Device management system, management apparatus, and program

The device management system addresses the challenge of ensuring security policy compliance by users outside an organization by comparing user and organization authentication policies within the system, thereby guaranteeing policy-compliant operations on managed equipment.

JP2025074528APending Publication Date: 2025-05-14BUFFALO CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023185379
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-30
Publication Date
2025-05-14

AI Technical Summary

Technical Problem

Existing security systems struggle to ensure compliance with an organization's security policy when outsourcing equipment management to users outside the organization, as there is no guaranteed authentication of these users according to the organization's policies.

Method used

A device management system that includes a management device capable of holding user authentication policy information, organization authentication policy information, and a device information database. This system compares the authentication policies of users with those of the organizations owning the devices, determining whether users are permitted to operate designated devices based on policy compliance.

Benefits of technology

The system ensures that users outside the organization comply with the security policies specified by the organization, even when managing equipment, by authenticating users according to the organization's defined policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025074528000001_ABST
    Figure 2025074528000001_ABST
Patent Text Reader

Abstract

To provide a device management system, a management apparatus, and a program with which compliance with a security policy specified in an organization can be enforced for outsourcing users outside the organization.SOLUTION: In a device management system 1, a device management apparatus 30P which manages devices 10a, 10b, ... to be operated is configured to: hold user authentication policy information related to authentication policy for each user, organization authentication policy information related to authentication policy for each organization, and a device information database formed by associating information identifying an organization that is an owner with each of the devices to be operated; identify, when receiving a designation of a device to be operated from a user, an organization of an owner for the device to be operated; compare the authentication policy related to the specified organization with the authentication policy of the user; and determine whether to permit the user to operate the device designated by the user for operation, on the basis of a result of the comparison.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a device management system, a management apparatus, and a program. [Background technology]

[0002] In recent years, various security systems have been developed and used. Patent Document 1 discloses a technique in which an authentication server measures the elapsed time from the time when it received an authentication request, and performs a second authentication process based on an authentication code received from a client terminal and a stored authentication code. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-144598 Summary of the Invention [Problem to be solved by the invention]

[0004] However, because there are a wide variety of security measures, even if an organization has established a security policy, if the organization entrusts the management of its devices to a user outside the organization, there is a problem in that it cannot guarantee that the user outside the organization has been authenticated in accordance with the organization's security policy.

[0005] The present invention has been made in consideration of the above-mentioned situation, and one of its objectives is to provide a device management system, management device, and program that can require compliance with the security policy defined by an organization even when work is outsourced to a user outside the organization. [Means for solving the problem]

[0006] One aspect of the present invention for solving the problems of the conventional examples is a device management system including a management device that manages devices to be operated and a user's terminal, the management device including: a storage means for storing user authentication policy information related to an authentication policy for each user, organization authentication policy information related to an authentication policy for each organization, and a device information database in which information identifying an organization that is an owner of each device to be operated is associated with each other; a comparison means for receiving designation of a device to be operated from a user of the terminal, identifying the organization that is the owner of the specified device by referring to the device information database, and comparing the authentication policy related to the identified organization with the authentication policy of the user; and a judgment means for judging, based on a result of the comparison by the comparison means, whether to grant the authenticated user permission to operate the device specified by the user as the device to be operated.

[0007] According to this aspect of the present invention, even when a task is outsourced to a user outside the organization, it is possible to require compliance with the security policy defined by the organization.

[0008] Another aspect of the present invention for solving the problems of the conventional examples is a management device for managing devices to be operated, comprising: a storage means for storing user authentication policy information related to an authentication policy for each user, organization authentication policy information related to an authentication policy for each organization, and a device information database in which information identifying the organization that is the owner of each device to be operated is associated with each other; a comparison means for receiving designation of a device to be operated from a user, identifying the organization of the owner of the designated device by referring to the device information database, and comparing the authentication policy related to the identified organization with the authentication policy of the user; and a determination means for determining whether or not to grant the authenticated user permission to operate the device designated by the user as the device to be operated, based on a result of the comparison by the comparison means.

[0009] According to this aspect of the present invention, even when the organization that is the owner outsources work to a user outside the organization, it is possible to require that the user comply with the security policy defined by the organization.

[0010] Here, the device information database further includes a setting means for setting administrator information that is associated with the device to be operated and identifies an administrator organization that can operate and view the device, and this setting means may prevent multiple administrator organizations from being set in association with the device to be operated if information identifying the organization that owns the device is not associated with the device to be operated.

[0011] According to this embodiment, it is possible to control so that multiple administrator organizations cannot be set until an owner organization is associated.

[0012] In addition, if the organization of the owner of the designated device is not held in the device information database, the comparison means may output information indicating that fact, and the judgment means, upon receiving the information that the organization of the owner of the designated device is not held in the device information database, may grant the authenticated user permission to operate the device that the user has designated as the target to be operated.

[0013] According to this embodiment, the device can be operated regardless of the authentication policy until the owner organization is associated with the device.

