Communication device, communication resource control method, control circuit, and storage medium

The communication device addresses security risks in wireless surveillance systems by identifying risk locations and adjusting resources, enhancing communication reliability and reducing interference.

WO2025262973A1PCT designated stage Publication Date: 2025-12-26MITSUBISHI ELECTRIC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/033876
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-18
Filing Date
2024-09-24
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing wireless surveillance camera systems face security risks such as interference, eavesdropping, and unauthorized login, particularly when multiple communication devices share limited wireless resources, leading to potential communication disruptions and resource wastage.

Method used

A communication device equipped with a wireless communication unit, security risk location estimation unit, and communication resource control unit that identifies security risks and selects less affected communication resources for transmission, thereby reducing the impact of these risks.

Benefits of technology

The solution effectively minimizes the impact of security risks like interference and eavesdropping by dynamically adjusting communication resources based on risk location and type, ensuring reliable wireless communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024033876_26122025_PF_FP_ABST
    Figure JP2024033876_26122025_PF_FP_ABST
Patent Text Reader

Abstract

A communication device (10) comprises: a wireless communication unit (103) that transmits and receives a wireless signal to and from another communication device; a security-risk position estimation unit (102) that estimates a security risk position indicating the position of occurrence of a security risk and a security risk type indicating the type of security risk on the basis of the monitoring result of the wireless environment around the own device and application traffic acquired from an external device; and a communication resource control unit (106) that selects a communication resource less susceptible to the security risk on the basis of the security risk position and the security risk type, and determines the selected communication resource as a communication resource to be used for transmission of application traffic.
Need to check novelty before this filing date? Find Prior Art

Description

COMMUNICATION DEVICE, COMMUNICATION RESOURCE CONTROL METHOD, CONTROL CIRCUIT, AND STORAGE MEDIUM

[0001] The present disclosure relates to a communication device having a wireless communication function, a communication resource control method, a control circuit, and a storage medium.

[0002] For physical protection security of critical industrial systems, surveillance camera systems are used both inside and outside the premises of the industrial systems. Until now, surveillance camera systems have been wired to communicate between the surveillance cameras and the monitoring headquarters, but in recent years, wireless surveillance camera systems have been considered for the purpose of DX (Digital Transformation) and reducing the number of cables, such as by equipping unmanned mobile vehicles with surveillance cameras and patrolling them. When going wireless, countermeasures against wireless interference, eavesdropping, unauthorized logins, etc. are required to build critical surveillance camera systems.

[0003] In addition, surveillance camera systems have a steady flow of traffic, and generally, "E2E packet loss = dropped video frames" is not acceptable, considering future use in image processing. Therefore, it is necessary to build a system that takes as many countermeasures as possible while securing wireless resources for service provision. For example, in order to prevent a communication device in a system from being connected to another communication control device that cannot ensure secure communication, a technology is known that outputs jamming signals to disrupt communication between the communication device in the system and other communication control devices (Patent Document 1).

[0004] International Publication No. 2020 / 137204

[0005] In particular, in wireless surveillance camera systems, etc., it is expected that there will be an environment in which there are multiple communication client devices integrated with the camera or multiple communication client devices located in the same location as the camera. In this case, wireless resources available for wireless communication, such as frequency division, time division, and space division, are shared by the entire communication system and are therefore limited.

[0006] The technology described in Patent Document 1 is considered to be effective when focusing only on the communication link between the client device and the upper network side. However, if cooperation with multiple client devices is not taken into consideration, there is a possibility that wireless resources may be wasted between client devices or that communication between other client devices in the same system and the upper network may be hindered.

[0007] The present disclosure has been made in consideration of the above, and aims to obtain a communication device that can reduce the impact of security risks using wireless communication by malicious individuals, etc., such as interference with the system itself via wireless communication, eavesdropping, and unauthorized login.

[0008] In order to solve the above-mentioned problems and achieve the objectives, the communication device disclosed herein is characterized by comprising a wireless communication unit that transmits and receives wireless signals with other communication devices, a security risk location estimation unit that estimates a security risk location indicating the location where a security risk occurs and a security risk type indicating the type of security risk based on the monitoring results of the wireless environment around the device and application traffic acquired from an external device, and a communication resource control unit that selects a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determines the selected communication resource as the communication resource to be used for transmitting the application traffic.

[0009] The present disclosure provides an advantage of realizing a communication device that can reduce the impact of wireless security risks posed by malicious individuals and the like.

[0010] FIG. 1 is a diagram showing an example of the configuration of a communication system realized by applying a communication device according to embodiment 1. Block diagram showing an example of the configuration of a communication device according to embodiment 1. Block diagram showing an example of the configuration of a communication control device according to embodiment 1. FIG. 1 is a diagram showing an example of the results of a communication device according to embodiment 1 analyzing a video stream input from a camera. FIG. 2 is a diagram showing another example of the results of a communication device according to embodiment 1 analyzing a video stream input from a camera. FIG. 2 is a diagram showing an example of the results of a security risk position estimation by a communication device of a communication system according to embodiment 1. FIG. 3 is a diagram showing each coordinate shown in FIG. 6 in a table format. FIG. 4 is a diagram showing an example of a result of a communication device according to embodiment 1 monitoring a wireless environment. FIG. 4 is a diagram showing an example of a monitoring result of a wireless environment by a communication device that estimates a security risk position shown in FIG. 6.

[0011] A communication device, a communication resource control method, a control circuit, and a storage medium according to embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0012] 1 is a diagram showing a configuration example of a communication system 100 realized by applying a communication device 10 according to embodiment 1. In this embodiment, as an example, a case where the communication system 100 is used in a social infrastructure system will be described.

