Device for integrated management of attribute information
Abstract
Problem to be solved.To enable integrated management of attribute information individually managed in a database and a directory. A conversion program 20 inputs change source change information and conversion destination write destination information as parameters, and is managed by an attribute DB 1 and an attribute directory 3 based on the information and the stored information of the conversion table 70. The attribute information specified by the change source change information is changed by the DB master conversion engine 15 and the directory conversion engine 14. [Selection diagram] Fig. 2

Term
Term ended
Projected expiry passed 15 July 2022, 4.2 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
6 claims: 3 independent, 3 dependent
- 1データベース及びディレクトリに個別に管理されている属性情報を統合管理するための変換ルールを格納している管理手段と、該管理手段に格納されている変換ルールを参照して、前記データベースまたは前記ディレクトリに管理されている属性情報を変更する変換手段と、を備えることを特徴とする属性情報統合管理装置。
- 2前記管理手段は、前記変換ルールを格納する変換テーブルを有し、該変換テーブルは、前記変換ルールに関する情報として、変換先のデータベースまたはディレクトリを識別するための情報、及び各データベース及び各ディレクトリの構造情報を格納し、前記変換手段は、前記識別情報及び前記構造情報を基に、前記変換先のデータベースまたはディレクトリをアクセスすることを特徴とする請求項1記載の属性情報統合管理装置。
- 3前記変換テーブルは、前記変換ルールに関する情報として、さらに、各データベースまたは各ディレクトリにおいて必要な特殊処理の識別情報を格納し、前記変換手段は、当該データベースまたは当該ディレクトリに対して前記識別情報により特定される特殊処理を実行することを特徴とすることを請求項2記載の属性情報統合管理装置。
- 4前記変換テーブルにおいて、対称範囲のデータベース及びディレクトリに共通な情報を一元的なキーとして定義し、前記変換手段は、前記キーを基に、前記対称範囲のデータベースまたは前記ディレクトリの属性情報の追加または削除を行うことを特徴とする請求項2記載の属性情報統合管理装置。
- 5データベース及びディレクトリに個別に管理されている属性情報を統合管理するための変換ルールを格納し、該変換ルールを参照して、前記データベースまたは前記ディレクトリに管理されている属性情報を変更することを特徴とする属性情報統合管理方法。
- 6データベース及びディレクトリに個別に管理されている属性情報を統合管理するための変換ルールを格納する機能と、該変換ルールを参照して、前記データベースまたは前記ディレクトリに管理されている属性情報を変更する機能を、コンピュータに実行させるプログラム。
Independent claims6
99 paragraphs, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates to an attribute information management technique for centrally managing attribute information such as name, affiliation, and position, and is particularly suitable for access control of an electronic authentication system.
【0002】
[Conventional technology]
For example, in an electronic authentication system, attribute information such as name, organization, and job title is used as determination information for controlling access rights. In addition, attribute information is used in employee authentication in government offices, employee authentication in private companies, PKI (Public Key Infrastructure) electronic signature authentication in electronic applications, PKI electronic signature authentication in electronic medical records, and the like.
【0003】
FIG. 6 is a diagram showing the configuration of a conventional electronic authentication system. In the figure, the authentication server 102 of the electronic authentication system 100 manages the electronic authentication data by the attribute DB (attribute database) 101, and the client 104 uses the authentication server 102 to access the electronic certificate in order to access the server 103. Need to get. Further, the authentication server 206 of the electronic authentication system 200 manages the electronic authentication data by the attribute directory 201, and the client 208 needs to acquire the electronic certificate from the authentication server 206 in order to access the server 207. There is. Further, the existing master 301 is a file that manages the attribute information like the attribute DB 101 and the attribute directory 201.
【0004】
In the conventional system shown in the figure, the attribute information is individually managed by the attribute DB (attribute database) 101, the attribute directory 201, the existing master 301, etc., and the attribute management (attribute information such as organization and position) Management) was not centralized. When trying to integrate two of these three types of management devices, it was necessary to take measures such as matching one to the other or constructing a new management device. By the way, regarding directories, there is a concept of metadirectory that integrates directories into one, but this supports only directories, not DB (database). In addition, this is not a specific one for electronic authentication, but a general-purpose one, and in order to actually use it for an electronic authentication system, individualized programming was required.
