Access right management system and access right management method
Abstract
[Subject] The present invention prevents the data leakage through intentionally [of a user] or negligence with the right to access about the access right management system 100 which manages access to data and prevents disclosure of this data, and a right-to-access management method. [Solution means] Two or more users who hold the right to access to data are associated and registered into the user account database 41, In the active user database 44, this right-to-access possession user's inside, Register the user who agrees on access to this data, and now this access agreement part 31, Only when the number of the present of this right-to-access possession user that agrees registered into the active user database 44 is plurality, access to this data is agreed with the user who holds this right to access that has carried out the access request to this data. [Selection figure] Fig. 1
Term
Term ended
Projected expiry passed 31 March 2024, 2.5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
5 claims: 5 independent, 0 dependent
- 1A user account database that associates a plurality of users who have access rights to data, an active user database that indicates users who currently agree to access the data among the users who have access rights, and the active users. Only when the current number of the agreed access right-holding users shown in the database is plural, the user who has the access right who has requested access to the data is agreed to access the data. An access right management system characterized by being composed of an access agreement department. データに対してアクセス権を保有する複数のユーザを関連付けたユーザアカウントデータベースと、 該アクセス権保有ユーザの内、現在、該データに対するアクセスに合意しているユーザを示すアクティブユーザデータベースと、 該アクティブユーザデータベースに示された該合意しているアクセス権保有ユーザの現在数が複数であるときのみ、該データに対してアクセス要求して来た該アクセス権を保有するユーザに該データへのアクセスを合意するアクセス合意部と、 で構成されたことを特徴とするアクセス権管理システム。
- 2In claim 1, the system consists of a server and one or more clients, the server comprising the user account database, the active user database, and the access agreement, and each client has its own current location. It includes a location information detection unit to detect, an access request unit that transmits the detected current position and an access request received from the user to the access agreement unit, and the access agreement unit accesses the received current position. An access right management system characterized in that the number of users registered in the active user database in association with the right-holding user and located within a predetermined range is set as the current number of agreed users. 請求項1において、 該システムがサーバと1つ以上のクライアントで構成され、 該サーバが、該ユーザアカウントデータベース、該アクティブユーザデータベース、及び該アクセス合意部を備え、 各クライアントが、自分の現在位置を検出する位置情報検出部と、該検出した現在位置及び該ユーザから受け付けたアクセス要求を該アクセス合意部に送信するアクセス要求部とを備え、 該アクセス合意部が、受信した該現在位置を該アクセス権保有ユーザに対応付けて該アクティブユーザデータベースに登録し、所定の範囲内に位置するユーザ数を、該合意しているユーザの現在数とすることを特徴としたアクセス権管理システム。
- 3In claim 1, the system comprises a server and one or more clients, the server comprising the user account database, the active user database, and the access agreement, each client with another client. It is provided with a network construction unit that builds a network between the two, an identification information of the access right-holding user of the client that has constructed the network, and an access request unit that transmits an access request received from the user of the own client to the access agreement unit. An access right management system characterized in that the access agreement unit registers the access right-holding user of the identification information in the active user database as the access right-holding user who has agreed to access the data. 請求項1において、 該システムがサーバと1つ以上のクライアントで構成され、 該サーバが、該ユーザアカウントデータベース、該アクティブユーザデータベース、及び該アクセス合意部を備え、 各クライアントが、他のクライアントとの間でネットワークを構築するネットワーク構築部と、ネットワークを構築したクライアントの該アクセス権保有ユーザの識別情報、及び自クライアントのユーザから受け付けたアクセス要求を該アクセス合意部に送信するアクセス要求部とを備え、 該アクセス合意部が、該識別情報の該アクセス権保有ユーザを、該データに対するアクセスに合意している該アクセス権保有ユーザとして該アクティブユーザデータベースに登録することを特徴としたアクセス権管理システム。
- 4In claim 1, each client includes a network construction unit and an access request unit in addition to the user account database, the active user database, and the access agreement unit, and the network construction unit is associated with other clients. A network is constructed between the two, and the access agreement unit sets the access right-holding user of the client connected to the constructed network as the access right-holding user who has agreed to access the data, and the active user database. An access right management system characterized in that the access request unit gives an access request received from a user of the own client to the access agreement unit of a client holding the data. 請求項1において、 各クライアントが、該ユーザアカウントデータベース、該アクティブユーザデータベース、及び該アクセス合意部の他に、さらにネットワーク構築部及びアクセス要求部を備え、 該ネットワーク構築部が、他のクライアントとの間でネットワークを構築し、 該アクセス合意部は、該構築されたネットワークに接続されているクライアントのアクセス権保有ユーザを、該データに対するアクセスに合意している該アクセス権保有ユーザとして該アクティブユーザデータベースに登録し、 該アクセス要求部が、該データを保持するクライアントの該アクセス合意部に、自クライアントのユーザから受け付けたアクセス要求を与えることを特徴としたアクセス権管理システム。
- 5The first step of associating and registering a plurality of users who have access rights to the data, and the second step of registering the users who currently agree to access the data among the users who have the access rights. Only when the current number of the agreed access right-holding users is plural, the third step of agreeing the access to the data with the access right-holding user who has requested access to the data. An access right management method characterized by having ,. データに対してアクセス権を保有する複数のユーザを関連付けて登録する第1ステップと、 該アクセス権保有ユーザの内、現在、該データに対するアクセスに合意しているユーザを登録する第2ステップと、 該合意しているアクセス権保有ユーザの現在数が複数であるときのみ、該データに対してアクセス要求して来た該アクセス権を保有するユーザに該データへのアクセスを合意する第3ステップと、 を有することを特徴したアクセス権管理方法。
Independent claims5
183 paragraphs, as filed
The present invention relates to an access right management system and an access right management method, and more particularly to an access right management system and an access right management method for controlling access to data and preventing leakage of the data.
In recent years, with the advanced development of communication technology, a huge amount of confidential information such as industrial confidential information (design documents, etc.) and privacy information (list, etc.) has been transferred over the network, and leakage of this information has become a problem. ing. Not only information leakage by unauthorized users who do not originally have access authority, but also information leakage due to intentional or negligence by legitimate users who have access authority account for a large proportion of the causes of leakage of confidential information, and access rights are managed. Technology is becoming more and more important.
Specific examples of leakage of confidential information include taking out storage media such as CDs / FDs, taking out in electronic file format by e-mail, and viewing data on mobile terminals (notebook PCs / PDAs, etc.) in the public such as trains. And so on. According to these examples, it can be said that the main cause of information leakage is that confidential information can be freely accessed at the will of one user who has access rights.
In order to solve such a leakage problem, various authentication systems and systems that encrypt files and enable access only in a communication environment where an encryption key can be exchanged with a document management server have been developed and introduced.
FIG. 24 shows an example of a conventional confidential information leakage prevention system (access right management system), and this system is collectively referred to as a management server 70 and clients 10a_1 to 10a_3 (hereinafter, reference numeral 10a) connected by a network 60. ). The management server 70 includes a document management DB (database) 81, a key management DB 82, a user management DB 83, a user operation management DB 84, and management software for managing these databases. Each client 10a is equipped with user-specific operation control software.
Users 1 to 3 corresponding to each client 10a send, for example, an edit request 900 of document J to the management server 70 via the dedicated operation control software, and after being authenticated by the management software of the management server 70, edit permission. Download the encrypted document J and key K together with 901 from the management server 70. The client 10a decrypts the encrypted document J into the normal document J with the key K. Users 1 to 3 (each client 10a) can operate the document within the range of access rights set in the user management DB83 and the user operation management DB84. This document operation includes, for example, viewing 84a, saving 84b, editing 84c, printing 84d, copy and paste 84e, and screen capture 84f.
Since the client 10a cannot perform an operation on the decrypted document without going through the user operation control software dedicated to the system, the client 10a cannot perform an operation other than the permitted access right. For example, user 1 has access rights only for viewing and editing the document name J. The target document types (Word, Excel, Acrobat, ..., etc.) differ in width depending on the implementation layer of the user control software. Generally, a wider range of documents can be targeted by implementing it in a layer close to the kernel layer of the OS. There is also an implementation example in which a management server that manages user management, user operation management, and key management essential for this, and a content server that manages documents are configured as separate servers. (See, for example, Non-Patent Document 1.).
However, fraud is possible depending on the intention of one user who has access rights, especially if data access of the internal network from outside the company is permitted by technology such as VPN (Virtual Private Network) connection, data may be leaked to the outside. The sex increases and becomes a problem. On the other hand, if access from outside the company is not permitted, it becomes a problem that impairs convenience in the mobile society in recent years.
As a conventional system for solving this problem, there is an example in which a system makes it possible to manage a user's position by GPS or the like, and controls whether or not data can be read by using this position information. All of these are systems that increase resistance to leakage by permitting viewing only when the access permission position registered in the database matches the actual position.
In addition, when a user who manages the user's location information and the location information of the terminal and has a predetermined access right to the computer resource requests access, the location information of the user and the terminal that has made the access request There is an access right management system that permits an access request only when the location information has a predetermined relationship (see, for example, Patent Document 1).
