability of edge network services.

WO2025121244A1PCT designated stage expired Publication Date: 2025-06-12NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/042205
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-07
Filing Date
2024-11-28
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing edge network management systems cannot verify whether a software image downloaded for deploying Edge Application Servers (EAS) is unmodified, leading to potential issues with the integrity and authenticity of the EAS deployment.

Method used

An edge network management node that acquires a software image and its digital signature from a storage device, determines if the software image has been tampered with based on the digital signature, and notifies an application device of the determination result.

Benefits of technology

Ensures that Edge Application Servers are deployed using unmodified software images, enhancing the integrity and authenticity of the edge network services provided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024042205_12062025_PF_FP_ABST
    Figure JP2024042205_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The purpose of the present invention is to provide an edge network management node in which an ASP can use EAS constructed by using an unaltered software image to provide a service. This edge network management node according to the present disclosure comprises: an acquisition unit that acquires, from a storage device, a software image used for constructing a virtual node and a digital signature pertaining to the software image; a determination unit that determines, on the basis of the digital signature, whether the software image has been altered; and a communication unit that notifies an application device, which provides a service using the virtual node, of the determination result pertaining to whether the software image has been altered.
Need to check novelty before this filing date? Find Prior Art

Description

Edge network management node, application device, communication system, communication method and program

[0001] The present disclosure relates to an edge network management node, an application device, a communication system, a communication method, and a program.

[0002] In recent years, the construction of networks using virtualization technology has been under consideration. For example, the 3GPP (registered trademark) 3rd Generation Partnership Project, which studies standard specifications for mobile networks, discloses a sequence for Edge Application Server (EAS) deployment in Non-Patent Document 1. An Application Service Provider (ASP) deploys an EAS, which is a virtualized system, in an Edge Data Network (EDN) by executing EAS deployment. In EAS deployment, an Edge Computing Service Provider (ECSP) downloads a software image from a predetermined storage device to start the virtualized EAS in the EDN. The ECSP starts the EAS in the EDN using the downloaded software image.

[0003] 3GPP TS 28.538 V18.4.0 (2023-09)

[0004] In order for an ASP to provide the desired services, it is necessary to properly deploy an EAS using an unaltered software image. However, the EAS deployment process disclosed in Cited Document 1 does not allow verification that the software image downloaded by the ECSP from the storage device is the correct software image. In other words, there is a problem that an EAS that has been deployed on the EDN may be started using a tampered software image.

[0005] The object of the present disclosure is to provide an edge network management node, application device, communication system, communication method, and program that allow an ASP to provide services using an EAS built using an unaltered software image.

[0006] An edge network management node according to a first aspect of the present disclosure includes an acquisition unit that acquires from a storage device a software image used to construct a virtual node and a digital signature related to the software image, a determination unit that determines whether the software image has been tampered with based on the digital signature, and a communication unit that notifies an application device that provides a service using the virtual node of the determination result regarding whether the software image has been tampered with.

[0007] An application device according to a second aspect of the present disclosure includes a generation unit that generates a digital signature for a software image used to construct a virtual node, and a communication unit that transmits the software image and the digital signature to a storage device, and the communication unit receives a determination result regarding whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.

[0008] A communication system according to a third aspect of the present disclosure includes an application device that transmits a software image used to construct a virtual node and a digital signature related to the software image to a storage device, and an edge network management node that acquires the software image and the digital signature from the storage device, determines whether the software image has been tampered with based on the digital signature, and transmits the determination result regarding whether the software image has been tampered with to the application device.

[0009] A communication method according to a fourth aspect of the present disclosure is executed in an edge network management node, which obtains from a storage device a software image used to construct a virtual node and a digital signature related to the software image, determines whether the software image has been tampered with based on the digital signature, and notifies an application device that provides a service using the virtual node of the determination result regarding whether the software image has been tampered with.

[0010] A communication method according to a fifth aspect of the present disclosure generates a digital signature for a software image used to construct a virtual node, transmits the software image and the digital signature to a storage device, and receives a determination result as to whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.

[0011] A program according to a sixth aspect of the present disclosure causes a computer to obtain from a storage device a software image used to construct a virtual node and a digital signature related to the software image, determine whether the software image has been tampered with based on the digital signature, and notify an application device that provides a service using the virtual node of the determination result regarding whether the software image has been tampered with.