【0005】
[Problems to be Solved by the Invention]
If the attribute information is managed by individual devices as in the conventional system, for example, every time an organizational change or personnel change occurs, a great deal of effort is required to manage the individual attribute DB 101 or attribute directory 201. It is necessary to change the information, which is costly, and there are problems such as the time required for the change and the occurrence of mistakes due to the change work. In addition, in order to integrate each attribute directory 201 or attribute DB 101, the existing system is modified, and there is a problem of whether or not the modification is possible. In addition, the metadirectory technology cannot be applied to DB, and there is also a problem that the system of attribute DB101 cannot be integrated.
【0006】
The present invention makes it easy, fast, and reliable to change the attribute information managed individually by the DB, the directory, and the existing master when the attribute information managed by the DB, the directory, and the existing master is changed. By making it possible to change all at once and to realize this change work without changing the existing system, it is possible to realize unified integrated management of attribute information managed in individual DBs and directories. The purpose is to reduce the cost of remodeling.
【0007】
[Means for solving problems]
The attribute information integrated management device of the present invention has a management means for storing conversion rules for integrated management of attribute information individually managed in a database and a directory, and a conversion rule stored in the management means. It is provided with a conversion means for changing the attribute information managed in the database or the directory with reference to the reference.
【0008】
In the attribute information integrated management device having the above configuration, for example, the management means has a conversion table for storing the conversion rule, and the conversion table identifies a conversion destination database or directory as information regarding the conversion rule. The information for the purpose and the structural information of each database and each directory may be stored, and the conversion means may be configured to access the conversion destination database or directory based on the identification information and the structural information. ..
【0009】
Further, in the attribute information integrated management device having the above configuration, for example, the conversion table stores, for example, information on the conversion rule and identification information of special processing required in each database or each directory, and the conversion means. May be configured to perform special processing specified by the identification information on the database or the directory.
【0010】
Further, in the attribute information integrated management device having the above configuration, for example, in the conversion table, information common to databases and directories in a symmetric range is defined as a unified key, and the conversion means is based on the key. The database in the symmetric range or the attribute information of the directory may be added or deleted.
【0011】
The attribute information integrated management method of the present invention stores a conversion rule for integrated management of attribute information individually managed in a database and a directory, and is managed in the database or the directory with reference to the conversion rule. Change the attribute information.
【0012】
The program of the present invention has a function of storing a conversion rule for integrated management of attribute information individually managed in a database and a directory, and is managed in the database or the directory with reference to the conversion rule. Have the computer perform the function of changing the attribute information.
【0013】
The present invention provides a conversion rule for integrated management of attribute information individually managed in a database and a directory, and changes the attribute information managed in the database or the directory with reference to the conversion rule. To do so. As a result, it is possible to collectively change the attribute information managed individually for each of the database and the directory, and it is possible to realize the integrated management of the database and the directory.
【0014】
Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIG. 1 is a diagram showing a system configuration of an electronic authentication system to which the attribute information management device according to the embodiment of the present invention is applied.
【0015】
In the figure, the authentication server 2 manages the access control information of the server (application server) 9 by the information managed by the attribute DB (attribute database) 1. The authentication server 5 manages the access control information of the server 9 by the information managed by the attribute directory 3. The extended metadirectory 7 integrates and manages the attribute DB1, the attribute directory 3, and the existing master 6 according to the conversion rule. The conversion rule is described in, for example, a table (conversion table).
【0016】
When the client 8 accesses the server 9, it manages the server 9 by acquiring the access authority level from the management information of the attribute directory 3 via the authentication server 5 and passing the access authority level to the server 9. Access is possible within the range permitted by the existing access authority level.
【0017】
Further, since the information of the attribute DB1, the attribute directory 3, and the existing master 6 is equivalent by the extended metadirectory 7, even if the client 8 is authenticated by the authentication server 2, the above-mentioned authentication by the authentication server 5 is performed. The result is similar to. However, the above result does not apply when the authentication server 2 manages unique attribute information and sets the access authority level independently.