However, in the end, these systems can be fraudulent depending on the intention of one user who has access rights, and the problem remains.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2001-175601</text></patcit><nplcit num="1"><text>ReEncryption: http://www.reencryption.com/frame_j2.html</text></nplcit>
<p> Further, as a conventional system for solving the above problem, there is an example in which a document is distributed and stored in a plurality of servers to improve security by paying attention to a vulnerability in centralized management of documents by a content server. However, since it is one administrator (user) who manages the server, fraud is possible depending on the intention of the administrator, so that the problem still remains.</p><p> Therefore, it is an object of the present invention to prevent data leakage due to intentional or negligence of a user who has an access right in an access right management system and an access right management method that manages access to data and prevents leakage of the data. ..</p>
<p> In order to solve the above problems, the access right management system of the present invention has a user account database in which a plurality of users who have access rights to data are associated with each other, and among the users who have access rights, the data is currently used. Only when there are a plurality of active user databases showing users who have agreed to access and the current number of users with the agreed access rights shown in the active user database, access is requested for the data. It is characterized in that it is composed of an access agreement unit that agrees to access the data to a user who has the access right.</p><p> FIG. 1 shows the principle of the access right management system 100 according to the present invention. The system 100 includes a user account database 41, an active user database 44, and an access agreement unit 31.</p><p> The user account database 41 is associated with a plurality of access right-holding users who have access rights to the data (for example, industrial confidential information such as design documents, privacy information such as lists, etc.). .. The active user database 44 shows, among the plurality of access right-holding users associated with the user account database 41, the access right-holding users who are currently agreeing to access the data. The agreement in this case is, for example, when the access right-holding user is in the same range.</p><p> The access agreement unit 31 informs the access right-holding user who has requested access to the data only when the current number of the agreed access right-holding users shown in the active user database 44 is plural. Agree to access the data.</p><p> This makes it possible to prevent data leakage due to intentional or negligence of one user with access rights, and to provide a data access environment (system) with enhanced resistance to data leakage compared to conventional systems. Becomes possible.</p><p> Further, in the above invention, in the above invention, the system is composed of a server and one or more clients, the server includes the user account database, the active user database, and the access agreement unit, and each client includes the user account database, the active user database, and the access agreement unit. The access agreement unit includes a position information detection unit that detects one's current position and an access request unit that transmits the detected current position and an access request received from the user to the access agreement unit. The current position can be registered in the active user database in association with the access right holding user, and the number of users located within a predetermined range can be set as the current number of agreed users.</p><p> In FIG. 1, the access right management system 100 is composed of a plurality of clients 10_1, 10_2 (hereinafter, may be collectively referred to by reference numeral 10) and a server 30. Each client 10 has a position information detection unit (not shown, for example, a position information receiving unit that receives position information from a position information transmitting device) that detects its own current position, and, for example, the detected current position or data. It is provided with an access request unit 11 that transmits an access request received from the user to the access agreement unit 31.</p><p> The server 30 includes a user account database 41, an active user database 44, and an access agreement unit 31. The access agreement unit 31 associates the current position received from each client 10 with the user and registers it in the active user database 44. Then, when the client (user with access right) 10 requests access to the data, the access agreement unit 31 refers to the active user database 44 and agrees on the number of users located within a predetermined range. It is the current number of users who have access rights, and access is agreed (permitted) only when this current number is more than one.</p><p> As a result, each access right-holding user can access the data by the agreement of each access right-holding user located within a predetermined range.</p><p> The client and the user do not necessarily have to have a one-to-one correspondence, and the same client may be used by a plurality of users.</p><p> In addition, the setting of "required number of people" is added, and instead of "access agreement only when there are more than one" above, the number of active users is regarded as an access agreement when the number of active users is more than the required number of people. Is also good.</p><p> Further, in the above invention, in the above invention, the system is composed of a server and one or more clients, the server includes the user account database, the active user database, and the access agreement unit, and each client includes the user account database and the access agreement unit. , The network construction unit that constructs a network with other clients, the identification information of the access right-holding user of the client that constructed the network, and the access request received from the user of the own client are transmitted to the access agreement unit. An access requesting unit is provided, and the access agreement unit can register the access right-holding user of the identification information in the active user database as the access right-holding user who has agreed to access the data.</p><p> That is, the access right management system 100 is composed of one or more clients 10 and a server 30. Each client 10 includes a network construction unit (not shown) and an access request unit 11. The network construction unit constructs a network (for example, an ad hoc network, not shown) with another client 10, and the access request unit 11 uses the identification information of the access right-holding user of the client 10 who has constructed the network and the user of the own client. The received access request for the data is sent to the access agreement unit 31.</p><p> The server 30 includes a user account database 41, an active user database 44, and an access agreement unit 31. The access agreement unit 31 registers the access right-holding user of the identification information received from each client 10 in the active user database 44 as the access right-holding user who has agreed to access the data.</p><p> Then, when the access agreement unit 31 receives an access request for data from the client 10, the access agreement unit 31 refers to the active user database 44 and accesses only when the current number of agreed access right holders is a plurality. Agree.</p><p> Thereby, for example, each access right-holding user can access the data by the agreement of each access right-holding user located within a predetermined range indicated by the connection of the ad hoc network.</p><p> In addition, instead of the ad hoc network, a network in which clients are connected by a wire of an appropriate length can be used.</p><p> Further, in the above invention, in the above invention, each client further includes a network construction unit and an access request unit in addition to the user account database, the active user database, and the access agreement unit, and the network construction unit , A network is constructed with other clients, and the access agreement unit has the access right possession that the access right holder user of the client connected to the constructed network has agreed to access the data. Registered in the active user database as a user, the access request unit can give an access request received from a user of the own client to the access agreement unit of the client holding the data.</p><p> That is, the access right management system is composed of only a plurality of clients. Each client has a network construction unit and an access request unit in addition to a user account database, an active user database, and an access agreement unit.</p><p> The network construction unit constructs, for example, an ad hoc network with other clients. The access agreement unit registers the access right-holding user of the client currently connected to the constructed network in the active user database as the access right-holding user who has agreed to access the data.</p><p> The access request unit makes an access request received from a user of its own client to the access agreement unit of the client that holds the data, and the access agreement unit that receives the access request refers to the active user database and agrees. Agree on access only when the current number of users with access rights is multiple.</p><p> By distributing the access agreement unit to each client in this way, it is possible to determine the agreement of a plurality of users and improve the resistance to data leakage without requiring a server.</p><p> Further, in the above invention, in the above invention, each client further has a database construction unit, and the database construction unit associates a plurality of users who have access rights to the data with the user account database. Can be registered or deleted.</p><p> That is, each client has a database construction unit distributed. This database construction unit can register or delete a plurality of users who have access rights to the data in association with the user account database.</p><p> This makes it possible to build a system without a server 30, prevent information leaks from privileged server administrators, and allow multiple users to monitor each other, increasing the resistance to leak protection of the system. It will be possible.</p><p> Further, in the present invention, the server may hold the data in the above invention.</p><p> Further, in the above invention, the present invention includes a data storage unit in which the client distributes and holds the data, and a data transmission unit and a data reception unit for transmitting and receiving the data to and from other clients. Can be further prepared.</p><p> That is, in addition to the above, the client further includes a data storage unit, a data transmission unit, and a data reception unit. For example, one document file (data) is distributed and stored in the data storage unit of each client. When access to the document file requested by one client is agreed, the data transmission unit of the other client transmits the divided document file stored in the data storage unit to the client requesting this document file. .. The data receiver of this client receives the data transmitted from other clients and forms one document file.</p><p> As a result, even if the security of individual clients is breached, all data is not leaked, so that it is possible to increase the resistance to leakage protection. The data transmission / reception may be, for example, a network connecting the server and the client, or an ad hoc network connecting the clients.</p><p> Further, in the above invention, the present invention may further include a database construction unit that registers or deletes a plurality of users who have access rights to the data in association with the user account database. As a result, a plurality of users who have access rights to the data can be registered or deleted in the user account database in association with each other.</p><p> Further, in order to solve the above problems, the access right management method according to the present invention includes the first step of associating and registering a plurality of users who have access rights to data, and among the users who have access rights. Only when the second step of registering the user who currently agrees to access the data and the current number of users who have the agreed access right are plural, the access request to the data is made. It is possible to have a third step of agreeing access to the data to the user who has the access right.</p>
<p> As described above, according to the access right management system according to the present invention, since the access permission is configured to require the agreement of a plurality of users, it is compared with the conventional system that determines the access permission for each user. As a result, resistance to data leakage is improved.</p><p> In addition, since the access right management system determines the agreement of multiple users based on the location information of multiple users, the ease of system operation and procedures when accessing data of each user is the same as that of the conventional system. , The resistance to data leakage is improved without the user's trouble when using the system.</p><p> In addition, the access right management system determines the access agreement of multiple users by configuring the network in close proximity to locations within the same range, so that the absolute position of each user cannot be obtained. Even in such a situation, the resistance to data leakage is improved.</p><p> In addition, since the access right management system distributes and holds data to each client, the bandwidth used by the network between the server and the client is saved, and the resistance to data leakage is improved. Furthermore, due to the distributed holding of data, even if the security of individual clients is breached, there is no leakage of all data, so the resistance to leakage protection is enhanced.</p><p> Further, since the client has the access agreement unit in a distributed manner, the agreement of a plurality of users can be determined without the need for a server, and the resistance to data leakage is improved.</p><p> Furthermore, the client can build a system without a server by holding the database construction unit in a distributed manner, preventing information leakage from privileged server administrators and cross-checking with multiple members, resulting in system leakage. It has the effect of increasing resistance to protection.</p>
<u style="single">Example (1): Access agreement based on location information</u> FIG. 2 shows a configuration example of the access right management system 100w according to the embodiment (1) of the present invention. The access right management system 100w is composed of a server 30 and clients 10_1 and 10_2 (hereinafter, may be collectively referred to by reference numeral 10), and these servers 30 and the client 10 are connected by a network 60. In addition to the access right management system 100w, the location information transmitting device 50 is shown in the figure. The server 30 includes an access agreement unit 31, a data transmission unit 32, a database construction unit 33, a database 40w, and a data storage unit 45w, and each client 10 has an access request unit 11, a data reception unit 12, and a location information reception unit. It has 13.
The position information receiving unit 13 among them detects the current position of the client 10 by communicating with the position information transmitting device 50. As the position information transmitting device 50, for example, there is a GPS (Global Positioning System), which measures the positional relationship between the client 10 and the satellite using information transmitted from the satellite, and determines the longitude of the current position of the client 10. It is a system that calculates longitude. Each client 10 can detect its own current position using the position information receiving unit 13. In the present embodiment (1), GPS is used as the current position detecting means, but the current position detecting means is not limited to GPS.
The database 40w of the server 30 is composed of a user account database 41w and an active user database 44w. The database 41w is composed of a group database 42w and a document file access right management database 43w.
In the embodiment (1), for example, the server 30 is connected to the network 60 via the company A's internal network 61 (see FIG. 1), and the user (employee) 1 and the user (employee) 2 (not shown). ) Indicates a case where the client 10_1 and 10_2 are used to access the confidential document file stored in the data storage unit 45w of the server 30 at the business trip destination, respectively. For such system operation, the group database 42w of the user account database 41w and the document file access right management database 43w that store the accounts of the user 1 and the user 2 are created in advance from the database construction unit 33 of the server 30.