[0013] The communication system 100 includes communication devices 10 and 20, a communication control device 30, and an application server 40, all of which are provided within an area surrounded by a social infrastructure system protective wall 1.

[0014] The social infrastructure system protective wall 1 is installed to prevent physical intrusion into an important social infrastructure system, and corresponds to a physical wall, fence, etc. that surrounds the premises of the social infrastructure system. The social infrastructure system protective wall 1 is equipped with cameras 2. Entry into the premises of the social infrastructure system is permitted only by passing through a security gate (not shown) following proper procedures. Note that while Figure 1 shows two communication devices 10 and two communication devices 20, the number of devices is not limited to this. The number of cameras 2 is also not limited to that shown in Figure 1.

[0015] The camera 2 is primarily physically installed at the social infrastructure system protective wall 1 for the purpose of monitoring the periphery of the social infrastructure system protective wall 1. The camera 2 samples and encodes video information from around the camera 2 and outputs it in the form of a video stream to a device connected via a wired connection. In FIG. 1 , a communication device 10 and an application server 40 are shown as examples of devices connected via a wired connection. The video stream output by the camera 2 is a series of digital information associated with sender information, timestamp, information type, encoding information, picture information, and the like, and is generally transmitted via a communication path over Internet Protocol (IP). The camera 2 may transmit the video stream to the application server 40 via a wired connection only, or it may be connected via a wired connection to the communication device 10, which then wirelessly communicates with the application server 40 via both the wireless section and the wired connection section. The camera 2 accepts various controls in response to control commands issued by the application server 40. The various controls include establishing and starting a video stream session, changing settings, and ending the session, tilting a physical camera, lighting up and down, zooming in and out of video information, and focusing.

[0016] The communication device 10, which is a first communication device, has an interface for wired communication and an antenna for inputting and outputting wireless signals, and typically transmits data received via wired communication via wireless communication and data received via wireless communication via wired communication. That is, the communication device 10 relays data between a device connected via wired communication and a device connected via wireless communication. The communication device 10 terminates the wireless protocol between the communication device 20 and the other communication device. Depending on the functionality of the wireless protocol, the communication device 10 may wirelessly relay data received wirelessly from another communication device 10 to the communication device 20 that is the relay destination. The communication device 10 also controls how communication resources are used depending on security risks, for example, by emitting a jamming wireless signal in the direction of an eavesdropper who poses a security risk.

[0017] The communication device 20, which is the second communication device, has an interface for wired communication and an antenna for inputting and outputting wireless signals, similar to the communication device 10, and typically transmits data received via wired communication via wireless communication and transmits data received via wireless communication via wired communication. The communication device 20 performs wireless communication with the communication device 10 and wired communication with the communication control device 30.

[0018] The communication control device 30 performs security management, mobility management, and QoS (Quality of Service) management for the communication device 10 , and serves as a mobile gateway for the application server 40 .

[0019] The application server 40 receives video streams transmitted from each camera 2, decodes the received video streams, stores them as video information, and displays them. In addition, the application server 40 controls the cameras 2 by generating and transmitting control commands for the cameras 2 in response to requests from users or the like.

[0020] 1, the camera 2 and the communication device 10 are described as separate devices, but they may be an integrated device, i.e., the communication device 10 has all the functions of the camera 2. Also, the camera 2 and the communication device 10 are described as being fixed to the periphery of the social infrastructure system protective wall 1, but they may be an integrated communication device 10 that moves inside the social infrastructure system protective wall 1. Also, while the communication device 10 is described as having two external antennas, it may be configured with one or fewer external antennas, a pattern antenna built into the communication device 10, or a configuration with three or more external antennas, and is not limited to the configuration shown in FIG.

[0021] 1 shows an example in which the communication control device 30 is wired to one application server 40, but a configuration in which there are two or more application servers 40 is also possible, and the number of application servers 40 is not limited to the configuration shown in Fig. 1. Also, while Fig. 1 shows that the communication control device 30 and the application server 40 are physically wired, switching or extension may be performed using a layer 2 switch, repeater, or the like as long as it does not affect the information handled by the application server 40, and the configuration is not limited to the configuration shown in Fig. 1.

[0022] 2 is a block diagram showing an example of the configuration of the communication device 10 according to embodiment 1. The communication device 10 includes a security risk detection unit 101, a security risk location estimation unit 102, a wireless communication unit 103, a wired communication unit 104, a traffic analysis unit 105, a communication resource control unit 106, a storage unit 107, a wired NIC (Network Interface Card) unit 109, and an antenna unit 110.

[0023] The security risk detection unit 101 acquires wireless environment information from the wireless communication unit 103 and constantly monitors whether there are any abnormalities in the surrounding wireless environment. The security risk detection unit 101 also manages the security risk detection status based on the security risk location candidate occurrence notification from the security risk location estimation unit 102 and the security risk notification acquired from the upper network via the communication resource control unit 106. Examples of security risks include communication interference, eavesdropping, and unauthorized login. The security risk location candidate occurrence notification from the security risk location estimation unit 102 includes information on locations where security risks may occur, detected by the communication device 10 itself. The security risk notification acquired from the upper network includes information on security risks detected by other communication devices 10, such as the type of security risk and information on the location where the security risk occurred.

[0024] The security risk position estimation unit 102 receives the video stream analyzed by the traffic analysis unit 105 and estimates whether a security risk has occurred within the picture information of the received video stream by utilizing pattern matching, etc. If the security risk position estimation unit 102 estimates that a security risk has occurred, it calculates the security risk position by image processing and notifies the calculated security risk position together with the security risk type to the communication resource control unit 106 and the security risk detection unit 101. The security risk position is information that indicates the location where a security risk has occurred, and the security risk type is information that indicates the type of security risk.