【0018】
As can be seen by comparing FIGS. 1 and 6, in the present embodiment, the extended metadirectory 7 is added to the conventional system of FIG. 6, and the extended metadirectory 7 adds the attribute DB1, the attribute directory 3, and the existing master 6. It is configured for integrated management.
【0019】
FIG. 2 is a software configuration diagram of the system of FIG. Attribute directory 3 manages attribute master information, certificates for PKI (Public Key Infrastructure) authentication, revocation list, and so on. The attribute DB1 manages information such as personnel information in the personnel master and affiliation and job title in the attribute master. In some cases, the attribute master manages generation information, which is past attribute information.
【0020】
The extended metadirectory 7 has a conversion table 70 that stores conversion rules for updating the contents of the attribute directory 3 and the attribute DB1. The conversion program 20 has a directory conversion engine 14 and a DB system master conversion engine 15, and starts the engine of these. The directory conversion engine 14 uses LAPD (Light Weight Directory Access Protocol) to access the information in the attribute directory 3. The DB master conversion engine 15 accesses the information of the attribute DB1 using SQL (Structure Query Language).
【0021】
The attribute information management device of this embodiment is composed of an extended metadirectory 7 and a conversion program 20 (including a directory conversion engine 14 and a DB system master conversion engine 15).
【0022】
Since the authentication server 2, the application server 9, and the client 8 are not components of the embodiment of the present invention, the description of the software configuration of the authentication server 2 and the application server 9 will be omitted. Client 8 is equipped with a PKI-compatible Web browser, a metadirectory, a master management tool that supports PMI (Privilege Management Infrastructure) functions, and an IC card reader that is equipped with a GPKI (Government PKI) -compatible IC card.
【0023】
FIG. 3 is a diagram showing the contents of conversion source change information which is an input value (parameter) of the conversion program 20. The conversion source change information 71 shown in the figure is the change attribute item that specifies which attribute information is to be changed, the information before the change (information before change) and the information after change (information after change) of the attribute information to be changed. This is a list of sets of, and is the input of conversion program 20. This conversion source change information 71 is input to the conversion program 20 when, for example, CSV format, Excel table, DB, or directory change information and change information are specified.
【0024】
The DB information (information of attribute DB1) and directory information (information of attribute directory 3) may be converted source change information 71 as it is. FIG. 4 is a diagram showing the configuration of the conversion table 70.
【0025】
FIG. 6A is a diagram showing items constituting the conversion rule stored in the conversion table 70. The conversion table 70 is composed of five items: "conversion ID 70a", "conversion destination type 70b (DB or directory)", "conversion destination name 70c", "DB and directory structure information 70d", and "conversion engine ID 70e". ing.
【0026】
The conversion ID 70a is an identifier set for each DB or each directory and used to identify the conversion. The conversion destination type 70b is information indicating whether the conversion destination is a DB or a directory. The conversion destination name 70c is the name of the DB or directory that is the conversion destination. The DB and directory structure information 70d is information indicating the database structure of the conversion destination attribute DB1 and the directory structure of the conversion destination attribute directory 3. The conversion engine ID 70e is an identifier used to identify the special processing when performing the special processing. The special process is a process required when, for example, the structure of the conversion destination DB is not normalized. In such a case, a conversion of 1 to N (N is a natural number of 2 or more) is required instead of 1 to 1. Since the conversion table 70 is based on one-to-one conversion, when one-to-N conversion is required, it is written in N places by special processing.
【0027】
FIG. 3B is a diagram showing an example of DB and directory structure information 70d stored in the conversion table 70. Figure (b) shows the structural information of master A (personnel master) and B (attribute master), which are master DBs belonging to attribute DB1, and directory A, which is the attribute master of attribute directory 3. .. Master A is, for example, a human resources master, and its record consists of three fields, a key and attributes A and B. Further, the master B is, for example, an attribute master, and the record is composed of four fields of a key and attributes A, B, and D. The object in directory A consists of keys, attributes A, B, and C. If the "conversion ID 70a" of the conversion table 70 is the ID of the attribute DB1, the "DB and directory structure information 70d" of the conversion table 70 includes the master A (personnel master) and the master B (personnel master) shown in the figure (a). The structure information of the attribute master) is stored.