Figures 3 (1) and 3 (2) show the group database 42w and the document file access right management database 43w that make up the user account database 41w (see Figure 2), respectively. The group database 42w shown in FIG. (1) is composed of a group identifier (hereinafter, may be abbreviated as ID) 42wa, a user identifier 42wb, and a password 42wc. In the database 42w, for example, it is registered that the user identifier 42wb = "user 1 to user 3" belongs to the group ID 42wa = "group A" and each password 42wc = "password P1 to password P3". ..
The document file access right management database 43w shown in Fig. (2) is composed of data 43wa, accessible location information 43wb, and group ID / user ID 43wc. In the database 43w, for example, the location information 43wb = prefecture town 1-1 or prefecture town 1-2 location group ID / user ID = user belonging to group A It is registered that only users 1 to 3 (see (1) in the figure) can access the data 43wa = document file 0.
Further, as described above, in addition to associating a user group (group ID) with a document file, it is also possible to associate only the user ID as a unit or as a unit with a group ID and a user ID.
Data registration / deletion to the databases 42w and 43w can be performed via the database construction unit 33, and may be manual registration from the administrator of the server 30, or each user (employee). It may be an automatic registration triggered by an account creation request from.
In this Example (1) and Examples (2) to (4) described later, only browsing is shown as access to the document file, but sentence saving, editing, printing, copy and paste, and screen are shown. Access such as capture is also possible.
FIG. 4 shows a configuration example of the active user database 44w shown in FIG. This database 44w consists of data 44wa, user ID 44wb, and user's current location 44wc. FIG. 4 (1) shows the database 44w when only user 1 has started client 10_1, and FIG. 4 (2) shows users 1 and 2 starting clients 10_1 and 10_2, respectively. The database 44w of the case is shown.
FIG. 5 shows an operation example of the access right management system 100w of the embodiment (1) shown in FIG. An example of this operation will be described below.
Users (employees) 1 and 2 (not shown) set the address of the server 30 in the client 10_1 and 10_2 (client 10_2 is not shown, see Fig. 2) in advance, respectively.
<u style="single">Step S200, S100</u>: Server 30 is running and user 1 launches client 10_1, for example, on a business trip. At this time, client 10_2 of user 2 is not started. The position information receiving unit 13 of the client 10_1 receives the position information 700_1,700_2, ... from the position information transmitting device, and notifies the access requesting unit 11 of the detected current position 701_1,701_2, ... of the client 10_1. To do.
<u style="single">Steps S101, S201</u>: Connection negotiation 710 is performed between client 10_1 and server 30, and connection 60a via network 60 is set between client 10_1 and server 30.
<u style="single">Steps S102, S103</u>: In client 10_1, user 1 inputs a start command to start the access request unit 11. The access request unit 11 is, for example, one application that runs on the OS, and has an input screen interface for the user 1 to input a user ID and a password. The access request unit 11 transmits the user ID 711a and the password 711b entered by the user 1 to the server 30.
<u style="single">Step S202</u>: On the server 30, the access agreement unit 31 refers to the database 42w to determine whether the password 711b is valid, and if it is valid, indicates "authentication OK712a", and if it is not valid, indicates "authentication NG712b". Send authentication result 712 to client 10_1.
<u style="single">Steps S104, S103</u>: In the client 10_1, when the user authentication result 712 indicates authentication NG, the access request unit 11 returns to the user ID and password input screen in step S103.
<u style="single">Steps S104, S105</u>: When the user authentication result 712 indicates "authentication OK", the access request unit 11 informs the server 30 constantly or periodically (for example, every 10 seconds or every several meters of the current position). After setting the position information receiving unit 13 to transmit the received user ID 713a and the position information (current position) 713b to the access agreement unit 31, the process proceeds to step S106.
<u style="single">Step S203</u>: In the server 30, the access agreement unit 31 registers the received user ID 713a and location information 713b in the active user database 44w 723.
That is, the access agreement unit 31 searches the user account database 44w based on the received user ID 713a and the location information 713b, and by this search, each document file associated with the user 1 is made accessible in the database. Determine if the position matches the current position. If they match, the access agreement unit 31 recognizes the document file 0 as the active user 1, and registers the user 1 in the active user database 44w. At this time, if the user ID has already been registered, the current position 44wc is overwritten.
In the case of a mismatch, the access agreement unit 31 recognizes the document file 0 as an inactive user, and for example, when the user 1 is registered in the active user database 44w, the user ID association data is deleted.
Here, the current location of user 1 = 1-1, prefecture town matches the location information 43wb of the document file access right management database 43w and the document file 0, while the document file 1 does not. .. As a result, the active user database 44w becomes the database shown in Fig. 6 (1). By updating the active user database 44w constantly or periodically in this way, the server 30 can grasp the current position of the client 10_1.
<u style="single">Step S106</u>: The access request unit 11 sends an access request 714 including the file name and the user ID to be received (viewed) to the server 30. That is, the access request unit 11 triggers the "OK notification" of the user authentication result 712 and the intention of the user 1 to view the document file 0, and the file name to be accessed = "document file 0" and the user ID = ". Send an access request 714 including "user 1" to the server 30. The method of triggering the viewing request and the specific method of the file name are not particularly limited. For example, if a dedicated data folder is prepared on the client 10_1 and the file name on the folder is clicked, the access request unit 11 files. First name = "Document file 0" and "User 1" may be notified to the server 30.
<u style="single">Steps S204, S205</u>: On the server 30, the access agreement unit 31 refers to the active user database 44w and acquires the user ID 44wb (that is, the active) associated with the file name = document file 0 and the current position 44wc. Determine whether or not two or more users (including user 1) who have the same current position as the user are registered on the database 44w.
If not registered, the access agreement unit 31 sends a judgment result (message) 715 indicating unagreement 715b to the client 10_1 in response to the access request, does not send the data file, and is sent from the client in step S203. Return to the reception waiting state of the current position. If registered, the access agreement unit 31 returns a determination result 715 indicating agreement 715a to the client 10_1, and further gives a transmission instruction 719 of document file 0 to the data transmission unit 32.
As shown in FIG. 4 (1), since only user 1 is currently registered in the database 44w, the access agreement unit 31 sends a judgment result 715 indicating unagreement 715b to the access request 714 to the client 10_1. And does not give a transmission instruction 719 to the data transmission unit 32.
<u style="single">Step S107</u>: In the client 10_1, the access request unit 11 receives the determination result 715 indicating unagreement, returns to step S106, and enters the input waiting state of the file name and the user ID.
After that, it is assumed that the user (employee) 2 activates the client 10_2 (both not shown) at the same business trip destination. The same operation as in steps S101 to S106 of client 10_1 and steps S201 to S203 of server 30 described above is performed between the client 10_2 and the server 30, and the user 2 is registered in the active user database 44w. FIG. 4 (2) shows the active user database 44w in which user 2 is further registered.
Subsequent operations between the client 10_2 and the server 30 will be described with reference to steps S106 to S110 shown in the client 10_1 and steps S204 to S208 of the server 30.
<u style="single">Step S106</u>: In client 10_2 (see client 10_1 in FIG. 5), the access request unit 11 sends an access request 714 including the file name = document file 0 and the user ID = user 2 to be received (viewed) to the server. Send to 30.
<u style="single">Steps S204, S205</u>: On the server 30, the access agreement unit 31 refers to the active user database 44w, acquires the user ID 44wb (that is, the active) associated with the file name = document file 0, and the current position 44wc, and obtains the user. It is determined whether or not two or more users (including user 2) having the same current position are registered on the database 44w.
As shown in Fig. 4 (2), unlike the case of client 10_1 shown in Fig. 4 (1), the database 44w is the user who has the access right to "Document file 0" and has the same current position as user 2. Since two users 1 (including user 2) are registered, the access agreement unit 31 responds to the access request 714 from the client 10_2 with a determination result 715 indicating "agreement 715a". Further, the access agreement unit 31 gives a transmission instruction 719 of document file 0 to the client 10_2 to the data transmission unit 32.
<u style="single">Step S107</u>: On the client 10_2, the access request unit 11 that has received the determination result 715 indicating agreement gives the data reception unit 12 the file reception preparation instruction 718.
<u style="single">Steps S206, S108</u>: In the server 30, the data transmission unit 32 transmits the data file (= document file 0) 716 stored in the document file database 46w of the data storage unit 45 to the data reception unit 12 of the client 10_2. The data receiving unit 12 receives the data file 716, and the user 2 of the client 10_2 can view the document file 0.
At this time, if the client 10_1 makes an access request 714 to the document file 0 to the server 30, the client 10_1 can access the document file 0 in the same manner as the client 10_2.
<u style="single">Steps S109, S110, S207, S208</u>: After clients 10_1 and 10_2 finish browsing "document file 0", each client 10 exchanges a negotiation 717 for disconnecting the connection 60a with the server 30, disconnects the connection 60a, and then disconnects the client 10 and Server 30 is stopped.
As described above, in the embodiment (1), when a user who has the access right to the document file 0 wants to access the document file 0, the same document file 0 is accessed at a position near the user. It is possible to allow access by regarding the existence of another user who has the right as an access agreement.
As a result, when multiple employees (users) go on a business trip, the document can be viewed by the same procedure as the existing authentication system, but when a certain user tries to take out illegal data, it cannot be viewed. Therefore, the protection resistance of data leakage can be enhanced.
In addition, if the setting of "required number of people" is added and, for example, "required number of people" = 5, it may be regarded as an access agreement when the number of active users is 5 or more.
Moreover, in Example (1), the position information was acquired by the absolute position (address in the example) by GPS. This GPS is suitable for outdoor use, but difficult for indoor use. Therefore, the embodiment (1) is suitable for use, for example, when a plurality of employees visit a customer, while traveling by transportation, or at the front door of the customer.
As an embodiment obtained by modifying this embodiment (1), the following embodiment may be used.
When the data type is data such as customer / resident ledger, in which the address and various information are associated with each customer / resident, the client (terminal) is lent to each customer in advance, and one employee When visiting a customer's house, the employee and the customer may enter the user ID and password into each client at the customer's house, which may be regarded as an agreement of a plurality of people based on the location information.
