Network setting device and network setting method
The network setting device addresses the challenge of seamless access across multiple networks by configuring relay devices based on authentication notifications, ensuring authorized terminals connect with appropriate services and bandwidth, regardless of network changes.
Patent Information
- Application Number
- PCT/JP2024/006239
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-21
- Publication Date
- 2025-08-28
AI Technical Summary
Existing technologies, such as SORACOM Gate Device LAN Connection and SORACOM Air, are limited to single-network environments and do not support bandwidth control according to service menus, making it difficult to provide seamless network access and authorized services across multiple networks.
A network setting device that receives authentication notifications from authentication devices on different networks, acquires setting information from a database, and configures relay devices to enable authorized terminals to connect with authorized services and bandwidth, allowing seamless service provision across multiple networks.
Enables authorized terminals to connect with authorized service content and bandwidth without manual network configuration, ensuring continuous service availability even when terminals move between networks.
Smart Images

Figure JP2024006239_28082025_PF_FP_ABST
Abstract
Description
Network setting device and network setting method
[0001] The present disclosure relates to a network configuration device and a network configuration method.
[0002] Recently, even in a multi-access network environment, there is an increasing demand for services to be provided by automatically opening a network on demand, and there is also a demand for the ability to set access according to the service menu.
[0003] For example, when a service provider wants to provide a service by combining multiple networks (such as private networks) provided by different business companies, the service provider is required to provide network communication between terminals and servers on demand, and to be able to seamlessly provide authorized services only to authorized terminals, regardless of which private network the terminal belongs to.
[0004] SORACOM, "SORACOM Gate Device LAN Connection", [online], Internet <https: / / soracom.jp / services / gate / > SORACOM, "SORACOM Air", [online], Internet <https: / / soracom.jp / services / air / >
[0005] Non-Patent Documents 1 and 2 are technologies for realizing terminal-to-terminal communication or communication from a terminal to a server. Non-Patent Documents 1 and 2 control network relay devices, but do not consider control according to service menus, such as bandwidth control. Furthermore, Non-Patent Documents 1 and 2 are only capable of connecting to a single network and are not compatible with multi-access environments.
[0006] The present disclosure has been made in consideration of the above circumstances, and an object of the present disclosure is to provide a technology for constructing a network on demand that allows authorized terminals to connect with authorized service content.
[0007] In order to achieve the above-mentioned object, one aspect of the present disclosure is a network setting device comprising: a receiving unit that receives an authentication notification from a first authentication device located on a first network, the authentication notification including an address assigned to a terminal that is permitted to access the first network, the terminal ID of the terminal, and the network ID of the first network; an acquiring unit that acquires, from a database based on the authentication notification, setting information corresponding to a service to be provided to the terminal on the first network; and a setting unit that sets the setting information in a first relay device located on the first network.
[0008] One aspect of the present disclosure is a network configuration method performed by a network configuration device, which receives an authentication notification from a first authentication device located on a first network, the authentication notification including an address assigned to a terminal that is permitted to access the first network, the terminal ID of the terminal, and the network ID of the first network, and based on the authentication notification, retrieves configuration information from a database corresponding to a service to be provided to the terminal on the first network, and sets the configuration information in a first relay device located on the first network.
[0009] According to the present disclosure, it is possible to provide a technology for constructing a network on demand that allows authorized terminals to connect with authorized service content.
[0010] FIG. 1 is an overall configuration diagram showing an example of a network system according to this embodiment. FIG. 2 is a block diagram showing an example of the configuration of a network setting device according to this embodiment. FIG. 3 is an explanatory diagram for explaining the setting process according to this embodiment. FIG. 4 is a diagram showing a specific example of the setting process of FIG. 3. FIG. 5 is a diagram showing a specific example of the setting process of FIG. 3. FIG. 6 is a diagram showing an example of service provision in a multi-access network environment. FIG. 7 is an example of a hardware configuration.
[0011] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0012] In a multi-access network environment where multiple networks, such as closed networks, coexist and terminals move between networks, the network setting device of this embodiment automatically configures network relay devices according to the network type when a terminal connects to a network. As a result, in this embodiment, services can be provided continuously even if the terminal moves to a different network.
[0013] 1 is a diagram showing an overall configuration of an example of a network system according to the present embodiment. In this embodiment, a service provider provides a predetermined service by combining a plurality of networks 3A and 3B, and provides the service while restricting access by terminals 5.