[0014] In still another aspect of the present invention, the authentication policy for each user and the authentication policy for each organization each include information regarding at least one authentication method requested at the time of authentication, and the comparison means receives designation of a device to be operated from the authenticated user, identifies the organization of the owner of the designated device by referring to the device information database, and compares the authentication method specified by the information contained in the authentication policy for the identified organization with the authentication method specified by the information contained in the authentication policy of the user, and when the authentication methods specified by the information contained in the authentication policy of the identified organization are all included in the authentication methods specified by the information contained in the authentication policy of the identified organization, the determination means grants the authenticated user permission to operate the device designated by the user as the device to be operated.

[0015] According to this embodiment, even when the organization that is the owner outsources a task to a user outside the organization, it is possible to require that the user comply with the security policy defined by the organization.

[0016] Here, the authentication methods included in the authentication policy may include at least an authentication method using multi-factor authentication.

[0017] The system may further include an authentication means for authenticating the user based on an authentication policy of the user, and the comparison means may receive a designation of a device to be operated from the authenticated user, identify the organization of the owner of the designated device by referring to the device information database, and compare the authentication policy of the identified organization with the authentication policy of the user.

[0018] In this example, the authentication policy of the authenticated user is compared with the authentication policy of the owner organization, so that even when the owner organization outsources work to a user outside the organization, the user can be made to comply with the security policy defined by the organization.

[0019] Furthermore, the determination means may determine, based on a result of the comparison by the comparison means, whether or not to permit the authenticated user to perform a predetermined operation on a device designated by the authenticated user as an operation target.

[0020] According to this example, whether or not an operation is permissible is determined for each operation, and even when various tasks are entrusted to users outside the organization, the security policy defined by the organization can be complied with.

[0021] Another aspect of the present invention is a program that causes a computer managing a device to be operated to function as: a storage means for storing user authentication policy information related to an authentication policy for each user, organization authentication policy information related to an authentication policy for each organization, and a device information database in which information identifying the organization that is the owner of each device to be operated is associated; a comparison means for receiving a device to be operated from a user, identifying the organization of the owner of the specified device by referring to the device information database, and comparing the authentication policy related to the identified organization with the authentication policy of the user; and a determination means for determining whether or not to grant the user permission to operate the device specified by the user as the device to be operated, based on a result of the comparison by the comparison means.

[0022] According to this aspect of the present invention, even when a task is outsourced to a user outside the organization, it is possible to require compliance with the security policy defined by the organization. Effect of the Invention

[0023] In this way, according to the present invention, even when work is outsourced to a user outside the organization, it is possible to require compliance with the security policy defined by the organization. [Brief description of the drawings]

[0024] [Figure 1] 1 is a block diagram illustrating an example of a configuration of a device management system according to an embodiment of the present invention. [Diagram 2]1 is a functional block diagram illustrating an example of a device management device according to an embodiment of the present invention. [Diagram 3] FIG. 4 is a flowchart illustrating an example of the operation of the device management system according to the embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0025] An embodiment of the present invention will be described with reference to the drawings. As shown in Fig. 1, a device management system 1 according to the embodiment of the present invention includes operation target devices 10a, 10b... to be operated, user terminals 20a, 20b... used by users belonging to each organization, and a management device 30, which are connected to each other so as to be able to communicate with each other via a communication means such as a network. The management device 30 may be configured to include a device management device 30P and a user management device 30U.

[0026] The operation target devices 10 (hereinafter, when there is no need to distinguish between the individual operation target devices 10a, b, ..., they will be collectively referred to as device 10) are computer-controlled wireless communication devices, storage devices, etc., which receive instructions for settings, etc. from the management device 30 via a communication means such as a network, and operate in accordance with the instructions.

[0027] The user terminal 20 is a personal computer or the like, and is used by a user belonging to each organization. In one example of this embodiment, the user terminal 20 responds to a request from the user, is authenticated by the management device 30, and issues a request to the management device 30 to operate the device 10 to be operated by specifying the device 10 to be operated.

[0028] The equipment management device 30P and the user management device 30U of the management device 30 are server devices or the like, and each includes a control unit 31, a storage unit 32, and a communication unit 33 as illustrated in FIG.

[0029] The memory unit 32P of the equipment management device 30P (hereinafter, when distinguishing between the various parts, the various parts of the equipment management device 30P will be given the suffix P, and the various parts of the user management device 30U will be given the suffix U) holds an equipment information database and a user database.

[0030] Here, for each operation target device 10, if there is an organization of a manager who manages the operation target device 10, the device information database stores manager organization identification information that identifies the manager organization in association with the device identification information of the operation target device 10. Furthermore, if there is an organization that is the owner of the operation target device 10, this device information database stores owner organization identification information that identifies the owner organization in association with the device identification information that identifies the device. If multiple organizations that are managers are associated with one device, the association of the owner organization may be required. Note that this device information database may further store information regarding the settings for each operation target device 10.

[0031] The user database stored in the storage unit 32P of the device management device 30P holds user identification information for identifying a user and operation authority information for specifying operations permitted to the user, in association with each other.

[0032] The storage unit 32U of the user management device 30U holds an authentication database that stores authentication information for each user, an organization identification database that associates the user identification information with organization identification information that represents the organization to which the user belongs, a user policy database that associates the user identification information with user authentication policy information that represents the authentication policy of the user, and an organization information database that associates, for each organization, organization identification information that identifies the organization with organization authentication policy information that represents the authentication policy of the organization. Note that the authentication information for each user is information used for passwords and multi-factor authentication, etc., that is associated with the user identification information that identifies the user, and the type of information varies depending on the authentication policy of each user.