[0025] The wireless communication unit 103 functions as a wireless interface that transmits and receives wireless signals input and output via the antenna unit 110. The wireless communication unit 103 physically controls the antenna unit 110 to perform beam control, or digitally controls the transmitted and received wireless signals to perform beam control. The wireless communication unit 103 also transfers control signals from the communication control device 30 to the communication resource control unit 106. The wireless communication unit 103 also has a modem function that performs wireless protocol processing, such as transmitting control signals and user data between other communication devices 10 and encrypting and decrypting wireless signals. The wireless communication unit 103 also transfers user data received via wireless communication to the wired communication unit 104 or the communication resource control unit 106, and transmits traffic transferred from the wired communication unit 104 via wireless communication. The wireless communication unit 103 also monitors the wireless environment and notifies the security risk detection unit 101 of the monitoring results. In addition, the wireless communication unit 103 has the function of irradiating jamming radio waves in a specified direction in accordance with instructions from the communication resource control unit 106, and the function of changing the communication resources used in wireless protocol processing in accordance with instructions from the communication resource control unit 106.

[0026] The wired communication unit 104 functions as a wired interface that processes wired signals input and output via the wired NIC unit 109. The wired communication unit 104 transmits application traffic transferred from the wireless communication unit 103 via wired communication from the wired NIC unit 109, and transfers application traffic received by the wired NIC unit 109 via wired communication to the wireless communication unit 103. The wired communication unit 104 also copies application traffic input from the wired NIC unit 109 and transfers the copied application traffic to the traffic analysis unit 105.

[0027] The traffic analysis unit 105 analyzes the video stream, which is application traffic transferred from the wired communication unit 104 to the wireless communication unit 103 , and outputs the obtained frames to the security risk location estimation unit 102 .

[0028] The communication resource control unit 106 acquires and manages communication resources available to the communication device 10 from the wireless communication unit 103. The communication resource control unit 106 also calculates communication resources to be used based on the security risk location and security risk type notified by the security risk location estimation unit 102 and the communication resources of the communication device 10, and notifies the wireless communication unit 103 of the calculation result. The communication resource control unit 106 also reports the communication resources managed by the communication device 10 to the communication control device 30, and acquires information on communication resources managed by communication devices 10 other than the communication device 10 from the communication control device 30.

[0029] The storage unit 107 stores setting information such as parameters for the operation of the communication device 10 , and also stores information used by various functional units of the communication device 10 .

[0030] The wired NIC unit 109 transmits signals input from the wired communication unit 104 via a wired connection, and outputs signals received via a wired connection to the wired communication unit 104. The wired NIC unit 109 is connected to the camera 2, which is an external device, and transmits and receives signals to and from the camera 2.

[0031] The antenna section 110 converts signals input from the wireless communication section 103 into radio waves and transmits them, and also outputs signals received as radio waves to the wireless communication section 103 .

[0032] Note that Figure 2 shows an example of a communication device 10 having one wired NIC unit 109 and two antenna units 110, but the arrangement and number of the wired NIC units 109 and antenna units 110 are not limited to the configuration shown in the figure.

[0033] While the configuration of the communication device 10 connected to the camera 2 has been described above, the communication device 20 connected to the communication control device 30 may have a configuration in which the security risk detection unit 101, security risk location estimation unit 102, and traffic analysis unit 105 are removed from the communication device 10, i.e., a configuration including the wireless communication unit 103, wired communication unit 104, communication resource control unit 106, storage unit 107, wired NIC unit 109, and antenna unit 110. Note that the communication resource control unit 106 of the communication device 20 does not execute processes related to the security risk detection unit 101 and security risk location estimation unit 102, such as processes that use the security risk location and security risk type. Furthermore, the communication device 20 may have the same configuration as the communication device 10, but may not use some of the processing units, such as the security risk detection unit 101.

[0034] 3 is a block diagram showing an example of the configuration of the communication control device 30 according to embodiment 1. The communication control device 30 includes a mobility management unit 301, a security management unit 302, a communication resource management unit 303, a wired communication unit 304, a storage unit 305, and a wired NIC unit 309.

[0035] The mobility management unit 301 performs redundancy control and link aggregation control using multiple wireless links when a communication device 10 that is not on the upper network side can wirelessly communicate with multiple communication devices 20 on the upper network side. The mobility management unit 301 also has a function of managing communication links between the communication device 10 and the communication device 20, such as handover control. The mobility management unit 301 also identifies the combination of a source and a destination by collating application traffic received from the wired communication unit 304 with information on the communication links it manages. That is, the mobility management unit 301 determines whether the source and destination of the application traffic are the communication device 10 or the application server 40. The mobility management unit 301 also transfers the combination of the source and destination of the application traffic, as well as the application traffic itself, to the security management unit 302.

[0036] Based on the combination of the source and destination of the application traffic transferred from the mobility management unit 301 and the application traffic itself, the security management unit 302 performs encryption or decryption on the application traffic linked to the communication device 10 or application server 40, which is the source and destination of the application traffic, and transfers the encryption or decryption to the wired communication unit 304.

[0037] The communication resource management unit 303 records and manages the communication resources available to each communication device 10, which are reported from each communication device 10 and 20. Furthermore, upon receiving a communication resource allocation request from the communication device 10 or 20, the communication resource management unit 303 determines the communication resources to be used and notifies the requesting communication device 10 or 20 of the determined communication resources via the wired communication unit 304.

[0038] The wired communication unit 304 functions as a wired interface that processes wired signals input and output via the wired NIC unit 309. The wired communication unit 304 transmits, via wired communication, information on application traffic, encrypted application traffic, or communication resources transferred from the mobility management unit 301, the security management unit 302, or the communication resource management unit 303 from the wired NIC unit 309, and also transfers application traffic or encrypted application traffic received by the wired NIC unit 309 via wired communication to the mobility management unit 301. The wired communication unit 304 also transfers, to the mobility management unit 301, reports on available communication resources and reports on acquired communication resources received from the communication device 10 or 20.

