Connection request transfer system and connection request transfer program
The connection request transfer system addresses the challenge of routing connection requests by evaluating HTTP request conditions and applying inhibition rules, ensuring accurate and efficient routing to the appropriate information processing systems.
Patent Information
- Application Number
- JP2023183329
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-25
- Publication Date
- 2025-05-12
Smart Images

Figure 2025072886000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a connection request forwarding system and a connection request forwarding program for forwarding a connection request from a connection source to any one of a plurality of information processing systems. [Background technology]
[0002] 2. Description of the Related Art Conventionally, there are known techniques for connecting to an information processing system from an external connection source of the information processing system and using functions provided by the information processing system (see, for example, Patent Documents 1 to 3). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2019-139691 A [Patent Document 2] Patent No. 6161803 [Patent Document 3] Patent No. 7111912 Summary of the Invention [Problem to be solved by the invention]
[0004] However, in conventional technology, when a system is provided with multiple information processing systems and a connection request forwarding system that forwards a connection request from a connection source to one of the multiple information processing systems, there is a problem in that the connection request from the connection source cannot be forwarded to an information processing system among the multiple information processing systems that corresponds to the content of the connection request.
[0005] Therefore, an object of the present invention is to provide a connection request forwarding system and a connection request forwarding program that can forward a connection request from a connection source to an information processing system among multiple information processing systems that corresponds to the content of the connection request. [Means for solving the problem]
[0006] The connection request forwarding system of the present invention is a connection request forwarding system that forwards a connection request from a connection source to one of a plurality of information processing systems, and is characterized in that when a forwarding condition as a condition for forwarding the connection request is satisfied based at least on the HTTP request of the connection request, and a prohibition condition as a condition for prohibiting the forwarding of the connection request is not satisfied, the connection request is forwarded to the information processing system as a forwarding destination corresponding to the forwarding condition, and even if the forwarding condition is satisfied based at least on the HTTP request, the connection request is not forwarded when the prohibition condition is satisfied.
[0007] With this configuration, the connection request forwarding system of the present invention forwards a connection request to an information processing system as a forwarding destination corresponding to the forwarding conditions when the forwarding conditions are satisfied based at least on the HTTP request of a connection request from the connection source, but the prohibition conditions are not satisfied; and even when the forwarding conditions are satisfied based at least on the HTTP request of a connection request from the connection source, the connection request is not forwarded when the prohibition conditions are satisfied. Therefore, the connection request from the connection source can be forwarded to an information processing system among multiple information processing systems that corresponds to the content of the connection request.
[0008] In the connection request transfer system of the present invention, the prohibition condition may include a condition that the IP address of the connection source is a specific IP address.
[0009] With this configuration, the connection request forwarding system of the present invention does not forward a connection request from a specific IP address even if the forwarding condition is satisfied based at least on the HTTP request of the connection request from the connection source, since the prohibition condition includes the condition that the IP address of the connection source is a specific IP address. As a result, the connection request from the connection source can be forwarded to an appropriate information processing system with a simple configuration.
[0010] In the connection request transfer system of the present invention, the prohibition condition may include a condition that the HTTP request contains a specific character string.
[0011] With this configuration, the connection request forwarding system of the present invention has a prohibition condition that an HTTP request contains a specific character string, so that even if the forwarding condition is satisfied based at least on the HTTP request of the connection request from the connection source, the connection request will not be forwarded when the HTTP request contains the specific character string.As a result, the connection request from the connection source can be forwarded to an appropriate information processing system with a simple configuration.
[0012] In the connection request transfer system of the present invention, the specific character string may include a character string indicating a specific tenant that uses the information processing system.
[0013] With this configuration, the connection request forwarding system of the present invention does not forward a connection request to a specific tenant even if the forwarding condition is satisfied based at least on the HTTP request of the connection request from the connection source, because the prohibition condition includes a condition that the HTTP request contains a specific character string indicating a specific tenant using the information processing system.As a result, the connection request from the connection source can be forwarded to an appropriate information processing system with a simple configuration.
[0014] In the connection request transfer system of the present invention, the specific character string may include a character string indicating a specific user who uses the information processing system.
[0015] With this configuration, the connection request forwarding system of the present invention does not forward a connection request from a specific user even if the forwarding condition is satisfied based at least on the HTTP request of the connection request from the connection source, because the prohibition condition includes a condition that the HTTP request contains a specific character string indicating a specific user using the information processing system.As a result, the connection request from the connection source can be forwarded to an appropriate information processing system with a simple configuration.
[0016] The connection request forwarding program of the present invention is a connection request forwarding program for forwarding a connection request from a connection source to one of a plurality of information processing systems, and is characterized in that when a forwarding condition as a condition for forwarding the connection request is satisfied based at least on the HTTP request of the connection request, and a prohibition condition as a condition for prohibiting the forwarding of the connection request is not satisfied, the program forwards the connection request to a computer addressed to the information processing system as a forwarding destination corresponding to the forwarding condition, and does not forward the connection request to the computer when the prohibition condition is satisfied, even if the forwarding condition is satisfied based at least on the HTTP request.