[0033] Here, the authentication policy of a user or an organization includes information that defines at least one authentication method required for user authentication. Specifically, the authentication policy includes information such as "single-factor authentication" that performs authentication using one type of authentication method, such as user identification information and a password, and "two-factor authentication" that uses two types of authentication methods, such as a biometric authentication method such as a fingerprint or a one-time password in addition to user identification information and a password (here, two-factor authentication is one aspect of multi-factor authentication). A user who belongs to an organization does not necessarily need to set user authentication policy information, but when individual user authentication policy information is set, this user authentication policy information includes at least an authentication method specified in the organization authentication policy information of the organization to which the user belongs.

[0034] For example, when the authentication method specified in the organization authentication policy information of an organization is "two-factor authentication", the user authentication policy information of a user belonging to the organization is not allowed to be "single-factor authentication" (because "two-factor authentication" is not included). On the other hand, when the authentication method specified in the organization authentication policy information of an organization is "single-factor authentication", the user authentication policy information of a user belonging to the organization is allowed to be either "single-factor authentication" or "two-factor authentication". The management device 30 (e.g., the user management device 30U) may allow or disallow such settings.

[0035] The control unit 31 is a program control device (processor) such as a CPU, and operates according to a program stored in the storage unit 32. In one aspect of this embodiment, the control unit 31P of the equipment management device 30P accepts a designation of the operation target equipment 10 to be operated from the user of the user terminal 20. The control unit 31P then identifies the organization of the owner of the designated operation target equipment 10 by referring to the equipment information database. The control unit 31P acquires and compares an authentication policy of the identified organization with an authentication policy of the user of the user terminal 20 from the user management device 30U, and determines whether or not to grant the authenticated user permission to operate the equipment designated as the user operation target based on the result of the comparison. The specific processing contents of this control unit 31P will be described later.

[0036] The storage unit 32 includes a memory device and a disk device. As already described, various databases are held in this storage unit 32. The storage unit 32 also holds a program executed by the control unit 31. This program may be provided by being stored in a computer-readable and non-transitory recording medium, and may be stored in this storage unit 32. Furthermore, the storage unit 32 also operates as a work memory for the control unit 31.

[0037] The communication unit 33 is a network interface or the like, and sends and receives various information between external devices connected via a network, such as the user terminal 20 and the target device 10, in accordance with instructions input from the control unit 31.

[0038] Next, the operation of control unit 31P of device management device 30P will be described. This control unit 31P operates according to a program stored in storage unit 32P, thereby realizing a configuration that functionally includes authentication unit 311, acceptance unit 312, comparison unit 313, judgment unit 314, and operation instruction unit 315, as illustrated in FIG.

[0039] The authentication unit 311 authenticates each user who operates the user terminals 20a, b, etc. This authentication is performed according to a preset authentication policy. Specifically, the authentication unit 311 accepts an authentication request together with user identification information from the user terminal 20, and acquires organization identification information, user authentication policy information, and authentication information associated with the user identification information from the user management device 30U.

[0040] The authentication unit 311 authenticates the user of the user terminal 20 that has made the authentication request according to the acquired user authentication policy information. For example, if the acquired user authentication policy information is "single-factor authentication", the authentication unit 311 accepts the user identification information and password information input from the user terminal 20, compares it with the authentication information acquired from the user management device 30U, and performs authentication processing. This authentication processing can employ widely known authentication processing using user identification information and password information, so a detailed description will be omitted here.

[0041] Furthermore, if the user authentication policy information acquired here is "two-factor authentication" or the like, the authentication unit 311 accepts the user identification information and password information input from the user terminal 20 that made the authentication request, performs authentication processing using these, and uses the authentication information to perform processing for two-factor authentication (such as sending a one-time password to a mobile phone short mail associated with the user identification information). A widely known method can be used for this two-factor authentication processing, so a detailed explanation will be omitted here.

[0042] Furthermore, if a different authentication method is set by the user authentication policy information, the authentication unit 311 may execute a process for the set authentication method.

[0043] When the authentication unit 311 succeeds in authenticating a user (authenticates the user according to the authentication policy), it associates the user identification information of the successfully authenticated user with information identifying the user terminal 20 used by the user, and accumulates and holds the information in a list of authenticated users (session list). When the successfully authenticated user makes a logout request, or after a predetermined time has elapsed after the successful authentication (such as when the session is disconnected), the authentication unit 311 may delete the user identification information of the user and the information identifying the associated user terminal 20 from the list of authenticated users.

[0044] The receiving unit 312 receives, from the user terminal 20, device identification information for identifying the device 10 to be operated and a request for operating the device 10 to be operated.

[0045] The comparison unit 313 compares the authentication policy related to the organization of the owner of the operation target device 10 designated as the target of operation with the authentication policy of the user of the user terminal 20. Specifically, as illustrated in Fig. 3, when the acceptance unit 312 accepts an operation request, the comparison unit 313 refers to the device information database and acquires the owner organization identification information and the administrator organization identification information stored in the storage unit 32P in association with the device identification information accepted by the acceptance unit 312 (S11).

