Maintenance interface user identifying method and device in client/server type distributed system
Abstract
Problem to be solved.To open and close a maintenance interface of a client device remotely from a server device in a client-server distributed system.
Solution.A request receiving unit 11 of a server device 1 receives an information setting request including user authentication information and a designation of a client device 3 and a setting invalidation request including a designation of a client device 3 from a server side console 2. , The request transfer unit 12 transfers to the designated client device 3 through LAN6. The remote request processing unit 33 of the client device 3 sets the received user authentication information in the setting request to the user authentication unit 32 that authenticates the user who uses the maintenance interface 30, and opens the maintenance interface 30. .. When a setting invalidation request is received, the user authentication information set in the user authentication unit 32 is invalidated and the maintenance interface 30 is blocked. [Selection diagram] Fig. 1
Term
Term ended
Projected expiry passed 9 December 2022, 3.8 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
56 claims: 6 independent, 50 dependent
- 1複数のクライアント装置とサーバ装置とがネットワークを通じて接続されたクライアント・サーバ型分散システムにおいて、前記サーバ装置は、サーバ側コンソールから、利用者認証情報と前記クライアント装置の指定とを含む利用者認証情報設定要求、および前記クライアント装置の指定を含む利用者認証情報設定無効要求を受け付ける要求受付手段と、前記要求受付手段で受け付けられた前記利用者認証情報設定要求および前記利用者認証情報設定無効要求を指定された前記クライアント装置に前記ネットワークを通じて転送する要求転送手段とを備え、前記それぞれのクライアント装置は、保守インタフェースの利用に際して利用者の認証を行う利用者認証手段と、前記サーバ装置から前記ネットワークを通じて前記利用者認証情報設定要求を受信したときに前記利用者認証情報設定要求に含まれる利用者認証情報を前記利用者認証手段に設定し、前記サーバ装置から前記ネットワークを通じて前記利用者認証情報設定無効要求を受信したときに前記利用者認証手段に設定されている利用者認証情報を無効にするリモート要求処理手段とを備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 2請求項1記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記それぞれのクライアント装置における前記利用者認証手段への利用者認証情報の設定は、前記サーバ側コンソールからのみ設定可能としたことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 3請求項1または2記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記サーバ装置は、前記要求転送手段が転送する利用者認証情報設定要求中の利用者認証情報を暗号化する暗号化手段を備え、前記それぞれのクライアント装置に、前記リモート要求処理手段が受信した利用者認証情報設定要求中の暗号化された利用者認証情報を復号化する復号化手段を備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 4請求項1または2記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記それぞれのクライアント装置は、前記利用者認証手段に既に設定されている利用者認証情報が前記ネットワークを通じて受信した新たな利用者認証情報設定要求によって再設定された場合に、前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする強制切断手段を備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 5請求項1または2記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、それぞれの前記クライアント装置は、前記利用者認証手段に利用者認証情報が設定されてから利用可能時間が経過したときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする利用時間管理手段を備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 6請求項5記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、それぞれの前記クライアント装置は、前記保守インタフェースを開放してからの初回のログインに限り、予め定められた延長時間だけ前記利用時間管理手段の残り利用時間を延長する利用時間延長手段を備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 7請求項6記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記利用時間延長手段は、前記保守インタフェースを開放してから初回のログイン要求があった際に、前記利用時間管理手段で管理されている残り利用時間が予め定められた一定時間以内かどうかを判定し、一定時間以内であれば予め定められた延長時間だけ前記利用時間管理手段の残り利用時間を延長するものであることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 8請求項6記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記利用時間延長手段は、前記保守インタフェースを開放してからの初回のログイン中、前記利用時間管理手段で管理されている残り利用時間が予め定められた一定時間以内となったかどうかを判定し、一定時間以内になった場合に予め定められた延長時間だけ前記利用時間管理手段の残り利用時間を延長するものであることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 9請求項5または6記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記利用時間管理手段は、前記利用可能時間として前記サーバ装置から送信された前記利用者認証情報設定要求で指定された利用可能時間を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 10請求項5または6記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記利用時間管理手段は、前記利用可能時間として前記クライアント装置に予め記憶されている利用可能時間基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 11請求項5または6記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記利用時間管理手段は、前記利用可能時間として、前記サーバ装置から送信された前記利用者認証情報設定要求で利用可能時間が指定されているときは該指定された利用可能時間を使用し、指定されていないときは前記クライアント装置に予め記憶されている利用可能時間基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 12請求項1または2記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、それぞれの前記クライアント装置は、前記利用者認証手段に利用者認証情報が設定されてからログイン可能回数のログインが行われたときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするログイン回数管理手段を備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 13請求項12記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記ログイン回数管理手段は、前記ログイン可能回数として前記サーバ装置から送信された前記利用者認証情報設定要求で指定されたログイン可能回数を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 14請求項13記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記ログイン回数管理手段は、前記ログイン可能回数として前記クライアント装置に予め記憶されているログイン可能回数基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 15請求項13記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、前記ログイン回数管理手段は、前記ログイン可能回数として、前記サーバ装置から送信された前記利用者認証情報設定要求でログイン可能回数が指定されているときは該指定されたログイン可能回数を使用し、指定されていないときは前記クライアント装置に予め記憶されているログイン可能回数基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 16請求項1または2記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置において、それぞれの前記クライアント装置は、前記保守インタフェースの利用者が前記保守インタフェースの利用を終了する際に前記利用者認証手段に設定されている利用者認証情報を無効にする認証無効化手段を備えることを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証装置。
- 17a)サーバ装置が、サーバ側コンソールから、利用者認証情報とクライアント装置の指定とを含む利用者認証情報設定要求を受け付け、指定された前記クライアント装置にネットワークを通じて転送するステップと、b)前記クライアント装置が、前記ネットワークを通じて前記利用者認証情報設定要求を受信し、保守インタフェースの利用に際して利用者の認証を行う利用者認証手段に設定するステップと、c)前記サーバ装置が、前記サーバ側コンソールから、前記クライアント装置の指定を含む利用者認証情報設定無効要求を受け付け、指定された前記クライアント装置に前記ネットワークを通じて転送するステップと、d)前記クライアント装置が、前記ネットワークを通じて前記利用者認証情報設定無効要求を受信し、前記利用者認証手段に設定されている利用者認証情報を無効にするステップと、を含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 18請求項17記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記それぞれのクライアント装置における前記利用者認証手段への利用者認証情報の設定は、前記サーバ側コンソールからのみ設定可能としたことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 19請求項17または18記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップaは、前記サーバ装置が前記転送する利用者認証情報を暗号化する処理を含み、前記ステップbは、前記クライアント装置が前記受信した利用者認証情報を復号化する処理を含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 20請求項17または18記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップbは、前記利用者認証手段に既に設定されている利用者認証情報が前記受信した新たな利用者認証情報に再設定された場合に、前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする処理を含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 21請求項17または18記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、e)それぞれの前記クライアント装置が、前記利用者認証手段に利用者認証情報が設定されてから利用可能時間が経過したときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするステップを含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 22請求項21記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、f)それぞれの前記クライアント装置が、前記保守インタフェースを開放してからの初回のログインに限り、予め定められた延長時間だけ前記利用可能時間を延長するステップを含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 23請求項22記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記スナップfは、前記保守インタフェースを開放してから初回のログイン要求があった際に、前記ステップeで管理されている残り利用時間が予め定められた一定時間以内かどうかを判定し、一定時間以内であれば予め定められた延長時間だけ前記残り利用時間を延長することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 24請求項22記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップfは、前記保守インタフェースを開放してからの初回のログイン中、前記ステップeで管理されている残り利用時間が予め定められた一定時間以内となったかどうかを判定し、一定時間以内になった場合に予め定められた延長時間だけ前記残り利用時間を延長することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 25請求項21または22記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップeにおける前記利用可能時間として前記サーバ装置から送信された前記利用者認証情報設定要求で指定された利用可能時間を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 26請求項21または22記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップeにおける前記利用可能時間として前記クライアント装置に予め記憶されている利用可能時間基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 27請求項21または22記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップeにおける前記利用可能時間として、前記サーバ装置から送信された前記利用者認証情報設定要求で利用可能時間が指定されているときは該指定された利用可能時間を使用し、指定されていないときは前記クライアント装置に予め記憶されている利用可能時間基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 28請求項17または18記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、e)それぞれの前記クライアント装置が、前記利用者認証手段に利用者認証情報が設定されてからログイン可能回数のログインが行われたときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするステップを含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 29請求項28記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップeにおける前記ログイン可能回数として前記サーバ装置から送信された前記利用者認証情報設定要求で指定されたログイン可能回数を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 30請求項29記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップeにおける前記ログイン可能回数として前記クライアント装置に予め記憶されているログイン可能回数基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 31請求項29記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、前記ステップeにおける前記ログイン可能回数として、前記サーバ装置から送信された前記利用者認証情報設定要求でログイン可能回数が指定されているときは該指定されたログイン可能回数を使用し、指定されていないときは前記クライアント装置に予め記憶されているログイン可能回数基準値を使用することを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 32請求項17または18記載のクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法において、e)それぞれの前記クライアント装置が、前記保守インタフェースの利用者が前記保守インタフェースの利用を終了する際に前記利用者認証手段に設定されている利用者認証情報を無効にするステップを含むことを特徴とするクライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法。
- 33複数のクライアント装置とネットワークを通じて接続されるサーバ装置において、サーバ側コンソールから、前記クライアント装置が保守インタフェースの利用に際して利用者の認証を行う利用者認証手段に設定する利用者認証情報と前記クライアント装置の指定とを含む利用者認証情報設定要求、および前記クライアント装置の指定を含む利用者認証情報設定無効要求を受け付ける要求受付手段と、前記要求受付手段で受け付けられた前記利用者認証情報設定要求および前記利用者認証情報設定無効要求を指定された前記クライアント装置に前記ネットワークを通じて転送する要求転送手段とを備えることを特徴とするサーバ装置。
- 34請求項33記載のサーバ装置において、前記要求転送部が転送する利用者認証情報設定要求中の利用者認証情報を暗号化する暗号化手段を備えることを特徴とするサーバ装置。
- 35請求項33記載のサーバ装置において、それぞれの前記クライアント装置が前記利用者認証手段に利用者認証情報が設定されてから利用可能時間が経過したときに前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする利用時間管理手段に設定する前記利用可能時間を、前記利用者認証情報設定要求に含めて送信する構成を備えることを特徴とするサーバ装置。
- 36請求項33記載のサーバ装置において、それぞれの前記クライアント装置が前記利用者認証手段に利用者認証情報が設定されてからログイン可能回数のログインが行われたときに前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするログイン回数管理手段に設定する前記ログイン可能回数を、前記利用者認証情報設定要求に含めて送信する構成を備えることを特徴とするサーバ装置。
- 37サーバ装置にネットワークを通じて接続されるクライアント装置において、保守インタフェースの利用に際して利用者の認証を行う利用者認証手段と、利用者認証情報を含む利用者認証情報設定要求を前記ネットワークを通じて前記サーバ装置から受信したときに前記利用者認証情報設定要求に含まれる利用者認証情報を前記利用者認証手段に設定し、利用者認証情報設定無効要求を前記ネットワークを通じて前記サーバ装置から受信したときに前記利用者認証手段に設定されている利用者認証情報を無効にするリモート要求処理手段を備えることを特徴とするクライアント装置。
- 38請求項37記載のクライアント装置において、前記利用者認証手段への利用者認証情報の設定は、前記サーバ装置から受信した利用者認証情報設定要求のみにより可能としたことを特徴とするクライアント装置。
- 39請求項37または38記載のクライアント装置において、前記サーバ装置から前記ネットワークを通じて受信した前記利用者認証情報設定要求中の暗号化された利用者認証情報を復号化する復号化手段を備えることを特徴とするクライアント装置。
- 40請求項37または38記載のクライアント装置において、前記利用者認証手段に既に設定されている利用者認証情報が前記ネットワークを通じて受信した新たな利用者認証情報設定要求によって再設定された場合に、前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする強制切断手段を備えることを特徴とするクライアント装置。
- 41請求項37または38記載のクライアント装置において、前記利用者認証手段に利用者認証情報が設定されてから利用可能時間が経過したときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする利用時間管理手段を備えることを特徴とするクライアント装置。
- 42請求項41記載のクライアント装置において、前記保守インタフェースを開放してからの初回のログインに限り、予め定められた延長時間だけ前記利用時間管理手段の残り利用時間を延長する利用時間延長手段を備えることを特徴とするクライアント装置。
- 43請求項37または38記載のクライアント装置において、前記利用者認証手段に利用者認証情報が設定されてからログイン可能回数のログインが行われたときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするログイン回数管理手段を備えることを特徴とするクライアント装置。
- 44請求項37または38記載のクライアント装置において、前記保守インタフェースの利用者が前記保守インタフェースの利用を終了する際に前記利用者認証手段に設定されている利用者認証情報を無効にする認証無効化手段を備えることを特徴とするクライアント装置。
- 45複数のクライアント装置とネットワークを通じて接続されるサーバ装置を構成するコンピュータを、サーバ側コンソールから、前記クライアント装置が保守インタフェースの利用に際して利用者の認証を行う利用者認証手段に設定する利用者認証情報と前記クライアント装置の指定とを含む利用者認証情報設定要求、および前記クライアント装置の指定を含む利用者認証情報設定無効要求を受け付ける要求受付手段、前記要求受付手段で受け付けられた前記利用者認証情報設定要求および前記利用者認証情報設定無効要求を指定された前記クライアント装置に前記ネットワークを通じて転送する要求転送手段、として機能させることを特徴とするサーバプログラム。
- 46請求項45記載のサーバプログラムにおいて、前記コンピュータを、更に、前記要求転送手段が転送する利用者認証情報設定要求中の利用者認証情報を暗号化する暗号化手段として機能させるサーバプログラム。
- 47請求項45記載のサーバプログラムにおいて、前記要求受付手段および前記要求転送手段は、それぞれの前記クライアント装置が前記利用者認証手段に利用者認証情報が設定されてから利用可能時間が経過したときに前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする利用時間管理手段に設定する前記利用可能時間を、前記サーバ側コンソールから受け付けて前記利用者認証情報設定要求に含めて転送することを特徴とするサーバプログラム。
- 48請求項45記載のサーバプログラムにおいて、前記要求受付手段および前記要求転送手段は、それぞれの前記クライアント装置が前記利用者認証手段に利用者認証情報が設定されてからログイン可能回数のログインが行われたときに前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするログイン回数管理手段に設定する前記ログイン可能回数を、前記サーバ側コンソールから受け付けて前記利用者認証情報設定要求に含めて転送することを特徴とするサーバプログラム。
- 49サーバ装置にネットワークを通じて接続されるクライアント装置を構成するコンピュータを、保守インタフェースの利用に際して利用者の認証を行う利用者認証手段、利用者認証情報を含む利用者認証情報設定要求を前記ネットワークを通じて前記サーバ装置から受信したときに前記利用者認証情報設定要求に含まれる利用者認証情報を前記利用者認証手段に設定し、利用者認証情報設定無効要求を前記ネットワークを通じて前記サーバ装置から受信したときに前記利用者認証手段に設定されている利用者認証情報を無効にするリモート要求処理手段、として機能させることを特徴とするクライアントプログラム。
- 50請求項49記載のクライアントプログラムにおいて、前記利用者認証手段への利用者認証情報の設定は、前記サーバ装置から受信した利用者認証情報設定要求のみにより可能としたことを特徴とするクライアントプログラム。
- 51請求項49または50記載のクライアントプログラムにおいて、前記コンピュータを、更に、前記サーバ装置から前記ネットワークを通じて受信した前記利用者認証情報設定要求中の暗号化された利用者認証情報を復号化する復号化手段として機能させることを特徴とするクライアントプログラム。
- 52請求項49または50記載のクライアントプログラムにおいて、前記コンピュータを更に、前記利用者認証手段に既に設定されている利用者認証情報が前記ネットワークを通じて受信した新たな利用者認証情報設定要求によって再設定された場合に、前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする強制切断手段として機能させることを特徴とするクライアントプログラム。
- 53請求項49または50記載のクライアントプログラムにおいて、前記コンピュータを更に、前記利用者認証手段に利用者認証情報が設定されてから利用可能時間が経過したときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にする利用時間管理手段として機能させることを特徴とするクライアントプログラム。
- 54請求項53記載のクライアントプログラムにおいて、前記コンピュータを更に、前記保守インタフェースを開放してからの初回のログインに限り、予め定められた延長時間だけ前記利用時間管理手段の残り利用時間を延長する利用時間延長手段として機能させることを特徴とするクライアントプログラム。
- 55請求項49または50記載のクライアントプログラムにおいて、前記コンピュータを更に、前記利用者認証手段に利用者認証情報が設定されてからログイン可能回数のログインが行われたときに、前記利用者認証手段に設定されている利用者認証情報を無効にすると共に前記保守インタフェースを現に利用している利用者の利用を強制的に不可能にするログイン回数管理手段として機能させることを特徴とするクライアントプログラム。
- 56請求項49または50記載のクライアントプログラムにおいて、前記コンピュータを更に、前記保守インタフェースの利用者が前記保守インタフェースの利用を終了する際に前記利用者認証手段に設定されている利用者認証情報を無効にする認証無効化手段として機能させることを特徴とするクライアントプログラム。
Independent claims56
385 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates to a maintenance interface user authentication method and device of a client device in a client-server distributed system, and particularly provides user authentication information for authenticating a user when using the maintenance interface provided in the client device in a network. The maintenance interface user authentication method and device that can be set and disabled from the server device through.