[0039] The storage unit 305 stores setting information such as parameters for the operation of the communication control device 30 , and also stores information used by various functional units of the communication control device 30 .

[0040] The wired NIC unit 309 transmits signals input from the wired communication unit 304 via a wired connection, and outputs signals received via a wired connection to the wired communication unit 304. The wired NIC unit 309 is connected to the application server 40 or the communication device 20, and transmits and receives signals to and from the application server 40 or the communication device 20.

[0041] Although FIG. 3 illustrates an example of a communication control device 30 including two wired NIC units 309, the arrangement and number of wired NIC units 309 are not limited to the illustrated configuration.

[0042] 4 is a diagram showing an example of the results of analysis of a video stream input from camera 2 by communication device 10 according to the first embodiment. Fig. 4 shows a first example of a frame obtained by analyzing a video stream, which is application traffic, by traffic analysis unit 105 of communication device 10. Because the video stream is for surveillance purposes, in a steady state, most of the frames are normal frames in which no suspicious person or the like is included in the field of view.

[0043] Fig. 5 is a diagram showing another example of the results of communication device 10 according to embodiment 1 analyzing the video stream input from camera 2. Fig. 5 shows a second example of a frame obtained by traffic analysis unit 105 of communication device 10 analyzing the video stream. Fig. 5 shows a frame in which a suspicious person 501 is within the angle of view in the video stream from camera 2, the same as the example shown in Fig. 4.

[0044] Fig. 6 is a diagram showing an example of the result of estimating a security risk location 50 by the communication device 10 of the communication system 100 according to embodiment 1. In Fig. 6, one of the two communication devices 20 of the communication system 100 shown in Fig. 1 is the communication device 20A, and the other is the communication device 20B.

[0045] FIG. 6 illustrates a case in which the security risk location estimation unit 102 of the communication device 10 estimates the security risk location 50 from the frame shown in FIG. 5 and calculates coordinates (x1, y1) as the horizontal coordinates of the security risk location 50. The horizontal coordinates of the security risk location 50 are calculated using a general-purpose method, such as pattern matching or image recognition using machine learning. During the station placement design stage, the communication device 10 can store the horizontal coordinates (x2, y2) of the communication device 10 itself, the horizontal coordinates (x3, y3) and (x4, y4) of the communication devices 20A and 20B on the upper network side, and information elements constituting the communication resources in the storage unit 107 or the like as parameters of the communication device 10. Therefore, the communication device 10 can recognize the positional relationship between the security risk location 50 and the inside and outside of the social infrastructure system protective wall 1 as information elements constituting the communication resources, as shown in FIG. 6 .

[0046] 7 is a diagram showing the coordinates shown in FIG. 6 in a table format, specifically, the table showing the positional relationship between the security risk position 50 recognized by the communication device 10 shown in FIG. 6 and each communication device 20 within the social infrastructure system protective wall 1. In FIG. 7, the own device is the communication device 10.

[0047] Fig. 8 is a diagram showing an example of the results of monitoring a wireless environment by the communication device 10 according to embodiment 1. In Fig. 8, the horizontal axis (a) indicates the direction of arrival of a wireless signal received by the communication device 10 during monitoring, and the vertical axis (P) indicates interference power, which is the power of the wireless signal received during monitoring.

[0048] The example shown in FIG. 8 indicates that the interference power from the vicinity of the arrival angle a1 as seen from the communication device 10 is large.

[0049] While Figure 8 shows an example in which the directions of arrival of wireless signals are continuously depicted, they may be depicted discretely, taking into consideration the processing performance of the communication device 10, the resolution for monitoring the wireless environment, and the like. In addition, although the wireless environment is not separated by frequency band in this embodiment, it may be separated into multiple frequency bands and the wireless environment may be monitored in each frequency band. Furthermore, although the wireless environment is not separated on the time axis, it may be separated to some extent on the time axis and monitored. Malicious jamming radio waves are likely to be ultra-wideband on the frequency axis and continuous for a long period of time on the time axis.

[0050] Fig. 9 is a diagram showing an example of the results of monitoring the wireless environment (hereinafter, may be referred to as the wireless environment monitoring results) by the communication device 10 that estimates the security risk location 50 shown in Fig. 6. Fig. 9 shows the table shown in Fig. 7 and the monitoring results shown in Fig. 8 in a tabular format.

[0051] When viewed from the communication device 10, the interference power of the radio environment monitoring results becomes high near the angle where the security risk position 50 exists. Normally, when the interference power of the radio environment monitoring results is greater than the interference power from other general radio systems, the type of security risk can be determined to be jamming radio waves. In this embodiment, an example will be described in which the type of security risk is jamming radio waves.

[0052] 9, "estimated received power from own device" is an estimated value of the received power at communication device 20A or 20B of the wireless signal transmitted by communication device 10. "Estimated interference power from security risk location" is an estimated value of the received power at communication device 20A or 20B of the jamming radio wave, which is a wireless signal transmitted from security risk location 50. "Estimated received power from own device" and "estimated interference power from security risk location" are calculated by communication device 10.

[0053] An example of a method for calculating the "estimated interference power from a security risk location" by the communication device 10 will be described. The communication device 10 first calculates the estimated transmission power of jamming radio waves from the security risk location 50 using the positional relationship between the security risk location 50 and the communication device 10 and a propagation path model. The propagation path model here may be a general propagation path model such as free space propagation, or an independently defined model may be used. The communication device 10 then calculates the distance based on the positional relationship between the upper network side communication device (communication devices 20A, 20B) and the security risk location 50, and calculates the "estimated interference power from the security risk location" using the calculated distance, the distance attenuation estimated from the propagation path model, and the estimated transmission power of the jamming wave calculated above.