[0017] With this configuration, a computer executing the connection request forwarding program of the present invention forwards a connection request to an information processing system as a forwarding destination corresponding to the forwarding conditions when the forwarding conditions are met based at least on the HTTP request of the connection request from the connection source, but the prohibition conditions are not met; even if the forwarding conditions are met based at least on the HTTP request of the connection request from the connection source, the computer does not forward the connection request when the prohibition conditions are met, so that the connection request from the connection source can be forwarded to an information processing system among multiple information processing systems that corresponds to the content of the connection request. Effect of the Invention
[0018] The connection request transfer system and the connection request transfer program of the present invention can transfer a connection request from a connection source to an information processing system, among a plurality of information processing systems, that corresponds to the content of the connection request. [Brief description of the drawings]
[0019] [Figure 1] FIG. 1 is a block diagram of a system according to an embodiment of the present invention. [Diagram 2] FIG. 2 is a block diagram of an example of the gateway shown in FIG. 1 when configured by one computer. [Diagram 3]3(a) is a diagram showing an example of a URL of a destination of a connection request sent from the connection source shown in Fig. 1. FIG. 3(b) is a diagram showing an example of an HTTP request of a connection request sent to the URL shown in Fig. 3(a). [Figure 4] FIG. 2 is a diagram illustrating an example of a transfer rule illustrated in FIG. [Diagram 5] 3 is a flowchart of the operation of the gateway shown in FIG. 2 when a connection request is received from the image forming apparatus. [Figure 6] 6A is a diagram showing an example of an HTTP request for a connection request sent to a pre-transfer URL, which is different from the example shown in Fig. 3B. (b) is a diagram showing an example of an HTTP request that a connection request forwarding unit that has received the HTTP request shown in Fig. 6A forwards to an image processing system cluster. [Figure 7] 7A is a diagram showing an example of an HTTP request for a connection request sent to a pre-transfer URL, which is different from the examples shown in Fig. 3B and Fig. 6A. Fig. 7B is a diagram showing an example of an HTTP request that a connection request forwarding unit that has received the HTTP request shown in Fig. 7A forwards to an image processing system cluster. [Figure 8] 8(a) is a diagram showing an example of an HTTP request for a connection request sent to a pre-transfer URL, which is different from the examples shown in Fig. 3(b), Fig. 6(a), and Fig. 7(a). Fig. 8(b) is a diagram showing an example of an HTTP request that a connection request forwarding unit that has received the HTTP request shown in Fig. 8(a) forwards to an image processing system cluster. [Figure 9] Fig. 3A is a diagram showing an example of a pre-transfer URL different from the example shown in Fig. 3A, and Fig. 3B is a diagram showing an example of an HTTP request different from the example shown in Fig. 3B. [Figure 10] FIG. 5 is a diagram illustrating an example of a transfer rule different from the transfer rule illustrated in FIG. 4. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0020] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0021] First, the configuration of the system according to the present embodiment will be described.
[0022] FIG. 1 is a block diagram of a system 10 according to the present embodiment.
[0023] As shown in FIG. 1, the system 10 includes an image processing system cluster 20 as an information processing system that realizes document processing such as generating, searching, editing, and saving documents. The system 10 includes at least one image processing system cluster having a similar configuration to the image processing system cluster 20 in addition to the image processing system cluster 20. The image processing system cluster may operate in a multi-tenant model in which the image processing system cluster is used by multiple tenants. The image processing system cluster may be configured by one computer such as a PC (Personal Computer), or may be configured by multiple computers. The image processing system cluster may be realized on a cloud.
[0024] In the system 10, an image processing system cluster may be installed for each region, such as the United States, Europe, Asia, etc. By installing an image processing system cluster for each region, the system 10 can, for example, distribute the processing load to each region, and even if one of the image processing system clusters goes down, the other image processing system clusters can continue processing.
[0025] In the system 10, an image processing system cluster may be arranged for each function with respect to at least some of the functions of the image processing system cluster, such as an authentication function for authenticating a user, a tenant management function for managing tenants, a device management function for managing image forming apparatuses described below, etc. By arranging an image processing system cluster for each function, the system 10 can reduce costs by, for example, consolidating image processing system clusters for specific functions into one cluster for the entire world.
[0026] An image processing system cluster may be arranged for each tenant for at least some of the tenants in the system 10. By arranging an image processing system cluster for each tenant in the system 10, for example, the processing load can be distributed among the tenants and security performance can be improved.
[0027] The system 10 includes a gateway 30 that relays a session to any one of image processing system clusters arranged in a backend based on a request from an image forming device, a computer, or an external system described below. The gateway 30 may be configured by one computer such as a PC, or may be configured by multiple computers. The gateway 30 may be realized on a cloud.
[0028] The system 10 includes a database 40 that stores transfer rules 41 as rules for transferring a connection request from an image forming device, a computer or an external system, which will be described later, serving as a connection source, to one of a plurality of image processing system clusters.