【0002】
[Conventional technology]
In a client-server distributed system, since each client device is geographically distributed and installed, remote maintenance of each client device may be performed from a remote maintenance console on the LAN via LAN during operation. However, since it is a remote maintenance from the LAN, it is necessary to ensure security, and as a countermeasure, the maintenance interface of the client device is made available only to those who know the preset user authentication information. Specifically, using the local maintenance console connected to the client device, user authentication information consisting of a user name and password is set in advance in the client device, and login and logout are called from the remote maintenance console. Maintenance work from the remote maintenance console only when the user name and password for authentication are entered when general operations are performed and the user name and password registered on the client device side match. Is possible.
【0003】
In this way, a technique for performing user authentication using a user name and password when performing maintenance of a certain device from a remote maintenance console via a network is described in Patent Document 1 described later. .. However, Patent Document 1 does not disclose a specific method for registering a user name and password in advance. Further, in Patent Document 2 described later, an IPsec authentication key for realizing a VPN session at the network layer of the OSI reference model is shared between a plurality of terminals connected to the Internet by a terminal type dial-up and a single maintenance server. The method of sharing the authentication key between the terminal and the maintenance server is described, but the point that the set authentication key is invalidated and the maintenance interface is blocked is not described.
【0004】
[Patent Document 1]
Patent No. 3214423 [Patent Document 2]
Japanese Unexamined Patent Publication No. 2001-197058 [0005]
[Problems to be Solved by the Invention]
In order to ensure the security of remote maintenance from the network, user authentication is performed using authentication information when using the maintenance interface of the client device as described above, but the user name and password set in advance are used. If the leak occurs, the client device can be accessed if the user name and password are entered in the same procedure from another terminal connected to the network, and there is a possibility of damage such as hacking via the maintenance interface. If there is a risk of being damaged by such hacking during system operation, it is necessary to protect it by deleting the user name / password registered in the client device or rewriting it with another user name / password. However, it takes time and effort to go to the location of each geographically dispersed client device and delete or change the authentication information from the local maintenance console, and the local maintenance console on the client side has already removed it. There is a problem that it takes time and effort to reconnect if it has been disconnected. In addition, once the authentication information is deleted, maintenance cannot be performed from the remote maintenance console during operation, so when performing maintenance, it is troublesome to go to the installation location of the client device again and set the authentication information. is there. In other words, it has been difficult to ensure both security and ease of maintenance with the conventional client-server system maintenance interface user authentication method.
【0006】
Therefore, an object of the present invention is a method for authenticating a maintenance interface user of a client-server system in which the security of the maintenance interface in the client device can be ensured and the permission / prohibition of the maintenance interface use of a plurality of client devices can be managed from the server device side. And to provide equipment.
【0007】
Another object of the present invention is to manage the available time of the maintenance interface of the client device, thereby minimizing the chance of hacking due to the maintenance interface of the client device being kept open for a long time. The purpose is to provide a maintenance interface user authentication method and device for a client-server system.
【0008】
Further, another object of the present invention is a client-server system in which the convenience of the maintenance interface is enhanced by extending the available time of the maintenance interface of the client device and blocking the maintenance interface from the maintenance person. Maintenance interface is to provide a user authentication method and a device.
【0009】
[Means for solving problems]
The maintenance interface user authentication device in the first client-server type distributed system of the present invention is a client-server type distributed system in which a plurality of client devices and server devices are connected via a network, and the server device is on the server side. A request receiving means for receiving a user authentication information setting request including the user authentication information and the designation of the client device, and a request for invalidating the user authentication information setting including the designation of the client device from the console, and the request receiving means. Each of the client devices includes a request transfer means for transferring the received user authentication information setting request and the user authentication information setting invalidation request to the designated client device through the network, and each of the client devices uses a maintenance interface. At the time, the user authentication means for authenticating the user and the user authentication information included in the user authentication information setting request when the user authentication information setting request is received from the server device through the network are used as the user. A remote request processing means that is set as an authentication means and invalidates the user authentication information set in the user authentication means when the user authentication information setting invalidation request is received from the server device through the network. Be prepared.
【0010】
In the maintenance interface user authentication device in this first client-server distributed system, user authentication information for ensuring security for the maintenance interfaces of multiple client devices is set remotely from the server-side console via the network. It is also possible to remotely invalidate the already set user authentication information from the server side console via the network, and it is possible to collectively manage the security management for the maintenance interface of each client device on the server side.
【0011】
The maintenance interface user authentication device in the second client-server distributed system of the present invention is the maintenance interface user authentication device in the first client-server distributed system, and the user authentication means in each of the client devices. The user authentication information can be set only from the server-side console. As a result, the maintenance interface of each client device can be opened only from the server-side console, and security can be further ensured.
【0012】
The maintenance interface user authentication device in the third client-server type distributed system of the present invention is the maintenance interface user authentication device in the first or second client-server type distributed system, and the server device is the request transfer. An encryption means for encrypting the user authentication information during the user authentication information setting request transferred by the means is provided, and the encryption during the user authentication information setting request received by the remote request processing means is provided to each of the client devices. It is provided with a decryption means for decrypting the converted user authentication information. As a result, the leakage of the user authentication information for opening the maintenance interface of the client device from the network can be prevented, and security can be ensured.
【0013】
The maintenance interface user authentication device in the fourth client-server distributed system of the present invention is the maintenance interface user authentication device in the first or second client-server distributed system. When the user authentication information already set in the user authentication means is reset by a new user authentication information setting request received through the network, the use of the user who is actually using the maintenance interface is used. Provided is a forced disconnection means for forcibly making it impossible. As a result, when malicious access is performed through the maintenance interface of the client device, the access can be stopped immediately by remote control from the server side console, and at the same time, the user recognition information used for intrusion is invalidated. And new user authentication information can be reset for regular maintenance.
【0014】
The maintenance interface user authentication device in the fifth client-server distributed system of the present invention is the maintenance interface user authentication device in the first or second client-server distributed system. When the available time elapses after the user authentication information is set in the user authentication means, the user authentication information set in the user authentication means is invalidated and the maintenance interface is actually used. Provide a usage time management means that forcibly disables the use of existing users. As a result, it is possible to prevent the maintenance interface of each client device from being continuously opened for a long period of time and increasing the risk of malicious access.
【0015】
The maintenance interface user authentication device in the sixth client-server distributed system of the present invention is the maintenance interface user authentication device in the fifth client-server distributed system, and each of the client devices has the maintenance interface. Only for the first login after opening, a usage time extension means for extending the remaining usage time of the usage time management means by a predetermined extension time is provided. Specifically, the usage time extension means has a predetermined fixed time remaining usage time managed by the usage time management means when the first login request is made after opening the maintenance interface. It is determined whether or not it is within a certain period of time, and if it is within a certain period of time, the remaining usage time of the usage time management means is extended by a predetermined extension time. Further, the usage time extension means determines whether or not the remaining usage time managed by the usage time management means is within a predetermined fixed time during the first login after opening the maintenance interface. However, when it is within a certain period of time, the remaining usage time of the usage time management means may be extended by a predetermined extension time. As a result, it takes a while for the maintenance person to actually use the maintenance interface of the client device after opening the maintenance interface of the client device, and sufficient maintenance work is performed even if the user logs in when the remaining usage time is short. Moreover, security can be ensured because the extension is allowed only for the first login.
【0016】
Here, in the maintenance interface user authentication device in the fifth or sixth client-server distributed system, the usage time management means sets the user authentication information transmitted from the server device as the usable time. The available time specified in the request may be used, or the available time reference value stored in advance in the client device may be used. Further, when the available time is specified in the user authentication information setting request transmitted from the server device, the specified available time is used, and when it is not specified, it is stored in the client device in advance. The available time reference value that has been set may be used.
【0017】
The maintenance interface user authentication device in the seventh client-server distributed system of the present invention is the maintenance interface user authentication device in the first or second client-server distributed system. When the user authentication means is set and the login is performed as many times as possible after the user authentication information is set, the user authentication information set in the user authentication means is invalidated and the maintenance interface is actually displayed. It is equipped with a login count management means that forcibly disables the use of the user who is using it. This makes it possible to ensure security against malicious users who repeatedly log in and out.
【0018】
Here, in the maintenance interface user authentication device in the seventh client-server distributed system, the login count management means is designated as the login possible number in the user authentication information setting request transmitted from the server device. The login possible number of times may be used, or the login possible number of times reference value stored in advance in the client device may be used. Further, when the number of times of login is specified in the user authentication information setting request transmitted from the server device, the specified number of times of login is used, and when it is not specified, the number of times of login is stored in the client device in advance. You may use the standard value of the number of times you can log in.
【0019】
The maintenance interface user authentication device in the eighth client-server distributed system of the present invention is the maintenance interface user authentication device in the first or second client-server distributed system. An authentication invalidation means for invalidating the user authentication information set in the user authentication means when the user of the maintenance interface ends the use of the maintenance interface is provided. As a result, the maintenance interface can be closed at the same time as the maintenance work is completed, and the security of the maintenance interface of the client device can be ensured.
【0020】
The maintenance interface user authentication method in the first client-server type distributed system of the present invention is as follows: a) The server device requests the user authentication information setting including the user authentication information and the designation of the client device from the server side console. And b) the client device receives the user authentication information setting request through the network and authenticates the user when using the maintenance interface. The step of setting to the person authentication means, and c) the server device receives a user authentication information setting invalidation request including the designation of the client device from the server side console, and transfers the user authentication information setting invalidation request to the designated client device through the network. And d) the client device receives the user authentication information setting invalidation request through the network and invalidates the user authentication information set in the user authentication means. Will be done.
【0021】
In the maintenance interface user authentication method in this first client-server distributed system, user authentication information for ensuring security for the maintenance interfaces of multiple client devices is set remotely from the server-side console via the network. It is also possible to remotely invalidate the already set user authentication information from the server side console via the network, and it is possible to collectively manage the security management for the maintenance interface of each client device on the server side.