[0054] The calculation of the "estimated received power from the communication device 10" by the communication device 10 may be performed in the same manner as the calculation of the "estimated interference power from a security risk location," by calculating the distance based on the positional relationship between the communication device 10 and the upper network side communication device (communication devices 20A, 20B) and then calculating the power based on the calculated distance and distance attenuation estimated from a propagation path model, or by exchanging received power information as a message over a wireless protocol, or by using the results of wireless environment monitoring and utilizing reciprocity to make an estimate.

[0055] In this embodiment, a device maliciously emitting jamming radio waves has no way of knowing the positions of communication devices 20A and 20B on the upper network side within social infrastructure system protective wall 1. For this reason, this embodiment describes an example in which radio waves whose emitted beam does not have gain at each angle are used as jamming radio waves. If it can be estimated or identified that the jamming radio wave beam has gain at each angle, correction may be made using that value.

[0056] FIG. 10 is a flowchart showing an example of an operation of the communication device 10 according to the first embodiment to control communication resources.

[0057] First, the communication device 10 is initialized and wireless communication is established (step S101).

[0058] Initialization of the communication device 10 refers to processing to ensure that the hardware (H / W) and software (S / W) required for the operation of each component of the communication device 10 operate normally. Initialization of the communication device 10 completes the initial value setting of parameters and variables used by each component, state transitions, and the like. Establishing wireless communication starts operation in accordance with a wireless communication protocol corresponding to the wireless communication technology used. Depending on the wireless communication technology used, it may be necessary to establish a connection with the communication device 20 on the upper network side, establish wireless resources, establish a traffic flow for transferring application traffic, exchange security keys, and establish a security sequence in accordance with the access method, duplexing method, and wireless resource control protocol. Establishing wireless communication involves these processes. After completing the processing of step S101, the communication device 10 becomes capable of transferring application traffic to the communication device 20 on the upper network side via wireless communication. Furthermore, it becomes possible for the application server 40 and the communication control device 30 to wirelessly receive control communication and application traffic transfers from the communication device 10.

[0059] Next, the communication device 10 determines whether or not a security risk has been detected (step S102).

[0060] In step S102, first, the traffic analysis unit 105 analyzes the application traffic received from the camera 2 and plays back images (frames) of the video stream, and then the security risk position estimation unit 102 analyzes the images of the video stream and estimates the security risk position.The security risk detection unit 101 then determines whether or not a security risk has been detected based on the results of monitoring the wireless environment by the wireless communication unit 103 and the security risk position estimated by the security risk position estimation unit 102.

[0061] If no security risk is detected (step S103: No), the communication device 10 executes the process of step S102 again.

[0062] If a security risk is detected (step S103: Yes), the communication device 10 updates the available communication resources (step S104).

[0063] In step S104, the communication resource control unit 106 of the communication device 10 updates the available communication resources obtained from the wireless communication unit 103 based on the type of security risk detected by the security risk detection unit 101, the security risk location estimated by the security risk location estimation unit 102, and the results of monitoring the wireless environment by the wireless communication unit 103.

[0064] Next, the communication device 10 performs control to switch the communication resources to be used (step S105).

[0065] In step S105, the communication resource control unit 106 of the communication device 10 weights and compares the "estimated interference power from security risk locations" and the "estimated received power from the communication device itself" of each of the multiple communication devices 20 on the upper network side, as described with reference to FIG. 9, and selects the communication device 20 on the upper network side that is determined to provide the best communication. Then, the communication resource control unit 106 instructs the wireless communication unit 103 to change the destination of the application traffic so that the selected communication device 20 becomes the destination of the application traffic. Having received this instruction, the wireless communication unit 103 switches the communication device 20 that is the destination of the application traffic in accordance with the instruction. The communication device 10 then returns to step S102 and repeats steps S102 to S105.

[0066] Figure 11 is a sequence diagram showing an example of communication resource control in communication system 100 according to embodiment 1, and specifically shows a control sequence for switching communication resources based on a video stream, which is application traffic from camera 2.

[0067] First, wireless communication paths are established between the communication device 10, the communication devices 20A and 20B on the upper network side, and the communication control device 30 (step S201). The wireless communication paths are established in accordance with a wireless communication protocol corresponding to the wireless communication technology used. Depending on the wireless communication technology used, connections and wireless resources are established with the communication devices 20A and 20B on the upper network side in accordance with the access method, duplexing method, and wireless resource control protocol. If a traffic flow for transferring application traffic between the communication device 10 and the communication control device 30, security key exchange, and security sequence establishment are required, these processes are also performed in step S201. Figure 11 shows an example in which the communication device 10 selects the communication device 20A as the destination of the wireless communication.

[0068] When the process of step S201 is completed and a wireless communication path is established, the application traffic output by the camera 2 reaches the communication device 10 (S202-1, S202-2, S202-3).

[0069] The application traffic that has reached the communication device 10 in step S202-1 is forwarded by the communication device 10, and reaches the application server 40 via the communication device 20A and the communication control device 30 (step S203).

[0070] After the process of step S201 is completed and a wireless communication path is established, the communication device 10 starts communication resource control (step S204). The communication resource control performed by the communication device 10 includes a process of detecting a security risk based on the analysis results of the application traffic received from the camera 2 and the monitoring results of the wireless environment, i.e., a process of analyzing the application traffic, playing back images of the video stream, and determining whether or not there is a security risk and estimating the location of the security risk based on the played back images and the monitoring results of the wireless environment.

