Shared data access management system
Abstract
[Subject] Grant of the right to access and right-to-access acquisition are made easy about the access right control of the shared data which a multiple user uses. [Solution means] Connection propriety User Information over the shared data managing server 1, The User Information setting part 21 sets to the User Information storage part 5, and the right-to-access setting part 22 sets up the access right information to the shared data held in the data storage part 4, Access right control of the shared data 11 to the user linked to the shared data managing server 1 is performed by the right control section 23 of a data access. [Selection figure] Fig. 1
Term
No projected expiry on record.
- Priority and filed
- Published
- Today
1 claim: 1 independent, 0 dependent
- 1A shared data management server that holds a plurality of shared data in a data storage unit and a plurality of terminal devices that are connected to the shared data management server via a network are provided, and the plurality of shared data are stored in the plurality of terminals. In a system accessed by a user from a device, the shared data management server has a user information storage unit, an access right storage unit, and an access right control unit, and the access right control unit sets user information for setting connected user information. Access right setting unit for setting access right setting, access right setting, access right delegation request password for each data, connection availability judgment, delegation connection availability judgment, connecting user information setting, access right permission / rejection judgment, delegation connection cancellation , A shared data access management system characterized by having a data access control unit that executes disconnection processing. 複数の共有データをデータ記憶部に保有する共有データ管理サーバと、前記共有データ管理サーバにネットワークを介して接続される複数台の端末装置とを備え、前記複数の共有データを前記複数台の端末装置からユーザがアクセスするシステムにおいて、前記共有データ管理サーバは、ユーザ情報記憶部、アクセス権記憶部及びアクセス権制御部を有し、前記アクセス権制御部は、接続ユーザ情報を設定するユーザ情報設定部と、データ別アクセス権設定、アクセス権設定、アクセス権委譲要求パスワードを設定するアクセス権設定部と、接続可否判定、委譲接続可否判定、接続中ユーザ情報設定、アクセス権可否判定、委譲接続解除、接続解除の処理を実行するデータアクセス制御部を有することを特徴とする共有データアクセス管理システム。
34 paragraphs, as filed
The present invention relates to a shared data access management system in which a user accesses from a plurality of terminal devices connected to a shared data management server holding a plurality of shared data via a network.
The conventional access right control method in the shared data management server that holds shared data accessed by multiple users from multiple terminal devices is such that only users who have access right setting authority from a specific terminal device have a large amount of data for each user. The access right is set, and the access right is acquired by referring to multiple tables each time the access right acquisition request is made. This is described in, for example, Patent Document 1 below.
<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2003-36207</text></patcit>
<p> The prior art has problems that the work of granting access rights is reduced and the efficiency of access right acquisition processing is not taken into consideration.</p><p> An object of the present invention is a shared data access management system that enables an unspecified data registration user to grant an access right, can easily grant the access right even when adding data or a user group, and can improve the access right acquisition processing efficiency. Is to provide.</p>
<p> The shared data access management system of the present invention includes a shared data management server that holds a plurality of shared data in a data storage unit, and a plurality of terminal devices that are connected to the shared data management server via a network. In a system in which a user accesses shared data from a plurality of terminal devices, the shared data management server has a user information storage unit, an access right storage unit, and an access right control unit, and the access right control unit stores connected user information. User information setting unit to be set, access right setting for each data, access right setting, access right delegation request password to be set, connection availability judgment, delegation connection availability judgment, connected user information setting, access right availability It has a data access control unit that executes determination, delegation connection cancellation, and connection cancellation processing.</p>
<p> In the present invention, in a system in which a plurality of users access a huge amount of shared data, the data registrant can easily set the access right grant at the time of sharing data registration and user group registration, and whether or not the connected user can have high-speed access right. Effective for judgment.</p>
The shared data management server holds a plurality of shared data in the data storage unit. A plurality of terminal devices are connected to the shared data management server via a network. A user accesses a plurality of shared data from a plurality of terminal devices. The shared data management server has a user information storage unit, an access right storage unit, and an access right control unit. The access right control unit includes a user information setting unit that sets connection user information, an access right setting unit that sets data-specific access right setting, access right setting, and access right delegation request password, and connection availability determination and delegation connection availability determination. It has a data access control unit that executes processing such as setting user information during connection, determining access right, delegating connection cancellation, and disconnection.