[0046] Here, the comparison unit 313 checks whether the user of the user terminal 20 that made the request to the acceptance unit 312 belongs to an organization identified by either the owner organization identification information or the administrator organization identification information acquired in step S11 (the organization in which the user is the owner or the organization in which the user is set as the administrator), and if the user does not belong to the organization, the comparison unit 313 may not execute the following processing.

[0047] If the requesting user belongs to an organization that is the owner of the operation target device 10 specified as the target of operation or an organization that is set as the administrator, the comparison unit 313 determines whether or not the owner organization identification information was acquired in step S11 (whether or not an owner organization was set) (S12), and if acquired (S12: Yes), acquires organization authentication policy information associated with the owner organization identification information (hereinafter referred to as owner organization authentication policy information) from the user management device 30U (S13).

[0048] The comparison unit 313 also acquires, from the user management device 30U, user authentication policy information associated with the user identification information of the user of the user terminal 20 that has requested the operation on the operation target device 10 (S14). Note that the user identification information of the user of the user terminal 20 may be acquired by referring to a list of authenticated users.

[0049] The comparison unit 313 then compares the acquired user authentication policy information with the owner organization authentication policy information (S15) to check whether the user has been authenticated in accordance with the owner organization authentication policy information, that is, whether the authentication methods represented by the owner organization authentication policy information are all included in the authentication methods represented by the user authentication policy information.

[0050] If all authentication methods represented by the owner organization authentication policy information are included in the authentication methods represented by the user authentication policy information (S15: Yes), the comparison unit 313 outputs information indicating that the user has been authenticated according to the owner organization authentication policy information (hereinafter referred to as authentication level conformance information) (S16). On the other hand, if any authentication method represented by the owner organization authentication policy information is not included in the authentication methods represented by the user authentication policy information (S15: No), the comparison unit 313 outputs information indicating that the user has not been authenticated according to the owner organization authentication policy information (hereinafter referred to as authentication level non-conformance information) (S17).

[0051] for example, (1) If the authentication method represented by the owner organization authentication policy information to be compared by the comparison unit 313 is "single-factor authentication" and the authentication method represented by the user authentication policy information is "two-factor authentication," the comparison unit 313 will output authentication level conformance information because the authentication methods represented by the owner organization authentication policy information are all included in the authentication methods represented by the user authentication policy information. (2) Even when the authentication method represented by the owner organization authentication policy information to be compared by the comparison unit 313 is "two-factor authentication" and the authentication method represented by the user authentication policy information is "two-factor authentication," the comparison unit 313 outputs authentication level conformance information because the authentication methods represented by the owner organization authentication policy information are all included in the authentication methods represented by the user authentication policy information. (3) When the authentication method represented by the owner organization authentication policy information to be compared by the comparison unit 313 is “two-factor authentication” and the authentication method represented by the user authentication policy information is “single-factor authentication,” “two-factor authentication” among the authentication methods represented by the owner organization authentication policy information is not included in the authentication methods represented by the user authentication policy information, so the comparison unit 313 outputs authentication level non-compliance information.

[0052] Furthermore, when the comparison unit 313 determines that it was unable to obtain the owner organization identification information in step S12, that is, if the owner organization identification information was not stored in the device information database in association with the device identification information in step S11 (S12: No), it outputs information to that effect (called owner absent information) (S21).

[0053] The judgment unit 314 judges whether or not to permit the request for operation of the operation target device 10 accepted by the acceptance unit 312 from the user terminal 20 (whether or not to grant permission to operate the device) based on the result of the comparison in the comparison unit 313. That is, in one example of this embodiment, when the comparison unit 313 is outputting authentication level conformity information (step S17), the judgment unit 314 permits the request for operation of the operation target device 10 accepted by the acceptance unit 312 from the user terminal 20, and causes the operation instruction unit 315 to send an instruction based on the content of the operation represented by the information accepted from the user terminal 20 to the operation target device 10 specified by the information accepted from the user terminal 20 (S19).

[0054] In addition, when the comparison unit 313 outputs authentication level non-compliance information (step S18), the judgment unit 314 executes processing such as not allowing the request for operation on the target device 10 accepted by the acceptance unit 312 from the user terminal 20, and notifying the user terminal 20 that originated the operation request of an error (S20).

[0055] Furthermore, when the comparison unit 313 outputs owner absence information (step S18), the judgment unit 314 proceeds to step S19 and causes the operation instruction unit 315 to send an instruction based on the content of the operation represented by the information accepted from the user terminal 20 to the target device 10 identified by the information accepted from the user terminal 20.

[0056] In addition, the judgment unit 314 may refer not only to the result of the comparison by the comparison unit 313 but also to information regarding permission or denial of operation set for each user to judge whether or not to permit the request for operation of the target device 10 accepted by the acceptance unit 312 from the user terminal 20 (whether or not to grant permission to operate the device).

[0057] For example, in the process of step S19, the determination unit 314 does not immediately send an instruction to the operation instruction unit 315, but refers to the user database stored in the storage unit 32P and acquires operation authority information that is associated with the user identifier of the user who requested the operation and that specifies the operation permitted for that user. Then, the determination unit 314 in this example judges whether the requested operation is included in the acquired operation authority information.