[0014] The illustrated network system includes a network setting device 1 (network setting device), a management DB 2 (database), multiple networks 3A and 3B, and a server 7. The network setting device 1, management DB 2, and server 7 are devices managed by a service provider. The networks 3A and 3B are networks managed by a network provider (e.g., a closed network provider). The network providers of the networks 3A and 3B may be the same network provider or different network providers.
[0015] In the illustrated example, two networks 3A and 3B are shown, but the number of networks is not limited to two. Each of the networks 3A and 3B includes an authentication device 31 and a relay device 32 (network relay device).
[0016] Upon receiving an authentication notification from the authentication device 31, the NW setting device 1 acquires setting information from the management DB 2 and sets the setting information in the relay device 32. The NW setting device 1 also registers information related to access control of the terminal 5 in advance in the authentication device 31 and the management DB 2.
[0017] The management DB 2 stores setting information corresponding to the services (service menu) of each terminal 5. The setting information may include service information (access control information) such as the servers 7 available to the terminal 5 for each network 3A, 3B, and bandwidth information. The management DB 2 may also store the connection status of each terminal 5.
[0018] The authentication device 31 accepts a request from the terminal 5, performs connection authentication of the terminal 5, and if the authentication is successful, assigns an IP address to the terminal 5 and transmits an authentication notification including the assigned IP address, the network ID of the network 3A or 3B to which the terminal 5 belongs, and the terminal ID sent from the terminal 5 to the NW setting device 1.
[0019] The relay device 32 controls access for each terminal 5 in accordance with the setting information set by the NW setting device 1 .
[0020] A portable wireless communication terminal (portable terminal, mobile terminal, mobile device) can be used as the terminal 5. The terminal 5 may be, for example, a smartphone. In the illustrated example, the terminal 5 is present in the area of the network 3A. In this case, the authentication device 31 of the network 3A authenticates the terminal 5, and the terminal 5 accesses the server 7 via the relay device 32 of the network 3A and uses the services provided by the server 7. When the terminal 5 moves to the area of the network 3B, the authentication device 31 of the network 3B authenticates the terminal 5, and the terminal 5 accesses the server 7 via the relay device 32 of the network 3B and uses the services provided by the server 7.
[0021] The server 7 provides various services to the terminal 5 via the networks 3A and 3B. The server 7 may be, for example, a content server that provides various content to the terminal 5.
[0022] 2 is a block diagram showing an example of the configuration of the NW setting device 1 of this embodiment. The illustrated NW setting device 1 includes a receiving unit 11, an acquiring unit 12, a setting unit 13, and a registering unit 14.
[0023] The receiving unit 11 receives an authentication notification from an authentication device 32 (first authentication device 31) located in network 3A (first network) that includes an IP address assigned to a terminal 5 that is permitted to access network 3A, a terminal ID of the terminal 5, and a network ID of network 3A. When terminal 5 moves to an area of network 3B (second network), the receiving unit 11 receives an authentication notification from an authentication device 31 (second authentication device) located in network 3B that includes the IP address assigned to terminal 5, the terminal ID of terminal 5, and the network ID of network 3B.
[0024] The acquisition unit 12 acquires, from the management DB 2, setting information corresponding to the service to be provided to the terminal 5 in the network 3A based on an authentication notification from the authentication device 31 in the network 3A. The acquisition unit 12 acquires, from the management DB 2, other setting information corresponding to the service to be provided to the terminal 5 in the network 3B based on an authentication notification from the authentication device 31 in the network 3B.
[0025] Setting unit 13 sets the setting information in relay device 32 (first relay device) located in network 3A. Setting unit 13 may set other setting information in relay device 32 (second relay device) located in network 3B, and may also delete the setting information set in relay device 32 located in network 3A.
[0026] The registration unit 14 registers in advance in the management DB 2 service information (service menu) of each terminal 5 that provides a service as setting information for the relay device 32. The service information includes, for each network 3A, 3B, servers available to the terminal 5, bandwidth information, etc. The registration unit 14 may also register and update the connection status of each terminal 5 in the management DB 2. The registration unit 14 registers in advance in the authentication device 31 of each network 3A, 3B the terminal ID of the terminal 5 that is permitted to access.
[0027] 3 is an explanatory diagram for explaining the setting process in this embodiment. In the illustrated example, the setting process will be explained when the terminal 5 accesses the network 3A. Therefore, the network 3B is omitted from FIG. 3.