【0028】
In this embodiment, unique information common to the symmetric DB (attribute DB1) and the directory (attribute directory 3) is defined as a key. In the example of Fig. (B), the name ID is the key. Some attribute information is common to all DBs and directories, and some is unique to each DB or directory.
【0029】
FIG. 5 is a flowchart showing the processing flow of the conversion program 20. The conversion program 20 is automatically or manually started in units of conversion ID 70a (see FIG. 4A) with the conversion source change information 71 and the conversion destination write destination information specified as parameters.
【0030】
First, in "Reading conversion information", when a personnel change or organizational change occurs, the change source change information 71 shown in FIG. 3 is read (step S1). The change information may be shown in a data column or in a format stored in a DB or directory. For example, in the case of a data string, it is shown in CSV format of "0011, Taro Yamada, position, assistant section chief, section chief". Also, in the case of DB,<img file="JP2004046733A_D0001.tif" />Indicated by.
[0031] In the case of a directory, it is indicated by the directory name ID 0011 before the change, Taro Yamada --- assistant manager of the position property section, and the directory name after the change, ID 0011 Taro Yamada --- the manager of the position property section.
【0032】
In this case, it is automatically generated from the DB or the directory based on the information read in step S3 described later. In other words, in the case of the above DB and the above directory, the difference between the information before change and the information after change is calculated, and the information of 0011 Taro Yamada, assistant section chief before change, and section chief after change is automatically created.
【0033】
Then, in "Read conversion table", the conversion table 70 shown in FIG. 4 (a) is read (step S2). Then, in "Reading the structural information of the conversion destination and the conversion destination", "Conversion destination type 70b", "Conversion destination name 70c" and "DB and directory structure information 70d" are read from the conversion table 70 (step S3).
【0034】
Next, in "Read conversion destination write destination information (temporary area, etc.)", the conversion destination write destination information specified as a parameter is read, and based on this information, the conversion source change information 71 read in step S1. Identify the write area (step S4). This is because the attribute information often has a fixed time to replace the information, and before that, the temporary area or the fixed area is written and operated at the specified time (in the conversion destination write destination information). This is because it is often actually written in the specified area)).
【0035】
Next, determine if there is "add or delete key", and if there is "add or delete key", if the name ID is used as the key, if the person is no longer moving out or new When transferring to, add / delete DB records and add directory attributes (step S6).
【0036】
If it is determined in step S5 that there is no key addition or deletion, or after the processing in step S6, read in step S1 with "Write the relevant information from the conversion source change information and structure information to the conversion destination write destination". However, based on the conversion source change information, the "conversion destination type 70b" read in step S2 using the structural information read in step S3 and the conversion destination write destination information read in step S4 (see Fig. 4 (a)). ), If the conversion destination is DB, the directory conversion engine 14 uses LDAP to access the information in the directory (attribute directory 3), and if the conversion destination is DB, the DB master conversion engine 15 uses SQL. Use to access the relevant information in the relevant DB (attribute DB1) and change the relevant information to the specified modified information (step S7). In step S7, both the directory conversion engine 14 and the DB master conversion engine 15 are executed as necessary.
【0037】
Finally, in "Execute conversion engine ID read special process", if there is a special process specified in conversion ID 70a (see Fig. 4 (a)) read in step S2, the special process is executed ( Step S8). As described above, special processing is performed when 1-to-N conversion is required, such as when the structure of the conversion destination DB is not normalized. Therefore, if the conversion source and conversion destination are one-to-one, no special processing is required.
【0038】
As described above, by the processing of steps S7 and S8, the attribute information of the directory and the DB (attribute information common to both) is collectively converted. A specific example of this batch conversion process will be described by taking up the case of batch conversion from master A in FIG. 4B to directories A and B.