【0022】
The maintenance interface user authentication method in the second client-server distributed system of the present invention is the user authentication means in each of the client devices in the maintenance interface user authentication method in the first client-server distributed system. The user authentication information can be set only from the server-side console. As a result, the maintenance interface of each client device can be opened only from the server-side console, and security can be further ensured.
【0023】
The maintenance interface user authentication method in the third client-server distributed system of the present invention is the maintenance interface user authentication method in the first or second client-server distributed system, in which step a is the server device. Includes a process of encrypting the transferred user authentication information, and the step b includes a process of decrypting the received user authentication information by the client device. As a result, the leakage of the user authentication information for opening the maintenance interface of the client device from the network can be prevented, and security can be ensured.
【0024】
The maintenance interface user authentication method in the fourth client-server distributed system of the present invention is the maintenance interface user authentication method in the first or second client-server distributed system, in which step b is the user. When the user authentication information already set in the authentication means is reset to the new received user authentication information, the user who is actually using the maintenance interface cannot be used forcibly. It is configured to include the processing to be performed. As a result, when malicious access is performed through the maintenance interface of the client device, the access can be stopped immediately by remote control from the server side console, and at the same time, the user recognition information used for intrusion is invalidated. And new user authentication information can be reset for regular maintenance.
【0025】
The maintenance interface user authentication method in the fifth client-server distributed system of the present invention is the maintenance interface user authentication method in the first or second client-server distributed system, in which e) each of the client devices is used. When the available time elapses after the user authentication information is set in the user authentication means, the user authentication information set in the user authentication means is invalidated and the maintenance interface is actually used. It consists of a step that forcibly disables the use of the user. As a result, it is possible to prevent the maintenance interface of each client device from being continuously opened for a long period of time and increasing the risk of malicious access.
【0026】
The maintenance interface user authentication method in the sixth client-server distributed system of the present invention is the maintenance interface user authentication method in the fifth client-server distributed system. Only the first login after opening the interface is configured to include a step of extending the available time by a predetermined extension time. Specifically, when the first login request is made after opening the maintenance interface, it is determined whether or not the remaining usage time managed in step e is within a predetermined fixed time, and the fixed time is determined. If it is within the range, the remaining usage time is extended by a predetermined extension time. In addition, during the first login after opening the maintenance interface, it is determined whether or not the remaining usage time managed in step e is within a predetermined fixed time, and if it is within a fixed time. The remaining usage time may be extended by a predetermined extension time. As a result, it takes a while for the maintenance person to actually use the maintenance interface of the client device after opening the maintenance interface of the client device, and sufficient maintenance work is performed even if the user logs in when the remaining usage time is short. Moreover, security can be ensured because the extension is allowed only for the first login.
【0027】
Here, in the maintenance interface user authentication method in the fifth and sixth client-server distributed systems, the available time in step e is specified in the user authentication information setting request transmitted from the server device. The available available time may be used, or the available time reference value stored in advance in the client device may be used. Further, when the available time is specified in the user authentication information setting request transmitted from the server device, the specified available time is used, and when it is not specified, it is stored in the client device in advance. The available time reference value that has been set may be used.
【0028】
The maintenance interface user authentication method in the seventh client-server distributed system of the present invention is the maintenance interface user authentication method in the first or second client-server distributed system, in which e) each of the client devices is used. When the user authentication information is set in the user authentication means and the user is logged in as many times as possible, the user authentication information set in the user authentication means is invalidated and the maintenance interface is used. It is configured to include a step that forcibly disables the use of the user who is actually using. This makes it possible to ensure security against malicious users who repeatedly log in and out.
【0029】
Here, in the maintenance interface user authentication method in the seventh client-server distributed system, the login specified in the user authentication information setting request transmitted from the server device is used as the number of logins that can be performed in step e. The possible number of times may be used, or the login possible number of times reference value stored in advance in the client device may be used. Further, when the number of times of login is specified in the user authentication information setting request transmitted from the server device, the specified number of times of login is used, and when it is not specified, the number of times of login is stored in the client device in advance. You may use the standard value of the number of times you can log in.
【0030】
The maintenance interface user authentication method in the eighth client-server distributed system of the present invention is the maintenance interface user authentication method in the first or second client-server distributed system, in which e) each of the client devices is used. It is configured to include a step of invalidating the user authentication information set in the user authentication means when the user of the maintenance interface ends the use of the maintenance interface. As a result, the maintenance interface can be closed at the same time as the maintenance work is completed, and the security of the maintenance interface of the client device can be ensured.
【0031】
The first server device of the present invention is set as a user authentication means for authenticating a user when the client device uses a maintenance interface from a server-side console in a server device connected to a plurality of client devices via a network. A request receiving means for receiving a user authentication information setting request including the user authentication information and the designation of the client device, and a request for invalidating the user authentication information setting including the designation of the client device, and the request receiving means. It also includes a request transfer means for transferring the user authentication information setting request and the user authentication information setting invalidation request to the designated client device through the network.
【0032】
In this first server device, user authentication information for ensuring security for the maintenance interfaces of multiple client devices can be set remotely from the server-side console via the network, and user authentication that has already been set can be set. Information can be invalidated remotely from the server-side console via the network, and security management for the maintenance interface of each client device can be centrally managed on the server side.
【0033】
The second server device of the present invention includes an encryption means for encrypting the user authentication information in the user authentication information setting request transferred by the request transfer unit in the first server device. As a result, the leakage of the user authentication information for opening the maintenance interface of the client device from the network can be prevented, and security can be ensured.
【0034】
The third server device of the present invention is the user authentication when the available time elapses after the user authentication information is set in the user authentication means for each of the client devices in the first server device. The available time set in the usage time management means that invalidates the user authentication information set in the means and forcibly disables the use of the user who is actually using the maintenance interface is set as described above. It has a configuration to be included in the user authentication information setting request and transmitted. As a result, the available time used to prevent the maintenance interface of each client device from being open for a long time and increasing the risk of malicious access is set for each client device remotely from the server device. can do.
【0035】
The fourth server device of the present invention is the first server device, when each of the client devices logs in as many times as possible after the user authentication information is set in the user authentication means. The number of logins set in the management means that invalidates the user authentication information set in the user authentication means and forcibly disables the use of the user who is currently using the maintenance interface. Is included in the user authentication information setting request and transmitted. As a result, the number of times that a malicious user who repeatedly logs in and out can be logged in to ensure security against a malicious user can be set remotely from the server device.
【0036】
The first client device of the present invention is a user authentication means for authenticating a user when using a maintenance interface in a client device connected to a server device via a network, and user authentication information setting including user authentication information. When the request is received from the server device through the network, the user authentication information included in the user authentication information setting request is set in the user authentication means, and the user authentication information setting invalidation request is sent to the server through the network. A remote request processing means for invalidating the user authentication information set in the user authentication means when received from the device is provided.
【0037】
In this first client device, user authentication information for ensuring security for the maintenance interface can be set remotely from the server device via the network, and the already set user authentication information can be set to the server via the network. It can be disabled remotely from the device, and security management for the maintenance interface of the client device can be managed on the server side.
【0038】
The second client device of the present invention has a configuration in which the user authentication information can be set in the user authentication means only by the user authentication information setting request received from the server device in the first client device. Has. As a result, the maintenance interface of the client device can be opened only from the server device, and security can be further ensured.
【0039】
The third client device of the present invention decrypts the encrypted user authentication information in the user authentication information setting request received from the server device through the network in the first or second client device. A decryption means is provided. As a result, the leakage of the user authentication information for opening the maintenance interface of the client device from the network can be prevented, and security can be ensured.
【0040】
In the fourth client device of the present invention, in the first or second client device, the user authentication information already set in the user authentication means is received by the new user authentication information setting request through the network. When reset, it is provided with a forced disconnection means that forcibly disables the use of the user who is actually using the maintenance interface. As a result, when malicious access is made through the maintenance interface of the client device, the access can be stopped immediately by remote control from the server device, and at the same time, the user recognition information used for intrusion is invalidated. Moreover, new user authentication information can be reset for regular maintenance.
【0041】
The fifth client device of the present invention becomes the user authentication means when the available time elapses after the user authentication information is set in the user authentication means in the first or second client device. It is provided with a usage time management means that invalidates the set user authentication information and forcibly disables the use of the user who is actually using the maintenance interface. As a result, it is possible to prevent the maintenance interface of the client device from being continuously opened for a long period of time and increasing the risk of malicious access.
【0042】
The sixth client device of the present invention extends the remaining usage time of the usage time management means by a predetermined extension time only for the first login after opening the maintenance interface in the fifth client device. Provide means for extending the usage time. As a result, it takes a while for the maintenance person to actually use the maintenance interface of the client device after opening the maintenance interface of the client device, and sufficient maintenance work is performed even if the user logs in when the remaining usage time is short. Moreover, security can be ensured because the extension is allowed only for the first login.
【0043】
The seventh client device of the present invention is the user when the user is logged in as many times as possible after the user authentication information is set in the user authentication means in the first or second client device. It is provided with a login count management means that invalidates the user authentication information set in the authentication means and forcibly disables the use of the user who is actually using the maintenance interface. This makes it possible to ensure security against malicious users who repeatedly log in and out.
【0044】
The eighth client device of the present invention is the user authentication set in the user authentication means when the user of the maintenance interface ends the use of the maintenance interface in the first or second client device. Provide an authentication invalidation means for invalidating the information. As a result, the maintenance interface can be closed at the same time as the maintenance work is completed, and the security of the maintenance interface of the client device can be ensured.
【0045】
BEST MODE FOR CARRYING OUT THE INVENTION
Next, an embodiment of the present invention will be described in detail with reference to the drawings.
【0046】
[First Embodiment of the invention]
Referring to FIG. 1, in the client-server system according to the first embodiment of the present invention, the server device 1, the plurality of client devices 3, and the remote maintenance console 5 are connected to each other so as to be able to communicate with each other through LAN6. There is. Further, the local maintenance console 2 is connected to the server device 1 through the serial interface or the like, and the local maintenance console 4 is connected to the client device 3 through the serial interface or the like. Hereinafter, the local maintenance console connected to the server device 1 is referred to as a server-side local maintenance console, and the local maintenance console connected to the client device 3 is referred to as a client-side local maintenance console. The client-side local maintenance console 4 is temporarily installed during the construction period of the client device 3 in order to set or change the system data of the client device 3, and does not need to be connected during operation. .. On the other hand, the server-side local maintenance console 2 monitors the failure and processing capacity of the server device 3, sets and changes system data, and is connected when necessary during operation. For example, when the present invention is applied to a client-server type IP-PBX which is a VoIP system, the server device 1 corresponds to an MGC (Media Gateway Controler) that controls calls in the IP-PBX, and the server-side local maintenance console 2 Corresponds to the console connected to MGC. In addition, the client device 3 corresponds to an MG (Media Gateway) that connects to the public telephone network, MC (Media Converter) that houses the telephone, or an IP telephone, and the local maintenance console 4 is the console connected to them. Equivalent to. Needless to say, the present invention is not limited to the client-server type IP-PBX.
【0047】
The server device 1 has a request receiving unit 11 that accepts a user authentication information setting request and a user authentication information setting invalidation request for which the client device 3 is specified from the server-side local maintenance console 2, and a request received by the request receiving unit 11. Is included in the request transfer unit 12 that transfers the information to the designated client device 3 through LAN6.
【0048】
FIG. 2 is a flowchart showing a processing example of the server device 1 when a user authentication information setting request is input from the server-side local maintenance console 2. The system administrator, etc., specifies the specified information of the client device 3 for which the user authentication information is set (for example, the name of the client device that uniquely identifies the client device), and the user name and password as the user authentication information that the system administrator wants to set. When a user authentication information setting request including is input from the server-side local maintenance console 2, this request is received by the request receiving unit 11 (S101), and the request receiving unit 11 also receives the normality such as the number of digits of the user name and password. Check (S102). If the number of digits does not meet the specified conditions, the request is rejected. If there is no problem, the received user authentication information setting request is transmitted from the request reception unit 11 to the request transfer unit 12 (S103). Next, the request transfer unit 12 confirms the IP address of the client device 3 specified in the user authentication information setting request by referring to, for example, a correspondence table (not shown) between the client device name and the IP address. Then, using this IP address, a user authentication information setting instruction including the user name and password in the user authentication information setting request is transmitted to the target client device 3 via LAN6 (S105). Then, when the user authentication information setting completion notification is returned from the target client device 3, the request transfer unit 12 receives this notification (S106) and transmits it to the request reception unit 11 (S107), and the request reception unit 11 outputs a user authentication information setting completion notification to the server-side local maintenance console 2 (S108).
【0049】
FIG. 3 is a flowchart showing a processing example of the server device 1 when a user authentication information setting invalidation request is input from the server-side local maintenance console 2. When the system administrator or the like inputs a user authentication information setting invalidation request that specifies the client device 3 for which the user authentication information setting is to be invalidated from the server-side local maintenance console 2, the request reception unit 11 receives this request. (S111), the received user authentication information setting invalidation request is transmitted from the request reception unit 11 to the request transfer unit 12 (S112). Next, the request transfer unit 12 confirms the IP address of the client device 3 specified in the user authentication information setting invalidation request (S113), and uses this IP address to issue a user authentication information setting invalidation instruction to LAN6. It is transmitted to the target client device 3 via (S114). Then, when the user authentication information setting invalidation completion notification is returned from the target client device 3, the request transfer unit 12 receives this notification (S115), transmits it to the request reception unit 11 (S116), and accepts the request. Part 11 outputs a user authentication information setting invalidation completion notification to the server-side local maintenance console 2 (S117).