[0028] As a preliminary process, the service provider uses a user terminal (not shown) to input registration information for the authentication device 31 and management DB 2 of each of the networks 3A and 3B to the NW setting device 1 (S10). Here, the NW setting device 1 sets the registration information input for the network 3A in the authentication device 31 and management DB 32 of the network 3A.
[0029] Specifically, the NW setting device 1 sets the terminal ID of the terminal 5 that is permitted to access (connect) to the network 3A in the authentication device 31 (S11). The authentication device 31 stores the terminal ID set by the NW setting device 1 in a terminal ID storage unit (not shown).
[0030] The NW setting device 1 registers, for each terminal 5, setting information in the management DB 2 according to the service to be provided to that terminal 5 (S12). The setting information includes the terminal ID, the IP address of the available server 7, the permitted network, and the bandwidth information of that network.
[0031] Next, the operation when the terminal 5 accesses the network 3A will be described.
[0032] When terminal 5 moves into an area under network 3A, it transmits an authentication request (connection request) to authentication device 31 (S21). The authentication request includes the terminal ID of terminal 5. If the terminal ID included in the authentication request is included in the terminal IDs previously set in S11, authentication device 31 determines that authentication has been successful and assigns an IP address to terminal 5 (S22).
[0033] Then, upon successful authentication, the authentication device 31 sends an authentication notification to the NW setting device 1, which includes the network ID (network information) of the network 3A to which the authentication device 31 belongs, the terminal IP address assigned to the terminal 5, and the terminal ID (S23).
[0034] Upon receiving the authentication notification, the NW configuration device 1 obtains from the management DB 2 the configuration information required for connecting to the service provided to the terminal 5 (S24). Specifically, the NW configuration device 1 obtains from the management DB 2 the configuration information corresponding to the terminal ID and network ID included in the authentication notification. The NW configuration device 1 then sets the obtained configuration information in the relay device 32 of the network 3A (S25). Specifically, the NW configuration device 1 sets the terminal IP address included in the authentication notification of S23, the IP address of the server 7 obtained from the management DB 2, and the bandwidth information of the network 3A as configuration information in the relay device 32. The NW configuration device 1 then registers or updates the connection status of the terminal 5 in the management DB 2 (S26). The terminal 5 can access the server 7 via the relay device 32 of the network 3A at the bandwidth set in S25 and use the service provided by the server 7 (S31).
[0035] In this way, this embodiment enables access settings according to the service menu of the destination network 3A. That is, this embodiment enables the service provider to build on-demand a network that enables an authorized terminal 5 to connect to an authorized service with an authorized bandwidth and access control details, without being aware of network configuration information such as the IP address of the terminal 5.
[0036] Furthermore, in this embodiment, when the terminal 5 connects to a certain network 3A, the relay device 32 is configured in accordance with the connected network 3A. Therefore, even if the terminal 5 moves to another network 3B, the relay device 32 can be similarly configured in accordance with the destination network 3B, so that services can be provided to the terminal 5 continuously (seamlessly).
[0037] Figures 4 and 5 are diagrams showing a specific example of the setting process described in Figure 3. In the example shown, the terminal 5 first connects to network 3A, and then moves and connects to network 3B.
[0038] 4, as a pre-processing, the NW setting device 1 sets the terminal ID (UE-1) of the terminal 5 to be permitted to use the service in the authentication device 31 of the network 3A and the authentication device 31 of the network 3B, respectively (S11A, S11B). In addition, the NW setting device 1 registers setting information (service information) for each terminal to be permitted to use the service in the management DB 2 (S12).
[0039] When terminal 5 (terminal ID: UE-1) moves into an area under network 3A, it transmits an authentication request including terminal ID: UE-1 to authentication device 31 (S21). If the terminal ID included in the authentication request is included in the terminal IDs preset by NW setting device 1 (authentication successful), authentication device 31 assigns an IP address (192.168.10.1) to terminal 5 (S22).
[0040] Then, the authentication device 31 transmits an authentication notification to the NW setting device 1, which includes the network ID (NW-A) of the network 3A to which the authentication device 31 belongs, the IP address (192.168.10.1) assigned to the terminal 5, and the terminal ID (UE-1) (S23).
[0041] When the NW setting device 1 receives the authentication notification, it acquires setting information corresponding to the terminal ID and network ID included in the authentication notification from the management DB 2 (S24). The setting information shown in the figure includes the IP address (192.168.13.1) of the server 7 available to the terminal 5, bandwidth information (1 Mbps) of the network ID (NW-A), etc.