[0012] A program according to a seventh aspect of the present disclosure causes a computer to generate a digital signature for a software image used to construct a virtual node, transmit the software image and the digital signature to a storage device, and receive a determination result regarding whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.

[0013] The present disclosure provides an edge network management node, application device, communication system, communication method, and program that allow an ASP to provide services using an EAS built using an unaltered software image.

[0014] FIG. 1 is a configuration diagram of an edge network management node according to the present disclosure. FIG. 2 is a diagram showing the flow of communication processing executed in an edge network management node according to the present disclosure. FIG. 3 is a diagram showing the configuration diagram of an application device according to the present disclosure. FIG. 4 is a diagram showing the flow of communication processing executed in an application device according to the present disclosure. FIG. 5 is a diagram showing the configuration diagram of a communication system according to the present disclosure. FIG. 6 is a diagram showing the flow of a recording process for recording a software image in a storage device according to the present disclosure. FIG. 7 is a diagram showing the flow of a process related to an integrity check of a software image according to the present disclosure. FIG. 8 is a diagram showing the flow of a process for notifying an ASP of the result of an integrity check according to the present disclosure. FIG. 9 is a diagram showing the configuration diagram of an edge network management node etc. according to the present disclosure.

[0015] (First Embodiment) Hereinafter, a configuration example of an edge network management node 10 will be described with reference to Fig. 1. The edge network management node 10 may be a computer device that operates when a processor executes a program stored in a memory. The edge network management node 10 may be, for example, a server device. The node may correspond to an entity (device) or a function.

[0016] The edge network may be an edge data network (EDN) that supports an architecture for enabling edge applications. The edge data network may also be referred to as a local data network. The edge application may be an application used to realize edge computing or edge computing services in the edge network.

[0017] The edge network management node 10 may be a node that provides an edge computing service in an edge network. In other words, the edge network management node 10 may be a node managed by an edge computing service provider (ECSP) that provides an edge computing service in an edge network.

[0018] The edge network management node 10 has an acquisition unit 11, a determination unit 12, and a communication unit 13. The acquisition unit 11, the determination unit 12, and the communication unit 13 may be software or modules that perform processing when a processor executes a program stored in a memory, or the acquisition unit 11, the determination unit 12, and the communication unit 13 may be hardware such as a circuit or a chip.

[0019] The acquisition unit 11 acquires a software image used to build a virtual node and a digital signature related to the software image from a storage device. The virtual node may be an edge application that functions as a network function in an edge network. The edge application may be an application that is started using the software image. For example, the virtual node may be an EAS.

[0020] The digital signature may be, for example, a unique value associated with the software image. In other words, the digital signature may be a value generated based on the software image. Specifically, the digital signature may be a hash value obtained by applying a hash function to the software image.

[0021] The storage device is assumed to hold in advance a software image and a digital signature related to the software image. Holding may be rephrased as storing, memorizing, recording, or managing.

[0022] The acquisition unit 11 acquiring the software image and the digital signature from the storage device may be rephrased as the acquisition unit 11 downloading the software image and the digital signature from the storage device. Alternatively, the acquisition unit 11 acquiring the software image and the digital signature from the storage device may be the acquisition unit 11 receiving the software image and the digital signature transmitted from the storage device.

[0023] The determination unit 12 determines whether the software image associated with the digital signature has been tampered with, based on the digital signature. Determining whether the software image has been tampered with may mean determining the integrity and authenticity of the software image.

[0024] The determination unit 12 may generate a digital signature using the acquired software image. The determination unit 12 may determine whether the software image has been tampered with by comparing the generated digital signature with a digital signature acquired from the storage device. The determination unit 12 may determine that the software image has not been tampered with if the generated digital signature matches the digital signature acquired from the storage device. The determination unit 12 may determine that the software image has been tampered with if the generated digital signature does not match the digital signature acquired from the storage device.

[0025] The communication unit 13 transmits or notifies the result of the determination as to whether the software image has been tampered with to the application device 20 that provides a service using the virtual node. The application device 20 may be, for example, a device managed or operated by an ASP.

[0026] By receiving the determination result regarding whether the software image has been tampered with, the application device 20 can recognize whether the virtual node activated in the edge network is operating normally or whether the virtual node will be activated normally. Alternatively, by receiving the determination result regarding whether the software image has been tampered with, the application device 20 may determine whether to provide a service using the activated virtual node.

