IP Library › Granted Patent US 12,730,900
Granted Patent B2
US 12,730,900 · App. 18/875,856 · Granted Sep 8, 2026

System design device, system design method, and storage medium

Inventors: Ryosuke Hotchi (Tokyo, JP); Takayuki Kuroda (Tokyo, JP)
Assignee: NEC CORPORATION
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,900
App. No.
18/875,856
Granted
Sep 8, 2026
Kind
B2
Abstract

First configuration information is acquired, which includes information on a topology using components of any one component of nodes in a computer system and an edge indicating a relationship between nodes. A configuration of a topology of first configuration information is concretized. Whether or not a security threat event may occur in a node or an edge in the configuration of the concretized topology is determined, and configuration information is generated in which information indicating a relationship between the configuration component in which a threat may occur if the threat event may occur and another configuration component in which another threat contributing to the occurrence of the threat may occur, is added. Whether the content of each threat is concrete or abstract in a threat chain path based on the relationship between the threat in the configuration information and another threat that contributes to the occurrence of the threat, is determined, and whether or not a design is insecure if the content of the threat is concrete or if it is abstract, is determined.

Claims (32)

1 . A system design device comprising:

at least one memory configured to store instructions; and

at least one processor configured to execute the instructions to:

acquire first configuration information at least including information on a topology of a computer system using configuration components in the computer system;

generate second configuration information that concretizes a configuration of the topology in the first configuration information;

determine whether or not a security threat event may occur in the configuration component of the concretized topology, and generate third configuration information by adding information indicating a relationship between: an identifier of a threat if a threat event may occur; the configuration component in which the threat may occur; an identifier of another threat contributing to the occurrence of the threat; and another configuration component in which this another threat may occur, to the second configuration information;

determine whether a content of each threat is concrete or abstract in a threat chain path based on a relationship between the threat in the third configuration information and another threat that contributes to the occurrence of the threat, and determine whether or not a design of a computer system in this third configuration information is insecure if a content of the threat is concrete or if it is abstract; and

determine the design of the computer system of the third configuration information as insecure if the content of the threat is all concrete in the threat chain path, or if the content of the threat is abstract in any configuration component of the threat chain path and it is determined that the abstract threat is unavoidably replaced with a concrete threat.

2 . The system design device according to claim 1 , wherein the at least one processor is configured to execute the instructions to:

generate the second configuration information that concretizes one of grouping units of predetermined configuration components in the topology of the computer system of the first configuration information input at the start of processing;

repeat a process of generating new second configuration information that concretizes the one of grouping units of the predetermined configuration components in the topology of the computer system of the first configuration information, where the third configuration information, generated based on the second configuration information, and not determined to be insecure in the design of the computer system, is used as new first configuration information;

repeat a process of generating the third configuration information based on the second configuration information; and

output the third configuration information as a design result if none of the grouping units of the predetermined configuration components in the topology of the computer system of the third configuration information can be further concretized and the design of the computer system of the third configuration information is not determined as insecure.

3 . The system design device according to claim 1 , wherein the at least one processor is configured to execute the instructions to give information indicating whether information on threat to be added to the second configuration information is concrete or abstract based on a threat concretization rule indicating a threat defined according to the topology, to the third configuration information, and

wherein the at least one processor is configured to execute the instructions to determine the design of the computer system of the third configuration information as insecure (1) if the content of the threat is all concrete in the threat chain path based on the information given to the third configuration information, or (2) if the content of the threat is abstract in any configuration component of the threat chain path and it is determined that there is no means of avoiding the abstract threat from being replaced with the concrete threat.

4 . The system design device according to claim 3 , wherein the at least one processor is configured to execute the instructions to:

identify, if the abstract threat is included in the threat chain path, the path as an abstract attack path indicating the threat chain path along which a security attack may occur, based on the threat included in the path; and

identify, if the abstract threat is not included in the threat chain path, the path as a concrete attack path indicating the threat chain path along which a security attack may occur, based on the threat included in the path.

5 . The system design device according to claim 4 , wherein the at least one processor is configured to execute the instructions to, if the content of the threat is such that any configuration component of the abstract attack path is abstract and all configuration components in which the abstract threat may occur cannot be given the characteristic of preventing the threat, determine that there is no means of avoiding the abstract threat from being replaced with the concrete threat; and

determine the design of the computer system of the third configuration information as insecure.

6 . A system design method comprising:

acquiring first configuration information at least including information on a topology of a computer system using configuration components in the computer system;

generating second configuration information that concretizes a configuration of the topology in the first configuration information;

determining whether or not a security threat event may occur in the configuration component of the concretized topology, and generating third configuration information by adding information indicating a relationship between: an identifier of a threat if a threat event may occur; the configuration component in which the threat may occur; an identifier of another threat contributing to the occurrence of the threat; and another configuration component in which this another threat may occur, to the second configuration information;

determining whether a content of each threat is concrete or abstract in a threat chain path based on a relationship between the threat in the third configuration information and another threat that contributes to the occurrence of the threat, and determining whether or not a design of a computer system in this third configuration information is insecure if a content of the threat is concrete or if it is abstract; and

determining the design of the computer system of the third configuration information as insecure if the content of the threat is all concrete in the threat chain path, or if the content of the threat is abstract in any configuration component of the threat chain path and it is determined that the abstract threat is unavoidably replaced with a concrete threat.

7 . A non-transitory storage medium storing a program that causes a computer of a system design device to execute:

acquiring first configuration information at least including information on a topology of a computer system using configuration components in the computer system;

generating second configuration information that concretizes a configuration of the topology in the first configuration information;

determining whether or not a security threat event may occur in the configuration component of the concretized topology, and generates third configuration information by adding information indicating a relationship between: an identifier of a threat if a threat event may occur; the configuration component in which the threat may occur; an identifier of another threat contributing to the occurrence of the threat; and another configuration component in which this another threat may occur, to the second configuration information;

determining whether a content of each threat is concrete or abstract in a threat chain path based on a relationship between the threat in the third configuration information and another threat that contributes to the occurrence of the threat, and determining whether or not a design of a computer system in this third configuration information is insecure if a content of the threat is concrete or if it is abstract; and

determining the design of the computer system of the third configuration information as insecure if the content of the threat is all concrete in the threat chain path, or if the content of the threat is abstract in any configuration component of the threat chain path and it is determined that the abstract threat is unavoidably replaced with a concrete threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2024
From: HOTCHI, RYOSUKE; KURODA, TAKAYUKI
To: NEC CORPORATION
Reel/Frame 069609/0514 →
Continuity (1)
Related Publication 20250384143A1 · Dec 18, 2025
References Cited (7)
US 12282562B2 · Stolbikov · 2025 [cited by examiner]
US 20180068241A1 · Varkey et al. · 2018 [cited by applicant]
JP 2008107982A · 2008 [cited by applicant]
JP 2013152577A · 2013 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2022/032256, mailed on Oct. 4, 2022. [cited by applicant]
Lukas Gressl et al., Design Space Exploration for Secure IoT Devices and Cyber-Physical Systems, ACM Transactions on Embedded Computing Systems, vol. 20, No. 4, May 2021. [cited by applicant]
Sian En Ooi et al., Intent-Driven Secure System Design: Methodology and Implementation, Preprint submitted to Computers & Security, Mar. 15, 2022. [cited by applicant]