[0071] When the communication device 10 detects a security risk (step S205), the communication device 10 switches communication resources between the communication devices 20A and 20B on the upper network side and the communication control device 30 (step S206). In the example shown in Fig. 11, the communication device 10 switches the destination of wireless communication, which is the transmission destination of application traffic, from the communication device 20A to the communication device 20B.

[0072] In this way, communication device 10 determines whether there is a security risk based on the video stream, which is application traffic output from camera 2, and the wireless environment surrounding communication device 10, and if a security risk is detected, executes communication resource switching processing to switch to communication using communication resources that further reduce the impact of the security risk. In the present embodiment, an example of switching communication paths is shown as an example of communication resource switching processing, but the communication resource switching method is not limited to this. For example, instead of switching communication paths, the frequency of wireless signals to be transmitted and received may be switched, or both the communication path and the frequency of wireless signals may be switched.

[0073] Note that there are cases where communication device 10 does not switch the wireless communication destination even when it detects a security risk. For example, if the location of the detected security risk while communication device 10 is communicating wirelessly with communication device 20A is close to communication device 20B and the impact of the security risk on communication device 20B is greater than that on communication device 20A, communication device 10 continues wireless communication with communication device 20A without switching the wireless communication destination. When the adverse impact of the security risk on communication device 20A is greater than the adverse impact of the security risk on communication device 20B, the operation sequence shown in FIG. 11 is performed.

[0074] If there is application traffic that the communication device 10 received in step S202-2 immediately before detecting a security risk in step S205 and is holding without forwarding it to communication device 20A, it switches communication resources in step S206 and then transmits the traffic to application server 40 via communication device 20B and communication control device 30 that constitute the switched communication resources (step S207).

[0075] The application traffic that arrived at the communication device 10 in step S202-3 after the communication resource switching in step S206 is forwarded by the communication device 10 and reaches the application server 40 via the communication device 20B and the communication control device 30 (step S208). The application traffic output by the camera 2 is forwarded to the application server 40 via the communication device 10, the communication device 20B, and the communication control device 30 until the next communication resource switching occurs.

[0076] Next, a description will be given of the hardware configuration of the communication device 10 according to the first embodiment. The wired NIC unit 109 of the communication device 10 is realized by, for example, a network interface card. The antenna unit 110 of the communication device 10 is realized by, for example, an antenna element.

[0077] The components of the communication device 10 other than the wired NIC unit 109 and the antenna unit 110 are realized by processing circuits. That is, the security risk detection unit 101, security risk location estimation unit 102, wireless communication unit 103, wired communication unit 104, traffic analysis unit 105, communication resource control unit 106, and memory unit 107 of the communication device 10 are realized by processing circuits. This processing circuit may be a processor that executes a program and a memory that stores the program, or may be dedicated hardware. The processing circuit is also called a control circuit.

[0078] 12 is a diagram showing an example of the configuration of a processing circuit 90 provided in the communication device 10 according to the first embodiment when the processing circuit is realized by a processor 91 and a memory 92. The processing circuit 90 shown in FIG. 12 is a control circuit.

[0079] When the processing circuit 90 is composed of a processor 91 and a memory 92, the storage unit 107 of the communication device 10 is realized by the memory 92. Furthermore, the functions of the security risk detection unit 101, security risk location estimation unit 102, wireless communication unit 103, wired communication unit 104, traffic analysis unit 105, and communication resource control unit 106 of the communication device 10 are realized by software, firmware, or a combination of software and firmware. The software or firmware is written as a program and stored in the memory 92. In the processing circuit 90, the processor 91 reads and executes the program stored in the memory 92, thereby realizing the security risk detection unit 101, security risk location estimation unit 102, wireless communication unit 103, wired communication unit 104, traffic analysis unit 105, and communication resource control unit 106 of the communication device 10. That is, the processing circuitry 90 includes a memory 92 for storing a program that results in the processing of the security risk detection unit 101, security risk location estimation unit 102, wireless communication unit 103, wired communication unit 104, traffic analysis unit 105, and communication resource control unit 106 of the communication device 10. This program can also be said to be a program that causes the communication device 10 to execute each function realized by the processing circuitry 90. This program may be provided by a storage medium on which the program is stored, or by other means such as a communication medium.

[0080] The processor 91 is, for example, a CPU (Central Processing Unit), a processing device, an arithmetic unit, a microprocessor, a microcomputer, or a DSP (Digital Signal Processor). The memory 92 is, for example, a non-volatile or volatile semiconductor memory such as a RAM (Random Access Memory), a ROM (Read Only Memory), a flash memory, an EPROM (Erasable Programmable ROM), or an EEPROM (Electrically EPROM), a magnetic disk, a flexible disk, an optical disk, a compact disk, a minidisk, or a DVD (Digital Versatile Disc).

[0081] FIG. 13 is a diagram illustrating an example of a processing circuit 93 in a case where the processing circuit included in the communication device 10 according to the first embodiment is configured with dedicated hardware. The processing circuit 93 illustrated in FIG. 13 corresponds to, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The processing circuit included in the communication device 10 may be partially implemented with dedicated hardware and the remaining portion implemented with software or firmware. In this way, the processing circuit can realize each of the above-described functions by dedicated hardware, software, firmware, or a combination thereof.

[0082] Although the hardware configuration of the communication device 10 has been described, the hardware configuration of the communication device 20 on the higher-level network side is also similar. Furthermore, the communication control device 30 can also be realized with the same hardware as the communication device 10. That is, the wired NIC unit 309 of the communication control device 30 can be realized with a network interface card, and the mobility management unit 301, security management unit 302, communication resource management unit 303, wired communication unit 304, and storage unit 305 can be realized with the processing circuits described above.