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. FIG. 1 is a system configuration diagram of a shared data access management system to which the present invention is applied.
In FIG. 1, reference numeral 1 denotes a shared data management server according to the present invention. 2 is a terminal device used by the user to access the shared data management server 1, and 3 is a network connecting the shared data management server 1 and the terminal device 2.
The shared data management server 1 includes a data storage unit 4 that holds shared data, a user information storage unit 5 that holds a user information-related table, and an access right storage unit 6 that holds an access right information-related table. The access right control unit 7 that constitutes the shared data management server 1 sets the user information setting unit 21 that sets the information of the user who can access the user information storage unit 5, and the access right that sets the access right information in the access right storage unit 6. It consists of a setting unit 22 and a data access control unit 23 that controls the connection from the terminal device 2 to the shared data management server 1 and the access right control of the connected user.
The data 11 stored in the data storage unit 4 is data that can be shared by a plurality of users and can be granted access rights. The unit to which the access right of data 11 can be granted can be a database unit, a database table unit, a file unit, a folder unit, or the like.
The table 12 held in the user information storage unit 5 is a user management table whose table configuration is shown in FIG. 2, a user ID for uniquely identifying a user, and a user belonging to each user for uniquely identifying a user group. Group ID, user classification that identifies whether it is a single user (S) that allows only one connection for one user ID or a multi-user (M) that can connect multiple times to one user, and a connection password that is a password when requesting a connection Remember. The record data in Table 12 is configured so that one user can concurrently serve as a plurality of user groups by adding a record at the time of new user registration or registration of a new user group and having a plurality of belonging user group information.
As shown in FIG. 3, the connected user information management table 13 stores a user ID, a unique session ID within the connected user, and access rights for each data ID of the connected user, as shown in FIG. The record data in Table 13 is added when the connection with the user is established, and the corresponding record is deleted when the connection is disconnected. There are three types of access rights: read / write (R / W), readable (R), and read / write not possible (-).
As shown in FIG. 4, the access right management table 14 for each data of the access right storage unit 6 has a unique data ID assigned to each data and a user ID of a user connected to the shared data management server 1 at the time of data registration. Stores the owner ID indicating, and the access right for each category. For the record data in table 14, the record is added when the data for which access right management is added is added. The categories are four categories: owner, own group, other group, and guest, for which the user sets access rights when registering data.
In addition, the access right management table 15 stores the access right to the access right grant target data for each owner, user group, and guest, as shown in FIG. There can be multiple user groups. Table 15 updates the information when adding a user group, adding data, or changing access rights. There are three types of access rights, similar to the access rights for each data ID in the connected user information management table 13 shown in FIG.
As shown in FIG. 6, the access right delegation management table 16 shows the user group ID for each user group that allows delegation of access rights, the delegation request password at the time of the access right delegation connection request, and the access right of the user group. Stores the delegating state indicating whether or not is being delegated, and the delegating user ID indicating the user ID of the user being delegated. Table 16 adds records when adding user groups that allow delegation of access rights.
The access right control unit 7 sets information in the user information storage unit 5 and information in the access right storage unit 6. The user information setting unit 21 sets registration, change, and deletion of the user ID, affiliated user group ID, user classification, and connection password of the user who is permitted to connect to the shared data management server 1 in the connection user information setting 31.