[0058] When the determination unit 314 determines that the requested operation is included in the acquired operation authority information, it permits the request for operation on the operation target device 10 accepted by the acceptance unit 312 from the user terminal 20. When the determination unit 314 determines that the requested operation is not included in the acquired operation authority information, it does not permit the request for operation on the operation target device 10 accepted by the acceptance unit 312 from the user terminal 20, and executes processing such as notifying an error to the user terminal 20 that has requested the operation.

[0059] When the judgment unit 314 judges that the request for operation on the target device 10 accepted from the user terminal 20 is permitted, the operation instruction unit 315 sends an instruction to the target device 10 identified by the information accepted from the user terminal 20, based on the content of the operation represented by the information accepted from the user terminal 20.

[0060] In still another example, the comparison unit 313 may control whether or not to perform the comparison process illustrated in FIG. 3 based on the content of the request for operation on the operation target device 10 accepted by the acceptance unit 312.

[0061] For example, in one example of this embodiment, if the content of a request for an operation on the operation target device 10 accepted from the user side device 20 is included in a predetermined list (called an authentication exception list), the device management device 30P permits the request for an operation on the operation target device 10 without performing the comparison process exemplified in Fig. 3. Specifically, this authentication exception list includes operations such as "display list of operation target devices."

[0062] In this case, the equipment management device 30P sends an instruction based on the content of the operation represented by the information accepted from the user terminal 20, without performing a process of comparing the user's user authentication policy information with the owner organization's organization authentication policy information.

[0063] On the other hand, even in this example, if the content of the operation request for the target device 10 accepted from the user device 20 is not included in the authentication exception list (for example, if it is a setting change operation, etc.), the device management device 30P executes the comparison process illustrated in Figure 3 as in the above example to determine whether or not to allow the operation.

[0064] [Operation] The device management system 1 of this embodiment basically has the above-mentioned configuration and operates as follows.

[0065] In the following example, The target devices 10 are devices 10a, 10b, and 10c. Of these, the device 10a is as follows: The administrators are Organization A and Organization X (hereinafter referred to as "Administrators: Organization A, Organization X"). Also, The owner is Organization A (hereinafter referred to as "Owner: Organization A") It shall be so.

[0066] Similarly, for device 10b, Administrator: Organization A, Organization B, Organization X Owner: Organization B and For device 10c, Administrator:Organization It is assumed that the owner of this device 10c is not registered (no owner organization identification information is associated with the device identification information of this device 10c in the device information database).

[0067] In the following example, User α belongs to organization A (hereinafter, this will be written as User α: Organization A), User β: Organization B, User ξ: Organization X, It is assumed that user η is organization X. It is assumed here that organization X is an administrator organization that is delegated the management of devices by organizations A, B, etc.

[0068] In addition, in this example, the organization information The authentication method specified in the organization authentication policy information of organization A is "single-factor authentication" (here, it is assumed that user identification information and password are used, the same applies below), The authentication method specified in the organization authentication policy information of organization B is "two-factor authentication" (using predetermined biometric information such as fingerprints and one-time passwords in addition to user identification information and passwords; the same applies below) It is assumed that the above is true.

[0069] and, The authentication method specified in the user authentication policy information for user ξ of organization X (administrator organization) is "single-factor authentication", It is assumed that the authentication method specified in the user authentication policy information for user η of organization X (administrator organization) is “two-factor authentication”.

[0070] Furthermore, each of users α, β, ξ, and η is authenticated in the device management device 30P according to its own user authentication policy information or (if user authentication policy information is not set) organization authentication policy information of the organization to which the user belongs. Based on the above example, an operation example of the device management system 1 of this embodiment will be described.

[0071] First, when organization A delegates the setting operation of the operation target device 10a owned by organization A to organization X, a user ξ of organization X uses his / her own user terminal 20 to send device identification information identifying the operation target device 10a to the device management device 30P, and a request for operation on the operation target device 10a.

[0072] Specifically, the user ξ is authenticated by the equipment management system 1 by inputting authentication information corresponding to the user's authentication information (e.g., user identification information and password information) previously registered in the user management device 30U, for example, by using the user's user terminal 20. The authenticated user ξ operates the user terminal 20 to request the equipment management device 30P to display a list of the operation target devices 10 for which the organization X to which the user ξ belongs is registered as the administrator.

[0073] In response to a request received from the user terminal 20, the equipment management device 30P refers to the equipment information database to generate a list of the target equipment 10 for which the organization X to which the user ξ belongs is registered as the administrator, sends the list to the user terminal 20 of the user ξ, and displays the list to the user ξ.

[0074] This allows the user ξ to specify the operation target device 10a to be operated from the displayed list and execute the operation request. Note that in this example, if the user is authenticated, a list of the operation target devices 10 for which the organization of the user is the administrator is displayed, but among the operation target devices 10, operation target devices 10 for which the authentication method of the user does not satisfy the authentication policy of the owner of the operation target device 10 may be removed from the list and not displayed to the user.

[0075] The equipment management device 30P acquires owner organization identification information associated with the equipment identification information of the operation target equipment 10a specified by the instruction received from the user terminal 20 of the user ξ. In this case, the equipment management device 30P acquires the owner organization identification information of the organization A that is the owner of the operation target equipment 10a.