[0083] As described above, the communication system 100 according to the first embodiment is constructed within an area surrounded by the social infrastructure system protective wall 1 and includes a communication device 10 connected to a camera 2 that captures images of the periphery of the social infrastructure system protective wall 1, a communication device 20 that wirelessly communicates with the communication device 10, a communication control device 30 connected to the communication device 20, and an application server 40 connected to the camera 2 and the communication control device 30 and that acquires and stores a video stream representing application traffic output by the camera 2. The communication device 10 detects a security risk and calculates the location of the security risk based on the surrounding wireless environment and the application traffic, and switches communication resources used to transmit the application traffic to the application server 40 as needed. Specifically, the communication device 10 switches to using a communication resource that has the least impact on wireless communication due to the detected security risk. For example, if the type of the detected security risk is jamming that interferes with communication, the communication device 10 controls switching the destination of the application traffic to the communication device 20 that is least susceptible to jamming.

[0084] This allows the system to reduce security risks while maintaining wireless communication quality as much as possible by identifying or estimating the location of the security risk when a security risk is detected, such as interference with the system by a malicious person using wireless communication, eavesdropping, or unauthorized login, and then taking communication resource control processing in accordance with the security risk.

[0085] In addition, the communication device 10 can also be configured to estimate the location of a security risk based on a notification from an application server 40 on a higher-level network, in which case it becomes possible to identify and estimate the location of a security risk, including the field of view of cameras other than the camera 2 connected to the communication device 10.

[0086] Furthermore, the communication device 10 may change the communication resource allocation in response to a request from a communication control device 30 that belongs to a higher-level network. In this case, the communication control device 30 comprehensively views the communication resource information collected from the multiple communication devices 10, and can optimize or switch communication resources accordingly.

[0087] Although the present embodiment has been described with reference to an example in which the security risk type is jamming, communication device 10 may determine that the security risk type is eavesdropping depending on the results of monitoring the wireless environment. In this case, communication device 10 may perform beamforming or antenna selection so that the beam gain in the direction of the security risk position is minimized during wireless transmission, or may select communication device 20 as the wireless transmission destination, thereby reducing the security risk.

[0088] Furthermore, when the communication device 10 detects wireless access to itself from an unknown communication device via a wireless protocol, it can determine that the security risk type is unauthorized login. In this case, the communication device 10 can reduce the security risk by emitting jamming radio waves in the direction of the security risk location at a time other than when the communication device 10 is wirelessly transmitting, or by wirelessly transmitting jamming radio waves using wireless resources that do not affect the reception of user data by the communication device targeted by the unauthorized login.

[0089] The configurations described in the above embodiments are merely examples, and may be combined with other known technologies. Parts of the configurations may be omitted or modified without departing from the spirit of the present disclosure. The sizes, shapes, and number of devices illustrated in the drawings used to describe the above embodiments are not limited to those shown and may be modified as appropriate within the scope of the effects of the present disclosure. Other modifications may be made as appropriate without departing from the scope of the present disclosure. For example, in the above embodiments, the external device connected to the communication device 10 via a wire is the camera 2. However, a radar or LiDAR (Light Detection and Ranging) device that detects objects may be used instead of the camera 2. In this case, object detection results including information such as the distance to an object detected by the radar or LiDAR, the shape and size of the object, etc., are input to the communication device 10 as application traffic.

[0090] Various aspects of the present disclosure are summarized below as appendices.

[0091] (Supplementary Note 1) A communication device comprising: a wireless communication unit that transmits and receives wireless signals to and from other communication devices; a security risk location estimation unit that estimates a security risk location indicating the location of a security risk and a security risk type indicating the type of security risk based on monitoring results of a wireless environment around the device and application traffic acquired from an external device; and a communication resource control unit that selects a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determines the selected communication resource as the communication resource to be used for transmitting the application traffic. (Supplementary Note 2) The communication device according to Supplementary Note 1, wherein, when the security risk is jamming, the communication resource control unit selects a communication device on the upper network side that is estimated to be least affected by jamming as the destination of the wireless signal transmitted by the wireless communication unit. (Supplementary Note 3) The communication device according to Supplementary Note 1 or 2, wherein, when the security risk is eavesdropping, the communication resource control unit determines to perform beamforming or antenna selection so as to reduce beam gain in the direction of the security risk location. (Supplementary Note 4) The communication device according to any one of Supplementary Notes 1 to 3, wherein, when the security risk is an unauthorized login, the communication resource control unit determines to emit jamming radio waves in the direction of the location of the security risk when the wireless communication unit does not transmit the wireless signal. (Supplementary Note 5) The communication device according to any one of Supplementary Notes 1 to 4, wherein a video stream obtained by capturing an image of the periphery of the device is used as the application traffic, and the security risk location estimation unit estimates the security risk location based on an image obtained by analyzing the video stream.(Supplementary Note 6) The communication device according to any one of Supplements 1 to 4, wherein the application traffic is a detection result of an object present in the vicinity of the communication device, and the security risk location estimation unit estimates the security risk location based on information on the distance from the communication device to the object obtained by analyzing the detection result and information on the shape and size of the object. (Supplementary Note 7) The communication device according to any one of Supplements 1 to 4, wherein the external device is a camera, and the security risk location estimation unit estimates the security risk location based on an image obtained by analyzing a video stream output by the camera. (Supplementary Note 8) The communication device according to any one of Supplements 1 to 4, wherein the external device is a radar, and the security risk location estimation unit estimates the security risk location based on the object detection result output by the radar. (Supplementary Note 9) The communication device according to any one of Supplements 1 to 4, wherein the external device is a LIDAR, and the security risk location estimation unit estimates the security risk location based on the object detection result output by the LIDAR. (Supplementary Note 10) A communication resource control method for determining communication resources to be used by a communication device having a wireless communication unit for transmitting and receiving wireless signals to and from other communication devices for transmitting and receiving the wireless signals, comprising: a first step of estimating a security risk location indicating the location where a security risk has occurred and a security risk type indicating the type of security risk, based on monitoring results of a wireless environment around the device and application traffic acquired from an external device; and a second step of selecting a communication resource that is less affected by the security risk, based on the security risk location and the security risk type, and determining the selected communication resource as the communication resource to be used for transmitting the application traffic.(Supplementary Note 11) A control circuit constituting a communication device having a function of transmitting and receiving wireless signals to and from other communication devices, characterized in that the control circuit executes the following steps: a first step of estimating a security risk location indicating the location where a security risk occurs and a security risk type indicating the type of security risk based on the results of monitoring the wireless environment around the device and application traffic acquired from an external device; and a second step of selecting a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determining the selected communication resource as the communication resource to be used for transmitting the application traffic. (Supplementary Note 12) A storage medium storing a program executed by a control circuit constituting a communication device having the function of transmitting and receiving wireless signals with other communication devices, the program causing the control circuit to execute the following steps: a first step of estimating a security risk location indicating the location where a security risk has occurred and a security risk type indicating the type of security risk based on the results of monitoring the wireless environment around the device and application traffic acquired from an external device; and a second step of selecting a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determining the selected communication resource as the communication resource to be used for transmitting the application traffic.

