FUNCTION ALLOCATION CONTROL APPARATUS, FUNCTION ALLOCATION CONTROL METHOD AND PROGRAM
A function allocation control device for controlling a security verification system that executes a security verification function allocated to a target entity, the function allocation control device including: a trust score calculation unit configured to calculate a trust score indicating a security level of each entity on the basis of verification result information indicating a result of verifying security of each entity; a security verification function allocation unit configured to allocate a security verification function to each entity on the basis of the calculated trust score and resource information indicating a resource used for achieving the security verification function allocated to each entity; and a security verification function control unit configured to control the security verification system so as to execute the allocated security verification function.
1 . A function allocation control device for controlling a security verification system that executes a security verification function, the function allocation control device comprising a processor configured to execute operations comprising:
calculating a trust score, the trust score indicating a security level of each entity on the basis of verification result information, and the verification result information indicating a result of verifying security of each entity;
allocating a security verification function to each entity on the basis of the calculated trust score and resource information, the resource information indicating a resource used for achieving the security verification function allocated to each entity; and
transmitting information of the allocated security verification function to the security verification system configured to execute the allocated security verification function.
2 . The function allocation control device according to claim 1 , wherein the allocating further comprises:
extracting an entity that is a candidate for changing the number of security verification functions to be allocated or changing a verification schedule, on the basis of the calculated trust score,
determining whether or not to change allocation of the security verification function or whether or not to change the verification schedule, for the extracted entity on the basis of the resource information, and,
determining, based on the determining to change, a more specific content of the change.
3 . The function allocation control device according to claim 2 , wherein the allocating further comprises extracting an entity indicating high trust as a candidate for changing the verification schedule either to reduce the number of security verification functions to be allocated or to reduce a verification execution frequency.
4 . The function allocation control device according to claim 3 , wherein the resource information includes information indicating a resource actually used by each entity in the security verification function, and
the allocating further comprises determining, on the basis of the resource information, a reduction amount of resources to reduce the security verification functions or to reduce a verification frequency.
5 . The function allocation control device according to claim 2 , wherein the allocating further comprises extracting an entity indicating low trust as a candidate for increasing the number of security verification functions to be allocated.
6 . The function allocation control device according to claim 5 , wherein the resource information includes information indicating a standard resource used in each security verification function, and
the allocating further comprises determining, on the basis of the resource information, an increase amount of resources when a security verification function is added.
7 . A computer-implemented method for controlling a security verification system that executes a security verification function, comprising:
calculating a trust score, the trust score indicating a security level of each entity on the basis of verification result information, and the verification result information indicating a result of verifying security of each entity;
allocating a security verification function to each entity on the basis of the calculated trust score and resource information, the resource information indicating a resource used for achieving the security verification function allocated to each entity; and
transmitting information of the allocated security verification function to the security verification system configured to execute the allocated security verification function.
8 . A computer-readable non-transitory recording medium storing a computer-executable program instructions that when executed by a processor cause a computer system to execute operations for controlling a security verification system that executes a security verification function, comprising:
calculating a trust score, the trust score indicating a security level of each entity on the basis of verification result information, and the verification result information indicating a result of verifying security of each entity;
allocating a security verification function to each entity on the basis of the calculated trust score and resource information, the resource information indicating a resource used for achieving the security verification function allocated to each entity; and
transmitting information of the allocated security verification function to the security verification system configured to execute the allocated security verification function.
9 . The function allocation control device according to claim 3 , wherein the allocating further comprises extracting an entity indicating low trust as a candidate for increasing the number of security verification functions to be allocated.
10 . The computer-implemented method according to claim 7 , wherein the allocating further comprises:
extracting an entity that is a candidate for changing the number of security verification functions to be allocated or changing a verification schedule, on the basis of the calculated trust score,
determining whether or not to change allocation of the security verification function or whether or not to change the verification schedule, for the extracted entity on the basis of the resource information, and,
determining, based on the determining to change, a more specific content of the change.
11 . The computer-implemented method according to claim 10 , wherein the allocating further comprises extracting an entity indicating high trust as a candidate for changing the verification schedule either to reduce the number of security verification functions to be allocated or to reduce a verification execution frequency.
12 . The computer-implemented method according to claim 11 , wherein the resource information includes information indicating a resource actually used by each entity in the security verification function, and
the allocating further comprises determining, on the basis of the resource information, a reduction amount of resources to reduce the security verification functions or to reduce a verification frequency.
13 . The computer-implemented method according to claim 10 , wherein the allocating further comprises extracting an entity indicating low trust as a candidate for increasing the number of security verification functions to be allocated.
14 . The computer-implemented method according to claim 13 , wherein the resource information includes information indicating a standard resource used in each security verification function, and
the allocating further comprises determining, on the basis of the resource information, an increase amount of resources when a security verification function is added.
15 . The computer-implemented method according to claim 11 , wherein the allocating further comprises extracting an entity indicating low trust as a candidate for increasing the number of security verification functions to be allocated.
16 . The computer-readable non-transitory recording medium according to claim 8 , wherein the allocating further comprises:
extracting an entity that is a candidate for changing the number of security verification functions to be allocated or changing a verification schedule, on the basis of the calculated trust score,
determining whether or not to change allocation of the security verification function or whether or not to change the verification schedule, for the extracted entity on the basis of the resource information, and,
determining, based on the determining to change, a more specific content of the change.
17 . The computer-readable non-transitory recording medium according to claim 16 , wherein the allocating further comprises extracting an entity indicating high trust as a candidate for changing the verification schedule either to reduce the number of security verification functions to be allocated or to reduce a verification execution frequency.
18 . The computer-readable non-transitory recording medium according to claim 17 , wherein the resource information includes information indicating a resource actually used by each entity in the security verification function, and
the allocating further comprises determining, on the basis of the resource information, a reduction amount of resources to reduce the security verification functions or to reduce a verification frequency.
19 . The computer-readable non-transitory recording medium according to claim 16 , wherein the allocating further comprises extracting an entity indicating low trust as a candidate for increasing the number of security verification functions to be allocated.
20 . The computer-readable non-transitory recording medium according to claim 19 , wherein the resource information includes information indicating a standard resource used in each security verification function, and
the allocating further comprises determining, on the basis of the resource information, an increase amount of resources when a security verification function is added.