【0039】
When attribute A is the position, it is assumed that attribute A of master A is "section chief" and attribute A of directory A and master B is "assistant section chief". In this case, since the attribute A of the master A before the change is "assistant section chief", the information "0011 Taro Yamada, assistant section chief before change, assistant section chief after change" is automatically created, and the directory is stored in the directory conversion engine 14. Rewrite the attribute A of A to "section chief" and the attribute A of master B to "section chief" in the DB system master conversion engine 15.
【0040】
If you want to refer to the generation information managed in the attribute master DB (see Fig. 2) of attribute DB1 on the server that refers to the directory (attribute directory 3), write area for the old generation (see Fig. 2) in advance. (Conversion destination write destination) is prepared, and the change source change information 71 read in step S1 is input as the input source, and the conversion destination write destination read in step S4 is set as the output destination. Generation information is stored.
【0041】
The present invention can be applied to the following attribute management and the like. 1) Attribute management by employee certification in government offices 2) Attribute management of employees by employee certification in private companies 3) Attribute management of PKI electronic signature authentication target persons in electronic applications 4) PKI electronic signature authentication target persons in electronic bidding Attribute management 5) Attribute management of PKI electronic signature authentication target person and accessor in electronic chart 6) Attribute management of participating companies or individuals in electronic commerce In addition, the conversion program 20 and the extended metadirectory 7 of this embodiment are various. It can also be distributed using portable recording media such as standard CDs, various standard DVDs, flexible discs, optical disks, optomagnetic discs, memory cards, and ROM cards. It can also be distributed via wired or wireless communication. Further, the conversion program 20 and the extended metadirectory 7 may be distributed by separate portable recording media. Then, the conversion program 20 and the extended metadirectory 7 distributed in this way are executed by the computer to cause the computer to execute each function of the present embodiment described above.
【0042】
The database to which the present invention is applied is not limited to a relational database, and the present invention can also be applied to the management of attribute information managed by another form of database such as an object-oriented database.
【0043】
[Effect of the invention]
As described above, according to the present invention, a conversion rule for integrated conversion of the information of the directory and the information of the database is stored in the extended metadirectory that integrates and manages the directory and the database, and the directory access. By writing the change information to the directory and the database in a batch by the conversion engine for and the conversion engine for database access, the attribute information managed by the directory and the attribute information managed by the database are equivalent. Attribute information common to the database can be changed easily, quickly, and reliably. In addition, the attribute information of the directory and the attribute information of the database can be integratedly managed without changing the existing system, and the modification cost can be reduced.
[Simple explanation of drawings]
FIG. 1 is a diagram showing a configuration of an electronic signature system to which an embodiment of the present invention is applied.
FIG. 2 is a diagram showing a software configuration according to the embodiment of FIG.
FIG. 3 is a diagram showing a data structure of change source change information.
FIG. 4 is a diagram illustrating a configuration of a conversion table.
FIG. 5 is a diagram illustrating a processing flow of a conversion program.
FIG. 6 is a diagram showing a configuration of a conventional electronic signature system.
[Explanation of symbols]
3 Attribute directory 6 Existing master 7 Extended metadirectory 14 Directory conversion engine 15 DB master conversion engine 20 Conversion program 70 Conversion table 70a Conversion ID 70b Conversion destination type 70c Conversion destination name 70d DB and directory structure information 70e Conversion engine ID 71 Change source Change information 72 DB and directory structure information 72a Master A structure 72b Directory A structure 72c Master B structure
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2006073003A | Cited by | Japan | Examiner |
| US9846847B2 | Cited by | United States of America | Applicant |
1 member in 1 office
Members1
| Document | Office | Kind | |
|---|---|---|---|
| JP2004046733AThis record | Japan | A |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written withdrawal of applicationJAPANESE INTERMEDIATE CODE: A761A761 | A761 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: A7422RD02 | RD02 |
Numbers
- Publication
- 2004046733
- Application
- 206043
Titles2
- Japanese
- 属性情報統合管理装置
- English
- Attribute information integrated management device
Classification
- IPC, 4
- G06F12 00
- G06F15 00
- G06F21 31
- G06F21 33