【0050】
On the other hand, each client device 3 has a maintenance interface 30 represented by a Telnet interface, and authenticates the maintenance target unit 31 to be maintained and the user who maintains the maintenance target unit 34. Receives the user authentication unit 32 that performs user authentication based on information, the user authentication information setting request and the user authentication information setting invalidation request sent from the server device 1 via LAN6, and performs processing according to each request. The remote request processing unit 33 to be executed, and the local request processing unit that receives the user authentication information setting request and the user authentication information setting invalidation request input from the client side local maintenance console 4 and executes the processing according to each request. It includes 34 and a login / logout processing unit 35 that executes processing related to login and logout from a device on LAN6 such as a remote maintenance console 5 to client device 3. The maintenance target unit 31 is, for example, a memory for recording the operating status and failure status of the hardware and software constituting the client device 3, a memory for recording various system setting data, the software itself, and the like. Further, the maintenance of the maintenance target unit 31 is an operation such as referring to the operation status and the failure status stored in the memory, changing the system setting data and the software, and the like.
【0051】
FIG. 4 is a flowchart showing a processing example of the client device 3 when a user authentication information setting instruction is transmitted from the server device 1 via LAN6. The client device 3 to which the user authentication information setting instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S121), and whether the user name and password instructing satisfy the predetermined number of digits. Check (S122). If the prescribed conditions are not met, this instruction will be rejected. If there is no problem, this instruction is transmitted from the remote request processing unit 33 to the user authentication unit 32 (S123). The user recognition unit 32 internally stores the transmitted user name and password in the instruction (S124). On the other hand, the remote request processing unit 33 transmits a user authentication information setting completion notification to the request source server device 3 via LAN 6 (S125).
【0052】
FIG. 5 is a flowchart showing a processing example of the client device 3 when the user authentication information setting invalidation instruction is transmitted from the server device 1 via LAN6. The client device 3 to which the user authentication information setting invalidation instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S131) and transmits the instruction to the user authentication unit 32 (S132). The user recognition unit 32 invalidates the user name and password registered internally by deleting them (S133). On the other hand, the remote request processing unit 33 transmits a user authentication information setting invalidation completion notification to the request source server device 3 via LAN 6 (S134).
【0053】
FIG. 6 is a flowchart showing a processing example of the client device 3 when a user authentication information setting request is input from the client-side local maintenance console 4. When a maintenance worker or the like inputs a user authentication information setting request including a user name and password as user authentication information to be set from the client-side local maintenance console 4, this request is received by the local request processing unit 34 (S141). ), Similarly, the local request processing unit 34 checks whether the user name and password being requested satisfy the predetermined number of digits (S142). If the prescribed conditions are not met, this request will be rejected. If there is no problem, the user authentication information setting instruction including the requesting user name and password is transmitted from the local request processing unit 34 to the user authentication unit 32 (S143). The user recognition unit 32 internally stores the transmitted user name and password in the instruction (S144). On the other hand, the local request processing unit 34 outputs a user authentication information setting completion notification to the client-side local maintenance console 4 (S145).
【0054】
FIG. 7 is a flowchart showing a processing example of the client device 3 when a user authentication information setting invalidation request is input from the client-side local maintenance console 4. When a maintenance worker or the like inputs a user authentication information setting invalidation request for invalidating the set user authentication information from the client-side local maintenance console 4, the local request processing unit 34 receives this request (S151). , Communicate to user authentication unit 32 (S152). The user recognition unit 32 invalidates the user name and password registered internally by deleting them (S153). On the other hand, the local request processing unit 34 outputs a user authentication information setting invalidation completion notification to the client-side local maintenance console 4 (S154).
【0055】
FIG. 8 is a flowchart showing a processing example of the client device 3 when a login request including a user name and password specification is sent from the remote maintenance console 5 via LAN6. The client device 3 to which the login request is sent via the LAN receives this login request in the login / logout processing unit 35 (S161), and whether the user name and password in the login request satisfy a predetermined number of digits or the like. Check (S162). If the prescribed conditions are not met, this login request will be rejected. If there is no problem, the login / logout processing unit 35 transmits the authentication instruction specifying the user name and password in the login request to the user authentication unit 32 (S163). The user recognition unit 32 determines whether or not the internal user authentication information is registered in advance (S164), and if it is registered (YES in S165), the authentication transmitted from the login / logout processing unit 35. Compare the instructed user name and password with the internally registered user name and password (S166). Then, when the two match (YES in S167), the successful authentication is transmitted from the user authentication unit 32 to the login / logout processing unit 35 (S168). The login / logout processing unit 35 executes a login process for allowing access to the maintenance target unit 31 from the remote maintenance console 5 (S169), and notifies the remote maintenance console 5 of the login permission (S170). As a result, after that, the maintenance worker can access the maintenance target unit 31 of the client device 3 from the remote maintenance console 5 via LAN6.
【0056】
On the other hand, whether the user authentication unit 32 has determined that the user authentication information has not been registered in advance (NO in S165), or the user name and password registered but the user name and password being instructed to authenticate are registered. If it is determined that the password does not match (NO in S167), the authentication failure is transmitted from the user authentication unit 32 to the login / logout processing unit 35 (S171), and the login / logout processing unit 35 uses the remote remote maintenance console 5 Notify login permission (S171).
【0057】
FIG. 9 is a flowchart showing a processing example of the client device 3 when a logout request is sent from the remote maintenance console 5 during login via LAN6. The client device 3 to which the logout request is sent via LAN6 receives this logout request in the login / logout processing unit 35 (S181), and prohibits further access from the remote maintenance console 5 to the maintenance target unit 31. Logout process (S182). Then, the login / logout processing unit 35 sends a logout completion notification to the remote maintenance console 5 (S183).
【0058】
Next, the operation of this embodiment will be described.
【0059】
FIG. 10 is a sequence chart showing an operation example of the present embodiment, and shows a sequence of the following four scenes. (1) Setting user authentication information from the server-side local maintenance console 2 to the client device 3 (2) Login and log-out to the client device 3 using the remote maintenance console 5 after registering the user authentication information (3) Server-side local Invalidation of user authentication information from maintenance console 2 to client device 3 (4) Login to client device 3 by remote maintenance console 5 after invalidation of user authentication information [0060]
Hereinafter, the operation of the present embodiment will be described with respect to the above four situations.
【0061】
(1) First, the operation when setting the user authentication information from the server-side local maintenance console 2 to the client device 3 will be described with reference to FIGS. 1, 2, 4, and 10.
【0062】
A system administrator or the like requests a user authentication information setting request from the server-side local maintenance console 2 including a user name and password for releasing the security of the maintenance interface 30 of the client device 3 and the designation of the target client device 3. Is entered (R101 in FIG. 10), and the server device 1 accepts this request (R102). In this reception process, the request reception unit 11 receives a user authentication information setting request and checks the normality of the user name and password (S101 and S102 in FIG. 2). If there is no problem, this request is transmitted to the request transfer unit 12 (S103 in FIG. 2). Next, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting request (S104 in FIG. 2), and then goes to the remote request processing unit 33 of the client device 3 via LAN6. User authentication information setting instructions including the user name and password are sent (R103 in Fig. 10 and S105 in Fig. 2).
【0063】
The client device 3 receives the user authentication information setting instruction transferred from the server device 1 by the remote request processing unit 33 (S121 in FIG. 4), confirms the normality of the user name and password (S122), and then confirms the normality of the user name and password (S122). If there is no problem, the user authentication information setting instruction is transmitted to the user authentication unit 32 (S123). The user authentication unit 32 stores the user name and password during the user authentication information setting instruction (R104 in FIG. 10 and S124 in FIG. 2). On the other hand, the remote request processing unit 33 sends a user authentication information setting completion notification to the request transfer unit 12 of the server device 1 via LAN6 (R105 in FIG. 10 and S125 in FIG. 2). When the request forwarding unit 12 receives the user authentication information setting completion notification, it outputs it to the server-side local maintenance console 2 through the request receiving unit 11 (R106 in FIG. 10, S106 to S108 in FIG. 2).
【0064】
(2) Next, with reference to FIGS. 1, 8, 9, and 10, the operation at the time of login and logout to the client device 3 by the remote maintenance console 5 after the user authentication information is registered will be described.
【0065】
After the user authentication information consisting of the user name and password is registered in the user authentication unit 32 of the client device 3, the maintenance worker performs the client device from the remote maintenance console 5 via LAN 6 as part of the preparation for the maintenance work. When a login request with a user name and password is entered for 3 (R111 in FIG. 10), a series of processes related to user authentication are executed in the client device 3 (R112 in FIG. 10 and S161 in FIG. 8). ~ S172). Specifically, the login request from the remote maintenance console 5 is received by the login / logout processing unit 35, the normality is checked (S161, S162), and if there is no problem, the user name and password in the login request are entered. The including authentication instruction is issued to the user authentication unit 32 (S163). Next, the user authentication unit 32 determines whether or not the user authentication information is registered (S164, S165), and matches the registered user name and password with the user name and password in the authentication instruction when there is registration. Judgment (S166, S167) is carried out. In the user authentication R112 of FIG. 10, it is assumed that the user authentication information is registered in advance and the user name and password specified in the login request match the registered user name and password, and the authentication is successful. doing. Therefore, the user authentication unit 32 notifies the login / logout processing unit 35 of the successful authentication (S168), the login / logout processing unit 35 performs the login process (S169), and gives login permission to the remote maintenance console 5. Notify (S170, R113 in Figure 10). As a result, the maintenance worker can access the maintenance target unit 31 of the client device 3 from the remote maintenance console 5 and start various maintenance work.
【0066】
When the maintenance worker finishes the maintenance work and inputs a logout request from the remote maintenance console 5 (R114 in FIG. 10), the login / logout processing unit 35 of the client device 3 receives this (S181 in FIG. 9). Perform the logout process (S182, R115 in Figure 10). Then, the login / logout processing unit 35 sends a logout completion notification to the remote maintenance console 5 (S183, R116 in FIG. 10). As a result, access from the remote maintenance console 5 to the maintenance target unit 31 of the client device 3 is prohibited. However, since the user name and password are stored in the user authentication unit 32 and are waiting for a login request, the maintenance interface 30 of the client device 3 is open. That is, the maintenance interface 30 of the client device 3 is not blocked. Therefore, when the next login request comes from the remote maintenance console 5 and the user name and password match and the authentication is successful, the access to the maintenance target unit 31 of the client device 3 becomes possible again.
【0067】
(3) Next, the operation when invalidating the user authentication information registered in the client device 3 from the server-side local maintenance console 2 will be described with reference to FIGS. 1, 3, 5, and 10. ..
【0068】
When the system administrator or the like inputs a user authentication information setting invalidation request that specifies the target client device 3 in order to secure security by blocking the maintenance interface 30 of the client device 3 from the server-side local maintenance console 2. (R121 in FIG. 10), the server device 1 performs the user authentication information invalidation request acceptance process (R122). In this reception process, the request reception unit 11 receives a user authentication information setting invalidation request and transmits the received request to the request transfer unit 12 (S111 and S112 in FIG. 3). Next, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting invalidation request (S113 in FIG. 3), and the remote request processing unit 33 of the client device 3 via LAN6. An instruction to invalidate the user authentication information setting is sent to (R123 in Fig. 10 and S114 in Fig. 3).
【0069】
The client device 3 receives the user authentication information setting invalidation instruction transferred from the server device 1 by the remote request processing unit 33 (S131 in FIG. 5), and sends the user authentication information setting invalidation instruction to the user authentication unit 32. Communicate (S132). The user authentication unit 32 invalidates the user authentication information composed of the registered user name and password (R124 in FIG. 10 and S133 in FIG. 5). On the other hand, the remote request processing unit 33 sends a user authentication information setting invalidation completion notification to the request transfer unit 12 of the server device 1 via LAN6 (R125 in FIG. 10 and S134 in FIG. 5). When the request forwarding unit 12 receives the user authentication information setting invalidation completion notification, it outputs the notification to the server-side local maintenance console 2 through the request receiving unit 11 (R126 in FIG. 10, S115 to S117 in FIG. 3).
【0070】
(4) Next, the operation when a login request is made from the remote maintenance console 5 to the client device 3 after the user authentication information is invalidated will be described with reference to FIGS. 1, 8 and 10.
【0071】
When a login request is input to the client device 3 from the remote maintenance console 5 via LAN 6 (R131 in Fig. 10), the client device 3 executes a series of processes related to user authentication (R132 in Fig. 10). S161 to S172 in Fig. 8). However, since the user authentication information is not registered in the user authentication unit 32, the authentication fails (NO in S165 in FIG. 8). Therefore, the login / logout processing unit 35 notifies the remote maintenance console 5 that login is not permitted (S172, R133 in FIG. 10). As a result, access from the remote maintenance console 5 to the maintenance target unit 31 of the client device 3 is prohibited. Even if the user name and password are registered in the user authentication unit 32, the user name and password specified in the login request from the remote maintenance console 5 are registered in the user authentication unit 32. If it does not match, the login / logout processing unit 35 similarly does not give login permission.
【0072】
FIG. 11 is a sequence chart showing an operation example of the present embodiment, and shows a sequence of the following two scenes. (1) Setting user authentication information from client-side local maintenance console 4 to client device 3 (2) Login and log-out to client device 3 using remote maintenance console 5 after user authentication registration (3) Client-side local maintenance Invalidation of user authentication information from console 4 to client device 3 [0073]
Hereinafter, the operation of the present embodiment will be described with respect to the above three situations.
【0074】
(1) First, the operation when the user authentication information is set from the client-side local maintenance console 4 to the client device 3 will be described with reference to FIGS. 1, 6 and 11.
【0075】
When the system administrator or the like inputs a user authentication information setting request including the specification of the user name and password for releasing the security of the maintenance interface 30 of the client device 3 from the client-side local maintenance console 4 (R141 in FIG. 11). ), The client device 3 receives this user authentication information setting request at the local request processing unit 34 (S141 in FIG. 6), confirms the normality of the user name and password (S142), and uses it if there is no problem. The user authentication information setting instruction is transmitted to the user authentication unit 32 (S143). The user authentication unit 32 stores the user name and password during the user authentication information setting instruction (R142 in FIG. 11 and S144 in FIG. 6). On the other hand, the local request processing unit 34 outputs a user authentication information setting completion notification to the client-side local maintenance console 4 (R143 in FIG. 11 and S145 in FIG. 6).