[0027] Next, the flow of communication processing executed in the edge network management node 10 will be described with reference to Figure 2. First, the acquisition unit 11 acquires from a storage device a software image used to build a virtual node and a digital signature associated with the software image (S11). Next, the determination unit 12 determines whether the software image has been tampered with based on the digital signature (S12). Next, the communication unit 13 notifies an application device that provides a service using the virtual node of the determination result as to whether the software image has been tampered with (S13).

[0028] Next, a configuration example of the application device 20 will be described with reference to Fig. 3. The application device 20 may be a computer device that operates when a processor executes a program stored in a memory.

[0029] The application device 20 includes a generation unit 21 and a communication unit 22. The generation unit 21 and the communication unit 22 may be software or modules that are executed by a processor executing a program stored in a memory, or may be hardware such as a circuit or a chip.

[0030] The generation unit 21 generates a digital signature for a software image used to build a virtual node. The generation unit 21 may generate a hash value as the digital signature by, for example, applying a hash function to the software image.

[0031] The communication unit 22 transmits the software image and a digital signature associated with the software image to the storage device. The communication unit 22 may encrypt the software image and the digital signature before transmitting them to the storage device.

[0032] The communication unit 22 receives a determination result as to whether or not a software image has been tampered with from the edge network management node 10. The software image to be determined as to whether or not it has been tampered with is the software image that the communication unit 22 has sent to the storage device.

[0033] Next, the flow of communication processing executed in the application device 20 will be described with reference to Figure 4. First, the generation unit 21 generates a digital signature for a software image used to build a virtual node (S21). Next, the communication unit 22 transmits the software image and the digital signature to the storage device (S22). Next, the communication unit 22 receives a determination result from the edge network management node 10 as to whether the software image has been tampered with (S23).

[0034] As described above, the edge network management node 10 determines whether the software image obtained from the storage device has been tampered with based on the digital signature. Furthermore, the edge network management node 10 transmits the determination result regarding whether the software image has been tampered with to the application device 20.

[0035] The application apparatus 20 receives the determination result regarding whether the software image has been tampered with. This allows the application apparatus 20 to determine whether the virtual node activated based on the software image is operating normally or whether the virtual node is activated normally based on the software image. Alternatively, the application apparatus 20 may determine whether to provide a service using the activated virtual node based on the determination result regarding whether the software image has been tampered with. That is, the application apparatus 20 may stop providing a service using the virtual node activated using the tampered software image.

[0036] Second Embodiment Next, an example of the configuration of a communication system will be described with reference to Fig. 5. The communication system includes an ASP 30, an ECSP 40, a MANO (Management and Orchestration) 50, an edge data network 60, a storage device 70, and an ECSP management system 80. EAS VNFs (Virtual Network Functions) 61 to 63 are deployed or activated on the edge data network 60. "Deploying or activating the EAS VNFs (Virtual Network Functions) 61 to 63 on the edge data network 60" can be rephrased as "the EAS VNFs (Virtual Network Functions) 61 to 63 are constructed on the edge data network 60."

[0037] The ECSP management system 80 may be part of a 3GPP management system. The ECSP management system 80 may enable the ASP 30, the ECSP 40, or the like to manage the edge data network 60 using a management service defined in 3GPP.

[0038] The ASP 30 corresponds to the application device 20 in FIG. 3 . The ECSP 40 corresponds to the edge network management node 10 in FIG. 1 . The ASP 30 and the ECSP 40 may be referred to as consumers that can use resources provided by the ECSP management system 80. The resources may be computer resources such as memory, a processor, and an operating system. The ECSP management system 80 may also be referred to as a producer that provides resources. When the ASP 30, which is a consumer, communicates with the ECSP 40 via the ECSP management system 80, the ECSP 40 may communicate with the ASP 30 as a producer.

[0039] The edge data network 60 may be, for example, a network provided to perform data processing at a location close to a user terminal (e.g., UE (User Equipment)) so as to reduce delays occurring in the user terminal. The user terminal may be a terminal that receives or uses a network service. A location close to the user terminal may be, for example, a location closer to the user terminal than a cloud system. The edge data network 60 may be, for example, a network provided to perform distributed processing of data processing that had been performed in a cloud system.

[0040] The EAS VNFs 61 to 63 are a group of virtualized network functions that operate as EAS on the Network Functions Virtualization Infrastructure (NFVI). NFVI is a platform that enables physical resources such as computing, storage, and networks to be flexibly handled as virtual resources. Here, the edge data network 60 is intended to be an NFVI. The EAS VNFs 61 to 63 may be the same network function or different network functions.