[0076] The device management device 30P further acquires organization authentication policy information associated with the owner organization identification information from the user management device 30U. Here, the device management device 30P acquires organization authentication information policy information including information for identifying the authentication method of “single-factor authentication” related to organization A. The device management device 30P also acquires user authentication policy information of user ξ.

[0077] Then, the equipment management device 30P compares the acquired user authentication policy information with the organization authentication policy information to check whether or not all authentication methods indicated by the organization authentication policy information are included in the authentication methods indicated by the user authentication policy information.

[0078] Here, the user authentication policy information of user ξ acquired by the device management device 30P is “single-factor authentication” and the organization authentication information policy information is “single-factor authentication”, so the device management device 30P determines that the authentication methods represented by the organization authentication policy information are all included in the authentication methods represented by the user authentication policy information, and permits the operation request for the operation target device 10 accepted from the user terminal 20. Then, the device management device 30P sends an instruction to the instructed operation target device 10a based on the content of the operation represented by the information accepted from the user terminal 20.

[0079] In addition, when organization B delegates the setting operation of the operation target device 10b owned by organization B to organization X, when a user ξ of organization X uses his / her own user terminal 20 to send device identification information identifying the operation target device 10b to the device management device 30P and makes a request to operate the operation target device 10b, the device management device 30P operates as follows.

[0080] The device management device 30P in this example acquires owner organization identification information associated with the device identification information of the operation target device 10b transmitted from the user side terminal 20. In this example, the device management device 30P acquires the owner organization identification information of organization B, which is the owner of the operation target device 10b.

[0081] The device management device 30P further acquires organization authentication policy information of organization B associated with the owner organization identification information from the user management device 30U. Here, the device management device 30P acquires organization authentication information policy information including information for identifying the authentication method of “two-factor authentication” related to organization B. The device management device 30P also acquires user authentication policy information of user ξ.

[0082] Then, the equipment management device 30P compares the acquired user authentication policy information of the user ξ with the organization authentication policy information of the organization B, and determines whether or not all of the authentication methods represented by the organization authentication policy information are included in the authentication methods represented by the user authentication policy information.

[0083] In this case, the user authentication policy information of user ξ acquired by the device management device 30P is “single-factor authentication”, and the organization authentication information policy information of organization B, the owner of the operation target device 10b, is “two-factor authentication”. Therefore, the device management device 30P determines that the authentication method represented by the organization authentication policy information is not included in the authentication methods represented by the user authentication policy information, and does not allow the operation request for the operation target device 10 accepted from the user terminal 20.

[0084] On the other hand, when user η of organization X uses his / her user terminal 20 to send device identification information for identifying the target device 10b to the device management device 30P and requests an operation on the target device 10a, the device management device 30P determines whether or not the authentication methods represented by the organization authentication policy information of organization B, which is the owner of the target device 10b, are all included in the authentication methods represented by the user authentication policy information of user η, similar to the example of user ξ described above.

[0085] Here, the user authentication policy information of user η acquired by the device management device 30P is "two-factor authentication", and the organization authentication information policy information of the operation target device 10b is also "two-factor authentication", so the device management device 30P determines that the authentication method represented by the organization authentication policy information of the owner of the operation target device 10b is included in the authentication methods represented by the user authentication policy information, and permits the operation request for the operation target device 10b accepted from the user terminal 20. Then, at this time, in accordance with the instruction from user η, the device management device 30P sends an instruction to the instructed operation target device 10b based on the content of the operation represented by the information accepted from the user terminal 20 of the user η.

[0086] [Devices without owner settings] Furthermore, when the operation target device 10c is designated as an operation target from the user side terminal 20, the device management device 30P gives the user who made the operation request (the authenticated user) permission to operate the operation target device 10c designated by the user as an operation target without comparing the user authentication policy information with the organization authentication policy information, since the organization of the owner of the designated operation target device 10c is not held in the device information database. Note that, since only organization X is registered as the administrator of the operation target device 10c, it is displayed in a list only for users belonging to organization X, and can be operated only by users belonging to organization X.

[0087] That is, in one example of this embodiment, when an operation request specifying an operation target device 10 for which an owner is not set is accepted from an authenticated user, the equipment management device 30P responds to the operation request by sending an instruction based on the content of the operation represented by the accepted information to the specified operation target device 10.

[0088] [Administrator / Owner Settings] In the device management system 1 of this embodiment, the device management device 30P receives, from a user (authenticated user) recorded in the list of authenticated users, device identification information for identifying a new operation target device 10, that is, a device not yet stored in the device information database, as well as an instruction (registration instruction) to set an organization designated by the user as the administrator or owner. Note that the organization to which the user belongs may be configured to be input as the administrator by default.

[0089] In accordance with this registration instruction, the equipment management device 30P associates the manager organization identification information and, if necessary, the owner organization identification information with the accepted equipment identification information, and adds the information to the equipment information database.

[0090] In addition, when the equipment management device 30P wishes to update information on an existing operation target equipment 10, the equipment management device 30P may update the equipment information database in accordance with an organization registration instruction only when the instruction is received from a user who belongs to the organization of the administrator or the organization of the owner of the operation target equipment 10.