[0029] The system 10 includes an image forming device 50 as a device for receiving documents from an image processing system cluster, transmitting documents to an image processing system cluster, and printing documents. The system 10 may include at least one image forming device having a similar configuration to the image forming device 50 in addition to the image forming device 50.
[0030] The system 10 includes a computer 60 configured, for example, by a mobile device such as a smartphone, a PC (Personal Computer), or the like. The system 10 may include at least one other computer having a similar configuration to the computer 60 in addition to the computer 60. The computer can use the image processing system cluster via an application such as a web browser or a native application. The computer can, for example, cause the image processing system cluster to store documents, search for documents managed by the image processing system cluster, refer to documents managed by the image processing system cluster, and edit documents managed by the image processing system cluster.
[0031] The system 10 includes an external system 70 that uses the image processing system cluster outside the image processing system cluster. The system 10 may include at least one external system having a similar configuration to the external system 70 in addition to the external system 70. The external system may be a cloud service.
[0032] FIG. 2 is a block diagram of the gateway 30 when configured by a single computer.
[0033] As shown in FIG. 2, the gateway 30 includes an operation unit 31 which is an operation device such as a keyboard or mouse through which various operations are input, a display unit 32 which is a display device such as an LCD (Liquid Crystal Display) that displays various information, a communication unit 33 which is a communication device that communicates with external devices via a network such as a LAN or the Internet, or directly by wired or wireless means without going through a network, a memory unit 34 which is a non-volatile memory device such as a semiconductor memory or an HDD (Hard Disk Drive) that stores various information, and a control unit 35 which controls the entire gateway 30.
[0034] The storage unit 34 can store a connection request transfer program 34a for transferring a connection request from a connection source to any one of a plurality of image processing system clusters. The connection request transfer program 34a may be installed in the gateway 30 during the manufacturing stage of the gateway 30, or may be additionally installed in the gateway 30 from an external storage medium such as a USB (Universal Serial Bus) memory, or may be additionally installed in the gateway 30 from a network.
[0035] The control unit 35 includes, for example, a CPU (Central Processing Unit), a ROM (Read Only Memory) that stores programs and various data, and a RAM (Random Access Memory) that serves as a memory used as a working area for the CPU of the control unit 35. The CPU of the control unit 35 executes programs stored in the storage unit 34 or the ROM of the control unit 35.
[0036] The control unit 35 executes the connection request transfer program 34a to realize a connection request transfer unit 35a that transfers a connection request from a connection source to one of a plurality of image processing system clusters. Therefore, the gateway 30 constitutes a connection request transfer system of the present invention.
[0037] Fig. 3(a) is a diagram showing an example of a Uniform Resource Locator (URL) of a destination of a connection request sent from a connection source. Fig. 3(b) is a diagram showing an example of a Hypertext Transfer Protocol (HTTP) request 80 of the connection request sent to the URL shown in Fig. 3(a).
[0038] A connection source such as the image forming apparatus, computer, or external system shown in FIG. 1 transmits a connection request to a specific URL (hereinafter referred to as the "pre-transfer URL") in order to connect to the image processing system cluster.
[0039] The pre-transfer URL is, for example, a URL in the format "https: / / example.net / region / " shown in FIG.
[0040] 3(a) is the domain name of the gateway 30. In reality, the "region" in the path of the pre-transfer URL contains a specific character string indicating the region, such as "us" indicating the United States, "eu" indicating Europe, or "as" indicating Asia.
[0041] An HTTP request 80 for a connection request sent from the connection source to the pre-transfer URL shown in FIG. 3(a) has, for example, a structure as shown in FIG. 3(b).
[0042] 3(b) includes a single request line 81 as an initial line, and a header field 82 which may consist of multiple lines and is placed immediately after the request line 81. The HTTP request 80 may include a blank line immediately after the header field 82, and a message body which may consist of multiple lines immediately after this blank line.
[0043] The request line 81 includes a method 81a that specifies the type of request, a request target 81b that is placed immediately after the method 81a with a space in between, and an HTTP version 81c that is placed immediately after the target 81b with a space in between.
[0044] The method 81a is "GET" in the example shown in FIG. 3(b), but may be a method other than "GET".
[0045] The target 81b is " / region / ", which is the path in the pre-transfer URL shown in FIG.
[0046] In the header field 82, headers are arranged in the format of "field name: value" for each line. For example, the header field 82 includes a Host header 82a that specifies the domain name of the server to be connected to, a tenant-id header 82b that specifies a tenant ID as identification information of the tenant to be connected to, a function header 82c that specifies the function of the image processing system cluster, and a user-id header 82d that specifies a user ID indicating identification information of the user who executed the connection request. The Host header 82a shown in FIG. 3(b) is "Host:example.net" that indicates the domain name in the pre-transfer URL shown in FIG. 3(a). The tenant-id header 82b shown in FIG. 3(b) is "tenant-id:000-111-333" that indicates "000-111-333" as the tenant ID. The function header 82c shown in FIG. 3(b) is "function:auth" that indicates an authentication function as a function. The value of "function" can be "auth", which indicates an authentication function, or various other values such as "TM", which indicates a tenant management function, and "DM", which indicates a device management function. The user-id header 82d shown in Fig. 3(b) is "user-id:U0001", which indicates "U0001" as the user ID.