[0041] The MANO 50 is responsible for the integrated management, control, and optimization of network services and resources in the NFV architecture including the NFVI and EAS VNFs 61-63. For example, the MANO 50 may determine specific function deployment using the EAS VNFs 61-63 based on the requirements for the network service. Furthermore, the MANO 50 may dynamically optimize the resource and function deployment of the entire edge data network 60. Dynamic optimization may include, for example, relocating functions so that network services can be continuously provided when a failure occurs or resources become constrained.

[0042] The storage device 70 holds software images used to activate or deploy the EAS VNFs 61-63 on the edge data network 60. Holding may be rephrased as storing, memorizing, recording, managing, or the like. In addition to the software images, the storage device 70 may also hold related information about the software images. The related information may be, for example, security information or other information related to the software images. Specifically, the security information may be key information used for digital signatures, encryption, or decryption.

[0043] 5, the storage device 70 may be a device separate from the MANO 50, or may be a part of the MANO 50. In other words, the storage device 70 may be used as an integral part of the MANO 50, or may be used as a device separate from the MANO 50. The storage device 70 may be a single unit, or may be a group of units in which a plurality of storage devices 70 operate in cooperation with one another.

[0044] Next, the flow of the recording process for recording a software image in the storage device 70 will be described with reference to FIG. 6. First, the ASP 30 generates a public key and a private key (S31). The public key and the private key are used as a pair. For example, data encrypted using the private key is decrypted using the public key of the pair. The public key may also be called a decryption key.

[0045] Next, the ASP 30 generates a digital signature based on the software image (S32). The software image may be, for example, a program or application used to launch one of the EAS VNFs 61-63, and may further include algorithms, etc. Assume that the ASP 30 previously stores software images related to the EAS VNFs required to provide the application service. Alternatively, the ASP 30 may acquire the software images from a device that generated the software images related to the EAS VNFs. Assume, for example, that the ASP 30 requires EAS VNFs 61-63, each with different functions, to provide the application service. In this case, the ASP 30 may store a software image related to the EAS VNF 61, a software image related to the EAS VNF 62, and a software image related to the EAS VNF 63.

[0046] The ASP 30 may generate a hash value as a digital signature by hashing the software image, for example. In other words, the ASP 30 may generate a hash value by applying a hash function to the software image. The hash function may be, for example, SHA-256 or SHA-512. The ASP 30 may generate a hash value by converting the entire software image using the hash function. Alternatively, the ASP 30 may generate a hash value by converting a portion of the data in the software image using the hash function.

[0047] Next, the ASP 30 transmits the software image and the digital signature generated based on the software image to the storage device 70 (S33). The ASP 30 may transmit the digital signature encrypted using the private key generated in step S31 to the storage device 70. Furthermore, if the ASP 30 generated the digital signature using part of the data included in the software image, it may also transmit identification information of the data used along with the software image and the digital signature. The identification information may be, for example, information indicating the bit position of the used data, or information indicating the starting position of the bit of the used data and the data length of the used data.

[0048] The storage device 70 stores the received software image and digital signature in association with each other. When the storage device 70 receives data identification information, it also records the data identification information in association with the software image and digital signature.

[0049] Next, the flow of processing related to the integrity check of a software image will be explained using FIG. 7 . First, the ASP 30 executes a createMOI (Managed Object Instance) operation with the ECSP 40. Specifically, the ASP 30 requests the ECSP 40 to generate an MOI based on the EAS Requirements IOC (Information Object Class) (S41). The request may be a request message. Alternatively, the createMOI operation may be the ASP 30 accessing or using a service provided by the ECSP 40. For example, the ASP 30 may use a service provided by the ECSP 40 by communicating with the ECSP 40 via HTTP (Hypertext Transfer Protocol).

[0050] The MOI is, for example, an entity (=instance) of a managed object corresponding to one of the EAS VNFs 61 to 63, and holds management data related to one of the EAS VNFs 61 to 63. A single createMOI operation may generate an MOI for managing the EAS VNFs 61 to 63, and then generate EAS VNF instances corresponding to each of the MOIs. Alternatively, the createMOI operation may be repeatedly executed to generate each EAS VNF instance.