When the access right setting unit 22 registers the shared data to be granted the access right in the data storage unit 4 in the access right setting 32 for each data, the data ID is assigned, and the owner ID and the access right for each category specified by the owner are classified by data. Set in the access right management table 14. The access right setting 33 sets the access rights for each owner, own group, other group, and guest of the data registered in the access right management table 15 based on the set access rights for each category in the access right management table 14 for each data. Automatically grant. Also, when changing or deleting the access right for the data already registered in the access right management table 14 for each data, the access right is changed or deleted for the target data in the access right management table 15.
Further, when a new user group is additionally registered in the connection user information setting 31, the user group is added to the access right management table 15, and the access right by data ID is registered in the access right management table 14 by data. Grant access to other groups of all existing data. Register the user group ID and delegation request password that allow delegation of access rights for each user group in the access right delegation management table.
Next, the data access control operation in the access right control unit 7 when the shared data management server 1 holding the shared data is accessed from the terminal device 2 via the network 3 will be described with reference to the flowchart of FIG. ..
When the user requests a connection using the terminal device 2, the data access control unit 23 registers the user ID and the user password notified from the terminal device 2 in the connection availability determination process 35 in step S1 in the user information management table 12. Check if. If it is determined that the terminal is not registered in step S1, the process proceeds to step S10, the connection request terminal device 2 is notified that connection is not possible, and the process ends.
If it is determined that the registration is registered in step S1, the process proceeds to step S2, and if the user classification of the connection requesting user is a single user from the user information management table 12, it is checked whether the same user ID is connected to the connecting user information management table 13. If it is already connected, the process proceeds to step S10, notifies the connection request terminal device 2 that connection is not possible, and ends the process. If it is not connected, it is judged that the connection is possible. If the user classification of the connection request user is multi-user, it is determined that the same user ID can be used for connection.
If it is determined in step S2 that the connection is possible, the process proceeds to step S3, and in the delegation connection availability determination process 36, it is determined whether or not the access right is delegated, which is notified from the terminal device 2. If the user is not the access right delegation request user, the process proceeds to step S4, and the access right of the user group to which the connection request user belongs for all data is extracted from the access right management table 15 in the connecting user information setting process 37. At this time, if the connection request user is a user who belongs to a plurality of user groups, an advantageous access right is extracted.
In step S5, the user ID of the connection requesting user, the session ID numbered with a unique value, and the access right for each data extracted in step S4 are registered in the connected user information management table 13, and the session ID can be connected in step S6. Notify the connection request terminal device 2 of the above.
On the other hand, when the connection requesting user is determined to be the access right delegation request user in the delegation connection availability determination process 36 in step S3, it is determined in step S7 whether the delegation request password notified from the terminal device 2 matches, and the delegation is performed. Determine from the access right delegation management table 15 whether the requesting user group is being delegated to another user.
If the delegation request password does not match, or if another user is already delegating, the process proceeds to step S10, notifies the connection request terminal device 2 that connection is not possible, and ends the process. If another user is not delegating, the connecting user information setting process 37 is executed in step S8, and the access right of all data to the delegation request user group in the access right management table 15 is extracted.
Moving from step S8 to step S9, the delegating state of the delegation request user group in the access right delegation management table 16 is being delegated, the user ID for which the access right delegation request is registered is registered in the delegating user ID, and the connecting user in step S5. The process ends through the information setting process 37 and step S6.
For the access right for each data of the connecting user, refer to the access right for each data ID in the connecting user information management table 13 in the access right approval / disapproval processing 38. If there is a disconnection request from the connected user, the record data of the session ID for which the connection disconnection request is made in the connected user information management table 13 is deleted in the connection disconnection process 40. In the case of a user who is delegating access rights, the delegation connection cancellation process 39 deletes the delegating status and the delegating user ID information in the access right delegation management table 16.
Although the access is performed in this way, it becomes possible to adapt to a system in which a plurality of users use the centrally managed shared data from a plurality of terminals. For example, a document management system can be mentioned.
The technical idea (invention) not described in the claims that can be grasped from the above-described embodiment is described below.