[0047] FIG. 4 is a diagram showing an example of the transfer rule 41. As shown in FIG.
[0048] The transfer rules 41 shown in FIG. 4 indicate, for each transfer condition, a transfer condition as a condition for transferring a connection request, an ID as identification information of the transfer condition, a transfer destination associated with the transfer condition, and a condition for prohibiting the transfer of a connection request associated with the transfer condition.
[0049] The smaller the ID number, the higher the priority of the forwarding condition. The forwarding condition with the ID "001" in the forwarding rule 41 shown in FIG. 4 is a condition that the path included in the request line 81 of the HTTP request 80 contains the character string " / eu / ". The forwarding condition with the ID "002" in the forwarding rule 41 shown in FIG. 4 is a condition that the path included in the request line 81 of the HTTP request 80 contains the character string " / us / ". The forwarding condition with the ID "003" in the forwarding rule 41 shown in FIG. 4 is a condition that the value of the tenant-id header 82b in the header field 82 of the HTTP request 80 completely matches the character string "000-111-333". The forwarding condition with the ID "004" in the forwarding rule 41 shown in FIG. 4 is a condition that the value of the function header 82c in the header field 82 of the HTTP request 80 contains the character string "auth". The transfer condition with ID “005” in the transfer rule 41 shown in FIG. 4 is a condition that the path included in the request line 81 of the HTTP request 80 and the header value in the header field 82 of the HTTP request 80 can be any character string.
[0050] In some cases, a transfer condition may be associated with an instruction to edit a path included in the request line 81 of the HTTP request 80 in the transfer rule 41. The transfer condition with ID "003" or "004" in the transfer rule 41 shown in FIG. 4 includes a character string ""url action":"non"", which indicates that no instruction to edit a path is associated with the transfer condition. The transfer condition with ID "001" in the transfer rule 41 shown in FIG. 4 includes a character string ""url action":"edit"," / "", which indicates that an instruction to edit the path, which is included in the request line 81 of the HTTP request 80, is replaced with the character string " / eu / ". The transfer condition with ID "002" in the transfer rule 41 shown in FIG. 4 includes a character string ""url action":"edit"," / "", which indicates that an instruction to edit the path, which is included in the request line 81 of the HTTP request 80, is replaced with the character string " / us / ". The replacement string may contain regular expressions.
[0051] The transfer destination in the transfer rule 41 indicates a portion of the URL of the transfer destination of the connection request other than the path. "eu.example.com" in the transfer destination associated with the transfer condition with ID "001" in the transfer rule 41 shown in FIG. 4 is, for example, a domain name of an image processing system cluster located in Europe. "us.example.com" in the transfer destination associated with the transfer condition with ID "002" in the transfer rule 41 shown in FIG. 4 is, for example, a domain name of an image processing system cluster located in the United States. "companyA.example.com" in the transfer destination associated with the transfer condition with ID "003" in the transfer rule 41 shown in FIG. 4 is, for example, a domain name of an image processing system cluster for a tenant with a tenant ID "000-111-333". "auth.example.com" in the transfer destination associated with the transfer condition with ID "004" in the transfer rule 41 shown in FIG. 4 is, for example, a domain name of an image processing system cluster for an authentication function. The "as.example.com" in the transfer destination associated with the transfer condition with the ID "005" in the transfer rule 41 shown in FIG. 4 is, for example, the domain name of an image processing system cluster located in Asia. The transfer condition with the ID "005" in the transfer rule 41 shown in FIG. 4 is a condition in which the path included in the request line 81 of the HTTP request 80 and the header value in the header field 82 of the HTTP request 80 may be any character string, as described above. Therefore, the transfer destination associated with the transfer condition with the ID "005" in the transfer rule 41 shown in FIG. 4 is a standard transfer destination that is identified when all other transfer conditions are not satisfied. Note that the transfer rule 41 does not need to include a standard transfer destination.
[0052] The prohibition condition associated with the transfer condition with ID "001" in the transfer rule 41 shown in FIG. 4 is a condition that "the IP (Internet Protocol) address of the connection source is one of "192.0.2.0 to 192.0.2.10" and the tenant ID is "000-111-333" or "000-111-444." The prohibition condition associated with the transfer condition with ID "002" in the transfer rule 41 shown in FIG. 4 is a condition that "the IP address of the connection source is one of "192.0.2.20 to 192.0.2.30" or "the user ID is "U0001" or "U0002." The prohibition condition associated with the transfer condition with ID "003" in the transfer rule 41 shown in FIG. 4 is a condition that "the user ID is "U0003." The prohibited condition associated with the transfer condition with ID "004" in the transfer rule 41 shown in Fig. 4 is the condition that "the IP address of the connection source is '192.0.2.40'" or "the tenant ID is '000-111-555'." There is no prohibited condition associated with the transfer condition with ID "005" in the transfer rule 41 shown in Fig. 4.