[0051] The EAS Requirements IOC includes deployment requirements. The deployment request may be used, for example, to request instantiation of an EAS VNF. The EAS VNF instantiation may be, for example, starting the EAS VNF on the edge data network 60 or performing a deployment process for the EAS VNF on the edge data network 60. More specifically, the EAS VNF instantiation may be starting the EAS VNF using optimized resources on the edge data network 60. The EAS VNF instantiation may be performed in conjunction with MANO 50.

[0052] The deployment request may include attributes indicating, for example, software image information and virtual resource information. Either the software image information or the virtual resource information may include, for example, information regarding a software image location or a minimum required RAM (minimum random access memory). Furthermore, either the software image information or the virtual resource information may indicate, for example, a software image location or a minimum required RAM (minimum random access memory). The EAS Requirements IOC also includes the public key generated in step S31 of FIG. 6. The public key may be included in either the software image information or the virtual resource information, or may be associated with an attribute included in the deployment request.

[0053] Next, the ECSP 40 responds to the request for generating an MOI based on the EAS Requirement IOC notified from the ASP 30 (S42). Responding may mean sending a message regarding the response to the ASP 30. The response here indicates that the activation process or deployment process of the EAS VNF is in progress.

[0054] Next, the ECSP 40 acquires the software image according to the storage location of the software image included in the software image information (S43). The storage location of the software image may be indicated using a URL in the software image descriptor, or may be other information indicating the storage location. The ECSP 40 may download the software image by accessing the URL indicated as the storage location of the software image. Here, a URL for accessing the storage device 70 may be used as the storage location of the software image. In step S43, the ECSP 40 may access the storage device 70 to download the software image. Alternatively, in step S43, the ECSP 40 may send a message to the storage device 70 to download or acquire the software image.

[0055] Next, the ECSP 40 receives a response message including the software image and the digital signature related to the software image from the storage device 70 (S44). In other words, the ECSP 40 may obtain the software image and the digital signature related to the software image using HTTP communication.

[0056] Next, the ECSP 40 performs an integrity check on the software image (S45). The ECSP 40 decrypts the encrypted digital signature using the public key received in step S41. Furthermore, the ECSP 40 generates a digital signature as security information using the downloaded software image. For example, the ECSP 40 generates the digital signature by hashing the software image using the same hash function as the hash function used to generate the digital signature in the ASP 30. The hash function used to generate the digital signature may be predetermined by the ASP 30 and the ECSP 40. Alternatively, the hash function used to generate the digital signature may be notified to the ECSP 40 by the ASP 30 in step S41.

[0057] The ECSP 40 compares the decrypted digital signature with the newly generated digital signature, and if the values ​​match, determines that the downloaded software image has not been tampered with.The ECSP 40 compares the decrypted digital signature with the newly generated digital signature, and if the values ​​do not match, determines that the downloaded software image has been tampered with.

[0058] Steps S43 to S45 may be processes that are executed as a result of the ECSP 40 analyzing the EAS Requirement IOC.

[0059] Next, the ECSP 40 notifies the ASP 30 of the results of the integrity check (S46). For example, the ECSP 40 notifies the ASP 30 of information indicating whether the software image downloaded from the storage device 70 has been tampered with. The notification may involve sending a message including the results of the integrity check to the ASP 30. The ECSP 40 may also send software image information including the determination result to the ASP 30. The determination result may be indicated as an attribute. The ECSP 40 may also send a message regarding step S45 to the ASP 30 after performing an integrity check on the software image in step S45.

[0060] After notifying the ASP 30 of the results of the integrity check, the ECSP 40 may use the downloaded software image to perform VNF instantiation to deploy or activate the EAS VNFs 61-63 on the edge data network 60.

[0061] If ASP 30 receives information that the software image has not been tampered with, it can recognize that the EAS VNFs 61 to 63 constructed in the edge data network 60 were constructed using an untampered software image.

[0062] Furthermore, if the ASP 30 receives information indicating that the software image has been tampered with, it can recognize that the construction of the EAS VNFs 61 to 63 has failed. Because the software image has been tampered with, there is a possibility that the construction of the EAS VNFs 61 to 63 will result in an error, or that the EAS VNFs 61 to 63 will have been constructed with incorrect data.

[0063] As described above, the ASP 30 receives the results of the integrity check for the software image from the ECSP 40. Specifically, the ASP 30 receives the results of the integrity check from an ECSP 40 that is different from the storage device 70 that stores the software image. This enables the ASP 30 to determine whether the EAS VNFs 61 to 63 activated in the edge data network 60 have been built using a tampered software image.