【0076】
(2) Since the operation at the time of login and logout to the client device 3 by the remote maintenance console 5 after the user authentication registration is the same as the sequences R111 to R116 of FIG. 10 described above, the description thereof will be omitted.
【0077】
(3) Next, the operation when invalidating the user authentication information registered in the client device 3 from the client-side local maintenance console 4 will be described with reference to FIGS. 1, 7, and 11.
【0078】
When the system administrator or the like inputs a user authentication information setting invalidation request to ensure security by blocking the maintenance interface 30 of the client device 3 from the client-side local maintenance console 4 (R151 in Fig. 11), the client device 3 receives the user authentication information setting invalidation instruction at the local request processing unit 34 (S151 in FIG. 7), and transmits the user authentication information setting invalidation instruction to the user authentication unit 32 (S152). The user authentication unit 32 invalidates the user authentication information composed of the registered user name and password (R152 in FIG. 11 and S153 in FIG. 7). On the other hand, the local request processing unit 34 outputs a user authentication information setting invalidation completion notification to the client-side local maintenance console 4 (R153 in FIG. 11 and S154 in FIG. 7).
【0079】
As described above, according to the present embodiment, the maintenance interface 30 of a plurality of client devices 3 located in remote locations can be opened from the server-side local maintenance console 2, and the maintenance interface 30 can be opened remotely from the server-side local maintenance console. The maintenance interface 30 of a plurality of client devices 3 on the ground can be blocked. When the local maintenance console 4 is connected to the client device 3, the maintenance interface 30 of the client device 3 can be opened or closed from the client-side local maintenance console 2 for each client device.
【0080】
[Second Embodiment of the Invention]
Referring to FIG. 12, the client-server system according to the second embodiment of the present invention is a local request from each client device 3 in the client-server system according to the first embodiment shown in FIG. The first embodiment is that the processing unit 34 is deleted so that the user authentication information cannot be set and invalidated from the client-side local maintenance console 4 to the user authentication unit 32 of the client device 3. The differences are the same as in the first embodiment.
【0081】
In the present embodiment, user authentication information for opening the maintenance interface 30 of the client device 3 from the remote maintenance console 5 via LAN 6 into the client device 3 from only the server-side local maintenance console 2 via LAN 6. (User name and password) can be set, and the user authentication information set in the client device 3 can be deleted from the server-side local maintenance console 2 to prohibit the use of the maintenance interface 30 in the client device 3. ..
【0082】
In this way, the maintenance interface 30 of multiple client devices 3 can be opened and blocked by limiting it to the server-side local maintenance console 2, so that the system administrator of the server device 1 can manage the security of the maintenance interface 30. It can be easily managed.
【0083】
[Third Embodiment of the invention]
Referring to FIG. 13, the client-server system according to the third embodiment of the present invention has a user name in the server device 13 in the client-server system according to the second embodiment shown in FIG. It differs from the second embodiment in that it is provided with an encryption unit 13 for encrypting the password and a decryption unit 36 for decrypting the encrypted user name and password in each client device 3. , Other points are the same as in the second embodiment.
【0084】
FIG. 14 is a flowchart showing a processing example of the server device 1 when a user authentication information setting request is input from the server-side local maintenance console 2, and the point that steps S301 to S303 are added is the flowchart of FIG. It's different. The system administrator, etc. makes a user authentication information setting request including the specified information of the client device 3 for which the user authentication information is set and the user name and password as the user authentication information to be set on the server-side local maintenance console. If you enter from 2, the request reception unit 11 receives this request (S101), checks the normality of the number of digits of the user name and password (S102), and if there is no problem, accepts the user authentication information setting request. User name and password are transmitted from the request reception unit 11 to the encryption unit 13 (S301). The encryption unit 13 encrypts the user name and password by any encryption method predetermined by the system, such as the common key encryption method and the private key encryption method (S302), and requests and accepts the encrypted user name and password. Communicate to part 11 (S303). The request reception unit 11 transmits a user authentication information setting request including an encrypted user name and password to the request transfer unit 12 (S103). Hereinafter, the same processing as that described with reference to FIG. 3 is executed (S104 to S108).
【0085】
FIG. 15 is a flowchart showing a processing example of the client apparatus 3 when a user authentication information setting instruction is transmitted from the server apparatus 1 via LAN6, and the flowchart of FIG. 4 is that steps S311 to S313 are added. Is different from. The client device 3 to which the user authentication information setting instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S121), and decrypts the encrypted user name and password being instructed in the decryption unit 36. (S311). The decryption unit 36 decrypts the encrypted user name and password (S312) and transmits the encrypted user name and password to the remote request processing unit 33 (S313). The remote request processing unit 33 checks whether the user name and password satisfy a predetermined number of digits (S122), and if there is no problem, transmits this instruction to the user authentication unit 32 (S123). Hereinafter, the same processing as that described with reference to FIG. 4 is executed (S124, S125).
【0086】
Next, the operation of this embodiment will be described.
【0087】
FIG. 16 is a sequence chart showing an operation example of this embodiment, and shows a sequence of user authentication information setting scenes from the server-side local maintenance console 2 to the client device 3. Hereinafter, the operation when the user authentication information is set from the server-side local maintenance console 2 to the client device 3 will be described with reference to FIGS. 13 to 16.
【0088】
A system administrator or the like requests a user authentication information setting request from the server-side local maintenance console 2 including a user name and password for releasing the security of the maintenance interface 30 of the client device 3 and the designation of the target client device 3. Is entered (R301 in FIG. 16), and the server device 1 accepts this request (R302). In this reception process, the request reception unit 11 receives a user authentication information setting request and checks the normality of the user name and password (S101 and S102 in FIG. 14). If there is no problem, the encryption unit 13 performs a process of encrypting the user name and password (R303 in FIG. 14 and S301 to S303 in FIG. 14). Then, the user authentication information setting request including the encrypted user name and password is transmitted from the request reception unit 11 to the request transfer unit 11 (S103). After that, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting request (S104), and sends the user name and the user name to the remote request processing unit 33 of the client device 3 via LAN6. Send the user authentication information setting instruction including the password (R304 in Fig. 16 and S105 in Fig. 14).
【0089】
The client device 3 receives the user authentication information setting instruction transferred from the server device 1 by the remote request processing unit 33 (S121 in FIG. 15), and decrypts the encrypted user name and password included in the instruction. Decryption is performed using the conversion unit 36 (R305 in FIG. 16 and S311 to S313 in FIG. 15). Subsequently, the normality of the decrypted user name and password is confirmed (S122), and if there is no problem, the user authentication information setting instruction is transmitted to the user authentication unit 32 (S123). The user authentication unit 32 stores the user name and password during the user authentication information setting instruction (R306 in FIG. 16 and S124 in FIG. 15). On the other hand, the remote request processing unit 33 sends a user authentication information setting completion notification to the request transfer unit 12 of the server device 1 via LAN6 (R307 in FIG. 16 and S125 in FIG. 15). When the request forwarding unit 12 receives the user authentication information setting completion notification, it outputs it to the server-side local maintenance console 2 through the request receiving unit 11 (R308 in FIG. 16 and S106 to S108 in FIG. 14).
【0090】
Other operations such as the procedure for the maintenance person to log in and out using the maintenance console 5 and the procedure for invalidating the user name and password set from the server-side local maintenance console 2 are the same as those in the second embodiment. is there.
【0091】
As described above, according to the present embodiment, when the maintenance interface 30 of the plurality of client devices 3 is opened from the server-side local maintenance console 2, the user name and password to be transferred between the server device 1 and the client device 3 are used. By encrypting the user authentication information composed of the above, leakage of the user authentication information can be prevented and security can be ensured.
【0092】
In the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may.
【0093】
[Fourth Embodiment of the invention]
Referring to FIG. 17, the client-server system according to the fourth embodiment of the present invention is used for each client device 3 in the client-server system according to the third embodiment shown in FIG. If there is a logged-in device that uses the maintenance interface 30 of the client device 3 when the user authentication information of the person authentication unit 32 is reset, a forced disconnection notification is sent to the device to perform forced disconnection. It differs from the third embodiment in that it includes a forced cutting portion 37, and is the same as the third embodiment in other points.
【0094】
FIG. 18 is a flowchart showing a processing example of the client apparatus 3 when a user authentication information setting instruction is transmitted from the server apparatus 1 via LAN6, and the flowchart of FIG. 15 is that steps S401 to S405 are added. Is different from. The client device 3 to which the user authentication information setting instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S121), and decrypts the encrypted user name and password in this instruction. Decrypt with 36 (S311 to S313), check whether the user name and password meet the specified number of digits (S122), and if there is no problem, remote the user authentication information setting instruction including the user name and password. It is transmitted from the request processing unit 33 to the user authentication unit 32 (S123). Up to this point, the operation is the same as that of the third embodiment. Subsequently, the user authentication unit 32 determines whether or not the user authentication information has already been registered (S401), and separates the processing between the unregistered case and the registered case.
【0095】
If the user authentication information has not yet been registered in the user authentication unit 32, promptly register the user name and password in the user authentication information setting instruction in the user authentication unit 32 (S124), and perform remote request processing. Unit 33 sends a user authentication information setting completion notification to server device 1 (S125).
【0096】
On the other hand, if the user authentication information has already been registered in the user authentication unit 32, the user authentication unit 32 requests the forced disconnection unit 37 to perform the forced disconnection process (S402). The forced disconnection unit 37 asks the login / logout processing unit 35 whether the remote maintenance console 5 logged in to use the maintenance interface 30 of the client device 3 exists (S403), and if it does not exist. Notifies the user authentication unit 32 of the completion of processing (S405). However, if the remote maintenance console 5 that is logged in exists, a forced disconnection notification is sent to the remote maintenance console 5, the forced disconnection is performed (S404), and the user authentication unit 32 is notified of the completion of the process. (S405). After that, the user authentication unit 32 registers the user name and password in the user authentication information setting instruction in the user authentication unit 32 (S124), and the remote request processing unit 33 notifies the user authentication information setting completion completion to the server device. Send to 1 (S125).
【0097】
Next, the operation of this embodiment will be described.
【0098】
FIG. 19 is a sequence chart showing an operation example of the present embodiment, and is a user name and a password for opening the maintenance interface 30 of the client device 3 into the client device 3 from the server-side local maintenance console 2 via LAN6. After making the initial settings of, while someone is logging in to the client device 3 from the remote maintenance console 5 and accessing the maintenance target unit 34, from the server-side local maintenance console 2 to the maintenance interface 30 of the client device 3 The sequence of scenes where the user name and password are reset and regular remote maintenance is performed is shown.
【0099】
Of the sequences shown in FIG. 19, the sequences R301 to R308 for initializing the user name and password from the server-side local maintenance console 2 to the client device 3 are the same as the processes described with reference to FIG. In this case, since the user name and password do not exist in the user authentication unit 32 before the setting, the processes S402 to S405 in FIG. 18 are skipped.
【0100】
After the user name and password are set in the user authentication unit 32 of the client device 3, when someone inputs a login request specifying the user name and password from the remote maintenance console 5 to the client device 3 via LAN6 ( A user whose client device 3 performs the same processing as that described with reference to R401), FIG. 8 and FIG. 10 in FIG. 19, and whose user name and password in the login request are registered in the user authentication unit 32. If the name and password match, login is permitted (R402 and R403 in FIG. 19), and the remote maintenance console 5 can access the maintenance target unit 31 of the client device 3.
【0101】
When a user authentication information setting request is input from the server-side local maintenance console 2 while the remote maintenance console 5 is logged in (R411 in FIG. 19), the following operations are performed. ..
【0102】
First, the request reception unit 11 of the server device 1 receives the user authentication information setting request from the server-side local maintenance console 2 and performs a reception process for checking its normality (R412 in FIG. 19). Subsequently, the user name and password are encrypted by the encryption unit 13 (R413 in FIG. 19), and the user authentication information setting instruction including the encrypted user name and password is sent from the request transfer unit 12 via LAN6. Is sent to the remote request processing unit 33 of the client device 3 (R414 in FIG. 19).
【0103】
The client device 3 receives the user authentication information setting instruction transferred from the server device 1 by the remote request processing unit 33 (S121 in FIG. 18), and decrypts the encrypted user name and password included in the instruction. Decryption is performed using the conversion unit 36 (R415 in FIG. 19 and S311 to S313 in FIG. 18). Subsequently, the normality of the decrypted user name and password is confirmed (S122), and if there is no problem, the user authentication information setting instruction is transmitted to the user authentication unit 32 (S123).
【0104】
Since the user authentication information 32 has already been registered (YES in S401), the user authentication unit 32 requests the forced disconnection unit 37 to perform the forced disconnection process (S402). The forced disconnection unit 37 confirms that the remote maintenance console 5 is logged in in the login / logout processing unit 35 (YES in S403), sends a forced disconnection notification to the remote maintenance console 5, and performs a forced disconnection. (R416 in FIG. 19 and S404 in FIG. 18), which makes it impossible to access the maintenance target unit 31 from the remote maintenance console 5. After that, the forced disconnection unit 37 notifies the user authentication unit 32 of the completion of the process (S405), and the user authentication unit 32 invalidates the already registered user authentication information by deleting the registered user authentication information, and then invalidates the user authentication unit 32. Register the user name and password in the user authentication information setting instruction (R417 in Fig. 19, S124 in Fig. 18). Then, the remote request processing unit 33 sends a user authentication information setting completion notification to the server device 1 (R418 in FIG. 19 and S125 in FIG. 18), and finally notifies the server-side local maintenance console 2 (FIG. 19). R419).