[0053] Next, the operation of the gateway 30 when a connection request is received from an image forming device, a computer, or an external system will be described.
[0054] Note that, in the following, an example will be described in which the gateway 30 receives a connection request from the image forming device 50; however, the same applies to the case in which the gateway 30 receives a connection request from an image forming device other than the image forming device 50, or the case in which the gateway 30 receives a connection request from a computer or an external system.
[0055] In order to connect to the image processing system cluster, the image forming apparatus 50 transmits a connection request to the pre-transfer URL as described above. In the following, a case will be described in which the pre-transfer URL has the format "https: / / example.net / region / " shown in FIG. 3(a).
[0056] FIG. 5 is a flowchart showing the operation of the gateway 30 when a connection request is received from the image forming apparatus 50. As shown in FIG.
[0057] When the connection request transfer unit 35a of the gateway 30 receives the connection request from the image forming apparatus 50, the connection request transfer unit 35a executes the operation shown in FIG.
[0058] As shown in FIG. 5, the connection request forwarding unit 35a acquires the forwarding rule 41 from the database 40 (S101).
[0059] When the process of S101 is completed, the connection request forwarding unit 35a determines whether or not there is a forwarding condition in the forwarding rule 41 acquired in S101 that has not yet been targeted in the current operation shown in FIG. 5 (S102).
[0060] When the connection request forwarding unit 35a determines in S102 that there is a forwarding condition in the forwarding rules 41 acquired in S101 that has not yet been targeted in the current operation shown in FIG. 5, the connection request forwarding unit 35a targets one forwarding condition with the smallest ID among the forwarding conditions in the forwarding rules 41 that have not yet been targeted in the current operation shown in FIG. 5 (S103).
[0061] When the process of S103 ends, the connection request forwarding unit 35a judges whether or not the condition related to the path included in the request line 81 of the HTTP request 80 is included in the currently targeted forwarding conditions (S104).
[0062] When the connection request forwarding unit 35a determines in S104 that the condition related to the path included in the request line 81 of the HTTP request 80 is included in the current target forwarding condition, the connection request forwarding unit 35a acquires the path included in the request line 81 of the HTTP request 80 of the connection request received from the image forming apparatus 50 (S105). That is, the connection request forwarding unit 35a acquires the path of the pre-forwarding URL.
[0063] The connection request forwarding unit 35a determines in S104 that the condition regarding the path included in the request line 81 of the HTTP request 80 is not included in the forwarding conditions of the current target, or when the processing of S105 is completed, determines whether or not the condition regarding the header value in the header field 82 of the HTTP request 80 is included in the forwarding conditions of the current target (S106).
[0064] When the connection request forwarding unit 35a determines in S106 that the condition related to the header value in the header field 82 of the HTTP request 80 is included in the current target forwarding conditions, it obtains the header value related to the current target forwarding conditions from the header field 82 of the HTTP request 80 of the connection request received from the image forming device 50 (S107).
[0065] When the connection request transfer unit 35a determines in S106 that the condition related to the header value in the header field 82 of the HTTP request 80 is not included in the forwarding conditions of the current target, or when the process of S107 ends, it determines whether the forwarding conditions of the current target are satisfied (S108). Here, when the connection request transfer unit 35a acquires a path in S105, it determines whether the forwarding conditions of the current target are satisfied based at least on the path acquired in S105. Similarly, when the connection request transfer unit 35a acquires a value in S107, it determines whether the forwarding conditions of the current target are satisfied based at least on the value acquired in S107.
[0066] If the connection request forwarding unit 35a determines in S108 that the current target forwarding condition is not satisfied, it executes the process of S102.
[0067] When the connection request forwarding unit 35a determines in S108 that the forwarding condition of the current target is satisfied, it determines whether or not the prohibition condition associated with the forwarding condition of the current target in the forwarding rule 41 acquired in S101 is satisfied (S109). Here, when the prohibition condition associated with the forwarding condition of the current target in the forwarding rule 41 acquired in S101 includes the IP address of the connection source, the connection request forwarding unit 35a may use the IP address of the connection source notified from the connection source in S109. For example, when the IP address of the connection source is included in the header field 82 of the HTTP request 80, the connection request forwarding unit 35a may acquire the IP address of the connection source from the header field 82 in S109. When the prohibition condition associated with the forwarding condition of the current target in the forwarding rule 41 acquired in S101 includes a tenant ID, the connection request forwarding unit 35a may acquire the value of the tenant-id header 82b in the header field 82 of the HTTP request 80 as the tenant ID in S109. If a user ID is included in the prohibited condition associated with the current target transfer condition in the transfer rules 41 acquired in S101, the connection request transfer unit 35a may acquire, as the user ID, in S109, the value of the user-id header 82d in the header field 82 of the HTTP request 80. If there is no prohibited condition associated with the current target transfer condition in the transfer rules 41 acquired in S101, the connection request transfer unit 35a determines in S109 that the prohibited condition is not met.