[0042] Then, the NW setting device 1 sets, in the relay device 32 of the network 3A, setting information including the IP address of the terminal 5 (192.168.10.1), the IP address of the server 7 to be used (192.168.13.1), and bandwidth information (1 Mbps) (S25). The NW setting device 1 uses the IP address notified in S23 as the IP address of the terminal 5. The NW setting device 1 updates the connection status of the terminal 5 stored in the management DB 2 (S26). Here, the NW setting device 1 sets the terminal IP address: 192.168.10.1, NW-A, Connected as the connection status of the terminal ID: UE-1. The terminal 5 accesses the server 7 via the relay device 32 of the network 3A at the bandwidth set in S25 and uses the service provided by the server 7 (S31).
[0043] FIG. 5 shows the process when a terminal 5 connected to a network 3A moves into the area of a network 3B.
[0044] When terminal 5 moves from network 3A to an area under network 3B, it transmits a connection request including terminal ID: UE-1 to authentication device 31 of network 3B (S41). If the terminal ID included in the connection request is included in the terminal IDs preset by NW setting device 1 (authentication successful), authentication device 31 assigns an IP address (192.168.11.2) to terminal 5 (S42).
[0045] Then, the authentication device 31 transmits an authentication notification to the NW setting device 1, which includes the network ID (NW-B) of the network 3B to which the authentication device 31 belongs, the IP address (192.168.11.2) assigned to the terminal 5, and the terminal ID (UE-1) (S43).
[0046] Upon receiving the authentication notification, the NW configuration device 1 acquires from the management DB 2 configuration information corresponding to the terminal ID and network ID included in the authentication notification (S44). The illustrated configuration information includes the IP address (192.168.13.1) of the server 7 available to the terminal 5, bandwidth information (100 Mbps) for the network ID (NW-B), and the like. The NW configuration device 1 then sets, in the relay device 32 of the network 3B, configuration information including the IP address (192.168.11.2) of the terminal 5, the IP address (192.168.13.1) of the server 7 to be used, and the bandwidth information (100 Mbps) (S45). The NW configuration device 1 uses the IP address notified in S43 as the IP address of the terminal 5. The terminal 5 accesses the server 7 via the relay device 32 of the network 3B using the bandwidth set in S45 and uses the services provided by the server 7 (S51).
[0047] 4 for the relay device 32 of network 3A (S46). Here, the NW setting device 1 deletes the IP address (192.168.10.1) of terminal 5 and the IP address (192.168.13.1) of the server 7 to be used from the relay device 32. As a result, the relay device 32 of network 3A disconnects the connection between terminal 5 and server 7 (S52).
[0048] The NW setting device 1 updates the connection status of the terminal 5 stored in the management DB 2 (S47). Here, the NW setting device 1 updates the connection status of the terminal ID: UE-1 to IP address: 192.168.11.2, NW-B, Connected.
[0049] 6 is a diagram showing an example of a service using the setting process of this embodiment in a multi-access network environment. Fig. 6 shows an example of remote automated driving, in which a terminal 5 is mounted on a vehicle 9. Here, two servers 7A and 7B provide automated driving services (control information necessary for the automated driving of the vehicle 9) to the terminal 5, regardless of which network 3A or 3B the terminal 5 is on. For example, server 7A provides a service accessible at a high volume to the terminal 5, and server 7B provides a service accessible at a low volume to the terminal 5.
[0050] 6 omits the management DB 2, and therefore omits the process of registering information in the management DB 2 as a pre-process by the NW setting device 1 (S12 in FIG. 4 ), the process of acquiring information from the management DB 2 (S24 in FIG. 4 , S44 in FIG. 5 ), and the process of updating the management DB 2 (S26 in FIG. 4 , S47 in FIG. 5 ), but the other processes are the same as those in FIGS. 4 and 5 .
[0051] The NW setting device 1 of the present embodiment described above comprises a receiving unit 11 that receives an authentication notification from 31 arranged on network 3A, the authentication notification including an address assigned to a terminal 5 that is permitted to access network 3A, the terminal ID of the terminal 5, and the network ID of network 3A; an acquiring unit 12 that acquires, based on the authentication notification, from management DB 2 setting information corresponding to a service to be provided to the terminal 5 on network 3A; and a setting unit 13 that sets the setting information in relay device 32 arranged on network 3A.