Further, the client (terminal) itself may be one, and each user may input a user ID and a password on the client.
Further, instead of GPS, the acquisition of location information may be the acquisition of location information in units of access points by a mobile phone or the acquisition of location information in units of access points by wireless LAN, which is beginning to spread. The acquisition of location information by mobile phone is rougher than GPS and the security is low, but instead, it can be used indoors such as in buildings as well as outdoors, and it can be applied flexibly. It is a form.
In addition, one client may support only one of the above as a location information acquisition unit, or has all of them according to the usage environment (outdoor / indoor, line speed). It may be used properly. Further, it is preferable for security that the connection between the client and the server is encrypted by a technology such as IPsec (Security Architecture for the Internet Protocol), but it is not essential.
Further, in each of the above databases and the database construction unit 33, for example, an access type (viewing, editing, printing, etc.) may be specified for each document file, and the access type may be controlled for each document / user.
Further, in order to improve security, the access request unit 11 waits for a while when the client 10 that receives the NG notification from the server 30 waits for a certain period of time until the next connection becomes possible or receives a fixed number of NG notifications. It is preferable that there is a mechanism that makes it impossible to connect.
Further, after sending the OK notification to the client 10_1, the access agreement unit 31 receives an access request by the user 2 from the client instead of the form in which the current position is periodically notified from the client 10 thereafter as described above. This may be a trigger to acquire the current position of another user and update the position information of the active user database to the latest information. In addition, instead of automatically determining agreement / non-agreement based on the number of users on the active user database, the access agreement unit 31 asks other users whether or not user 2 can access them, and grants permission to other users. Therefore, an agreement may be reached.
<u style="single">Example (2): Access agreement based on ad hoc network connection</u> In the above-described embodiment (1), the approval or disapproval of the agreement was determined based on the absolute position of each user. In the present embodiment (2), it is determined whether or not the users who are located in the close range have agreed to access the data depending on whether or not they have constructed a network (for example, an ad hoc network).
Therefore, (1) the radio wave from GPS / mobile phone / wireless LAN cannot be received, (2) the absolute position cannot be estimated based on the connection status with the mobile phone / wireless LAN, or (3) it can be estimated. However, in the present embodiment (2), there is an effect that each user can agree even in a situation where the absolute position of each user cannot be obtained due to reasons such as not being able to obtain sufficient granularity.
FIG. 6 shows a configuration example of the access right management system 100x according to the embodiment (2) of the present invention. The access right management system 100x is similar to the access right management system 100w shown in the embodiment (1), although the access right management system 100x is composed of a plurality of clients 10 and servers 30 connected by the network 60. , Unlike the first embodiment, the location information transmitting device 50 is not required, but the clients 10 are connected to each other by the ad hoc network 62.
The configuration of the server 30 is basically the same as that of the server 30 of the embodiment (1), but the database 40x is different. The configuration of the client 10 includes an ad hoc network construction unit 14 instead of the location information receiving unit 13 of the client 10 of the embodiment (1).
There is an ad hoc network as a general conventional technique in which a user (client) is close to a position within the same range to construct a network. An ad hoc network is a network that connects a large number of terminals to each other without the intervention of an access point while using technologies such as IEEE802.11x and Bluetooth, which are widely used for wireless connection of computers and the like. In an ad hoc network, a network can be configured with only mutual terminals in a place where there is no infrastructure such as a base station or an access point. Conversely, unless the terminals are close to each other at a distance according to the wireless technology used, the terminals cannot build a network. Although it is less convenient than an ad hoc network, terminals may be connected to each other in a timely and appropriate length by wire as a means for users to approach positions within the same range and construct a network.
FIG. 7 shows in more detail the configuration of the general ad hoc network construction unit 14 in the clients 10_1 and 10_2 shown in FIG. Each ad hoc network construction unit 14 has attributes of ARP (Address Resolution Protocol) tables 27_1 and 27_2 (hereinafter, may be collectively referred to by reference numeral 27) and a logical interface (hereinafter, may be abbreviated as logical IF). It has a table 28_1, 28_2 (hereinafter, may be collectively referred to by reference numeral 28) and a logical interface 14f_1, 14f_2 (hereinafter, may be collectively referred to by reference numeral 14f).
The technology of the ad hoc network construction unit 14 is a conventional ad hoc network technology, and tables 27 and 28 show table examples in the wireless LAN technology of IEEE802.11x. That is, the ARP table 27 is composed of the IP address 27a, the MAC address 27b, and the output logic IF27c as the client information in the ad hoc network 62. The attribute table 28 of the logical IF is composed of ESS-ID (Extended Service Set Identifier) 28b, channel number (frequency) 28c, and encryption key 28d, which are incidental information of the logical interface 14f, as information for each group of the ad hoc network. ing. The ESS-ID is an identifier in the wireless LAN defined by the IEEE802.11x series, and is used as an identifier of the ad hoc network in this embodiment (2).
On the ad hoc network 62, for example, client 10_1 refers to tables 27_1 and 28_1 when sending data to client 10_2, and the MAC address corresponding to the destination IP address = ip # 1 = MAC # 1. Etc. are acquired, the data is encoded using the wireless LAN technology of IEEE802.11, and then sent to the client 10_2. Client 10_2 decodes the received data based on tables 27_2 and 28_2. As a result, data communication is performed within the ad hoc network 62.
In the present embodiment (2), only when a plurality of clients 10 exist within the connectable range of the ad hoc network 62 and are connected, the access agreement unit 31 of the server 30 allows the client 10 to access the data. Agree to. The connection status of this client 10 is managed by the database 40x.
FIG. 8 shows the user account database 41x in the database 40x shown in FIG. Figures (1) and (2) show the group database 42x and the document file access right management database 43x in the database 41x, respectively. The database 42x is the same as the database 42w of the embodiment (1) shown in FIG. 3 (1), and the database 43x does not have the location information 43wb to be accessible, which is the database 43w shown in FIG. 3 (2). Is different.
FIG. 9 shows the active user database 44x shown in FIG. This database 44x is different from the active user database 44w of the embodiment (1) shown in FIG. 4, and is composed of a user ID 44xa and an ad hoc network connection user ID list 44xb. The ad hoc network connection user ID list is a list of identifiers of opposite users who can currently communicate with the user having the user ID 44xa via the ad hoc network 62.
In the database 44x of FIG. 9, for example, user 1 opposite user = user 2: 1 person, user 3 opposite user = user 4 and 5: 2 people (list by multiple people) and ad hoc to each other. You can see that you are building a network.
FIG. 10 shows an operation example of the access right management system 100x of the embodiment (2) shown in FIG. An example of this operation will be described below.
<u style="single">Steps S130, S131</u>: The server is running, client 10_1 is started by user 1 (not shown), and ad hoc network construction unit 14 sends ad hoc network connection request 730_1 to other clients 10_2. The mechanism by which ad hoc networks discover other clients depends on conventional ad hoc network technology. The ad hoc network construction unit 14 of the client 10_1 receives the ad hoc network connection request availability 731_1 from the other client 10_2. The ad hoc network construction unit 14 of the client 10_1 constructs an ad hoc network 62 with the client 10_2 when the ad hoc network connection request is possible or not 731_1 = Yes, and when it is No, the ad hoc network with the client 10_2 is established. Do not build 62.
The ad hoc network construction unit 14 continuously attempts to construct an ad hoc network by an event, a regular event, or an event that discovers a new other client.
<u style="single">Steps S131 ~ S134, S231, S232</u>: Negotiation 740 and user authentication of the connection between the server 30 and the client 10_1 are the same as in steps S101 to S104 and S201 and S202 of the embodiment (1).
<u style="single">Step S233</u>: In client 10_1, contrary to step S130, the ad hoc network construction unit 14 receives an ad hoc network connection request 730_2 including the user ID and password of client 10_2 from another client 10_2. Then, the ad hoc network construction unit 14 gives the ad hoc network connection user authentication request 743 including the received user ID and password to the access agreement unit 31 of the server 30.
The access agreement unit 31 refers to the group database 42x (see Fig. 8), and when the received ad hoc network connection user authentication request 743 is valid (authentication possible), the user ID of the active user database 44x = user 1. User ID = "User 2" is registered or updated in the ad hoc network connection user ID list 44xb, and is not updated when it is not valid (authentication rejected). Further, the access agreement unit 31 returns the ad hoc network connection user authentication result 744 addressed to the client 10_2, which is the source of the user authentication request 743, to the ad hoc network construction unit 14 of the client 10_1.
In client 10_1, when the received user authentication result 744 indicates that authentication is possible, the ad hoc network construction unit 14 returns ad hoc network connection request availability 731_2 indicating that authentication is possible to client 10_2, and ad hoc with client 10_2. Build network 62. When indicating authentication failure The ad hoc network construction unit 14 returns the ad hoc network connection request availability 731_2 indicating authentication failure to the client 10_2, and does not construct an ad hoc network with the client 10_2.
As described above, the client 10_1 queries the server 30 for the authentication of another client 10_2 (user 2), and when authenticated, builds an ad hoc network with this client 10_2. Then, the server 30 registers / updates the user 2 (client 10_1) whose ad hoc network is constructed by the client 10_1 (user 1) in the active user database 44x.
Note that user 2 is deleted from the active user database 44x when the ad hoc network between client 10_1 and client 10_2 is disconnected.
<u style="single">Steps S135, S234 ~ S235</u>: User 1 of client 10_1 wants to view document file 0 and sends an access request 745 including user ID = "user 1" and file name to be received = "document file 0" to server 30. In the server 30, the access agreement unit 31 refers to the document file access right management database 43x, acquires the group ID / user ID 43xb = group A associated with the document file 0, and further obtains the database 42x. Refer to it and get the user ID 42xb = "User 1, User 2, User 3" that expanded "Group A".
In addition, the access agreement unit 31 acquires the ad hoc network connection user ID list 44xb = user 2 corresponding to the user 1 requesting browsing from the active user database 44x, that is, interconnects with the user 1 in the ad hoc network. Get user 2 forming a connection. Then, since the access agreement unit 31 belongs to the group A in which the user 2 has the access right to the document file 0, the access agreement unit 31 agrees to access the document file 0 of the user 1 746a, and the agreement determination result indicating the agreement 746a. Reply 746 to client 10_1. If the interconnection connection is not formed, the access agreement unit 31 returns the agreement determination result 746 indicating the unagreement 746b to the client 10_1.