[0068] If the connection request forwarding unit 35a determines in S109 that the prohibition condition associated with the current target forwarding condition in the forwarding rule 41 acquired in S101 is satisfied, the connection request forwarding unit 35a executes the process of S102.
[0069] When the connection request transfer unit 35a determines in S109 that the prohibition condition associated with the current target transfer condition in the transfer rules 41 acquired in S101 is not satisfied, it determines whether an instruction to edit the path is associated with the current target transfer condition in the transfer rules 41 (S110).
[0070] When the connection request forwarding unit 35a determines in S110 that an instruction to edit a path is associated with the current target forwarding condition in the forwarding rule 41, it edits the path included in the request line 81 of the HTTP request 80 in accordance with the editing instruction associated with the current target forwarding condition in the forwarding rule 41 (S111). For example, if the forwarding rule 41 acquired in S101 is the one shown in Fig. 4 and the request line 81 of the HTTP request 80 is "GET / eu / HTTP / 1.1", when the forwarding condition with ID "001" is the current target forwarding condition, the connection request forwarding unit 35a edits the request line 81 of the HTTP request 80 to "GET / HTTP / 1.1" by the process of S111.
[0071] When the connection request forwarding unit 35a determines in S110 that the path editing instruction is not associated with the current target forwarding condition in the forwarding rules 41, or when the processing of S111 is completed, it identifies a forwarding destination that is associated with the current target forwarding condition in the forwarding rules 41 acquired in S101 (S112).
[0072] When the process of S112 is completed, the connection request transfer unit 35a transfers the HTTP request 80 to the image processing system cluster identified as the transfer destination in S112 (S113), and ends the operation shown in FIG.
[0073] If the connection request forwarding unit 35a determines in S102 that there are no forwarding conditions in the forwarding rules 41 acquired in S101 that have not yet been targeted in the current operation shown in FIG. 5, it issues an error response such as “404 not found” to the image forming device 50 that is the connection source (S114), and terminates the operation shown in FIG. 5.
[0074] Fig. 6(a) is a diagram showing an example of an HTTP request 80 of a connection request sent to a pre-transfer URL, which is different from the example shown in Fig. 3(b). Fig. 6(b) is a diagram showing an example of an HTTP request 80 that is transferred to an image processing system cluster by the connection request transfer unit 35a that has received the HTTP request 80 shown in Fig. 6(a).
[0075] When the connection request forwarding unit 35a receives the HTTP request 80 shown in FIG. 6(a) from the forwarding source whose IP address is "192.0.2.50" in the case where the forwarding rule 41 is the one shown in FIG. 4, the forwarding condition whose ID is "003" is satisfied (YES in S108), the prohibition condition is not satisfied (NO in S109), and the forwarding condition whose ID is "003" is not associated with an instruction to edit the path in the forwarding rule 41 (NO in S110), based at least on the value of the tenant-id header 82b in the header field 82 of the HTTP request 80. Therefore, the connection request forwarding unit 35a rewrites the Host header 82a of the HTTP request 80 from "Host:example.net" (see FIG. 6(a)) to "Host:companyA.example.com" (see FIG. 6(b)), which indicates the domain name of the forwarding destination associated with the forwarding condition whose ID is "003", and then forwards the HTTP request 80 shown in FIG. 6(b) (S113).
[0076] Fig. 7(a) is a diagram showing an example of an HTTP request 80 of a connection request sent to a pre-transfer URL, which is different from the examples shown in Fig. 3(b) and Fig. 6(a). Fig. 7(b) is a diagram showing an example of an HTTP request 80 that is transferred to an image processing system cluster by the connection request transfer unit 35a that has received the HTTP request 80 shown in Fig. 7(a).
[0077] When the connection request forwarding unit 35a receives the HTTP request 80 shown in FIG. 7(a) from the forwarding source whose IP address is "192.0.2.60" in the case where the forwarding rule 41 is the one shown in FIG. 4, the connection request forwarding unit 35a determines that, based on at least the path included in the request line 81 of the HTTP request 80, the forwarding condition whose ID is "001" is satisfied (YES in S108), the prohibition condition is not satisfied (NO in S109), and an instruction to edit the path is associated with the forwarding condition whose ID is "001" in the forwarding rule 41 (YES in S110). ), then " / eu" is removed from the path included in the target 81b of the request line 81 of the HTTP request 80 as shown in FIG. 7(b) (S111), and the Host header 82a of the HTTP request 80 is rewritten from "Host:example.net" (see FIG. 7(a)) to "Host:eu.example.com" (see FIG. 7(b)), which indicates the destination domain name associated with the forwarding condition whose ID is "001", and the HTTP request 80 shown in FIG. 7(b) is forwarded (S113).
[0078] Fig. 8(a) is a diagram showing an example of an HTTP request 80 of a connection request sent to a pre-transfer URL, which is different from the examples shown in Fig. 3(b), Fig. 6(a) and Fig. 7(a). Fig. 8(b) is a diagram showing an example of an HTTP request 80 that is transferred to an image processing system cluster by the connection request transfer unit 35a that has received the HTTP request 80 shown in Fig. 8(a).