[0091] Furthermore, when the owner organization identification information is not associated with the device identification information received together with the organization registration instruction, the device management device 30P may perform control so that multiple administrator organizations cannot be set. In this example, when information identifying the organization that is the owner is not associated with the device to be operated, it becomes impossible to set multiple administrator organizations in association with the device to be operated.

[0092] Furthermore, the equipment management device 30P may receive an instruction from a user belonging to an organization identified by the owner organization identification information or the administrator organization identification information recorded in association with any of the equipment identification information stored in the equipment information database to edit (delete, change, etc.), and perform a process of updating the equipment information database in accordance with the instruction.

[0093] [Authentication at the time of operation] In the above description, the equipment management device 30P authenticates a user before accepting an operation instruction from the user for the operation target equipment 10 that is to be operated, but the present embodiment is not limited to this.

[0094] In one example of this embodiment, when the equipment management device 30P accepts an operation instruction from a user for the operation target equipment 10 that is the subject of the operation instruction, the equipment management device 30P compares the user authentication policy information of the user with the organization authentication policy information of the organization of the owner of the operation target equipment 10 that is the subject of the operation instruction, regardless of whether the user is already authenticated (the user is identified by information recorded in the list of authenticated users), and when it is determined as a result of the comparison that operation permission should be granted (after the determination), the equipment management device 30P may re-authenticate the user, and when the authentication is successful, send an instruction based on the content of the operation represented by the information accepted from the user to the operation target equipment 10.

[0095] In this case, when a request is made to operate the operation target device 10, the user making the request must be authenticated every time. This makes the operation complicated, but improves security.

[0096] Alternatively, after the above-mentioned judgment, the equipment management device 30P may check whether the user is already in an authenticated state or not, and if the user is in an authenticated state, send an instruction based on the content of the operation represented by the information accepted from the user to the equipment 10 to be operated, and if the user is not in an authenticated state, may re-authenticate the user, and if the authentication is successful, send an instruction based on the content of the operation represented by the information accepted from the user to the equipment 10 to be operated.

[0097] In this example, when an operation is requested for the target device 10, if a predetermined time has passed since the last authentication of the user making the request, and even if the user identification information identifying the user has been deleted from the list of authenticated users, authentication of the user will be performed again at that time.

[0098] [Authentication method level information] In the above example, if the authentication methods represented by the organization authentication policy information of the owner organization are all included in the authentication methods represented by the user authentication policy information, the user is deemed to have been authenticated in accordance with the organization authentication policy information of the owner organization, and is permitted to operate the target device 10 owned by the owner organization.

[0099] However, the present embodiment is not limited to this example. For example, all possible authentication methods may be associated with level information, and the level information may be compared to determine whether or not to permit an operation on the target device 10.

[0100] Here, the level information can be set manually according to the security level. For example, an authentication method using user identification information and a password can be set as "Level 1." Also, two-factor authentication can be set as "Level 2," two-factor authentication involving biometric authentication such as fingerprints or faces as "Level 3," and so on.

[0101] In this case, the device management device 30P compares the highest level information Lc among the level information set in the authentication method (there may be multiple) represented by the organization authentication policy information of the owner organization with the highest level information Lu among the level information set in the authentication method represented by the user authentication policy information of the user who made the operation request, and if Lc≦Lu, the device management device 30P permits the operation of the operation target device 10 owned by the owner organization. Also, if Lc>Lu, the device management device 30P does not permit the operation of the operation target device 10 owned by the owner organization.

[0102] [Multiple Owners] Furthermore, in this embodiment, in the device information database of the device management device 30P, there may be cases where multiple owner organization identification information are associated with and registered as device identification information identifying one operation target device 10, that is, one operation target device 10 is shared by multiple organizations.

[0103] In this case, when the equipment management device 30P accepts equipment identification information identifying the equipment 10 to be operated and a request to operate the equipment 10 to be operated from the user terminal 20, and refers to the equipment information database to obtain the owner organization identification information stored in the memory unit 32P in association with the accepted equipment identification information, it obtains multiple owner organization identification information.

[0104] At this time, the device management device 30P may perform the following process: That is, the device management device 30P acquires, from the user management device 30U, organization authentication policy information associated with each of the acquired pieces of owner organization identification information.

[0105] The equipment management device 30P acquires from the user management device 30U user authentication policy information associated with the user identification information of the user of the user terminal 20 that requested the operation on the target equipment 10, and compares the acquired user authentication policy information with at least one of the multiple organization authentication policy information previously acquired.

[0106] For example, the equipment management device 30P calculates a logical sum (including information included in any of) of information identifying an authentication method included in each of the acquired multiple pieces of organization authentication policy information, and if all of the authentication methods resulting from the calculation of the logical sum are included in the authentication methods represented by the acquired user authentication policy information, it determines that the user has been authenticated in accordance with the organization authentication policy information of the owner organization and permits operation of the target equipment 10.

[0107] Specifically, the acquired organizational authentication policy information is as follows: {Authentication method A, Authentication method B} and, {Authentication method A, Authentication method C} When this is the case, the device management device 30P calculates the logical sum {Authentication method A, Authentication method B, Authentication method C} If the authentication methods represented by the obtained user authentication policy information include all of authentication methods A, B, and C, authentication level conformance information is output.