(Invention 1) In a system in which the shared data management server holding a plurality of shared data is accessed from the terminal device via a network, the access right control unit is a user who permits access to the shared data management server in the user information management table. The user information setting unit that has the connection user information setting that sets the user ID, belonging user group ID, user classification, and connection password for identifying the data, and the access right for each category to the data registered by the user when registering new data. Access right setting for each data to be registered in another access right management table, granting access right to the data registered in the access right management table to all user groups based on the access right management table for each data, and new user group At the time of registration, based on the access rights by category of the access right management table for each data, the access right setting that grants access rights to all data for the new user group of the access right management table and the access right delegation management table Access right delegation request for each user group Access right setting unit that has a delegation request password setting, and when a user requests a connection to a shared data management server from a terminal device, the connection request user registers in the user information management table. If it is an access right delegation request user, it is judged whether the connection is possible or not, whether it is a single user or a multi-user, and whether it is a single user or a multi-user. , Refer to the access right delegation management table, and determine whether the access right delegation connection is possible or not, and if it is judged that the connection is possible and it is not an access right delegation request, the access right for each data of the connection request user is extracted. The connected user information stored in the connected user information management table and, if it is an access right delegation request, the access right for each data of the delegation request destination user group is extracted and stored in the connected user information management table. Settings, access right availability judgment for each data of connected user, and connected userWhen the connection disconnection request is made, if the access right is being delegated, the delegation connection cancellation that resets the delegating state of the access right delegation management table and the connection disconnection request user information of the connected user information management table are deleted. A shared data access right control method comprising a data access control unit having a release.
<figref num="1">It is a block diagram which shows one Example of this invention.</figref><figref num="2">It is an example block diagram of a user information management table.</figref><figref num="3">It is an example configuration diagram of the connected user information management table.</figref><figref num="4">It is an example configuration diagram of the access right management table for each data.</figref><figref num="5">It is an example configuration diagram of the access right management table.</figref><figref num="6">It is an example configuration diagram of the access right delegation management table.</figref><figref num="7">It is a flowchart for demonstrating operation of this invention.</figref>
Code description
1 ... shared data management server, 2 ... terminal equipment, 3 ... network, 4 ... data storage, 5 ... user information storage, 6 ... access right storage, 7. .. Access right control unit, 11 ... shared data, 12 ... user information management table, 13 ... connected user information management table, 14 ... access right management table by data, 15 ... access Right management table, 16 ... Access right delegation management table, 21 ... User information setting section, 22 ... Access right setting section, 23 ... Data access control section, 31 ... Connection user information setting, 32 ... Access right setting by data, 33 ... Access right setting, 34 ... Delegation request password setting, 35 ... Connection availability judgment, 36 ... Delegation connection availability judgment, 37 ... Connecting User information setting, 38 ... Access right availability judgment, 39 ... Delegation connection cancellation, 40 ... Connection cancellation.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2008142138A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8176535B2 | Cited by | United States of America | Applicant |
| JP2008035501A | Cited by | Japan | Examiner |
| US8914897B2 | Cited by | United States of America | Applicant |
| WO2008142138A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2007265242A | Cited by | Japan | Examiner |
| JP2007157024A | Cited by | Japan | Examiner |
| US9129307B2 | Cited by | United States of America | Applicant |
| US7668830B2 | Cited by | United States of America | Applicant |
| JP2010128557A | Cited by | Japan | Examiner |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004111663 | Japan | A | |
| JP20040111663 | – | – | – |
Numbers
- Publication
- 2005293513
- Publication, DOCDB
- 2005293513
- Publication, EPODOC
- JP2005293513
- Application
- 111663
- Application, DOCDB
- 2004111663
- Application, EPODOC
- JP20040111663
Titles2
- Japanese
- 共有データアクセス管理システム
- English
- Shared data access management system
Classification
- IPC, 3
- G06F21 24
- G06F12 00
- G06F12 14