[0079] When the connection request forwarding unit 35a receives the HTTP request 80 shown in FIG. 8(a) from a source whose IP address is "192.0.2.40" in the case where the forwarding rule 41 is as shown in FIG. 4, the forwarding condition whose ID is "004" is satisfied based on at least the value of the function header 82c in the header field 82 of the HTTP request 80 (YES in S108), but the prohibition condition is also satisfied based on the IP address of the source (YES in S109), so the connection request forwarding unit 35a does not forward the HTTP request 80 to the destination associated with the forwarding condition whose ID is "004". Then, since the transfer condition with ID "005" is satisfied (YES in S108), the prohibition condition is not satisfied (NO in S109), and an instruction to edit the path is not associated with the transfer condition with ID "005" in the transfer rules 41 (NO in S110), the connection request transfer unit 35a rewrites the Host header 82a of the HTTP request 80 from "Host:example.net" (see FIG. 8(a)) to "Host:as.example.com" (see FIG. 8(b)), which indicates the transfer destination domain name associated with the transfer condition with ID "005", and then transfers the HTTP request 80 shown in FIG. 8(b) (S113).
[0080] As described above, when the transfer conditions are met based at least on the HTTP request 80 of the connection request from the connection source (YES in S108) but the prohibition conditions are not met (NO in S109), the gateway 30 transfers the connection request to the information processing system as the transfer destination corresponding to the transfer conditions (S112 and S113). Even when the transfer conditions are met based at least on the HTTP request 80 of the connection request from the connection source (YES in S108), the gateway 30 does not transfer the connection request if the prohibition conditions are met (YES in S109). Therefore, the connection request from the connection source can be transferred to an image processing system cluster among multiple image processing system clusters according to the content of the connection request.
[0081] Since the prohibition conditions of the gateway 30 include a condition that the IP address of the connection source is a specific IP address (the prohibition conditions are associated in the transfer rules 41 with the transfer conditions whose IDs are "001", "002", or "004"), even if the transfer conditions are satisfied based at least on the HTTP request 80 of the connection request from the connection source, the gateway 30 does not transfer the connection request from the specific IP address, and as a result, the gateway 30 can transfer the connection request from the connection source to an appropriate image processing system cluster with a simple configuration. Since the gateway 30 does not transfer connection requests from specific IP addresses, it is possible not to transfer connection requests from areas corresponding to specific IP addresses.
[0082] Since the prohibition condition of the gateway 30 includes a condition that the HTTP request 80 contains a specific character string indicating a specific tenant using the image processing system cluster (the prohibition condition is associated in the transfer rule 41 with the transfer condition whose ID is "001" or "004"), even if the transfer condition is satisfied based at least on the HTTP request 80 of the connection request from the connection source, the gateway 30 does not transfer the connection request to the specific tenant, and as a result, the connection request from the connection source can be transferred to the appropriate image processing system cluster with a simple configuration.
[0083] Since the prohibition condition of the gateway 30 includes a condition that the HTTP request 80 contains a specific character string indicating a specific user using the image processing system cluster (the prohibition condition is associated in the transfer rule 41 with the transfer condition whose ID is "002" or "003"), the gateway 30 does not transfer the connection request from the specific user even if the transfer condition is satisfied based at least on the HTTP request 80 of the connection request from the connection source, and as a result, the connection request from the connection source can be transferred to the appropriate image processing system cluster with a simple configuration.
[0084] 4 includes a transfer condition related only to the region among the region, tenant ID, and function (a transfer condition with an ID of "001" or "002"), a transfer condition related only to the tenant ID among the region, tenant ID, and function (a transfer condition with an ID of "003"), and a transfer condition related only to the function among the region, tenant ID, and function (a transfer condition with an ID of "004"). However, the transfer rule 41 may include at least one of a transfer condition related to all of the region, tenant ID, and function, a transfer condition related only to the region and tenant ID among the region, tenant ID, and function, a transfer condition related only to the region and function among the region, tenant ID, and function, and a transfer condition related only to the tenant ID and function among the region, tenant ID, and function. For example, possible transfer conditions relating only to region and function among region, tenant ID, and function include the transfer condition "the path included in request line 81 of HTTP request 80 of the connection request from the connection source contains a string indicating a specific region," or "the value of a specific header in header field 82 of HTTP request 80 of the connection request from the connection source contains a string indicating a specific function of the image processing system cluster," or "the path included in request line 81 of HTTP request 80 of the connection request from the connection source contains a string indicating a specific region, and the value of a specific header in header field 82 of this HTTP request 80 contains a string indicating a specific function of the image processing system cluster."
[0085] The transfer rules 41 may be set so that the transfer condition related to the tenant ID and all of the functions is applied with the highest priority among the transfer condition related to all of the tenant IDs and functions, the transfer condition related to only the tenant ID among the tenant IDs and functions, and the transfer condition related to only the functions among the tenant IDs and functions.The transfer rules 41 may be set so that the transfer condition related to only the tenant ID among the tenant IDs and functions is applied with the highest priority among the transfer condition related to only the tenant ID among the tenant IDs and functions, and the transfer condition related to only the functions among the tenant IDs and functions.