【0105】
After the user name and password are reset, the maintainer logs in to the client device 3 from the remote maintenance console 5 using the new user name and password that has been reset, performs maintenance work, and logs out when the work is completed. The sequences R111 to R116 of the scenes to be performed are the same as the sequences described with reference to FIG.
【0106】
As described above, according to the present embodiment, when the server-side local maintenance console 2 instructs the user authentication unit 32 to set the user name and password of the maintenance interface 30 of the client device 3. If the user authentication information has already been set, if the remote maintenance console 5 is logged in, a forced disconnection notification is sent to perform the forced disconnection, and the user name and password are reset in the user authentication unit 32. .. Therefore, if malicious access is being made to the maintenance interface 30 of the client device 3, the user name and password of the maintenance interface 30 of the client device 1 should be reset from the server-side local maintenance console 2. Therefore, malicious access can be blocked, and at the same time, the user name and password can be reset, and sufficient security can be ensured.
【0107】
In the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may. Further, the user authentication information may be transferred from the server device 1 to the client device 3 without being encrypted, in which case the encryption unit 13 and the decryption unit 36 are omitted.
【0108】
[Fifth Embodiment of the invention]
Referring to FIG. 20, the client-server system according to the fifth embodiment of the present invention is attached to the server device 1 in the client-server system according to the fourth embodiment shown in FIG. 17 on the server side. The function of accepting the request for setting the available time from the local maintenance console 2 and transferring it to the client device 3 is provided, and each client device 3 manages the usage time of the maintenance interface 30 from the remote maintenance console 5. However, if the available time set in advance is exceeded from the server device 1, a usage time end notification is sent to the remote maintenance console 5 to forcibly disconnect the server, and the usage registered in the user recognition unit 32 is used. It differs from the fourth embodiment in that it includes a usage time management unit 38 that invalidates the person authentication information, and is the same as the fourth embodiment in other respects.
【0109】
FIG. 21 is a flowchart showing a processing example of the server device 1 when a user authentication information setting request is input from the server-side local maintenance console 2. User authentication information in which the system administrator or the like specifies the specified information of the client device 3 for which the user authentication information is set, the user name and password as the user authentication information to be set, and the available time to be set. When a setting request is input from the server-side local maintenance console 2, the request reception unit 11 receives this request (S501) and checks the normality of the user name, password, and the number of digits of the available time (S502). If the number of digits does not meet the specified conditions, the request is rejected. If there is no problem, the received user name and password in the user authentication information setting request are encrypted by the encryption unit 13 (S503 to S505), and the user authentication including the encrypted user name and password and the available time is performed. The information setting request is transmitted to the request transfer unit 12 (S506). Next, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting request (S507), and uses this IP address for encryption during the user authentication information setting request. A user authentication information setting instruction including the user name and password and the available time is sent to the target client device 3 via LAN6 (S508). Then, when the user authentication information setting completion notification is returned from the target client device 3, this notification is received by the request forwarding unit 12, and the user authentication information is set in the server-side local maintenance console 2 via the request receiving unit 11. Output a completion notification (S509 to S511).
【0110】
FIG. 22 is a flowchart showing a processing example of the client device 3 when the user authentication information setting instruction is transmitted from the server device 1 via LAN6, and the point that steps S521, S522, and S523 are added is shown in FIG. It is different from the flowchart of. The client device 3 to which the user authentication information setting instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S121), and decrypts the encrypted user name and password in this instruction. Decrypt with 36 (S311 to S313), check whether the user name, password and available time meet the specified number of digits (S122), and if there is no problem, send the available time to the usage time management unit 38. Communicate (S521). The usage time management unit 38 stores this available time (S522). On the other hand, the remote request processing unit 33 transmits the user authentication information setting instruction including the user name and password to the user authentication unit 32 (S123). After that, the same processing as in FIG. 18 is performed (S401 to S405, S124, S125), and when the user authentication information is stored in the user authentication unit 32 and the maintenance interface 30 is opened, the usage time management unit 38 Starts managing the usage time according to the stored usable time (S523).
【0111】
FIG. 23 is a flowchart showing a processing example after the usage time management unit 38 starts managing the usage time. When the usage time management unit 38 starts managing the usage time, the usable time recorded inside is subtracted according to the passage of time, and whether or not the remaining usage time becomes 0, that is, it is set in advance. Determine if the available time has passed (S541). Then, when the remaining usage time becomes 0, if the logged-in remote maintenance console 5 exists (YES in S542), a usage time end notification is sent to the logged-in remote maintenance console 5 and forced disconnection is performed (). S543). If there is no remote maintenance console 5 logged in, this step S543 is skipped. Next, the usage time management unit 38 instructs the user authentication unit 32 to invalidate the user authentication information, and invalidates the user authentication information registered in the user authentication unit 32 accordingly ( S544). After that, the usage time management unit 38 is initialized (S545).
【0112】
FIG. 24 is a sequence chart showing an operation example of the present embodiment, and shows a sequence of the following two scenes. (1) Setting user authentication information and available time from the server-side local maintenance console 2 to the client device 3 (2) Login to the client device 3 using the remote maintenance console 5 [0113]
Hereinafter, the operation of the present embodiment will be described with respect to the above two situations.
【0114】
(1) First, the operation when setting the user authentication information and the available time from the server-side local maintenance console 2 to the client device 3 will be described with reference to FIGS. 20 to 24.
【0115】
The system administrator, etc. includes the user name and password for releasing the security of the maintenance interface 30 of the client device 3 from the server-side local maintenance console 2, the designation of the target client device 3, and the available time. When a user authentication information setting request is input (R501 in FIG. 24), the server device 1 accepts the request (R502). In this reception process, the request reception unit 11 receives a user authentication information setting request and checks the normality of the user name, password, and available time (S501 and S502 in FIG. 21). If there is no problem, the encryption unit 13 performs a process of encrypting the user name and password (R503 in FIG. 24, S503 to S505 in FIG. 21). Then, the user authentication information setting request including the encrypted user name and password and the available time is transmitted from the request reception unit 11 to the request transfer unit 11 (S506). After that, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting request (S507), and is encrypted to the remote request processing unit 33 of the client device 3 via LAN6. Send the user authentication information setting instruction including the user name and password and the available time (R504 in Fig. 24, S508 in Fig. 21).
【0116】
The client device 3 receives the user authentication information setting instruction transferred from the server device 1 by the remote request processing unit 33 (S121 in FIG. 22), and decrypts the encrypted user name and password included in the instruction. Decryption is performed using the conversion unit 36 (R505 in FIG. 24, S311 to S313 in FIG. 22). Then, the decrypted user name and password and the normality of the available time are confirmed (S122), and if there is no problem, the available time is first transmitted to the usage time management unit 38 (S521). The usage time management unit 38 stores this available time (R506 in FIG. 24, S522 in FIG. 22). Next, the remote request processing unit 33 transmits the user authentication information setting instruction including the user name and password to the user authentication unit 32 (S123). After that, the same process as the process described with reference to FIG. 18 is performed (S401 to S405, S124, S125), the user name and password are set in the user authentication unit 32 (R507 in FIG. 24), and the user is used again. The user authentication information setting completion notification is notified from the client device 3 to the server-side remote maintenance console 2 (R508, R509). Then, the usage time management unit 38 starts managing the usage time (R510, S523 in FIG. 22).
【0117】
(2) Next, the operation when someone logs in to the client device 3 from the remote maintenance console 5 will be described with reference to FIGS. 23 and 24.
【0118】
After the user name and password are set in the user authentication unit 32 of the client device 3 and the usage time management is started in the usage time management unit 38, someone from the remote maintenance console 5 to the client device 3 via LAN6. When a login request with a user name and password is entered (R511 in FIG. 24), a process similar to the process described with reference to FIGS. 8 and 10 is executed in the client device 3, and the user in the login request is performing the same process. If the name and password match the user name and password registered in the user authentication unit 32, login is permitted (R512 and R513 in FIG. 24), and access to the maintenance target unit 31 of the client device 3 from the remote maintenance console 5 Is possible.
【0119】
However, if the available time elapses before the logout request is input from the remote maintenance console 5 to the login / logout processing unit 35 (R515 in Fig. 24, YES in S541 and S542 in Fig. 23), the usage time management Part 35 sends a usage time end notification to the remote maintenance console 5 to perform a forced disconnection (R516 in FIG. 24, S543 in FIG. 23). In addition, the usage time management unit 38 instructs the user authentication unit 32 to invalidate the user authentication information, and the user authentication unit 32 invalidates the registered user authentication information (R517 in FIG. 24). , S544 in Figure 23).
【0120】
As described above, according to the present embodiment, it is possible to manage the usage time of the maintenance interface 30 of the client device 3 by designating the available time from the server-side local maintenance console 2. Therefore, after the maintenance interface 30 of the client device 3 is opened once, it is possible to prevent the maintenance interface 30 from being continuously opened for a long time and increasing the risk of malicious access.
【0121】
In this embodiment, the server-side local maintenance console 2 instructed the client device 3 to set the user authentication information together with the available time, but the server-side local maintenance console 2 instructed the client. The instruction to set the user authentication information to the device 3 and the instruction to set the available time from the server-side local maintenance console 2 to the client device 3 may be made independent. Further, the function of setting the available time from the server-side local maintenance console 2 to the client device 3 may be eliminated, and the fixed available time stored in advance in the usage time management unit 38 may be used.
【0122】
Further, in the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may. Further, the user authentication information may be transferred from the server device 1 to the client device 3 without being encrypted, in which case the encryption unit 13 and the decryption unit 36 are omitted. Further, the remote maintenance console 5 that is logged in may not be forcibly disconnected when the user authentication information is reset. In that case, the forcible disconnection unit 37 is omitted.
【0123】
[Sixth Embodiment of the invention]
Referring to FIG. 25, the client-server system according to the sixth embodiment of the present invention is attached to the server device 1 in the client-server system according to the fifth embodiment shown in FIG. 20 on the server side. It has a function of accepting requests for the number of logins from the local maintenance console 2 and transferring it to the client device 3, and each client device 3 manages the number of logins from the remote maintenance console 5 to manage the server device 1. If the number of logins set from is exceeded, login is not permitted and a notification of the end of the number of uses is sent to the remote maintenance console 5, and the user authentication information registered in the user recognition unit 32 is invalidated. It differs from the fifth embodiment in that it is provided with the login count management unit 39, and is the same as the fifth embodiment in other respects.
【0124】
FIG. 26 is a flowchart showing a processing example of the server device 1 when a user authentication information setting request is input from the server-side local maintenance console 2. The system administrator, etc., specifies the specified information of the client device 3 for which the user authentication information is set, the user name and password as the user authentication information to be set, the available time to be set, and the number of logins that can be set. When a user authentication information setting request with the specified is input from the server-side local maintenance console 2, the request reception unit 11 receives this request (S601), and the user name, password, available time, number of possible logins, etc. Check the normality of (S602). If the number of digits does not meet the specified conditions, the request is rejected. If there is no problem, the received user name and password in the user authentication information setting request are encrypted by the encryption unit 13 (S603 to S605), and the encrypted user name and password, available time, and number of times of login can be obtained. The user authentication information setting request including the user authentication information setting request is transmitted to the request transfer unit 12 (S606). Next, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting request (S607), and uses this IP address for encryption during the user authentication information setting request. A user authentication information setting instruction including the user name and password, the available time, and the number of times the user can log in is sent to the target client device 3 via LAN 6 (S608). Then, when the user authentication information setting completion notification is returned from the target client device 3, this notification is received by the request forwarding unit 12, and the user authentication information is set in the server-side local maintenance console 2 via the request receiving unit 11. Output the completion notification (S609 ~ S611).
【0125】
FIG. 27 is a flowchart showing a processing example of the server device 1 when a user authentication information setting request is input from the server-side local maintenance console 2, and the point that steps S621 and S622 are added is the flowchart of FIG. 22. It's different. When the client device 3 to which the user authentication information setting instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S121), the decryption unit decrypts the encrypted user name and password in this instruction. Decrypt in 36 (S311 to S313), and check whether the user name, password, available time, and number of logins meet the specified number of digits (S122). If there is no problem, the available time is transmitted to the usage time management unit 38 (S521), and the usage time management unit 38 stores this available time (S522). Further, the number of possible logins is transmitted to the number of logins management unit 39 (S621), and the number of logins management unit 39 stores the number of possible logins (S622). After that, the same processing as in FIG. 22 is performed (S123, S401 to S405, S124, S125, S523).
【0126】
FIG. 28 is a flowchart showing a processing example of the client device 3 when a login request including a user name and password specification is sent from the remote maintenance console 5 via LAN6, and steps S631 to S635 are added. Is different from the flowchart in FIG. In the present embodiment, when the login / logout processing unit 35 receives the login request from the remote maintenance console 5 (S161), the login count management unit 39 increments the login count by +1 (S631), which is set in advance. Determine if the number of logins has been exceeded (S632). If the number of logins has not been exceeded, the same processing as in Fig. 8 is performed (S162 to S172).
【0127】
On the other hand, if the number of logins exceeds the number of logins that can be performed, a notification of the end of the number of uses is sent to the remote maintenance console 5 that has issued a login request from the login count management unit 39 (S633). At this time, the login / logout processing unit 35 does not give login permission. Furthermore, the user authentication unit 32 invalidates the registered user authentication information (S634). Then, the login count management unit 38 is initialized (S635).
【0128】
FIG. 29 is a sequence chart showing an operation example of the present embodiment, and shows a sequence of the following two scenes. (1) Setting user authentication information, available time, and number of logins from the server-side local maintenance console 2 to the client device 3 (2) Frequent login to the client device 3 from the remote maintenance console 5 [0129]
Hereinafter, the operation of the present embodiment will be described with respect to the above two situations.
【0130】
(1) First, with reference to FIGS. 25 to 27 and 29, the operation when setting the user authentication information, the available time, and the number of times of login from the server-side local maintenance console 2 to the client device 3 will be described. ..