When the client 10_1 (= user 1) requests to view the document file 0, the data in FIGS. 8 and 9 show a more detailed method for determining whether or not an interconnection connection of the ad hoc network 62 is formed. It will be explained below based on the contents.
(1) Refer to the document file access right management database 43x and check whether the user ID associated with document file 0 includes the user ID that requested browsing. If not, it is determined that there is no interconnection connection of the ad hoc network. Here, group A = user 1 is included.
(2) Extract the user ID associated with document file 0. Here, users 1 to 3.
(3) Refer to the active user database 44x and extract the user ID from the ad hoc network connection user ID list 44xb of the user 1 who requested browsing. Here, user 2 is extracted.
(4) AND operation the user ID extracted in (2) and (3) above. Here, the calculation result is user 2.
(5) It is determined whether or not the ID of the user who requested browsing = User 1 exists in the ad hoc network connection user ID list 44xb of each user ID in (4) above. Here, since the user 1 is in the ad hoc network connection user ID list 44xb of the user 2, it is determined as "yes".
(6) In (5) above, if there is even one "Yes", it is determined that there is an interconnection connection of the ad hoc network. If there is no "Yes", it is determined that there is no interconnection connection of the ad hoc network. Here, there is an ad hoc network interconnect connection.
In (5) above, if there is even one "Yes", it is determined that "there is an interconnection connection of the ad hoc network". For example, in the document file access right management database 43x in Fig. 8 (2), If you add the "required number of connections" as an attribute of the document file and there are more than this "required number of connections" of ad hoc network interconnection connections, it is possible to determine that there are "interconnection connections". It is possible to realize an agreement by multiple users.
<u style="single">Steps S136, S137, S235, S236</u>: In the client 10_1, the access request unit 11 returns to step S135 when the agreement determination result 746 indicates unagreement, and when it indicates agreement, the access request unit 11 issues a data (document file 0) reception preparation instruction 749 to the data reception unit. Give to 12. On the other hand, in the server 30, when the access agreement unit 31 has an interconnection connection of the ad hoc network, the data transmission unit 32 is given a transmission instruction 750 of the document file 0, and there is no interconnection connection of the ad hoc network. , Do not give the transmission instruction of document file 0 to the data transmission unit 32.
Upon receiving the transmission instruction 750, the data transmission unit 32 transmits the document file 0 (data file 747) stored in the data storage unit 45 to the client 10_1. In the client 10_1 that requested browsing, the data receiving unit 12 receives the document file 0 (data file 747).
This allows user 1 to view document file 0 on client 10_1.
<u style="single">Steps S138, S237</u>: After the data transfer is completed, the connection disconnection negotiation 748 is performed between the server 30 and the client 10_1, and the connection 60a is disconnected.
Further, the ad hoc network construction unit 14 sends an ad hoc network disconnection request to another client 10_2 when it is no longer necessary to construct the ad hoc network 62. Upon receiving the ad hoc network disconnection request, the ad hoc network construction unit 14 sends an ad hoc network disconnection user authentication request including the user ID and password of the disconnection request source to the server 30 (not shown).
If the authentication is OK, the access agreement unit 31 of the server 30 that has received the ad hoc network disconnection user authentication request updates the active user database 44x and sends the ad hoc network connection user authentication result indicating the authentication OK to the client 10_2. At the time of authentication NG, the access agreement unit 31 sends the authentication NG to the client 10_2 without updating the active user database 44x (not shown).
Upon receiving the above ad hoc network connection user authentication result, the ad hoc network construction unit 14 of the client 10_2 disconnects the ad hoc network 62 from the other client 10_1 if the authentication is OK, and if the authentication is NG, the ad hoc network 62 Do not disconnect.
Further, the ad hoc network construction unit 14 sends an ad hoc network disconnection request of another client to the server 30 even when another client cannot be found as a conventional ad hoc network technology. At this time, the ad hoc network construction unit 14 of the client 10 cannot transmit the authentication information (password, etc.) of another client, but the communication is already impossible, for example, the distance between the clients is too large. Since the situation is such that the access agreement unit 31 of the server 30 updates the active user database 44x without the authentication of the other client 10 described above.
As described above, according to the access right management system 100x of the embodiment (2), a plurality of users are close to a position within the ad hoc network constructable range to form an ad hoc network, so that the user who holds the access right can use the access right. It is considered an agreement and allows access to the data. As a result, in addition to being able to increase the resistance to leakage protection similar to that in the first embodiment, the agreement of the users who have the access right is realized even in the situation where each user cannot acquire the absolute position. There is an effect that can be done.
<u style="single">Example (3): Data distribution retention by the client</u> In the above-described embodiment (2), the data is held only in the data storage unit 45 of the server 30, whereas in the present embodiment (3), the data encrypted by the plurality of clients 10 and the encryption of this data are performed. The key for encryption / decryption is distributed and held.
FIG. 11 shows a configuration example of the access right management system 100y according to the embodiment (3) of the present invention. The difference between the access right management system 100y and the access right management system 100x of the embodiment (2) shown in FIG. 6 is that the data storage unit 45 provided in the server 30 in the embodiment (2) is different from the embodiment (2). In 3), each client 10_1 and 10_2 are distributed as data storage units 25_1 and 25_2 (hereinafter, may be abbreviated by reference numeral 25). Further, the access right management system 100y differs from the access right management system 100x of the embodiment (2) in that the data transmission unit 32 of the server 30 and the data reception of the client 10 for transmitting data from the server 30 to the client 10. Instead of the unit 12, a data transmission unit 15 and a data reception unit 16 for transmitting and receiving data stored in the distributed data storage unit 25 between the clients 10 are added to the client 10.
FIG. 12 shows the user account database 41y provided by the server 30. Figures (1) and (2) show the group database 42y and the document file access right management database 43y in the user account database 41y, respectively.
The group database 42y and the document file access right management database 43y are the same as the group database 42x and the document file access right management database 43x shown in the embodiment (2) of FIG. 8. FIG. 13 shows the active user database 44y. Ori. This database 44y is similar to the active user database 44x shown in Example (2) of FIG.
Note that FIGS. 12 and 13 include data of user 3, user 4, and user 5 (client 10_3, client 10_4, and client 10_5) not shown in FIG.
14 (1) and 14 (2) show the document file databases 26y_1 and 26y_2 (hereinafter, may be collectively referred to by reference numeral 26y) held by the data storage unit 25 of the clients 10_1 and 10_2, respectively. 26y is composed of a data name 26ya, a data content 26yb, and a key 26yc. That is, the database 26y holds the data content 26yb = "encrypted divided document file nm" and the divided key 26yc = "divided key nm" with the data name 26ya = document file n as the primary key. The encrypted divided document file nm means the divided portion m obtained by encrypting and dividing the document file n. The division key nm means a division portion m obtained by dividing the key n of the document file n.
For example, the document file 0 is divided and stored as encrypted divided document files 0-0 and 0-1 in the data contents 26yb of the databases 26y_1 and 26y_2, respectively. In addition, since each encrypted split document file 0-0, 0-1 is encrypted / decrypted (decrypted), the split keys 0-0, 0-1 which are a part of the key 0 are stored in the databases 26y_1 and 26y_2, respectively. It is stored in the key 26yc of.
The encrypted divided document files 0-0,0-1 are combined to form the encrypted document file 0, and the divided keys 0-0,0-1 are combined to form the key 0. Then, by decrypting the encrypted document file 0 with the key 0, the document file 0 that can be viewed can be obtained.
FIG. 15 shows an operation example of the access right management system 100y in the embodiment (3). An example of this operation will be described below.
<u style="single">Steps S150 ~ S154, S250 ~ S252</u>: Same as steps S130 to S134 and S230 to S232 in Example (2). Negotiate a connection between server 30 and client 10_1 and authenticate the user.
<u style="single">Steps S155, S253 ~ S255</u>: Same as steps S135, S136, S234 to S236 of Example (2). The ad hoc network connection user ID is registered in the active user database 44y, and an access (view) request 775 including the user ID and file name and a judgment result 776 indicating agreement / non-agreement are sent and received between the client 10_1 and the server 30. To.
The determination procedure of step S255, that is, the determination procedure of whether or not an interconnection connection of an ad hoc network is formed is different from the determination operation of step S235 of the embodiment (2).
When the data contents of the databases 41y (42y, 43y), 44y, 25y are shown in FIGS. 12, 13 and 14, respectively, the client 10_1 (= user 1) accesses (views) the file name = document file 0. The judgment procedure in the embodiment (3) when the request 775 is made will be described below.
(1) In the document file access right management database 43y, check whether the group ID / user ID 43yb corresponding to the data 43ya = access-requested document file 0 has the access-requested user ID = user 1. To do. Here, there is user 1. If there is no user 1, it is determined that user 1 does not have access to the document file 0.
(2) Extract the user ID excluding the user ID = "user 1" who requested access from the group ID / user ID 43yb corresponding to the data 43ya = "document file 0" of the database 43y. Here, user 2 is extracted.
(3) In the active user database 44y, all the users extracted in (2) above are included in the user IDs registered in the ad hoc network connection user ID list 44yb corresponding to user ID 44ya = "user 1 who requested access". Check if it is. Here, user 2 is included. If it is not included, it is determined that there is no interconnection connection of the ad hoc network.
(4) For all the user IDs in (2) above, it is determined whether or not the ID of the user who made the access request = "User 1" exists in the ad hoc network connection user ID list 44yb. Here, since the user 1 is in the ad hoc network connection user ID list 44yb of the user 2, it is determined as "yes".
(5) In the above (4), if "Yes", it is determined that there is an interconnection connection of the ad hoc network. Here, there is an ad hoc network interconnect connection.
The judgment in step S255 shown in the above steps (1) to (5) is different from the judgment in step S235 in the embodiment (2) when a certain user requests access to a certain document file. Only when an ad hoc network has been constructed with all users who have access rights to the requested document file, it is determined that "there is an interconnection connection of the ad hoc network".
