Virtual Communication Model Using Library-Level Security Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual models of communication systems lack detailed information about software vulnerabilities, making it difficult to diagnose security risks accurately.

Innovation Solution

A data processing device and method that acquire and analyze information security inspection results to generate a virtual model of a communication system, incorporating configuration and security inspection information to detail library functions and file access, enabling precise security risk diagnosis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a virtual model is generated using conventional vulnerability diagnosis tools, then the model can be constructed without physical duplication costs, but the model lacks detailed vulnerability information necessary for precise security risk diagnosis

Engineering Contradiction:
Improvesecurity risk diagnosis precisionVSAvoidvulnerability detail information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the virtual model into multiple hierarchical layers: device information, software component information, library function information, and vulnerability information. This segmentation allows each layer to contain specific types of data, with the vulnerability layer providing detailed security information while maintaining an organized structure that prevents information loss.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary information collection and organization before constructing the virtual model. Inspection results are gathered in advance, parsed to extract vulnerability details, and structured into the virtual model framework beforehand, ensuring that detailed vulnerability information is captured and preserved in the final model.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If detailed security inspection information is collected and integrated into the virtual model, then security risk diagnosis capability is improved, but the complexity of the virtual model increases

Engineering Contradiction:
Improvesecurity risk diagnosis reliabilityVSAvoidvirtual model complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual model is divided into distinct modules: device information module, software component module, library function module, and vulnerability information module. Each module handles specific types of data, which improves reliability by ensuring comprehensive coverage while managing complexity through modular organization and clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the virtual model structure, organizing information from general device-level data down to specific vulnerability-level details. This dimensional organization allows the model to accommodate detailed security information without becoming unwieldy, as the hierarchy provides a natural framework for managing complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12574402B2Data processing device, data processing method, and recording medium
Publication Date: 2026.03.10 NEC CORP
  • US12574402B2 patent drawing
  • US12574402B2 patent drawing
  • US12574402B2 patent drawing

AI summary

To provide a virtual model for a communication system, the virtual model being required for specific diagnosis of the security risk of the communication system. An acquisition unit (11) acquires the inspection result of an information security inspection on a device constituting a communication system, an extraction unit (12) extracts, from the inspection result, security inspection information including at least one of first information about a library function used by the constituent device or second information about the presence or absence of access to a file via the library function, and a generation unit (13) generates a virtual model for the communication system by using configuration information for identifying a constituent component of an information communication device and the security inspection information.