[0086] In the above, a case has been described in which the header field 82 includes the tenant-id header 82b and the function header 82c. However, at least one of the tenant-id header 82b and the function header 82c does not have to be included in the header field 82. For example, if the header field 82 does not include the tenant-id header 82b, the pre-transfer URL and the HTTP request 80 may be as shown in FIG.
[0087] Fig. 9(a) is a diagram showing an example of a pre-transfer URL different from the example shown in Fig. 3(a). Fig. 9(b) is a diagram showing an example of an HTTP request 80 different from the example shown in Fig. 3(b).
[0088] In the "tenant-id" of the pre-transfer URL "https: / / example.net / region / tenant-id / " shown in Fig. 9(a), a specific character string indicating a tenant ID, such as "000-111-333," is actually described. The header field 82 of the HTTP request 80 shown in Fig. 9(b) does not include the tenant-id header 82b (see Fig. 3).
[0089] When the pre-transfer URL and the HTTP request 80 are as shown in FIG. 9, the transfer rule 41 may be as shown in FIG.
[0090] FIG. 10 is a diagram showing an example of a transfer rule 41 that is different from the transfer rule 41 shown in FIG.
[0091] The transfer condition with ID "003" in the transfer rule 41 shown in FIG. 10 is a condition that the path included in the request line 81 of the HTTP request 80 contains the character string " / 000-111-333 / ".
[0092] When the transfer rule 41 shown in FIG. 10 is used, the connection request transfer unit 35a uses the tenant ID included in the path included in the request line 81 of the HTTP request 80 in S109.
[0093] In the above, the transfer condition has been described as a condition related to the value of the tenant-id header 82b in the header field 82 of the HTTP request 80 and a condition related to the value of the function header 82c in the header field 82 of the HTTP request 80. However, a condition related to the value of a specific header other than the tenant-id header 82b and the function header 82c in the header field 82 of the HTTP request 80 may be set as the transfer condition.
[0094] In the above, the following prohibition conditions have been described: a condition on a character string indicating a tenant ID included in a path included in a request line 81 of an HTTP request 80; a condition on a value of a tenant-id header 82b in a header field 82 of an HTTP request 80; and a condition on a value of a user-id header 82d in a header field 82 of an HTTP request 80. However, as a prohibition condition, a condition on a specific character string other than a tenant ID included in a path included in a request line 81 of an HTTP request 80 may be set, or a condition on a value of a specific header other than the tenant-id header 82b or the user-id header 82d may be set.
[0095] The image processing system cluster may operate in a multi-tenant model in this embodiment, however, the image processing system cluster may also operate in a single-tenant model where the image processing system cluster is used by one tenant.
[0096] In this embodiment, the information processing system of the present invention is an image processing system cluster, however, the information processing system of the present invention does not have to be one that executes image processing. [Explanation of symbols]
[0097] 20. Image Processing System Cluster (Information Processing System) 30 Gateway (Connection Request Forwarding System, Computer) 34a Connection request forwarding program 50 Image forming device (connection source) 60 Computer (source) 70 External system (connection source) 80 HTTP requests
Claims
1. A connection request forwarding system that forwards a connection request from a connection source to any one of a plurality of information processing systems, when a transfer condition as a condition for transferring the connection request is satisfied based on at least an HTTP request of the connection request, and a prohibition condition as a condition for prohibiting the transfer of the connection request is not satisfied, transfer the connection request to the information processing system as a transfer destination associated with the transfer condition; 13. A connection request forwarding system, comprising: a connection request forwarding unit that forwards a connection request to a server that has a connection terminal and a forwarding condition that is satisfied based on at least the HTTP request, the connection request being forwarded when the prohibition condition is satisfied.
2. 2. The connection request transfer system according to claim 1, wherein the prohibition condition includes a condition that the IP address of the connection source is a specific IP address.
3. 2. The connection request transfer system according to claim 1, wherein the prohibition condition includes a condition that the HTTP request contains a specific character string.
4. 4. The connection request transfer system according to claim 3, wherein the specific character string includes a character string that indicates a specific tenant that uses the information processing system.
5. 4. The connection request transfer system according to claim 3, wherein the specific character string includes a character string that indicates a specific user who uses the information processing system.
6. A connection request forwarding program for forwarding a connection request from a connection source to any one of a plurality of information processing systems, when a transfer condition as a condition for transferring the connection request is satisfied based on at least an HTTP request of the connection request, and a prohibition condition as a condition for prohibiting the transfer of the connection request is not satisfied, causing a computer to transfer the connection request to the information processing system as a transfer destination associated with the transfer condition; A connection request forwarding program, characterized in that even if the forwarding condition is satisfied based on at least the HTTP request, when the prohibition condition is satisfied, the connection request is not forwarded to the computer.
Citation Information
Patent Citations
Coloring machining method of wood such as lumber from thinning
JP1986061803A
Server device, client device, and data processing system
JP2019139691A
System and method for virtual session connections using component-based connection leasing
JP7111912B2