The reason for making such a determination is that in the present embodiment (3), the document file is distributed and held among all users (clients) who have access rights to the document file.
For example, when the number of users who have access rights to document file 0 is large and the operational convenience is reduced, not all users but users who combine two or more specific users. When constructing an ad hoc network, it may be determined that there is an interconnection connection of the ad hoc network. In this case, the document file database 26y (see FIG. 14) of each client 10 may hold the encrypted divided document file and the divided key for each document file according to the combination pattern of the users.
<u style="single">Step S156</u>: In the client 10_1, when the access request unit 11 receives the determination result 776 indicating "agreement", the access request unit 11 gives a reception preparation instruction 779 to the data reception unit 12.
<u style="single">Steps S157, S255</u>: In the access agreement unit 31, when the determination result 776 is "agreement (there is an interconnection connection of the ad hoc network)", the server 30 sends the document file 0 transmission instruction 777_1 and 777_2 to the clients 10_1 and 10_2, respectively. Hereinafter, it may be generically referred to by reference numeral 777.). This transmission instruction 777 includes the user ID = user 1 and the file name = document file 0 of the client 10_1 that is the browsing request source.
The data transmission unit 15 of each client 10 that receives the transmission instruction 777 reads the encrypted divided document file and the division key corresponding to the document file 0 from the document file databases 26y_1 and 26y_2 of the data storage units 25_1 and 25_2, respectively, and reads the encrypted divided document file and the divided key corresponding to the document file 0. If the user is the access request source, the encrypted divided document file 762a_1 and the division key 762b_1 are transmitted to the own data receiving unit 12, and if the user is not the access request source, the access specified by the transmission instruction 777 is sent. The encrypted divided document file 762a_2 and the divided key 762b_2 are transmitted to the data receiving unit 12 of the requesting client 10_1.
<u style="single">Step S158</u>: In the client 10_1, the data receiving unit 16 receives all the encrypted divided document files of the document file 0 and all the divided keys. Then, the data receiving unit 16 combines the encrypted divided document file and the divided key, respectively, to form the encrypted document file 0 and the key 0, and decrypts the encrypted document file 0 with the key 0, respectively. Create a viewable document file 0. As a result, user 1 of client 10_1 can view the document file 0.
<u style="single">Steps S159, S160, S255, S256</u>: The procedure for disconnecting the connection 60a between the client 10_1 and the server 30 is the same as the procedure for disconnecting negotiation 748 shown in steps S138, S139, S237, and S238 of the second embodiment.
In this way, the client 10 distributes and holds the data (document file), so that the resistance to the same leakage protection as in the embodiment (1) can be enhanced. In addition, it becomes possible to save the bandwidth used by the network 60 between the server 30 and the client 10. That is, it is possible to send and receive a large amount of document file data between clients 10 without using the network 60 between the client 10 and the server 30, which has a narrower bandwidth than the ad hoc network 62 or has a pay-as-you-go charge. become. As a result, the bandwidth used by the network 60 between the server 30 and the client 10 can be saved.
Furthermore, even if the security of each client 10 is breached, it is possible to increase the resistance to leakage protection that complete data (document file) is not leaked.
In the above-described embodiment (3), the document file and the key are distributed and held, but it is also possible to hold only the key in a distributed manner. If only the key is distributed and held, if the security of one client is breached, there is a risk that a complete file will be leaked, but the bandwidth used by the ad hoc network 62 can be saved.
<u style="single">Example (4): Each client keeps the access agreement part distributed</u> In this embodiment (4), the functions of the access agreement unit 31 of the server 30 in the embodiment (3) are distributed to each client 10 as the access agreement unit 18. As a result, the server 30 is not required in the embodiment (4).
FIG. 16 shows a configuration example of the access right management system 100z according to the embodiment (4) of the present invention. This access right management system 100z is composed of a plurality of clients, for example, clients 10_1 to 10_3. The configuration of each client 10 is different from that of the client 10 shown in the embodiment (3). Instead of the access request unit 11 that requests access to the server 30, the access request unit 17 that requests mutual access between the clients 10 is used. To be prepared. Further, in the embodiment (3), the access agreement unit 31, the database construction unit 33, and the database 40y held by the server 30 are replaced by each client 10 with the access agreement unit 18, the database construction unit 19, and the database 20z (code). It is also different in that it is provided as a general term for 20z_1 and 20z_1).
In this embodiment (4), [1] an example related to "agreement of access rights to documents" and [2] an example related to "access right management when the database construction unit is distributed" will be described separately.
<u style="single">[1] Agreement on access to documents</u> FIG. 17 shows the user account database 21z that constitutes the database 20z. This database 21z consists of a group database 22z and a document file access right management database 23z.
Figure (1) shows the group databases 22z_1 and 22z_2 held by clients 10_1 and 10_2. The group databases 22z_1 and 22z_2 are the same database and are composed of a group ID 22za, a user ID 22zb, and a password 22zc.
Figures (2) and (3) show the document file access right management databases 23z_1 and 23z_2 of clients 10_1 and 10_2 (hereinafter, may be collectively referred to by reference numeral 23z), and the data 23za and the group ID, respectively. / Consists of user ID 23zb. Database 23z is a database of document files that each client 10 has access to. For example, in the database 23z_1 of FIG. (2), the client 10_1 holds the user ID including itself who has access rights to the document file 0 and the document file 1, and in the database 23z_2 of the figure (3), the client 10_2 holds the user ID having the access right to the document file 0.
Figures 18 (1) and 18 (2) show the active user databases 24z_1 and 24z_2 held by clients 10_1 and 10_2, respectively. The databases 24z_1 and 24z_2 hold a list of ad hoc network connection user IDs in which clients 10_1 and 10_2 form an ad hoc network, respectively.
19 (1) and (2) show the document file databases 26z_1 and 26z_2 (hereinafter, may be collectively referred to by reference numeral 26z) held by the clients 10_1 and 10_2, respectively. The document file database 26z is the same as the document file database 26y of the embodiment (3) shown in FIG. 14, and is composed of a data name 26za, a data content 26zb, and a key 26zc.
FIG. 20 shows the operation procedure in the embodiment (4). This operation procedure will be described below. In this description, the case where only two clients 10_1 and 10_2 are provided will be described, but the operation procedure when there are three or more clients is also the same.
<u style="single">Steps S170, S270</u>: Clients 10_1 and 10_2 are started respectively.
<u style="single">Steps S171, S172, S271, S272</u>: The ad hoc network construction unit 14 of the clients 10_1 and 10_2 continuously constructs the ad hoc network 62 with other clients, respectively. That is, in the client 10_1, the ad hoc network construction unit 14 transmits the ad hoc network connection request 790 to the client 10_2. Upon receiving the ad hoc network connection request 790 on the client 10_2, the ad hoc network construction unit 14 gives the user authentication request 791 for the ad hoc network connection to the access agreement unit 18. The access agreement unit 18 refers to the user account database 21z_1 811 and authenticates in the same manner as in the third embodiment, and returns the user authentication result 792 of the ad hoc network connection to the ad hoc network construction unit 14. Further, if the authentication is OK, the access agreement unit 18 registers the client 10_1 (= user 1) in the active user database 24z_2 813.
Upon receiving the user authentication result 792, the ad hoc network construction unit 14 sends an ad hoc network connection request response 793 to the ad hoc network construction unit 14 of the client 10_1. This response 793 contains client 10_2 credentials (user 2 and password P2).
Upon receiving the response 793 in the client 10_1, the ad hoc network construction unit 14 sends a user authentication request 794 including the authentication information (user 2 and password P2) included in the response 793 to the access agreement unit 18. The access agreement unit 18 refers to the user account database 21z_1 802, authenticates, and gives the user authentication result 795 to the ad hoc network construction unit 14. Further, if the authentication is OK, the access agreement unit 18 registers the client 10_2 (= user 2) in the active user database 24z_1 803.
By performing this series of operations of ad hoc network construction, user 2 and user 1 are registered / updated in the user ID list as shown in the active user databases 24z_1 and 24z_2 in FIGS. 18 (1) and 18 (2).
<u style="single">Steps S173, S273, S274</u>: In the client 10_1, the access request unit 17 refers to the document file access right management database 23z_1 of the user account database 21z_1 802, and extracts all user IDs other than itself who have the access right to the document file 0. Here, user 2 is extracted. Further, the access request unit 17 refers to the active user database 24z_1 804, and confirms that the extracted user ID = user 2 is in the ad hoc network connection user ID list (active user database 24z_1 (see FIG. 18 (1))). Confirm. Here, user 2 is in the ad hoc network connection user ID list. Access request unit 17 sends an access (view) request 796 to all clients other than itself who have access to document file 0. , The access request unit 17 sends the access request 796 of the document file 0 to the client 10_2.
Upon receiving the access request 796 on the client 10_2, the access agreement unit 18 refers to the active user database 24z_2 to see whether or not an ad hoc network interconnection connection is formed with the client 10_1 (user 1) 814. to decide. If so, the access agreement unit 18 returns the determination result 797 indicating agreement 797a to the client 10_1 that sent the access request 796, and sends the data transmission instruction 807 to the data transmission unit 15. give. If it is not formed, the judgment result 797 indicating "unagreement 797b" is returned.
Here, a more detailed determination operation of "whether or not an interconnection connection of the ad hoc network 62 is formed" in step S274 will be described below.
(1) Refer to the document file access right management database 23z_2, and check whether the user ID associated with the document file 0 includes the user ID = user 1 who requested the access. If not, check it. , Judge that there is no access right. Here, since there is user 1, it is determined that there is an access right.
(2) Refer to the active user database 24z_2 and check whether there is user ID = user 1 who requested access to the ad hoc connection user ID list. If not, it is determined that there is no interconnection connection of the ad hoc network. Here, since there is user 1, it is determined as "yes".
(3) In the above (2), if it is determined that there is an ad hoc network interconnection connection, it is determined that there is an ad hoc network interconnection connection. Here, there is an ad hoc network interconnect connection.