【0131】
From the server-side local maintenance console 2, the system administrator, etc. can use the user name and password to release the security of the maintenance interface 30 of the client device 3, specify the target client device 3, and allow the maximum login time. When a user authentication information setting request including a certain available time and the maximum number of logins that can be logged in within this available time is input (R601 in FIG. 29), the server device 1 accepts this request. It is done (R602). In this reception process, the request reception unit 11 receives a user authentication information setting request and checks the normality of the user name, password, available time, and number of logins (S601 in FIG. 26, S602). If there is no problem, the encryption unit 13 performs a process of encrypting the user name and password (R603 in FIG. 29, S603 to S605 in FIG. 26). Then, the request for setting the user authentication information including the encrypted user name and password, the available time, and the number of times the login can be performed is transmitted from the request receiving unit 11 to the request transfer unit 11 (S606). After that, the request transfer unit 12 acquires the IP address of the client device 3 specified in the user authentication information setting request (S607), and is encrypted to the remote request processing unit 33 of the client device 3 via LAN6. Send the user authentication information setting instruction including the user name and password and the available time (R604 in Fig. 29, S608 in Fig. 26).
【0132】
The client device 3 receives the user authentication information setting instruction transferred from the server device 1 by the remote request processing unit 33 (S121 in FIG. 27), and decrypts the encrypted user name and password included in the instruction. Decryption is performed using the conversion unit 36 (R605 in FIG. 29, S311 to S313 in FIG. 27). Next, check the decrypted user name and password, the available time, and the number of logins (S122), and if there are no problems, use the available time in the usage time management unit 38 and the number of logins. It is transmitted to the management unit 39, and the usage time management unit 38 stores the available time, and the login count management unit 39 stores the login count (R606 in FIG. 29, S521, S522, S621, S622 in FIG. 27). Next, the remote request processing unit 33 transmits the user authentication information setting instruction including the user name and password to the user authentication unit 32 (S123). After that, the same processing as in FIG. 22 is performed (S401 to S405, S124, S125, S523), the user name and password are set in the user authentication unit 32 (R607 in FIG. 29), and the user authentication information setting is completed. The notification is notified from the client device 3 to the server-side remote maintenance console 2 (R608, R609). Furthermore, the usage time management unit 38 starts managing the usage time (R610).
【0133】
(2) Next, the operation when the maintenance worker frequently logs in to the client device 3 from the remote maintenance console 5 will be described with reference to FIGS. 25, 28, and 29.
【0134】
After the user name and password are set in the user authentication unit 32 of the client device 3, the available time is set in the usage time management unit 38, and the number of login times is set in the login count management unit 39, someone else When a login request with a user name and password is entered from the remote maintenance console 5 to the client device 3 via LAN 6 (R611 in Fig. 29), the login count management unit 39 updates the login count (R612 in Fig. 29). If the user authentication process R613 is executed and the user name and password in the login request match the user name and password registered in the user authentication unit 32, login is permitted (Fig. 28). 29 R614). As a result, the remote maintenance console 5 can access the maintenance target unit 31 of the client device 3. Then, in the sequence of FIG. 30, the remote maintenance console is logged out and logged in again.
【0135】
In the fifth embodiment, login and logout could be repeated many times from the remote maintenance console 5 using the user name and password within the available time. However, in the case of this embodiment, the login count management unit 39 updates the login count every time there is a login request, and when the login count exceeds the preset log-in possible count (R621 in FIG. 29, FIG. 28). YES in S632), even before the end of the available time, the remote maintenance console 5 is notified of the end of the number of uses (R622 in Fig. 29, S633 in Fig. 28), and login is not permitted. In addition, the user authentication unit 32 invalidates the registered user name and password (R623 in FIG. 29, S634 in FIG. 28).
【0136】
As described above, according to the present embodiment, it is possible to manage the number of times the maintenance interface 30 of the client device 3 is used (the number of logins). Therefore, after the maintenance interface 30 of the client device 3 is opened once, it is possible to prevent the maintenance interface 30 from being frequently attacked, and it is possible to prevent the client device 3 from being congested.
【0137】
In the present embodiment, the server-side local maintenance console 2 instructed the client device 3 to set the number of logins together with the instruction to set the user authentication information, but the server-side local maintenance console 2 instructed the client. The instruction to set the user authentication information to the device 3 and the instruction to set the number of times that the client device 3 can be logged in from the server-side local maintenance console 2 may be made independent. Alternatively, the function for setting the number of times that the client device 3 can be logged in from the server-side local maintenance console 2 may be eliminated, and the fixed number of times that the login can be performed stored in advance in the login number management unit 39 may be used.
【0138】
Further, in the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may. Further, the user authentication information may be transferred from the server device 1 to the client device 3 without being encrypted, in which case the encryption unit 13 and the decryption unit 36 are omitted. Further, the remote maintenance console 5 that is logged in may not be forcibly disconnected when the user authentication information is reset. In that case, the forcible disconnection unit 37 is omitted. Further, the available time may not be managed, in which case the used time management unit 38 is omitted.
【0139】
[7th Embodiment of the invention]
Referring to FIG. 30, the client-server system according to the seventh embodiment of the present invention is used for each client device 3 in the client-server system according to the sixth embodiment shown in FIG. 25. The available time standard value 3A-1 and the number of possible login times The standard value 3A-2 is stored in advance, and the available time and the number of possible login times are not included in the user authentication information setting instruction from the remote maintenance console 5. Or, even if it is included, if it cannot be used due to poor reception, etc., the available time reference value 3A-1 and the loginable count reference value 3A-2 should be set in the usage time management unit 38 and the login count management unit 39. In that respect, it differs from the sixth embodiment, and other than that, it is the same as the sixth embodiment.
【0140】
FIG. 31 is a flowchart showing a processing example of the server device 1 when a user authentication information setting request is input from the server-side local maintenance console 2. The system administrator, etc., has the specified information of the client device 3 for which the user authentication information is set, the user name and password as the user authentication information to be set, the available time to be set, and the number of logins that can be set. Enter the user authentication information setting request for which is specified from the server-side local maintenance console 2. In the case of this embodiment, the available time and the number of times that can be logged in are specified arbitrarily, and are specified when the reference value 3A-1 for the available time and the standard value 3A-2 for the number of times of login of the client device 3 are used. No need. The above request from the server-side local maintenance console 2 is received by the request receiving unit 11 (S701), and thereafter, the same processing as in steps S602 to S611 of FIG. 26 is performed (S702 to S711).
【0141】
FIG. 32 is a flowchart showing a processing example of the client device 3 when a user authentication information setting instruction is transmitted from the server device 1 via LAN6, and steps S521, S522, S621, and S622 in FIG. 27 are steps. It differs from the flowchart of FIG. 27 in that it is replaced with S701 to S708. When the client device 3 to which the user authentication information setting instruction is transmitted via the LAN receives this instruction in the remote request processing unit 33 (S121), the decryption unit decrypts the encrypted user name and password in this instruction. Decrypt in 36 (S311 to S313), and check whether the user name and password, and if included, the available time and the number of times you can log in meet the specified number of digits (S122). If the available time is included and available (YES in S701), it is communicated to the usage time management unit 38 (S702), and if the available time is not included or it cannot be used due to poor reception. (NO in S701), the available time reference value 3A-1 is transmitted to the usage time management unit 38 (S703). The usage time management unit 38 stores this transmitted available time (S704). Further, if the number of logins is included in the instruction and is available (YES in S705), the remote request processing unit 33 transmits it to the login count management unit 39 (S706), and the number of logins is included. If it is not available or cannot be used due to poor reception (NO in S705), the login count reference value 3A-2 is transmitted to the login count management unit 39 (S707). The login count management unit 39 stores the transmitted number of logins possible (S708). After that, the same processing as in FIG. 27 is performed (S123, S401 to S405, S124, S125, S523).
【0142】
According to this embodiment, when the user authentication information is set from the server-side local maintenance console 2 to the client device 3 and the maintenance interface 30 is opened, the available time is not set from the server-side local maintenance console 2. However, the usage time can be managed by using the available time reference value 3A-1 of the client device 3, and the use of the maintenance interface 30 can be forcibly prohibited when the usable time reference value 3A-1 is exceeded. .. Therefore, even if the maintenance interface 30 of the client device 3 is opened without specifying the available time, it is possible to prevent the maintenance interface 30 from being continuously opened for a long time and increasing the risk of malicious access.
【0143】
Further, according to the present embodiment, when the user authentication information is set from the server-side local maintenance console 2 to the client device 3 and the maintenance interface 30 is opened, the number of times that the login is possible from the server-side local maintenance console 2 is not set. In addition, the number of logins can be managed using the reference value 3A-2 for the number of logins of the client device 3, and the use of the maintenance interface 30 is forcibly prohibited when the number of logins exceeds the reference value 3A-2 for the number of logins. can do. Therefore, even if the maintenance interface 30 of the client device 3 is opened without specifying the number of times that the login is possible, it is possible to prevent the maintenance interface 30 from being attacked many times.
【0144】
In the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may. Further, the user authentication information may be transferred from the server device 1 to the client device 3 without being encrypted, in which case the encryption unit 13 and the decryption unit 36 are omitted. Further, the remote maintenance console 5 that is logged in may not be forcibly disconnected when the user authentication information is reset. In that case, the forcible disconnection unit 37 is omitted.
【0145】
[Eighth Embodiment of the invention]
Referring to FIG. 33, the client-server system according to the eighth embodiment of the present invention is maintained on each client device 3 in the client-server system according to the seventh embodiment shown in FIG. Only for the first login after opening the interface 30, the usage time extension unit 3B that extends the remaining usage time in the usage time management unit 38 by a predetermined extension time is provided. Unlike the embodiment, the others are the same as those of the seventh embodiment.
【0146】
FIG. 34 (A) is a flowchart showing a processing example of the usage time extension unit 3B. The usage time extension unit 3B is activated at the same time as the usage time management unit 38, for example. The usage time management unit 38 first detects whether or not the remote maintenance console 5 has been logged in for the first time after the maintenance interface 30 is opened by setting the user authentication information in the user authentication unit 32 ( S801). This is possible, for example, by detecting whether or not the number of logins managed by the login count management unit 34 has become 1. When the first login from the remote maintenance console 5 is detected, the usage time extension unit 3B detects whether the remaining usage time managed by the usage time management unit 38 is less than or equal to the preset time ( S802). Then, if the remaining usage time is less than or equal to the preset time (YES in S802), the predetermined extension time is added to the remaining usage information managed by the usage time management unit 38 (S803). You may reset only the extension time as the remaining time without adding. On the other hand, if the remaining usage time at the time of the first login is not less than or equal to the preset time (NO in S802), the usage time extension process is no longer performed, so the process of FIG. 34 (A) is terminated.
【0147】
FIG. 35 is a sequence chart showing an operation example of the present embodiment, and shows a sequence of the following two scenes. (1) Setting user authentication information, available time, and number of logins from the server-side local maintenance console 2 to the client device 3 (2) First login to the client device 3 from the remote maintenance console 5 [0148]
Since the operation of the present embodiment in the sequence of (1) is the same as that of the sequence of FIG. 29, the operation of the scene (2) in which the maintenance worker logs in to the client device 3 for the first time from the remote maintenance console 5 is described below. , FIGS. 33 to 35 will be described.
【0149】
A while after the user name and password are set in the user authentication unit 32 of the client device 3, the available time is set in the usage time management unit 38, and the number of login times is set in the login count management unit 39. , When the maintenance worker inputs a login request specifying the user name and password to the client device 3 from the remote maintenance console 5 via LAN 6 (R801 in Fig. 35), the login count management unit 39 updates the login count (R801 in Fig. 35). R802) in Fig. 35, the number of logins = 1. If the user authentication process R803 is executed and the user name and password in the login request match the user name and password registered in the user authentication unit 32, login is permitted (R804 in FIG. 35). As a result, the remote maintenance console 5 can access the maintenance target unit 31 of the client device 3.
【0150】
Since it took a while for the remote maintenance console to log in after the user authentication information was set in the user authentication unit 32 and the maintenance interface 30 was opened, the remaining usage time was predetermined at the time of login. If it is less than the time (R805 in Fig. 35), it is detected by the usage time extension unit 3B (YES in S802 in Fig. 34 (A)), and it is predetermined to the remaining usage time of the usage time management unit 33. The extension time is added (R806 in Fig. 35, S803 in Fig. 34 (A)). After that, in the sequence shown in FIG. 35, the maintenance worker has completed the maintenance work, so the remote maintenance console 5 is logged out (R807 to R809).
【0151】
As described above, according to the present embodiment, after the maintenance interface 30 of the client device 3 is set and opened from the local maintenance console 2 on the server side, the first login from the remote maintenance console 5 is executed near the end of the usage time. If this happens, the usage time can be extended for a certain period of time for the purpose of performing sufficient maintenance work. Therefore, even if the first login is delayed for some reason, the maintenance work can be performed without any trouble. In the process shown in Fig. 34 (A), the extension of the usage time was permitted when the remaining usage time at the time of the first login was less than the predetermined time, but the remaining usage time at the time of the first login was more than the predetermined time. However, if the maintenance work takes a long time and the remaining usage time is insufficient, the usage time may be extended. FIG. 34 (B) is a flowchart showing a processing example of the usage time extension unit 3B in such an embodiment, and step S804 is added to the flowchart of FIG. 34 (A). When the usage time management unit 38 detects that the remote maintenance console 5 has been logged in for the first time since the maintenance interface 30 was opened by setting the user authentication information in the user authentication unit 32 (S801). , Whether the remaining usage time managed by the usage time management unit 38 is less than or equal to the preset time (S802), and whether the first login is ongoing (S803) are detected respectively. Whether or not the first login is ongoing can be detected by referring to the login status managed by the login / logout processing unit 35. Then, when it is detected that the remaining time of the usage time is less than or equal to the predetermined time during the first login (YES in S802), the remaining time information managed by the usage time management unit 38 is set in advance. Add the extended time given (S803). You may reset only the extension time as the remaining time without adding. On the other hand, when the first login is completed and the remote maintenance console 5 is logged out (NO in S804), the usage time extension process is no longer performed, so the figure
【0152】
In the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may. Further, the user authentication information may be transferred from the server device 1 to the client device 3 without being encrypted, in which case the encryption unit 13 and the decryption unit 36 are omitted. Further, the remote maintenance console 5 that is logged in may not be forcibly disconnected when the user authentication information is reset. In that case, the forcible disconnection unit 37 is omitted. Further, the number of logins that can be logged in may not be managed, in which case the login count management unit 39 is omitted. In this case, whether or not the login is the first time after the maintenance interface 30 is opened can be determined by, for example, managing the number of logins after the maintenance interface 30 is opened in the usage time extension unit 3B.