[0092] 1 Social infrastructure system protective wall, 2 Camera, 10, 20, 20A, 20B Communication device, 30 Communication control device, 40 Application server, 50 Security risk location, 100 Communication system, 101 Security risk detection unit, 102 Security risk location estimation unit, 103 Wireless communication unit, 104, 304 Wired communication unit, 105 Traffic analysis unit, 106 Communication resource control unit, 107, 305 Memory unit, 109, 309 Wired NIC unit, 110 Antenna unit, 301 Mobility management unit, 302 Security management unit, 303 Communication resource management unit, 501 Suspicious person.

Claims

1. A communication device comprising: a wireless communication unit that transmits and receives wireless signals to and from other communication devices; a security risk location estimation unit that estimates a security risk location indicating the location where a security risk occurs and a security risk type indicating the type of security risk based on the results of monitoring the wireless environment around the device and application traffic obtained from an external device; and a communication resource control unit that selects a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determines the selected communication resource as the communication resource to be used for transmitting the application traffic.

2. The communication device described in claim 1, characterized in that, when the security risk is jamming, the communication resource control unit selects a communication device on the upper network side that is estimated to be least susceptible to jamming as the destination of the wireless signal from the wireless communication unit.

3. The communication device according to claim 1 or 2, characterized in that, when the security risk is eavesdropping, the communication resource control unit determines to perform beamforming or antenna selection so as to reduce the beam gain in the direction of the location where the security risk occurs.

4. A communication device described in any one of claims 1 to 3, characterized in that, when the security risk is an unauthorized login, the communication resource control unit decides to emit jamming radio waves in the direction of the location where the security risk occurs when the wireless communication unit does not transmit the wireless signal.

5. A communication device as described in any one of claims 1 to 4, characterized in that the application traffic is a video stream obtained by photographing the area around the device, and the security risk location estimation unit estimates the security risk location based on an image obtained by analyzing the video stream.

6. A communication device as described in any one of claims 1 to 4, characterized in that the application traffic is the detection result of an object present in the vicinity of the device, and the security risk location estimation unit estimates the security risk location based on information on the distance from the device to the object obtained by analyzing the detection result, and information on the shape and size of the object.

7. A communication device as described in any one of claims 1 to 4, characterized in that the external device is a camera, and the security risk position estimation unit estimates the security risk position based on an image obtained by analyzing a video stream output by the camera.

8. A communication device as described in any one of claims 1 to 4, characterized in that the external device is a radar, and the security risk position estimation unit estimates the security risk position based on the object detection results output by the radar.

9. A communication device described in any one of claims 1 to 4, characterized in that the external device is a LIDAR, and the security risk position estimation unit estimates the security risk position based on the object detection results output by the LIDAR.

10. A communications resource control method for determining communications resources to be used by a communications device having a wireless communication unit for transmitting and receiving wireless signals to and from other communications devices for transmitting and receiving said wireless signals, comprising: a first step of estimating a security risk location indicating the location where a security risk has occurred and a security risk type indicating the type of security risk based on the results of monitoring the wireless environment around the device and application traffic acquired from an external device; and a second step of selecting communications resources that are less affected by the security risk based on the security risk location and the security risk type, and determining the selected communications resources as communications resources to be used for transmitting the application traffic.

11. A control circuit constituting a communication device having the function of transmitting and receiving wireless signals to and from other communication devices, characterized by executing the following steps: a first step of estimating a security risk location indicating the location where a security risk occurs and a security risk type indicating the type of security risk based on the results of monitoring the wireless environment around the device and application traffic acquired from an external device; and a second step of selecting a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determining the selected communication resource as the communication resource to be used for transmitting the application traffic.

12. A storage medium storing a program executed by a control circuit constituting a communication device having the function of transmitting and receiving wireless signals to and from other communication devices, characterized in that the program causes the control circuit to execute the following steps: a first step of estimating a security risk location indicating the location where a security risk occurs and a security risk type indicating the type of security risk based on the results of monitoring the wireless environment around the device and application traffic acquired from an external device; and a second step of selecting a communication resource that is less affected by the security risk based on the security risk location and the security risk type, and determining the selected communication resource as the communication resource to be used for transmitting the application traffic.

Citation Information

Patent Citations

  • Collaborative Early Threat Detection Using Sensor Sharing

    JP2024519792A

  • Systems and methods for detecting microwave pulses

    US20230132787A1