<u style="single">Step S174</u>: In client 10_1, when the access request unit 17 receives the agreement judgment result 797 indicating "agreement" from all the clients that sent the access request 796 (here, only the client 10_2), the access request unit 17 goes to the data transmission unit 15. , The data transmission instruction 805a instructing the transmission of the encrypted divided document file 0-0 and the division key 0-0 is given, and the reception preparation instruction 805b is given to the data receiving unit 16.
<u style="single">Steps S175, S176, S275</u>: In the client 10_2, the access agreement unit 18 gives the data transmission unit 15 the transmission instruction 807 of the encrypted divided document file 0-1 and the divided key 0-1 held in the document file database 26z_2. The data transmission unit 15 transmits the encrypted divided document file 798a including the document file 0-1 and the divided key 0-1 and the divided key 798b to the client 10_1, respectively.
The client 10_2 receives the encrypted split document file 0-1 and the split key 0-1 from the data transmission unit 15. The data transmission unit 15 of the client 10_1 includes the encrypted split document file 0-0 and the split key 0-0 held by the document file database 26z_1 in the encrypted split document file 806a and the split key 806b, respectively, for data. Give to the receiver 16. The data receiving unit 16 combines the received encrypted divided document file 0-0,0-1 and the divided key 0-0,0-1 to form the encrypted document file 0 and the key 0, and forms the encrypted document 0. Create document file 0 by decrypting file 0 with key 0.
As a result, user 1 of client 10_1 can view the document file 0.
<u style="single">Steps S177, S276</u>: Clients 10_1 and 10_2 are stopped, respectively.
According to the operation procedure described above, a plurality of clients 10 can have the access agreement unit in a distributed manner. As a result, the document file can be accessed in the absence of the server 30 while enjoying the same effect as in the third embodiment.
<u style="single">[2] Access right decentralized management</u> The operation procedure when the access right is distributed will be described below. In this description, for example, the case where the clients 10_1 and 10_2 hold the document file 0 distributedly will be described.
First, client 10_1 (= user 1), client 10_2 (= user 2), and client 10_3 (= user 3) construct an ad hoc network 62. Then, when the client 10_3 requests the access right to the document file 0 that does not have the access right, in each client 10_1 to 10_3, the access right management function of the database construction unit 19_1 to 19_3 sets the document file 0 to the client 10_1. Distribute to ~ 10_3.
FIG. 21 shows Example (4): User account database 21z in distributed access right management. This database 21z is composed of the group database 22z shown in Fig. (1) and the document file access right management database 23z shown in Fig. (2) to (4), which are different for each client.
The group database 22z in FIG. 1 (1) is common to all clients 10_1 to 10_3, and is the same as the group database 22z in Example (4). The document file access right management databases 23z_1 to 23z_3 (hereinafter, may be collectively referred to by reference numeral 23z) in FIGS. (2) to (4) are databases held by clients 10_1 to 10_3, respectively. This is the same as the database 23z of Example (3) shown in 17 (2) and (3). Database 23z_3 of client 10_3 in FIG. 21 (4) shows that client 10_3 is currently managing document file 1.
Note that (2a) to (4a) in the databases 23z of (2) to (4) in the same figure indicate the databases 23z_1 to 23z_3 before the update, and (2b) to (4b) are the databases 23z_1 ~ after the update. It shows 23z_3.
FIGS. 22 (1) to 22 (3) show document file databases 26z_1 to 26z_3 (hereinafter, may be collectively referred to by reference numeral 26z) held by each client 10_1 to 10_3. The databases 26z_1 and 26z_2 are similar to the document file databases 26z_1 and 26z_2 shown in FIG. The database 26z_3 of client 10_3 shows that client 10_3 manages the encrypted split document file 1-2 in the document file 1 and the split key 1-2 of key 0.
Note that (1a) to (3a) in FIGS. 22 (1) to (3) indicate the database 26z_1 to 26z_3 before the update, and (1b) to (3b) indicate the database 26z_1 to 26z_3 after the update. There is.
FIG. 23 shows an operation procedure in Example (4): Access right decentralized management. This operation procedure will be described below. The access right decentralized management function is provided by the ad hoc network construction units 14_1 to 14 of each client.
<u style="single">Steps S10, S20, S30</u>: In clients 10_1 to 10_3, the ad hoc network construction unit 14_1 to 14 constructs the ad hoc network 62. The database construction unit 19_1 of client 10_3 broadcasts the document search 820,821 to all clients 10_1,10_2 other than itself that make up the ad hoc network 62. That is, since client 10_3 does not know the existence of the document file requesting the access right, it is necessary to search the document for the existing document file. The search condition may include a keyword for search.
<u style="single">Steps S11, S21</u>: In the client 10_1, the database construction unit 19 that has received the document search 820 authenticates the document search message by referring to the user account database 21z_1 822a. If the authentication is OK, the database construction unit 19_1 refers to the user account database 21z_1 822b and has all the document names (or the document names that match the search conditions if there are search conditions) and the access right for this document. The user ID to be used is returned to client 10_3. Similarly, the client 10_2 also returns the document name and the user ID having the access right to the client 10_3.
<u style="single">Step S31</u>: In the client 10_3, the database construction unit 19_3 authenticates the search result message returned from the clients 10_1 and 10_2 by referring to the user account database 21z_3 826, and extracts the ones whose authentication is OK. Here, it is assumed that all the messages have been authenticated.
<u style="single">Step S32 (Determine access permission request document file)</u>: Furthermore, the database construction unit 19_3 determines the document file for which access rights are requested. This decision is made manually, for example, by user 3, and here document file 0 is determined. Then, the database construction unit 19_3 transmits access right permission requests 827_1 and 827_2 to all the clients 10_1 (= user 1) and clients 10_2 (= user 2) who have the access right of the document file 0, respectively.
<u style="single">Steps S12, S21</u>: The database construction unit 19_1 that received the access right permission request 827_1 in the client 10_1 determines whether or not the access right permission is permitted, and sends the access right permission request result 830 to the client 10_3. When the access right permission is "OK", the database construction unit 19_1 outputs the encrypted divided document file 829a and the divided key 829b including the encrypted divided document file 0-0 and the divided key 0-0 from the document file database 26z_1, respectively. Read and include this encrypted split document file 829a and split key 829b in the permission permission request result 830. For example, the above-mentioned pass / fail judgment may be made manually by the user 1, or instead of being made manually by the user 1, a condition may be given to the agent in advance so that the agent can make an automatic judgment. Furthermore, it may be automatically enabled by constructing the ad hoc network 62. Here, it is assumed that it is "OK".
In the same operation procedure for the client 10_2, the database construction unit 19_2 returns the access right permission request result (OK, encrypted split document file 0-1 and split key 0-1) 832 to the client 10_3.
<u style="single">Step S33</u>: In client 10_3, the database construction unit 19_3 receives all the encrypted divided document files of the document file 0 and all the divided keys of the key 0, and performs the subdivision process of the document file 0. If the received access right permission result is not valid, the database construction unit 19_3 does not perform the subsequent processing, and the client 10_3 cannot obtain the access right.
Here, the document file subdivision process is a user who once again combines the encrypted divided document files, decrypts them, obtains a complete document file 0, and then becomes a new access right-holding user again. This is a process of subdividing into three users 1 to 3 (clients 10_1 to 10_3) including 3 (client 10_1). The database construction unit 19_3 of the client 10_3 updates the user account database 21z_3 and the document file database 26z_3 based on the new division information 833 and 834, respectively. Further, the database construction unit 19_3 transmits the new division information 835 and 836 to the clients 10_1 and 10_2, respectively.
In the clients 10_1 and 10_2, the database construction units 19_1 and 19_2 update the user account databases 21z_1 and 21z_23 and the document file databases 26z_1 and 26z_2, respectively, based on the received new division information 835 and 836, 837 to 840.
As a result, in each client 10, the user account database 21z_1 to 21z_3 and the document file database 26z_1 to 26z_3 are shown in FIGS. 21 (2) to (4) and 22 (1b) to (3b) based on the new division information. Will be updated as. That is, the document file access right management database held in a distributed manner is updated, and the document file database corresponding to this update is updated.
As described above, according to the present embodiment (4), it is possible to realize the agreement of the user who has the access right to the document without communicating with the server 30. Further, the fact that it is not necessary to communicate with the server 30 has an effect that access to documents can be realized by each client 10 appropriately constructing an ad hoc network 62 in a situation where there is no communication infrastructure with the server. In addition, the system can be constructed without a server, which has the effect of preventing information leakage from privileged server administrators and increasing the resistance to leakage protection of the system.
Also, when updating the group database, for example, when a completely new user 6 joins this system, client 10_6 (= user 6) transmits its own authentication information (here, password) to other clients. It can be realized.
The database construction unit (access right management function) is a group database that realizes user admission and a document file access right management database that realizes management of users who have access rights for each document file. It is a user account database including, and a database construction unit that constructs the data contents of the database.
In addition, the network between clients does not necessarily have to be an ad hoc network, and a general wired LAN is used only for the purpose of increasing the resistance to leakage protection of the system by constructing the system without a server. But it doesn't matter.