[0064] For example, if the ASP 30 determines that the EAS VNFs 61 to 63 have been constructed using a tampered software image, the ASP 30 may stop providing services, register a new software image, etc. In this way, the ASP 30 can execute processing to prompt the reconstruction of the EAS VNFs 61 to 63 using a software image that has not been tampered with.

[0065] Furthermore, if the ECSP 40 determines that the software image has been tampered with as a result of the integrity check, the ECSP 40 may decide not to perform VNF instantiation. In this case, instead of notifying the ASP 30 of the integrity check result, the ECSP 40 may notify the ASP 30 of information indicating that VNF ​​instantiation will not be performed.

[0066] Third Embodiment Next, a process flow for notifying the ASP 30 of an integrity check result different from that shown in FIG. 7 will be described with reference to FIG.

[0067] In Fig. 8, the same processes as steps S41 to S45 in Fig. 7 are executed. Next, the ECSP 40 executes VNF instantiation in cooperation with the MANO 50 (S51).

[0068] Next, the ECSP 40 notifies the ASP 30 of the execution result of the VNF instantiation (S52). Here, the ECSP 40 notifies the ASP 30 of the result of the integrity check along with the execution result of the VNF instantiation. For example, the ECSP 40 may notify the ASP 30 of the result of the integrity check if the VNF instantiation was executed successfully. If the result of the integrity check indicates that the software image has been tampered with, the ASP 30 can recognize that the EAS VNFs 61 to 63 activated in the edge data network 60 were built using a tampered software image. If the result of the integrity check indicates that the software image has not been tampered with, the ASP 30 can recognize that the EAS VNFs 61 to 63 were built using an untampered software image.

[0069] Furthermore, if the ECSP 40 determines as a result of the integrity check that the software image has not been tampered with, the ECSP 40 may execute VNF instantiation. In this case, the execution of VNF instantiation indicates that the software image has not been tampered with. Therefore, when the ASP 30 is notified of the execution result of VNF instantiation, the ECSP 40 may recognize that the software image has not been tampered with.

[0070] Furthermore, if the VNF instantiation is not executed normally, the ECSP 40 may or may not notify the result of the integrity check to the ASP 30. For example, if the ASP 30 is notified that the VNF instantiation was not executed normally and that the software image has been tampered with, the ECSP 40 may infer that the VNF instantiation was not executed normally because the software image has been tampered with.

[0071] FIG. 9 is a block diagram showing a configuration example of the edge network management node 10, application device 20, ASP 30, ECSP 40, and MANO 50 (hereinafter referred to as edge network management node 10, etc.) described in the above embodiment. Referring to FIG. 9, the edge network management node 10, etc. includes a network interface 1201, a processor 1202, and a memory 1203. The network interface 1201 may be used to communicate with network nodes. The network interface 1201 may include, for example, a network interface card (NIC) compliant with the IEEE 802.3 series. IEEE stands for Institute of Electrical and Electronics Engineers.

[0072] The processor 1202 reads and executes software (computer programs) from the memory 1203 to perform the processing of the edge network management node 10 and the like described using flowcharts in the above-described embodiments. The processor 1202 may be, for example, a microprocessor, an MPU, or a CPU. The processor 1202 may include multiple processors.

[0073] The memory 1203 is configured by a combination of volatile memory and non-volatile memory. The memory 1203 may include storage located remotely from the processor 1202. In this case, the processor 1202 may access the memory 1203 via an I / O (Input / Output) interface (not shown).

[0074] 9, the memory 1203 is used to store software modules. The processor 1202 reads and executes these software modules from the memory 1203, thereby performing the processing of the edge network management node 10 and the like described in the above-described embodiment.

[0075] As explained using Figure 9, each of the processors possessed by the edge network management node 10, etc. in the above-mentioned embodiments executes one or more programs including a group of instructions for causing a computer to perform the algorithm explained using the drawings.

[0076] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disc (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.

[0077] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0078] Each drawing is merely an example for describing one or more embodiments. Each drawing may not relate to only one particular embodiment, but may also relate to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.