[0108] As another example, when comparing level information associated with an authentication method, the device management device 30P extracts the highest level information Lc from among the level information set for the authentication method included in each of the acquired multiple pieces of organization authentication policy information. The device management device 30P also extracts the highest level information Lu from among the level information set for the authentication method represented by the user authentication policy information of the user who has requested the operation, and compares it with the previously extracted level information Lc. If Lc≦Lu, the device management device 30P permits the operation of the operation target device 10 specified as the operation target. If Lc>Lu, the device management device 30P does not permit the operation of the specified operation target device 10.

[0109] [Management Device] In the explanation of this embodiment so far, the equipment management device 30P and the user management device 30U have been described as separate server devices that are communicatively connected to each other via a network, but this embodiment is not limited to this, and the equipment management device 30P and the user management device 30U may be configured as an integrated server device.

[0110] [Effects of the embodiment] According to this embodiment, even if the owner outsources work to a user outside the organization and sets the user as an administrator, the owner can require the user who belongs to the organization who is the administrator to comply with the security policy defined by the owner's organization. [Explanation of symbols]

[0111] 1 device management system, 10 device to be operated, 20 user terminal, 30 management device, 31 control section, 32 storage section, 33 communication section, 311 authentication section, 312 acceptance section, 313 comparison section, 314 judgment section, 315 operation instruction section.

Claims

1. A management device that manages the device to be operated; A device management system including a user terminal, The management device includes a storage means for storing user authentication policy information related to an authentication policy for each user, organization authentication policy information related to an authentication policy for each organization, and a device information database in which information identifying an organization that is an owner of each device to be operated is associated with each device; a comparison means for receiving a designation of a device to be operated from a user of the terminal, identifying an organization of an owner of the designated device by referring to the device information database, and comparing an authentication policy of the identified organization with an authentication policy of the user; a determination means for determining whether or not to grant the user permission to operate a device designated by the user as an operation target based on a result of the comparison by the comparison means; Includes an equipment management system.

2. A management device for managing an operation target device, a storage means for storing user authentication policy information related to an authentication policy for each user, organization authentication policy information related to an authentication policy for each organization, and a device information database in which information identifying an organization that is an owner of each device to be operated is associated with each other; a comparison means for receiving from a user a designation of a device to be operated, identifying an organization of an owner of the designated device by referring to the device information database, and comparing an authentication policy of the identified organization with an authentication policy of the user; a determination means for determining whether or not to grant the user permission to operate a device designated by the user as an operation target based on a result of the comparison by the comparison means; A management device including:

3. The management device according to claim 2, The device information database further includes a setting unit for setting administrator information that is associated with the device to be operated and that specifies an administrator organization that can operate the device, This setting means is a management device that, when information identifying an organization that is the owner of a device to be operated is not associated with the device to be operated, makes it impossible to set multiple administrator organizations in association with the device to be operated.

4. The management device according to claim 2, If the organization of the owner of the designated device is not stored in the device information database, the comparison means outputs information to that effect; The judgment means is a management device that receives information that the organization of the owner of the specified device is not held in the device information database, and gives the authenticated user permission to operate the device that the user has specified as the target to be operated.

5. 3. The management device according to claim 2, The authentication policy for each user and the authentication policy for each organization each include information regarding at least one authentication method to be requested at the time of authentication, the comparing means receives, from an authenticated user, a designation of a device to be operated, identifies an organization of an owner of the designated device by referring to the device information database, and compares an authentication method specified by information included in an authentication policy for the identified organization with an authentication method specified by information included in an authentication policy for the user; The judgment means is a management device that grants the authenticated user permission to operate a device designated by the user as an operation target when all of the authentication methods specified by information contained in an authentication policy for the specified organization are included in the authentication methods specified by information contained in an authentication policy for the user.

6. The management device according to claim 5 , A management device, in which the authentication methods included in the authentication policy include at least an authentication method using multi-factor authentication.

7. The management device according to any one of claims 2 to 6, further comprising an authentication means for authenticating the user based on an authentication policy of the user; The comparison means is a management device that receives designation of a device to be operated from the authenticated user, identifies the organization of the owner of the designated device by referring to the device information database, and compares the authentication policy of the identified organization with the authentication policy of the user.

8. The management device according to claim 2, The determination means is a management device that determines, based on a result of the comparison by the comparison means, whether or not to permit the authenticated user to perform a predetermined operation on a device designated by the authenticated user as an operation target.

9. The computer that manages the device to be operated is a storage means for storing user authentication policy information related to an authentication policy for each user, organization authentication policy information related to an authentication policy for each organization, and a device information database in which information identifying an organization that is an owner of each device to be operated is associated with each other; a comparison means for receiving from a user a designation of a device to be operated, identifying an organization of an owner of the designated device by referring to the device information database, and comparing an authentication policy of the identified organization with an authentication policy of the user; a determination means for determining whether or not to grant the user permission to operate a device designated by the user as an operation target based on a result of the comparison by the comparison means; A program that functions as a

Citation Information

Patent Citations

  • Two-factor authentication system, two-factor authentication method, two-factor authentication program, and authentication operation application

    JP2021144598A