[0052] As a result, this embodiment can provide a technology for constructing on-demand networks 3A and 3B that allow an authorized terminal 5 to connect with authorized service contents. That is, in this embodiment, in a multi-access network environment, a network that allows an authorized terminal 5 to connect with authorized services with authorized bandwidth and access control contents can be constructed on-demand without the service provider being aware of network configuration information, and even when the terminal 5 moves to another network, the access control contents can be set according to the destination network without an administrator having to perform manual configuration work.
[0053] Furthermore, in this embodiment, in an environment where the authentication device 31 and the relay device 32 exist independently for each network, even if the authentication method differs for each network, the NW setting device 1 can receive an authentication notification from the authentication device 31 by registering in advance the terminal IDs of terminals that can be permitted in the authentication device 31.
[0054] In this embodiment, by storing setting information corresponding to the service provided to the terminal for each terminal and for each network in the management DB 2, when a service provider provides a service in a multi-access network environment, the service provider does not need to input connection settings including network configuration information such as the IP addresses of terminals to be permitted to the relay device 32. In other words, the service provider can easily create a network without knowing the network configuration information.
[0055] Furthermore, in this embodiment, even when a terminal moves to another network, the NW setting device 1 receives an authentication notification from the authentication device 31 of the destination network, and acquires setting information corresponding to the service of the destination network from the management DB 2 and sets it in the determination unit 32 of the destination network, thereby enabling seamless service to be provided.
[0056] The above-described NW setting device 1, authentication device 31, and relay device 32 can be implemented, for example, by a general-purpose computer system as shown in Fig. 7. The illustrated computer system includes a CPU (Central Processing Unit, processor) 901, a memory 902, a storage 903 (HDD: Hard Disk Drive, SSD: Solid State Drive), a communication device 904, an input device 905, and an output device 906. The memory 902 and the storage 903 are storage devices. In this computer system, the CPU 901 executes a predetermined program loaded on the memory 902, thereby realizing the functions of the NW setting device 1, authentication device 31, and relay device 32.
[0057] The NW setting device 1, the authentication device 31, and the relay device 32 may be implemented on a single computer or multiple computers. The NW setting device 1, the authentication device 31, and the relay device 32 may be virtual machines implemented on a computer. The programs for the NW setting device 1, the authentication device 31, and the relay device 32 may be stored on a computer-readable recording medium such as a HDD, SSD, USB (Universal Serial Bus) memory, CD (Compact Disc), or DVD (Digital Versatile Disc), or may be distributed via a network. The computer-readable recording medium is, for example, a non-transitory recording medium.
[0058] The present disclosure is not limited to the above-described embodiments, and various modifications are possible within the scope of the present disclosure.
[0059] 1: NW setting device (network setting device) 11: Receiving unit 12: Acquiring unit 13: Setting unit 14: Registration unit 2: Management DB (database) 3A, 3B: Network 31: Authentication device 32: Relay device 5: Terminal 7: Server
Claims
1. A network setting device comprising: a receiving unit that receives, from a first authentication device located on a first network, an authentication notification including an address assigned to a terminal that has been granted access to the first network, the terminal ID of the terminal, and the network ID of the first network; an acquiring unit that acquires, from a database, setting information corresponding to a service to be provided to the terminal on the first network based on the authentication notification; and a setting unit that sets the setting information in a first relay device located on the first network.
2. The network setting device according to claim 1, wherein the database stores the setting information for each terminal and each network.
3. The network setting device according to claim 1, wherein when the terminal moves into an area of a second network, the receiving unit receives an authentication notification from a second authentication device located on the second network, the authentication notification including an address assigned to the terminal, the terminal ID of the terminal, and the network ID of the second network; the acquiring unit acquires, based on the authentication notification, other setting information from a database according to services to be provided to the terminal on the second network; and the setting unit sets the other setting information in a second relay device located on the second network and deletes the setting information set in the first relay device.
4. A network configuration method performed by a network configuration device, comprising: receiving an authentication notification from a first authentication device located on a first network, the authentication notification including an address assigned to a terminal permitted to access the first network, the terminal ID of the terminal, and the network ID of the first network; retrieving, based on the authentication notification, configuration information corresponding to a service to be provided to the terminal on the first network from a database; and setting the configuration information in a first relay device located on the first network.
Citation Information
Patent Citations
Method for setting network device and updating firmware, network device and computer program
JP2006311177A
Apparatus, method and program for authenticating communication terminal
JP2008160252A
Automatic setting system and automatic setting method for network device
JP2009194710A