[0079] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. (Supplementary Note 1) An edge network management node comprising: an acquisition unit that acquires, from a storage device, a software image used to build a virtual node and a digital signature related to the software image; a determination unit that determines whether the software image has been tampered with based on the digital signature; and a communication unit that notifies an application device that provides a service using the virtual node of the determination result as to whether the software image has been tampered with. (Supplementary Note 2) The edge network management node according to Supplementary Note 1, wherein the communication unit receives a decryption key for decrypting the digital signature from the application device, and the determination unit generates security information using the software image and determines whether the software image has been tampered with based on the digital signature decrypted using the decryption key and the security information. (Supplementary Note 3) The edge network management node according to Supplementary Note 1 or 2, wherein the communication unit notifies the application device of the determination result before notifying the application device of the execution result of the virtual node construction. (Supplementary Note 4) The edge network management node according to Supplementary Note 1 or 2, wherein the communication unit notifies the application device of the determination result together with the execution result of construction of the virtual node. (Supplementary Note 5) The edge network management node according to Supplementary Note 3, wherein the communication unit notifies the application device of the determination result before notifying the application device of the execution result of instantiation of a virtual network function that constitutes the virtual node using the software image. (Supplementary Note 6) The edge network management node according to Supplementary Note 4, wherein the communication unit notifies the application device of the determination result together with the execution result of instantiation of a virtual network function that constitutes the virtual node using the software image.(Supplementary Note 7) The edge network management node according to any one of Supplementary Notes 1 to 6, wherein the communication unit notifies the application device of software image information including an attribute indicating the determination result. (Supplementary Note 8) An application device comprising: a generation unit that generates a digital signature for a software image used to build a virtual node; and a communication unit that transmits the software image and the digital signature to a storage device, wherein the communication unit receives a determination result as to whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature. (Supplementary Note 9) The application device according to Supplementary Note 8, wherein the generation unit encrypts the digital signature and generates a decryption key for decrypting the encrypted digital signature, and the communication unit transmits the decryption key to the edge network management node. (Supplementary Note 10) A communication system comprising: an application device that transmits a software image used to construct a virtual node and a digital signature related to the software image to a storage device; and an edge network management node that acquires the software image and the digital signature from the storage device, determines whether the software image has been tampered with based on the digital signature, and transmits the determination result as to whether the software image has been tampered with to the application device. (Supplementary Note 11) A communication method executed in an edge network management node, which acquires a software image used to construct a virtual node and a digital signature related to the software image from a storage device, determines whether the software image has been tampered with based on the digital signature, and notifies an application device that provides a service using the virtual node of the determination result as to whether the software image has been tampered with.(Supplementary Note 12) The communication method according to Supplementary Note 11, receiving a decryption key for decrypting the digital signature from the application device before determining whether the software image has been tampered with, and, when determining whether the software image has been tampered with, generating security information using the software image, and determining whether the software image has been tampered with based on the digital signature decrypted using the decryption key and the security information. (Supplementary Note 13) The communication method according to Supplementary Note 11 or 12, notifying the application device of the determination result before notifying the application device of the execution result of construction of the virtual node. (Supplementary Note 14) The communication method according to Supplementary Note 11 or 12, notifying the application device of the determination result together with the execution result of construction of the virtual node. (Supplementary Note 15) The communication method according to Supplementary Note 13, notifying the application device of the determination result before notifying the application device of the execution result of instantiation of a virtual network function that configures the virtual node using the software image. (Supplementary Note 16) The communication method according to Supplementary Note 14, wherein the application device is notified of the determination result together with the execution result of instantiation of a virtual network function that configures the virtual node using the software image. (Supplementary Note 17) The communication method according to any one of Supplements 11 to 16, wherein the communication unit notifies the application device of software image information including an attribute that indicates the determination result. (Supplementary Note 18) A communication method executed in an application device, comprising: generating a digital signature for a software image used to construct a virtual node; transmitting the software image and the digital signature to a storage device; and receiving a determination result as to whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.(Supplementary Note 19) A program that causes a computer to execute the following steps: acquire a software image used to construct a virtual node and a digital signature for the software image from a storage device, determine whether the software image has been tampered with based on the digital signature, and notify an application device that provides a service using the virtual node of the determination result as to whether the software image has been tampered with. (Supplementary Note 20) A program that causes a computer to execute the following steps: generate a digital signature for the software image used to construct a virtual node, send the software image and the digital signature to a storage device, and receive the determination result as to whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.