【0153】
[Ninth Embodiment of the invention]
Referring to FIG. 36, the client-server system according to the ninth embodiment of the present invention logs in to each client device 3 in the client-server system according to the eighth embodiment shown in FIG. 33. When the maintenance interface usage end notification is received from the remote maintenance console 5 inside, the user authentication information registered in the user authentication unit 32 is invalidated, and the notification to the effect that the user authentication information is invalidated is sent to the remote maintenance console. It differs from the eighth embodiment in that it includes the authentication invalidation unit 3C to be transmitted to 5, and is the same as the eighth embodiment in other respects.
【0154】
FIG. 37 is a sequence chart showing an operation example of the present embodiment, and shows a sequence of the following two scenes. (1) Setting user authentication information, available time, and number of logins from the server-side local maintenance console 2 to the client device 3 (2) Login to the client device 3 from the remote maintenance console 5 and notification of the end of use of the maintenance interface Sending [0155]
Since the operation of the present embodiment in the sequence of (1) is the same as that of the sequence of FIG. 29, in the following, the maintenance worker logs in to the client device 3 from the remote maintenance console 5 to perform the maintenance work, and the maintenance work is performed. The operation of the scene (2) in which the maintenance interface usage end notification is input from the remote maintenance console 5 at the end of is described with reference to FIGS. 36 and 37.
【0156】
After the user name and password are set in the user authentication unit 32 of the client device 3, the available time is set in the usage time management unit 38, and the number of login times is set in the login count management unit 39, the maintenance worker Enters a login request with a user name and password from the remote maintenance console 5 to client device 3 via LAN 6 (R901 in Fig. 37), and the login count management unit 39 updates the login count (R902 in Fig. 37). ), And if the user authentication process R903 is executed and the user name and password in the login request match the user name and password registered in the user authentication unit 32, login is permitted (R904 in FIG. 37). .. As a result, the remote maintenance console 5 can access the maintenance target unit 31 of the client device 3.
【0157】
When the maintenance worker finishes the maintenance of the maintenance target unit 31 of the client device 3 and inputs the maintenance interface usage end notification from the remote maintenance console 5 (R905), it invalidates the authentication through the login / logout processing unit 35 of the client device 3. It is transmitted to part 3C. The authentication invalidation unit 3C instructs the user authentication unit 32 to invalidate the user authentication information, and the user authentication unit 32 deletes the registered user authentication information accordingly. Disable (R906). After that, the authentication invalidation 3C sends a user authentication information invalidation notification to the remote maintenance console 5 (R907). After that, the maintenance interface 30 is blocked until it is opened again, and its use becomes impossible.
【0158】
As described above, according to the present embodiment, after setting the time and opening the maintenance interface 30 of the client device 3 from the server-side local maintenance console 2, log in from the remote maintenance console 5 to perform the maintenance work, and at the end of the maintenance work. By inputting the maintenance interface usage end notification from the remote maintenance console 5, it is possible to prohibit the use of the maintenance interface 30 of the client device 3 even before the usage time ends. By making it possible to invalidate the user authentication information when the maintenance work is completed in this way, it is possible to prevent the maintenance interface 30 from being continuously opened for a long time and increasing the risk of malicious access.
【0159】
In the present embodiment, as in the first embodiment, the client-side local maintenance console 4 shown in FIG. 1 is connected to each client device 3, and the local request processing unit 34 is provided in the client device 3. You may. Further, the user authentication information may be transferred from the server device 1 to the client device 3 without being encrypted, in which case the encryption unit 13 and the decryption unit 36 are omitted. Further, the remote maintenance console 5 that is logged in may not be forcibly disconnected when the user authentication information is reset. In that case, the forcible disconnection unit 37 is omitted. Further, the usage time may not be extended, in which case the usage time extension portion 3B is omitted. Further, the available time may not be managed, in which case the usage time management unit 38 and the usage time extension unit 3B are omitted. Further, the number of times that the login can be performed may not be managed, in which case the login number management unit 39 is omitted.
【0160】
Although the embodiments of the present invention have been described above, the present invention is not limited to the above embodiments, and various other additions and changes are possible. For example, the network connecting the server device 1 and the client device is not limited to the LAN, and may be another type of network such as the Internet or an intranet.
【0161】
The server device and the client device of the present invention can be realized not only by hardware but also by a computer, a server program, and a client program. The server program and client program are recorded and provided on a computer-readable recording medium such as a magnetic disk or semiconductor memory, and are read by the computer when the computer constituting the server device or the console constituting the client device is started up. By controlling the operation of the computer, the computer functions as a server device and a client device in each of the above-described embodiments.
【0162】
[Effect of the invention]
As described above, according to the present invention, the following effects can be obtained.
【0163】
In a client-server distributed system, the setting and invalidation of user authentication information for ensuring security for the maintenance interfaces of multiple client devices can be controlled remotely from the server-side console, achieving both security and ease of maintenance. It becomes possible to make it.
【0164】
Since the user authentication information transferred from the server device to the client device via the network is encrypted, stronger security can be realized.
【0165】
By introducing the time that these are valid after the user authentication information is set in the client device, that is, the available time of the maintenance interface, and automatically invalidating the user authentication information after the available time has elapsed. It is possible to prevent the maintenance interface from being left open for a long time and increasing the risk of malicious access. In particular, if the available time is specified by the server device, it will be used, and if it is not specified, the available time reference value stored on the client side will be used. The available time can be freely determined by selection, and even if the specification is forgotten, the maintenance interface will continue to be open for a long time, and the risk of malicious access can be prevented from increasing.
【0166】
By automatically extending the available time only for the first login, it is possible to ensure security and allow maintenance workers who are late to log in to perform maintenance work without any problems.
【0167】
When the number of logins since the maintenance interface is opened reaches the specified number of logins, access during login is stopped and user authentication information is invalidated, so a malicious person who frequently logs in and out repeatedly logs in and out. Frequent attacks can be prevented and security can be ensured.
【0168】
Since the user authentication information is automatically invalidated in conjunction with the maintenance interface usage end notification entered by the maintenance operator who has completed the maintenance work, the maintenance interface continues to be open for a long time, and there is a risk of malicious access. Can be prevented from increasing.
[Simple explanation of drawings]
FIG. 1 is a block diagram of a client-server system according to the first embodiment of the present invention.
FIG. 2 is a flowchart showing a processing example of a server device when a user authentication information setting request is input from a server-side local maintenance console according to the first embodiment of the present invention.
FIG. 3 is a flowchart showing a processing example of a server device when a user authentication information setting invalidation request is input from a server-side local maintenance console according to the first embodiment of the present invention.
FIG. 4 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is transmitted from a server device according to the first embodiment of the present invention via a LAN.
FIG. 5 is a flowchart showing a processing example of a client device when a user authentication information setting invalidation instruction is transmitted from a server device according to the first embodiment of the present invention via a LAN.
FIG. 6 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is input from a client-side local maintenance console according to the first embodiment of the present invention.
FIG. 7 is a flowchart showing a processing example of a client device when a user authentication information setting invalidation request is input from a client-side local maintenance console according to the first embodiment of the present invention.
FIG. 8 is a flowchart showing a processing example of a client device when a login request including a user name and password designation is transmitted from a remote maintenance console according to the first embodiment of the present invention via a LAN.
FIG. 9 is a flowchart showing a processing example of a client device when a logout request is transmitted via a LAN from a remote maintenance console during login according to the first embodiment of the present invention.
FIG. 10 is a sequence chart showing an operation example of the first embodiment of the present invention.
FIG. 11 is a sequence chart showing an operation example of the first embodiment of the present invention.
FIG. 12 is a block diagram of a client-server system according to a second embodiment of the present invention.
FIG. 13 is a block diagram of a client-server system according to a third embodiment of the present invention.
FIG. 14 is a flowchart showing a processing example of a server device when a user authentication information setting request is input from a server-side local maintenance console according to the third embodiment of the present invention.
FIG. 15 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is transmitted from a server device according to a third embodiment of the present invention via a LAN.
FIG. 16 is a sequence chart showing an operation example of the third embodiment of the present invention.
FIG. 17 is a block diagram of a client-server system according to a fourth embodiment of the present invention.
FIG. 18 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is transmitted from a server device according to a fourth embodiment of the present invention via a LAN.
FIG. 19 is a sequence chart showing an operation example of the fourth embodiment of the present invention.
FIG. 20 is a block diagram of a client-server system according to a fifth embodiment of the present invention.
FIG. 21 is a flowchart showing a processing example of a server device when a user authentication information setting request is input from a server-side local maintenance console according to a fifth embodiment of the present invention.
FIG. 22 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is transmitted from a server device according to a fifth embodiment of the present invention via a LAN.
FIG. 23 is a flowchart showing a processing example after the usage time management unit in the fifth embodiment of the present invention has started management of usage time.
FIG. 24 is a sequence chart showing an operation example of the fifth embodiment of the present invention.
FIG. 25 is a block diagram of a client-server system according to a sixth embodiment of the present invention.
FIG. 26 is a flowchart showing a processing example of a server device when a user authentication information setting request is input from a server-side local maintenance console according to a sixth embodiment of the present invention.
FIG. 27 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is transmitted from a server device according to a sixth embodiment of the present invention via a LAN.
FIG. 28 is a flowchart showing a processing example of a client device when a login request including a user name and password designation is transmitted from a remote maintenance console according to a sixth embodiment of the present invention via a LAN.
FIG. 29 is a sequence chart showing an operation example of the sixth embodiment of the present invention.
FIG. 30 is a block diagram of a client-server system according to a seventh embodiment of the present invention.
FIG. 31 is a flowchart showing a processing example of a server device when a user authentication information setting request is input from a server-side local maintenance console according to the seventh embodiment of the present invention.
FIG. 32 is a flowchart showing a processing example of a client device when a user authentication information setting instruction is transmitted from a server device according to a seventh embodiment of the present invention via a LAN.
FIG. 33 is a block diagram of a client-server system according to an eighth embodiment of the present invention.
FIG. 34 is a flowchart showing a processing example of a usage time extension portion in the eighth embodiment of the present invention.
FIG. 35 is a sequence chart showing an operation example of the eighth embodiment of the present invention.
FIG. 36 is a block diagram of a client-server system according to an eighth embodiment of the present invention.
FIG. 37 is a sequence chart showing an operation example of the ninth embodiment of the present invention.
[Explanation of symbols]
1 ... Server device 11 ... Request reception section 12 ... Request transfer section 13 ... Encryption section 2 ... Local maintenance console for server device 3 ... Client device 31 ... Maintenance target Part 32 ... User authentication part 33 ... Remote request processing part 34 ... Local request processing part 35 ... Login / logout processing part 36 ... Decryption part 37 ... Forced disconnection part 38. .. Usage time management unit 39 ... Login count management department 3A-1 ... Available time standard value 3A-2 ... Login possible number standard value 3B ... Usage time extension 3C ... Authentication invalid Cryptography 4 ... Local maintenance console for client devices 5 ... Remote maintenance console 6 ... LAN
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2019148976A | Cited by | Japan | Search report |
| WO2019167710A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2016024722A | Cited by | Japan | Search report |
| JP2016024722A | Cited by | Japan | Search report |
| JP2016024722A | Cited by | Japan | Examiner |
| JP2020149728A | Cited by | Japan | Search report |
| JP2018073052A | Cited by | Japan | Search report |
| JP2006259810A | Cited by | Japan | Search report |
| JP2008035235A | Cited by | Japan | Search report |
| US8166293B2 | Cited by | United States of America | Applicant |
| US7965846B2 | Cited by | United States of America | Applicant |
12 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2002356839 | Japan | A | |
| JP20020356839 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| GB0328543D0 | United Kingdom | D0 | |
| GB2396720A | United Kingdom | A | |
| AU2003266777A1 | Australia | A1 | |
| JP2004192134AThis record | Japan | A | |
| US2004153560A1 | United States of America | A1 | |
| CN1520098A | China | A | |
| GB2396720B | United Kingdom | B | |
| AU2003266777B2 | Australia | B2 | |
| AU2003266777B8 | Australia | B8 | |
| AU2003266777C1 | Australia | C1 | |
| JP4346898B2 | Japan | B2 | |
| CN100568811C | China | C |
18 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A712A711 | A711 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2004192134
- Publication, DOCDB
- 2004192134
- Publication, EPODOC
- JP2004192134
- Application
- 356839
- Application, DOCDB
- 2002356839
- Application, EPODOC
- JP20020356839
Titles2
- Japanese
- クライアント・サーバ型分散システムにおける保守インタフェース利用者認証方法および装置
- English
- Maintenance interface user authentication method and device in client-server distributed system
Classification
- CPC, 4
- H04L41/26
- H04L41/28
- H04L63/04
- H04L63/08
- IPC, 8
- G06F11 30
- G06F9 00
- G06F11 00
- G06F21 10
- G06F21 31
- H04L9 32
- H04L12 24
- H04L29 06