(Appendix 1) A user account database that associates multiple users who have access rights to the data, and an active user database that shows the users who currently agree to access the data among the users who have the access rights. Only when the current number of the agreed access right-holding users shown in the active user database is plural, the user who holds the access right who has requested access to the data is sent to the data. An access right management system that is characterized by being composed of an access agreement department that agrees on access to. (Appendix 2) In Appendix 1 above, the system is composed of a server and one or more clients, the server including the user account database, the active user database, and the access agreement unit, and each client. It includes a position information detection unit that detects one's current position, and an access request unit that transmits the detected current position and an access request received from the user to the access agreement unit. The access agreement unit registers the received current position in association with the access right-holding user in the active user database, and sets the number of users located within a predetermined range as the current number of agreed users. An access right management system characterized by doing. (Appendix 3) In Appendix 1 above, the system is composed of a server and one or more clients, the server including the user account database, the active user database, and the access agreement unit, and each client. Access to send the identification information of the access right-holding user of the client who built the network and the access request received from the user of the own client to the access agreement unit. It is characterized in that the access agreement unit registers the access right-holding user of the identification information in the active user database as the access right-holding user who has agreed to access the data. Access right management system. (Appendix 4) In Appendix 1 above, Each client has a network construction unit and an access request unit in addition to the user account database, the active user database, and the access agreement unit, and the network construction unit constructs a network with other clients. Then, the access agreement unit registers the access right-holding user of the client connected to the constructed network in the active user database as the access right-holding user who has agreed to access the data. An access right management system characterized in that an access request unit gives an access request received from a user of its own client to the access agreement unit of a client holding the data. (Appendix 5) In Appendix 4 above, each client further has a database construction unit, and the database construction unit associates a plurality of users who have access rights to the data with the user account database. An access right management system characterized by registration or deletion. (Appendix 6) In Appendix 2 or 3 above, An access right management system characterized in that the server holds the data. (Appendix 7) In Appendix 2 or 3 above, the data storage unit in which the client distributes and holds the data, and the data transmission unit and data reception unit for transmitting and receiving the data to and from other clients. An access right management system characterized by having more and more. (Appendix 8) The access according to the above-mentioned appendices 1 to 3 is further provided with a database construction unit for registering or deleting a plurality of users who have access rights to the data in association with the user account database. Rights management system. (Appendix 9) The first step of associating and registering a plurality of users who have access rights to data, and the first step of registering users who currently agree to access the data among the users who have access rights. Only when the current number of the agreed access right holders is more than one in two steps, the user who has the access right who has requested access to the data is agreed to access the data. The third step and the access right management method characterized by having.
<figref num="1">It is a block diagram which showed the principle of the access right management system and access right management method which concerns on this invention.</figref><figref num="2">It is a block diagram which showed the system configuration in Example (1) of the access right management system which concerns on this invention.</figref><figref num="3">It is a figure which showed the user account database in Example (1) of the access right management system which concerns on this invention.</figref><figref num="4">It is a figure which showed the active user database in Example (1) of the access right management system which concerns on this invention.</figref><figref num="5">It is a flowchart which showed the operation procedure in Example (1) of the access right management system which concerns on this invention.</figref><figref num="6">It is a block diagram which showed the system configuration in Example (2) of the access right management system which concerns on this invention.</figref><figref num="7">It is a block diagram which showed the example of the table held by the general ad hoc network construction part.</figref><figref num="8">It is a figure which showed the user account database in Example (2) of the access right management system which concerns on this invention.</figref><figref num="9">It is a figure which showed the active user database in Example (2) of the access right management system which concerns on this invention.</figref><figref num="10">It is a flowchart which showed the operation procedure in Example (2) of the access right management system which concerns on this invention.</figref><figref num="11">It is a block diagram which showed the system configuration in Example (3) of the access right management system which concerns on this invention.</figref><figref num="12">It is a figure which showed the user account database in Example (3) of the access right management system which concerns on this invention.</figref><figref num="13">It is a figure which showed the active user database in Example (3) of the access right management system which concerns on this invention.</figref><figref num="14">It is a figure which showed the document file database in Example (3) of the access right management system which concerns on this invention.</figref><figref num="15">It is a flowchart which shows the operation procedure in Example (3) of the access right management system which concerns on this invention.</figref><figref num="16">It is a block diagram which showed the system configuration in Example (4) of the access right management system which concerns on this invention.</figref><figref num="17">Example (4) of the access right management system according to the present invention: It is a figure which showed the user account database in "agreement of access right to a document".</figref><figref num="18">Example (4) of the access right management system according to the present invention: It is a figure which showed the active user database in "agreement of access right to a document".</figref><figref num="19">Example (4) of the access right management system according to the present invention: It is a figure which showed the document file database in "agreement of access right to a document".</figref><figref num="20">Example (4) of the access right management system according to the present invention: It is a flowchart which showed the operation procedure in "agreement of access right to a document".</figref><figref num="21">Example (4) of the access right management system according to the present invention: It is a figure which showed the user account database in "access right management at the time of distribution of database construction part".</figref><figref num="22">Example (4) of the access right management system according to the present invention: It is a figure which showed the document file database in "access right management at the time of distribution of database construction part".</figref><figref num="23">Example (4) of the access right management system according to the present invention: It is a sequence diagram which showed the operation procedure of "access right management at the time of distribution of database construction part".</figref><figref num="24">It is a block diagram which showed the conventional access right management system.</figref>
Code description
100,100w ~ 100z Access right management system 1 ~ 5 User 10,10_1 ~ 10_3,10a, 10a_1 ~ 10a_3 Client (user terminal) 11 Access request unit 12 Data reception unit 13 Location information reception unit 14,14_1 ~ 14_3 Ad hoc network construction unit 14f, 14f_1, 14f_2 Logical interface 15 Data transmission unit 16 Data reception unit 17 Access request unit 18 Access agreement unit 19,19_1 ~ 19_3 Database construction unit 20z, 20z_1, 20z_2 Database 21z, 21z_1 ~ 21z_3 User account database 22z, 22z_1, 22z_2 Group database 23z, 23z_1 ~ 23z_3 Document file access right management database 24z, 24z_1,24z_2 Active user database 25,25_1,25_2 Data storage 26y, 26y_1,26y_2,26z, 26z_1 ~ 26z_3 Document file database 27_1,27_2 ARP table 28_1,28_2 Logical IF attribute table 30 Server 31 Access agreement part 32 Data transmission part 33 Database construction part 40,40w, 40y Database 41,41w ~ 41y User account database 42w ~ 42y Group database 43w ~ 43y Document file access right management database 44,44w ~ 44y Active user database 45 Data storage 46 Document file database 50 Location information transmitter 60 Network 60a Connection 60b Connection 61 Internal network 62 Ad hoc network 62a Connection 70 Management server 81 Document management DB 82 Key management DB 83 User management DB 84 User operation management DB 700_1 ~ 700_4 Location information 701_1 ~ 701_4 Current position 710 Connection negotiation 711a User ID 711b Password 712 User authentication result 712a Authentication OK 712b Authentication NG 713a User ID 713b Location information 714 Access request 715 Judgment result 715a Agree 715b Not agreed 716 Data file 717 Disconnection negotiation 718 Reception preparation instruction 719 Send instruction 720 Registration / deletion 721,722,724 See 723 Registration / update / deletion 725 Delete 730_1,730_2 Ad hoc network connection / disconnection request 731_1,731_2 Connection request availability 740 Connection negotiation 741a User ID 741b Password 742 User authentication result 742a Authentication OK 742b Authentication NG 743 Ad hoc network connection user authentication request 744 Ad hoc network connection user authentication result 745 Access request 745a User ID 745b File name 746 Judgment result 746a Agreement 746b Not agreed 747 Data file 748 Disconnection negotiation 749 Receive preparation instruction 750 Send instruction 751 Registration / deletion 752 ~ 754,756 Reference 755 Registration / update 758 Delete 760_1,760_2 Ad hoc network connection / disconnection request 761_1,761_2 Connection request availability 762a_1,762a_2 Encrypted split document file 762b_1,762b_2 Split key 770 Connection negotiation 771a User ID 771b Password 772 User authentication result 772a Authentication OK 772b Authentication NG 773 Ad hoc network connection / disconnection request 774 User authentication result 775 Access request 776 Judgment result 776a Agreement 776b Not yet Agree 777,777_1,777_2 Send instruction 778 Disconnection negotiation 779 Receive preparation instruction 780 Registration / deletion 781 ~ 783,785 Reference 784 Registration / update 786 Delete 790 Ad hoc network connection / disconnection request 790 Ad hoc network connection request 791 User authentication request 792 User authentication result 793 Connection request response 794 User authentication request 795 User authentication result 796 Access request 797 Judgment result 797a Agreement 797b Unagreement 798a Encrypted split document file 798b Split key 801,802,804 Refer to 803 Registration 805a Send instruction 805b 806a Encrypted split document file 806b Split key 807 Send instruction 811,812,814 See 813 Registration 820,821 Document search 822a, 822b,823a, 823b, 826 See 824,825 Document search response 827_1,827_2 Access right permission request 829a Encrypted split document file 829b Split key 830 Access right permission request result 831a Encrypted split document file 831b Split key 832 Access right permission request result 833 ~ 836 New split information 837 ~ 840 Update 900 Edit request 901 Edit permission In the figure, the same code indicates the same or equivalent part.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2014178826A | Cited by | Japan | Search report |
| US8812866B2 | Cited by | United States of America | Applicant |
| JP2015076044A | Cited by | Japan | Search report |
| JP2008035501A | Cited by | Japan | Examiner |
| JP2009541861A | Cited by | Japan | Examiner |
| JP2015125546A | Cited by | Japan | Examiner |
| JP2014178826A | Cited by | Japan | Examiner |
| WO2016170780A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JPWO2016170780A1 | Cited by | Japan | Search report |
| WO2015098172A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2007312128A | Cited by | Japan | Examiner |
| JP2013109601A | Cited by | Japan | Examiner |
| JP2014130638A | Cited by | Japan | Examiner |
| US8457317B2 | Cited by | United States of America | Applicant |
| JPWO2016170780A1 | Cited by | Japan | Search report |
| JP2014178826A | Cited by | Japan | Search report |
| JP2015125546A | Cited by | Japan | Search report |
| JP2011180987A | Cited by | Japan | Examiner |
| JP2008203369A | Cited by | Japan | Examiner |
| JP2010530562A | Cited by | Japan | Examiner |
| JP2015125547A | Cited by | Japan | Examiner |
| JP2001092961A | Cites | Japan | Examiner |
| JP2002366530A | Cites | Japan | Examiner |
| JPH10240690A | Cites | Japan | Examiner |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004104521 | Japan | A | |
| JP20040104521 | – | – | – |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2005293004
- Publication, DOCDB
- 2005293004
- Publication, EPODOC
- JP2005293004
- Application
- 104521
- Application, DOCDB
- 2004104521
- Application, EPODOC
- JP20040104521
Titles2
- Japanese
- アクセス権管理システム及びアクセス権管理方法
- English
- Access right management system and access right management method
Classification
- CPC, 5
- G06F21/40
- G06F21/6218
- G06F2221/2111
- G06F2221/2141
- G06F2221/2147
- IPC, 8
- G06F21 62
- G06F12 00
- G06F12 14
- G06F15 00
- G06F17 30
- G06F21 00
- G06F21 31
- G06F21 60