[0080] Some or all of the elements (e.g., configurations and functions) described in Supplementary Notes 2 to 7 that are dependent on Supplementary Note 1 may also be dependent on Supplementary Notes 11 and 19 in the same dependency relationship as Supplementary Notes 2 to 7. Some or all of the elements (e.g., configurations and functions) described in Supplementary Note 9 that are dependent on Supplementary Note 8 may also be dependent on Supplementary Note 18 and Supplementary Note 20 in the same dependency relationship as Supplementary Note 9. Some or all of the elements described in any Supplementary Note may be applicable to various hardware, software, recording means for recording software, systems, and methods.

[0081] This application claims priority based on Japanese Patent Application No. 2023-206720, filed December 7, 2023, the disclosure of which is incorporated herein by reference in its entirety.

[0082] REFERENCE SIGNS LIST 10 Edge network management node 11 Acquisition unit 12 Determination unit 13 Communication unit 20 Application device 21 Generation unit 22 Communication unit 30 ASP 40 ECSP 50 MANO 60 Edge data network 61 EAS VNF 62 EAS VNF 63 EAS VNF 70 Storage device 80 ECSP management system

Claims

1. An edge network management node comprising: an acquisition means for acquiring from a storage device a software image used to construct a virtual node and a digital signature related to the software image; a determination means for determining whether the software image has been tampered with based on the digital signature; and a communication means for notifying an application device that provides a service using the virtual node of the determination result as to whether the software image has been tampered with.

2. An edge network management node as described in claim 1, wherein the communication means receives a decryption key for decrypting the digital signature from the application device, and the determination means generates security information using the software image and determines whether the software image has been tampered with based on the digital signature decrypted using the decryption key and the security information.

3. An edge network management node as described in claim 1 or 2, wherein the communication means notifies the application device of the judgment result before notifying the application device of the execution result of the construction of the virtual node.

4. The edge network management node according to claim 1 or 2, wherein the communication means notifies the application device of the judgment result together with the execution result of the construction of the virtual node.

5. An edge network management node as described in claim 3, wherein the communication means notifies the application device of the judgment result before notifying the application device of the execution result of instantiating a virtual network function that constitutes the virtual node using the software image.

6. The edge network management node according to claim 4, wherein the communication means notifies the application device of the judgment result together with the execution result of instantiating a virtual network function that configures the virtual node using the software image.

7. An edge network management node according to any one of claims 1 to 6, wherein said communication means notifies said application device of software image information including an attribute indicating said determination result.

8. An application device comprising: a generation means for generating a digital signature for a software image used to construct a virtual node; and a communication means for transmitting the software image and the digital signature to a storage device, wherein the communication means receives a determination result as to whether or not the software image has been tampered with from an edge network management node which determines whether or not the software image has been tampered with based on the digital signature.

9. The application device according to claim 8, wherein the generation means encrypts the digital signature and generates a decryption key for decrypting the encrypted digital signature, and the communication means transmits the decryption key to the edge network management node.

10. A communications system comprising: an application device that transmits a software image used to construct a virtual node and a digital signature related to the software image to a storage device; and an edge network management node that acquires the software image and the digital signature from the storage device, determines whether the software image has been tampered with based on the digital signature, and transmits the determination result regarding whether the software image has been tampered with to the application device.

11. A communications method executed in an edge network management node, which comprises obtaining a software image used to construct a virtual node and a digital signature relating to the software image from a storage device, determining whether the software image has been tampered with based on the digital signature, and notifying an application device that provides a service using the virtual node of the determination result as to whether the software image has been tampered with.

12. A communications method executed in an application device, comprising: generating a digital signature for a software image used to construct a virtual node; transmitting the software image and the digital signature to a storage device; and receiving a determination result as to whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.

13. A program that causes a computer to execute the following steps: obtain a software image used to construct a virtual node and a digital signature related to the software image from a storage device; determine whether or not the software image has been tampered with based on the digital signature; and notify an application device that provides a service using the virtual node of the determination result as to whether or not the software image has been tampered with.

14. A program that causes a computer to generate a digital signature for a software image used to construct a virtual node, transmit the software image and the digital signature to a storage device, and receive a determination result as to whether the software image has been tampered with from an edge network management node that determines whether the software image has been tampered with based on the digital signature.

Citation Information

Patent Citations

  • Computer system and virtual computer management method

    JP2014154050A

  • Key revocation for edge devices

    US20220209946A1

  • Virtual network system, virtual network control method, integrated control device, control device, and control method and control program therefor

    WO2016132783A1

  • Methods and apparatus for enhanced lifecycle management in 5g edge computing servers

    WO2023018727A1